Has my computadora been [attempted] haxxored?

Dec 30, 2004
12,553
2
76
GRRRRRR well I can't seem to upload a picture of my system log, so I'll just describe it: for about 25 minutes at 1:25am April 5th, there is a list of "Warning"s in my event viewer. The source is MSFTPSVC, and under the properties, it says, "The Server was unaable to logon the Windows NT account 'Administrator' due to the following error: Logon failure: unknown username or bad password. The data is the error code." Then there's a message about additional data found at microsoft.com blah blah.

Theres some byte code at the bottom, 0000: 2e 05 00 00.

There are at least a thousand attempts. Unfortunately for my secret admirer, I have designed a password that would take appoxomately 604 years to crack (given all the computers in the world).

So is there any reason to believe I wasn't targetted? What can I do to ensure this doesn't happen again (I've had remote desktop connection enabled, was planning on using it but I'm not, perhaps I should just remove it)?

Thanks for any input.....
 
Dec 30, 2004
12,553
2
76
Hm, why do you say nevermind? What you had before sounds right (an anandtech email update included your reply). I was looking at it as MSFT PSVC...but MS FTP SVC, as you say, seems correct. A while ago I had enabled the FTP service so I could host my files and whatnot.

But now that I check it, it is disabled. The only thing enabled in that list is "Toredo", an IPV6 Microsoft program.

Any other ideas?


Thanks for the replies.
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0
Originally posted by: soccerballtux
Hm, why do you say nevermind? What you had before sounds right (an anandtech email update included your reply). I was looking at it as MSFT PSVC...but MS FTP SVC, as you say, seems correct..
Well, it IS the ftp service. But I did a quick search and found reference also to a potential internal account issue, where the "Administrator" account is being used for the FTP service, but the password is wrong.

And since you've found that the Microsoft FTP Service is disabled, I have no idea what's going on. Hence, the n.m. ;)