<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Van's FSS/Antigen Blog</title><subtitle type="html" /><id>http://blogs.technet.com/msfss_stuff/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/msfss_stuff/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2009-07-02T08:38:48Z</updated><entry><title>Issue with SP2 for Antigen for exchange</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/12/11/issue-with-sp2-for-antigen-for-exchange.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/12/11/issue-with-sp2-for-antigen-for-exchange.aspx</id><published>2009-12-11T15:15:56Z</published><updated>2009-12-11T15:15:56Z</updated><content type="html">&lt;p&gt;We are seeing a few calls from people that have upgraded to Antigen for Exchange SP2.&lt;/p&gt;  &lt;p&gt;These calls have AntigenService.exe hanging. This can create issues updating, connecting with the client and mail flow issues.&lt;/p&gt;  &lt;p&gt;This issue is caused when we initialize the cloud mark engine.&lt;/p&gt;  &lt;p&gt;There is a hot fix rollup for SP2 at &lt;a title="http://support.microsoft.com/kb/975355" href="http://support.microsoft.com/kb/975355"&gt;http://support.microsoft.com/kb/975355&lt;/a&gt; that addresses this issue. The current KB does not have this issue listed but we are working on changing this.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3299913" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Performance" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Performance/default.aspx" /><category term="Antigen" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Antigen/default.aspx" /><category term="Antigen Upgrade" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Antigen+Upgrade/default.aspx" /><category term="Anti-Spam" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Anti-Spam/default.aspx" /><category term="Engine Updates" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Engine+Updates/default.aspx" /></entry><entry><title>If you are updating to SP2</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/11/23/if-you-are-updating-to-sp2.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/11/23/if-you-are-updating-to-sp2.aspx</id><published>2009-11-23T13:18:48Z</published><updated>2009-11-23T13:18:48Z</updated><content type="html">&lt;p&gt;make sure your engines have updated after October. &lt;/p&gt;  &lt;p&gt;SP2 has a mapper (packaged with the engines) requirement that was released two months before SP2 came out.&lt;/p&gt;  &lt;p&gt;we have seen a case that had a customer not updating for a year and this caused the engines to not load after the upgrade to service pack 2. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3295797" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>10 days till engine deprecation</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/11/20/10-days-till-engine-deprecation.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/11/20/10-days-till-engine-deprecation.aspx</id><published>2009-11-20T21:54:10Z</published><updated>2009-11-20T21:54:10Z</updated><content type="html">&lt;p&gt;If you have written into support lately you should have seen something like this in the signature of the engineer you were working with&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td width="60"&gt;         &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/msfss_stuff/WindowsLiveWriter/10daystillenginedeprecation_EDB0/clip_image002_2.gif"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/msfss_stuff/WindowsLiveWriter/10daystillenginedeprecation_EDB0/clip_image002_thumb.gif" width="43" height="43" /&gt;&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="864"&gt;         &lt;p&gt;Did you know Antigen and Forefront will be removing support for the CA, Sophos, AhnLab and SpamCure engines on December 1st, 2009?&amp;#160; To find out more, please visit the &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/dd940095.aspx"&gt;Antimalware Engine Notifications and Developments&lt;/a&gt; TechNet page.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In 10 days we will be removing these engines from our update servers.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;One thing that customers need to be aware of &lt;/p&gt;  &lt;p&gt;If they have the “Box Set” license that comes with Antigen, CAVet, Microsoft, Norman, Sophos&lt;/p&gt;  &lt;p&gt;they will be running with only the Microsoft updated engine as of the first. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The solution to this is to request a new license file that will unlock the Kaspersky, VirusBuster and Command engine and Cloud Mark for Anti-Spam.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The instructions for the license is in the link above.l&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3295454" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the week 10/9/09</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/10/08/issue-of-the-week-10-9-09.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/10/08/issue-of-the-week-10-9-09.aspx</id><published>2009-10-08T22:25:33Z</published><updated>2009-10-08T22:25:33Z</updated><content type="html">&lt;p&gt;Issue:&lt;/p&gt;  &lt;p&gt;Constant StatisticsManagerServer event id 100 on the passive node of a 2003 cluster (maybe on a SCC cluster in 2008 as well)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Cause:&lt;/p&gt;  &lt;p&gt;Antigen Statistics Service needs to access the statistics.xml located in the %data% folder of the Antigen install. &lt;/p&gt;  &lt;p&gt;On a passive node this xml file is located on the shared drive that is controlled by the active node. This causes a failure to start for the service.&lt;/p&gt;  &lt;p&gt;The service is starting because something is making a call to it. &lt;/p&gt;  &lt;p&gt;In most cases there is monitoring software that loads up our Scan counters for performance monitor. &lt;/p&gt;  &lt;p&gt;Other issues could stem from FSSMC collecting scan data from the passive node.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Workaround:&lt;/p&gt;  &lt;p&gt;Monitoring software. This is expected behavior and the process loading these counters need to be configured to not monitor Antigen on passive nodes.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;FSSMC: If you are using FSSMC to monitor the passive node you can try re-deploying the agent to the passive node.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3285611" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Runner up – 9/30/09</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/09/30/runner-up-9-30-09.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/09/30/runner-up-9-30-09.aspx</id><published>2009-09-30T20:53:03Z</published><updated>2009-09-30T20:53:03Z</updated><content type="html">&lt;p&gt;We have seen the following issue a few times in the last two weeks&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Issue:&lt;/p&gt;  &lt;p&gt;After installing Antigen or recycling the server where we are installed with, Exchange fails to start up. Error is dependency failed to start. &lt;/p&gt;  &lt;p&gt;Trying to start Antigen Monitor results in a “%t is not a valid win32 application” message.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Cause:&lt;/p&gt;  &lt;p&gt;Our paths are not wrapped in quotes in the registry. &lt;/p&gt;  &lt;p&gt;Antigen is installed into a path with spaces in it (Program files)&lt;/p&gt;  &lt;p&gt;A file matching the first word in the install path is in the root directory. &lt;/p&gt;  &lt;p&gt;Example:&lt;/p&gt;  &lt;p&gt;0 byte file called program in the root of c:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Analysis:&lt;/p&gt;  &lt;p&gt;Without wrapping you paths in quotes you run into windows guessing what you mean when you pass it a command&lt;/p&gt;  &lt;p&gt;For example&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;C:\program files\Microsoft antigen\exchange\antigenservice.exe&lt;/p&gt;  &lt;p&gt;In a normal system would launch antienservice. &lt;/p&gt;  &lt;p&gt;In a system with a file called program in the c:\ folder it would launch&lt;/p&gt;  &lt;p&gt;C:\program&lt;/p&gt;  &lt;p&gt;with the argument files\Microsoft antigen\exchange\antigenservice.exe&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Solution:&lt;/p&gt;  &lt;p&gt;Remove the file that matches the word before the first space (In my example the 0 byte program file)&lt;/p&gt;  &lt;p&gt;You can also re-install in a path with no spaces (c:\antigen)&lt;/p&gt;  &lt;p&gt;If you remove the file in the root of the drive and it comes back you can use process explorer to trace the creation of the file and then find out what program is dropping files in your root directory.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;We should also be implementing a fix for this in the next hotfix rollup.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3284124" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the week 9/30/09</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/09/30/issue-of-the-week-9-30-09.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/09/30/issue-of-the-week-9-30-09.aspx</id><published>2009-09-30T20:36:20Z</published><updated>2009-09-30T20:36:20Z</updated><content type="html">&lt;p&gt;I had a good question today from one of my customers &lt;/p&gt;  &lt;p&gt;What is the background scan.&lt;/p&gt;  &lt;p&gt;here is my response. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You should never use a background scan.&lt;/p&gt;  &lt;p&gt;Ever…&lt;/p&gt;  &lt;p&gt;Background scanning was a clever idea back in the day when VSAPI 1.0 was released. &lt;/p&gt;  &lt;p&gt;You have a background scan running in VSAPI that goes through every file in your database.&lt;/p&gt;  &lt;p&gt;Then when that file is accessed, if it has been scanned with the latest definitions it skips the scan on access and the file is allowed to pass.&lt;/p&gt;  &lt;p&gt;Problem is.. back in 1999-2000 when that came out, virus definitions updated on average once a week. &lt;/p&gt;  &lt;p&gt;Today you can have engines that update every 1-4 hours. And with 5 engines.. you get the point.&lt;/p&gt;  &lt;p&gt;The scan never finishes and basically acts as a resource pit.&lt;/p&gt;  &lt;p&gt;We support it, because VSAPI still supports it.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3284120" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the Week 9/24</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/09/24/issue-of-the-week-9-24.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/09/24/issue-of-the-week-9-24.aspx</id><published>2009-09-24T19:44:10Z</published><updated>2009-09-24T19:44:10Z</updated><content type="html">&lt;p&gt;The following error is logged every 60 minutes on Forefront Server for Exchange SP2 &lt;/p&gt;  &lt;p&gt;This is a informational warning but the way it is worded might cause some concern. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;Log Name:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Application&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Source:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; FSEAgent&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 8/28/2008 2:13:21 AM&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 8048&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Task Category: (8)&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Level:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Error&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Keywords:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Classic&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;User:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; N/A&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; XXXXXXXXXXXXXX&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;&lt;b&gt;1 messages have been archived and purged due to an error while scanning. Please ensure that mail is not queuing.&lt;/b&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This error stems from mail being stuck in the Undeliverable folder of our archive folder. &lt;/p&gt;  &lt;p&gt;The default path is c:\Program files (x86)\Microsoft Forefront for Exchange\Archive\Undeliverable\&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;There should be a file stuck in that folder or under a subfolder. &lt;/p&gt;  &lt;p&gt;Removing this message will stop the error.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3282959" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the Week 9/17</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/09/17/issue-of-the-week-9-17.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/09/17/issue-of-the-week-9-17.aspx</id><published>2009-09-17T22:25:11Z</published><updated>2009-09-17T22:25:11Z</updated><content type="html">&lt;p&gt;Missed a week.&lt;/p&gt;  &lt;p&gt;This is for the following error&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Event Type:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Error&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Event Source:&amp;#160;&amp;#160;&amp;#160; GetEngineFiles&lt;/p&gt;    &lt;p&gt;Event Category:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Engine Error &lt;/p&gt;    &lt;p&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 6012&lt;/p&gt;    &lt;p&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; #/##/####&lt;/p&gt;    &lt;p&gt;Time:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; #:##:## ##&lt;/p&gt;    &lt;p&gt;User:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; N/A&lt;/p&gt;    &lt;p&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Testlab01&lt;/p&gt;    &lt;p&gt;Description:&lt;/p&gt;    &lt;p&gt;Microsoft Forefront Server Security encountered an error while performing a scan engine update.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160; Scan Engine: Microsoft&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160; Error Code: 0x80070102&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160; Description: Unable to acquire the scan engine update mutex within the&amp;#160;&amp;#160;&amp;#160; designated timeout period.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This is a timeout and there is a KB (&lt;a title="http://support.microsoft.com/kb/939411" href="http://support.microsoft.com/kb/939411"&gt;http://support.microsoft.com/kb/939411&lt;/a&gt;)&amp;#160; that discusses increasing the download scan timeout but it does not take into account the other issues you will see with longer download times. Our mutex timeout is hardcoded at 3 minutes.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If you have increased your InternetDownloadtimeout to match the longest download times you see in your programlog you need to take into consideration that you can run into a situation where you have scan engine updates timing out because we timeout waiting for the current download.&lt;/p&gt;  &lt;p&gt;For example &lt;/p&gt;  &lt;p&gt;if the following engines are set to download at these times&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Ahlab at 07 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Kaspersky at 09 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Norman at 34 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Microsoft at 39 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Vbuster at 48 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Sophos at 44 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;CAVet at 49 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;Command at 54 min after the hour Repeat every 1 hours&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;And the engines take 15-25 minutes to download&lt;/p&gt;  &lt;p&gt;This is never going to work correctly.&lt;/p&gt;  &lt;p&gt;If it takes 15-30 minutes for you to download an engine you need to make sure that no engine downloads in that timeframe.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Here is a suggestion (1800 minutes for the download setting)&lt;/p&gt;  &lt;p&gt;8:00 AM Ahnlab update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;8:32 AM Kaspersky update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;9:04 AM Norman Update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;9:36 AM Microsoft Update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;10:08 AM VBuster Update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;10:40 AM Sophos Update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;11:12 AM CaVet Update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;11:44 AM Command update Repeat every 4 hours&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This would ensure that you never have two engines fighting for the download at the same time. If your downloads are faster you can repeat the update faster. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let me know if this helps you out.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3281763" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the week 8/31/09</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/08/31/issue-of-the-week-8-31-09.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/08/31/issue-of-the-week-8-31-09.aspx</id><published>2009-08-31T20:00:07Z</published><updated>2009-08-31T20:00:07Z</updated><content type="html">&lt;p&gt;Another FSCIMC hung in a start pending state issue.&lt;/p&gt;  &lt;p&gt;Before this was tied to execution policy being set to restricted or locally signed&lt;/p&gt;  &lt;p&gt;This time certificates are to blame.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If for some reason your Microsoft root authority certificate expires you can expect to see FSCIMC and Edge transport fail to start with the execution policy at the default setting.&lt;/p&gt;  &lt;p&gt;We require at least remote signed but if there is an issue with contacting the CA and you have an invalid or expired certificate you will have to lower your exchange power shell script permissions to unrestricted.&lt;/p&gt;  &lt;p&gt;This will allow you to start up but the real fix would be to fix your certificates as other issues will occur with updates not able to verify the digital signatures. &lt;/p&gt;  &lt;p&gt;This issue occurs because there is a popup warning of an invalid certificate. Since we are running as system we never see that popup and sit and wait for something to happen.&lt;/p&gt;  &lt;p&gt;If you remove our produce you will then see a pop-up generated by edge transport with the same information about an invalid certificate. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278297" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Forefront for Exchange" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Forefront+for+Exchange/default.aspx" /><category term="Forefront Server Security" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Forefront+Server+Security/default.aspx" /><category term="Forefront" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Forefront/default.aspx" /></entry><entry><title>PDF false detects</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/08/20/pdf-false-detects.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/08/20/pdf-false-detects.aspx</id><published>2009-08-20T20:11:00Z</published><updated>2009-08-20T20:11:00Z</updated><content type="html">&lt;p&gt;*Update*&lt;/p&gt;  &lt;p&gt;MSAV has been updated and has resolved this issue. &lt;/p&gt;  &lt;p&gt;Command engine has resolved this issue as well.&lt;/p&gt;  &lt;p&gt;*Update* &lt;/p&gt;  &lt;p&gt;Looks like there is a false detect issue with some engines and PDF files.