Antigen ForumTopics Include: Antigen for Exchange, Antigen for SMTP, Antigen for SharePoint, and Antigen for IM.© 2009 Microsoft Corporation. All rights reserved.Thu, 26 Nov 2009 02:41:49 Zee61d1aa-f276-45c3-aad5-2a8898fd00d3http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/24b400b1-0e96-4c2f-a509-5d9431968ed8http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/24b400b1-0e96-4c2f-a509-5d9431968ed8Tonacohttp://social.technet.microsoft.com/Profile/en-US/?user=TonacoCloudmark scanTry to update cloudmark with no luck, got this message:<br/> PS: Verify the post &quot;http://social.technet.microsoft.com/Forums/en-US/forefrontexchange/thread/b35414f4-e80b-42ff-92d6-b996af6913a0/&quot; and applied all recomendation, but I still cant update.<br/> <br/> Event log from 2 diffent <br/> <br/> Event Type:    Information<br/> Event Source:    GetEngineFiles<br/> Event Category:    General <br/> Event ID:    2012<br/> Date:        20-11-2009<br/> Time:        15:00:03<br/> User:        N/A<br/> Computer:    <strong>SWLEXM01</strong> <br/> Description:<br/> There are currently no new scan engine files available for the Cloudmark scan engine at http://forefrontdl.microsoft.com/server/scanengineupdate/x86/Cloudmark.<br/> <br/> For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.<br/> <br/> Event Type:    Error<br/> Event Source:    GetEngineFiles<br/> Event Category:    Engine Error <br/> Event ID:    6014<br/> Date:        20-11-2009<br/> Time:        16:08:23<br/> User:        N/A<br/> Computer:    <strong>SWLEXB02</strong> <br/> Description:<br/> Unable to load manifest from: http://forefrontdl.microsoft.com/server/scanengineupdate/x86/Cloudmark/Package/manifest.cab : (0x00002ee2) The operation timed out.  WinHttpClient failed while sending a request. [Timeout=0] Secure[0].<br/> <br/> For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.<br/> <br/>Fri, 20 Nov 2009 17:23:14 Z2009-11-25T09:52:27Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/d620221c-b0cf-4d98-9814-9095a9a71e58http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/d620221c-b0cf-4d98-9814-9095a9a71e58tomuzarhttp://social.technet.microsoft.com/Profile/en-US/?user=tomuzarERROR: Unable to load the Cloudmark scannerSun Nov 22 20:16:01 2009 ( 4400- 8008), &quot;ERROR: Could not create Cloudmark object, hr = 0x80070003.&quot;Sun, 22 Nov 2009 19:30:39 Z2009-11-25T07:30:43Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/8110d355-e6d5-4aa2-add0-8dbafb4a08e0http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/8110d355-e6d5-4aa2-add0-8dbafb4a08e0roscop2009http://social.technet.microsoft.com/Profile/en-US/?user=roscop2009upgrade to Antigen 9 SP2 Hi <br/><br/>We have several servers running Antigen for SMTP 9.0 and several running Antigen for Exchange 9.0. I know that some of the AV engines are bing retired on 01/12/09<br/><br/>As per this notification below.<br/><br/>My question is do we need to upgrade to SP2 to avail of the new engines such as Kaspersky and Authentium? Also I have only found this information out today. If we cannot upgrade before the 01/12/09 will the old engines still work with the last definitions the downloaded until we are ready to upgrade?<br/><br/>Regards.<br/><br/>Roscop2009<br/><br/> <p class=MsoNormal style="margin:0cm 0cm 6pt"><strong><span style="text-decoration:underline"><span lang=EN-US><span style="font-size:small"><span style="font-family:Calibri">Antimalware Protection</span></span></span></span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 6pt"><span lang=EN-US><span style="font-size:small"><span style="font-family:Calibri">The AhnLab, CA and Sophos engines will be retired on Dec. 1, 2009.  As of this date, customers will <strong style="">not</strong> receive any updates for these retired engines. Any customers running the AhnLab, CA or Sophos engines must <strong>DISABLE</strong> these engines before Dec. 1, 2009 and select from the new set of five engines – Authentium, Kaspersky, Microsoft, Norman and VirusBuster.<span style="">  </span></span></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 6pt"><span lang=EN-US><span style="font-size:small"><span style="font-family:Calibri">At this time we also encourage you to upgrade to the latest Antigen 9.0 Service Pack 2 releases, which include a rollup of the latest software fixes.<span style="">  </span>These service packs can be accessed on the MVLS and VLSC sites.<span style="">  </span></span></span></span></p>Wed, 18 Nov 2009 13:54:02 Z2009-11-26T02:41:49Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/23116d0c-5d00-4b9d-99d0-b7eadf6a50b8http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/23116d0c-5d00-4b9d-99d0-b7eadf6a50b8sime3000http://social.technet.microsoft.com/Profile/en-US/?user=sime3000SP2 for Antigen 9.0 download ?We're currently using Antigen for Exchange version 9 with SP1 (9.1) on several clustered and standalone Exchange 2003 servers.  We would like to upgrade to SP2 asap to address the issues with some of the engines being deprecated.<br/><br/>Where can we find the download for the SP2 update or the complete Antigen for Exchange version 9 with SP2 (9.2) package ? <br/><br/> We're not particularly interested in the &quot;Microsoft Antigen for Exchange with Antigen Spam Manager with SP2 Trial Software&quot; download which seems to be the only one available. ( <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=866b63bf-6207-4197-9c5d-511b7212e40c&amp;DisplayLang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=866b63bf-6207-4197-9c5d-511b7212e40c&amp;DisplayLang=en</a> )<br/><br/>Thanks<br/><br/><br/>SamThu, 16 Jul 2009 21:56:51 Z2009-11-17T14:31:17Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cbcac4e9-8b4e-4f1b-b76e-384e573b4ea3http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cbcac4e9-8b4e-4f1b-b76e-384e573b4ea3Mimmhttp://social.technet.microsoft.com/Profile/en-US/?user=MimmHotfix Rollup 1 for Antigen 9.0 Service Pack 2 Hi,<br/> my configuration:<br/> <ul> <li>Windows Server 2003 R2 SP1</li> <li>ISA Server 2006 SP0</li> <li>Antigenfor SMTP 9.0 Service Pack 2</li> </ul> At the weekend I installed the Hotfix Rollup 1 for Antigen 9.0 Service Pack 2, because the features and bugfixes sounds very interesting. To complete the installation, I restarted the whole system. But now the problems began :-)<br/> <br/> If I start the server now , I get an error message like &quot;One or more services couldn't start. Please check the event log&quot;, that's why several services (5 I think) aren't active.<br/> The service Microsoft ISA Server-Control don't start automatically after reboot, so all dependent services don't start too. But if I start the services manuelly, everything is fine.<br/> <br/> So If the system crashs or there is a electrical power outage, I have to go to the server room and reset everything by hand - not very well ;-)<br/> Does anybody have problems like this? What can I do? Would the newest service pack for Windows or ISA help?<br/> <br/> Thanks,<br/> Mimm<br/>Mon, 16 Nov 2009 18:48:34 Z2009-11-24T08:42:23Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2a107e6c-96d0-4a75-9a2a-fcda4abe07fbhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2a107e6c-96d0-4a75-9a2a-fcda4abe07fbBMcMullanhttp://social.technet.microsoft.com/Profile/en-US/?user=BMcMullanBlock Messages with Malformed From Addresses?<p>Running Antigen for Exchange SP2 on Cloudmark.  While Cloudmark was doing quite well for the past few weeks, I've noticed a significant uptick in the number of messages that have made it through in the past 5 days.  Many of those messages appear to have malformed &quot;From&quot; addresses, such as <a href="mailto:IAMSPAM@localhost">IAMSPAM@localhost</a> or <a href="mailto:DOEJOE@A9u75509808">DOEJOE@A9u75509808</a>.  These addresses are malformed as they don't include the .com, .net, etc. on them. <br/><br/>Is there any filter setting I can use to prevent these messages from making it through?