After installing OfficeScan (OSCE) 11.0 and deploying the agent to the machines on the network, client machines' OfficeScanNT RealTime Scan (ntrtscan.exe) or OfficeScanNT Monitor (PccNTMon.exe) processes crash.
Debugging the product gives logs with error messages similar to either of the following:
2014 05/28 12:19:18 [17d4 : 1c00] (00) (D) [-IO-][PccNTMon.exe]OsceIntegration::CConfigureManager::IsRunAsOfficeScanClient - ::RegOpenKeyExW failed with Windows error code: . - [oicm_ConfigureManager.cpp(421)]
2015 01/27 14:53:58 [13f0 : 100c] (00) (D) [-REAL-][ntrtscan.exe]OsceIntegration::CConfigureManager::IsRunAsOfficeScanClient - ::RegOpenKeyExW failed with Windows error code: . - [oicm_ConfigureManager.cpp(421)]
This issue has been known to occur due to the following reasons:
- The customer had previously installed Worry-Free Business Security (WFBS) and then removed it to install OfficeScan Corporate Edition (OSCE). Some changes to the Windows registry by WFBS may cause the OSCE real-time scan to crash.
- The Visual C++ runtime library may trigger a "bad locale name" runtime exception error while the OfficeScan ICRCHdler sets the locale for writing debug logs.
- Ntrtscan.exe may stop after starting the OfficeScan NT RealTime Scan service due to an extra format specified when writing to the debug log.
Fix the error by making sure that the OSCE servers and client machines have been patched to at least OSCE 11.0 Service Pack 1 (SP1) Build 2995-r1 or later. The latest Service Packs and Product Patches for OSCE are available at the OSCE Download Center.
If the issue is not resolved by updating the OSCE servers and clients to the latest build, then check whether the customer had previously installed WFBS. If they did, edit the OSCE client’s registry.
- Unload the OfficeScan client from the system tray.
- Open the Services console (services.msc) and temporarily change the Startup Type of the following services to "Disabled".
- OfficeScan NT Listener
- Trend Micro Unauthorized Change Prevention Service
- Open the Windows Registry Editor (regedit.exe).
- Search for the following registry value:
"RCS"=dword:000000CA (decimal 202)
- Change the value of "RCS" to dword:00000065 (decimal 101).
- Exit the Registry Editor.
- Open the Services console (services.msc) and change the Startup Type of the following services to the following:
- OfficeScan NT Listener to Automatic
- Trend Micro Unauthorized Change Prevention Service to Manual
- Reload the OSCE client to check if the ntrtscan.exe and PccNTMon.exe process both stay started.
If they did not install WFBS previously, or if the issue still persists after performing the steps above, then contact Trend Micro Technical Support to request for assistance in debugging the product.