&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;&lt;b&gt;Antivirus&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;&lt;b&gt;Version&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;&lt;b&gt;Last Update&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;&lt;b&gt;Result&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;AntiVir&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;7.9.1.3&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;2009.08.20&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;HTML/Malicious.PDF.Gen&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;BitDefender&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;7.2&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;2009.08.20&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;Exploit.PDF-JS.Gen&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;GData&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;19&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;2009.08.20&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;Exploit.PDF-JS.Gen&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;table border="0" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;McAfee-GW-Edition&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;6.8.5&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;2009.08.20&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;Script.Malicious.PDF.Gen&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;         &lt;p&gt;Microsoft&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;1.4903&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;2009.08.20&lt;/p&gt;       &lt;/td&gt;        &lt;td&gt;         &lt;p&gt;Exploit:Win32/Pdfjsc.gen!A&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Antigen-Command - 5.1.0.5 2009-08-20 09:40 PDF/CollabExpl.C!Camelot&lt;/p&gt;  &lt;p&gt;These seem to be false detects as this is the result of files built at a customer site. &lt;/p&gt;  &lt;p&gt;We are currently investigating the cause as this effects our Microsoft engine and Command&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3275325" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author></entry><entry><title>Issue of the week 8/17/2009</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/08/17/issue-of-the-week-8-17-2009.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/08/17/issue-of-the-week-8-17-2009.aspx</id><published>2009-08-17T16:33:00Z</published><updated>2009-08-17T16:33:00Z</updated><content type="html">&lt;p&gt;This issue deals with Antigen 9.x and clusters with Multiple Active Nodes.&lt;/p&gt;  &lt;p&gt;&lt;font color="#ffff00"&gt;You do not need the cluster resource on a single Active cluster&lt;/font&gt;.&lt;/p&gt;  &lt;p&gt;There is a fix in Antigen 9.1 RU5 and Antigen 9 Service Pack 2 that addresses an issue when moving Active nodes to a passive node. &lt;/p&gt;  &lt;p&gt;Below is an example of what you see when you have the issue resolved in RU5 or SP2&lt;/p&gt;  &lt;p&gt;When the first Node is moved over to the passive node we set a registry key that identifies the database path for the engines and databases. In this example Server1 has its databases on G:\AntigenCluster&lt;/p&gt;  &lt;p&gt;The store is then moved back to the original node and then server2 is moved to the passive. &lt;/p&gt;  &lt;p&gt;Sever2’s database path is in F:\AntigenCluster&lt;/p&gt;  &lt;p&gt;Most of the time Server2 will move the database path to the Passive cluster and everything works. Sometimes this process fails. You end up with a wrong database path and in this example server2 is on the passive with the database path still set to G:\AntigenCluster&lt;/p&gt;  &lt;p&gt;This will cause us to initialize with no scan engines and no settings for our scanjobs. &lt;/p&gt;  &lt;p&gt;The symptoms of this issue is as follows&lt;/p&gt;  &lt;p&gt;End users cannot open or send mail. &lt;/p&gt;  &lt;p&gt;Messages queue in Local delivery&lt;/p&gt;  &lt;p&gt;&lt;font color="#ffff00"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#ffff00"&gt;The fix requires you to do one of the following to to create the cluster resource&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;1. Full uninstall (Pause passive nodes, uninstall from all active nodes and then passive nodes) and run a fresh install.&lt;/p&gt;  &lt;p&gt;2. Upgrade to SP2 and do the following. Run Antutil.exe /disable and then Antutil.exe /enable on each active node (Pause passive nodes, bring exchange resources offline, leave CMS up.)&lt;/p&gt;  &lt;p&gt;Both methods Require downtime &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3274181" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Cluster" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Cluster/default.aspx" /><category term="Antigen" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Antigen/default.aspx" /><category term="Install" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Install/default.aspx" /><category term="Upgrade" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Upgrade/default.aspx" /></entry><entry><title>Issue of the week 8/7/2009</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/08/07/issue-of-the-week-8-7-2009.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/08/07/issue-of-the-week-8-7-2009.aspx</id><published>2009-08-07T21:19:00Z</published><updated>2009-08-07T21:19:00Z</updated><content type="html">&lt;P&gt;I have been looking for a good issue to post this week.&lt;/P&gt;
&lt;P&gt;So here is a post for all those 8.0 customers looking to upgrade to 9 by the time 8.x for Exchange reaches its end of life at the end of the year.&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#ffff00&gt;Mail Queues after an upgrade from 8.0 to 9.x&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Symptoms:&lt;/P&gt;
