Versions / Builds Affected20131111, 20140616
Problem Summarymarc.search.exe allocating all available RAM when indexing certain attachments (virus)
TT / JIRAID1989
How to IdentifyCertain emails can cause that marc.search.exe to allocate all available RAM on a system which will effectively leave Search and the whole server in an unresponsive state and might also cause other processes to crash.
You can spot the memory allocation via the Windows Task manager.
Based on the cases we have seen all email samples seem to contain the same virus, but the emails / attachments appear to have random names.
Samples of subject:
Track your shipment No037591
Samples of attachment names:
The virus appears to be generic. E.g. VIPRE identified it as: Trojan.Win32.Generic!BT. This lists how other engines named it:
Avast: Win32:SmokeLoader-JZ [Trj]
K7AntiVirus: Trojan ( 19ee9cec0 )
Panda: Generic Malware
To identify the the last attachment / decompressed file check the last lines of Search/DebugLogs/ZipAttachment.log resp. IndexableAttachment.log from the point in time when the RAM allocation begins. Here is an example:
2014-02-28,14:47:24,078,1,"#00000D5C","#0000000C","info ","ZipAttachment","Decompressing Invoice_ID27515.zip at depth 0"
2014-02-28,14:47:24,078,1,"#00000D5C","#0000000C","info ","IndexableAttachment","Processing attachment [file] Invoice_ID27515.exe at depth 1"
2014-02-28,14:47:24,078,1,"#00000D5C","#0000000C","info ","IndexableAttachment","Processing attachment [file] system__/doc-21.txt at depth 1"
2014-02-28,14:47:24,078,1,"#00000D5C","#0000000C","info ","IndexableAttachment","Processing attachment [file] system__/system.docx at depth 1"
At this point in time marc.search.exe is taking up all available RAM very quickly.
- The behavior / memory consumption cannot be followed via a set of troubleshooting files on their own. Normally a remote session is needed to determine this issue.
Workaround / Fix DetailsWORKAROUND
Disable indexing of attachments (see article ) or pause indexing
Fixed in GFI Archiver 2015 build 20141117
Required ActionsUpgrade to GFI Archiver 2015 build 20141117 or newer