I have SEP 2012 installed on a Windows 2008 Ent R2 server, running SEPM for our organization.
I have a series of event logs that keep popping up aveyr minute or two. It looks like a process called USNWash.exe is trying to start, which in turn starts conhost.exe, and then both terminate immedietly. It is causing a lot of chatter in my security event log on this server.
What is USNWash.exe? It is part of SEP, I just cannot tell what it does or why it keeps trying to spawn. Here you can see both processes start, then immedietly terminate. This happens every minute or so:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/22/2013 12:06:08 PM
Event ID: 4688
Task Category: Process Creation
Level: Information
Keywords: Audit Success
User: N/A
Computer: xxxxxxx
Description:
A new process has been created.
Subject:
Security ID: SYSTEM
Account Name: xxxxx
Account Domain: xxxxxx
Logon ID: 0x3e7
Process Information:
New Process ID: 0x1980
New Process Name: D:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\USNWash.exe
Token Elevation Type: TokenElevationTypeDefault (1)
Creator Process ID: 0x1114
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/22/2013 12:06:08 PM
Event ID: 4688
Task Category: Process Creation
Level: Information
Keywords: Audit Success
User: N/A
Computer: xxxxx
Description:
A new process has been created.
Subject:
Security ID: SYSTEM
Account Name: xxxxx
Account Domain: xxxxx
Logon ID: 0x3e7
Process Information:
New Process ID: 0x1efc
New Process Name: C:\Windows\System32\conhost.exe
Token Elevation Type: TokenElevationTypeDefault (1)
Creator Process ID: 0x174
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/22/2013 12:06:08 PM
Event ID: 4689
Task Category: Process Termination
Level: Information
Keywords: Audit Success
User: N/A
Computer: xxxxx
Description:
A process has exited.
Subject:
Security ID: SYSTEM
Account Name: xxxxx
Account Domain: xxxxx
Logon ID: 0x3e7
Process Information:
Process ID: 0x1980
Process Name: D:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\bin\USNWash.exe
Exit Status: 0x40000001
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/22/2013 12:06:08 PM
Event ID: 4689
Task Category: Process Termination
Level: Information
Keywords: Audit Success
User: N/A
Computer: xxxxx
Description:
A process has exited.
Subject:
Security ID: SYSTEM
Account Name: xxxxx
Account Domain: xxxxx
Logon ID: 0x3e7
Process Information:
Process ID: 0x1efc
Process Name: C:\Windows\System32\conhost.exe
Exit Status: 0x0
Thanks!