This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SAV service hangs after installing KB4493472

Hello,

Last night one of my Windows 2008R2 servers hung after installing Microsoft patch KB4493472. After initial examination I discovered that SAV service was logging lots of error messages in event log. Event IDs : 7022 (service hang), 80, 81, 83, 85, 82, 566, 608, 592.

The server became unresponsive, no rdp, no file share access, Ctrl Alt Delete not working.

I rebooted the server in to safe mode and disabled the Sophos services. After this, I was able to reboot normally. Then I uninstalled Sophos, rebooted and tried to install again but this time the installation didn't complete and the server hang again. I rebooted again in safe mode, disabled services, rebooted and uninstalled sophos again. After checking the Windows logs I realised that the server had installed update KB4493472 last night. I uninstalled the patch, rebooted and installed sophos again. This time there was no problem.

Currently we are trying to unauthorise KB4493472 on our update system.

Is there any known issues with KB4493472 on Windows Server 2008R2?

Thank You.



This thread was automatically locked due to age.
Parents
  • Does anyone know what the best practice is for W7 machines which already have this errant update?

    So far 15+ PC's have been affected at my workplace. The symptoms range between stuck at the Welcome screen or Configuring Updates or black screen of death! Google Chrome appears to suffer as it will not launch unless you un-installed and re-install.

    I have been Buttoning the PC, F8 for booting in Safe Mode with Cmd prompt and running "rstrui.exe" to get the Windows Restore point before these updates. Then when I eventually get a working system I'm disabling Microsoft updates! This is not best practice but if MS will insist on publishing updates more damaging than any Virus then that's the way it will stay.

    I'm surprised by the lack of news on the Internet about this problem. It must be affecting millions of users globally...?

Reply
  • Does anyone know what the best practice is for W7 machines which already have this errant update?

    So far 15+ PC's have been affected at my workplace. The symptoms range between stuck at the Welcome screen or Configuring Updates or black screen of death! Google Chrome appears to suffer as it will not launch unless you un-installed and re-install.

    I have been Buttoning the PC, F8 for booting in Safe Mode with Cmd prompt and running "rstrui.exe" to get the Windows Restore point before these updates. Then when I eventually get a working system I'm disabling Microsoft updates! This is not best practice but if MS will insist on publishing updates more damaging than any Virus then that's the way it will stay.

    I'm surprised by the lack of news on the Internet about this problem. It must be affecting millions of users globally...?

Children
No Data