If you install a McAfee hotfix, VSE Access Protection (AP) can block the hotfix installer from writing to a log file.
IMPORTANT: This block action does not prevent the hotfix from being installed.
The AP event indicates the log file was protected from being written to by the hotfix's executable process.
Example
[date/time] Blocked by Access Protection rule NT AUTHORITY\SYSTEM C:\ProgramData\McAfee\Common Framework\Current\VIRUSCAN8800\HotFix\793640\0000\VSE88HF793640.exe C:\ProgramData\McAfee\Common Framework\Current\VIRUSCAN8800\HotFix\793640\0000\Patch.log Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings Action blocked : Write
Where:
- Blocked by Access Protection rule
The rule in question is set to Block. (It is also set to Report because it is in the log and an Event was created.)
- C:\ProgramData\McAfee\Common Framework\Current\VIRUSCAN8800\HotFix\793640\0000\VSE88HF793640.exe
The process that is blocked. The hotfix number is unique, and not a predictable name.
- C:\ProgramData\McAfee\Common Framework\Current\VIRUSCAN8800\HotFix\793640\0000\Patch.log
The file/folder that was protected. This log file contains (or would contain) only summary information for the hotfix installation.
- Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings
The name of the specific AP rule that blocked the action taken by the process. To avoid reoccurrence of this violation, this rule would be edited to add an exclusion for the affected process name.
- Action blocked : Write
The operation that the rule blocked.