Click here to get back home

strange file on c: root

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
strange file on c: root Pedro Leite 10-18-2005
Posted by Pedro Leite on October 18, 2005, 11:04 am
Please log in for more thread options
hello everybody

this morning i found a strange file on my c:\ root
this one --> sc12.bin.incr.2005.10.17.14.16.10.2005.10.17.19.30.28.utp
created on 17 - oct at 22:38:10 , owned by the administrators group. i
didn't do it.

the setup is sbs2k3, running isa as a firewall.
on the packet filter logs for isa, i found :
from 22:00 onwards, some allowed connections on port 80, and some allowed
connections on remote port 110, due to the pop3connector retreiveing mail.
all other connections are reported as blocked, including on port 135 at
22:38:10
PFlogDate PFlogTime SourceAddress DestinationAddress Protocol Param#1
Param#2 TcpFlags FilterRule Interface IPHeader IPHeaderDump Payload
PayloadDump
17-10-2005 22:38:10 81.193.19.13 xx.xx.xx.xx Tcp 4715 445 SYN
BLOCKED Dialout 45 00 00 30 d6 87 40 00 7e 06 f4 99 51 c1 13 0d 51 c1 7b
17
12 6b 01 bd 3b 4d 93 ea 00 00 00 00 70 02 75 30 f8 f0 00 00 02 04 05 ac
01 01 04 02



still, does this means i have been hacked ?
how can i make sure i have been, or not, hopefully

many thanks
Pedro Leite, from Portugal




Similar ThreadsPosted
Migrate Enterprise root authority CA to stand-alone root CA December 13, 2005, 7:57 am
Stans-alone root CA or Enterprise root CA August 31, 2006, 6:32 pm
Strange issue with ACL September 26, 2005, 7:21 pm
very very strange problem.. please help! February 24, 2007, 10:40 am
Strange Stuff June 19, 2008, 5:51 pm
Strange appearances in Logs December 21, 2005, 8:10 am
NTFS Deny not Working STRANGE September 30, 2005, 4:40 am
Security Log Event has Strange Timestamp April 5, 2006, 2:20 pm
Rather strange issuance of Kerberos tickets July 9, 2006, 6:31 pm
Strange folder security problem October 4, 2006, 3:45 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap