D
DBLWizard
Howdy All,
I need some help. I have a development server that is connected to
the internet. I just got this lssas.exe virus removed from my machine
and cleaned up the registry. In the process I used Security
Configuration Mangager to properly configure windows firewall for all
the services that are running and updated the lasted updates from
Microsoft for Windows 2003 and Sql Server. I also run IIS, DNS and
DHCP on this server. I disabled all the forwarding from my linksys
wrt54G router so nothing is getting forwarded to my server.
This morning when I came to my server Symantec had quarantined another
version of the lssas.exe from my machine. Can somebody help me figure
out where my vulnerabilty is and how these are getting put on my
server.
I use this server to remote into other machines but do not do any
email on this machine itself and the virus software on the other
servers is not throwing up any flags.
Thanks
dbl
I need some help. I have a development server that is connected to
the internet. I just got this lssas.exe virus removed from my machine
and cleaned up the registry. In the process I used Security
Configuration Mangager to properly configure windows firewall for all
the services that are running and updated the lasted updates from
Microsoft for Windows 2003 and Sql Server. I also run IIS, DNS and
DHCP on this server. I disabled all the forwarding from my linksys
wrt54G router so nothing is getting forwarded to my server.
This morning when I came to my server Symantec had quarantined another
version of the lssas.exe from my machine. Can somebody help me figure
out where my vulnerabilty is and how these are getting put on my
server.
I use this server to remote into other machines but do not do any
email on this machine itself and the virus software on the other
servers is not throwing up any flags.
Thanks
dbl