Do you have latest Hotfix Rollup installed? are you getting any error or warning in event viewer?
Main Topics
Browse All TopicsI keep getting frequent eventID 4008 from AntigenSMTPSink that all say:
TION: Smtp sink status 3, method returned 0x80004005.
I can't find any relevant info other than 1 person's suggestion to run antutil /disable then /enable... I've done that and I'm still getting these errors. The spam filter/antivirus is working, but it certainly isn't working as well as it should. I suspect these errors are at least partly why.
Also, the updates for some of the engines almost always timeout... the kaspersky ones in particular have problems and haven't successfully updated in so long all the update info is blank.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
This will occur when Antigen is unable to access message objects in the SMTP Queue. This may indicate a temporary resource problem on the system.
Recycle the Antigen services
Stop all Antigen services > Wait for all services to completely shut down > Use Task Manager to make > sure that no Antigen processes are still running > Start all Antigen services.
Run Restart-Service MSExchangeTransport
Or if possible reboot the server.
If the issue persists then :
Provide Get-TransportAgent command result.
Also in server event log do you have any error or warning related to the transport service?
What is the Exchange rollup update you have on server?
The services were all shutdown and restarted a few times recently... although I have not done a full reboot yet.
These commands you are mentioning look like Exchange 2007 commands... Unfortunately I am using Exchange 2003 SP2. Unless I am mistaken Antigen is for 03 and before only, and Forefront would be used with 07. Is there an equivalent to these command for 03? I went ahead and tried them from a command prompt just in case and they are not recognized.
My Bad, I didn't ask you the version of exchange.
Do you have Netlogon service started on your server?
You may try rebooting the server, if it doesn't resolve try to rebuild the scan engine
http://technet.microsoft.c
For update engine issue try : http://support.microsoft.c
I think I might have figured this out. It seems somehow it lost the license agreement information. When I looked under product license it showed XXXXXXXXX for the agreement number and 10/4/11 as the expiration. I knew that the expiration was wrong and it should have been 7/31/11. After inputting the agreement number again and then doing the updates it appears to be in working order once again.
The link you provided for the update time out was very helpful. I had found something similar for forefront when I searched google about it, but when looking for an antigen key to edit instead of a forefront one, I forgot to keep in mind that it used to belong to Sybari. It seemed at first that every time I upped the download timeout it would simply download slower... but then I finally just set it to 1 hour and I was able to update everything that had been timing out. at at 10 minutes it made it to 60% or so, at 20 minutes it made it to 50% or so... our connection is not that slow or unstable so this strikes me as odd.
After looking at the event logs again I realize I didn't notice that the 4008 events had indeed stopped the night I ran the antutil /disable and /enable. They had not stopped right when I did it but the last ones were roughly an hour later. so that at least was successful, but I'm not sure how the license agreement information was lost.
I'm going to keep an eye on this until next week before officially calling it fixed.
Business Accounts
Answer for Membership
by: cymrichPosted on 2009-07-04 at 00:28:09ID: 24776175
the /disable and /enable command appears to have actually made things worse... as far as I can tell now the spam filter is not working at all and the only thing catching spam is the IMF.
any suggestions?