N
Newscene
We have developed the strangest new problem with one of our Win2000AS
servers. This is one of 4 virtually identical system, in this case its
primary role is SMTP/POP email. This server runs Merak Mail Server ver 8 but
the problem doesn't APPEAR to be related to the email server functions.
About three weeks ago, the day before DST went into effect for the US, the
system simply shut itself down about 3 minutes after midnight EST. The ONLY
indication in the Event Log is that the eventlog service was stopped. The
following night the shutdown occured at about 1AM EDT but returned to a few
minitues after EDT midnight on the following night. It continued like this
for several days and then stopped only to return after an absence of two
nights. Two days ago the shutdown changed and occured around 7:00 PM EDT.
Today, Monday 4/18 the shutdown occured at 09:45 EDT and again at 14:00 EDT
today.
We have examined every possible source of a scheduled event that might even
remotely be related and have found nothing. There are currently no system
actions in the Scheduled Tasks. The mailserver is set to update the
anti-Spam functions at 04:00 EDT. Further, we have examined every task and
service running in Task Manager and the Service control and all of them are
legitimate.
Thinking that the system might have been compromised somehow we have run
Spybot Search and Destroy as well as Microsoft's AntiSpyware and everything
comes up negative. The firewall is very tight and the there is only limited
external access to the network --- the only only ports open on the system
firewall are for WWW, SMTP, POP and VPN accesses --- so we do not think that
the cause is external.
In every case there is abolutely no indication of the source of the shutdown
or the cause. We have put together a small PERL program to send a
Wake-On-LAN to the machine when the shutdown is detected and it has worked
flawlessly since we implemented it --- so clearly it is an orderly shutdown.
servers. This is one of 4 virtually identical system, in this case its
primary role is SMTP/POP email. This server runs Merak Mail Server ver 8 but
the problem doesn't APPEAR to be related to the email server functions.
About three weeks ago, the day before DST went into effect for the US, the
system simply shut itself down about 3 minutes after midnight EST. The ONLY
indication in the Event Log is that the eventlog service was stopped. The
following night the shutdown occured at about 1AM EDT but returned to a few
minitues after EDT midnight on the following night. It continued like this
for several days and then stopped only to return after an absence of two
nights. Two days ago the shutdown changed and occured around 7:00 PM EDT.
Today, Monday 4/18 the shutdown occured at 09:45 EDT and again at 14:00 EDT
today.
We have examined every possible source of a scheduled event that might even
remotely be related and have found nothing. There are currently no system
actions in the Scheduled Tasks. The mailserver is set to update the
anti-Spam functions at 04:00 EDT. Further, we have examined every task and
service running in Task Manager and the Service control and all of them are
legitimate.
Thinking that the system might have been compromised somehow we have run
Spybot Search and Destroy as well as Microsoft's AntiSpyware and everything
comes up negative. The firewall is very tight and the there is only limited
external access to the network --- the only only ports open on the system
firewall are for WWW, SMTP, POP and VPN accesses --- so we do not think that
the cause is external.
In every case there is abolutely no indication of the source of the shutdown
or the cause. We have put together a small PERL program to send a
Wake-On-LAN to the machine when the shutdown is detected and it has worked
flawlessly since we implemented it --- so clearly it is an orderly shutdown.