Event ID/Source search
Keyword searchExample: Windows cannot unload your registry file
Event ID: 257 Source: McLogEvent
Blocked by access protection rule. Access to object \REGISTRY\USER\S-1-5-21-1269120271-1817062919-1859928627-1091\Software\Microsoft\Internet Explorer\Security\P3Global\Enabled was blocked by rule Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings.
|English: Request a translation of the event description in plain English.|
This event simply records the details for an instance where the McAfee security software blocked a potential malware from performing action specifically denied by the configured security settings.
The event will specify the "object" that was the target (it could be a file, a registry key, etc) and the rule currently configured that was triggered.
From a support forum: "Go into your access protection rules and disable monitoring of the rules in question. There are 2 check boxes...block and report. When set to block & report, you'll see the log entry but it will say "blocked by access protection rule...". When only report is set, you'll see "would be blocked...". If you uncheck both, you won't get the logging. If you just block and don't report, you'll get the blocking without reporting (bad idea)."
According to EV100249 (SAFeService.exe used by GroupShield is blocked by VirusScan Access Protection Rule), SAFeService.exe should be added to the list of processes to exclude in VirusScan Enterprise.
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated