Share via


TMG 2010 Firewall Service Crashing. Event ID Pointing to Malware Updates (Resolution)

If you're getting the following Event over the Application logs...

Log Name:      Application
Source:        Microsoft Forefront TMG Web Proxy
Date:          3/18/2013 3:11:22 PM
Event ID:      23486
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      TMG.nslabs.in
Description:
The Microsoft Forefront TMG Firewall Service failed to start because the definitions for malware inspection could not be loaded from the folder {FA8B448B-8958-48F4-9D66-FA6FFB9DEE01}. To correct this issue, set the data in all the values under the registry key SOFTWARE\Microsoft\Fpc\EmpScanner\Versions to "0.0.0.0", update the malware inspection definitions in the Update Center, and start the Microsoft Forefront TMG Firewall Service. 

Perform these steps...
** 
**-- Go to HKLM\Software\Microsoft\Fpc\Empscanner
-- Zero the value of CurrentEngineDirectory
-- Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fpc\EmpScanner\Versions
-- Change the values to 0.0.0.0 for mpasbase.vdm, mpasdlta.vdm, mpavbase.vdm, mpavbase.vdm and mpengine.dll
-- Go to C:\Program Files\Microsoft Forefront Threat Management Gateway\MPEngine deleted the folder under it.
-- Start firewall service. No reboot required.

-- Install Malware Update definitions, if customer's Malware license has not expired.