A few days ago I posted about a problem with the administrator password. I couldn't logon from anywhere on the network. Now I realized that the administrator's password had been changed. I changed the administrator password and created a new account for admin purposes. When I changed the admin password the dc was only locked then i got access to it and be able to change the password.
This morning i was checking the TS connections a notice one connection using the administrator account. I'm the only one using the admin account, therefore i new it was something odd, then i remoted control the connection and found out that this connection (administrator) was running AMS (Advance Mass Sender), also notice that it was forwarding a lot of emails.
I logged off the intruder, but a few minutes later it was connected again. Then I changed the administrators's local account password on the TS, whic is the only one left to change, then I ckicked him/her/it off and haven't see it connected again for the last 20 minutes.
When this administrator account was connected to TS, there was no connection for it on the RRAS. How were they connected then to my TS which is running on another box.
On my router I have only the needed ports open, I'm running ISA with a multi-homed system.
BTW....I'm running SBS2003 (1 DC, multi-home) The TS is a windows 2000 server.
How can i make sure that this people does connect again...
as i mentioned i changed the administrator password and created a new account to logon for admin purpose.
Please help as soon as posible!!!
This morning i was checking the TS connections a notice one connection using the administrator account. I'm the only one using the admin account, therefore i new it was something odd, then i remoted control the connection and found out that this connection (administrator) was running AMS (Advance Mass Sender), also notice that it was forwarding a lot of emails.
I logged off the intruder, but a few minutes later it was connected again. Then I changed the administrators's local account password on the TS, whic is the only one left to change, then I ckicked him/her/it off and haven't see it connected again for the last 20 minutes.
When this administrator account was connected to TS, there was no connection for it on the RRAS. How were they connected then to my TS which is running on another box.
On my router I have only the needed ports open, I'm running ISA with a multi-homed system.
BTW....I'm running SBS2003 (1 DC, multi-home) The TS is a windows 2000 server.
How can i make sure that this people does connect again...
as i mentioned i changed the administrator password and created a new account to logon for admin purpose.
Please help as soon as posible!!!