We have an environment of 220 computers managed by ePO Orchestrator, versions are deployed are VSE 8.8 patch 2 and Agent 4.6 patch 2. In November prepared some test computers (5) and changed sensitivity artermesis very low (by default) to high and actived check "scanning active processes" inside the scanning options in real time, looking image attached.
A few days after it appeared many events enabled 560 with access to McAfee objects at exactly the same time. This makes the security Windows registry is fulland a conventional user unable to log. See attached image.
I've since December with an incidence McAfee open but to this day I have no solution yet. I would appreciate comments from someone who has been through this experience.
Someone can help me?, someone can understand what are happen?
The normal sensitivity should be Medium. High and Very High are usually reserved for machines that you highly suspect are infected. However, I have to admit that I'm stumped why they would be correlated. I found this article and this one and this one from our knowledge base. If it were me, I'd do the following:
1. Uninstall VSE.
2. Reinstall VSE 8.8 patch 2.
4. Try again.
My thinking is that you might not actually be running patch 2. Or that you think you are but something might not be working right.
Either way. Call support back and ask for escalation.
Thank your for information. Well, i was thinking about known bug event 560, but in this case is different. The known bug event 560 was every "X" minutes continuously and with patch 2 I could see that was solved.
I tried reinstall VSE 8.8 patch 2 with same result.
I will try with sensitivity Medium...