1 Reply Latest reply on Apr 14, 2011 1:35 PM by georgec

    windows 2003 server backup,  access protection log

      While doing windows 2003 server backup, I got the following logs in the access protection log. Any explain for this please

       

      Blocked by Access Protection rule  SERVER2003-1\Admin            C:\WINDOWS\system32\ntbackup.exe    C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\AgentEvents\20110405074826078968600000BF0.xml  Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings    Action blocked : Create

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe         Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\ctfmon.exe   Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

       

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\explorer.exe   Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\services.exe Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\smss.exe     Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\svchost.exe  Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

       

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtServicePackUninstall$\winlogon.exe Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read

      Would be blocked by Access Protection rule  (rule is currently not enforced)             SERVER2003-1\Admin    C:\WINDOWS\system32\ntbackup.exe            \Device\HarddiskVolumeShadowCopy1\WINDOWS\$NtUninstallKB956572$\services.exe    Anti-virus Standard Protection:Prevent Windows Process spoofing     Action blocked : Read