troubleshooting Question

edb.log deleted by Norton A/V, store dismounted and won't remount.

Avatar of medguru
medguru asked on
Exchange
10 Comments1 Solution4384 ViewsLast Modified:
This morning, everyone got kicked out of email and i checked event viewer to find that norton a/v detected the netsky virus in edb.log and deleted it.  Exchange tried to recreate the edb.log and remount to store to no avail.  I tried to do a backup of the edb.log file from a few hours before it was deleted and the store still won't mount.  
Event Viewer logs:
Virus Found!Virus name: W32.Netsky.C@mm in File: C:\exchsrvr\MDBDATA\edb.log by: Realtime Protection scan.  Action: Delete succeeded : Access denied
MSExchangeIS (2756) Unable to create the log. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1811.
MSExchangeIS (2756) The database engine failed with error -510 while trying to log the commit of a transaction.  To ensure database consistency, the process was terminated.  Simply restart the process to force database recovery and return the database to a consistent state.
An error was returned from the messaging software the Internet Mail Service uses to process messages on the Microsoft Exchange Server.  As a result, the message in spool file HCG1SBPR will be retried when the server is restarted.
The error 0x80040115 was encountered while trying to communicate with the message store. An attempt to refresh the connection will be made.  If not successful, the service will be shut down.
An error was returned from the messaging software the Internet Mail Service uses to process messages on the Microsoft Exchange Server.  As a result, the message in spool file HCG1SBPT will be retried when the server is restarted.
The error 0x8004011d occurred while trying to refresh network connections to the Information Store. The Internet Mail Service is being shut down.
A serious error has occurred while trying to send mail into the Exchange Information Store. The Internet Mail Service is being shut down.
An unexpected error [0x80040115] occurred in maintenance thread.
Error 0xfffffdfd initializing the Microsoft Exchange Server Information Store database.
Error Database is in inconsistent state initializing the Microsoft Exchange Server Information Store database.

After unsuccessfully trying to copy a backed up edb.log and restart the store, i copied the priv.edb to a server with enough room to run an eseutil /p on it.  (not enough room on the mail server and without correct log files anyway, didn't think a soft recovery would be possible)
So now i've run the eseutil /p and it found many inconsistencies and I guess repaired them so now i'm running an eseutil /d (as per an article I read on here)
I plan on running the (isinteg -pri -fix -test alltests) next for good measure but am not sure what to do afterwards.  
I have deleted all of the log files and edb.chk from the mdbdata folder (as per a suggested solution from microsoft) but need to know the proper way to remount the defragged/checked priv.edb

Not sure where to go from here.  
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 10 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 10 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros