I have the impression, that it is the blade of the Antibot.
I am not sure.
The Cluster object, in the "Antibot/Antivirus" section is set to DETECT ONLY, but other than that, we have an explicit rule in the TP section, and I'm not sure, if the CLUSTER, omits its global setting in the object and gives more importance to what is "explicitly" defined by rules.
The explicit TP rule has an OPTIMIZED profile, and that profile, as I see, has several "PREVENT" enabled.
Maybe this could be the root-cause of the problem.
I am not sure about this behavior.