&lt;P&gt;After upgrading to 9.x from 8.x Mail on SMTP and Real-time does not flow.&lt;/P&gt;
&lt;P&gt;Cause:&lt;/P&gt;
&lt;P&gt;8.x did not have the Microsoft scan engine &lt;/P&gt;
&lt;P&gt;9.x only comes with the Microsoft scan engine.&lt;/P&gt;
&lt;P&gt;On an upgrade the Microsoft Scan engine is not selected. If you incorrectly entered your proxy server address or have an issue pulling down updates you are left with no engines and mail flow is stopped pending updates.&lt;/P&gt;
&lt;P&gt;Quick Solution:&lt;/P&gt;
&lt;P&gt;Open the Forefront Console and select the Microsoft Scan engine for all scan jobs.&lt;/P&gt;
&lt;P&gt;After that you should have mail flow again and you can fix your updating issue.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3271596" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Antigen" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Antigen/default.aspx" /></entry><entry><title>Issue Of the week 7/27/09 – Antigen Upgrade results in Expired evaluation.</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/07/27/issue-of-the-week-7-27-09-antigen-upgrade-results-in-expired-evaluation.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/07/27/issue-of-the-week-7-27-09-antigen-upgrade-results-in-expired-evaluation.aspx</id><published>2009-07-27T21:00:12Z</published><updated>2009-07-27T21:00:12Z</updated><content type="html">&lt;p&gt;We have seen a few cases of licensed builds coming online as expired evaluations as people upgrade to Antigen Service Pack 2 for exchange.&lt;/p&gt;  &lt;p&gt;I believe this is somehow triggered on Active Passive server installs where the Active node fail’s over to the Passive during our install. This leaves the AntigenCluster folder on the shared drive missing the licence.cfg file.&lt;/p&gt;  &lt;p&gt;I have yet to reproduce this but the lack of a license file and other files that are created during the install on the shared drive is leading me to that conclusion.&lt;/p&gt;  &lt;p&gt;I would suggest always pausing the passive node while installing on the active node to avoid any issues with the server failing over during the install. This should probably be added to the online cluster install steps.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3268456" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Antigen Upgrade" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Antigen+Upgrade/default.aspx" /></entry><entry><title>Issue of the week 7-17-09</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/07/17/issue-of-the-week-7-17-09.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/07/17/issue-of-the-week-7-17-09.aspx</id><published>2009-07-17T19:05:00Z</published><updated>2009-07-17T19:05:00Z</updated><content type="html">&lt;P&gt;We are currently seeing a failure to allocate memory error &lt;/P&gt;
&lt;P&gt;Error in the programlog:&lt;/P&gt;
&lt;P&gt;Failed to allocate memory for local stream 0x8007000e&lt;/P&gt;
&lt;P&gt;Mail flow issues occur at the same time as these memory allocation errors. The mail flow issue is a result of the memory issue and not a cause.&lt;/P&gt;
&lt;P&gt;we are looking to collect more data to find the root cause of this issue.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3265738" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Engine issues" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Engine+issues/default.aspx" /></entry><entry><title>Cloudmark engine added to SP2 for 9.0 Antigen</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msfss_stuff/archive/2009/07/02/cloudmark-engine-added-to-sp2-for-9-0-antigen.aspx" /><id>http://blogs.technet.com/msfss_stuff/archive/2009/07/02/cloudmark-engine-added-to-sp2-for-9-0-antigen.aspx</id><published>2009-07-02T15:38:48Z</published><updated>2009-07-02T15:38:48Z</updated><content type="html">&lt;p&gt;&lt;a title="http://support.microsoft.com/kb/971063" href="http://support.microsoft.com/kb/971063"&gt;http://support.microsoft.com/kb/971063&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This should be a much better engine choice. In the coming weeks I will be sharing any experiences we have with this engine. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;One suggestion:&lt;/p&gt;  &lt;p&gt;If you switch over to the Cloudmark engine you need to disable the Starengine service and disable updates for Spamcure. (I would then delete the Spamcure engine folder)&lt;/p&gt;  &lt;p&gt;Spamcure will spool up its service on an update. Since this is not being used, you end up wasting 350-500MB of physical ram. &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260754" width="1" height="1"&gt;</content><author><name>Van.f@microsoft.com</name><uri>http://blogs.technet.com/members/Van.f%40microsoft.com.aspx</uri></author><category term="Anti-Spam" scheme="http://blogs.technet.com/msfss_stuff/archive/tags/Anti-Spam/default.aspx" /></entry></feed>