![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2007
Location: Swansea, Wales, UK
Posts: 36
OS: winxp
|
[SOLVED] User's keep appearing in administrators group??
Hello All
Over the last few weeks something very strange has ben happening with my server. (server 2003) Every few days users ( that I have not created) keep on showing up in members of adminsitrators group? I keep on deleting these users but they keep on coming back! I have Macaffe AV and a fire wall on the server but I think this is spyware? the user names that appear are things like...sony...spy...pm...exit etc what do you think I should do? run spybot or maybe adaware? thanks in advance Nick |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) | ||
|
Moderator Hardware Team
|
Re: User's keep appearing in administrators group??
It does sound like an infection of some kind, but could also be one of your users messing about with profile settings.
How many legitimate users are on the network, and can they be trusted not to try to bypass your security settings? For example, if this is a work environment, admin rights would allow them to surf MySpace, play Flash games, install software, view private documents, etc. Run some malware scans and if you find anything that can't be fixed, post back to the HJT forum so our analysts can see what's going on. Have you tried auditing the new accounts to see what the user is doing? From http://support.microsoft.com/kb/300549 Quote:
From http://www.lockergnome.com/it/2004/1...2003-auditing/ Quote:
__________________
![]() New members: Subscribe to your thread (Thread Tools) to receive an instant email notification when you get a reply. TSF Folding@Home Team 85015 - details here |
||
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jan 2007
Location: Swansea, Wales, UK
Posts: 36
OS: winxp
|
Re: User's keep appearing in administrators group??
Hi thanks for the reply
to be honest I dont think its one of the user's...I have about 60 users on the network but none would need to or be capable of that. I have checked all the security logs and there are no suspicious events?? But I'm going to run some malware scans and let you know how I get on Thanks for your help |
|
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jan 2007
Location: Swansea, Wales, UK
Posts: 36
OS: winxp
|
Re: User's keep appearing in administrators group??
Ran a scan on the server lastnight and my spyware doctor pciked up a trojan "online games"....anyway since then I have not had any new admins appear in the group...so fingers crossed!
let you know in soon if we can close this! thanks |
|
|
|
|
|
#5 (permalink) |
|
TSF Enthusiast
Join Date: Aug 2008
Posts: 2,294
OS: Windows 2000 SP4 and Windows XP SP3
|
Re: User's keep appearing in administrators group??
Reminds me of the old exploit in Windows NT: getadmin and sechole. Anyone (even guests!) could run the command and add themselves to the administrators group. Quickly patched, but freaky as heck.
Be sure your server is all patched up, and enable DEP to protect from remote buffer overflow attacks. |
|
|
|
![]() |
| Thread Tools | |
|
|