Not a typical win2k question, but I thought I’d give it a shot!
I call a call from a customer this morning stating that they could not log on with the admin acount. after further investigation I found two new users, both with admin rights, and thatall other users that HAD admin rights now did not. more investigation shows a couple files created after hours, and the existence of several tftp files that were created after hours AND infected with the Nimda virus. My question is this, does anyoneknow if the nimda could have created these new users, and changed rights to existing users, and set itself up to transfer via ftp on this server, or should I be concerned that a hacker was in my system as well. Are there any tools that can help identify the presence of a hacker after the fact? Any ideas, advice, or suggestions will be greatly appreciated!!