Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Problem in Windows server 2008 R2

Reply
Thread Tools Display Modes

Problem in Windows server 2008 R2

 
 
Vijay
Guest
Posts: n/a

 
      01-17-2010
Hi,
I'm using windows server 2008 R2. I'm using it for learning purpose in my
PC.
I've listed some problem I'm experiencing. Please tell me whether it is a
virus attack or is someone trying to hack my system.

1. Server summary in server manager is not displaying its contents.
2. My system hangs(Even caplock key or ctrl alt del didn't work).
3. When I double click a file or folder it opens the property of the file or
folder(fixed it with regsvr32 /i shell32).
4. My internet connection was blocked and I've did a bare metal recovery(2
times)(Actually first it was blocked for some minutes and then was ok. After
a week it was entirely blocked).
5. A suspicious login in my system. I found it in my Event log. My system
hanged after 11.01 pm.

I also found some events that occurs at 11 pm and I've noticed "Logon
Process: Advapi" which is a virus.
/////////////////////////////////////////////////////////////////////////////////////
Special privileges assigned to new logon.
Subject:
Security ID: SYSTEM
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
/////////////////////////////////////////////////////////////////////
An account was successfully logged on.
Subject:
Security ID: SYSTEM
Account Name: MyserverName$
Account Domain: myWorkgroup
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: SYSTEM
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x260
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name: Source
Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi (I've found this page when I googled:
http://www.auditmypc.com/process/advapi.asp)
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
////////////////////////////////////////////////////////////////////////////////////////

//////////////////////////////////////////////////////////////////////////////////////////
Special privileges assigned to new logon.
Subject:
Security ID: SYSTEM
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
////////////////////////////////////////////////////////////////////////////////////////////////
An account was successfully logged on.
Subject:
Security ID: SYSTEM
Account Name: MyServername$
Account Domain: MyWORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: SYSTEM
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x260
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name: Source
Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

Thanks in Advance.
Vijay chandar



 
Reply With Quote
 
 
 
 
CK
Guest
Posts: n/a

 
      01-19-2010
HI Vijay I am seeing the same thing below with the Logon GUID being all
zeroes. Here is the answer:

http://blogs.technet.com/ken_brumfie...-question.aspx



"Vijay" wrote:

> Hi,
> I'm using windows server 2008 R2. I'm using it for learning purpose in my
> PC.
> I've listed some problem I'm experiencing. Please tell me whether it is a
> virus attack or is someone trying to hack my system.
>
> 1. Server summary in server manager is not displaying its contents.
> 2. My system hangs(Even caplock key or ctrl alt del didn't work).
> 3. When I double click a file or folder it opens the property of the file or
> folder(fixed it with regsvr32 /i shell32).
> 4. My internet connection was blocked and I've did a bare metal recovery(2
> times)(Actually first it was blocked for some minutes and then was ok. After
> a week it was entirely blocked).
> 5. A suspicious login in my system. I found it in my Event log. My system
> hanged after 11.01 pm.
>
> I also found some events that occurs at 11 pm and I've noticed "Logon
> Process: Advapi" which is a virus.
> /////////////////////////////////////////////////////////////////////////////////////
> Special privileges assigned to new logon.
> Subject:
> Security ID: SYSTEM
> Account Name: SYSTEM
> Account Domain: NT AUTHORITY
> Logon ID: 0x3e7
> Privileges: SeAssignPrimaryTokenPrivilege
> SeTcbPrivilege
> SeSecurityPrivilege
> SeTakeOwnershipPrivilege
> SeLoadDriverPrivilege
> SeBackupPrivilege
> SeRestorePrivilege
> SeDebugPrivilege
> SeAuditPrivilege
> SeSystemEnvironmentPrivilege
> SeImpersonatePrivilege
> /////////////////////////////////////////////////////////////////////
> An account was successfully logged on.
> Subject:
> Security ID: SYSTEM
> Account Name: MyserverName$
> Account Domain: myWorkgroup
> Logon ID: 0x3e7
> Logon Type: 5
> New Logon:
> Security ID: SYSTEM
> Account Name: SYSTEM
> Account Domain: NT AUTHORITY
> Logon ID: 0x3e7
> Logon GUID: {00000000-0000-0000-0000-000000000000}
> Process Information:
> Process ID: 0x260
> Process Name: C:\Windows\System32\services.exe
> Network Information:
> Workstation Name: Source
> Network Address: -
> Source Port: -
> Detailed Authentication Information:
> Logon Process: Advapi (I've found this page when I googled:
> http://www.auditmypc.com/process/advapi.asp)
> Authentication Package: Negotiate
> Transited Services: -
> Package Name (NTLM only): -
> Key Length: 0
> ////////////////////////////////////////////////////////////////////////////////////////
>
> //////////////////////////////////////////////////////////////////////////////////////////
> Special privileges assigned to new logon.
> Subject:
> Security ID: SYSTEM
> Account Name: SYSTEM
> Account Domain: NT AUTHORITY
> Logon ID: 0x3e7
> Privileges: SeAssignPrimaryTokenPrivilege
> SeTcbPrivilege
> SeSecurityPrivilege
> SeTakeOwnershipPrivilege
> SeLoadDriverPrivilege
> SeBackupPrivilege
> SeRestorePrivilege
> SeDebugPrivilege
> SeAuditPrivilege
> SeSystemEnvironmentPrivilege
> SeImpersonatePrivilege
> ////////////////////////////////////////////////////////////////////////////////////////////////
> An account was successfully logged on.
> Subject:
> Security ID: SYSTEM
> Account Name: MyServername$
> Account Domain: MyWORKGROUP
> Logon ID: 0x3e7
> Logon Type: 5
> New Logon:
> Security ID: SYSTEM
> Account Name: SYSTEM
> Account Domain: NT AUTHORITY
> Logon ID: 0x3e7
> Logon GUID: {00000000-0000-0000-0000-000000000000}
> Process Information:
> Process ID: 0x260
> Process Name: C:\Windows\System32\services.exe
> Network Information:
> Workstation Name: Source
> Network Address: -
> Source Port: -
> Detailed Authentication Information:
> Logon Process: Advapi
> Authentication Package: Negotiate
> Transited Services: -
> Package Name (NTLM only): -
> Key Length: 0
>
> Thanks in Advance.
> Vijay chandar
>
>
>

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WLM Get faultcode: Windows Live Communication Platform has stoped working Masse Borglund Windows Live Messenger 21 03-28-2010 12:41 AM
Error number 80073712 naraku4656 Windows Update 51 02-18-2010 11:36 PM
2nd Domain in a 2 domain forest cannot be contacted David Alge DNS Server 30 01-21-2010 05:26 AM
Windows Vista-Ready Products LPH Windows Vista General Discussion 2 01-13-2010 01:48 PM
Getting Ready for Windows BETA 2 - QuickStarter Andre Da Costa [Extended64] Windows Vista Installation 2 06-07-2006 05:22 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59