To verify that the ML Protect scanning feature is installed and working correctly, you can schedule a scan, then check that it completed successfully. Each time ML Protect completes a scan of a file, it creates an entry in the AdaptiveThreatProtection_Activity.log file with an ID that indicates the result of the scan.
AdvancedThreatProtection_Activity.log is saved at this location by default: %ProgramData%\McAfee\Endpoint Security\Logs
ML Protect ID | Description |
|---|---|
0 | Process found with clean reputation |
1 | Process found with unknown reputation |
2 | Time out |
3 | Unknown failure |
4 | Unsupported version of ML Protect |
5 | Not enough events |
6 | Managed product request does not scan |
7 | Phase 1 remediation is over |
8 | Process terminated |
9 | No network detected |
10 | Process restarted multiple times during a short period of time and no scan was performed |
11 | Process is cached with unknown reputation |
12 | ETW session is not available |
13 | Multiple DLL scan requests are issued for the same process |