1 Reply Latest reply on Aug 29, 2012 12:26 PM by bselles

    HKLM\SOFTWARE\McAfee\SystemCore\VSCore\DisableProcessImpersonation

      Howdy,

       

      I'm wondering if anybody can tell me what this registry key is for.  We are having issues with mcshield hogging cpu time and one of the things that I am seeing in SysInternals Process Monitor is mcshield trying to open this registry key that doesn't exists repeatedly.  The log looks like this and it can happen many many times in the course of a single second(I counted over ten in just 3 tenths of a second):

       

      12:20:02.7782592 PM mcshield.exe 3344 RegOpenKey HKLM\SOFTWARE\McAfee\SystemCore\VSCore SUCCESS Desired Access: Read

      12:20:02.7782860 PM mcshield.exe 3344 RegQueryValue HKLM\SOFTWARE\McAfee\SystemCore\VSCore\DisableProcessImpersonation NAME NOT FOUND Length: 144

      12:20:02.7782993 PM mcshield.exe 3344 RegCloseKey HKLM\SOFTWARE\McAfee\SystemCore\VSCore SUCCESS

       

      There other operations similar to this that is just repeatly doing, other registry keys and files that it opens.  Is there some cache setting that limits this or is this a desired behavior.

       

      Thanks

       

      dbl