DLP agent showing block pop up message when right click on any file on the local drive, even if the Local Drive scanning is unchecked.
Other Symptoms - every time the drive is mapped it will show scanning box even if the Network Shares is unchecked.
Obfuscated edpa_ext0 logs shows :-
Dim Detection Request Details :
Process Id : 5164
Process Path : \Device\HarddiskVolume1\Windows\explorer.exe
Application Name : explorer.exe
User : <username>
Domain : <domain>
Time Stamp : 09/08/2011 11:51:40
Dim Event Type : File System
DIM File Detection Request Details :
file: C:\Users\<username>\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
]09/08/2011 11:51:40 | 2136 | INFO | MessageLogger | MESSAGETYPE_SCHEDULE_DETECTION MESSAGESOURCE_DETECTION_CACHE 09/08/2011 11:51:40 [req#84 DetectionThreadPriority=NORMAL CrackingProcessPriority=NORMAL]
09/08/2011 11:51:40 | 2136 | INFO | MessageLogger | MESSAGETYPE_DETECTION_RESULT MESSAGESOURCE_DETECTION 09/08/2011 11:51:40 [req#84 SUCCESS has incidents]
...
09/08/2011 11:51:40 | 2136 | INFO | MessageLogger | MESSAGETYPE_RESPONSE_POPUP MESSAGESOURCE_POSTPROCESSOR 09/08/2011 11:51:40 [req#84 response#0]
09/08/2011 11:51:40 | 2136 | INFO | MessageLogger | MESSAGETYPE_DETECTION_RESPONSE MESSAGESOURCE_POSTPROCESSOR 09/08/2011 11:51:40 [
Request Id #84 SUCCESS prevent
Scan Time : 31 ms]09/08/2011 11:51:40 | 2136 | INFO | MessageLogger | MESSAGETYPE_DETECTION_REQUEST MESSAGESOURCE_FILE_SYSTEM_CONNECTOR 09/08/2011 11:51:40 [
Request Id #91
Detection Request Details :
Session Command : Single Request
Request Type : Data In Motion Request
Check On the Endpoint server if the following is added under Add Monitoring Filter
Enforce > System > Servers > Overview > {endpoint server} > Configure > Agent Monitoring
Ignore CD/DVD, Local Drive type = *
If the above filters are not added then add the following in the Add Monitoring Filter
Ignore CD/DVD, Local Drive type = *.ini