Event viewer records the following in the System log:
- A service was installed in the system.
- Service Name: hdlpflt
- Service File Name: system32\DRIVERS\hdlpflt.sys
- Service Type: Kernel mode driver
- Service Start Type: system start
- Service Account:
- File System Filter 'hdlpflt' (6.1, yyyy-mm-dd T hh:mm:ss.000000000Z) has successfully loaded and registered with Filter Manager.
- A service was installed in the system.
- Service Name: McAfee DLP Endpoint Service
- Service File Name: "C:\Program Files\McAfee\DLP\Agent\fcags.exe"
- Service Type: user mode service
- Service Start Type: Auto start
- Service Account: LocalSystem
- File System Filter 'hdlpflt' (Version 6.1, yyyy-mm-dd T hh:mm:ss.000000000Z) unloaded successfully.
This system log shows that the DLP Endpoint agent installation completed, service was started successfully, and it rolled back immediately.