Microsoft
Software
Hardware
Network
Question : Exchange recovery
I am looking at a problem with a SBS 2003 Exchange server. It looks like the antivirus program had not been configured to bypass the Exchange files and has deleted an entry in a log file. This is the entry from the antivirus log:
18/06/2010 17:18:44 Deleted (Clean failed) NT AUTHORITY\SYSTEM C:\Program Files\Exchsrvr\bin\store.e
xe I:\Program Files\Exchsrvr\mdbdata\E00
.log\00002
d8c.js JS/Redirector (Trojan)
The databases will now not mount and the entry in the Event Viewer is below. Is there any action I can take other than restoring yesterday’s backup?
Event Type: Error
Event Source: ESE
Event Category: General
Event ID: 486
Date: 18/06/2010
Time: 17:18:44
User: N/A
Computer: SHERWOODSRVR01
Description:
Information Store (3688) First Storage Group: An attempt to move the file "I:\Program Files\Exchsrvr\mdbdata\E00
.log" to "I:\Program Files\Exchsrvr\mdbdata\E00
1279F.log"
failed with system error 2 (0x00000002): "The system cannot find the file specified. ". The move file operation will fail with error -1811 (0xfffff8ed).
There is also another Event Viewer entry:
Event Type: Error
Event Source: ESE
Event Category: Logging/Recovery
Event ID: 413
Date: 18/06/2010
Time: 17:18:44
User: N/A
Computer: SHERWOODSRVR01
Description:
Information Store (3688) First Storage Group: Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1811.
Answer : Exchange recovery
You should be able to run ESEUTIL to repair the database. Since the file was deleted by A/V, ESEUTIL will just update the index and there *should* be no data loss. As always, have a backup. And set up your A/V exclusions!!!
Random Solutions
How to use a Unit
cfinvoke problem
Policy-based routing using port numbers? Is it possible?
Error 3001 in Excel VBA with MySQL - Query runs fine in MySQL
What's the best (free) logging framework for C++?
What is the easiest (cost effective) way of connecting two or more offices/sites?
which pdf reader for linux?
Copy/Paste Relative to other column's number of rows
Visio 2007 shapes are missing
Microsoft Access 2003