This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

what to do when computer is slow

The difference after the installation of Sophos Endpoint (linked to the central) is big , when you have the Welcome message of Windows, we can wait 30 seconds and then start  it



This thread was automatically locked due to age.
  • I think you will not get it noticeably faster, and probably wasting your time trying to tune something.

    Sophos has over 30 processes, belonging to a dozend services, depending on some other and so on.

    We're living with it, drinking more coffee while we wait the few seconds in the morning.

  • This should change considerably soon, I understand that Sophos Anti-Virus component is going to be removed soon, that will remove:

    4 Drivers:

    1. savonaccess
    2. sdcfilter
    3. swi_callout
    4. SophosBootDriver

    6 User mode services:

    1. SAVService
    2. SAVAdminService
    3. Sophos Device Control Service
    4. Sophos Web Control Service
    5. swi_filter
    6. swi_service

    2 Processes:

    1. swi_fc.exe
    2. savapi.exe

    I think that the following services are also going to be removed as well around the same time and become just processes:

    1. Sophos Clean Service
    2. Sophos Safestore Service
    3. Sophos AutoUpdate Service

    Something to look forward to.

  • As a test, if you exclude in the threat protection policy 

    C:\

    Does that restore the time?  This is just a quick test to see if exclusions would at least help.It is useful info to know and a very quick test.

    As a check, the C:\ exclusion should end up in the reg value OnAccessExcludeFilePaths under:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Scanning\Config

    One thing to mention, I suppose, if you are using roaming/remote profiles, excluding remote files as a test might also be worth doing.

    Disabling remote file scanning in policy will set the DWORD OnAccessExcludeRemoteFiles to 1 under the same key.

    Please report back how that test affected the time.  You can create a new Threat Protection policy in Central and link just your computer to it.