We help IT Professionals succeed at work.
Get Started

Loss of RDP via youngzsoft.com/cn

iMonkey69 asked
Last Modified: 2013-02-10
Good day all.  I have a strange occurance and am seeking the Experts whom know a way to work this out.

Recently a Windows 2003 lost RDP access from external or internal connections.
After some snooping I noticed that a telnet to 3389 produced a strange result:

+++º-²¦+¦+ú¼¦d+d-ú+++f+¦-¬-¦¦¦-= http://www.youngzsoft.com/cn/

CCProxy seems to be associated with the link, which is valid software....If you installed it??  We didn't.

So, scans produced a couple backdoor trojans and were cleaned but the problem persists.
Subsequent scans are clean.

So, I cannot see any programs relating to CCProxy or the like.  I'm  attaching a Hijack log for review.

Having said all that I DO know that the spoolsv.exe process seems to be the hijacked culprit.  A netstat -no produces: <local server IP>:3389 being ESTABLISHED about 20 times with the PID that macthes the spoolsv.exe.

However killing the process does not free it and a reboot re-establishes the port being blocked.

Nonetheless....I'm a little at a loss on how to trouble shoot this further.

Warmest regards,
C HJT.txt
Watch Question
This problem has been solved!
Unlock 1 Answer and 4 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE