This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SAV service hangs after installing KB4493472

Hello,

Last night one of my Windows 2008R2 servers hung after installing Microsoft patch KB4493472. After initial examination I discovered that SAV service was logging lots of error messages in event log. Event IDs : 7022 (service hang), 80, 81, 83, 85, 82, 566, 608, 592.

The server became unresponsive, no rdp, no file share access, Ctrl Alt Delete not working.

I rebooted the server in to safe mode and disabled the Sophos services. After this, I was able to reboot normally. Then I uninstalled Sophos, rebooted and tried to install again but this time the installation didn't complete and the server hang again. I rebooted again in safe mode, disabled services, rebooted and uninstalled sophos again. After checking the Windows logs I realised that the server had installed update KB4493472 last night. I uninstalled the patch, rebooted and installed sophos again. This time there was no problem.

Currently we are trying to unauthorise KB4493472 on our update system.

Is there any known issues with KB4493472 on Windows Server 2008R2?

Thank You.



This thread was automatically locked due to age.
  • From https://community.sophos.com/kb/en-us/133945 :

    add the following Windows exclusions to all  Anti-virus and HIPS  policies in your Enterprise Console:

    %programfiles%\Sophos\Sophos Anti-Virus

    %programfiles(x86)%\Sophos\Sophos Anti-Virus

    This will prevent the issue occurring on any computers where the Windows update is installed but the computer has not been rebooted.

    From Twitter : [UPDATE} We have released an update for our Enterprise Console users that will automatically add Windows exclusions to all Anti-virus and HIPS policies in your Enterprise Console.

    Anyone know if this fix only apply for the reboot problem or if it's 100% Ok compatible with new windows updates ? 

    Can i reinstall sophos without removing windows updates if i have excluded sophos directories ?

  • The KB has been updated again:

    Note:

    • This automatic update will take place on all supported versions of Enterprise Console, version 5.4.1 and above.
    • This update will only occur when you're Sophos Update Manager (SUM) performs an update as part of the configured scheduled update interval. To receive this update as soon as possible you may need to reduce the schedule.
    • For Enterprise Console 5.4.1, the modified policy will not automatically be sent to your computers. This will result in a 'Differs from Policy' status being alerted against your managed computers. To resolve you will need to push out the policy to your computers via the 'Comply with Group Anti-Virus and HIPS policy' option.
    • If you already have exclusions in place matching those listed above, we will not perform this action.
    • Sophos will automatically remove the exclusions at a later date. This article will be updated to advise when this takes place.
    • Sophos recommends enabling enhanced tamper protection on your managed computers. For further information see Sophos Endpoint Defense: How to enable Enhanced Tamper Protection.

    So basically, it's just saying those 2 folders will be pushes to everyone endpoints exclusions automatically.

  • I've excluded the folders and still had the issue, so it's not a 100% fix (actually haven't had a single case that this "fix" has solved)

  • Thanx for you quick answer .

     

    So i think i'll have to uninstall the updates :(

  • What were the paths you put in exactly (did they have a trailing backslash for example as they need one) and did they make it to machine.xml (\ProgramData\Sophos\Sophos Anti-Virus\Config\machine.xml)?

  • Do you have any positive feedback excluding sophos directories ?

  • Hmm, didn't know it stored the exclusions there, but yeah it's there. And yeah it has the final \. It won't let you add it without it.

  • And what happened after putting exclusions for you ? it's only fixing reboot issue ?

  • I mentioned a few posts ago it had no effect.

  • Hello all,

    an update that will automatically add the following Windows exclusions
    I wasn't aware that such a feature exists, apparently (For Enterprise Console 5.4.1, the modified policy will not automatically be sent) it has gradually been implemented.

    Anyway, they haven't been added to all AV policies - while this is expected for policies that have exclusions in place matching those listed the exclusions are missing from some of the policies. Couldn't find a pattern though.

    Christian