{"id":22789,"date":"2022-01-01T10:47:04","date_gmt":"2022-01-01T09:47:04","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=22789"},"modified":"2022-01-02T01:45:03","modified_gmt":"2022-01-02T00:45:03","slug":"exchange-fip-fs-scan-engine-failed-to-load-cant-convert-2201010001-to-long-1-1-2022","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/01\/01\/exchange-fip-fs-scan-engine-failed-to-load-cant-convert-2201010001-to-long-1-1-2022\/","title":{"rendered":"Exchange Year 2022 Problem: FIP-FS Scan Engine failed to load &#8211; Can&rsquo;t Convert &ldquo;2201010001&rdquo; to long (2022\/01\/01 00:00 UTC)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/07\/Office1.jpg\" width=\"55\" height=\"60\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/01\/01\/exchange-fip-fs-scan-engine-failed-to-load-cant-convert-2201010001-to-long-1-1-2022\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]A short note to the administrators whose on-premises Exchange servers are currently on strike and cannot load the FIP-FS scan engine (virus scanner) and report an error <em>Can't Convert \"2201010001\" to long<\/em>. You are probably not alone, as of Jan. 1, 2022 0:00 UTC on-premises Exchange servers seem to freezing transport of all emails &#8211; a date can't get converted. Here is a quick overview of what is going on.<\/p>\n<p><!--more--><\/p>\n<h2>FIP-FS Scan Engine<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg09.met.vgwort.de\/na\/6a738b9f60b54952b3c6e20581afc48f\" alt=\"\" width=\"1\" height=\"1\" \/>FIP-FS is probably the anti-malware virus scanner that has been on board since Exchange Server 2013. This is supposed to scan the on-premises Exchange Server installation for malicious content. However, this anti-malware scan engine seems to cause problems more often. Back in October 2016, Frank Z\u00f6chling published the German blog post <a href=\"https:\/\/www.frankysweb.de\/exchange-2016-fipfs-event-id-6027-filter-updates-werden-nicht-runtergeladen\/\" target=\"_blank\" rel=\"noopener\">Exchange 2016: FIPFS Event ID 6027 Filter Updates werden nicht runtergeladen<\/a>, which pointed out numerous error possibilities when updating the signature files. ver\u00f6ffentlicht, der auf zahlreiche Fehlerm\u00f6glichkeiten beim Aktualisieren der Signaturdateien hinweist.<\/p>\n<p>And in early December 2021, someone on serverfault.com posted the entry <a href=\"https:\/\/serverfault.com\/questions\/1085840\/exchange-2019-antimalware-engine-updates-download-but-dont-get-applied\" target=\"_blank\" rel=\"noopener\">Exchange 2019 Antimalware engine updates download but don't get applied<\/a>. There, the FIP-FS MS Filtering Engine permanently generates entries in the Event Viewer because updates could not be installed. It has probably affected different Exchange versions and might be related to downloads of updates or virus signatures. There the error was probably corrected by Microsoft.<\/p>\n<h2>FIP-FS error Can't Convert \"2201010001\" to long<\/h2>\n<p>I was just alerted on Twitter by a follower to the following <a href=\"https:\/\/twitter.com\/miketheitguy\/status\/1477097527593734144\" target=\"_blank\" rel=\"noopener\">tweet<\/a>, which briefly describes the problem, which has been occurring since January 1, 2022.<\/p>\n<p><a href=\"https:\/\/twitter.com\/miketheitguy\/status\/1477097527593734144\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Exchange: FIPS Scan Engine failed to load - Can't Convert \"2201010001\" to long \" src=\"https:\/\/i.imgur.com\/Pbyvf3L.png\" alt=\"Exchange: FIPS Scan Engine failed to load - Can't Convert \"2201010001\" to long \" \/><\/a><\/p>\n<p>Under Exchange, the Microsoft Scan Engine FIP-FS cannot be loaded. Instead, the error Can't Convert \"2201010001\" to long is reported. Seems that the new date is a challenge for Exchange. In follow-up tweets, another <a href=\"https:\/\/twitter.com\/JRoosen\/status\/1477108315888967688\" target=\"_blank\" rel=\"noopener\">user reports<\/a> with the name Joseph Roosen:<\/p>\n<blockquote><p>Umm ya having issues with no mailflow because of this since that keeps crashing over and over since 0000 UTC.<br \/>\nDear we have a problem with hybrid since this service keeps crashing so basically mail is down.