This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos registry acces performance

Hello @all,

is there a posibility to exclude files and espacialy the registry in a real time envirement.

in our productive area are computers which works with a real time envirement. I found there no way how sophos on access Scan didn't slow down the speed of the PC without stopping the OnAccessScan service.

for example:
we have some PCs who takes photos of a product and analyse it's geometrie. If the OnAccessServices is stopped, the analyse of the picture takes about 12 to 20 ms in case of an active service it takes about 500ms. I found out by the help of processmonitor(of sysinternals) that writhing registry access needs about 10 to 100 times longer to do the same job.

an other example:

some pc in our envirement are responsible for chemical analysis by the help of an web frontend witch works togehter with an Software SPS-Solution and an IIS webserver Version 5.x who controls ans visualize the hole process. at computers with WinXP SP2 the exclusions works fine and it works but the same didn't work on WinXP SP3.

All in all this mashines producess about 500.000 events(monitored by processmonitor of sysinternals) in about  minutes. From mashine to mashine it differences of about 100.000 file or registry access in about 5 minutes by writhing or reading access.

Has someone a goog idea?
All is managed by sophos enterprise console of version 4.7 and an installed AntiVirus Scan of Version 9.7.
the most directories of the progrmms itselfs are exclude by OnAccessScan. Is there a posibility to exclude the Registry like HKLM and it's subdirectories.
By the help of the exclusion of file-directories somes of the mashines works better but not everyone. the OnAccessScan is configured to scan files while writhing them on hdd.

I hope you can help me! I'm dispaired because I worked on this problems since 3 month.

:18981


This thread was automatically locked due to age.
  • HI,

    Under on-access there are a number of sub-components.  

    Have you tried turning off suspicious behavior scanning under the HIPS runtime options?  Does that help?

    Regards,

    Jak

    :18987
  • Hy,

    I've tested different options at ScanOnAcces like rename or reading or writhing the files by default it was reading but writhing is the better option.

    I've configured it that it just scan for viruses and nothing other... no rootkit and PUA scanning.

    If the sophos Antivirus service is stopped all works fine but that is'n t the solution.
    Also exclusion of the directory where the registryfiles storred didn't help anythink.

    :18997
  • Hi,

    But have you tried turning off suspicious behaviour that can be quite intensive, depending on what the application being monitored is doing?  SAVService will monitor registry operations with this enabled.  It will also monitor system files being changed, files being opened with write flags, processes being created and killed, etc..

    Regards,

    Jak

    :18999