<br/><br/>I appreciate any help!<br/><br/>Thank you</p>Tue, 10 Nov 2009 12:54:10 Z2009-11-16T03:15:22Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3fb42a6a-fb98-4d4e-a9a0-49770ea87b9fhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3fb42a6a-fb98-4d4e-a9a0-49770ea87b9fChristian Groebner [MVP]http://social.technet.microsoft.com/Profile/en-US/?user=Christian%20Groebner%20%5bMVP%5dRollup 1 for Antigen 9 SP2 has been releasedFor more information see:<br/><br/><a href="http://blogs.technet.com/fss/archive/2009/11/09/rollup-1-for-antigen-9-0-with-service-pack-2-has-been-released.aspx">http://blogs.technet.com/fss/archive/2009/11/09/rollup-1-for-antigen-9-0-with-service-pack-2-has-been-released.aspx</a><br/><br/>Greetings<br/><br/>Christian<hr class="sig">Christian Groebner MVP ForefrontWed, 11 Nov 2009 07:34:01 Z2009-11-11T07:34:01Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/33aba9c0-233c-427b-ac2d-a0c8d09fc5f2http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/33aba9c0-233c-427b-ac2d-a0c8d09fc5f2Tonacohttp://social.technet.microsoft.com/Profile/en-US/?user=TonacoUpgrade to Antigen 9.0 SP2Hi<br/> I going to upgrade Antigen 9.0 SP1 to Antigen 9.0 SP2, and I have to following problem:<br/> <br/> - I have a 4 node exchange 2003 sp2 cluster (3 active\1 passive)<br/> - Antigen is install in the c:\ driver<br/> - To use a share disk resource for antigen I need to uninstall Antigen 9.0 SP1 and install Antigen 9.0 SP2 with the cluster live starting from active node.<br/> - We have lots of Filtering options configure (ex. about 100 subject line blocked, some file extension block as well) <br/> <br/> My question how to I keep this configuration, I can´t use FCSSM because this options is only for Forefront for Exchange 10 (exchange 2007)?<br/> <br/>Tue, 29 Sep 2009 10:03:16 Z2009-11-10T01:40:28Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/ec2ddb78-df0a-49c8-be40-738d0c09ec69http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/ec2ddb78-df0a-49c8-be40-738d0c09ec69ryanbjhttp://social.technet.microsoft.com/Profile/en-US/?user=ryanbjCloudmark Update Path?For the Cloudmark Authority Engine, what should be the Network Update Path?  Any secondary ones?<br/>Mon, 14 Sep 2009 13:08:50 Z2009-11-25T07:00:22Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/5580583d-b1e7-40a3-9ae1-cea4f6123b64http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/5580583d-b1e7-40a3-9ae1-cea4f6123b64TedF1http://social.technet.microsoft.com/Profile/en-US/?user=TedF1Event ID 5035Antigen 9, SP1 started flooding our applog with 5035 events, &quot;Could not create mapper object&quot;, for both realtime and internet scanner.  I've removed and re-installed the application, but the errors returned.  I don't find much info on this anywhere.  Help please.<br/> <br/> TedSat, 07 Nov 2009 15:54:28 Z2009-11-12T08:34:02Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/9ae4c1f1-4d48-457e-a010-29004c65056ehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/9ae4c1f1-4d48-457e-a010-29004c65056eluckysavagehttp://social.technet.microsoft.com/Profile/en-US/?user=luckysavageVery high memory useage - Antigen 9.2.1097 SP2 <p>FSEContentScanner.exe is using a constant 191,000 K of memory.  Combined with the other process like AntigenInternet.exe that are low now, but were each running 140,000 K a piece before, I've got a situation where I'm seeing system slowdown (4GB memory) because of this software and all I'm running is Exchange 2003 with 25 users.</p>Mon, 27 Jul 2009 04:50:10 Z2009-11-04T23:37:23Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/329c81b1-0684-4749-b92b-edae2f8180eahttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/329c81b1-0684-4749-b92b-edae2f8180earewsterukhttp://social.technet.microsoft.com/Profile/en-US/?user=rewsterukFile Filtering Problem - Body of Message<div>I am testing Antigen for SMTP gateways.</div> <div><br/></div> <div>I am trying to configure the server to block ALL attachments, except for certain types, here is what I have configured (which based on example from Chapter 8 of the Antigen guide):</div> <div><br/></div> <div>&lt;in&gt;*</div> <div>File Types: only these checked BMPFILE, DOCFILE, GIFFILE, JPEG, OPENXMLFILE, PNGFILE, RTFFILE, TEXT, TIFFILE, TNEFFILE, UNICODE, WINEXCEL1, WINWORD1&amp;2, WINWRITE</div> <div>Action: Skip: detect only</div> <div>General Send Notifications and Quarantine unchecked</div> <div><br/></div> <div>&lt;in&gt;*</div> <div>File Types: All Types selected</div> <div>Action: Delete: remove contents</div> <div>General: Quarantine Files</div> <div><br/></div> <div>I have sent through an email with an attachment A90ExQuickStart.pdf from a Hotmail account, but this is breaks down to 3 incidents:</div> <div><br/></div> <div>1 removed file &quot;A90ExQuickStart.pdf&quot; FILE FILTER= &lt;in&gt;*</div> <div>2 removed file &quot;body of message&quot; FILE FILTER= &lt;in&gt;*</div> <div><br/></div> <div>In the logs the Body of Message is detected as fileType of 33 (FOBTYPE_TEXT_PLAIN)</div> <div><br/></div> <div>I am used to GFI Mail essentials where the body of message would be delivered with a text message saying the attachment has been removed, if I add a rule &lt;in&gt;Body Of Message  , Action Skip: detect only , General Send Notifications and Quarantine unchecked, then this acts the same way as GFI, is this a correct way to get this to work? Should the file scanner be checking the body of message anyway?</div> <div><br/></div> <div>Paul</div> <div><br/></div> <div>Here are the diagnostic logs:</div> <div><br/></div> <div><br/></div> <div>Tue Oct 27 15:50:12 2009 ( 2832- 2844), &quot;DIAGNOSTIC: Begin scanning SMTP message&quot;</div> <div><br/></div> <div>Tue Oct 27 15:50:12 2009 ( 2832- 2844), &quot;DIAGNOSTIC: Begin scanning SMTP Inbound message named: Tester 15:50&quot;</div> <div><br/></div> <div>Tue Oct 27 15:50:27 2009 ( 2832- 2844), &quot;INFORMATION: AVE multi engine manager enabled&quot;</div> <div><br/></div> <div>Tue Oct 27 15:50:27 2009 ( 2832- 2844), &quot;INFORMATION: Loading MultiMapper (10908, F000000)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:33 2009 ( 2832- 2844), &quot;DIAGNOSTIC: Check allowed senders is scanning the sender address &quot;paulrewston@hotmail.com&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:33 2009 ( 2832- 2844), &quot;DIAGNOSTIC: Check allowed senders has finished scanning the sender address &quot;paulrewston@hotmail.com&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000) ulBypassTypes(0x00000000)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:33 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner is performing the AseScan test on the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner has finished the AseScan test with hResult(0x00000000)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner detected a FileType of 33 (FOBTYPE_TEXT_PLAIN)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x015C0101)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:34 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner is attempting to delete the file named &quot;Body of Message&quot;&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2836), &quot;INFORMATION: Internet scan found virus:</div> <div><br/></div> <div>   Folder: SMTP Messages\Inbound</div> <div><br/></div> <div>   Message: Tester 15:50</div> <div><br/></div> <div>   File: Body of Message</div> <div><br/></div> <div>   Incident: FILE FILTER=  &lt;in&gt;*</div> <div><br/></div> <div>   State: Removed&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner detected a FileType of 33 (FOBTYPE_TEXT_PLAIN)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2316- 2360), &quot;Changed Time: 2009/10/27 15:51:35&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x015C0101)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:35 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner is attempting to delete the file named &quot;Body of