The Endpoint Protection system log repeatedly displays "Already running process <Process ID> 'C:\<path to executable>' is affected by a change to the application rules."
search cancel

The Endpoint Protection system log repeatedly displays "Already running process <Process ID> 'C:\<path to executable>' is affected by a change to the application rules."

book

Article ID: 164872

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

The SEP client system log has a number of entries for various processes stating that it is "affected by a change to the application rules." The entries will appear similar to the following:

Already running process (PID:8344) 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' is affected by a change to the application rules.
Already running process (PID:9208) 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' is affected by a change to the application rules.
Already running process (PID:7100) 'C:\Program Files (x86)\Microsoft Office\Office15\lync.exe' is affected by a change to the application rules.

Cause

This log entry is a status message notifying you that the Symantec Endpoint Protection (SEP) Memory Exploit Mitigation (MEM) has changed it's rules for that application.
This message will appear if the process is running when MEM starts or if you remove the application from the list of applications that MEM protects.

Resolution

The log entry is informational only, no further action or follow-up is necessary.
For more information see - Memory Exploit Mitigation Settings