Forefront Client Security Alerting and Monitoring ForumDiscussions and questions around the alerting, the dashboard and policy authoring© 2009 Microsoft Corporation. All rights reserved.Wed, 02 Dec 2009 11:56:46 Zc4e84bcb-4e25-46bb-8866-05ad6eb61e3fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/d311839f-77a6-4a00-9699-34f4686e3a3ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/d311839f-77a6-4a00-9699-34f4686e3a3eGreg Allanhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20AllanFCS Management Console Issue: Snap-in errorEvery time I attempt to run the FCS Management Console it closes down, with a pop-up error message: &quot;MMC has detected an error in a snap-in and will unload it&quot;. If I unload and continue running the MCC I get another message: &quot;FX:{f337d96e-45c1-4106-88b1-e417a7703d6b} Exception has been thrown by the target of an invocation.&quot; <br/> <br/> Exception Type: System.Reflection.TargetInvocationException <br/> Exception stack trace: <br/> at Microsoft.ManagementConsole.Internal.SnapInMessagePumpProxy.OnThreadException(Object sender, ThreadExceptionEventArgs e)<br/> at System.Windows.Forms.Application.ThreadContext.OnThreadException(Exception t)<br/> at System.Windows.Forms.Control.InvokeMarshaledCallbacks()<br/> at System.Windows.Forms.Control.WndProc(Message&amp; m)<br/> at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message&amp; m)<br/> at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message&amp; m)<br/> at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)<br/> <br/> Please can someone advise me on how to get my Management Console to work again, I tried to run the FCSMS.msi install file again, but it doesn't run.Wed, 02 Dec 2009 11:56:45 Z2009-12-02T11:56:46Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e6fe1a5a-cc39-420d-82d1-98c7828b37cfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e6fe1a5a-cc39-420d-82d1-98c7828b37cfJeffery Mark Tatumhttp://social.technet.microsoft.com/Profile/en-US/?user=Jeffery%20Mark%20TatumMy name is Jeff Tatum, and I should be already a member of your Forums. The Microsoft Help Menue had the right answers about the servers and any other additions to sending an email to bdefer1@mac.com. . I believe, since I am an Administrator, I should bfI do not believe that The Webmaster has the right to keep me off the 1973 Bell High School Page, and since I am customizing everything within my control, I, Jeff Tatum, amg4322 will change any and all settings that an Administrator ha s at his disposal.<br/><br/>Jeff Tatum.Fri, 20 Nov 2009 11:48:10 Z2009-11-27T10:44:00Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f97e0167-487c-491a-a03d-1ce4220f2b57http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f97e0167-487c-491a-a03d-1ce4220f2b57littlejanehttp://social.technet.microsoft.com/Profile/en-US/?user=littlejanei found a problem as below when i log in my window live messenger,can anybody help me?<p> Problem Event Name: APPCRASH<br/>  Application Name: msnmsgr.exe<br/>  Application Version: 14.0.8089.726<br/>  Application Timestamp: 4a6ce533<br/>  Fault Module Name: kernel32.dll<br/>  Fault Module Version: 6.0.6001.18215<br/>  Fault Module Timestamp: 49953395<br/>  Exception Code: c0000005<br/>  Exception Offset: 0004502e<br/>  OS Version: 6.0.6001.2.1.0.768.2<br/>  Locale ID: 17417</p> <p>Additional information about the problem:<br/>  LCID: 2052</p> <p>Read our privacy statement:<br/>  <a href="http://go.microsoft.com/fwlink/?linkid=50163&amp;clcid=0x0409">http://go.microsoft.com/fwlink/?linkid=50163&amp;clcid=0x0409</a><br/> </p>Fri, 13 Nov 2009 05:02:03 Z2009-11-23T02:05:22Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/73e8c499-61b1-467d-89c3-312e2f0add50http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/73e8c499-61b1-467d-89c3-312e2f0add50MGMNVAhttp://social.technet.microsoft.com/Profile/en-US/?user=MGMNVAForefront Alerting - Do not want alerts on successful cleans. How do I configure that in MOMI am getting to much alert noise from FCS. All my workstation 8000 are set at alert level 3. I do not want to recieve an alert if FF successfully responded to an event. How do  I configure this? I recieve emails  that tell me Forefront successfuly removed stuff.Thu, 05 Nov 2009 20:28:05 Z2009-11-05T21:03:25Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/11f102cf-c9a3-4911-aa9a-8497ebb0fb74http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/11f102cf-c9a3-4911-aa9a-8497ebb0fb74Thomas Overbeckhttp://social.technet.microsoft.com/Profile/en-US/?user=Thomas%20OverbeckSending Alerts to different users depending on a serverHi all,<br/><br/>I don't know if this is the right forum for my question (it could be a MOM question).<br/><br/>I have one central Forefront Server. But we have several Servers in severals sites which are all reporting to the central forefront server. <br/>If a alert is taken I want to send this mail only to the site administrator. <br/>All servers are running in one child domain, but they are reside in different organizational units.<br/><br/>I don't see any configuration settings to do it.<br/>Does anybody know a solution for me?<br/><br/>many thanks,<br/>Thomas<br/><br/><hr class="sig">S070004Thu, 29 Oct 2009 15:30:29 Z2009-11-06T09:53:37Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/25e490ec-02d5-4e74-800c-66b74ede4946http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/25e490ec-02d5-4e74-800c-66b74ede4946Juan Matiashttp://social.technet.microsoft.com/Profile/en-US/?user=Juan%20MatiasConfiguring E-Mail alertHi people!<br/> First of all, i'm not another guy asking for the same thing... this time is quite different. I don't have an email server in the enterprise so i have to rely on my external ISP e-mail server. ¿Is there a way to configure e-mail alerting in FCS with Authentication-Required SMTP servers? I couldn't find the option :(<br/> <br/> Thanks!!!!<br/> Mat.Fri, 24 Apr 2009 02:31:28 Z2009-10-31T20:08:26Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/df04b10b-fb10-4412-9349-247672c4a180http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/df04b10b-fb10-4412-9349-247672c4a180MGMNVAhttp://social.technet.microsoft.com/Profile/en-US/?user=MGMNVAForefront Client Security SNMP TrapsHow do you configure the FCS management infrastructure to send traps?Mon, 26 Oct 2009 13:30:28 Z2009-10-26T13:30:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/4d3dab7f-8a9d-49ad-bfe2-5a564414e8b3http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/4d3dab7f-8a9d-49ad-bfe2-5a564414e8b3PJ51530http://social.technet.microsoft.com/Profile/en-US/?user=PJ51530Mom 2005 (Forefront) Client SettingsHello,<br /> <br /> I had a question regarding the configuration of the Global setting for the Agents. <br /> <br /> This is the settings under mom 2005 admin console, global settings, and agents. <br /> <br /> I was wandering if anyone knew of a Microsoft document highlighting recommended settings or best practices for these settings. <br /> Also, would anyone mind sharing some information about their settings and if they tweaked any settings and if there was a reason behind the tweak.<br /> <br /> I am wanting to learn more about the impact, or helpfulness of these settings as well as the defaults that came out of the box. But, i have not found much information.<br /> <br /> Many Thanks<br /> <br />Thu, 08 Oct 2009 21:48:39 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/378c3c2e-0e97-4998-b5dd-b0c1a67cee14http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/378c3c2e-0e97-4998-b5dd-b0c1a67cee14Guy Yardenihttp://social.technet.microsoft.com/Profile/en-US/?user=Guy%20YardeniFCS on a domain controller with SCOM agentWe have FCS deployed with agents on all domain controllers.  <div><br/></div> <div>We are now deploying SCOM 2007 R2 and would like to monitor the domain controllers. As I understand it, multi homing between SCOM and MOM on a domain controller is not supported due to the incompatible versions of the helper objects. </div> <div>Is it possible to support FCS agents with alerting and monitoring on the DCs as well as SCOM agents?</div> <div><br/></div> <div>Thanks,</div> <div>Guy</div>Fri, 25 Sep 2009 17:54:05 Z2009-10-07T16:42:49Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/191bc35b-c6cc-4ccb-bd32-5ad387463ecehttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/191bc35b-c6cc-4ccb-bd32-5ad387463ececsp122http://social.technet.microsoft.com/Profile/en-US/?user=csp122mom 2005 generates thousands of blank e-mail alerts<div class=body>we've got mom 2005 as installed by forefront, with alerts being sent for antivirus activities... has anybody observed mom 2005 go bonkers and spew thousands of blank alerts each day?<br/></div>Wed, 09 Sep 2009 13:14:10 Z2009-10-31T20:08:27Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/dc15707a-a33d-46f5-a69f-4a91847654e9http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/dc15707a-a33d-46f5-a69f-4a91847654e9lanman_4http://social.technet.microsoft.com/Profile/en-US/?user=lanman_4Forefront reports sent out to email addressHi,<br/>I have been asked to setup scheduled Forefront reports to be emailed out to one of our admin staff. I am the SCOM admin not the Forefront server admin. Can these emailed reports not be sent out directly from the Forefront server? If so, how is this setup, similar to SCOM? (channel, subscription, etc..)<br/>Thanks for any help,<br/>L<br/>Mon, 14 Sep 2009 12:32:32 Z2009-09-22T02:13:28Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/1a064cc0-6a5a-4c79-8905-a93e42e217aahttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/1a064cc0-6a5a-4c79-8905-a93e42e217aaMike Crowleyhttp://social.technet.microsoft.com/Profile/en-US/?user=Mike%20CrowleyAccurate, point in time report.<p>The reporting in Forefront shows a 24 hour window.  I want to know status of my clients right now.  