• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

plesk login page problem

Re: Back up and running - How About A Bounty

Originally posted by SteveDude

Maybe we should put a bounty out on the chump that wasted our whole day and cost people who knows how much money. Supposed to be going on Vaction next week and I'm a day behind.

Yeah count me in on that.. what a bastard!!

For me, I've got a brand new windows installation up, and I got plesk 8.1 instead of 7.6.1. Also mailenable is updated to 1.981.

So right now, I'm trying to restore my 1,3gb .psa file from 7.6.1 into 8.1 - i reallyyyy hope this works the Mac way (meaning: works right out of the box!!)
 
please update what is the soluton to this probelm. all my websites are still in the same state and customer making life hell.
 
In case anyone cares: The issue where winlogon.exe keeps throwing errors can be resolved by whacking everying in c:\windows\config. (There are two .dll files in particular – config.dll and dhcp(d?).dll that seem to be tied to the rootkit. (Can’t remove them until you clean MailEnable SMTP Relay Service and the rdriv.sys foo).

Additionally, it is easy, in most cases, to modify the procedure to work via Remote Desktop – assuming the box is stable and not in a reboot loop.

I’m finally off to sleep. Everyone take care,

Steve
 
Originally posted by umangbagla
please update what is the soluton to this probelm. all my websites are still in the same state and customer making life hell.

What is the issue you are facing in resolving this ? I have PMed you, in case you need someone to help you fix this.
 
I'm finally done, re-install everything :(


Everything ran smoothly with help from lunarpages support staffers, upgrading also from 7.6.1 to 8.1, and newest version of MailEnable.

Only 2 things went wrong. On my old harddrive, in the MySQL Databases directory, there are 2 tables which is only named "<tablename>.frm" , for all other tables, there's ALSO a .MYD and .MYI file, whichh I think is essential for the table to work. So without these files, I can't get my 2 tables to work, it just says the tables does not exist :( Dont know how they could just have disappeared.
 
Originally posted by madguy24
Earlier may be a innodb storage format and current is not ?
You were sooo close to becoming my hero there, for a second!! It is true that if you use InnoDB, then all there is, is a .frm file - not the MYD and MYI files.

But still, I'm unable to read it.
It actually seems like the mysql server crashes, when phpmyadmin is trying to read my table, if I copy it over to the new database folder.
 
Some back up is available for those two tables or the entire DB ?
 
Originally posted by madguy24
Some back up is available for those two tables or the entire DB ?

I have like 10 MySQL databases, of which most of them were copied without problems.

One of the databases had 1 table in it, this table was only a table.frm file, which I could not read afterwards. Also, it says it was last modified february 13th, but I KNOW that data was added to it just 1 day ago.

Another database contains 2 tables, where only one table is no longer working, also here it's a "table.frm" file. The "other-table.frm" DOES have corresponding .MYD and .MYI files in the same folder.

I usually use only MyISAM for table types, not InnoDB.
 
Stepos to remove...

I got this info from PowerVPS...

It has come to our attention that a severe virus has been leashed onto the Internet which uses security flaw in older versions of MailEnable to infiltrate the server. Keep in mind that this only affects people who are using MailEnable and do not have the latest version (Standard - 1.981, Professional - 2.37, Enterprise - 2.37). If you are not using MailEnable, you can ignore this email.

Symptoms are inaccessible websites, permission problems and Plesk malfunctioning (if you use it).

First thing you should do is go to Administrative Tools and then Services.

Scroll down and find MailEnable\'s services and look for the one called \"MailEnable SMTP Relay Service\". If you don\'t have it, you are probably not infected by this virus.

If you do have it, however, right click it, go to Properties and choose Disabled as the Startup option.

Click OK and open Task Manager. Find the service called \"mesmtpsvc.exe\", right click on it and kill it.

Then open Windows Explorer and navigate to C:\\WINDOWS\\System32. Look for the following files: a.exe bot.exe bw.exe gethashes.exe getsyskey.exe nc.exe rdriv.sys start.bat

Delete them by holding down the Shift key and pressing the Delete button on your keyboard. Then go to C:\\WINDOWS and make sure \"mesmtpsvc.exe\" is not present - if it is, delete it.

Open up Windows Registry (Start -> Run -> regedit). Go to Edit -> Search and search for rdriv.sys and then for start.bat. Make sure to remove any and all references to these two from the Registry.

Download the latest version of MailEnable from http://www.mailenable.com/download.asp and just run the installer as if you would with any Windows application. Don't change any of the settings, leave it as-is.

Reboot the server and double check if those .exe files are present again. If you did not remove start.bat, you are likely to get infected again.

If you are using Plesk for Windows, run Plesk Reconfigurator (Start -> All Programs -> SWSoft -> Plesk -> Plesk Reconfigurator) -> Repair Plesk Installation -> Check \"Plesk Server Accounts\" and \"Plesk Virtual Hosts Security\".
 
