Hi Peter
Hope this is what you mean:
These are what are showing as active when I click on 'window' in Mercury:
Mercury Core Process
Mercury SMPT server
Mercury POP3 server
Mercury SMTP client (end to end process)
MercuryX scheduling module
Mercury IMAP4 server
I tried using the command prompt to:
I did phone my ISP (plusnet) who said they were not blocking ports and they had not done any maintainance etc around the time the problem happened).
I tried using the command prompt to:
telnet domain.com 25
telnet domain 110
Nothing seemed to be blocked and I could see the server was ready and waiting on both ports
I have Mercury running on Windows 2000 server
Pegasus is also running on the server as well as on 6 workstations all running XP
The problem started around 5pm on Tuesday the 15th of May and I have been looking at the server logs to try and fathom out what went wrong around that time.
The virus checker on the server was McAfee (more about this later) and the server logs show that McAfee (Network Associates) tried to install something new around that time
I have been trying to fathom out what some of the messages on the server logs mean:
Looking at the DNS server log:
AT 16:24 it shows:
The DNS server encountered a bad packet from 192.43.172.30. Packet processing leads beyond packet length.
On the Application log:
At 5pm exactly:
WebShield SMTP Service - AutoUpdate about to install new version
At 5:01pm
WebShield SMTP Service - Shutdown request for Network Associates Inc. WebShield SMTP MailScan Service
WebShield SMTP Service - Startup request for Network Associates Inc. WebShield SMTP MailScan Service
WebShield SMTP Service - Parent Scan engine failed to initialize
WebShield SMTP Service - Shutdown request for Network Associates Inc. WebShield SMTP MailScan Service
At 5:02pm
The description for Event ID ( 5000 ) in Source ( McLogEvent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: 256731, None, None, None, VirusScan Enterprise, 5.1.00, 5031.
On the 16th of May around 4pm, thinking that McAfee was responsible and was blocking something, I uninstalled it, rebooted the server, rebooted Mercury but emails still did not arrive.
Not wanting to be without any virus check I then installed Nod32
On the 17th of May I requested the host of my domain name to redirect my emails to a yahoo mailbox.
This proved impossible to handle so they have set them up as POP3 but as we have so many email address and so many mail boxes in Pegasus this is also impossible to handle.
Last night Nod32 started to show virus attempt logs and I was amazed to find that even though McAfee had been uninstalled, some part of it was still trying to do updates etc:
Time Module Object Name Threat Action User Information
18/05/2007 09:09:52 AMON file C:\Program Files\Network Associates\TVD\WebShield SMTP\AutoUpdate\scan.dat probably unknown SCRIPT virus quarantined - deleted Event occurred on a file modified by the application: C:\Program Files\Network Associates\TVD\WebShield SMTP\frontend.exe. The file was moved to quarantine. You may close this window.
(lots more of these but exactly the same just different times).
I then looked in the TVD\WebShield folder and everything seems to be around the year 2004 except for in the 'deferred' folder where it shows the following:
files which just contain copies of email addresses, the last one being in november 2004 and then starting on the 12th of May 2007 it starts to show files which contain copies of what appear to spam emails, there are hundreds of these.
The last file showing a spam email appears at 16:41 and that email is a failed spam multi-part email, using notepad to view it the very last line is:
/dKjq9AwPdM0XdNMkLuSO9I2LQouvdM+/dO4GAQAOw==
------=_NextPart_000_000B_01C79718.4290E5B0--
After that the 'deferred' folder contains hundreds of .log and .rcp files of which I have shown the first and last ones to appear:
File date: 15th May 2007 16:45
Log file contains:
[DeferFailureLog]
LastReason=Mail Server is down or unreachable. error: 10060
LastReasonCode=1001
Sat May 12 20:36:26 2007=Mail Server is down or unreachable. error: 10060
(above is repeated until: the last few lines show:
Tue May 15 14:29:43 2007=Mail Server is down or unreachable. error: 10061
Tue May 15 16:45:56 2007=Mail Server is down or unreachable. error: 10060
There are again hundreds of logs all on the 15th of may with the last one being:
[DeferFailureLog]
LastReason=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]
LastReasonCode=442
Tue May 15 07:53:23 2007=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]
(above message repeated but the last few lines are):
Tue May 15 15:53:53 2007=Mail Server is down or unreachable. error: 10060
Tue May 15 17:01:02 2007=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]
I am sorry to have posted so much but I simply do not know what is applicable and what is irrelevent.
If you can make any sense out of any of this I would really appreciate it.
Lynn
<p>Hi Peter
Hope this is what you mean:
These are what are showing as active when I click on 'window' in Mercury:</p><p>Mercury Core Process
Mercury SMPT server
Mercury POP3 server
Mercury SMTP client (end to end process)
MercuryX scheduling module
Mercury IMAP4 server</p><p>I tried using the command prompt to:</p><p>I did phone my ISP (plusnet) who said they were not blocking ports and they had not done any maintainance etc around the time the problem happened).</p><p>I tried using the command prompt to:
telnet domain.com 25
telnet domain 110
</p><p>Nothing seemed to be blocked and I could see the server was ready and waiting on both ports
</p><p>I have Mercury running on Windows 2000 server
Pegasus is also running on the server as well as on 6 workstations all running XP</p><p>The problem started around 5pm on Tuesday the 15th of May and I have been looking at the server logs to try and fathom out what went wrong around that time.
