I have a new setup of MSME v7.6 patch 1 for Exchange 2010 SP2. So there is probably a configuration issue somewhere, I'm just not sure how to troubleshoot further.
I created an On Deman Scan Task using the locally installed application on my mailbox server (only hosts the mailbox roll on this server). CAS/HUB is elsewhere.
The on-demand task is pretty much out-of-the box with these exceptions:
- schedule - none (run manually for testing)
- what to scan - tried all, also tried a single database with the same issue
- policy - default On Demand policy - resumable scanning enabled
When I click the run now button, the task starts ok. But after 6 seconds the job ends (same happened for every attempt I made).
In the product log I see this error:
ID = 2173
On demand scan task failed due to 'EWSWrapper failure while CoCreateInstance'. Error 0xffffffff.
The McAfee Agent is also installed, and because of its reporting the failure to my EPO (v4.6) I get sent this email about the failure:
On-demand Scan task failed on '10/31/2012 23:09:29'.
1. Check product logs for more details.
2. Ensure that the processes SAFeService.exe and RPCServ.exe are started.
3. Check Windows event log for more details.
4. If issue exists, contact McAfee Technical Support.
Both of the EXE processes are running at the moment (after the failure).
Any suggestions? I also enabled warning type events in the MSME product log, but nothing has popped up yet.
MSME on E2010 relies on an OD User (McOD_<servername>@yourdomain.com) for the OnDemand scan.
In certain instances this user may not be created and can happen if deployed by ePO - have a look at
Basically there should be McODUser information available in the registry at
There should be a corresponding mailbox in Exchange and the address retrieved from AD and added to the registry for that user should be in its list of associated e-mail addresses (does not need to be primary).
There is instruction in the KB article on creating but if user details/mb etc don't match up you could run a cmd prompt ("run with admin" if any UAC involvement)
CD to <MSMEInstallFolder>\bin
(To remove incomplete info)
(to create new info)
If still fails set up debug logging to "High" use a new or empty local folder (e.g. C:\McAfee\Logs)
Start the ODS (as you state this should take only a few seconds)
Once fails - Set Debug logging to "None"
Zip up all the debug logging
Export HKEY_LOCAL_MACHINE\Software\Wow6432Node\McAfee\ to txt file.
Open a case with Support.
Add those files as attachment or provide to your support representative for examination.
Thanks for the quick reply. Will try re-creating the user today.
In the registry there is currently only one entry relating to the user account McOD which is ODUserID, I'm not sure if there are supposed to be more based off your post.
A mailbox for this account was created, and of course an AD account as well.
Problem remains. After I re-created the McOD account, a new "Password" registry key appeared... but that didn't fix the problem. Submitted issue to McAfee for more help.
Problem has been fixed. During the install the email address given to the McOD user account was McOD_serverName@myPublicDomain.ca as per my Exchange email address (default) policy.
To fix the problem, I added a secondary email address to the McOD user account (as per McAfee's recomendation) which matched the UserID field in the registry key mentioned above thread (similar to McOD_servername@myLocalDomain.local). Afterwards the OD scan starts fine!