Re: Server running slow and MSSearch problems

Re: Server running slow and MSSearch problems

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Server running slow and MSSearch problems Paul King 01-09-2008
Posted by Paul King on January 9, 2008, 5:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Hi Newell,
>
> Thanks for the update. I will post to the security group, but seriously
> thinking of converting over to Mac OS X Server!!
>
> 1) Viruses found were:
>
> TROJ_DLOADER.TDX, TROJ_RENOS.LZ. TROJ_VUNDO.AAH, PE_VIRUT.AV,
> TROJ_SMALL.ISY, PE_VIRUT.AV
>
> 2) Ran a complete scan using the Trend Micro OfficeScan product, as well
> as use Vundofix.
> 3) Used a product called "WinUtilities" from YLSoftware as it stated that
> this could be run on a Windows 2003 machine.
>
> Still having problems starting the MSSearch service - even after
> reinstalling MS SQL2000.....
>
> Any suggestions please.....
>
> Cheers
> Paul.
>
>>
>> "Paul King" wrote:
>>
>>> Dear all,
>>>
>>> I have a 2003.net stanmdard server with SQL2000 and Exchange 2003. I
>>> have
>>> since contracted a nasty virus even though I had Trend AV installed.
>>>
>>> Anyways, I think I have got rid of the viruses but also did a registry
>>> cleanup using one of the tools on the web, this however has slowed the
>>> machine up.
>>>
>>> The processor is running fine (no high utilitisation) but the hard disk
>>> is
>>> going like the clappers. The only correlation I can make is that the
>>> one of
>>> the services failed to start which is Microsoft Search.
>>>
>>> When launched the error could not find the file specified is recorded,
>>> yet
>>> the MSSearch.exe is located in the correct directory.
>>>
>>> Any help would be appreciated.
>>> Regards
>>> Paul.
>>>
>>>
>> Not my area of expertise, but it is likely you are still infected with
>> something.
>>
>> Try posting to one of the security groups, and include the following
>> info:
>> 1) Which virus you suspected you had, and why (if Trend did not spot it).
>> 2) What you did to eradicate it.
>> 3) Which registry cleanup tool and from where you downloaded it - plain
>> text, not URL link.
>> --
>> Regards,
>> Newell White
>>
>
>



Posted by David H. Lipman on January 9, 2008, 6:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

< snip >

>>
>> TROJ_DLOADER.TDX, TROJ_RENOS.LZ. TROJ_VUNDO.AAH, PE_VIRUT.AV,
>> TROJ_SMALL.ISY, PE_VIRUT.AV
>>

< snip >

If you have the above trojans and virus on a Win2003 server, you have a major
problem in
that iot is being used WRONG!

Servers are NOT workstations and should be used as one. The fact that you have
the Vundo
and Renos trojans means that someone is willy-nilly downloading "crap" while
using the
server. This is very bad and that user should LOOSE access to that server (lose
admin
rights).

Additionally the Virut is a file infecting virus and does spread. The server
should be
REMOVED from the network. It *may* need to be wiped and rebuilt!

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Paul King on January 9, 2008, 6:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David,

I appreciate your help on this mater and we have taken adequate steps to
address the person involved... However rebuilding this server is a last
resort process and would like to find another way to resolve this.

For the fact we had what we considered a high-end antivirus solution (Trend
SMB Product) this did not deal with this effectivley and has waivered my
faith in Microsoft Operating systems.

Needless to say that at the moment, the Mac OSX Server looks better on
paper!


>
> < snip >
>
>>>
>>> TROJ_DLOADER.TDX, TROJ_RENOS.LZ. TROJ_VUNDO.AAH, PE_VIRUT.AV,
>>> TROJ_SMALL.ISY, PE_VIRUT.AV
>>>
>
> < snip >
>
> If you have the above trojans and virus on a Win2003 server, you have a
> major problem in
> that iot is being used WRONG!
>
> Servers are NOT workstations and should be used as one. The fact that you
> have the Vundo
> and Renos trojans means that someone is willy-nilly downloading "crap"
> while using the
> server. This is very bad and that user should LOOSE access to that server
> (lose admin
> rights).
>
> Additionally the Virut is a file infecting virus and does spread. The
> server should be
> REMOVED from the network. It *may* need to be wiped and rebuilt!
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by David H. Lipman on January 9, 2008, 6:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| David,
|
| I appreciate your help on this mater and we have taken adequate steps to
| address the person involved... However rebuilding this server is a last
| resort process and would like to find another way to resolve this.
|
| For the fact we had what we considered a high-end antivirus solution (Trend
| SMB Product) this did not deal with this effectivley and has waivered my
| faith in Microsoft Operating systems.
|
| Needless to say that at the moment, the Mac OSX Server looks better on
| paper!
|

I am glad that you identified the miscreant admin and took appropriate actions.

Again, this server needs to be removed from the LAN ASAP !

A server is very difficult to work with especuially if dealing with RAID arrays.

A suggested path would usually be remove the hard disk(s) and put them in a
surrogate PC and
the use anti virus scanners (such as my Multi AV Scanning Tool) and scan the
affected hard
disk(s).

However, this is good for plain drives, not arrays.


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Paul King on January 9, 2008, 8:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David,

Many thanks for your sound advice. Im going to try that method as this
Server is only using Raid1 using SATA drives.

What does Multi AV do differently?

Regards
Paul.

>
> | David,
> |
> | I appreciate your help on this mater and we have taken adequate steps to
> | address the person involved... However rebuilding this server is a last
> | resort process and would like to find another way to resolve this.
> |
> | For the fact we had what we considered a high-end antivirus solution
> (Trend
> | SMB Product) this did not deal with this effectivley and has waivered my
> | faith in Microsoft Operating systems.
> |
> | Needless to say that at the moment, the Mac OSX Server looks better on
> | paper!
> |
>
> I am glad that you identified the miscreant admin and took appropriate
> actions.
>
> Again, this server needs to be removed from the LAN ASAP !
>
> A server is very difficult to work with especuially if dealing with RAID
> arrays.
>
> A suggested path would usually be remove the hard disk(s) and put them in
> a surrogate PC and
> the use anti virus scanners (such as my Multi AV Scanning Tool) and scan
> the affected hard
> disk(s).
>
> However, this is good for plain drives, not arrays.
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.pctipp.ch/downloads/dl/35905.asp
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to
> go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
> Normal Mode.
> This way all the components can be downloaded from each AV vendor's web
> site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
> Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files
> or you can
> download the files and perform a scan in Normal Mode. Once you have
> downloaded the files
> needed for each scanner you want to use, you should reboot the PC into
> Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want
> to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal
> Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
> comprehensive PDF help
> file.
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Similar ThreadsPosted
Running slow, know it's a virus but can't find it! December 18, 2005, 7:49 pm
Problems with MSCEP website running as anonymous December 21, 2006, 5:29 am
ISA 2006 Server Array Problems February 29, 2008, 6:58 am
Problems with SQL Server after installing security updates July 7, 2006, 10:02 am
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 7:58 am
Slow 802.1X Authentication February 17, 2008, 3:48 am
Slow performance September 12, 2008, 10:38 am
System freezing and slow October 23, 2007, 10:21 pm
Slow Shutdown issue March 20, 2008, 7:03 pm
Antigen slow performance July 14, 2008, 12:00 pm

The site map in XML format XML site map

Contact Us | Privacy Policy