User accounts are unexpectedly locked, and event ID 12294 is logged in Windows Server

Applies to: Windows Server version 1803Windows Server 2016Windows Server 2012 R2 More

Symptoms


Users on your network may unexpectedly have their user accounts locked. This behavior occurs even though users have not previously tried to log on and have not typed any incorrect user names or passwords. When this behavior occurs, the following event is recorded in the event log on Microsoft Windows Server 2003-based computers:

 

Cause


This issue may occur when a computer on your network is infected with the W32.Randex.F worm or with a variant of it.

Resolution


To resolve this issue, run a complete virus scan on your network using the latest available virus definitions. Use the scan to remove the W32.Randex.F worm. For information about how to perform a virus scan or how to obtain the latest virus definitions, see your antivirus software documentation, or contact the manufacturer.

For additional information about how to contact the manufacturer of your antivirus program, click the following article number to view the article in the Microsoft Knowledge Base:

49500 List of antivirus software vendors

More Information


For additional information, click the following article number to view the article in the Microsoft Knowledge Base:

129972 Computer viruses: description, prevention, and recovery