RE: Windows 2000 login hack

From: Evans, TJ (tjevans@kpmg.com)
Date: 03/15/02


From: "Evans, TJ" <tjevans@kpmg.com>
To: "Dill, Stephen" <SDill@MassMutual.com>, "'Jeremy'" <prrthd@myrealbox.com>, focus-ms@securityfocus.com
Date: Fri, 15 Mar 2002 11:53:57 -0500

The safest course would be the tactical nuke <i.e. - reload from scratch>,
however reality often steps in and prevents that from being a viable option.

Strictly speaking in terms of getting the box up and running - have you
tried booting off of the Win2k CD and doing a repair?

Thanks!
TJ

-----Original Message-----
From: Dill, Stephen [mailto:SDill@MassMutual.com]
Sent: Thursday, March 14, 2002 4:02 PM
To: 'Jeremy'; focus-ms@securityfocus.com
Subject: RE: Windows 2000 login hack

I can't think of a way to repair the problem other than a reinstall of
windows. If this was a warez version of some software, whoever 'warezed' it
might have snuck in a back door of some sort. My suggestion would be to
reformat and reinstall or reimage the machine.

-----Original Message-----
From: Jeremy [mailto:prrthd@myrealbox.com]
Sent: Thursday, March 14, 2002 13:18
To: focus-ms@securityfocus.com
Subject: Windows 2000 login hack

Hello all,

  One of my users recently downloaded some warez off the internet and
proceeded to install it on his windows 2000 Pro box. Well, suprise suprise
it screwed up his PC. Now when any user tries to login to the PC they can
get to the login screen and type their username and password but when he
hits enter it pauses for a couple seconds then sends him back to the "Press
ctrl-alt-delete to Login" screen. I can get into the PC in safe mode and I
have removed the program he installed, I have also looked in the startup
folder for all the local users with no luck. I went ahead and searched the
registry for logoff/logout and looked in the run, runonce and startup areas
in the registry but everything looks fine. Has anyone ever heard of
something like this before, any ideas as to where I can look next to try and
fix this?

Thanks for your help

Jeremy

*****************************************************************************
The information in this email is confidential and may be legally privileged.
It is intended solely for the addressee. Access to this email by anyone else
is unauthorized.

If you are not the intended recipient, any disclosure, copying, distribution
or any action taken or omitted to be taken in reliance on it, is prohibited
and may be unlawful. When addressed to our clients any opinions or advice
contained in this email are subject to the terms and conditions expressed in
the governing KPMG client engagement letter.
*****************************************************************************



Relevant Pages

  • RE: Password never set - locked out of Windows XP Home
    ... Ran fixboot last night, and although the system said it had fixed the boot ... I am still stuck in the redundant loop of getting to a pop-up login ... only to not have it shutdown but instead pop back up with the same login box. ... my Windows XP Home system worked great. ...
    (microsoft.public.windowsxp.accessibility)
  • Re: sp_revoke login is not working as expected.
    ... EXEC xp_logininfo 'MyDomain\SomeUserAccount','members' ... Try specifying a group member rather than the group. ... This should list the Windows groups the user can connect with. ... connect with the non-existing login. ...
    (microsoft.public.sqlserver.security)
  • Re: Windows 98 getting stuck logging into a W2K3 domain.
    ... > workaround I've turned off Windows 98's ability in Client for MS ... > login stating that the domain can not be found, ... > Client for MS networks does the password validation. ...
    (microsoft.public.win2000.general)
  • RE: How to create a trusted connection
    ... You need to grant access for the Windows login by referring to the books ... is set to use Windows authentication to be able to do trusted connection. ... There are two modes of authentication in SQL Server: ...
    (microsoft.public.sqlserver.security)
  • Re: RDC Failing from home to work???
    ... Jeffrey Randow (Windows Networking & Smart Display MVP) ... >> login screen but after I put in my username and password ... >> login...after I attempt to login I see the connection ... >> the same network from home. ...
    (microsoft.public.windowsxp.work_remotely)

Quantcast