I need to know, right now, what computers have viruses and what viruses they have.<br/><br/>How can I do this?</p><hr class="sig"><html> <head> <meta http-equiv=Content-Type content="text/html; charset=unicode"> <meta name=Generator content="Microsoft SafeHTML"> </head> <body lang=EN-US link="#0033CC" vlink=purple> <div class=Section1> <p class=MsoNormal style="line-height:normal;background:white"><b><span style="font-size:10.0pt;font-family:'Arial','sans-serif';color:#365F91">Mike Crowley </span></b><span style="font-size:8.0pt;font-family:'Arial Narrow','sans-serif';color:gray">A+, Network+, Security+, MCT, MCSE, MCTS, MCITP: Enterprise Administrator / Messaging Administrator<br/> <i>Do you still have Exchange 2000?  Looking to upgrade to Exchange 2010?  <a href="http://mike-crowley.spaces.live.com/blog/cns!C23CB95E1200929!324.entry"><span style="border:none"><span style="border:none">Read how.</span></span></a></i></span></p> </div> </body> </html>Thu, 03 Sep 2009 19:11:12 Z2009-09-03T19:11:12Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f3e36907-56d6-4a58-a493-b8006dd0894bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f3e36907-56d6-4a58-a493-b8006dd0894bPete Lambiehttp://social.technet.microsoft.com/Profile/en-US/?user=Pete%20LambieForeFront removal reportsWe've been getting lots of emailed reports from ForeFront lately to do with conficker, the report says <br/><br/> <p class=MsoPlainText style="margin:0cm 0cm 0pt"><span style="font-size:small;font-family:Consolas">Description:<span style="">  </span>Client Security failed to eliminate the following threat:</span></p> <p class=MsoPlainText style="margin:0cm 0cm 0pt"><span style="font-size:small"><span style="font-family:Consolas"><span style="">            </span>- Threat name: Worm:Win32/Conficker.B!inf</span></span></p> <p class=MsoPlainText style="margin:0cm 0cm 0pt"><span style="font-size:small"><span style="font-family:Consolas"><span style="">            </span>- Attempted action: Remove<br/><br/>However when we visit the PC in its history it has successfully removed.  One one occasion we found successfully removed but using the DART disc the virus was still there.<br/><br/>We're a bit sensitive about conficker here and any help on why the reports differ from the information on the client machine would be appreciated.</span></span></p>Wed, 01 Apr 2009 15:39:27 Z2009-09-03T14:35:58Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/26930be8-e7ee-4f92-bef5-2f273fdbb635http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/26930be8-e7ee-4f92-bef5-2f273fdbb635justlilyhttp://social.technet.microsoft.com/Profile/en-US/?user=justlilyVISTA APPCRASH WHILE ON WINDOWS LIVE MESSENGER<p align=left><font face=Arial size=2></font> </p> <p>HELP! </p> <p align=left> </p> <p align=left>Every time I am on my Windos Vista pc and log on to Window Live Messenger the program crashes. I need help because I do not know how to fix this problem.</p> <p align=left> </p> <p align=left>The following shows the error message that I receive as soon as it crashes:</p> <p align=left> </p><b><font color="#0066cc" size=1> <p>Problem signature:</p></b></font><font size=1> <p>Problem Event Name: APPCRASH</p> <p>Application Name: msnmsgr.exe</p> <p>Application Version: 8.1.178.0</p> <p>Application Timestamp: 45b12d6a</p> <p>Fault Module Name: dfsr.dll</p> <p>Fault Module Version: 8.1.178.0</p> <p>Fault Module Timestamp: 45b12b28</p> <p>Exception Code: c0000005</p> <p>Exception Offset: 00002ef4</p> <p>OS Version: 6.0.6000.2.0.0.768.3</p> <p>Locale ID: 1033</p></font><b><font color="#0066cc" size=1> <p>Additional information about the problem:</p></b></font><font size=1> <p>LCID: 1033</p></font><b><font color="#0066cc" size=1> <p>Read our privacy statement:</p> <p></b><u>http://go.microsoft.com/fwlink/?linkid=50163&amp;clcid=0x0409</p></u></font>Thu, 13 Sep 2007 23:53:42 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/71cbc6a4-6b69-4569-9318-9804b0b04652http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/71cbc6a4-6b69-4569-9318-9804b0b04652Ryan Seniohttp://social.technet.microsoft.com/Profile/en-US/?user=Ryan%20SenioEmail Alerts - Windows 2008 Standard ServerI've got FCS running on a Windows 2008 box. Clients can report in, things seem to be working. However I can't get email alerts to work when a virus is detected on a client machine. I've followed the steps here <a href="http://blogs.microsoft.co.il/blogs/yanivf/archive/2008/02/06/configure-e-mail-notifications-for-forefront-client-security-step-by-step-guide.aspx">http://blogs.microsoft.co.il/blogs/yanivf/archive/2008/02/06/configure-e-mail-notifications-for-forefront-client-security-step-by-step-guide.aspx</a><br/><br/>To test whether or not it was my internal relay I followed the steps in <a href="http://support.microsoft.com/kb/920736">http://support.microsoft.com/kb/920736</a> and was able to get the email from the generated alert as a test. Has anyone had issues, or been able to get email notifications to work from a FCS client that has a detected a virus? Should there not be alerts setup in MOM for this? I dont see it in the step by step article aboveThu, 16 Jul 2009 23:06:17 Z2009-07-23T01:59:10Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f40cb457-967e-47e7-a45f-f18420dfca5ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f40cb457-967e-47e7-a45f-f18420dfca5aDan Chiassonhttp://social.technet.microsoft.com/Profile/en-US/?user=Dan%20ChiassonAny way to determine which clients have been uninstalled?We noticed in the FCS Management console that the number of managed computers fluctuates (usually because of newly installed FCS Clients.) However recently we noticed this number <strong>decrease</strong> , causing to be concerned that certain end-users (with administrative privileges on their PC) have possibly uninstalled the FCS Client.<br/> <br/> Is there a way to see the recent &quot;uninstall activity&quot;, either with a report or via a SQL query?  (I looked through the MOM logs, but couldn't decipher anything useful.)<br/> <br/> Thanks,<br/> Dan ChiassonMon, 13 Jul 2009 16:19:15 Z2009-07-15T15:28:58Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/7f797a68-01f4-4513-b7f9-5bbc60310610http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/7f797a68-01f4-4513-b7f9-5bbc60310610SakkieJhttp://social.technet.microsoft.com/Profile/en-US/?user=SakkieJForefront Domain controller<p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;color:black;font-family:'Verdana','sans-serif'">Hi All.<br/><br/>We have a client that installed forefront in his domain. All the updates are deployed to all the agents. The problem we have is that the Domain controllers aren't being updated. I assume that we need to create a GPO policy that will point to the WSUS server.<br/><br/>Is this to correct approach or are there other troubleshooting avenues I could use to indentify the problem?<br/><br/>Thanks, all tips will help.</span></p> <p> </p>Tue, 07 Jul 2009 03:17:55 Z2009-07-15T10:10:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/ba2c71a7-aee9-46c2-91a4-0b20c5e79ceahttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/ba2c71a7-aee9-46c2-91a4-0b20c5e79ceaSuetechiehttp://social.technet.microsoft.com/Profile/en-US/?user=SuetechieClient security management console spyware & virus logsHi<br/><br/>I want to make sure that Forefront is working correctly and catching viruses/anti spyware.  On the management console it displays alerts and malware detected as zero.  Is this correct?  I would have assumed we'd have had some viruses/spyware detected.<br/><br/>thanks!Tue, 14 Jul 2009 13:56:44 Z2009-07-21T08:29:15Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/33470fc3-6a04-4c35-a8e3-df3fb007412ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/33470fc3-6a04-4c35-a8e3-df3fb007412aS Clarkhttp://social.technet.microsoft.com/Profile/en-US/?user=S%20Clarkemail administrator for infected systems?<p align=left><font face=Arial size=2></font> </p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3>In our current environment we are running TrendMicro OfficeScan version 6. When a workstation encounters a virus, OfficeScan immediately notifies via e-mail the A/V administrator indicating username and machine name and other pertinent information concerning the virus. We are looking for the same functionality in FFCS. </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3> </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3>We introduced a test virus (eicar.com) to a Vista workstation with FFCS installed. FFCS detected the test virus and allowed the user to take appropriate action. This was also indicated in the Forefront reporting feature. However, we also need to receive immediate notification via email when such an event occurs anywhere among our 600+ workstations. </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3> </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3>Most application that we administer have direct, built-in SMTP notification features that allow set up and testing of the notification process without having to have prior knowledge of what Event ID to filter. </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3> </font></p> <p class=MsoPlainText style="margin:0in 0in 0pt"><font face=Consolas size=3>Does FFCS have this capability, and if so, what are the steps to set it up. Other than what you send me yesterday concerning the setup steps in MOM?</font></p>Mon, 04 Feb 2008 22:35:53 Z2009-10-31T20:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/b680cd15-183a-4ded-b23e-bba74b7e332bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/b680cd15-183a-4ded-b23e-bba74b7e332bslav_sammyhttp://social.technet.microsoft.com/Profile/en-US/?user=slav_sammywindow registeryHi;<br/>    How to detect changes in window Regisitry using c#Sat, 04 Jul 2009 16:27:05 Z2009-07-06T04:02:37Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/30f596e5-30df-4091-b10d-7d76a6f66c4fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/30f596e5-30df-4091-b10d-7d76a6f66c4fBuzy Mindhttp://social.technet.microsoft.com/Profile/en-US/?user=Buzy%20MindIllegal file downloadI have been ordered to find the person(computer) from my network who downloaded an illegal file from the internet. How do i do this please?<br/><br/>ThanksMon, 29 Jun 2009 15:06:12 Z2009-07-07T01:48:22Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f658a44f-9ab9-4ccc-85fd-13f1e264203fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f658a44f-9ab9-4ccc-85fd-13f1e264203fsmutechhttp://social.technet.microsoft.com/Profile/en-US/?user=smutechEnabling managed clients to "Always Allow" instead of just "Permit" <p>The FCS client alerts when turned on to prompt users for unclassified software imply that the user can select &quot;Always Allow&quot;, however that is not listed as an option in the alert action field when an alert is generated. For example, our environment is a Windows domain with WSUS/MOM, but being a university our end users are all administrators. This means we must try to protect them as much as possible, but allow them to make customized exceptions. If a department is using an application that loads in the startup, instead of excluding it globally, can the individual not just be offered the option to always allow, or is this just a feature of the unmanaged FCS? If so, and we can only add this as a policy exclusion, when do you add a path as an exclusion vs. adding as an  &quot;Override&quot;?<br/><br/>Thanks!</p>Mon, 01 Jun 2009 13:57:55 Z2009-06-10T05:10:58Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/5e2e1de8-ec21-4581-bc3e-f3bac054e696http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/5e2e1de8-ec21-4581-bc3e-f3bac054e696take back the dayhttp://social.technet.microsoft.com/Profile/en-US/?user=take%20back%20the%20daycomputer securityCan anyone explain why Internet Explorer is factory preset with Internet Options Security Restricted Sites allowing font download.Tue, 02 Jun 2009 15:03:46 Z2009-06-02T15:03:47Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/374f0f1f-241a-4190-a2fb-8e2b3c2008edhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/374f0f1f-241a-4190-a2fb-8e2b3c2008edThomas Bergerhttp://social.technet.microsoft.com/Profile/en-US/?user=Thomas%20BergerUsing existing SCOMHI<br/><br/>I have a customer who have an existing SCOM, and they want to know if they can get alerts from FCS MOM over to SCOM, so they only need to look one place?<br/>The customer have a one-server topology where everything is configured on 1 server. From what I have read it is not possible to replace FCS's MOM with SCOM, but is the other thing possible?<br/><br/>Regards<br/>Thomas<hr class="sig">-Sun, 17 May 2009 14:31:35 Z2009-05-25T01:56:06Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/9a3f931a-9165-42ef-8e10-47754c10a0cbhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/9a3f931a-9165-42ef-8e10-47754c10a0cbtex from texashttp://social.technet.microsoft.com/Profile/en-US/?user=tex%20from%20texasForefront Client no longer updating from WSUS, showing alertI have migrated approx. half of my enterprise to Forefront.  Deployed through GPO and WSUS.  Updates are managed through WSUS as well.<br/><br/>For about 2 weeks now, some of my clients show an alert ( ! ) status and out of date definition files.  The clients' Forefront definitions never get updated, all though other WSUS updates are coming down.  WSUS shows that many clients have not downloaded the new definitions, but the Forefront Client Security console is only alerting to a couple machines with out of date definition files and not most of the ones showing an alert.<br/><br/>If I go to update.microsoft.com one one of these machines I see there is an available definition update and I can apply it then my status is then updated reflecting green check mark.  However, by default my clients cannot download updates from microsoft.com, they have to go through wsus.<br/><br/>Also, where do I look for logs on Forefront updates? I have checked windowsupdate.log and it does not show issues re forefront definition udpates.  <br/><br/>Any suggestions/throughts on where to go next?Mon, 04 May 2009 14:12:16 Z2009-05-04T14:12:16Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/33d5441c-b203-4440-886c-ac4748b89839http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/33d5441c-b203-4440-886c-ac4748b89839Pete Lambiehttp://social.technet.microsoft.com/Profile/en-US/?user=Pete%20LambieBuilding client into 'image' for desktopsOur technicians are re-building their images for lab computers and want to know if they can put forefront in the image, which will then be deployed using SCCM (new SMS).<br/><br/>My gut reaction was no, is this right?<br/><br/>I thought FF writes to the registry with it's computer name, also it'd want added to the mom server with forefront.  The technicians are a bit wary about putting an image out which contains no AV and just waits on SCCM (new SMS) to eventually deploy the software to the newly imaged machine.<br/><br/>Thanks,<br/> PeteWed, 01 Apr 2009 15:41:56 Z2009-04-30T21:26:02Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f67d33aa-3da1-47d7-b62d-262b1204e743http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f67d33aa-3da1-47d7-b62d-262b1204e743JustinCochranhttp://social.technet.microsoft.com/Profile/en-US/?user=JustinCochranNo Longer receiving AlertsAbout a month ago we realized that our Transaction Logs were full. We cleared them out. Ever since then we have not been receiving alerts such as when some gets a virus.<br/><br/>We received them before this happened. Can someone help me with this?<hr class="sig">Justin CochranWed, 15 Apr 2009 14:48:58 Z2009-04-27T01:34:51Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/0959fb11-6a2b-4f17-9859-e37598eddda4http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/0959fb11-6a2b-4f17-9859-e37598eddda4tgawareckihttp://social.technet.microsoft.com/Profile/en-US/?user=tgawareckiAlerts and reporting for machines in a workgroupI have several machines I want to protect with FCS that are not part of my domain.  I know how to get the client installed, but I'm not clear on how alerting and reporting will work for these machines.  I don't see anywhere to set up any alerting.  Can someone please help?<br/>ThanksTue, 07 Apr 2009 12:44:01 Z2009-10-31T20:08:30Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/5340b632-97a0-4c18-bc04-720bae67aaf2http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/5340b632-97a0-4c18-bc04-720bae67aaf2Pete Lambiehttp://social.technet.microsoft.com/Profile/en-US/?user=Pete%20LambieRepeatedly asked to "review changes".We have a group policy to set the home page of a machine depending on how logs onto it, staff to an intranet.  Students to another site.<br/><br/>However we are getting continually prompted by the wee blue box with a white question mark asking to approve the change to IE.<br/><br/>I'm guessing this isnt normal!<br/><br/>We recently opened forefront up to staff/students to help with removing conficker, if it was locked down they weren't being prompted to remove it and that wasn't working very well. So we've ticked &quot;prompt user when unclassified software is detected&quot;.  Since giving them rights they've been prompted to approve this change several times per day.<br/><br/>Thanks for any help<br/><br/> Pete<br/><br/><strong><span style="font-size:xx-small"> <p>Summary:</p> <p>Internet Explorer Configurations change occurred.</p> <p>This agent monitors end user and security related configuration changes made to Internet Explorer, including the default home page.</p> <strong> <p>Detected changes:</p> </strong> <p>New: <a href="http://ABCweb">http://ABCweb</a></p> <p>Original: Not available</p> <p>iemain (New):</p> <p>HKCU@S-1-5-21-2428622596-161815611-3700723485-4076\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page</p> <strong> <p>Advice:</p> </strong> <p>Permit this configuration change only if you trust its origin. It is recommended that you run a quick scan if you choose to deny this change.</p> <strong> <p>Detected by:</p> </strong> <p>Definition file</p> <strong> <p>Checkpoint:</p> </strong> <p>Internet Explorer Home Page</p> <strong> <p>Category:</p> </strong> <p>Configuration Change</p> <p> </p> </span></strong>Wed, 01 Apr 2009 15:46:56 Z2009-10-31T20:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/eec395ec-6c79-4b30-9a3c-c5a87f5ae0b2http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/eec395ec-6c79-4b30-9a3c-c5a87f5ae0b2Freddie Davishttp://social.technet.microsoft.com/Profile/en-US/?user=Freddie%20DavisAutomatic ScanningI have the client installed and setup the automatic scanning at 2 AM and it did it the first day and now it is stopped scanning at 2AM.  Is there something wrong or do I need to do something else?  I do leave the computer on so it can scan. Mon, 19 Jan 2009 14:32:55 Z2009-03-30T11:45:09Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f796a82c-2d70-4e1e-ac25-cbf6174136cfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/f796a82c-2d70-4e1e-ac25-cbf6174136cfStMaSihttp://social.technet.microsoft.com/Profile/en-US/?user=StMaSiRepeating Alerts...Windows XP Professional SP3<br>ForeFront Client Security<br>Client: 1.5.1958.0<br>Engine: 1.1.4405.0<br>AntiVirus: 1.53.612.0<br>AntiSpyware: 1.53.612.0<br><br>Out of over 500 clients, this one machine throws the same 45 alerts approximately every 30 minutes. Even though I've chosen &quot;permit&quot; every time it alerts, the same alerts continue.<br><br>&quot;Review items that haven't been classified yet: 45 total&quot;<br><br>Any ideas on how to eliminate the unnecessary alerts?<br><br>Thanx.Mon, 16 Mar 2009 17:39:40 Z2009-03-16T17:39:42Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e4c1ef13-2dcd-4c65-8814-c6543f3ff7a6http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e4c1ef13-2dcd-4c65-8814-c6543f3ff7a6ichintuhttp://social.technet.microsoft.com/Profile/en-US/?user=ichintuHey Guys really hoping some one can help me with this problemThe Data Access Server (DAS) on computer localhost returned an error. <br> <br>System error code: -2147024891 <br>System error text: Access is denied. <br>DAS method called: ProcessRuleSelectWithPK_Fields_all <br>Called from file: d:\bt\4\private\product\config\tools\managementpacksupport\drivers\momdb\src\db2mpsupport.cpp <br>Called from line: 1234<br><br>I am getting this error on my forefront collection server every hour.<br><br>I have checked that the DAS account has db_owner on both OnePoint and the SystemReporting database.<br>Thu, 05 Mar 2009 22:06:14 Z2009-03-06T23:23:27Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/739b9724-d797-4ba5-afcc-c6943bc970c7http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/739b9724-d797-4ba5-afcc-c6943bc970c7Ray_Ghttp://social.technet.microsoft.com/Profile/en-US/?user=Ray_GFCS client can not add Allowed ItemsI have configured my Policy to allow Clients to &quot;Allow users to add exclusions and overrrides&quot; with the hope that it will allow exactly that.<br><br>What happens on the client side is the FCS detects a change, the user is then presented with two Action options:  PERMIT, DENY.  They chose PERMIT, and then the next time GP refreshes they get prompted again, and again, and again.<br><br>What is lacking from this list is 'ALWAYS ALLOW' - the help documentation shows this option and I hope that this is what checking that box on the FCS server meant.  My guess is that it then would put these &quot;ALWAYS ALLOW&quot; items in the ALLOWED ITEMS &quot;repository&quot; under the TOOLS menu.<br><br>Currently there is no other way for me to allow items except for by doing it at the POLICY level.  This is actually a step backward in functionality and my users are letting me know it!<br><br>My policy is getting messy with all of the users exceptions.... and some aren't even working correctly.  Not to mention I'm allowing things for users that don't even need them.  I know what you'll say, add more POLICYS and then deploy them all seperatly.  Why should I have to do this?.. if the software is setup to allow users to PERMIT their own.  <br><br>How can i enable this setting in the FCS client - PERMIT ALWAYS (search FCS help for Allowed Items to see what I mean).  I think that this is a bug?<br><br>Thanks in advance,<br>RayTue, 03 Mar 2009 16:22:27 Z2009-03-03T16:22:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/759fd802-f1a8-47b8-9110-09ee9fbb52a5http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/759fd802-f1a8-47b8-9110-09ee9fbb52a5Xdata666http://social.technet.microsoft.com/Profile/en-US/?user=Xdata666SCOM 2007 & FCS Management PackHello!<br> <br>Is there a operations manager 2007 management pack for forefront client security? If not, are there plans to make one? Or has anyone been able to successfully convert the MOM 2005 MP to import into 2007? Thanks in advance!Fri, 14 Nov 2008 14:03:29 Z2008-11-14T14:03:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/9527a45c-3188-4618-9fec-b88212539f18http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/9527a45c-3188-4618-9fec-b88212539f18GEB01http://social.technet.microsoft.com/Profile/en-US/?user=GEB01Last scan alert Hi,<br>We have a policy in which we execute a daily quick scan and we would like to monitor if there are clients for which their last scan was older then 7 days. I can however not find back any report to obtain this information nor is it included in the alerts.<br><br>Is it possible to make a custom event rule and generate an alert in the category warning for such a situation?<br>Thanks!<br><br>Rgds,<br>GertMon, 06 Oct 2008 13:40:56 Z2008-10-06T13:40:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/ee843ca6-a025-4c1c-9dcf-f5b6ddb124b4http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/ee843ca6-a025-4c1c-9dcf-f5b6ddb124b4wqwalterhttp://social.technet.microsoft.com/Profile/en-US/?user=wqwalterRegistry change involving C:\WINDOWS\web\AOpenClient.htm<p>I keep getting a warning with the following information:</p> <p> </p><b><font size=1> <p>Summary:</p></b> <p>Internet Explorer Add-ons change occurred.</p> <p>This agent monitors additions to IE, such as new toolbars, browser helper objects, and ActiveX controls. These add-ons can automatically run when IE is started.</p><b> <p>Path:</p></b> <p>C:\WINDOWS\web\AOpenClient.htm</p><b> <p>Detected changes:</p></b> <p>regkey:</p> <p>HKCU@S-1-5-21-1592928892-2373870068-2624222429-1135\Software\Microsoft\Internet Explorer\MenuExt\Open Client to monitor &amp;2</p> <p>iemenuext:</p> <p>HKCU@S-1-5-21-1592928892-2373870068-2624222429-1135\Software\Microsoft\Internet Explorer\MenuExt\Open Client to monitor &amp;2</p> <p>file:</p> <p>C:\WINDOWS\web\AOpenClient.htm</p><b> <p>Advice:</p></b> <p>Permit this detected item only if you trust the program or the software publisher.</p> <p>Programs that may compromise your privacy or damage your computer were detected. You can still access the file without removing the threat, although this is not recommended. To do so, select &quot;Always Allow&quot; as the action and click the &quot;Apply Actions&quot; button. If this option is not available, log on as an administrator or ask an administrator for help.</p><b> <p>Detected by:</p></b> <p>Definition file</p><b> <p>Publisher:</p></b> <p>Not available</p><b> <p>Digitally Signed By:</p></b> <p>NOT SIGNED</p><b> <p>Product name:</p></b> <p>Not available</p><b> <p>Description:</p></b> <p>Not available</p><b> <p>Size:</p></b> <p>1173 bytes</p><b> <p>Version:</p></b> <p>Not available</p><b> <p>Type:</p></b> <p>file type unknown</p><b> <p>Checkpoint:</p></b> <p>Internet Explorer Menu Extension</p><b> <p>Category:</p></b> <p>Not Yet Classified</p> <p> </p> <p></font><font size=3>I select permit and a few minutes later it comes back. Does anyone know what this is and how can I get the warning to stop if it is harmless?</font></p> <p> </p> <p>Bill Walter</p> <p> </p>Wed, 23 May 2007 15:06:27 Z2008-09-24T22:22:00Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/16835205-013a-495a-a7d1-2fa708ed245ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/16835205-013a-495a-a7d1-2fa708ed245aYasir Memonhttp://social.technet.microsoft.com/Profile/en-US/?user=Yasir%20MemonForefront Clients are not reporting - DashboardHello Everyone i have a little query regarding Forefront Client Security Reporting &amp; Monitoring, i hope i will get appropriate answers from you guys...<br><br>i have set up Forefront Client Security (Stand-Alone Server with all components), it is working well &amp; configured properly, everything was good, clients were reporting but from last week suddenly they stoped reporting &amp; there is only one client in &quot;Reporting No Issue&quot; &amp; all others are in &quot;NOT REOPORTING&quot; even i have detected viruses in my computer but that is not shown in &quot;Reporting Critical Issues&quot;, only one computer is reporting i guess that is forefront itself.<br><br>how can i troubleshoot this issue &amp; what is the cause behind this problem.?<br><br><br>BRegards<hr size="1" align="left" width="25%">M.Yasir MemonTue, 02 Sep 2008 05:46:53 Z2008-09-18T18:41:41Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/8d4037f6-8d8a-4dca-805c-6e6e0d0182d0http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/8d4037f6-8d8a-4dca-805c-6e6e0d0182d0acschnabelhttp://social.technet.microsoft.com/Profile/en-US/?user=acschnabelISA gives RST Segment error when RDP I am not able to RDP into my ISA server. I can RDP into all of my other servers and computers on the network. When checking the logs, I get the message <br><br>&quot;A connection was abortively closed after one of the peers sent an RST segment&quot;<br><br>Can anyone tell me how to go about fixing this so I can RDP into my ISA server (2004).<br> <br>Thank you.Tue, 26 Aug 2008 15:59:19 Z2008-09-11T19:59:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/8f03b5d3-e0d5-4dd2-96e7-ecad491b9be0http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/8f03b5d3-e0d5-4dd2-96e7-ecad491b9be0ChrisHelthttp://social.technet.microsoft.com/Profile/en-US/?user=ChrisHeltTotal viruses cleaned Hello!<br><br>How would I find the total number of viruses cleaned by virus type within a 24 hour period?  Is there a log file, database or something that will give me this information?  <br><br>Thanks in advance.Fri, 18 Jul 2008 19:50:38 Z2008-09-02T12:23:52Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e93d506d-3734-4dea-821e-0a123323c902http://social.technet.microsoft.com/Forums/en-US/Forefrontclientalert/thread/e93d506d-3734-4dea-821e-0a123323c902Interactive Networkshttp://social.technet.microsoft.com/Profile/en-US/?user=Interactive%20NetworksFalse Virus Alarm <b>Hello,<br><br>This is Cristina from Customer Service Department of Interactive Networks. Our company develops instant messaging software and we have recently received a report from one of our customers about a false virus detected by Forefront Client Security software in one of our files.<br>The name of the file is &quot;bircd.exe&quot; and it is part of the IRC component integrated in one of our chat modules. <br>I have been trying to reach Forefront Client Security support people but it was not possible, I have just received automatic replies.<br>Our customers need a quick solution since they are no longer able to use our product because of this false alarm.<br>Who should I contact to help me out with this? <br><br>Thank you.<br><br>Cristina<br>Interactive Networks Inc.<br></b><a href="mailto:crodriguez@interactiveni.com"><b>crodriguez@interactiveni.com</b></a><b> </b>Thu, 21 Aug 2008 14:22:22 Z2008-08-27T20:43:48Z