Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help With this Event ID Please

Status
Not open for further replies.

Tona955

Technical User
Oct 19, 2007
8
GB
Hi All,

I posted this question on the SBS side and just realised that I should have posted it here on the Server 2003 side, appologies for that.

I have an event showing up on my application events that I can't find a fix on.

Source: UserInit
Event ID: 1000
Computer PUMPKIN-2003 ( Our Server)
Description:
Could not execute the following script C:\WINDOWS\$NtUninstallKB945553$\spuninst\1.bat. The system cannot find the file specified.

Some history.

This server was being hacked by someone in China end of last year, I Formated the server and rebuilt it, I formatted all the workstations and reinstalled Windows XP Pro.
We are running Symantec AntiVirus and I usually check for malware and trojans (Malware Bytes)
Few weeks ago I lost some users out of Active Driectory, I recreated these two users, last weekend I lost all users except the administrator and my own login from the active directory, at that time I could see allot of (Events 1202 source SceCli, security policies were propogated with warning0x534. no mapping between account names and security IDs were done.

I think we might still be under attact, a couple of users use RDP to connect remotely, my intension is to install a second network card and configure VPN for remote access.

I would really appreciate some help with this event.

Many thanks in advance.
 
I'd say you're right. There is something nefarious going on there. Something shouldn't be trying to run a .bat file during normal operations (AFAIK).

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
Microsoft Security Bulletin MS08-020 – High
lack of security in DNS-Client might be used for spoofing (945553)

i go with 58sniper, something is wrong
 
a couple of users use RDP to connect remotely

Where do they RDP to to?? To their desktops or to a server?, not the DC surely?

You are on the right track as the others have said, although I personally would have a dedicated device such as a router/firewall/VPN device acting as my VPN endpoint and not a server.

Paul
MCSE 2003
MCSA 2003
MCITP Enterprise Administrator

If there are no stupid questions, then what kind of questions do stupid people ask? Do they get smart just in time to ask questions?
Scott Adams
 

Thanks all for your support.

We do have a router in place with firewall implemented within it, not sure how good it is tho.

The clients RDP straight into an application on the server utilising MS-Access.
The only two clients going directly into the DC is myself and the software support company.

The client is curreltly using Wanadoo/Orange broadband with a dynamic WAN address, we are in the process of moving them to Eclipse business broadband with a static IP WAN address, this should help also.

I have arranged a site visit for tomorrow to further investagate, I will also be running some RootKit scanners.

Will keep you posted, many thanks once again.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top