Windows 2003 Server Weird Crashing

machoman013

Member
Oct 20, 2003
74
0
0
Yesterday one of our 2k3 server computers which is also DNS, DHCP, DC and File server just imploded on itself yesterday and disconnected from the network. Server was restarted and everything appeared normal except that it kept popping up with IIS 6.0 crashing errors related to w3wp.exe. I've checked the event logs as well and found a bunch of 'fault bucket' errors 1001. When I opened up the cmd shell, and tried to do a typical command, it gave the following:

'dir' is not recognized as an internal or external command

Samething happens with the most basic of dos functions, however here's the catch, ipconfig, ver, etc works. Even more bizzare is that the other server running DC, DNS, and Exchange is having the same cmd shell issue.

Scanning both servers now, found hidden32.exe and hideexec.A in the system vol information on the first server that originally crashed. Both servers also turned up Smitfraud.C from spyboy 1.4 and adaware is still unclear yet for both too.

Is there a path issue or something much more serious?
 

Fraggable

Platinum Member
Jul 20, 2005
2,799
0
0
Sounds like a simple spyware/malware/virus issue to me. I recently had a virus that disabled my ability to run cmd and the task manager. Ewido security suite took care of it and I got my system back easily.

Don't even tell me you didn't have a virus scanner running on your file server...
 

machoman013

Member
Oct 20, 2003
74
0
0
No way man, what the hell.. that's like an insult. AVG Network Edition 7.1.x I also had spybot and adaware on there. Though I wasn't exactly scanning once a week like a good boy.
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
You got something on there, it doesn't really matter how it got there. Although one possibility is web browsing. Web browsing on a server is Really Bad.

On a DC/Exchange server, getting infected with malware is a devastating event, since you can no longer assume your entire domain hasn't been compromised. You're looking at a complete rebuild of that system. If this is not the only domain controller, you're also looking at a reset of every account password at a minimum.

 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
Let me just add, if you want to have any chance of saving anything, I would highly, highly recommend a call to Microsoft PSS Security (1866-PCSAFETY)
 

machoman013

Member
Oct 20, 2003
74
0
0
I don't have a gold or silver level membership with them, it'd be cheaper for me to use a professional consultant in our area that has such resources. Thanks for your insights.
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: machoman013
I don't have a gold or silver level membership with them, it'd be cheaper for me to use a professional consultant in our area that has such resources. Thanks for your insights.

It's free.
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
I don't understand. You're infected with malware and spyware and who knows what else - and you're blaming a MS update?
 

machoman013

Member
Oct 20, 2003
74
0
0
I didn't say I was blaming them for it, but it was at the sametime this happened too on both servers right after rebooot of the updated patches.
 

machoman013

Member
Oct 20, 2003
74
0
0
Originally posted by: stash
Let me just add, if you want to have any chance of saving anything, I would highly, highly recommend a call to Microsoft PSS Security (1866-PCSAFETY)

1866 pc saftey no longer works for me.
 

Xtremist

Golden Member
Dec 2, 1999
1,342
0
0
Either you have a typo in your post or you aren't dialing the correct number stash referred.

This is a little OT but you seem pretty defensive towards people that are trying to help you out.

Good luck with your issue though, the fact that it's a DC is absolutely terrifying.
 

machoman013

Member
Oct 20, 2003
74
0
0
Thanks for the gl. I'm only defensive for people who don't seem to try to link other variables into the equation other than 'assumption'. If you would like to type out those #'s for the hotline, please do, because it ain't working from my logix T line phone or any phone I'm using.

p.s. please think about how people type to each other. read it out loud and see if you would someone to tell you either you're stupid or the fact is wrong.
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0
Direct from Microsoft's site: (I don't know if it works or not)
----------------------------------------
No-Charge Support
Call 1-866-PCSAFETY (866-627-2338) for virus related support at no charge (US and Canada only).
----------------------------------------
Contact your antivirus vendor for assistance with identifying or removing virus or worm infections. If you need more help with virus-related issues, contact Microsoft Product Support Services.

? For support within the United States and Canada, call toll-free (866) PCSAFETY (727-2338)
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |