Good Day,
Recently one of my Windows 2003 SBS servers crashed. It was not a hardware crash - it was the OS itself. It was a mirrored system and both mirrors went down and were unbootable. I was able to Ghost the data from one the failed drives onto another HD. After reloading the OS as a new installation on the ghosted HD I noticed there was a folder called "wyndows" on the drive with a subfolder "system32". Both folders were empty.
Curiously they were created at just about the time I suspect the OS crashed; 21:11 on a Sunday night.
No one was in the building at that time and no users have access to the server or system drive on the server anyway.
We have a SonicWall TZ170 for a firewall. Port 3389 (terminal server) was open on the firewall and was being directed to a workstation PC on the network, but Remote Desktop was disabled on that workstation at the time. Port 443 was also open on the firewall but was protected by a strong password. The firewall logs show nothing. No other ports were open.
My question is; In your opinion did I somehow get hacked? and if so did the hacker leave behind the "wyndows" folder as a taunt? Has anyone else ever seen this?
Thanks for reading.
ChrisK
Recently one of my Windows 2003 SBS servers crashed. It was not a hardware crash - it was the OS itself. It was a mirrored system and both mirrors went down and were unbootable. I was able to Ghost the data from one the failed drives onto another HD. After reloading the OS as a new installation on the ghosted HD I noticed there was a folder called "wyndows" on the drive with a subfolder "system32". Both folders were empty.
Curiously they were created at just about the time I suspect the OS crashed; 21:11 on a Sunday night.
No one was in the building at that time and no users have access to the server or system drive on the server anyway.
We have a SonicWall TZ170 for a firewall. Port 3389 (terminal server) was open on the firewall and was being directed to a workstation PC on the network, but Remote Desktop was disabled on that workstation at the time. Port 443 was also open on the firewall but was protected by a strong password. The firewall logs show nothing. No other ports were open.
My question is; In your opinion did I somehow get hacked? and if so did the hacker leave behind the "wyndows" folder as a taunt? Has anyone else ever seen this?
Thanks for reading.
ChrisK