Possible Duplicate:
How do I deal with a compromised server?
I noticed some unusual network behaviour on my Windows web server 2008 R2 x64 server, when I investigated on Resource Monitor I noticed that this was related to and unknown IP being connected to "svchost.exe (termsvcs)" with a PID 3148. My connection to the service was also showing as a separate instance.
An average of 15-30 kB/sec was being sent to this IP and it seems to be in bursts every few seconds. I followed the PID to TermService - Remote Desktop Services. I restarted the service and the unknown IP seemed to disconnect and a new one shortly connected.
On the users tab of Task Manager only one user (me) is connected.
Should I be concerned? Thanks :)
It is a system that is only a few days old with not much at all installed on it:
Full windows updates
Agent Ransack (search tool by mythicsoft)
TortoiseSVN
VisualSVN
Winrar
MSSQL