Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > DNS Server > SBS2003 Not Authenticating Users/Other Computers - Possible DNS Pr

Reply
Thread Tools Display Modes

SBS2003 Not Authenticating Users/Other Computers - Possible DNS Pr

 
 
SuperFlyBoy
Guest
Posts: n/a

 
      05-16-2010
Hi,

We had our server running very slow and acting funny recently, and for 2
days users were sometimes not able to authenticate with the server (SBS2003,
with latest Service Packs)

We then found out that we were infected with Conficker, and even though we
run a hardware firewall (Fortinet box) as well as AV, it still managed to get
through.

(Fortinet tech support is reporting being overwhelmed and hasn't replied to
online support for days now - I wonder why!)

We then attempted disinfection with 2 different tools:

1. Bitware network version, which was able to disinfect workstations, but
could not take ownership of some .tmp files.

2. Enigma Software's tool, which originally got one on the server removed,
but there was another reported in SBCore, which it could not remove.

I then uninstalled TrendMicro's AV, and installed Avira's Small Business AV,
which scanned the whole primary drive and found nothing.

However, on the on-access reporting, it still reports an "EICAR_TEST_FILE"
being reported, which was how we detected the Conficker virus initially.

Before noting that we were infected (all scans were okay, with Malwarebytes,
ASquared, others), I decided to change the DNS settings and WINS as well.

However, I have now reverted back to the original DNS IP of the server for
the single LAN connection (our firewall is the gateway and DHCP server), and
still none of our workstations is able to connect or log onto the Domain.

Possibly AD is affected somehow?

All services appear to be working okay, and nothing is being reported in the
Event Log.

Can anyone advise what further steps I can take on this SBS box and should I
simply reinstall and migrate the Exchange store to the new HD?

Thanks in advance!
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      05-16-2010
Hello SuperFlyBoy,

As this belongs to the SBS version, please use one of the newsgroups/forums
listed here:
www.sbs2008.com

There are the SBS experts.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> We had our server running very slow and acting funny recently, and for
> 2 days users were sometimes not able to authenticate with the server
> (SBS2003, with latest Service Packs)
>
> We then found out that we were infected with Conficker, and even
> though we run a hardware firewall (Fortinet box) as well as AV, it
> still managed to get through.
>
> (Fortinet tech support is reporting being overwhelmed and hasn't
> replied to online support for days now - I wonder why!)
>
> We then attempted disinfection with 2 different tools:
>
> 1. Bitware network version, which was able to disinfect workstations,
> but could not take ownership of some .tmp files.
>
> 2. Enigma Software's tool, which originally got one on the server
> removed, but there was another reported in SBCore, which it could not
> remove.
>
> I then uninstalled TrendMicro's AV, and installed Avira's Small
> Business AV, which scanned the whole primary drive and found nothing.
>
> However, on the on-access reporting, it still reports an
> "EICAR_TEST_FILE" being reported, which was how we detected the
> Conficker virus initially.
>
> Before noting that we were infected (all scans were okay, with
> Malwarebytes, ASquared, others), I decided to change the DNS settings
> and WINS as well.
>
> However, I have now reverted back to the original DNS IP of the server
> for the single LAN connection (our firewall is the gateway and DHCP
> server), and still none of our workstations is able to connect or log
> onto the Domain.
>
> Possibly AD is affected somehow?
>
> All services appear to be working okay, and nothing is being reported
> in the Event Log.
>
> Can anyone advise what further steps I can take on this SBS box and
> should I simply reinstall and migrate the Exchange store to the new
> HD?
>
> Thanks in advance!
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
your computer could not be joined to the domain because the follow takman_777 Windows Small Business Server 4 12-26-2009 08:16 AM
SBS2003 R2 to SBS 2003 - to swing or not to swing.... Jim Windows Small Business Server 21 11-30-2009 05:10 PM
Cannot View Computers on Network HankL Windows Vista Networking 3 11-28-2009 08:43 PM
SBS 2008 AD Users and Computers Snap-in MSVCRT.DLL odd fault NickM Windows Small Business Server 3 11-28-2009 12:40 PM
sync with two computers Lara Z ActiveSync 1 06-02-2005 03:35 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59