Virus cleanup - fix compromised windows firewall settings



I am running Windows 2003 R2 and had the box compromised by a virus.
Symantec cleaned it all up I think, but I keep getting reinfections.
After investigating the windows firewall, it had been disabled.
Further, it appears that a group policy has been applied to it that I
can't edit.

When I open the firewall admin, I see an entry in the exceptions:
2941:TCP is allowed from all IPs. The problem is, I cannot edit it,
it's grayed out. Also, explorer.exe has been added to the list and is
also grayed out (that might have been there before though, I'm not
sure). In the exception config box, all entries do say group policy =
no. However, when I run "netsh firewall show state" it says "Group
policy version = Windows Firewall" which from what I'm reading, means
that it's using a group policy indeed. Also, when I run gpedit.msc
and go to Admin templates -> ... -> Windows Firewall, it indicates
"Not configured" for every entry.

So, can anybody tell me how I can remove this port exception from my
firewall configuration? I'm pretty much baffled at this point. Can I
remove the group policy from the machine altogether (at least for the
firewall, my other servers show they're not using group policy)? If
so, how do I do that?

These servers are not on a domain, by the way, they are stand-alone
boxes, if that's relevant to your answers.

Thanks a bunch in advance for your help.

.



Relevant Pages

  • Re: How do I turn off SP2 firewal Group Policy setting
    ... I followed the instructions, but when I go to modify Group Policy, all ... settings are Not Configured Already. ... > Windows XP SP2 client computer in the SBS domain. ... > Firewall for client computers that are running Windows XP Professional. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2003 & Win2K DC
    ... 872769 You cannot configure Windows Firewall settings or Security Center ... | why a change I made to Group Policy (using gpupdate /force after the ...
    (microsoft.public.windows.server.sbs)
  • RE: Workstation Firewall / Group Policy
    ... configure the clients' firewall by SBS GPO to let network backup software ... you could try to edit the GPO '' Small Business Server Windows ... Firewall'' on SBS to configure the firewall on client. ... been truncated" error message when you edit or view Group Policy in Windows ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO does not disable XP Firewall
    ... I'm assuming your talking about the Windows Firewall/Internet Connection ... > network connections: Disabled ... > use of Firewall on Internet Domain: ... > Last time Group Policy was app ...
    (microsoft.public.windows.group_policy)
  • Re: Windows 2003 SP1 Firewall Control through Group Policy
    ... in group policy of applying a GPO to a selected set of targets. ... Is there a way to turn on the firewall on some machines and not others? ... JSI Tip 8378. ... Windows XP SP2 Firewall Update for Windows Small Business ...
    (microsoft.public.windows.server.active_directory)