Server is "Blue Screening" due to an issue with "rdriv.sys". what do i do in order to make it ping and be accessible through remote desktop.
 
Anyone having issues controlling directory permissions after this "fix" was applied?

I'm getting this error:

WebServerManager::getWebDirs() failed: websrvmng failed: Site autismawarefare.org doesn't exist
at (WebServerMap::get line 2706)
at execute console command --list-wdirs(vconsoleapp::start line 128)
at execute "C:\Program Files\SWsoft\Plesk\/admin/bin/websrvmng" --list-wdirs "--vhost-name=autismawarefare.org" "--wdir-name=/"(vconsoleapp::run line 138)
---------------------- Debug Info -------------------------------
0: C:\Program Files\SWsoft\Plesk\admin\plib\common_func.php3:152
psaerror(string 'WebServerManager::getWebDirs() failed: websrvmng failed: Site autismawarefare.org doesn't exist
at (WebServerMap::get line 2706)
at execute console command --list-wdirs(vconsoleapp::start line 128)
at execute "C:\Program Files\SWsoft\Plesk\/admin/bin/websrvmng" --list-wdirs "--vhost-name=autismawarefare.org" "--wdir-name=/"(vconsoleapp::run line 138)')
1: C:\Program Files\SWsoft\Plesk\admin\htdocs\domains\webdirs\webdirs.php:67
 
I installed Plesk on another machine and tried restore backup, but only sites without mysql works.
I'm having the same popup problem on a clean install with sites using mysql.
At least some sites are working now, but still, I'm afraid to go to work tomorrow as probably I'll get fired even though it's not my fault.

Any help regarding how to fix it is most welcome!
I still have old machine with mysql and everything. On I new machine Plesk restore didn't finish the job properly.

Thx in advance...
 
Here is another email regarding this issue I just received from the Plesk Support Team:

Hello, Sir

We have been working on a solution for this problem and have come over the following steps, which appeared to resolve the issue on a pack of servers.
As for the psacln, this is not a user, but a user group. And, sfc /scannow should be run from console session (use mstsc /console to start an RDP session). Please, check the other steps:

1. Restart your computer.
2. When you are prompted to select the operating system to start, press F8.
3. On the Windows Advanced Option menu, use the arrow keys to select Safe Mode, and then press Enter.
4. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
5 In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>Services
6. In the left panel, locate and delete the key:
rdriv
7. Close Registry Editor.
8. Open Windows Explorer. Right-click Start then click Explore.
9. On the Tools menu, click Folder Options.
10. Click the View tab.
11. Select Show hidden files and folders, then click OK.
12. Uncheck the Hide protected operating system files check box (if found).
13. Click Yes when prompted.
14. Uncheck the Hide file extension for known file types check box.
15. Click OK.
16. Right-click Start then click Search or Find, depending on the version of Windows you are running.
17. In the Named input box, type:
RDRIV.SYS
18. In the Look In drop-down list, select the drive that contains Windows, then press Enter.
19. Once located, select the file then press Delete.
20. Restart your server and make sure there is no c:\windows\system32\rdriv.sys file 21. run: gpedit.msc -> Open Computer Configuration -> Windows Settings -> Security -> Local Policies -> User Rights 22. Double click "Access this computer from the network" and make sure the following users/groups are added:
Group: Administrators
Group: Users
Group: Everyone
User: psacln
Group: psaserv
In order to add groups, you must select object types and enable searching in the groups type.
23. Verify that rdriv.sys is no longer found in c:\windows\system32 on the VPS 24. Verify that web sites can be viewed without the login prompt.
25. Check your server for viruses and make sure there are no any left

It's more or less everything from this thread if you've already read it.
 
at the point 22 I can't add user psacln or psaserv as it says "object not found"

Can't beleive my luck...
 
Originally posted by djape
at the point 22 I can't add user psacln or psaserv as it says "object not found"

Can't beleive my luck...

After you click on "Add User or Group", make sure you click the "Object Types" button in the top right. Check the "Groups" box there.

From there, I usually go to Advanced->Find Now and select from that window. It'll avoid typos.
 
thx for the tip mate,I managed to add users, but still the same, erlier today I have deleted virus and it's not present any more according to tips from this thread.

The bad thing is non mysql sites works (private clients) but mysql sites (companies) do not, it pop-ups as usual.

not sure how to implent mysql from old server, as plesk couldn't do it...

Thx ;)
 
FYI

My server did the same as everyone elses.. I did narrow the blue screen and spawn to the "mailenable smtp relay service" It was a fake service starting up an exe in the windows directory. Once i set that service to disabled the server would start up. I had to use a windows live cd to modify the services directly as remote.

Unfortunately i tried to upgrade from 7.5.1. to 7.5.6 and created more issues.. Ugghh


Hopefully the service may help some others! I believe it linked to mesmtprelay.exe or something like that but it was in the windows directory instead of the mail enable directory. That was how I caught which service was creating the error and blue screen.

Hope it helps!
 
Back
Top