SEP 用戶端一直產生ccSvcHst-*.dmp檔案,每一個都1點多GB,一天可能有1個以上

C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Install\Logs下,
會有ccSvcHst-*.dmp檔案產生,每一個都1點多GB,一天可能有1個以上,這個.dmp檔到底是那個設定所產生的,即便我把logs目錄設定唯讀,還是會寫入。而且我還刪不掉。

这个问题是RU5版本的已知问题

Title
CCSvcHst.exe generates multiple process dumps in ProgramData exhausting disk space 
 
Issue

CCSvcHst.exe appears to generating exceptions forcing a process dump in C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Install\Logs during a scan. Each dump is over 1GB and free disk space is quickly exhausted.
 
Environment

Windows 2012 R2
 
 
Cause

Certain archive files appear to be triggering the issue. Issue has been with some large archive files with older file dates (4+ years) in .zipx and .blb format.
 
Solution

Symantec is aware of the issue and is researching a solution.

Workaround:

Make an exception for the file extension or directory which has been identified through debugging.

Or…
1.Disable Tamper Protection.
2.Open a Command Prompt window.
3.del “C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Install\Logs\*.dmp"

or

del C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Install\Logs\*.dmp

4.Using regedit.exe, set the following values to 0 (zero):
HKLM\SOFTWARE(\Wow6432Node)\Symantec\Symantec Endpoint Protection\CurrentVersion\Common Client\Debug\CrashHandler\DumpOn*
5.Re-enable Tamper Protection.
6.Open a Command Prompt window.
7.cd “C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Bin"
8.smc -stop
9 .smc –start

【6 7 8 9 可如下執行】

請按鍵盤上【Windows 鍵】+【R鍵】→會跳出【執行】視窗

※ XP 請按【開始】→【執行】

在出現的視窗中,輸入【smc –stop】【smc –start】,並按下【確定】

clip_image005

 

【SEP FAQ】開啟SEPM時,若Windows系統出現錯誤訊息事件時,該如何處理呢?

問題描述:

當要啟動Symantec Endpoint Protection Manager服務時,會出現服務無法啟動的一般性錯誤或Apache Web服務錯誤之訊息。

解決方法:

此問題主要是因為SEPM Server本身為工作群組中的一份子或是SPEM的主機名稱並非設定為完整的網域名稱Fully Qualified Domain Name (FQDN)。

 

請依下列步驟來解決:

一. 工作群組(Workgroup)之環境:

1. 停止Symantec Endpoint Protection Manager Webserver之服務,此服務是依附在Symantec Endpoint Protection Manager服務上,所以會一併停止。

 

2. 備份下列路徑中之『httpd.conf』檔案。

C:\Program Files\Symantec\Symantec Endpoint Protection Manager\apache\conf\httpd.conf

 

3. 使用記事本(Notepad)編輯『httpd.conf』檔案。

 

4. 搜尋關鍵字【ServerName】,然後於其下方新增一行『ServerName <IP>:<Port>』。

(例如ServerName 192.168.1.168:8014,SEPM預設是使用port 8014)

 

5. 儲存httpd.conf檔案並關閉記事本(Notepad)。

 

6. 啟動Symantec Endpoint Protection ManagerSymantec Endpoint Protection Manager Webserver 之服務。

 

 

二. 網域(Domain)之環境:

請於內部DNS Server中加入一筆主機(A)紀錄來導向SEPM Server即可。

 

 

 

資料來源:http://www.symantec.com/docs/TECH187592

SEP Troubleshooting


How to enable Sylink debugging for the Symantec Endpoint Protection 11.x and 12.1 client in the Windows Registry

http://www.symantec.com/business/support/index?page=content&id=TECH104758


Symantec Endpoint Protection Client installation failed: error “"Pending system changes that require a reboot have been detected" "

http://www.symantec.com/business/support/index?page=content&id=TECH208775


Symantec Endpoint Protection 12.1: Best Practices for Disaster Recovery with the Symantec Endpoint Protection Manager

http://www.symantec.com/business/support/index?page=content&id=TECH160736