Re: Windows 2000 server hacked

From: Shenan Stanley (
Date: 06/22/05

Date: Wed, 22 Jun 2005 03:45:39 -0500

Rick Totedo wrote:
> I have a Windows 2000 server that was hacked. The OS partition is on
> a 4 gig drive. The OS and profiles take up about 1.5 gig. When I
> look at the drive properties, it says I only have 80 mb free. That
> means someone is storing almost 3 gig of stuff on my omputer. I have
> used every tool and command line I can to find the data, but nothing
> will read the directory structure. All attempts come back displaying
> just the data that was original to the system. The hackers must have
> done something to the system to hide" their data from anything that
> reads NTFS. I also cannot empty my recycle bin. It tells me that
> one of the folders is not empty. When I look at that folder nothing
> is in it.
> Does anyone have an idea on how to access this data so I can find it
> and delete it from my system. As of now, I am looking at the
> format/reload method, but I would rather not do that.

GHOST the partition, use ghost viewer to look at the partition.

Shenan Stanley
How To Ask Questions The Smart Way 

Relevant Pages

  • Re: Setting up LVM
    ... You have to run pvcreate on a partition (file, disk, whatever) to create ... disks, one empty, one full, with the full one being /dev/sda1 and the ... Then you mkfs that LV and copy everything on sda1 to the LV. ...
  • Re: Empty Folders
    ... Recently I noticed that almost all my folders were empty in one partition and encountered only one empty folder in an another partition. ... Using Acronis I reverted to a backup I had done on Feb 20th wondering whether some recent update or SP3 had caused this problem, but the folders are still empty. ...
  • Re: Need advice on increasing performance on my SBS R2 Server
    ... There are a number of default services that you can move off, and you can move off all the update undeleted files and folders as well. ... do the the normal things such as empty the temp folder and so on. ... After you have more free space on your C partition, it does not hurt to defrag. ... My problem is that the server appears to be running slower than ...
  • Re: OpenPartition if the partition doesnt have a name
    ... I'll post source code and debug output, ... expected "Part03" it's just empty. ... > partition names, so you should never be able to create a partition with an ...
  • Re: disc suddenly full after using boot manager
    ... For those interested I moved all folders on D to a new drive (amounted to ... 25GB) which left the *empty* D drive showing 85GB used! ... > Also D is now listed as an active primary boot partition but ... (Partition magic partition info- ...