Message&quot;&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2836), &quot;INFORMATION: Internet scan found virus:</div> <div><br/></div> <div>   Folder: SMTP Messages\Inbound</div> <div><br/></div> <div>   Message: Tester 15:50</div> <div><br/></div> <div>   File: Body of Message</div> <div><br/></div> <div>   Incident: FILE FILTER=  &lt;in&gt;*</div> <div><br/></div> <div>   State: Removed&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2316- 2360), &quot;Changed Time: 2009/10/27 15:51:36&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner detected a FileType of 47 (FOBTYPE_PDFFILE)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner is scanning the file named &quot;A90ExQuickStart.pdf&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS Virus scanner has finished scanning the file named &quot;A90ExQuickStart.pdf&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner is scanning the file named &quot;A90ExQuickStart.pdf&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS File Filter scanner has finished scanning the file named &quot;A90ExQuickStart.pdf&quot; from the message named &quot;Tester 15:50&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x015C0101)&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2844), &quot;DIAGNOSTIC: The IMS scanner is attempting to delete the file named &quot;A90ExQuickStart.pdf&quot;&quot;</div> <div><br/></div> <div>Tue Oct 27 15:51:36 2009 ( 2832- 2836), &quot;INFORMATION: Internet scan found virus:</div> <div><br/></div> <div>   Folder: SMTP Messages\Inbound</div> <div><br/></div> <div>   Message: Tester 15:50</div> <div><br/></div> <div>   File: A90ExQuickStart.pdf</div> <div><br/></div> <div>   Incident: FILE FILTER=  &lt;in&gt;*</div> <div><br/></div> <div>   State: Removed&quot;</div> <div><br/></div> <div><br/></div>Wed, 28 Oct 2009 12:52:04 Z2009-11-04T16:50:01Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/bb20754d-ad51-4ff0-a241-e081b6658dc3http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/bb20754d-ad51-4ff0-a241-e081b6658dc3Brita Jenquin - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Brita%20Jenquin%20-%20MSFTAction required by Dec. 1, 2009: Keep protections current<span style="font-size:small;font-family:Calibri"> <p class=MsoNormal style="margin:0in 0in 6pt"><a href="http://blogs.technet.com/forefront/archive/2009/07/01/the-multi-engine-advantage-and-updates.aspx"><span style="color:#0000ff">As announced on July 1, 2009</span></a>, Microsoft is revising its engine mix on December 1, 2009, for the Forefront and Antigen products.  Below is a quick overview of the actions Antigen 9.0 and Antigen 8.0 users need to take in order to keep their protections current: <br/></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="text-decoration:underline"><span style="font-size:12pt;color:black"><strong>Antimalware Protection</strong></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="font-size:12pt;color:black">The AhnLab, CA, and Sophos engines will be retired on Dec. 1, 2009.  After December 1<sup>st</sup>, customers will not receive any updates for these retired engines. In order to make sure your Antigen and Forefront products continue to scan efficiently and effectively for malware, any customers running the AhnLab, CA, or Sophos engines must DISABLE these engines before Dec. 1, 2009 and select from the new set of five engines – Authentium, Kaspersky, Microsoft, Norman, and VirusBuster.</span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black">SPECIAL NOTE:<span style="">  </span>Antigen for SharePoint 8.0 and Antigen for Instant Messaging 8.0 customers – In order to gain access to the new engine set and provide optimal protection for your messaging and collaboration environments, please download the Service Pack 1 releases of these products on the MVLS or VLSC site prior to Dec. 1, 2009.  The updates for the new engine set will use a new update infrastructure as of Dec. 31, 2009 – the Service Pack 1 releases will allow you to continue to receive updates correctly from their new location.<span style="">  </span></span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black">For more information about Service Pack 1 for Antigen for SharePoint and Antigen for IM, see the following KB article:</span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"><a href="http://support.microsoft.com/kb/975850/"><span style="font-family:'Calibri','sans-serif'"><span style="color:#0000ff">http://support.microsoft.com/kb/975850/</span></span></a></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal;tab-stops:177.75pt"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"><span style="">                                              </span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"> </span></p> <p class=MsoNormalCxSpMiddle style="margin:0in 0in 6pt 41.2pt;text-indent:-5.2pt"><span style="font-size:12pt;color:black;line-height:115%"><span style="font-family:Times New Roman">SPECIAL NOTE:<span style="">  </span>Antigen for Exchange 8.0 and Antigen for SMTP Gateways 8.0 customers –These products will end of life on Dec. 31, 2009.<span style="">  </span>Customers must upgrade to Antigen 9.0 SP2 for Exchange before this date, as the product will no longer continue to receive anti-malware updates starting Jan. 1, 2010.<span style="">   </span>With the retirement of the CA, Sophos, and AhnLab engines on Dec. 1, customers running Antigen for Exchange 8.0 or Antigen SMTP Gateways 8.0 will only be protected by the Norman engine.<span style="">  </span>For customers who need to continue using this product between Dec. 1, 2009 and the end-of-life date of Dec. 31, 2009, please contact </span><a href="mailto: fssadm@microsoft.com"><span style="color:#0000ff;font-family:Times New Roman">Forefront Contract Administration</span></a><span style="font-family:Times New Roman"> for access to the revised engine set.<span style="">  </span></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black">For more information on upgrading your Antigen for Exchange 8.0 or Antigen for SMTP Gateways 8.0 to Antigen 9.0, see the following KB article: </span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"><a href="http://support.microsoft.com/kb/932396/"><span style="font-family:'Calibri','sans-serif'"><span style="color:#0000ff">http://support.microsoft.com/kb/932396/</span></span></a></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"><strong> </strong></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="text-decoration:underline"><span style="font-size:12pt;color:black"><strong>Antispam Protection</strong></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="font-size:12pt;color:black">One of the most important changes in our engine revision strategy is moving to the Cloudmark antispam engine*, which provides 99%+ detection rate and less than 1 in 250,000 false positives (West Coast Labs).</span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="font-size:12pt;color:black">The Mail-Filters SpamCure antispam engine will be retired on Dec. 1, 2009. Customers using Antigen products for antispam protection must upgrade to the latest service pack releases listed below BEFORE DEC. 1, 2009 to maintain their antispam defenses.  This is the only way to gain access to the new Cloudmark engine.  