Hi
Any one know how to fix the McAfee Event 516 issue.
We followed the KB articles by McAfee (All three articles )
McAfee Corporate KB - Event ID 514/516/519, Warning, Process **\VSTSKMGR.EXE pid (XXXX) contains signed but untrusted co…
Also tried to Reinstalling McAfee products, but no luck
It's happening with All versions of Windows servers. Tried with latest McAfee agent and VSE versions., Still this is happening.
Our servers flooded this event and we don't have answer for this why it's happening. Multiple cases logged with support team but no proper solution.
No proper answer found for this issue. As per McAfee it's warning events, but it's creating entries in every policy enforcement and some machines DAT update.
All agent versions including 5.0.5 we have tried, no luck . This issue was happening from long time ,but there is no fix from McAfee.
Reinstalling McAfee products (Re installation not fixing the issue ) is not a solution for us. So far found the same event with more than 100 servers.
Example :
Process **\macompatsvc.exe pid (3040) contains signed but untrusted code, but was allowed to perform a privileged operation with a McAfee driver
Log Name: System
Source: mfehidk
Date: 8/16/2017 10:27:56 PM
Event ID: 516
Task Category: (256)
Level: Warning
Keywords: Classic
User: N/A
Computer: XXXXXXX.
Description:
Process **\macompatsvc.exe pid (3040) contains signed but untrusted code, but was allowed to perform a privileged operation with a McAfee driver.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="mfehidk" />
<EventID Qualifiers="33024">516</EventID>
<Level>3</Level>
<Task>256</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-08-16T20:27:56.206339200Z" />
<EventRecordID>305729</EventRecordID>
<Channel>System</Channel>
<Computer>XXXXXXX</Computer>
<Security />
</System>
<EventData>
<Data>\Device\mfehidk</Data>
<Data>**\macompatsvc.exe</Data>
<Data>3040</Data>
<Binary>00000000030030000001000004020081000000000000000000000000000000000000000000000000</Binary>
</EventData>
</Event>
----------------------------------------------
Log Name: System
Source: mfehidk
Date: 8/16/2017 10:20:55 PM
Event ID: 516
Task Category: (256)
Level: Warning
Keywords: Classic
User: N/A
Computer: XXXXXXX
Description:
Process **\mcdatrep.exe pid (7188) contains signed but untrusted code, but was allowed to perform a privileged operation with a McAfee driver.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="mfehidk" />
<EventID Qualifiers="33024">516</EventID>
<Level>3</Level>
<Task>256</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-08-16T20:20:55.501038000Z" />
<EventRecordID>305712</EventRecordID>
<Channel>System</Channel>
<Computer>XXXXXXXX</Computer>
<Security />
</System>
<EventData>
<Data>\Device\mfehidk</Data>
<Data>**\mcdatrep.exe</Data>
<Data>7188</Data>
<Binary>00000000030030000001000004020081000000000000000000000000000000000000000000000000</Binary>
</EventData>
</Event>
Thanks in advance .
Thanks
Dileep