useractive
Programmer
I have a feeling an NT Server in a remote office has been the victim of foul play. Ever since Monday, accounts have been locked out after 3 attempts (when nobody was on the system) and other such weird things. The event viewer log was also cleared for the day of the 15th only. My questions are these:
Is there a way to look around and see if anything was installed on there? (Packet sniffer, etc).
Is there a way to tell if anything has been done like password programs or other type stuff installed?
I'm looking at getting zone alarm to run across the computer to tell, but I want to trace back the IP address of whatever did this somehow. Any suggestions or comments would be helpful.
Thanks,
Swish
Is there a way to look around and see if anything was installed on there? (Packet sniffer, etc).
Is there a way to tell if anything has been done like password programs or other type stuff installed?
I'm looking at getting zone alarm to run across the computer to tell, but I want to trace back the IP address of whatever did this somehow. Any suggestions or comments would be helpful.
Thanks,
Swish