Server reboots randomly

G

Guest

Guest
Archived from groups: microsoft.public.windowsnt.misc (More info?)

Our ancient NT4 web server which has been humming away since 1999 has been
rebooting randomly.

NT4 with sp6a, IIS, patched with all Microsoft patches as of 5/17. McAfee
4.5 indicates 5/18.

A GIS administrator handles the GIS/Land Records software and upgraded some
files from Access 97 to Access 2000, around the time it started, I think.
Moad and/or ERSI software does the Land Records inquiry, and sits on top of
IIS.

Symptoms - Server running a little bit slower than normal (Was always slow
but somewhat slower now)

Server reboots and nothing concrete in the Event View logs. There is over
800 *.mem files on the partition where IIS sits, and is in the root of that
partition.

I ran performance analyzer but am not finding anything. Tonight McAfee shows
a virus 'Generated Zombie' program in the inet pub folder.

Any ideas what is causing this and where to look?

Thanks

George
MCP,CNA, A+
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsnt.misc (More info?)

Sounds like the Sasser Virus. Have a look at your running services to
see if you can find "avserve.exe". If it is there and running you have
the Sasser virus. You need to update your antivirus (or get a decent
one) and remove it. You also need to make sure that the specific patch
from Microsoft has been installed.
If you're not keen on buying another AV program try some of the online
ones such as Trend Micro's House call.
sh4d03

someone someplace wrote:

> Our ancient NT4 web server which has been humming away since 1999 has been
> rebooting randomly.
>
> NT4 with sp6a, IIS, patched with all Microsoft patches as of 5/17. McAfee
> 4.5 indicates 5/18.
>
> A GIS administrator handles the GIS/Land Records software and upgraded some
> files from Access 97 to Access 2000, around the time it started, I think.
> Moad and/or ERSI software does the Land Records inquiry, and sits on top of
> IIS.
>
> Symptoms - Server running a little bit slower than normal (Was always slow
> but somewhat slower now)
>
> Server reboots and nothing concrete in the Event View logs. There is over
> 800 *.mem files on the partition where IIS sits, and is in the root of that
> partition.
>
> I ran performance analyzer but am not finding anything. Tonight McAfee shows
> a virus 'Generated Zombie' program in the inet pub folder.
>
> Any ideas what is causing this and where to look?
>
> Thanks
>
> George
> MCP,CNA, A+
>
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsnt.misc (More info?)

I downloaded and ran the analyzer Microsoft has. It found vulnerabilities that Windows Update was not finding.

I patched 5 items, and also made an important discovery.... A 260 meg log file IIS was using!

Deleted the log file and patched the server. No reboots for two days now. Lets hope.

George
 

TomK

Distinguished
Apr 9, 2001
2
0
18,510
Archived from groups: microsoft.public.windowsnt.misc (More info?)

Still working? I have this exact same problem with an almost exact same
configuration, except no trace of the sasser virus. I'm curious if this
seems to have fixed your problem!