Views:

To address this issue:

  1. Stop the Aegis TMBMSRV service.
    • Using the Services MMC (services.msc), stop the Trend Micro Unauthorized Change Prevention Service.
    • You can also run sc stop tmbmservice on a command prompt to stop the service.
  2. Open the Registry Editor.
     
    Always back up the whole registry before making any modifications. Incorrect changes to the registry can cause serious system problems.
  3. Look for the hive [HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\Aegis].
    For a 64-bit server OS: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\TrendMicro\AEGIS\RmSysEventDebugFlags
  4. Locate the string "RmSysEventDebugFlags" and add a dword value 000f0001.
    "RmSysEventDebugFlags"=dword:000f0001 will remove the file hooking from AEGIS. This means that AEGIS service will no longer receive the any file events.
  5. Restart the machine.
 
Add the .bkf extension in the exclusion list for real time scan.