Solved

Event ID 9673 when MS Exchange Information Store service terminates unexpectedly

Posted on 2004-10-05
7
795 Views
Last Modified: 2008-02-20
I am running Exchange 2003 Ent. Ed. on Windows 2003 Ent. Ed. The IS service stops randomly but can be restarted. The server works fine until the next random crash. The following is logged in the application log:

Event Type:      Error
Event Source:      MSExchangeIS
Event Category:      General
Event ID:      9673
Date:            10/5/2004
Time:            10:42:12 AM
User:            N/A
Computer:      BMI-EX01
Description:
An exception with code 0xc00000fd was thrown in module C:\WINNT\system32\ntdll.dll; some parameters and their values were <Exception address - 8962c983>. A significant section of the call stack is in the data section.

Any suggestions?
0
Comment
Question by:LowStealth
  • 3
  • 3
7 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 12228704
Have you installed SP1 for Exchange? If not then you need to.

The other reference I found was it being caused by users trying to attach things in OWA. Again I believe this is fixed by the service pack.

If you have already SP the Exchange install then you need to state that as it does make a difference.

Simon.
0
 
LVL 1

Author Comment

by:LowStealth
ID: 12228834
Service Pack 1 for exchange is installed.
0
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 12229583
The only things I am finding on this are relating to attachments in OWA. Have you verified if this is the cause?

Unless anyone else comes up with a solution, I think a call to Microsoft is going to be the answer.

Simon.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 1

Author Comment

by:LowStealth
ID: 12229817
I have verified that adding an attachment in OWA regardless of size or file type will cause the problem. Got a solution?
0
 
LVL 104

Expert Comment

by:Sembee
ID: 12230475
Unfortunately not. I have found a load of newsgroup postings that point to the same problem, but there are no answers. Again, it might have to be a call to Microsoft. If enough people call then a KB article will be created.

Simon.
0
 
LVL 1

Author Comment

by:LowStealth
ID: 12237420
Turns out HackerDefender was on this machine. Similar to the issue here:

http://www.experts-exchange.com/Networking/Email_Groupware/Exchange_Server/Q_21063900.html

Although I had a newer version. The IS stopping when a file is attached in OWA is a bug in the rootkit. I will go over the cleanup because information seems scarce.

Download the rootkit detector and run from a command prompt:
http://bagpuss.swan.ac.uk/comms/RKDetectorv0[1].62.zip

If it says you have HackerDefender100 do the following. I am mirroring this information from http://www.buriedtruth.com/spysoftware/spynews/spyware-newgroup-archive/spyware-newgroup-archive-p-3198.html 

1) go to the command prompt and type in the following:
net stop HACKERDEFENDERDRV100
2) next open up regedit and do a search on "powerful"
3) You should see a key with a pharse that says "Powerful NT RootKit"
Export this key to your desktop and then delete this key.
4) Then reboot your computer
5) After the reboot go back to the command prompt and make sure the
HACKERDEFENDERDRV100 service is not running ( STEP 1)
6) Next go to start and search for files and folders
7) Type in the "a word or a phrase in the file" hxdefdrv.sys
8) This will then list several files that reference HackerDefender
9) I made a backup of all these files first and renamed the extensions
on them.
10) Find the *.ini file that is referenced in this search. This file
will contain *.dlls and *.exe that will need to be deleted from your
system.
11) Nuke the files that are referenced!
12) Then run regedit and look for "hackerdefenderdrv100". I would
strongly suggest that you make a full backup of your registry first,
then nuke all references to "hackerdefenderdrv100" then reboot.
13) After reboot you will need once more to make sure the
hackerdefenderdrv100 service is not running (Step 1)
14) If this service is still trying to run you will need to get your
Operating System disk and boot up to recovery console mode, then you
will need to login to the winnt system. Once your logged in, you will
need to type "listsvc".
You will see a ton of services, we are looking for
HACKERDEFENDERDRV100. If this one is listed you will then need to type
the following. Disable HACKERDEFENDERDRV100 Service_Disabled
Then type exit, and login into your clean system.

 

0
 

Expert Comment

by:ERDALISLAM
ID: 13023488
Do Anyone solve this problem? There is same problem my on Exchange Server.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now