I am definetly not a security expert so i must ask for help.I noticed a session open in server manager (win srvr 2003 r2) of a username(mark) on a machine he does not use(04W6JXV) Today i asked this individual if they were logged on to machine X they said no and i believe them which is the scary part the attached picture is from the security logs on machine X logging the username i had seen with a session after hours on the machine he doesnot use it looks obvious to me here that "mark" logged on to machine "04W6JXV" at 1:57am is it possible that some program or service is logging in this individuals username was previously used to setup numerous things by our oldIT guy--also "mark" has a user directory on the machine in question and the ntuser.dat has a time stamp from a couple of days ago is it possible this username is being used to...
↧