I am Desperate! Please help! WIN 2K Server!

kerndads

Junior Member
Jan 3, 2005
7
0
0
I have windows 2000 Server running with Terminal Services. Someone got onto the server and was looking at shady websites here at my office. Anyway the server was highjacked with Some type of spyware\junk. Now when I try to log on I hit CTRL\ALT\DEL at the logon screen, enter my username and password, hit ok, and then it appears as if it is going to log in but then just goes directly to saving system settings and the logon screen just reappears. I can not log in at all...it just goes directly back to the login screen. Does not matter what user name I use, Or safe mode or anything. I have access to the servers registry and can browse the file system through one of my other servers. I can also access services from another server, but I cant find anything wrong and dont know what is causing this! PLEASE HELP!
 

KB

Diamond Member
Nov 8, 1999
5,406
389
126
Look in the startup folder (All users and Administrator) and the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key for a mention to shutdown.exe. It is possible the spyware put a reference in these areas to shutdown -l, the command for logging off.

Does the Event Log have anything useful in it? Are there any errors? System errors may mean you have some corruption and will need to reimage. Look in the security event log. If it shows a user logging it, then immediately logging out, then my hunch about shutdown -l may be correct. Good luck.
 

kerndads

Junior Member
Jan 3, 2005
7
0
0
I checked the Run Folder in that key and it is empty. I see no entry in the event viewer for any log offs or log on attempts even though there were attempts. There are some errors in the event log (system) They have to do with ntrfs and certain dns errors (the dns errors I am pretty sure are not related. The funny thing is the server runs fine, It is still doing everything it should be I just cannot bring up the desktop or log in at all! I am at my wits end here! SOmeone please help me!!! I will be eternally grateful! This machine is our terminal server and my boss is going away soon and he will need to log into it to work while he is away..so If it is not up and running by then it could mean my JOB!! Anyone else with any info whatsoever please let me know!!! I also do not have a win 2k server cd..or I would reinstall! I lost the disk and I could never get a replacement in time...I also do not have an image of the server! UNFORTUNATELY!!!