DXXD: Ransomware apparently attacks Windows Server directly

The DXXD ransomware apparently attacks Windows servers directly. Like other ransomware, DXXD encrypts files and appends the extension .dxxd to the encrypted file. Up to now, an attack on Windows servers has usually started from an infected client, which then encrypted files on network drives. In the Bleeping Computer forum, however, it is suspected that ... Read more

Microsoft now also distributes Windows updates as an update rollup

Since this month, Microsoft has also been distributing Windows updates as update rollups, similar to Exchange Server. Several updates are combined in update rollups. On the one hand, this has the advantage that not countless individual updates have to be installed, but significantly fewer. The disadvantage, however, is that certain updates can no longer be deselected or uninstalled individually. ... Read more

Windows Nano Server and VMware ESXi

Microsoft introduced the Nano Server with Windows Server 2016. Nano Servers have no GUI and are even more reduced than Server Core installations. Nano servers are only managed remotely and corresponding images must first be created. It is quite simple for Hyper-V, as VHD files can be created directly here. However, it also works ... Read more

VSS: Backup fails with error message ConvertStringSidToSid

Today I once again had a Windows server that could no longer be backed up via VSS. The creation of a VSS snapshot aborted with the following error message: Volume Shadow Copy Service Error: An unexpected error occurred while calling the routine "ConvertStringSidToSid(S-1-5-21-1629892529-1905228445-1032730592-4125.bak)". hr = 0x80070539, The structure of the security identifier is invalid. . Operation: OnIdentify event Generator data is being collected Context: Execution context: ... Read more

Exchange 2016: Noderunner.exe high memory consumption and CPU load

I have already received the following questions about the Noderunner process or statements in one form or another by e-mail: Noderunner.exe consumes almost all the RAM and almost always has 100 % CPU load, what can I do? Here's something more desperate: From day one, the noderunner has been eating up resources we ... Read more

HowTo: Installing Exchange 2016 on Windows Server 2016

This howto describes the installation of Exchange 2016 on Windows Server 2016. Note: This article is a bit older. There is an updated version here: Create Active Directory account Windows Server 2016 relies on a stricter user separation. It is therefore not advisable to install the Exchange Server with the "Administrator" user, but to create an ... Read more

Exchange 2016: Virus scanner exclusions (script for Windows Defender)

Windows Defender is activated by default on Windows Server 2016. As Exchange Server requires some exclusions from the virus scanner, these must also be stored accordingly in Windows Defender. The same applies to virus scanners from other manufacturers. The following note can be found on the Exchange Team Blog: Windows Defender is on by default in Windows Server 2016. Attention to ... Read more

Windows Server 2016 available!

Microsoft released Windows Server 2016 at the start of Ignite in Atlanta. So far, however, the new server operating system can only be downloaded as a demo version (evaluation version): Windows Server 2016 Evaluation The evaluation version is 5 GB in size and is also available in German. As of today, no version is available in MSDN. But I think it will be ... Read more