I recently discovered the presence of an unauthorized visitor on a 2000 server machine. I have gone through all the nessesary steps to prevent any further access, but I am curious about one thing. A batch file was created and placed in the startup folder that deleted the IPC$ share, along with a couple other default administrative shares. Does anyone know why a hacker would want to do that? Is this a standard procedure for some kind of established “hacking” technique? I also found Windows MediaServer had been installed on the system, any ideas why?
Thanks in advance