Windows XP Community - XPHeads



F-Prot triggers huge amounts of Security Audit Failures on Windows XP

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 03-19-2008, 07:30 PM
Rob
 
Posts: n/a
F-Prot triggers huge amounts of Security Audit Failures on Windows XP
Hello,

I have F-prot version 6 (Anti-Virus) loaded on several Windows XP
systems in our lab. The Windows XP systems have been configured for
security auditing (per NISPOM Ch. 8 requirement). Using event viewer
to look at the security logs, I'm seeing 8500+ security messages for
two days worth of usage, of which 94% of them read exactly like the
printout below.

I'm not sure, but it seems like FPAVserv (f-prot process) might
running with the user's rights and not running as a system service.

Any thoughts on how I can fix this?

Thanks,

Rob Ramsey
Colorado

Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 2/7/2008
Time: 10:37:39 PM
User: STK-NODE\dave
Computer: STK-NODE
Description:
Object Open:
Object Server: SC Manager
Object Type: SERVICE OBJECT
Object Name: FPAVServer
Handle ID: -
Operation ID: {0,2766732}
Process ID: 740
Image File Name: C:\WINDOWS\system32\services.exe
Primary User Name: STK-NODE$
Primary Domain: WORKGROUP
Primary Logon ID: (0x0,0x3E7)
Client User Name: dave
Client Domain: STK-NODE
Client Logon ID: (0x0,0x281EF9)
Accesses: Query status of service
Start the service

Privileges: -
Restricted Sid Count: 0


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

8760 messages of event type 560 out of 8855 events
6 Feb 2008 11:24:40PM - 8 Feb 2008 3:16:52PM
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 03-19-2008, 08:06 PM
David H. Lipman
 
Posts: n/a
Re: F-Prot triggers huge amounts of Security Audit Failures on Windows XP
From: "Rob" <ramseyrt@gmail.com>

| Hello,
|
| I have F-prot version 6 (Anti-Virus) loaded on several Windows XP
| systems in our lab. The Windows XP systems have been configured for
| security auditing (per NISPOM Ch. 8 requirement). Using event viewer
| to look at the security logs, I'm seeing 8500+ security messages for
| two days worth of usage, of which 94% of them read exactly like the
| printout below.
|
| I'm not sure, but it seems like FPAVserv (f-prot process) might
| running with the user's rights and not running as a system service.
|
| Any thoughts on how I can fix this?
|
| Thanks,
|

< snip >


Interesting.

If you have to follow "NISPOM Ch. 8 requirement", you can't use F-Prot. It is an unapproved
anti virus solution.

The requirements are only for the DISA approved anti virus solutions under the DISA DoD wide
license which include only; Trend Micro, Symantec and MCafee.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-24-2008, 05:12 PM
Rob
 
Posts: n/a
Re: F-Prot triggers huge amounts of Security Audit Failures onWindows XP
On Mar 19, 2:06*pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
wrote:
> From: "Rob" <ramse...@gmail.com>
>
> | Hello,
> |
> | I have F-prot version 6 (Anti-Virus) loaded on several Windows XP
> | systems in our lab. *The Windows XP systems have been configured for
> | security auditing (per NISPOM Ch. 8 requirement). *Using event viewer
> | to look at the security logs, I'm seeing 8500+ security messages for
> | two days worth of usage, of which *94% of them read exactly like the
> | printout below.
> |
> | I'm not sure, but it seems like FPAVserv (f-prot process) might
> | running with the user's rights and not running as a system service.
> |
> | Any thoughts on how I can fix this?
> |
> | Thanks,
> |
>
> < snip >
>
> Interesting.
>
> If you have to follow "NISPOM Ch. 8 requirement", you can't use F-Prot. *It is an unapproved
> anti virus solution.
>
> The requirements are only for the DISA approved anti virus solutions underthe DISA DoD wide
> license which include only; *Trend Micro, Symantec and MCafee.
>
> --
> Davehttp://www.claymania.com/removal-trojan-adware.html
> Multi-AV -http://www.pctipp.ch/downloads/dl/35905.asp


Hello Dave,

Contractors are governed by DSS. Their regulation reads:

DoD 5220.22-M, February 28, 2006

8-305. Malicious Code. Policies and procedures to detect and deter
incidents caused by malicious code, such as viruses or unauthorized
modification to software, shall be implemented. All files must be
checked for viruses before being introduced on an IS and checked for
other malicious code as feasible. The use of personal or public domain
software is strongly discouraged. Each installation of such software
must be approved by the ISSM.

I have F-Prot listed in my protection profile and I have an ATO letter
in-hand. I haven't read anything on DSS's website stating that a
particular piece of anti-virus software has to be used; at least not
for our classification level.

Not that any of that matters anyway. Any thoughts on the message I
posted?

Thanks,

Rob
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 03-24-2008, 07:51 PM
Malke
 
Posts: n/a
Re: F-Prot triggers huge amounts of Security Audit Failures on Windows XP
Rob wrote:

>> From: "Rob" <ramse...@gmail.com>
>>
>> | Hello,
>> |
>> | I have F-prot version 6 (Anti-Virus) loaded on several Windows XP
>> | systems in our lab. *The Windows XP systems have been configured for
>> | security auditing (per NISPOM Ch. 8 requirement). *Using event viewer
>> | to look at the security logs, I'm seeing 8500+ security messages for
>> | two days worth of usage, of which *94% of them read exactly like the
>> | printout below.
>> |
>> | I'm not sure, but it seems like FPAVserv (f-prot process) might
>> | running with the user's rights and not running as a system service.
>> |
>> | Any thoughts on how I can fix this?


Contact F-Prot tech support. Although they may take a day or so to answer
(time difference between US and Iceland), my experience with them is that
they are very responsive.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 03-24-2008, 07:54 PM
David H. Lipman
 
Posts: n/a
Re: F-Prot triggers huge amounts of Security Audit Failures on Windows XP
From: "Rob" <ramseyrt@gmail.com>


|
| Hello Dave,
|
| Contractors are governed by DSS. Their regulation reads:
|
| DoD 5220.22-M, February 28, 2006
|
| 8-305. Malicious Code. Policies and procedures to detect and deter
| incidents caused by malicious code, such as viruses or unauthorized
| modification to software, shall be implemented. All files must be
| checked for viruses before being introduced on an IS and checked for
| other malicious code as feasible. The use of personal or public domain
| software is strongly discouraged. Each installation of such software
| must be approved by the ISSM.
|
| I have F-Prot listed in my protection profile and I have an ATO letter
| in-hand. I haven't read anything on DSS's website stating that a
| particular piece of anti-virus software has to be used; at least not
| for our classification level.
|
| Not that any of that matters anyway. Any thoughts on the message I
| posted?
|
| Thanks,
|
| Rob

Contractors are not covered under the DISA DoD wide anti virus contract. Therfore F-Prot
fits the bill.

I'll find out what I can about what you originally posted through my contacts.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:12 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74