<br \/>\n<a href=\"https:\/\/twitter.com\/MSFTExchange\">@MSFTExchange<\/a>\u00a0<a href=\"https:\/\/twitter.com\/Microsoft\">@Microsoft<\/a>\u00a0<a href=\"https:\/\/twitter.com\/MSFT365Status\">@MSFT365Status<\/a><\/p><\/blockquote>\n<p>So it fits, the Exchange doesn't let any mails through anymore. And via Facebook, someone pointed me to this tweet from Joseph Roosen, which puts it a bit in context:<\/p>\n<p><a href=\"https:\/\/twitter.com\/JRoosen\/status\/1477120097747677184\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/1QG6plg.png\" \/><\/a><\/p>\n<p>Just in time for the new year, the virus scanner on Exchange Server goes on strike and scares administrators. Since March 2021, Microsoft has published the article <a href=\"https:\/\/docs.microsoft.com\/en-us\/answers\/questions\/302892\/the-fip-fs-scan-process-failed-initialization-erro.html\" target=\"_blank\" rel=\"noopener\">The FIP-FS Scan Process failed initialization. Error: 0x80010105 AND Faulting application name: scanningprocess.exe<\/a>, which refers to Exchange Server 2016 on Windows Server 2016. There is the current entry from 1\/1\/2022:<\/p>\n<blockquote><p>The exchange server was stuck with this error:<\/p>\n<p>The FIP-FS \"Microsoft\" Scan Engine failed to load. PID: 39268, Error Code: 0x80004005. Error Description: Can't convert \"2201010003\" to long. \/ Event ID 5300<\/p>\n<p>I have disabled filtering:<\/p>\n<p>Set-MalwareFilteringServer exch-19 -BypassFiltering $true<\/p>\n<p>and email is going agian &#8230; and I am looking for more info how to recover malware scanning service<\/p>\n<p>FYI<br \/>\nhappy new year exchnage<\/p><\/blockquote>\n<p>So it seems that some (all?) Exchange servers are affected.<\/p>\n<h2>Workaround: Disable Anti Malware Agent<\/h2>\n<p>The affected person from the above tweet has meanwhile posted a very <a href=\"https:\/\/twitter.com\/miketheitguy\/status\/1477109221145473026\" target=\"_blank\" rel=\"noopener\">simple solution<\/a> via Twitter. He has deactivated the anti-malware agent on the Exchange server.<\/p>\n<p><img decoding=\"async\" title=\"Exchange fix\" src=\"https:\/\/i.imgur.com\/CoyP1MA.png\" alt=\"Exchange fix\" \/><\/p>\n<p>For this purpose there is the script Disable-AntiMalwareScanning.ps1. Then malware scans are no longer executed &#8211; but the mails can be sent and delivered again. Someone else who is affected by this New Year's surprise.<\/p>\n<p>Addendum: Microsoft has now confimed the issue and is working on a fix &#8211; see\u00a0<a href=\"https:\/\/borncity.com\/win\/2022\/01\/02\/microsoft-besttigt-exchange-year-2022-problem-fip-fs-scan-engine-failed-to-load-1-jan-2022\/\" rel=\"bookmark\">Microsoft confirms Exchange Year 2022 problem that FIP-FS Scan Engine failed to load (Jan. 1, 2022)<\/a>.<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2021\/07\/14\/sicherheitsupdates-fr-exchange-server-juli-2021\/\">Security updates for Exchange Server (July 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/06\/29\/kumulative-exchange-updates-juni-2021-verffentlicht\/\">Cumulative Exchange CUs June 2021 released<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/04\/14\/exchange-server-security-update-kb5001779-13-april-2021\/\">Exchange Server Security Update KB5001779 (April 13, 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/03\/06\/exchange-probleme-mit-ecp-nach-sicherheitsupdate-mrz-2021\/\">Exchange isues with ECP\/OWA search after installing security update (March 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/07\/17\/exchange-sicherheitsupdates-von-juli-2021-zerschieen-ecp-und-owa\/\">Exchange security updates from July 2021 breaks ECP and OWA<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/07\/13\/exchange-2016-2019-outlook-probleme-durch-amsi-integration\/\">Exchange 2016\/2019: Outlook problems due to AMSI integration<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/08\/22\/angriffswelle-fast-2-000-exchange-server-ber-proxyshell-gehackt\/\">Wave of attacks, almost 2,000 Exchange servers hacked via ProxyShell<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/08\/29\/exchange-server-2016-2019-benutzerdefinierte-attribute-in-ecp-nach-cu-installation-juli-2021-nicht-mehr-aktualisierbar\/\">Exchange Server 2016-2019: Custom attributes in ECP no longer updatable after CU installation (July 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/08\/30\/exchange-server-authentifizierungs-bypass-mit-proxytoken\/\">Exchange Server: Authentication bypass with ProxyToken<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/08\/08\/exchange-schwachstellen-droht-hafnium-ii\/\">Exchange vulnerabilities: Will we see Hafnium II?<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/07\/13\/exchange-2016-2019-outlook-probleme-durch-amsi-integration\/\">Exchange 2016\/2019: Outlook problems due to AMSI integration<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/27\/exchange-server-september-2021-cu-kommt-zum-28-9-2021-mit-microsoft-exchange-emergency-mitigation-service\/\">Exchange Server September 2021 CU comes Sept. 28 with Microsoft Exchange Emergency Mitigation Service<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/09\/29\/exchange-server-september-2021-cu-28-9-2021\/\">Exchange Server September 2021 CU (2021\/09\/28)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/10\/13\/sicherheitsupdates-fr-exchange-server-oktober-2021\/\">Security updates for Exchange Server (October 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/10\/17\/tifanu-cup-2021-exchange-2019-und-iphone-gehackt\/\">Tianfu Cup 2021: Exchange 2019 and iPhone hacked<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/06\/babuk-gang-nutzt-proxyshell-schwachstelle-in-exchange-fr-ransomware-angriffe\/\">Babuk gang uses ProxyShell vulnerability in Exchange for ransomware attacks<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/10\/exchange-server-november-2021-sicherheitsupdates-schlieen-rce-schwachstelle-cve-2021-423\/\">Exchange Server November 2021 Security Updates Close RCE Vulnerability CVE-2021-423<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/13\/bsi-cert-warnung-kompromittierte-exchange-server-werden-fr-e-mail-angriffe-missbraucht-nov-2021\/\">CERT warning: Compromised Exchange servers are misused for email attacks (Nov. 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/18\/warnung-cert-bund-usa-gb-vor-angriffen-auf-exchange-und-fortinet\/\">CERT-Federation, USA, GB warns about attacks on Exchange and Fortinet<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/20\/proxynoshell-mandiant-warnt-vor-neuen-angriffsmethoden-auf-exchange-server-nov-2021\/\">ProxyNoShell: Mandiant warns of new attack methods on Exchange servers (Nov. 2021)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/11\/23\/warnung-proxyshell-squirrelwaffle-und-ein-poc-eploit-patcht-endlich-eure-exchange-server\/\">ProxyShell, Squirrelwaffle and a new PoC Exploit, patch your Exchange Server!<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/12\/03\/beispiele-fr-viren-mails-nach-bernahme-eines-exchange-servers\/\">Examples of virus mails from a compromised Exchange server<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/12\/01\/cert-bund-warnung-30-der-deutschen-exchange-server-mit-offenem-owa-angreifbar\/\">German CERT-Bund warns about vulnerable Exchange Server with OWA reachable from Internet<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A short note to the administrators whose on-premises Exchange servers are currently on strike and cannot load the FIP-FS scan engine (virus scanner) and report an error Can't Convert \"2201010001\" to long. You are probably not alone, as of Jan. &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/01\/01\/exchange-fip-fs-scan-engine-failed-to-load-cant-convert-2201010001-to-long-1-1-2022\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,1547],"tags":[869,47],"class_list":["post-22789","post","type-post","status-publish","format-standard","hentry","category-issue","category-software","tag-exchange","tag-issue"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=22789"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22789\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=22789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=22789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=22789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}