troubleshooting Question

Loss of RDP via youngzsoft.com/cn

Avatar of iMonkey69
iMonkey69 asked on
Windows 2000
4 Comments1 Solution431 ViewsLast Modified:
Good day all.  I have a strange occurance and am seeking the Experts whom know a way to work this out.

Recently a Windows 2003 lost RDP access from external or internal connections.
After some snooping I noticed that a telnet to 3389 produced a strange result:

+++º-²¦+¦+ú¼¦d+d-ú+++f+¦-¬-¦¦¦-= http://www.youngzsoft.com/cn/

CCProxy seems to be associated with the link, which is valid software....If you installed it??  We didn't.

So, scans produced a couple backdoor trojans and were cleaned but the problem persists.
Subsequent scans are clean.

So, I cannot see any programs relating to CCProxy or the like.  I'm  attaching a Hijack log for review.

Having said all that I DO know that the spoolsv.exe process seems to be the hijacked culprit.  A netstat -no produces: <local server IP>:3389 being ESTABLISHED about 20 times with the PID that macthes the spoolsv.exe.

However killing the process does not free it and a reboot re-establishes the port being blocked.

Nonetheless....I'm a little at a loss on how to trouble shoot this further.

Warmest regards,
C HJT.txt
ASKER CERTIFIED SOLUTION
iMonkey69

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 4 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 4 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros