Hey my name is james.
I was recently looking through the taskmanager and found cmd.exe running. It was taking up no ram but was just sitting there. I checked the user name and I found that it was one of a previous account that was not working at the time and that I had not logged in on. I found no other suspicious process runned under that name so I am very confused. I fear that they might be running a listening netcat but I found no evidence of this. I have found no other signs of a any backdoors and I
have a pretty good knowledge of computer systems.
Fport-found nothing unusual
Netstat -an-found a few suspicious ports and telneted to them and found nothing
Taskmanager-found suspicious process
NTLast-Found Logged in unused account
Event Viewer-found audited accounts for unused user account and found that it had logged in multiple times over the last few months.
Plz help. This computer is extremely important to business and other parts of my life.
Email me if you have any suggestions/questions. email@example.com