Re: repeated failure of store - securty hack?





In news:05004143-60D4-45E8-B0E4-7E2E874BDCDD@xxxxxxxxxxxxx,
John McCombe <JohnMcCombe@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
> Hi
>
> I have a problem with a sbs 2003 server runnig fine since
> commissioning August 05. On last Monday morning 08:39 ther were 50+
> attempts to log in to the server from a (win98) client using the
> wrong password and the user was locked out.

Disable account lockout - it's a bad idea.

> I received an email
> warning. Then the users came in at 9:00 and advised me that noone
> could log in. I am remote from the server, and could not access it
> either.
>
> I recommended a soft re-boot, but unfortunately they could not do so,
> and powered off & on.
>
> At this stage, login was allowed, but email delivery was not working.
> I checked in the event logs and was told that stor could not stsrt as
> the exxx log file was corrupt
>
> Using the MS KB I restored the log files form backup and the store
> stsred ok - email traffic ok.
>
> This lasted about 28 hours, and the same symptoms occured - store not
> mounted emails received (by pop3) but not delivered.
>
> I went to visit the server - re-booted restored the log files all ok.
> I ran MS malicious software removel tool nothing found I ran MS
> antispyware tool nothing found. (it is now running in the background).
>
> I left site at 2pm will all messages tracked as delivered ok.
>
> At 2:06 the sam happened and email delivery went down
>
> I got the following events logged:
>
>
> Event Type: Warning
> Event Source: ESE
> Event Category: Performance
> Event ID: 508
> Date: 23/11/2005
> Time: 14:06:16
> User: N/A
> Computer: COULTER-MAIN
> Description:
> Information Store (3196) First Storage Group: A request to write to
> the file "D:\exchsrvr\mdbdata\E00tmp.log" at offset 0
> (0x0000000000000000) for 1048576 (0x00100000) bytes succeeded, but
> took an abnormally long time (244 seconds) to be serviced by the OS.
> This problem is likely due to faulty hardware. Please contact your
> hardware vendor for further assistance diagnosing the problem.
>
> For more information, click
> http://www.microsoft.com/contentredirect.asp.
>
>
> Event Type: Warning
> Event Source: ESENT
> Event Category: Performance
> Event ID: 508
> Date: 23/11/2005
> Time: 14:06:15
> User: N/A
> Computer: COULTER-MAIN
> Description:
> wins (1656) A request to write to the file
> "C:\WINDOWS\system32\wins\j50.log" at offset 389632
> (0x000000000005f200) for 512 (0x00000200) bytes succeeded, but took
> an abnormally long time (60 seconds) to be serviced by the OS. This
> problem is likely due to faulty hardware. Please contact your
> hardware vendor for further assistance diagnosing the problem.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
>
> Event Type: Warning
> Event Source: ESENT
> Event Category: Performance
> Event ID: 508
> Date: 23/11/2005
> Time: 14:06:15
> User: N/A
> Computer: COULTER-MAIN
> Description:
> tcpsvcs (2064) A request to write to the file
> "C:\WINDOWS\System32\dhcp\j50.log" at offset 15360
> (0x0000000000003c00) for 512 (0x00000200) bytes succeeded, but took
> an abnormally long time (60 seconds) to be serviced by the OS. This
> problem is likely due to faulty hardware. Please contact your
> hardware vendor for further assistance diagnosing the problem.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> when I checked the counters it doe show dics idle time low and
> transfer rate low, which suggests hardware - but considering recent
> events (and the fact that the driv is new) I am not sure.t

Well, I'd be inclined to believe it. What's your disk setup? Hardware RAID
is the best. Got good backups? Take a full backup now.


> Also, on checing the security logs I get repeated logon/logoff evemnt
>
<snip>
>
> I have successfully restored the store again;but for how long?
>
> I am thinking rootkit trojan - I have not come across one before and
> do not want to!
>


> Please help, I am getting overwhelmed here!

You need good antivirus software running on your whole network. Do you have
a separate 'edge' firewall in place or are you using ISA?
Don't run beta software on your server. And spyware is unlikely to be on it
unless someone's using it as a workstation, which they shouldn't be. I think
you have hardware problems, myself.

>
> Many thanks
>
> John


.



Relevant Pages

  • Re: repeated failure of store - securty hack?
    ... Latest update I have the same MO appearing on another server, not related to or connected to the first one. ... Security logs show repeated logon logoff events, Store log files were corrupted. ... I have antivirus software running at the webhost for email, and for each workstation - not a free one. ... I am still not convinced that it is hardware - not on two different systems, ...
    (microsoft.public.windows.server.sbs)
  • Re: repeated failure of store - securty hack?
    ... Latest update I have the same MO appearing on another server, ... Store log files were corrupted. ... I have antivirus software running at the webhost for email, ... I am still not convinced that it is hardware - not on two different systems, ...
    (microsoft.public.windows.server.sbs)
  • Re: Recovering exchange data from a hard drive in a seperate machine...
    ... they don't have a whole lot of spare hardware right now. ... Once you have new server booting from HDD, reapply service packs, updates and come back with information on whatever errors you get in logs. ... Is there not a way to mount the store as read only and then copy info out of it? ... Google event log errors and you will find plenty of articles to help you recover exchange data. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recovering exchange data from a hard drive in a seperate machine...
    ... they don't have a whole lot of spare hardware right now. ... Once you have new server booting from HDD, reapply service packs, updates and come back with information on whatever errors you get in logs. ... where are the store files located? ...
    (microsoft.public.windows.server.sbs)
  • Re: Recovering exchange data from a hard drive in a seperate machine...
    ... I do have a server to mount the store on, but SBS2003 is limited to one store! ... they don't have a whole lot of spare hardware right now. ...
    (microsoft.public.windows.server.sbs)