Solved

Win2000 Server - local admin password changed to blank

Posted on 2004-08-13
6
195 Views
Last Modified: 2010-04-13
Setup:
Win2000 Server SP4
File and Printer server, not a DC
Not running Active Directory

Our sysadmin tried to reboot this server and found that he couldn't.
While investigating, he discovered some strange behaviour:
  - could not run Norton AV
  - the local admin password was blank
  - couldn't surf the internet
  - couldn't open Computer Management
  - couldn't open Services
  - couldn't execute batch files in a command window
  - couldn't run 'net stop' in command window
  - could not stop most processes in task manager. "Access denied"
  - computer would not shut down.  When he pressed the power button, a message flashed
    saying something about Remote Storage not shutting down. (message flashed too quickly to get more detail)

When he powered the computer back up, he booted into safe mode and ran a virus scan.  It came back clean.

After determining the admin password was blank, he changed the password and all is running fine now.

The questions are:  have you heard of this happening before?  What would cause this?

bkt
0
Comment
Question by:bkthompson2112
6 Comments
 
LVL 15

Accepted Solution

by:
Rob Stone earned 200 total points
ID: 11793505
Someone may have been taking the p**s and used the password recovery tools to mess your server up (http://home.eunet.no/~pnordahl/ntpasswd/)

Other than that I don't know
0
 
LVL 4

Assisted Solution

by:shard26
shard26 earned 100 total points
ID: 11794725
For those of you who don't know, "taking the p**s" means messing with you.
0
 
LVL 9

Assisted Solution

by:BigC666
BigC666 earned 100 total points
ID: 11796591
sounds like they did a good job too
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 
LVL 15

Expert Comment

by:Rob Stone
ID: 11807855
Cheers shard26 :-)
0
 
LVL 6

Author Comment

by:bkthompson2112
ID: 11809360
Thanks for your responses.

Yeah, we thought we were probably hacked, but can't determine how they got in.

Unlikely it's an insider.

I'll leave this open, hopefully get some more responses.

Thanks again,
bkt
0
 

Assisted Solution

by:RobertMAtkins
RobertMAtkins earned 100 total points
ID: 11893857
Make sure that you read and UNDERSTAND the syskey.txt at that site :)
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now