Solved

Win2000 Server - local admin password changed to blank

Posted on 2004-08-13
6
200 Views
Last Modified: 2010-04-13
Setup:
Win2000 Server SP4
File and Printer server, not a DC
Not running Active Directory

Our sysadmin tried to reboot this server and found that he couldn't.
While investigating, he discovered some strange behaviour:
  - could not run Norton AV
  - the local admin password was blank
  - couldn't surf the internet
  - couldn't open Computer Management
  - couldn't open Services
  - couldn't execute batch files in a command window
  - couldn't run 'net stop' in command window
  - could not stop most processes in task manager. "Access denied"
  - computer would not shut down.  When he pressed the power button, a message flashed
    saying something about Remote Storage not shutting down. (message flashed too quickly to get more detail)

When he powered the computer back up, he booted into safe mode and ran a virus scan.  It came back clean.

After determining the admin password was blank, he changed the password and all is running fine now.

The questions are:  have you heard of this happening before?  What would cause this?

bkt
0
Comment
Question by:bkthompson2112
6 Comments
 
LVL 15

Accepted Solution

by:
Rob Stone earned 200 total points
ID: 11793505
Someone may have been taking the p**s and used the password recovery tools to mess your server up (http://home.eunet.no/~pnordahl/ntpasswd/)

Other than that I don't know
0
 
LVL 4

Assisted Solution

by:shard26
shard26 earned 100 total points
ID: 11794725
For those of you who don't know, "taking the p**s" means messing with you.
0
 
LVL 9

Assisted Solution

by:BigC666
BigC666 earned 100 total points
ID: 11796591
sounds like they did a good job too
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 15

Expert Comment

by:Rob Stone
ID: 11807855
Cheers shard26 :-)
0
 
LVL 6

Author Comment

by:bkthompson2112
ID: 11809360
Thanks for your responses.

Yeah, we thought we were probably hacked, but can't determine how they got in.

Unlikely it's an insider.

I'll leave this open, hopefully get some more responses.

Thanks again,
bkt
0
 

Assisted Solution

by:RobertMAtkins
RobertMAtkins earned 100 total points
ID: 11893857
Make sure that you read and UNDERSTAND the syskey.txt at that site :)
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Adults who share images on social media aren’t the only ones who need to worry about their privacy. Our culture’s tendency to share every move and celebration affects the privacy of our children, too.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question