This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SAV service hangs after installing KB4493472

Hello,

Last night one of my Windows 2008R2 servers hung after installing Microsoft patch KB4493472. After initial examination I discovered that SAV service was logging lots of error messages in event log. Event IDs : 7022 (service hang), 80, 81, 83, 85, 82, 566, 608, 592.

The server became unresponsive, no rdp, no file share access, Ctrl Alt Delete not working.

I rebooted the server in to safe mode and disabled the Sophos services. After this, I was able to reboot normally. Then I uninstalled Sophos, rebooted and tried to install again but this time the installation didn't complete and the server hang again. I rebooted again in safe mode, disabled services, rebooted and uninstalled sophos again. After checking the Windows logs I realised that the server had installed update KB4493472 last night. I uninstalled the patch, rebooted and installed sophos again. This time there was no problem.

Currently we are trying to unauthorise KB4493472 on our update system.

Is there any known issues with KB4493472 on Windows Server 2008R2?

Thank You.



This thread was automatically locked due to age.
Parents
  • Hi Everyone, 

    The reported issue is currently being investigated.

    If you have not yet performed the update we recommend not doing so. If you have performed the update but not yet rebooted we recommend removing the update prior to rebooting.

    If you have performed the update and have rebooted, triggering the issue:

    1. Boot into safe mode
    2. Disable the Sophos Anti-Virus service
    3. Boot into normal mode
    4. Uninstall the Windows KB
    5. Enable the Sophos Anti-Virus service
      • If enabled, Tamper Protection will need to be disabled to re-enable the service 

     

    Please follow the below KBA for more updates and workaround.

    Sophos Central Endpoint and SEC: Computers fail/hang on boot after the Microsoft Windows April 9, 2019 update

    Regards,

    Gowtham Mani
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • From https://community.sophos.com/kb/en-us/133945 :

    add the following Windows exclusions to all  Anti-virus and HIPS  policies in your Enterprise Console:

    %programfiles%\Sophos\Sophos Anti-Virus

    %programfiles(x86)%\Sophos\Sophos Anti-Virus

    This will prevent the issue occurring on any computers where the Windows update is installed but the computer has not been rebooted.

    From Twitter : [UPDATE} We have released an update for our Enterprise Console users that will automatically add Windows exclusions to all Anti-virus and HIPS policies in your Enterprise Console.

    Anyone know if this fix only apply for the reboot problem or if it's 100% Ok compatible with new windows updates ? 

    Can i reinstall sophos without removing windows updates if i have excluded sophos directories ?

Reply
  • From https://community.sophos.com/kb/en-us/133945 :

    add the following Windows exclusions to all  Anti-virus and HIPS  policies in your Enterprise Console:

    %programfiles%\Sophos\Sophos Anti-Virus

    %programfiles(x86)%\Sophos\Sophos Anti-Virus

    This will prevent the issue occurring on any computers where the Windows update is installed but the computer has not been rebooted.

    From Twitter : [UPDATE} We have released an update for our Enterprise Console users that will automatically add Windows exclusions to all Anti-virus and HIPS policies in your Enterprise Console.

    Anyone know if this fix only apply for the reboot problem or if it's 100% Ok compatible with new windows updates ? 

    Can i reinstall sophos without removing windows updates if i have excluded sophos directories ?

Children