The service packs can be accessed on the Microsoft MVLS and VLSC sites:</span><span style="font-size:12pt;color:black;font-family:'Times New Roman','serif'"></span></p> <p class=MsoNormal style="margin:0in 0in 0pt 41.2pt;text-indent:-0.25in;line-height:normal"><span style="font-size:12pt;color:black">-</span><span style="font-size:7pt;color:black;font-family:'Times New Roman','serif'">          </span><span style="font-size:12pt;color:black">Antigen for Exchange Server with Antigen Spam Manager 9.0 with SP2</span></p> <p class=MsoNormal style="margin:0in 0in 5.2pt 41.2pt;text-indent:-0.25in;line-height:normal"><span style="font-size:12pt;color:black">-</span><span style="font-size:7pt;color:black;font-family:'Times New Roman','serif'">          </span><span style="font-size:12pt;color:black">Antigen for SMTP Gateways with Antigen Spam Manager 9.0 with SP2</span></p> <font face=Calibri size=3> <p class=MsoNormal style="margin:0in 0in 6pt"><br/><br/>For more information on the engine revision strategy, see the</p> </font></span> <p class=MsoNormal style="margin:0in 0in 6pt"><a href="http://technet.microsoft.com/en-us/forefront/serversecurity/dd940095.aspx"><span style="font-size:small;font-family:Calibri">Antimalware Engine Notifications and Developments</span></a><span style="font-size:small;font-family:Calibri"> Web page or contact </span><a href="mailto: fssadm@microsoft.com"><span style="font-size:small;color:#0000ff;font-family:Calibri">Forefront Contract Administration</span></a><span style="font-size:small"><span style="font-family:Calibri">. Again, we strongly urge that you update your engine configurations and move to the newest service packs before December 1, 2009, to get the full protection benefits of the Forefront server products.  </span></span></p>Tue, 03 Nov 2009 03:46:03 Z2009-11-03T03:46:04Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cd71f9fc-4f63-451e-9b3b-d3368617f7f9http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cd71f9fc-4f63-451e-9b3b-d3368617f7f9ryanbjhttp://social.technet.microsoft.com/Profile/en-US/?user=ryanbjGetting more spam since switch from SpamCure to CloudmarkDon't know if just coincidence, but ever since I switched from SpamCure to CloudMark spam engine in Antigen, my personal mailbox is getting much much more spam (not being caught by Antigen on the server, being delivered to Junk folder in Outlook 2007).  I haven't heard many complaints from users, and Cloudmark is catching alot of spam, and I'm also using sbl.xbl.spamhaus.org for my RBL.  But just wondering if anyone else experienced that, or if there is anything I should look into to make sure Cloudmark is working as best as possible?  I do forward all spam not caught to forefront-spam@submit.cloudmark.com.<br/> <br/> Thanks.Wed, 21 Oct 2009 13:49:43 Z2009-11-05T00:28:30Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/0de34c28-b3b2-4f53-8b99-10859b6fe946http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/0de34c28-b3b2-4f53-8b99-10859b6fe946Nicholas Marriotthttp://social.technet.microsoft.com/Profile/en-US/?user=Nicholas%20MarriottUninstalling AntigenHi<br/> <br/> We're currently on Antigen for Exchange 9.1 but we're going to drop it, anyone aware of any gotchas when or after uninstalling it?<br/> <br/> We've had issues with it being rather complicated and tied into the Exchange services in funny ways before, so I'd like to get as much info as possible before we go ahead.<br/> <br/> Thanks<br/> <br/> NicholasFri, 30 Oct 2009 10:01:27 Z2009-11-09T02:22:04Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/23c264da-5ae5-4efc-a91f-3ac5c5090ffehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/23c264da-5ae5-4efc-a91f-3ac5c5090ffeTonacohttp://social.technet.microsoft.com/Profile/en-US/?user=TonacoAction Required by Dec. 1, 2009 &lt;!-- /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-parent:&quot;&quot;; margin:0cm; margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:12.0pt; font-family:&quot;Times New Roman&quot;; mso-fareast-font-family:&quot;Times New Roman&quot;;} a:link, span.MsoHyperlink {color:blue; text-decoration:underline; text-underline:single;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline; text-underline:single;} @page Section1 {size:595.3pt 841.9pt; margin:70.85pt 3.0cm 70.85pt 3.0cm; mso-header-margin:35.4pt; mso-footer-margin:35.4pt; mso-paper-source:0;} div.Section1 {page:Section1;} --&gt; <p class=MsoNormal><span lang=EN-GB>Hi, <br/> At 1/12/2009 there is a lot of changes happening, AhnLab, CA, or Sophos engines must disable, SpamCure will stop receiving new definition. I a little bite confused, Andy Day said in this post (<a href="Antigen/thread/ec2ddb78-df0a-49c8-be40-738d0c09ec69/#2e4b2618-5602-4781-801b-cb12729c490e">http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/ec2ddb78-df0a-49c8-be40-738d0c09ec69/#2e4b2618-5602-4781-801b-cb12729c490e</a> ) that “<em>Cloudmark signature updates occur directly from the Cloudmark website only</em> ” and “<em>FSSMC, which now supports the redistribution of Cloudmark engine updates only</em> ”, my doubt is what is the better way to configure may Antigen 9 SP2 and FSSMC to get the engine/signature/definition and keep my Exchange Server from contacting the Net.</span></p> <p class=MsoNormal> </p> <p class=MsoNormal>It´s there a best pratice doc?<span lang=EN-GB></span></p>Wed, 28 Oct 2009 16:40:42 Z2009-11-04T08:13:59Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/88a7946f-c80a-462a-bf30-87671664969fhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/88a7946f-c80a-462a-bf30-87671664969fsleb123http://social.technet.microsoft.com/Profile/en-US/?user=sleb123see all emails going through antigen<div>Hi,<br/><br/>I have antigen for smtp installed on a windows 2003 server which sends email to our exchange server when done. The antigen server is a dedicated server for antigen. I am suspecting a problem with antigen but not sure. I was wondering if it's possible to see all emails pass, not just the ones that are in the &quot;incident&quot; or &quot;quarantine&quot; report in the antigen administrator.</div> <div>Basically, one of my users is having problems receiving e-mails (not all of them). I don't see them in exchange so it can only be blocked by the antigen server. Looked in incidents and quarantine and nothing there that I'm looking for. Is there a log file or a monitor somewhere that I can see all emails that passed through antigen?<br/></div> <div>Thanks</div>Mon, 26 Oct 2009 20:44:51 Z2009-11-03T01:34:23Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/f57ab840-3445-4274-8531-fdfe1b8865c0http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/f57ab840-3445-4274-8531-fdfe1b8865c0Jeff Belthttp://social.technet.microsoft.com/Profile/en-US/?user=Jeff%20BeltAntigen Cloudmark Signature updatesHi,<br/><br/>Does anyone know how often the signatures are updated for Cloudmark integrated with Antigen 9 SP2, i installed it about 10 days ago, it picked up the first set of sig files and engine but hasn't had anything else since then.  Without regular updates i wouldn't think it would be too effective.<br/><br/>It has been checking for updates as per its schedule but not finding any.<br/><br/>Thanks<br/><br/>Jeff<br/>Mon, 24 Aug 2009 11:02:47 Z2009-10-26T15:33:46Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c4b17ac4-3aa6-436d-86b8-5501efc7d46ehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c4b17ac4-3aa6-436d-86b8-5501efc7d46eNetgh0sthttp://social.technet.microsoft.com/Profile/en-US/?user=Netgh0stJust Installed AntiGen 9.0 SP2 for SMTP Gateaways.. A lot of new Engines.. Which one to choose from?I was satisfied with SpamCure, but with SP2, i now have 10 engines, should i enable them all? Or i should just use spamcure?  Is there a doc somewhere explaining what all those engines are doing?Thu, 22 Oct 2009 14:33:36 Z2009-10-29T06:57:11Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3155bf92-ec1a-49ee-9daa-963046fe4b99http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3155bf92-ec1a-49ee-9daa-963046fe4b99Tonacohttp://social.technet.microsoft.com/Profile/en-US/?user=Tonaco"Antigenrealtime" process high CPU ocupationHi<br/> <br/> I Have Exchange 2003 (Cluster 4 node) with Antigen 9 SP 2, now in one of the node after boot, the &quot;Antigenrealtime&quot; process start to exhaust the CPU.<br/> <br/> I can´t see any errors in the Event viewer? Where more cam I look, if I Stop the the Store (Realtime Scan Job) in Antigen 9 Scan Job tab, the process became flat again, then a restart one Store (Realtime Scan Job) at time,waiting for cpu to became stable between with restart, the Server became it´s old self.