</p><p>The virus checker on the server was McAfee (more about this later) and the server logs show that McAfee (Network Associates) tried to install something new around that time
&nbsp;</p><p>&nbsp;I have been trying to fathom out what some of the messages on the server logs mean:
Looking at the DNS server log:</p><p>AT 16:24 it shows:
The DNS server encountered a bad packet from 192.43.172.30.&nbsp; Packet processing leads beyond packet length. </p><p>On the Application log:</p><p>At 5pm exactly:
WebShield SMTP Service - AutoUpdate about to install new version&nbsp;&nbsp; </p><p>At 5:01pm
WebShield SMTP Service - Shutdown request for Network Associates Inc. WebShield SMTP MailScan Service&nbsp;&nbsp; </p><p>WebShield SMTP Service - Startup request for Network Associates Inc. WebShield SMTP MailScan Service&nbsp;&nbsp;
WebShield SMTP Service - Parent Scan engine failed to initialize&nbsp; </p><p>WebShield SMTP Service - Shutdown request for Network Associates Inc. WebShield SMTP MailScan Service</p><p>At 5:02pm
The description for Event ID ( 5000 ) in Source ( McLogEvent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: 256731, None, None, None, VirusScan Enterprise, 5.1.00, 5031.</p><p>On the 16th of May around 4pm, thinking that McAfee was responsible and was blocking something, I uninstalled it, rebooted the server, rebooted Mercury but emails still did not arrive.
Not wanting to be without any virus check I then installed Nod32</p><p>On the 17th of May I requested the host of my domain name to redirect my emails to a yahoo mailbox.
This proved impossible to handle so they have set them up as POP3 but as we have so many email address and so many mail boxes in Pegasus this is also impossible to handle.</p><p>Last night Nod32 started to show virus attempt logs and I was amazed to find that even though McAfee had been uninstalled, some part of it was still trying to do updates etc:</p><p>Time&nbsp;&nbsp;&nbsp; Module&nbsp;&nbsp;&nbsp; Object&nbsp;&nbsp;&nbsp; Name&nbsp;&nbsp;&nbsp; Threat&nbsp;&nbsp;&nbsp; Action&nbsp;&nbsp;&nbsp; User&nbsp;&nbsp;&nbsp; Information
18/05/2007 09:09:52&nbsp;&nbsp;&nbsp; AMON&nbsp;&nbsp;&nbsp; file&nbsp;&nbsp;&nbsp; C:\Program Files\Network Associates\TVD\WebShield SMTP\AutoUpdate\scan.dat&nbsp;&nbsp;&nbsp; probably unknown SCRIPT virus&nbsp;&nbsp;&nbsp; quarantined - deleted&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; Event occurred on a file modified by the application: C:\Program Files\Network Associates\TVD\WebShield SMTP\frontend.exe. The file was moved to quarantine. You may close this window.
(lots more of these but exactly the same just different times).</p><p>&nbsp;I then looked in the TVD\WebShield folder and everything seems to be around the year 2004 except for in the 'deferred' folder where it shows the following:</p><p>files which just contain copies of email addresses, the last one being in november 2004 and then starting on the 12th of May 2007 it starts to show files which contain copies of what appear to spam emails, there are hundreds of these.
The last file showing a spam email appears at 16:41 and that email is a failed spam multi-part email, using notepad to view it the very last line is:</p><p>/dKjq9AwPdM0XdNMkLuSO9I2LQouvdM+/dO4GAQAOw==
------=_NextPart_000_000B_01C79718.4290E5B0--</p><p>After that the 'deferred' folder contains hundreds of .log and .rcp files of which I have shown the first and last ones to appear:</p><p>File date: 15th May 2007 16:45
Log file contains:
[DeferFailureLog]
LastReason=Mail Server is down or unreachable. error: 10060
LastReasonCode=1001
Sat May 12 20:36:26 2007=Mail Server is down or unreachable. error: 10060
(above is repeated until: the last few lines show:
Tue May 15 14:29:43 2007=Mail Server is down or unreachable. error: 10061
Tue May 15 16:45:56 2007=Mail Server is down or unreachable. error: 10060
&nbsp;There are again hundreds of logs all on the 15th of may with the last one being:</p><p>[DeferFailureLog]
LastReason=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]
LastReasonCode=442
Tue May 15 07:53:23 2007=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]
(above message repeated but the last few lines are):
Tue May 15 15:53:53 2007=Mail Server is down or unreachable. error: 10060
Tue May 15 17:01:02 2007=Requested action aborted: Network socket error (10020). [SMTP Error Code 442]</p><p>
I am sorry to have posted so much but I simply do not know what is applicable and what is irrelevent.
If you can make any sense out of any of this I would really appreciate it.</p><p>Lynn
</p><p>&nbsp;</p><p>&nbsp;
</p>