I would like to suggest that Symantec stop logging unauthorized access blocks in the the Norton Protection Tamper Protection history, or at the very least change the severity from Medium to Info. ManFromOz has posted an eloquent argument for this here in a thread titled Is Tamper Protection Crying Wolf?
The Behavior and Security Heuristics update of 09-Sep-2013 has resulted in a huge upswing in the logging of these unauthorized access blocks. Norton Product Tamper Protection makes no distinction between the severity of an attempted read/write/edit/delete of Norton files by malware vs. legitimate Windows processes (e.g., svchost.exe, services.exe, iexplore.exe, dfrgntfs.exe) and this has caused unnecessary alarm for many users who assume that these blocks mean that their system is under constant attack.
Here are five recent threads started in the NIS/NAV forum on this topic since the heuristics update:
10-Sep-2013 Unauthorized Access Blocked Question by Calls
11-Sep-2013 Unauthorized Access Blocked (open file) - Major Security Breach in Norton? by melen
13-Sep-2013 Unauthorized Access Blocked (open file) - Mozilla by kermit
18-Sep-2013 Norton Internet Security: Unauthorized Access Blocked Notification by Rico_NORTIN
27-Sep-2013 Unauthorized Access Blocked by emirpk
------------
MS Windows Vista Home Premium 32-bit SP2 * Firefox 24.0 * IE 9.0 * NIS 2013 v. 20.4.0.40
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS
I agree . Get rid of these messages. They go on all day and every few seconds. Only on a few days have they've been on for a half a day. I have to go to Live Updates or Scan history or something else specific as recent history has only the Unauthorized Access Blocked (Open File) messages. VERY ANNOYING!!!!!!! Also if I go to Perfomance Alert, these too are numerous for High CPU Usage and it's related to the above messages as the Acotr in each of thes is C:/WINDOWS/SYSTEM32/DFRG.
Holly