This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

savscanD 100% cPU ant talpa not installed

Hello,

 

I'm just install Sophos antivirus free version on my Debian 8.

I activate Check on-access scanning option.

First problem:

this process use 100% cpu 

version installed:

 

Copyright 1989-2016 Sophos Limited. All rights reserved.
Sophos Anti-Virus = 9.12.3
Build Revision = 2629392
Threat detection engine = 3.65.2
Threat data = 5.34
Threat count = 12413902
Threat data release = mar. 29 nov. 2016 00:00:00
Last update = sam. 17 déc. 2016 19:18:46 CET

 

 

Second problem:

 I received mail whit this indication: "The threat data is out of date and should be updated".

 

What this problem ???

Have you one idea for resolve my problems ?

 

Thank's



This thread was automatically locked due to age.
Parents Reply Children
  • Hello christophe rousseau,

    I'm not sure what the issue is or if there is perhaps more than one.

    talpa not installed
    indeed? If not on-access scanning wouldn't be enabled.
    Or is The threat data is out of date ... your second problem?  If so, what's the output of ./savconfig --all get ? And what happens when you request an update with ./savupdate ?

    Christian

  • thank' you for your response.

     

    this result of first commande.

    [code]

    ./savconfig --all
    Email: root@localhost
    EmailDemandSummaryIfThreat: TRUE
    EmailLanguage: English
    EmailNotifier: TRUE
    EmailServer: localhost:25
    EnableOnStart: FALSE
    ExclusionEncodings: UTF-8
    EUC-JP
    ISO-8859-1
    LogMaxSizeMB: 100
    NotifyOnUpdate: FALSE
    PrimaryUpdateSourcePath: sophos:
    PrimaryUpdateUsername: FAVL3LPMS8733
    PrimaryUpdatePassword: ********
    UploadSamples: FALSE
    SendErrorEmail: TRUE
    SendThreatEmail: TRUE
    UINotifier: TRUE
    UIpopupNotification: TRUE
    UIttyNotification: TRUE
    UpdatePeriodMinutes: 60
    NamedScans NOT CONFIGURED
    LiveProtection: ENABLED
    ScanArchives: MIXED

    [/code]

    second command make that:

     

    [code]

    ./savupdate
    Successfully updated Sophos Anti-Virus from sdds:SOPHOS[/code]

  • Hello christophe rousseau,

    thanks, seems to be ok. Should have mentioned the ./savdstatus command. If it says ... active and on-access scanning is running you should be fine. Did you again get a mail about the detection data?

    Christian

  • Hello,

     

    I obtain this result when I lauch ./savdstatus

                        active but on-acces scanning is not running

    Yes I received on mail.

     

     

    christophe.

  • Hello christophe,

    please see chapter 5 in the Startup Guide, on-access should be enabled by default, try to enable on-access, start the service if necessary. If it doesn't work there might be an error message which gives a hint what's wrong.

    Christian

  • ok I make config for check on-acces scanning and start. sav-protect

     

    Now I launch "htop" and I see 2 process savscand use 200% cpu.

     

    it's really creazy......

     

    I'm not say when resolve my  problem...

     

  • Hello christophe,

    this is definitely not as it should be. I'm not a fan of indiscriminately uninstalling and reinstalling but it looks like the issue was there from the start. Two savscand processes are correct but they shouldn't grab all the CPU available (in fact they should only consume an insignificant amount). So please uninstall, reboot, check if the Sophos processes are gone, and then ry to reinstall. Note any errors and check the savscand process(es). If the issue persists ... well, hopefully it doesn't.

    Christian

  • I mad this operation:

     

    1) uninstall Sophos av.

    2) reboot

    3) see if one process avscand = no.

    4) install version=ok.

    5) reboot

    6) after  2 hours VM run, I see htop and. 2 process savscan run 100%

     

    I think I will have to uninstall sophos that I appreciate very much.

    Really not cool