Endpoint Protection

 View Only
  • 1.  ccSvcHst.exe flooding security logs with failed write access

    Posted Feb 22, 2019 03:24 PM

    Only on my Domain Controller (Windows Server 2k8 R2) I am seeing my security logs flooded with Failed Audit Access events during every system scan. The process is ccSVCHst.exe (running as System) and it appears it is failing access on most everything under C:\Windows\*.

     

    I have checked the specific file permissions on a few of the failed items and System only has Read & Execute. The failed audit flag is showing ccSvcHst.exe is being denied WRITE accesses to each file which is why the event is being logged. I wanted to see why ccSvcHst.exe virus scanner is needing WRITE permissions to these files and how to best fix this. I did not want to exclude C:\Windows\* from the daily scans as that would be a large chunk of critical files not getting scanned. I also did not want to grant WRITE access to System for all those files until I found out why it needed WRITE accesses. 

     

    I have this same SEP scan running on my Windows 7 clients and it has none of these errors shown even though the NTFS file permissions are identical with only allowing System Read & Execute. 



  • 2.  RE: ccSvcHst.exe flooding security logs with failed write access

    Broadcom Employee
    Posted Feb 23, 2019 12:29 PM

    Hi There,

    If you could collect vpdebug logging as well as a Process Monitor (low alt) I could take a look at what is going on for you?  Open a case and I will take it over and we can get started on this. Just send me the case number.

    Thanks,

    John Owens