I've seen similar issues in access protection logs when upgrading from VSE 8.8 w/P5 (22.214.171.1245) to VSE 8.8 Patch 7. Primarily I've seen it on a few XP systems we still have in our environment, but also a couple of W7 O/S's. Our Helpdesk has reported that these few systems are generating thousands of alert emails. The Access Protection Rule "Common Standard Protection: Prevent modification of McAfee Common Management Agent files and settings" is triggering "Action blocked: Write" alerts and references MFEVTPS.exe, NAPRDMGR.exe, VSTSKMGR.exe, MFEANN.exe, and SCAN32.exe. I've tried reference the "Installation Sequence Chart" here: McAfee KnowledgeBase - Intel Security - Security Bulletin: Protected resource access bypass vulnerability resolved in mu… but all of the upgrade options start with VSE 126.96.36.1998 which isn't my scenario.
It seems that this is caused by the fact I had DAT reputation disabled when DAT reputation was upgraded from 1.0.3 to 1.0.4. Installing VSE 8.8 patch 7 doesn't cause the problem, it just exposes it. Details can be found in KB86569, though I've had mixed results when testing the fix.