Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Exchange 5.5 issue caused by virus ????

Status
Not open for further replies.

jcck2003

IS-IT--Management
Mar 21, 2003
168
US
Hi All:

I believe all of you heard of recent stream of new virus and worms, we have been hit by many of them on our Exchange 5.5 box and VPN server host with NT server. (sp6a)

this morning some user reported to me the email was down, I looked at it, nothing occur to me first something was wrong, however, when I tried to get to the service manager in control panel, the system just sits there, and nothing else except the internet explorer would run, have anybody seem this issue ?

JDK
 
Look at your Task Manager if you ca. Is DSAMAIN.EXE taking up about 99% of the cpu? This is happening on ours. I ran a check today becuase our anti-virus pattern file was outdated and when I updated it I found WORM_SOBIG.F all over my exchange server. DSAMAIN.EXE has been doing this since monday of last week right around the time this virus popped up.
 
I did see DSAMAIN.EXE running on the system, is that EXE part of the virus ???, but I don't remember it was 100% of the CPU though, our virus definition file is very up to date and I did a full scan (except the Exchange folders) and found nothing

any comments
thanks
JDK
 
Its part of the echange directory service. ours has been gonig crazy. make sure you get a very new pattern file. We use trend micro products and they didn't have a patern file that found it until two days ago.
 
ours has the newest one out there, but I think it also got hit by bunch other things which tried to install FTP service in the mail server box

 
I wound up doing the eseutil on our database, it did find some errors but i won't know if it worked until the morning when i check the server.
 
any suggestions what kind of maintenance I should be performing on the exchange server? We are small business with 5 email accounts. However, exchange server is now taking up 5 gigabites of storage and I am down to 560 kb of storage on my c drive. Thanks, Rich
 
I ran into some similar problems with the storage on c drive after sobig virus. Check to see if you NAV for exchange is set to "quarantine." The cause of my sudden disk space increase. If so change it to "delete attachments and send remainder to recipents" and delete your quarantine and backup files for NAV. They are located in c:\program files\navmse\backup and quarantine. Hope this help your storage problem a little. By the way, I have a 5.5 box.
 
that is pretty big for 5 users,

if you using both NAV for Exchange and NAV corp edition
also check your profile directory see if its filled with logs. I had cases where a corrupted virus definition, NAV making those .log files like crazy, eventually people find out when they can't print

1. check all your directories see what is actually taking up the space

2. check file by sizes, kill the big files first (do a search on any file more than 10-15 MB, if you delete all your finding, that is usually 80% your disk space back)

3. check the NT profiles folder, under All Users, Application data, Symantec ...etc

what about my oginial question, any more input ???

JDK
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top