lusrmgr.msccommand to see whether there are any new accounts. If there are new accounts in the Administrators group, disable or delete them immediately.
regeditto open the Registry Editor.
netstat –naoto check whether the server is being listened to by an unauthorized port.
Check whether there are abnormal startup items on the server.
msconfigto see whether there are startup items with abnormal names, and if yes, uncheck them and go to the paths displayed in the commands to delete the files.
regeditto open the Registry Editor. Check whether the startup items are normal. Especially, check the following three registry entries:
View the connected sessions.
cmdand then enter
netstat -anoto check ongoing sessions between your computer and other computers on the network and confirm whether they are normal. Enter
schtasksto check scheduled tasks on your computer and confirm whether they are normal.
PortNumbervalue on the right.