F-Prot triggers huge amounts of Security Audit Failures on Windows XP



Hello,

I have F-prot version 6 (Anti-Virus) loaded on several Windows XP
systems in our lab. The Windows XP systems have been configured for
security auditing (per NISPOM Ch. 8 requirement). Using event viewer
to look at the security logs, I'm seeing 8500+ security messages for
two days worth of usage, of which 94% of them read exactly like the
printout below.

I'm not sure, but it seems like FPAVserv (f-prot process) might
running with the user's rights and not running as a system service.

Any thoughts on how I can fix this?

Thanks,

Rob Ramsey
Colorado

Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 2/7/2008
Time: 10:37:39 PM
User: STK-NODE\dave
Computer: STK-NODE
Description:
Object Open:
Object Server: SC Manager
Object Type: SERVICE OBJECT
Object Name: FPAVServer
Handle ID: -
Operation ID: {0,2766732}
Process ID: 740
Image File Name: C:\WINDOWS\system32\services.exe
Primary User Name: STK-NODE$
Primary Domain: WORKGROUP
Primary Logon ID: (0x0,0x3E7)
Client User Name: dave
Client Domain: STK-NODE
Client Logon ID: (0x0,0x281EF9)
Accesses: Query status of service
Start the service

Privileges: -
Restricted Sid Count: 0


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

8760 messages of event type 560 out of 8855 events
6 Feb 2008 11:24:40PM - 8 Feb 2008 3:16:52PM
.



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • Re: The Myth of the secure Mac
    ... OEM Windows XP Home goes for a bit under $100. ... >> secure than Home. ... Though this really has nothing to do with security. ... Microsoft counts on third-party developers to provide more ...
    (comp.sys.mac.advocacy)
  • Re: Linux client in Windows Domain (Security Advice)
    ... I have a windows environment and all clients are XP controled with strict security measures controled via group policy etc. ... one of the other IT guys has a liux client that sits out side most of these systems. ... (You've probably worked out I'm a windows man with very basic Linux experience. ...
    (microsoft.public.windows.server.sbs)
  • SecurityFocus Microsoft Newsletter # 149
    ... MICROSOFT VULNERABILITY SUMMARY ... EveryBuddy Long Message Denial Of Service Vulnerability ... Intellitactics Network Security Manager ... Windows operating systems. ...
    (Focus-Microsoft)