Finding a Hacker



One of my clients has a Win 2003 standard PDC with about 10 winXP clients.
I've had AD setup and been running fine for years. Last week, I was sitting
at one of the XP clients on the domain and suddenly I got logged off and a
user "userHacker" logged back in. I had to hit ctrl-alt-delete and logged
myself back in.

After about 60 seconds, it happened again. So I cut off access to the net
and looked at the pc's user profiles and noticed their was a local account
for "userHacker". I deleted the profile and left the pc off line.

I should mention that I have Remote Desktop and pcAnywhere ports open in the
firewall for this XP machine.

1. Is there a log within the PDC AD that would show a record of users that
logged into the WinXP machine?
2. How can I determine which port the hacker is coming through?
3. Although I searched AD's Users and Computers applet, I couldn't find a
"userHacker" account. I'm assuming the account was a local account on the XP
machine. Is there anyway for him to have created an "hidden" account?
4. Does "Remote Desktop" keep any type of activity log that would help me?

Any ideas on restricting remote desktop connections by user account or ip
address would be appreciated.


.



Relevant Pages

  • Re: Mixed day yesterday
    ... I thought if i told them it was on account of some long ago song triggering me they would think i was being really daft. ... Was very tempted to rush out the door and flee home .We were going to go to Starbucks on account of it being one of the clients 60th birthday ... This afternoon went to my mothers and had my hair cut. ...
    (uk.people.support.depression)
  • Re: Take Over Practices
    ... didn't steal an account as much as you lost an account! ... customer is unhappy with services provided. ... takeover clients from ADT and the other mass market "paper flippers"...... ...
    (alt.security.alarms)
  • Re: OT Why ... Ping DerbyDad03
    ... checking account. ... or just pinching the pennies too much. ... our clients and ourselves and then faxed to insurance companies, ... either networked to the PC's of the operations staff that ...
    (alt.home.repair)
  • Re: Relationships
    ... This is my first experience with building a database, ... >>every account is in the process of receiving or delivering assets. ... > multiple clients and individual clients within an account might have ...
    (microsoft.public.access.tablesdbdesign)
  • Re: Please Help - User Profile Problems???
    ... Can the same user log in successfully to an NT workstation? ... > I have an SBS4.5 network with mainly NT4w clients. ... > means of a single general account that is enabled through Proxy Server so ...
    (microsoft.public.windowsxp.security_admin)