Link to home
Start Free TrialLog in
Avatar of dllowry2
dllowry2

asked on

Lost the M: drive on Exchange server. Store files were on the M: drive. Cannot start Exchange Services any longer


I had what appeared to be a DNS problem with one of the Domain controllers.  We could not access the file server shared drive from users PC'.  Rebooted server and we could access the File server drive again.
We also could not seem to access outlook.
I killed the Outlook processes witht eh KILL.exe process and restarted the Exchange services and all was fine.
I started Looking at Domain controller where I run Exchange 2000 and it appeared to have a few executables running that looked suspicious.
VPC32.exe
CHUMIL32.exe

I attempted to kill the VPC32.exe and outlook immediatly went down.
I rebooted server and could then not start teh exchange services.
I looked and the M: drive was no longer an available drive.
It does not show any event logs indicating it was removed, lost, etc.
 Also after the reboot I now see a process servicechat2.exe running on the Exchagne server pc.

Any suggestions on what course of action I can take to troubleshoot this?
Help me make this work and you can name your price on points.

Thanks
David


Avatar of dllowry2
dllowry2

ASKER

Note:
I also rean Search & Destroy on this Exchange server after I started experiencing this porblem.
I run Norton antivirus and ran this on the existing viewable C: & D: Drives.  No viruses or trojans detected.
POP3,  MTA Stack, Exchange Management,  Information Store, and Exchange Event services will not start.
The others did.
ASKER CERTIFIED SOLUTION
Avatar of yuja
yuja

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
OK,
Can I delete the bside folder and its files?

Here is the Hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 2:05:46 PM, on 8/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\System32\CpqRcmc.exe
C:\Compaq\vcagent\vcagent.exe
C:\PROGRA~1\NAV\DefWatch.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Expertcity\GoToMyPC\g2svc.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\Expertcity\GoToMyPC\g2comm.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
C:\Program Files\MonitorIT\AgentService.exe
C:\Program Files\Expertcity\GoToMyPC\g2tray.exe
D:\Program Files\NovaNET\NNWINSDR.EXE
C:\Program Files\MonitorIT\RpmAgent.exe
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\snmp.exe
C:\compaq\survey\Surveyor.EXE
C:\PROGRA~1\NAV\Rtvscan.exe
C:\Program Files\Pwrchute\ups.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\CPQNiMgt\CPQNIMGT.EXE
C:\WINNT\system32\cpqmgmt\CqMgServ\CqMgServ.EXE
C:\WINNT\system32\cpqmgmt\cqmgstor\cqmgstor.exe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\mqsvc.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\System32\sysdown.exe
C:\WINNT\system32\cpqmgmt\CqMgHost\CQMGHOST.EXE
C:\WINNT\System32\CPQMGMT\CPQWMGMT.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CPQTEAM.EXE
C:\WINNT\system32\Atiptaxx.exe
C:\PROGRA~1\NAV\VPTray.exe
C:\winnt\system32\bside\system32.exe
C:\WINNT\system32\sysop.exe
D:\Program Files\SolarWinds\2002 Engineers Edition\SolarWinds-Toolbar.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\winnt\system32\bside\Chumil32.EXE
C:\WINNT\system32\mmc.exe
C:\WINNT\system32\dmremote.exe
C:\WINNT\System32\dmadmin.exe
C:\WINNT\system32\mmc.exe
C:\WINNT\system32\mmc.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Trend\Smex\InstMon.exe
C:\Program Files\Trend\Smex\RMonitor.exe
C:\Program Files\Trend\Smex\InstRTS.exe
C:\Program Files\Trend\Smex\SmexVS.exe
C:\Program Files\Trend\Smex\SMEXMA.exe
C:\Program Files\GFI\MailEssentials\msecatt.exe
C:\Program Files\GFI\MailEssentials\pop2exch.exe
C:\WINNT\system32\mmc.exe
C:\utility\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & 
Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [CPQTEAM] CPQTEAM.EXE
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [GoToMyPC] C:\Program Files\Expertcity\GoToMyPC\g2svc.exe -logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NAV\VPTray.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Win2KService] C:\winnt\system32\bside\system32.exe
O4 - HKLM\..\Run: [Microsoft Windows Update] sysop.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Update] sysop.exe
O4 - HKCU\..\Run: [SolarWinds Toolbar] D:\Program Files\SolarWinds\2002 Engineers
Edition\SolarWinds-Toolbar.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {08F04139-8DFC-11D2-80E9-006008B066EE} (ConfigChkr Class) -
https://onsite.trustwise.com/services/FortisBankSANV/vscnfchk.cab
O16 - DPF: {70D86F3C-BA4D-11D2-80F5-006008B066EE} (VSPrefMgmt Class) -
https://onsite.megasign.nl/services/FortisBankNederlandNVDCI/vspcakm.cab
O16 - DPF: {86C4AF33-6171-11D2-80CD-006008B066EE} (VSRenewSgn Class) -
https://onsite.megasign.nl/VSRenewSign.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rhotrading.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDCC6CE4-F7EB-4E72-A165-1300F8852CE8}: NameServer =
192.168.0.31,192.168.0.32
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = rhotrading.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rhotrading.com
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Compaq NIC Agents (CPQNicMgmt) - Compaq Computer Corp. -
C:\WINNT\System32\CPQNiMgt\CPQNIMGT.EXE
O23 - Service: Compaq Remote Monitor Service (CpqRcmc) - Compaq - C:\WINNT\System32\CpqRcmc.exe
O23 - Service: Compaq Version Control Agent (cpqvcagent) - Compaq Computer Corporation -
C:\Compaq\vcagent\vcagent.exe
O23 - Service: Compaq Web Agent (CpqWebMgmt) - Compaq Computer Corp. -
C:\WINNT\System32\CPQMGMT\CPQWMGMT.EXE
O23 - Service: Compaq Foundation Agents (CqMgHost) - Compaq Computer Corp. -
C:\WINNT\system32\cpqmgmt\CqMgHost\CQMGHOST.EXE
O23 - Service: Compaq Server Agents (CqMgServ) - Compaq Computer Corp. -
C:\WINNT\system32\cpqmgmt\CqMgServ\CqMgServ.EXE
O23 - Service: Compaq Storage Agents (CqMgStor) - Compaq Computer Corp. -
C:\WINNT\system32\cpqmgmt\cqmgstor\cqmgstor.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation -
C:\PROGRA~1\NAV\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. -
C:\WINNT\System32\dmadmin.exe
O23 - Service: GFI MailEssentials Attendant - GFI Software Ltd. - C:\Program
Files\GFI\MailEssentials\msecatt.exe
O23 - Service: GFI POP2Exchange - GFI Software Ltd. - C:\Program
Files\GFI\MailEssentials\pop2exch.exe
O23 - Service: GoToMyPC - Unknown owner - C:\Program Files\Expertcity\GoToMyPC\g2svc.exe" -service
(file missing)
O23 - Service: Intel Alert Handler - Unknown owner - C:\WINNT\system32\ams_ii\hndlrsvc.exe (file
missing)
O23 - Service: Intel Alert Originator - Unknown owner - C:\WINNT\system32\ams_ii\iao.exe (file
missing)
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: GFI List Server (listserv) - GFI Software Ltd - C:\Program
Files\GFI\MailEssentials\ListServ.exe
O23 - Service: MonitorIT Agent Service - Unknown owner - C:\Program
Files\MonitorIT\AgentService.exe
O23 - Service: NovaNET - Unknown owner - D:\Program Files\NovaNET\NNWINSDR.EXE
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation -
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: ScanMail_MailAction - Trend Micro Inc.  - C:\Program Files\Trend\Smex\SMEXMA.exe
O23 - Service: ScanMail_Monitor - Trend Micro Inc.  - C:\Program Files\Trend\Smex\InstMon.exe
O23 - Service: ScanMail_RealTimeScan - Trend Micro Inc.  - C:\Program Files\Trend\Smex\InstRTS.exe
O23 - Service: ScanMail_Web - Trend Micro Inc.  - C:\Program Files\Trend\Smex\WebRoot\InstWeb.exe
O23 - Service: SecureNetworkChatService - SecureAction Research Ltd. - C:\Program Files\Secure
Network Chat\ServiceChat2.exe
O23 - Service: Surveyor - Compaq Computer Corp. - C:\compaq\survey\Surveyor.EXE
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\PROGRA~1\NAV\Rtvscan.exe
O23 - Service: Compaq System Shutdown Service (sysdown) - Compaq Computer Corporation -
C:\WINNT\System32\sysdown.exe
O23 - Service: Tardis time service (Tardis) - Unknown owner - C:\WINNT\System32\tardisnt.exe
O23 - Service: UPS - APC PowerChute plus (UPS) - APC - C:\Program Files\Pwrchute\ups.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe"
-service (file missing)

not only you can, but you should... also, remove the appropriate key from your registry (HKLM/Software/Microsoft/Windows/CurrentVersion/Run/)

O4 - HKLM\..\Run: [Win2KService] C:\winnt\system32\bside\system32.exe

fully patch the system before bringing it back online.
Done and rebooting.
I will pass information on the event logs shortly.  Disconnected from the network from teh server at the moment.
OK,  after a final reboot and start of the exchange services it still appears I cannot start the Exchange services without errors .  Below is events in the event log after the reboot.  If I could attatch teh event logs I would ,  I just dont think we can on this website!

