Solved

Cannot access printer on 2nd W2K workstation

Posted on 2003-12-10
3
203 Views
Last Modified: 2013-12-04
I have a peer to peer with W2K machines.  We set it up to share the laser printer on one machine.  Recently we discover that the machine had been compromised and Firedaemon loaded on it.  I have disabled the Firedaemon service but now we cannot get access to any of the resources on that computer.  I have removed and readded the user but still no access.  What's up?
0
Comment
Question by:bergm57
3 Comments
 
LVL 4

Expert Comment

by:MobileOakAI
ID: 9917593
You can try removing it and readding to domain if you have one (do you?)

Any time a system is badly compromised, I think a good idea is to rebuild it from scratch to remove both the known and the unknown abuse.  After making a build, getting that onto CD helps later on for further builds. I'd also suggest giving it a different name and address in case it is a target, and make sure you do not have too many programs running at startup or too many /quote/ users defined.  Make sure the box gets a new admin and admin password.
0
 
LVL 13

Accepted Solution

by:
Gnart earned 500 total points
ID: 9917633
Firedaemon is a legitimate software.  It's being used as payload by trojan and worm.  Run trojan/worm/keystroke remover to get rid of the real culprit.

AdAware==> http://www.lavasoftusa.com/support/download/
SpyBot ==> http://www.webattack.com/download/dlspybot.shtml

Check for viruse online:

http://housecall.trendmicro.com/ 
http://us.mcafee.com/root/mfs/default.asp?cid=9059 
http://security.symantec.com/
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.pcpitstop.com/antivirus/default.asp 
http://www.f-prot.com/download/download_fpdos.html 

Check the resource's NTFS permission security.  Also, restore group policy and run computer policy basicwk.inf... to restore your security settings.

cheers
0
 

Expert Comment

by:JamesWillison
ID: 9919739
lets start at the begining can you ping the other computer??

0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
OfficeMate Freezes on login or does not load after login credentials are input.

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question