<br/> <br/> <br/>  Tue, 20 Oct 2009 13:03:57 Z2009-11-06T11:33:22Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/fe734a33-45a9-44a8-863c-e4718207ab9dhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/fe734a33-45a9-44a8-863c-e4718207ab9dChristoph.Mhttp://social.technet.microsoft.com/Profile/en-US/?user=Christoph.MError updating AhnLab V3 Engine (expired manifest)<p>Hi guys,<br /><br />I'm getting an expired manifest error when trying to update the AhnLab V3 Engine through Antigen.<br /><br />The engine last updated 10/10/09 at 13:53:37 and when I try to force an update via <a href="http://antigendl.microsoft.com/antigen">http://antigendl.microsoft.com/antigen</a>&nbsp;it says:<br /><br />Event Type:&nbsp;Information<br />Event Source:&nbsp;GetEngineFiles<br />Event Category:&nbsp;General <br />Event ID:&nbsp;2012<br />Date:&nbsp;&nbsp;16/10/2009<br />Time:&nbsp;&nbsp;08:50:30<br />User:&nbsp;&nbsp;N/A<br />Computer:&nbsp;**********<br />Description:<br />Attempting to download the AhnLab scan engine package from <a href="http://antigendl.microsoft.com/antigen/x86/AhnLab">http://antigendl.microsoft.com/antigen/x86/AhnLab</a>.</p> <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>.<br /><br />Followed by:<br /><br />Event Type:&nbsp;Error<br />Event Source:&nbsp;GetEngineFiles<br />Event Category:&nbsp;Engine Error <br />Event ID:&nbsp;6014<br />Date:&nbsp;&nbsp;16/10/2009<br />Time:&nbsp;&nbsp;08:50:41<br />User:&nbsp;&nbsp;N/A<br />Computer:&nbsp;**********<br />Description:<br />Expired manifest.</p> <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>.<br /><br />Please help!<br /><br />Is the engine no longer supported? If so we will need to disable it but I can't find any information regarding this</p>Fri, 16 Oct 2009 07:54:00 Z2009-10-22T08:18:58Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cd6443c4-cbb0-4e83-aed4-9c577c3a74b4http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cd6443c4-cbb0-4e83-aed4-9c577c3a74b4Westmilchhttp://social.technet.microsoft.com/Profile/en-US/?user=WestmilchManaging Antigen 9 SP2 with latest Forefront Server Security Management Console HFRU3 (template.adb distribution)<span style="font-size: x-small;">Hi everyone,<br /><br />I'm using the latest versions of Antigen for Exchange and Forefront System Security Management Console<br />- Antigen 9 SP2<br />- Forefront Security Management Console Rollup 3 - 10.5.1241.28<br /><br />I would like to manage 2 4-node Exchange clusters (active, active, passive, passive) an 3 standalone Exchange servers (1 PubFol, 2 Mail-Hubs, 1 FSSMC server). All Exchange servers have Service Pack 2 and all the latest Rollups and security hotfixes installed. My described experiences are made in a test environment with a 2-node mailbox cluster, 1 PubFol server and 1 Mail-Hub and a dedicated FSSMC server. The production environment is currently unmanaged running already with the latest FSSMC for log collection. All Exchange servers are running Antigen 9 SP1 RU3 which was manually installed.<br /><br />FSSMC SW-package distribution works fine (even on my 2 node active passive test-cluster on the shared SAN-disk) on clean machines. At the moment I have no idea how it will work with active, active, passive, passive clusters, but I think the passive nodes are a kind of neutral concerning the shared drive and they could take over both (different letter) drives from the active nodes independent of the first bundle installation. Any experiences?<br /><br />The next thing was the deployment of the general settings which works also fine.<br /><br />The&nbsp;main problem is the distribution of the template.adb. I have generated one master template with the Antigen administrator (deleting the default one, restarting antigen services, Antigen will generate a new template.adb based on the other dedicated sub adb-Files). In the Antigen Administrator the default setting for processing the template.adb is default (the other choice is none in the template section of the admin tool). I haven&rsquo;t changed that and I want to modify the default settings on all our 11 Exchange servers.</span> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">We are only using the virus scanning function of Antigen. My main problem is that I can&rsquo;t disable &ldquo;content filtering, spam filtering, keyword filtering, mailhost filtering and spam filtering in the template which I want to deploy with FSSMC.</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">On every Exchange server I must disable everything again in the Operate section of the antigen admin tool. Only the internet, realtime, manual and MTA of the server can be modified. Every template setting concerning the filtering is greyed out in the template view. The behaviour doesn&rsquo;t change with user defined named templates.</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">Another issue was the deployment of customized notifications with the help of the template distribution. The stand alone servers work fine (they process changes quite in realtime) the clustered server doesn&rsquo;t process the changes. After enabling the template view the templates have the new notification texts.</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">Has someone experience with the deployment of ALL Antigen 9 SP2 settings using the FSSMC template.adb distribution?</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">All&nbsp;program versions of antigen and FSSMC are up to date and should work. The topic would be a great challenge for a new white paper ;-)</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">Thanks in advance for your help.</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">&nbsp;</span></p> <p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Verdana; color: black; font-size: 8pt;" lang="EN-GB">Guido</span></p>Mon, 12 Oct 2009 13:19:10 Z2009-10-12T13:19:10Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/773ee886-a213-4985-83ce-fa19d819c265http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/773ee886-a213-4985-83ce-fa19d819c265St.Sparkyhttp://social.technet.microsoft.com/Profile/en-US/?user=St.SparkyWhy is Antigen not deleting spam messages?Hi all,<br/> <br/> We have antigen 9.0 /w spam manager for smtp installed. and we havent had any problems for a while, but wen i came back from leave the spam was excessive.<br/> I have the  spam cure updating every 15min and it is being updated according to the timers. i have 2 RBL's (sbl-xbl.spamhaus.org and list.dsbl.org) everything is set to quarantine, send notification and purge spam. but wen i send myself a test spam with &quot;be your own boss&quot; in the header it still gets delivered.<br/> <br/> it does seem to tag it and so is delivered to my junk mail but with my settings it shouldnt get to me at all.there is nothing in the quarantine and i dont see much on the monitor. what is goin on?<br/> <br/>Fri, 15 May 2009 08:20:15 Z2009-10-12T08:35:35Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a9765f39-bf14-491e-9576-96fc80bcfc3ahttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a9765f39-bf14-491e-9576-96fc80bcfc3aJosé Luis Brioneshttp://social.technet.microsoft.com/Profile/en-US/?user=Jos%u00e9%20Luis%20BrionesTo qualify IMF?<br /> <p class="MsoNormal">Hello, I have installed Antigen 9.2.1097 SP2 in a Exchange 2003 SP2, can be qualified the IMF or it is not necessary?</p> <p class="MsoNormal">&nbsp;</p> <p class="MsoNormal">On the other hand, &nbsp; how I must form Antigen to avoid D.E.P messages.?</p>Wed, 07 Oct 2009 09:23:53 Z2009-10-15T09:31:58Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/6bd0b71b-0310-4da9-9b77-9da078353e77http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/6bd0b71b-0310-4da9-9b77-9da078353e77Barb Playfoothttp://social.technet.microsoft.com/Profile/en-US/?user=Barb%20PlayfootAntigen 9 - Blocking All emails from RussiaIs it possible to block all emails from a specific&nbsp;country, if so&nbsp;can anyone tell me how to block all emails from .ru in Antigen9 rinning on Exchange 2003.Wed, 07 Oct 2009 09:32:29 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c983c59e-8aed-4787-a9f4-472a84b83664http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c983c59e-8aed-4787-a9f4-472a84b83664moriteukhttp://social.technet.microsoft.com/Profile/en-US/?user=moriteukForefront Security Manager IssueHi All, <br/> <p>We have installed forefront server security management console to <br/> manage our exchange sevrers. We have 2 clusters both with 5 nodes, 3 <br/> active and 2 passive. All using exchange 2003 sp2 with Antigen 9 sp1</p> <p>We have moved to Forefront and the Antigen Enterprise Manager Didn't <br/> manage clusters very well.</p> <p>When I have installed the agents into one of the clusters all the <br/> physical servers show they are running the same virtual node and are <br/> in passive mode. The other cluster is fine and reports correctly.</p> <p>This is causing a problem with signature updates and filter list <br/> changes.</p> <p>The only thing I can find that might point be vaild is about the node <br/> name has to be less than 15 characters which it isn't for this cluster <br/> but it is for the cluster that is fine. The hotfix for this installed <br/> forfront onto the exchange nodes and is 64bit so I can't install it on <br/> our servers.</p> <p>Has anyone seen this problem or know of a workaround for it</p> <p>TIA <br/> Andy</p>Thu, 27 Aug 2009 12:22:11 Z2009-09-16T13:12:52Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3aca4a92-5aef-494c-a5ad-4327f72d742ehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/3aca4a92-5aef-494c-a5ad-4327f72d742eTedF1http://social.technet.microsoft.com/Profile/en-US/?user=TedF1Event ID 5044, AntigenInternet ErrorRunning Antigen 9.1.  Noticed many 5044 errors in the applog, with the following description:<br/><span style="font-size:xx-small"><span style="font-size:xx-small"> <p>Call to engine scan function returned 0x80004005 within Internet scan job (file &quot;winmail.dat-&gt;Untitled Attachment&quot;, message &quot;Folder Content&quot;, folder &quot;Outbound&quot;)</p> </span></span> These also show up in the Antigen console quarantine, although they don't show up in the Incidents window.<br/><br/>In the Quarantine window the incident reads as EngineError, and the scan engine in use won't update.  I changed engines and the error goes away.  Question is, were all these messages really quarantined?  We have notification enabled, and no users have complained.  Anyone have any clues as to what's going on here?<br/><br/>TedWed, 02 Sep 2009 17:12:01 Z2009-09-14T02:51:05Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/22d95f2e-012d-43b2-9b8c-8de826d33158http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/22d95f2e-012d-43b2-9b8c-8de826d33158vduber_khttp://social.technet.microsoft.com/Profile/en-US/?user=vduber_kAntigen 9.1 SpamCure updates cause spam checking to crash.<p>Any ideas or suggestions?<br/><br/>Running Antigen Version: 9.1.1097  SP1<br/><br/>Sometimes during the SpamCure updates it timesout which then causes the spam aspect of the filter(s) to stop. <br/><br/>Looking at Report&gt;Quarantine the only email getting blocked is the result of RBL parameters.<br/><br/>Getting it restart varies in methods. I try using the manual update, or restart the Antigen Store process then manual update.<br/><br/>While it's in this crashed/hung state the &quot;Scanner Information&quot; for SpamCure is blank or &quot;Unknown&quot;<br/><br/>Log contains.....<br/><br/>8508 - 8464 INFORMATION: The SpamCure scan engine for Antigen has been downloaded<br/>8508 - 8464 INFORMATION: The SpamCure scan engine for Antigen has been staged.<br/>8652 - 8932 INFORMATION: Testing the SpamCure scan engine.<br/>8508 - 8512 ERROR: The SpamCure scan engine update timed out while loading scanner<br/>8508 - 8464 ERROR: The scan engine update thread has been stopped due to a timeout condition while loading scanner.<br/>8508 - 8512 INFORMATION: The SpamCure scan engine for Antigen has been rolled back.<br/>4432 - 4484 ERROR: Could not load SpamCure mapper.</p> <p>This can happen daily or once a week. It ran fine for many months.</p> <p>Once it gets to this state it will stay that way until someone plays with it to get it going again even though it's attempted many updates (automatically, every 20 mins)</p> <p>I have tried rebuilding the SpamCure by deleting the parent directory, updating, and allowing it to recreate itself.</p>Tue, 04 Aug 2009 16:00:00 Z2009-08-28T14:29:49Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/bd2252cc-a7af-4779-87c1-48940e398bc1http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/bd2252cc-a7af-4779-87c1-48940e398bc1Charles_Evanshttp://social.technet.microsoft.com/Profile/en-US/?user=Charles_EvansSUSPECT Messages being delivered to InboxHello,<br/><br/>I've just installed and am testing AntiGen 9 SP2 and am trying to figure out how to automatically get messages that are marked as SUSPECT to immediately go to the users Junk Mail folder even without the Outlook client being open.  I have configured the spam filter to tag messages on subject line, MIME and SCL level but only some are being placed into Junk Mail.  The ones delivered to the Junk Mail folder also have the SUSPECT prefix in the subject line so I'm wondering why some goto Junk Mail and others don't.<br/><br/>I have IMF installed and configured to send all email over a 7 to the Junk Mail folder.  So far all the email with the SUSPECT prefix seem to be junk mail and it would save a lot of frustration if I could somehow quarantine these emails on the server or at least automatically move them to the Junk Mail folder.<br/><br/>I only installed Antigen yesterday and have played around with the settings as well as going through some of the help file.  I was hoping someone would be able to give some advice as how to best leverage Antigen to stop these messages appearing in the Inbox.<br/><br/>Also, I was hoping for a solution other than a client side exchange rule to move these messages.  Our employees have smart phones with email push and without the Outlook client running the phones would receive all the junk mail until the client started and the rule ran.<br/><br/>Thanks in advance,<br/>CharlesWed, 19 Aug 2009 13:09:34 Z2009-08-26T15:44:27Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c743d7b2-d2c1-4bd0-97a6-c9678d948699http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/c743d7b2-d2c1-4bd0-97a6-c9678d948699nunoineshttp://social.technet.microsoft.com/Profile/en-US/?user=nunoinesForefront Antigen 9 with ASM - Not detecting SPAMHello,<br/><br/>I manage a SBS2003 server with Exchange server 2003 and Forefront Antigen 9 with ASM installed.<br/>Spamcure isn't detecting any spam!!!??<br/>The Spamcure engine is running, It downloads the updates fine, but... doesn't detect any spam. And we receive a lot of It.<br/><br/>I have the exchange server configured to send email via smtp and receive via pop3, is this a problem? Antigen detects pop3 messages?<br/><br/>Any clues about what's wrong?<br/><br/><br/>Here is a description of the antigen server:<br/><br/>Version: 9.00.1055 (Licensed)<br/>Service Pack: 0<br/>Product ID: 77823-270-2325117-04162<br/>Licensed Components:<br/>Component License Type Expiration Date<br/>ASM       Subscription  29-MAR-2012    <br/>Antigen   Subscription  29-MAR-2012    <br/>Antigen Mode: VSAPI<br/>Exchange Version: 6.5<br/>Exchange Service Pack: Service Pack 2<br/>Exchange IS Version: 6.5.7638.2<br/>Computer Name: STMSBSSRV<br/>Operating System: Windows NT Version 5.2, Build number 3790<br/>Operating System Service Pack: Service Pack 2<br/>Processor: Intel processor<br/>Number of Processor(s): 2<br/>Total Physical Memory: 4294004 KBytes<br/>Available Physical Memory: 1124458 KBytes<br/>Temporary Directory Being Used: C:\WINDOWS\Temp\<br/>Available Space on Drive C:\   61711304 KBytes<br/>Available Space on Drive E:\   559991201 KBytes<br/><br/>Thanks<br/><br/>NunoTue, 11 Aug 2009 19:25:09 Z2009-08-26T15:14:31Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a24af308-7912-4440-8907-4d1a8c1de837http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a24af308-7912-4440-8907-4d1a8c1de837Brita Jenquin - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Brita%20Jenquin%20-%20MSFTNow Available – Antigen 9.0 Service Packs<p class=MsoNormal style="margin:0in 0in 10pt"><span style="color:black"><span style="font-size:small;font-family:Calibri">Microsoft announced today the release of </span></span><a href="http://technet.microsoft.com/en-us/bb738101.aspx"><strong style=""><span style=""><span style="font-size:small;font-family:Calibri">Antigen for Exchange with Antigen Spam Manager 9.0 with Service Pack 2</span></span></strong></a><span style="font-size:small;font-family:Calibri"> and </span><a href="http://technet.microsoft.com/en-us/bb738091.aspx"><strong style=""><span style=""><span style="font-size:small;font-family:Calibri">Antigen for SMTP Gateways with Antigen Spam Manager 9.0 with Service Pack 2</span></span></strong></a><span style="font-size:small"><span style="font-family:Calibri"><span style="">  </span><span style="color:black">which include visibility of all actively published engines, alerts and notifications for new engine availability, <span style="">improved anti-spam detection through integration of the Cloudmark engine,</span> and a rollup of software fixes.<span style="">  </span><strong style=""></strong></span></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><strong style=""><span style="color:black"><span style="font-size:small;font-family:Calibri"> </span></span></strong></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="color:black"><span style="font-size:small"><span style="font-family:Calibri">These releases <span style=""><span style=""> </span></span>introduce technology<span style=""> that will notify customers of engine changes – including the addition or elimination of engines – and allow administrators to update their engine configurations without having to deploy any new product updates<span style="">.<span style="">  </span>This update allows customers to accommodate engine changes effortlessly, helping maintain the high level of security provided in the Antigen and Forefront server security products.</span></span></span></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="color:black"><span style="font-size:small;font-family:Calibri"> </span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="color:black"><span style="font-size:small"><span style="font-family:Calibri">As with previous releases of Forefront Antigen, the SP2 releases provide a multi-engine protection approach for superior detection of the latest threats when compared to single engine solutions.<span style="">  </span>In fact,<span style="">  </span></span></span></span><a href="http://www.av-test.org/"><span style=""><span style="font-size:small;color:#0000ff;font-family:Calibri">AV-Test.org</span></span></a><span style="font-size:small"><span style="font-family:Calibri"> <span style="color:black">has tested our products with competitors and found our detection rates have an average response time of </span><strong style=""><em><span style="color:black">3-6</span></em></strong><span style="color:black"> <strong style=""><em>hours</em></strong> <span style="">for new viruses.<span style="">  </span>In contrast, competitive single-engine solutions average </span>response times are more than <strong style=""><em>2-9 days.</em></strong></span></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt;line-height:normal"><span style="color:black"><span style="font-size:small;font-family:Calibri"> </span></span></p> <p class=MsoNormal style="margin:0in 0in 10pt"><span style="color:black"><span style="font-size:small"><span style="font-family:Calibri">Microsoft continually monitors antivirus engine quality and detection rates using internal and 3<sup>rd</sup> party independent testing organizations.<span style="">  </span>Testing for the last several years has indicated that using more than five malware engines concurrently does not improve overall detection rates. In order to develop stronger technology relationships with our antimalware partners and ensure continued customer value for the longer term, we are making available a set of five antimalware engines, with confidence that this solution will continue to offer industry leading detection rates and response times. <span style=""> </span></span></span></span></p> <p class=MsoNormal style="margin:0in 0in 10pt"><span style="color:black"><span style="font-size:small;font-family:Calibri">As an example of Microsoft’s commitment to continual improvement of our malware detection leadership, we are investing in new antispam technology through a partnership with </span></span><a href="http://www.cloudmark.com/releases/docs/ds_cse_0309.pdf"><span style=""><span style="font-size:small;color:#0000ff;font-family:Calibri">Cloudmark</span></span></a><span style="color:black"><span style="font-size:small;font-family:Calibri"> that will provide an overall better antispam experience including higher detection rates, lower false positives, and improved submission and service experience.<span style="">  </span>The Cloudmark engine is now included in latest service pack releases of </span><a href="http://technet.microsoft.com/en-us/bb738101.aspx"><span style="font-size:small;font-family:Calibri">Antigen for Exchange with Antigen Spam Manager 9.0</span></a><span style="font-size:small"><span style="font-family:Calibri"><span style="">  </span>and </span></span><a href="http://technet.microsoft.com/en-us/bb738091.aspx"><span style="font-size:small;font-family:Calibri">Antigen for SMTP Gateways with Antigen Spam Manager 9.0</span></a><span style="font-size:small;font-family:Calibri"> products as Beta while it undergoes customer trials. <span style=""> </span>Upon the near term completion of the customer trials, it will be released by Microsoft for both the Antigen 9.0 products, as well as be included in the next generation releases of Forefront server security products later this year.<span style="">  </span>More information is available on the </span><a href="http://technet.microsoft.com/en-us/forefront/serversecurity/dd940095.aspx"><span style="font-size:small;color:#0000ff;font-family:Calibri">Antimalware Engine Notifications and Developments</span></a><span style="font-size:small"><span style="font-family:Calibri"> (AMEND) TechNet page.</span></span></span></p> <p class=MsoNormal style="margin:0in 0in 10pt"><span style="color:black"><span style="font-size:small;font-family:Calibri">For more information on latest Antigen 9.0 service pack and engine revisions, please visit the </span></span><a href="http://technet.microsoft.com/en-us/forefront/serversecurity/dd940095.aspx"><span style=""><span style="font-size:small;color:#0000ff;font-family:Calibri">AMEND</span></span></a><span style="font-size:small"><span style="font-family:Calibri"> <span style="color:black">page. </span></span></span><span style="color:black"></span></p>Wed, 01 Jul 2009 20:05:53 Z2009-08-26T12:07:28Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/acefa578-d8d7-4815-864a-f093e61e2f93http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/acefa578-d8d7-4815-864a-f093e61e2f93Anderson Erikssonhttp://social.technet.microsoft.com/Profile/en-US/?user=Anderson%20ErikssonTask Scheduler - Update Engines - 0x8007000d: The data is invalid.Hi,<br/>I finished installation Antigen for Exchange SP2.<br/>Engines aren't update. I check the Task Scheduler and all tasks for Antigen show error.<br/>What's happening?<br/>Anderson.