Solved

Cannot access printer on 2nd W2K workstation

Posted on 2003-12-10
3
206 Views
Last Modified: 2013-12-04
I have a peer to peer with W2K machines.  We set it up to share the laser printer on one machine.  Recently we discover that the machine had been compromised and Firedaemon loaded on it.  I have disabled the Firedaemon service but now we cannot get access to any of the resources on that computer.  I have removed and readded the user but still no access.  What's up?
0
Comment
Question by:bergm57
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 4

Expert Comment

by:MobileOakAI
ID: 9917593
You can try removing it and readding to domain if you have one (do you?)

Any time a system is badly compromised, I think a good idea is to rebuild it from scratch to remove both the known and the unknown abuse.  After making a build, getting that onto CD helps later on for further builds. I'd also suggest giving it a different name and address in case it is a target, and make sure you do not have too many programs running at startup or too many /quote/ users defined.  Make sure the box gets a new admin and admin password.
0
 
LVL 13

Accepted Solution

by:
Gnart earned 500 total points
ID: 9917633
Firedaemon is a legitimate software.  It's being used as payload by trojan and worm.  Run trojan/worm/keystroke remover to get rid of the real culprit.

AdAware==> http://www.lavasoftusa.com/support/download/
SpyBot ==> http://www.webattack.com/download/dlspybot.shtml

Check for viruse online:

http://housecall.trendmicro.com/ 
http://us.mcafee.com/root/mfs/default.asp?cid=9059 
http://security.symantec.com/
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.pcpitstop.com/antivirus/default.asp 
http://www.f-prot.com/download/download_fpdos.html 

Check the resource's NTFS permission security.  Also, restore group policy and run computer policy basicwk.inf... to restore your security settings.

cheers
0
 

Expert Comment

by:JamesWillison
ID: 9919739
lets start at the begining can you ping the other computer??

0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question