Solved

Antigen 9.1 SP1 error TION: Smtp sink status 3, method returned 0x80004005.

Posted on 2009-07-02
9
1,933 Views
Last Modified: 2013-11-22
I keep getting frequent eventID 4008 from AntigenSMTPSink that all say:

TION: Smtp sink status 3, method returned 0x80004005.

I can't find any relevant info other than 1 person's suggestion to run antutil /disable then /enable... I've done that and I'm still getting these errors.  The spam filter/antivirus is working, but it certainly isn't working as well as it should.  I suspect these errors are at least partly why.

Also, the updates for some of the engines almost always timeout... the kaspersky ones in particular have problems and haven't successfully updated in so long all the update info is blank.  
0
Comment
Question by:cymrich
  • 5
  • 4
9 Comments
 

Author Comment

by:cymrich
ID: 24776175
the /disable and /enable command appears to have actually made things worse... as far as I can tell now the spam filter is not working at all and the only thing catching spam is the IMF.

any suggestions?
0
 
LVL 40

Expert Comment

by:Subsun
ID: 24776527
Do you have latest Hotfix Rollup installed? are you getting any error or warning in event viewer?
0
 

Author Comment

by:cymrich
ID: 24777896
my original post has the error I am receiving... I have SP1 installed and supposedly once you have that you receive updates through windows updates.  I've checked for updates there and there are none.  
0
 
LVL 40

Expert Comment

by:Subsun
ID: 24778051
This will occur when Antigen is unable to access message objects in the SMTP Queue. This may indicate a temporary resource problem on the system.

Recycle the Antigen services
Stop all Antigen services > Wait for all services to completely shut down > Use Task Manager to make > sure that no Antigen processes are still running > Start all Antigen services.
Run Restart-Service MSExchangeTransport
Or if possible reboot the server.

If the issue persists then :
Provide Get-TransportAgent command result.
Also in server event log do you have any error or warning related to the transport service?
What is the Exchange rollup update you have on server?
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:cymrich
ID: 24787465
The services were all shutdown and restarted a few times recently... although I have not done a full reboot yet.  

These commands you are mentioning look like Exchange 2007 commands... Unfortunately I am using Exchange 2003 SP2.  Unless I am mistaken Antigen is for 03 and before only, and Forefront would be used with 07.   Is there an equivalent to these command for 03?  I went ahead and tried them from a command prompt just in case and they are not recognized.  
0
 

Author Comment

by:cymrich
ID: 24787529
forgot to add... the only transport errors I see in the event logs are NDRs and errors from IMF saying it can't filter a messge.... ID #s 3030 for the NDRs and 7515 for the IMF
0
 
LVL 40

Accepted Solution

by:
Subsun earned 500 total points
ID: 24787934
My Bad, I didn't ask you the version of exchange.
Do you have Netlogon service started on your server?
You may try rebooting the server, if it doesn't resolve try to rebuild the scan engine
http://technet.microsoft.com/en-us/library/bb914086.aspx

For update engine issue try : http://support.microsoft.com/kb/905991/en-us
0
 

Author Comment

by:cymrich
ID: 24799157
I think I might have figured this out.  It seems somehow it lost the license agreement information.  When I looked under product license it showed XXXXXXXXX for the agreement number and 10/4/11 as the expiration.  I knew that the expiration was wrong and it should have been 7/31/11.  After inputting the agreement number again and then doing the updates it appears to be in working order once again.  

The link you provided for the update time out was very helpful.  I had found something similar for forefront when I searched google about it, but when looking for an antigen key to edit instead of a forefront one, I forgot to keep in mind that it used to belong to Sybari.  It seemed at first that every time I upped the download timeout it would simply download slower... but then I finally just set it to 1 hour and I was able to update everything that had been timing out.  at at 10 minutes it made it to 60% or so, at 20 minutes it made it to 50% or so... our connection is not that slow or unstable so this strikes me as odd.

After looking at the event logs again I realize I didn't notice that the 4008 events had indeed stopped the night I ran the antutil /disable and /enable.  They had not stopped right when I did it but the last ones were roughly an hour later.  so that at least was successful, but I'm not sure how the license agreement information was lost.  

I'm going to keep an eye on this until next week before officially calling it fixed.
0
 
LVL 40

Expert Comment

by:Subsun
ID: 24800131
Hmm.. Green light.... :-)
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Resolve Outlook connectivity issues after moving mailbox to new Exchange 2016 server
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now