Also when attempting to go to DNS the exchange server only see'd itself in DNS.  From the other domain controller it see's itself and the exchange server DC but cannot access it.
I cannot access or map teh drives of each server.

From the Exchange Server Domain Controller:  SYSTEM LOG
Source:w3svc
The server was unable to add the virtual root '/public' for the directory 'M:\rhotrading.com\Public Folders' due to the following error: The system cannot find the path specified.  The data is the error code.
For additional information specific to this message please visit the Microsoft Online Support site located at:

The server was unable to add the virtual root '/Exchange' for the directory 'M:\rhotrading.com\MBX' due to the following error: The system cannot find the path specified.  The data is the error code.
For additional information specific to this message please visit the Microsoft Online Support site located at:

The server was unable to add the virtual root '/Exadmin' for the directory '\\.\BackOfficeStorage' due to the following error: The system cannot find the path specified.  The data is the error code.
For additional information specific to this message please visit the Microsoft Online Support site located at:

Source:NNTPSVC
The server was unable to add the virtual root '/' for the directory '/Internet Newsgroups' due to the following error: The parameter is incorrect.  The data is the error code.

The Microsoft NNTP Service 5.00.0984 Version: 5.0.2195.6972 has been started.

Source:Schannel
A fatal error occurred while creating an SSL server credential.

Source:Browser
The browser was unable to retrieve a list of servers from the browser master \\RHOSVR01 on the network \Device\NetBT_Tcpip_{CDCC6CE4-F7EB-4E72-A165-1300F8852CE8}. The data is the error code.

The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{CDCC6CE4-F7EB-4E72-A165-1300F8852CE8}. The backup browser is stopping.



APPLICATION LOG
Source:IISinfoCTRS
Unable to query the IIS Info service performance data. The error code returned by the service is data DWORD 0.

Source:MSMQ
The server cannot support automatic recognition of site and connected networks for clients.
Source:Perflib
The configuration information of the performance library "C:\WINNT\system32\ftpctrs2.dll" for the  "MSFTPSVC" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.
Source:perflib
The Open Procedure for service "ScanMail_Monitor" in DLL "C:\Program Files\Trend\Smex\SmxPerf.dll" failed.  Performance data for this service will not be available. Status code  returned is data DWORD 0.


I BELIEVE THE BELOW IS BECAUSE I RENAMEd THE VPC32.exe file to another extention becasue I thought it was a virus.

Source:msiinstaller
Detection of product '{848AC794-8B81-440A-81AE-6474337DB527}', feature 'SAVUI' failed during request for component '{0ABF6425-272D-4795-9BD8-F2428110EC95}'
Product: Symantec AntiVirus -- Error 1606.Could not access network location \\Rhosvr01\E\users\administrator\.

Source:MsExchangeDSAccess
Process MAD.EXE (PID=2148). All Global Catalog Servers in use are not responding:
Rhosvr01.rhotrading.com

Source:MSEchangeAL
Permanent failure reported by policy group provider for 'CN=System Policies,CN=Rho Trading,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rhotrading,DC=com':'MAD.EXE', error=80040103.  Taking provider offline.  
Source: MSExhangeFBPublish
Error initializing session for virtual machine RHOSVR02. The error number is 0x80040111. Make sure Microsoft Exchange Store is running.
Source:MSExchangeSA
The Directory Service Referral interface failed to service a client request. RFRI is returning the error code:[0x3f0].
Source:POP3SVC
An error occurred while starting the Microsoft Exchange POP3 Service: server instance number 1 failed to start with error 0x80004005.
Then a message stating the POP3 service started successfully.

The Directory Service Referral interface failed to service a client request. RFRI is returning the error code:[0x3f0].

FILE REPLICATION SERVICE
Source NtFrs
The File Replication Service is having trouble enabling replication from RHOSVR01 to RHOSVR02 for c:\winnt\sysvol\domain using the DNS name Rhosvr01.rhotrading.com. FRS will keep retrying.
 Following are some of the reasons you would see this warning.
 
 [1] FRS can not correctly resolve the DNS name Rhosvr01.rhotrading.com from this computer.
 [2] FRS is not running on Rhosvr01.rhotrading.com.
 [3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
 
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.


