Security Basics mailing list archives

XP Box appears to be compromised


From: "Gregory M. Brown" <gbrown () alvalearning com>
Date: Wed, 6 Aug 2003 11:03:31 -0600

I've got an issue with what appears to be remote desktop management of
an XP box.  It's weird...

There are deliberate mouse movements on this box.  I'm assuming it's an
internal person doing this as our FW and Fortinet device will block any
remote seizing of a desktop.  I've disabled all the XP remote services,
and it continues to happen.  I could bust open packets with sniffer, but
there is a time constraint as the organization laid virtually all IT
people off.  Imagine that....

What should I be looking for?  I need to nail whoever is doing this. 

Thanks for any help.

Greg B.



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: