Hello!
I'm currently experiencing an issue with my TMG 2010 server. My firewall no longer starts and the log states the following:
The Microsoft Forefront TMG Firewall Service failed to start because the definitions for malware inspection could not be loaded from the folder {2AF2304F-319F-45C8-8DDA-846861A9F438}. To correct this issue, set the data in all the values under the
registry key SOFTWARE\Microsoft\Fpc\EmpScanner\Versions to "0.0.0.0", update the malware inspection definitions in the Update Center, and start the Microsoft Forefront TMG Firewall Service.
The failure is due to error: The parameter is incorrect.
I have done this but TMG never updates the definitions. It always fails. Also where is this '{2AF2304F-319F-45C8-8DDA-846861A9F438}' folder located?
This snippet is from the Windows Update log:
2011-03-24 16:55:04:183 5716 da0 Misc =========== Logging initialized (build: 7.5.7601.17514, tz: -0400) ===========
2011-03-24 16:55:04:183 5716 da0 Misc = Process: C:\Program Files\Microsoft Forefront Threat Management Gateway\UpdateAgent.exe
2011-03-24 16:55:04:183 5716 da0 Misc = Module: C:\Windows\system32\wuapi.dll
2011-03-24 16:55:04:182 5716 da0 COMAPI -------------
2011-03-24 16:55:04:183 5716 da0 COMAPI -- START -- COMAPI: Search [ClientId = Forefront TMG]
2011-03-24 16:55:04:183 5716 da0 COMAPI ---------
2011-03-24 16:55:04:188 864 b94 Agent *************
2011-03-24 16:55:04:188 5716 da0 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = Forefront TMG]
2011-03-24 16:55:04:188 864 b94 Agent ** START ** Agent: Finding updates [CallerId = Forefront TMG]
2011-03-24 16:55:04:188 864 b94 Agent *********
2011-03-24 16:55:04:188 864 b94 Agent * Online = Yes; Ignore download priority = No
2011-03-24 16:55:04:188 864 b94 Agent * Criteria = "(IsInstalled = 0 and IsHidden = 0 and CategoryIDs contains '84a54ea9-e574-457a-a750-17164c1d1679' and
CategoryIDs contains 'e0789628-ce08-4437-be74-2495b842f43b')"
2011-03-24 16:55:04:188 864 b94 Agent * ServiceID = {7971F918-A847-4430-9279-4A52D1EFE18D} Third party service
2011-03-24 16:55:04:188 864 b94 Agent * Search Scope = {Machine}
2011-03-24 16:55:04:191 864 b94 Misc Validating signature for C:\Windows\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\muv4wuredir.cab:
2011-03-24 16:55:04:197 864 b94 Misc Microsoft signed: Yes
2011-03-24 16:55:46:197 864 b94 Misc WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <localhost:8080> Bypass List used : <<local>>
Auth Schemes used : <>
2011-03-24 16:55:46:197 864 b94 Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://download.windowsupdate.com/v9/windowsupdate/redir/muv4wuredir.cab>.
error 0x80072ee2
2011-03-24 16:55:46:197 864 b94 Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2011-03-24 16:55:46:197 864 b94 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2011-03-24 16:55:46:197 864 b94 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2011-03-24 16:56:28:200 864 b94 Misc WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <localhost:8080> Bypass List used : <<local>>
Auth Schemes used : <>
Then it starts repeating. I'm able to find updates through Windows Update so I'm not sure what the issue is. I have 'use microsoft update sevices, directly' for my update service.
Any suggestions?
Thank you.