<hr class="sig">Anderson ErikssonFri, 21 Aug 2009 00:18:23 Z2009-08-26T18:21:44Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/92591978-f927-424a-be50-44164c30726bhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/92591978-f927-424a-be50-44164c30726bBegiehttp://social.technet.microsoft.com/Profile/en-US/?user=BegieRealtime scan job timeouts and messages get stuck in awaiting directory lookupHi all,<br/>we had to reboot our exchange 2003 server.<br/>After this i noticed messages got stuck in awaiting directory lookup.<br/>After some investigation i found out that every messages get timedout by the realtime scan job of antigen 9.0 sp1.<br/>When i disable the realtime scan job, the message flow is normal.<br/><br/>I don't see anyting special in the event log, except the timeout messages. Is there anywhere else i can look to see what is causing these errors?<hr class="sig">RgdsTue, 07 Jul 2009 10:19:55 Z2009-08-24T10:11:09Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/84c8678e-6810-4fbc-a8fd-5007f0b0ce32http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/84c8678e-6810-4fbc-a8fd-5007f0b0ce32Vicinitechhttp://social.technet.microsoft.com/Profile/en-US/?user=Vicinitech9.1 - stripping Office 2007 XML - UnwritableCompressedFile - why?<p align=left><font face=Arial size=2></font> </p> <p>So I thought 9.1 was to now work with Office 2007 files - well, it does not.   It strips them (xlsm, xlsx etc.).  I am not blocking zip files.   I use file filter lists (not names) so I cannot add office files to a list and expect them to hit first and let them thru with a SKIP/DETECT.  Do I need to add all of them to a names in order to have them in order (vs. lists)?    If that works, great - but why is this 9.1 not working with office files?</p> <p> </p> <p align=left>Also, noticed when I send an xlsx file thru - CPU on mail server hit 100% for 10 or more seconds.  Wow - really does not like XML files.</p> <p align=left> </p> <p align=left>I hope someone knows how to let these files thru - from what I read in the forums - this should not be happening I think.</p> <p align=left> </p> <p align=left>Ron</p>Thu, 15 May 2008 21:57:13 Z2009-08-25T14:20:19Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2cdc2307-6524-447a-96f0-d0c74512af24http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2cdc2307-6524-447a-96f0-d0c74512af24Sandy Woodhttp://social.technet.microsoft.com/Profile/en-US/?user=Sandy%20WoodAntigen Worm List Update?Just noticed that my Antigen Worm List Scanner hasn't updated since May 5th. I get this event when it tries to update<br/><br/>Unable to load manifest from: <a href="http://antigendl.microsoft.com/antigen/x86/Microsoft/Package/manifest.cab">http://antigendl.microsoft.com/antigen/x86/Microsoft/Package/manifest.cab</a> : (0x00002ee7) The server name or address could not be resolved.  WinHttpClient failed while sending a request.<br/><br/> Is this scanner obsolete?<hr class="sig">Orange County District AttorneyThu, 23 Jul 2009 16:10:02 Z2009-08-06T14:15:04Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a90f76ae-3084-40aa-8dbe-dd1fdbffcecchttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/a90f76ae-3084-40aa-8dbe-dd1fdbffceccSandy Woodhttp://social.technet.microsoft.com/Profile/en-US/?user=Sandy%20WoodAntigen internet scan timed out and recovered<p>Just upgraded my Exchange 2003 boxes with Antigen SP2 and I got this puzzling email alert:<br/><br/>Subject: Antigetn internet scan timed out and recovered<br/><br/>timeout occurred while scanning D:\Program Files\Microsft Antigen for Exchange\Archive\SMTP message. Please contact Microsoft.<br/><br/>I checked the server and found that I did not have a SMTP folder under the Archive folder. Could this have been the cause?</p><hr class="sig">Orange County District AttorneyWed, 05 Aug 2009 18:16:22 Z2009-08-06T14:11:02Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/fa4aebdd-23a3-4cc4-b35a-af4afdce1476http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/fa4aebdd-23a3-4cc4-b35a-af4afdce1476luckysavagehttp://social.technet.microsoft.com/Profile/en-US/?user=luckysavageIntegration with Outlook allowed senders lists?<p>I'm on Exchange 2003 on Server 2003 and my client computers all run Office 2003.  Is there any way to allow users to update their own whitelists?  Does Antigen use Outlook's safe sender list or any other way to create a whitelist or is there just the filter in the admin console?</p>Thu, 30 Jul 2009 22:36:05 Z2009-08-06T00:03:21Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2784e3dc-040d-49dc-bfef-919f7cf87d29http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/2784e3dc-040d-49dc-bfef-919f7cf87d29ibakeshttp://social.technet.microsoft.com/Profile/en-US/?user=ibakesAntigen 9 Un-install problem<p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana">Hi All<br/><br/>I am having trouble after I made a mistake and un-installed Antigen 9 without clearing the regkeys and failing over the cluster.<br/><br/>I have an Active/Passive Windows server 2003 running Exchange 2003 SP2 with Antigen 9.1 SP1.<br/><br/>We were having trouble with antigen on one of the nodes, when you opened the application it stated the license was out of date even though it had been upgraded from version 8. I decided to remove antigen and reinstall, so I removed it by add remove programs and failed the cluster over to enable me to restart.<br/><br/>After the restart i can no longer fail the cluster over to the passive node as 2 services fail to start, Exchange system attendant and SMTP Virtual server Instance 1 and it does seem to take a while for Cluster name and Disk services to stop and start.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana">I now know that I should have removed the keys and may be I should remove antigen from the current node but I do not want to cause any more problems.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana">If anyone has any suggestion as to what I can try it would be greatly appreciated.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:Verdana">Thanks in advance</span></p>Fri, 17 Jul 2009 15:16:53 Z2009-07-30T10:19:35Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/91f737ec-a5e2-47ad-8e2e-11d9f142114ehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/91f737ec-a5e2-47ad-8e2e-11d9f142114eSandy Woodhttp://social.technet.microsoft.com/Profile/en-US/?user=Sandy%20WoodError GetEngineFiles not really an error?<p>I just noticed an event on one of my Exchange 2003 servers running Antigen 9.1;<br/><br/>Type: Error<br/>Source: GetEngineFiles<br/>Event ID: 6014<br/>Event Time: 7/7/2009 3:31:11 PM<br/>User: n/a<br/>Computer: OCDAEX00<br/>Description:<br/>Unable to load manifest from: <a href="http://antigendl.microsoft.com/antigen/x86/CAVet/Package/manifest.cab">http://antigendl.microsoft.com/antigen/x86/CAVet/Package/manifest.cab</a> : (0x00002ee7) The server name or address could not be resolved.  WinHttpClient failed while sending a request.<br/><br/><br/>I opened the Antigen Console and noticed that it appeared to in fact update. It showed<br/><br/><br/>Last Checked 15:31:11<br/>Last Updated 03:31:23</p> <p>Update Version 0907070001<br/>Signature version 31.6.25.201<br/><br/><br/>It looks good no?</p><hr class="sig">Orange County District AttorneyTue, 07 Jul 2009 22:49:39 Z2009-07-30T10:29:14Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cfc0b820-c150-4d6e-9f8d-d12e27a1296chttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/cfc0b820-c150-4d6e-9f8d-d12e27a1296cishmael.whalehttp://social.technet.microsoft.com/Profile/en-US/?user=ishmael.whaleusing antigen 9 for exchange - "allowed senders" options grayed out for real time scan jobHi<br/> we are using antigen 9, and want to exclude certain senders from realtime scanning. we have created a test list, and populated it with addresses. the list appears as expected in the filtering options for the smtp scan job, but does not appear in the bottom left pane for the realtime scan job. all options in the righthand bottom pane are therefore grayed out.Thu, 02 Jul 2009 10:27:19 Z2009-10-31T20:08:33Z