Active Directory Lockout Recovery & Clean Rebuild for AJM Engineering

Client: AJM EngineeringCompleted: 12 August 2026Tags: Cybersecurity · Managed Services · Incident Response

AJM Engineering — AJM Engineering was locked out of their own server after a previous provider changed Active Directory passwords and planted a logoff script plus monitoring malware across the network. African Vanilla recovered the domain, SAGE on SQL Server, and a degraded RAID 5 server over a weekend, then took over as the accountable IT partner.

Organised server room with blue ethernet cabling and network switches, representing recovered infrastructure for AJM Engineering

The Challenge

AJM Engineering called African Vanilla after a breakdown with their previous IT provider left the business locked out of its own infrastructure. The outgoing provider had changed Active Directory passwords, altered the logon path, and planted a logoff.exe that fired for every user profile via a scheduled task — kicking people off as soon as they signed in. The same footprint included monitoring malware on the server and on workstations across the network. SAGE accounting, which ran on SQL Server, was unavailable with the rest of the estate. The production server was also running in a degraded RAID 5 state because maintenance had been neglected, and usable backups stopped in 2023 — so there was no recent restore path to fall back on. Production and office systems were effectively held hostage until someone who understood AD, Group Policy, storage recovery and forensic cleanup could reclaim control.

Our Solution

Jacques and the African Vanilla team spent a focused weekend on emergency recovery: regain console and domain access, reverse the malicious logon/logoff chain, rotate credentials end-to-end, and strip monitoring malware from the server and every affected PC. In parallel we recovered the SQL Server environment so SAGE accounting was usable again, and addressed the degraded RAID 5 array that neglect had left fragile. Once the domain and accounting stack were stable we hardened AD, rebuilt trust in the workstation estate, put backups back on a managed cadence, and moved AJM onto the Vanilla Partnership Programme — monitoring, helpdesk, patching and a 2-hour critical response guarantee — so a single provider can never again hold the keys without transparency.

When a manufacturer or engineering firm loses Active Directory, it is not an “IT inconvenience”. It is payroll, drawings, email, file shares, accounting and shop-floor systems stopping at once.

AJM Engineering found themselves in exactly that position. The previous provider had not simply handed over credentials — they had changed Active Directory passwords, interfered with the logon script / profile path, and left a logoff.exe that ran for every user through a scheduled task. As soon as someone signed in, the script logged them off. Alongside that, monitoring malware sat on the server and on PCs across the network. SAGE accounting, running on SQL Server, was down with everything else. The server itself was running in a degraded RAID 5 state because maintenance had been neglected — and the last backups dated from 2023, so there was no recent recovery safety net. From the business’s point of view it felt like a ransom: without the outgoing provider’s cooperation, they could not run their own domain or books.

What we walked into

  • No usable privileged path into Active Directory
  • Logon hijack that made interactive sessions unusable
  • Persistence via scheduled tasks (not a one-off script on a single desktop)
  • Monitoring / remote-control malware spanning server + workstation estate
  • SAGE / SQL Server unavailable during the lockout
  • A production server in degraded RAID 5 from neglected maintenance
  • Backup neglect — last usable backups from 2023
  • An urgent need to reclaim ownership, not negotiate indefinitely with the outgoing party

Weekend recovery

African Vanilla treated it as an incident-response engagement, not a ticket.

  1. Regain access — console and privileged recovery paths until domain control was back with AJM.
  2. Break the kill-chain — remove logoff.exe, scheduled tasks and logon-script tampering from every profile path.
  3. Credential reset — rotate AD and privileged accounts so old provider credentials were worthless.
  4. Malware sweep — clean monitoring implants from the server and networked PCs.
  5. Accounting recovery — bring SQL Server and SAGE back into a usable state so the business could invoice and close books again.
  6. Storage recovery — address the degraded RAID 5 condition and stop treating a neglected array as “good enough”.
  7. Stabilise — validate Group Policy, shares and day-to-day logons before Monday production pressure returned; put backups back under managed discipline.

After the firefight: accountable managed IT

Recovery without a new operating model just invites the next failure. AJM moved onto African Vanilla’s managed stack: 24/7 monitoring, unlimited helpdesk, patching, backups and a documented 2-hour critical SLA — on transparent month-to-month terms. The lesson for every Gauteng engineering and manufacturing SME is blunt: if your provider can lock you out of Active Directory — and your backups stopped years ago — you do not have a partner — you have a single point of failure.

Who this is for

Engineering firms, manufacturers and professional practices that need a clean break from a hostile or opaque IT provider — and a team that will show up on a weekend when AD, accounting and storage are all on the line.

Locked out, ransomed by credentials, or unsure what your previous provider left behind? Book a free IT audit or call +27 71 672 3800.

"We were locked out of our own systems. African Vanilla came in over a weekend, took back Active Directory, got SAGE and SQL Server running again, fixed a RAID array that had been left in a bad state, and cleaned out what the previous provider had left behind. We finally have IT we can trust — and we own our environment again."
Marco Marques
Director, AJM Engineering

Key Results

  • Domain and server reclaimed from the outgoing provider over a weekend emergency engagement
  • Malicious logoff.exe + scheduled-task logon hijack removed from all profiles
  • Monitoring malware cleaned from the server and workstations across the network
  • SAGE accounting recovered on its SQL Server stack after the lockout made it unavailable
  • Degraded RAID 5 server restored to a maintainable state after neglected array health
  • Backup neglect called out (last usable backups from 2023) and replaced with managed backup discipline
  • Active Directory passwords and privileged accounts rotated; trust path restored for day-to-day work
  • Ongoing managed IT so AJM owns their environment again — month-to-month, no lock-in

Want similar results for your Gauteng business?

Start with a free, no-obligation IT audit. We will give you clarity on your current state and what a transparent partnership would deliver.

Book Your Free IT Audit →

Or call — we're local and we answer +27 71 672 3800