Yea, cleanup timealready changed password to something more obscure, looked for any other accounts created or weak accounts.
Exported all security logs so I can check through all successful logins.
Also discovered when they first got in and how - rdp by the looks of it.
And also found their dictionary file- and low and behold, it contained my (now changed) password
Posted via Topify using iPhone/iPad
Is it a cloud based server? If so, I would dump it and start a new instance. You will never fully clean a hacked Windows OS. It's just swiss cheese with its undeletable files, unstoppable services, infinitely complicated registry and you name it....my worst nightmare was to work in a Microsoft server rack years ago.
antichrist said:Maybe this is a sign to learn chinese XD
If that doesn't make you want to shoot the Windows developers in the face, I don't know what does...