edb.log deleted by Norton A/V, store dismounted and won't remount.
Posted on 2004-03-25
This morning, everyone got kicked out of email and i checked event viewer to find that norton a/v detected the netsky virus in edb.log and deleted it. Exchange tried to recreate the edb.log and remount to store to no avail. I tried to do a backup of the edb.log file from a few hours before it was deleted and the store still won't mount.
Event Viewer logs:
Virus Found!Virus name: W32.Netsky.C@mm in File: C:\exchsrvr\MDBDATA\edb.log by: Realtime Protection scan. Action: Delete succeeded : Access denied
MSExchangeIS (2756) Unable to create the log. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1811.
MSExchangeIS (2756) The database engine failed with error -510 while trying to log the commit of a transaction. To ensure database consistency, the process was terminated. Simply restart the process to force database recovery and return the database to a consistent state.
An error was returned from the messaging software the Internet Mail Service uses to process messages on the Microsoft Exchange Server. As a result, the message in spool file HCG1SBPR will be retried when the server is restarted.
The error 0x80040115 was encountered while trying to communicate with the message store. An attempt to refresh the connection will be made. If not successful, the service will be shut down.
An error was returned from the messaging software the Internet Mail Service uses to process messages on the Microsoft Exchange Server. As a result, the message in spool file HCG1SBPT will be retried when the server is restarted.
The error 0x8004011d occurred while trying to refresh network connections to the Information Store. The Internet Mail Service is being shut down.
A serious error has occurred while trying to send mail into the Exchange Information Store. The Internet Mail Service is being shut down.
An unexpected error [0x80040115] occurred in maintenance thread.
Error 0xfffffdfd initializing the Microsoft Exchange Server Information Store database.
Error Database is in inconsistent state initializing the Microsoft Exchange Server Information Store database.
After unsuccessfully trying to copy a backed up edb.log and restart the store, i copied the priv.edb to a server with enough room to run an eseutil /p on it. (not enough room on the mail server and without correct log files anyway, didn't think a soft recovery would be possible)
So now i've run the eseutil /p and it found many inconsistencies and I guess repaired them so now i'm running an eseutil /d (as per an article I read on here)
I plan on running the (isinteg -pri -fix -test alltests) next for good measure but am not sure what to do afterwards.
I have deleted all of the log files and edb.chk from the mdbdata folder (as per a suggested solution from microsoft) but need to know the proper way to remount the defragged/checked priv.edb
Not sure where to go from here.