APPLICATION LOG
Source:MsExchangeMTA
A fatal error occurred reading a value from the directory. No MTA name was found. Contact Microsoft Technical Support. [MTA MAIN BASE 1 12] (16)
There is not enough Performance Monitor memory to display the MTA Connections information.  Stop attached Performance Monitors and re-start the MTA. [BASE MAIN BASE 1] (14)

SYSTEM LOG
The Microsoft Exchange Information Store service terminated with service-specific error 0.
OK,
Here is what I have learned so far.
I shut down the File server DC and then rebooted the Exchange server DC.
I then restarted the File server DC and was able to start all the Exhcange server processes??
Do you know of this type of behavior?
I will wait to see if you might be able to assist me further with this before closing this ticket.  I am still not confident it is stable.  Your insite into my event logs would be helpful.  
Please let me know what you want for points or if the 500 will be sufficiant
Ok, so assuming that the Exchange server is looking at the internal DNS server ONLY on the TCP/IP properties, where is the GC/DC that it's looking for? Have you reapplied any exchange or windows service packs during this? How many DCs and GCs do you have?
not sure I follow.  We have two Domain Controllers.  The two I have been speaking about.
We NAT tot eh outside world.  The Exchange server has a DNS address with out Internet provider for external mail, OWA, and Internet access.
GC?
GC=global catalog server

Which server is this? Rhosvr01.rhotrading.com

Are both DCs also GCs? Look on the DSAccess tab of the Exchange server props, in the ESM
OK, It seems to be an active directory problem.
I get a message that the Domain controller for Group policy operations is not available.

Failed to open the group policy object.  You may not have appropriate rights when trying to go into domain controller security policy.

I did not see a tab for DSAccess on the Exchange server properties.
I am doing this from Rhosvr01 & Rhosvr02.

Presently Exchange is down again and File access is random at this time with some users gaining access to the File server and others not being able to connect.
Might be called Directory Access too...
I have done a repair of the the Domain Group Policy objects.
It then all seems to be fine.  Within 20 minutes it was corrept in some way again.
I did get into the Exchange system manager properties and am looking at the Directory access tab.
It shows two entries.  Both are RHOSVR02
Site:  Default-First-Site-Name  for both
Domain : rhotrading.com  for both
Type : Config(auto) for the first
Type : DC(auto) for teh second entry

LDAP port : 389 for both
That's a problem, there should be 3 entries. No entry for a GC?
It now appears as though it worked for about another 20 minutes and then gives me an error Network connection to Policy storage has been lost.  Attempt to reconnect now.
IP Sec Policy storage failed to open.
When attempting to reconnect it fails again and again.
Soory I did not see your last comment.
OK,  so there should not be an entry for a GC and there should be a total of three entries within this Directory Tab.
Could you help me determine what they should be?
Im nowhere near an expert at this and im sure you figured that out already.
Thanks
No, you MUST have an entry for the GC, and you don't. You need to add that under the GC area in the Directory Access tab. Are the exchange services running at this point?
They are not.  I can attempt to start them but they fail.  At least some of them.
So the Global catalog entry should be what?
It should point to your local GC, whichever server that is. You tell me...and it should operate on port 3268, just in case you need to know.
OK,
Well the GC servers has the Check box set for automatically discover servers and it does not find one.
AD sites and services shows me that the RHOSVR01 server is th be the Global catalog server.
Should I attempt to manually add this server to teh Directory access tab from within Exchange system manager?
Thanks
OK, I did a manual add for the Global Catalog.
You are correct that it should be port 3268.
Trying a few things now.
yes, I'd try to manually add it. Make sure that the Exchange server is looking at internal DNS servers only.
DNS settings on the server point to the internal domain controllers.
The group policy is still available for more than an hour so Im feeling good about that.

But I attempted to start the Exchange services from RHOSVR02 and it faild on the same services.  I am assuming I may need to restart the DC that I have added the values too.
Ill tell you whats going on with it.
Thanks
Rebooted the Exchange server and still cannot get the services to start.

Just a recapp.
The three entries under the directory access tab should be the following.

Two entries for RHOSVR02 (Exchange server) One for DC (Auto) and one for Conf (Auto)

Then one entry for the Global Catalog which is on RHOSVR01.

Thanks
Im not splitting between every answer which it appears to force me to do.
I hope you guys/girls get the points.
A final note on this: never, EVER log onto the console except to do administrative functions. And then do NOT, EVER, do any websurfing other than to known legitimate sites (like microsoft.com to do research).