Solved

Win2000 Server - local admin password changed to blank

Posted on 2004-08-13
6
202 Views
Last Modified: 2010-04-13
Setup:
Win2000 Server SP4
File and Printer server, not a DC
Not running Active Directory

Our sysadmin tried to reboot this server and found that he couldn't.
While investigating, he discovered some strange behaviour:
  - could not run Norton AV
  - the local admin password was blank
  - couldn't surf the internet
  - couldn't open Computer Management
  - couldn't open Services
  - couldn't execute batch files in a command window
  - couldn't run 'net stop' in command window
  - could not stop most processes in task manager. "Access denied"
  - computer would not shut down.  When he pressed the power button, a message flashed
    saying something about Remote Storage not shutting down. (message flashed too quickly to get more detail)

When he powered the computer back up, he booted into safe mode and ran a virus scan.  It came back clean.

After determining the admin password was blank, he changed the password and all is running fine now.

The questions are:  have you heard of this happening before?  What would cause this?

bkt
0
Comment
Question by:bkthompson2112
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 15

Accepted Solution

by:
Rob Stone earned 200 total points
ID: 11793505
Someone may have been taking the p**s and used the password recovery tools to mess your server up (http://home.eunet.no/~pnordahl/ntpasswd/)

Other than that I don't know
0
 
LVL 4

Assisted Solution

by:shard26
shard26 earned 100 total points
ID: 11794725
For those of you who don't know, "taking the p**s" means messing with you.
0
 
LVL 9

Assisted Solution

by:BigC666
BigC666 earned 100 total points
ID: 11796591
sounds like they did a good job too
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 
LVL 15

Expert Comment

by:Rob Stone
ID: 11807855
Cheers shard26 :-)
0
 
LVL 6

Author Comment

by:bkthompson2112
ID: 11809360
Thanks for your responses.

Yeah, we thought we were probably hacked, but can't determine how they got in.

Unlikely it's an insider.

I'll leave this open, hopefully get some more responses.

Thanks again,
bkt
0
 

Assisted Solution

by:RobertMAtkins
RobertMAtkins earned 100 total points
ID: 11893857
Make sure that you read and UNDERSTAND the syskey.txt at that site :)
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question