Answer
PROBLEM
A corrupted definition is causing the Email Exploit engine to fail to auto-update.ENVIRONMENT
- GFI MailEssentials
- All supported environments
SOLUTION
There are two ways to initiate the update.Solution 1
- Navigate to the following directory <GFI MailEssentials installation path>\GFI\MailEssentials\Updater\eed
and delete the following files:
- exploitdb_current_revision.txt
- exploitdb_current_revision.txt.checked
- exploitdb_current_revision.txt.tmp
- Open Services.msc and restart the GFI MailEssentials AV Scan Engine and GFI MailEssentials Autoupdater services.
- Open MailEssentials Configuration and navigate to Email Security > Virus Scanning Engines > Email Exploit Engine > Updates.
- Click Download Updates and click Apply.
- Verify that the definitions successfully installed on the Update status.
If the above steps do not update the definitions a manual update is required in order to clear the possible corrupt definitions out of the MailEssentials Directories. Follow the steps below in order to complete the manual update process.
- Open a browser and navigate to http://cdnupdate.gfi.com/
- Navigate to the following directory incav2 > exploitdb > C1 folder and click the exploitdb_current_version.c1.zip link to download the latest Email Exploit definitions.
- After the download has completed you will need to navigate to service.msc and stop the SMTP or transport service(note this will stop mail flow and queue the messages in exchange until restarted)
- In services.msc console locate and stop all gfi services related to MailEssentials
- Extract the downloaded zip from step 2 to the following location <GFI MailEssentials installation path>\GFI\MailEssentials\Updater\eed overwrite when prompted by windows
- Navigate to the directory where you just extracted the files to from the previous step <GFI MailEssentials installation path>\GFI\MailEssentials\Updater\eed and locate the file exploitdb2.zip
- Extract the exploitdb2.zip twice to the following locations <GFI MailEssentials installation path>\GFI\MailEssentials\EmailSecurity\Engines\eed and <GFI MailEssentials installation path>\GFI\MailEssentials\EmailSecurity\Engines\Backup\EED overwrite when prompted.
- Start all services stopped in step 3 and 4.
- Open MailEssentials configuration and verify that the Bitdefender Engine has been updated Successfully with the latest version.
CAUSE
- The definitions files were corrupted and that can cause update failures.
- Third party antivirus or backup scanning of the GFI MailEssentials folders can corrupt definitions.
- Content filter type Hardware firewalls can corrupt the MD5 checksum during the update process please verify the proper exclusions are in your hardware firewall for successful updates. See the following article for the current update sites needed to be excluded in your firewall. https://www.gfi.com/support/products/gfi-mailessentials/What-sites-are-used-for-GFI-Product-Updates
Priyanka Bhotika
Comments