Solved

Event ID 9673 when MS Exchange Information Store service terminates unexpectedly

Posted on 2004-10-05
7
790 Views
Last Modified: 2008-02-20
I am running Exchange 2003 Ent. Ed. on Windows 2003 Ent. Ed. The IS service stops randomly but can be restarted. The server works fine until the next random crash. The following is logged in the application log:

Event Type:      Error
Event Source:      MSExchangeIS
Event Category:      General
Event ID:      9673
Date:            10/5/2004
Time:            10:42:12 AM
User:            N/A
Computer:      BMI-EX01
Description:
An exception with code 0xc00000fd was thrown in module C:\WINNT\system32\ntdll.dll; some parameters and their values were <Exception address - 8962c983>. A significant section of the call stack is in the data section.

Any suggestions?
0
Comment
Question by:LowStealth
  • 3
  • 3
7 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 12228704
Have you installed SP1 for Exchange? If not then you need to.

The other reference I found was it being caused by users trying to attach things in OWA. Again I believe this is fixed by the service pack.

If you have already SP the Exchange install then you need to state that as it does make a difference.

Simon.
0
 
LVL 1

Author Comment

by:LowStealth
ID: 12228834
Service Pack 1 for exchange is installed.
0
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 12229583
The only things I am finding on this are relating to attachments in OWA. Have you verified if this is the cause?

Unless anyone else comes up with a solution, I think a call to Microsoft is going to be the answer.

Simon.
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Author Comment

by:LowStealth
ID: 12229817
I have verified that adding an attachment in OWA regardless of size or file type will cause the problem. Got a solution?
0
 
LVL 104

Expert Comment

by:Sembee
ID: 12230475
Unfortunately not. I have found a load of newsgroup postings that point to the same problem, but there are no answers. Again, it might have to be a call to Microsoft. If enough people call then a KB article will be created.

Simon.
0
 
LVL 1

Author Comment

by:LowStealth
ID: 12237420
Turns out HackerDefender was on this machine. Similar to the issue here:

http://www.experts-exchange.com/Networking/Email_Groupware/Exchange_Server/Q_21063900.html

Although I had a newer version. The IS stopping when a file is attached in OWA is a bug in the rootkit. I will go over the cleanup because information seems scarce.

Download the rootkit detector and run from a command prompt:
http://bagpuss.swan.ac.uk/comms/RKDetectorv0[1].62.zip

If it says you have HackerDefender100 do the following. I am mirroring this information from http://www.buriedtruth.com/spysoftware/spynews/spyware-newgroup-archive/spyware-newgroup-archive-p-3198.html

1) go to the command prompt and type in the following:
net stop HACKERDEFENDERDRV100
2) next open up regedit and do a search on "powerful"
3) You should see a key with a pharse that says "Powerful NT RootKit"
Export this key to your desktop and then delete this key.
4) Then reboot your computer
5) After the reboot go back to the command prompt and make sure the
HACKERDEFENDERDRV100 service is not running ( STEP 1)
6) Next go to start and search for files and folders
7) Type in the "a word or a phrase in the file" hxdefdrv.sys
8) This will then list several files that reference HackerDefender
9) I made a backup of all these files first and renamed the extensions
on them.
10) Find the *.ini file that is referenced in this search. This file
will contain *.dlls and *.exe that will need to be deleted from your
system.
11) Nuke the files that are referenced!
12) Then run regedit and look for "hackerdefenderdrv100". I would
strongly suggest that you make a full backup of your registry first,
then nuke all references to "hackerdefenderdrv100" then reboot.
13) After reboot you will need once more to make sure the
hackerdefenderdrv100 service is not running (Step 1)
14) If this service is still trying to run you will need to get your
Operating System disk and boot up to recovery console mode, then you
will need to login to the winnt system. Once your logged in, you will
need to type "listsvc".
You will see a ton of services, we are looking for
HACKERDEFENDERDRV100. If this one is listed you will then need to type
the following. Disable HACKERDEFENDERDRV100 Service_Disabled
Then type exit, and login into your clean system.

 

0
 

Expert Comment

by:ERDALISLAM
ID: 13023488
Do Anyone solve this problem? There is same problem my on Exchange Server.
0

Featured Post

Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now