0
我在辦公室PC上看到一些黑客攻擊。上週五我的電腦突然重啓兩次,當我登錄時,我的一些重要文件不在那裏。剛刪除。 所以我檢查了事件查看器以查找有關此重新啓動的原因。 我收到了這些日誌,並在該日誌中看到某人的PC名稱。有人可以向我解釋這一點嗎?黑客攻擊 - Windows服務器2003
謝謝!
Date:7/27/2012 Source:Security
Time:2.35.26 PM Category:Account Logon
Type:Success A Event ID:680
User:MyPC/Administrator
Computer: MyPC
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:Administrator
Source Workstation:OtherPC
Error Code:0x0
Date:7/27/2012 Source:Security
Time:2.35.26 PM Category:Logon/Logoff
Type:Success A Event ID:576
User:MyPC/Administrator
Computer: MyPC
Description:
Special privileges assigned to new logon:
User Name:Administrator
DOMAIN: MyPC
Logon ID: (0x0, 0x251E985)
Privileges:SeSecurityPrivilege
SeBackupPrivilege
...
Date:7/27/2012 Source:Security
Time:2.35.26 PM Category:Logon/Logoff
Type:Success A Event ID:540
User:MyPC/Administrator
Computer: MyPC
Description:
Successful Network Logon:
User Name:Administrator
DOMAIN: MyPC
Logon ID: (0x0, 0x251E985)
Logon Type:3
Logon Process:NtLmSsp
Authentication Package:NTLM
Workstation Name:OtherPC
Logon GUID:-
Caller User Name:-
Caller Domain:-
Caller Logon ID:-
Caller Process ID:-
Transited services:-
Source Network Address:192.168.x.x
Source Port:0
Date:7/27/2012 Source:Security
Time:2.35.26 PM Category:Logon/Logoff
Type:Success A Event ID:551
User:MyPC/Administrator
Computer: MyPC
Description:
User initiated logoff:
User Name:Administrator
DOMAIN: MyPC
Logon ID: (0x0, 0x2059c)
這是我的錯。我寫下了這些東西。我將名稱更改爲'MyPC'和'OtherPC'。我無法訪問'OtherPC'。那麼你需要什麼樣的信息? – sura2k 2012-07-31 01:25:18
老實說,沒有更多的信息可以幫助您不用訪問其他PC。我唯一的建議是確保你有最新的防火牆。如果你還沒有和你的管理/ IT部門談談。似乎特別懷疑它是連接到你的內部計算機。 – alexgerst 2012-07-31 14:19:33
非常感謝。我只是想要一個建議,我得到了一個。 – sura2k 2012-08-01 09:23:18