General discussion
October 5, 2005 at 01:08 PM
psx

Error: Symantec AV10 on Exchange 2k3 SVR

by psx . Updated 19 years, 8 months ago

About 2 weeks ago my Exchange server started having problems with its file-system Antivirus scanner (Symantec AV 10.0.1, client). Whenever virus scan starts, it starts scanning the file system and all running services then crashes when it gets to “common infection locations (load points)”. The error message says “Buffer overrun detected!” then it point to rtvscan.exe as the source. The title of the message box says “Microsoft Visual C++ Runtime Library”.

Buffer overflow and problem with AV scanner usually point to either a virus infection or a trojan horse infection. However, I’ve run multiple AV scans on this system (using scanners other than Symantec’s) but nothing was found. I’ve also ran a couple of rootkit revealers which revealed nothing. A port scan on the system didn’t reveal any commonly-known trojan ports.

I thought this might be caused by a corruption in the SAV client software so I completely uninstalled it, rebooted, then reinstall but the problem still persists. I’ve narrowed the problem down to a couple of things:

1) Everytime the virus scan crashes, it shows that AeLookupSvc was the last item being scanned and it always crashes at this point.

2) A scan of the entire file system plus all running services will NOT fail but as soon as you add Common Loadpoints and Scan for traces of well-known threats, it crashes.

3) AeLookupSvc is a new service introduced in Windows 2003 Server for monitoring application compatibility problems.

Also, this shouldn’t have anything to do with my problem with the filesystem AV scanner but my Exchange server is also running Symantec AV for Exchange version 4.62. I’ve also excluded all necessary folders and files as described in MS and Symantec’s guides for AV on Exchange server. My Exchange server has been running fine until about 2 weeks ago.

I really need help with this problem. I’m forced to exclude Common Loadpoints and Scan for traces of well-known threats from my AV scans on this server.

This discussion is locked

All Comments