On our RDS servers, occasionally we get a report of a virus and go to do a follow-up scan and it will not move past 1%. It is frozen at scanning for rootkits. Sometimes we can't even cancel the scan.
My theory is that one of the instances (maybe even "System") has a dialogue box open that nobody is clicking on - perhaps a prompt to clean the infection.
I stumbled upon a quick, no-reboot fix.
1. Shut down Protection (a bit scary, but not as bad as having a frozen AV product!)
2. Kill all WRSA processes.
3. Restart the WRSVC
4. Scan away!
We use Labtech to make killing the processes and restarting the service a bit easier. Also Process Explorer comes in handy to watch them all stop and restart.
Come to think of it, it is also possible that a -poll command sent in the background produced a dialogue box that nobody even sees to click on.
Solved
Webroot Scan Frozen - Fix
Best answer by JohnnyS
My name is Johnny and I work with Webroot Enterprise Support. I believe the server's policy may not be configured with servers in mind. We recommend using the Recommended Server Defaults but if you configure your own please confirue it along these guidelines:
Basic Configuration - Favor low disk usage over verbose logging - ON
Scan Schedule - Time - Choose a day and time that fits in with low disk io activity (i.e. every day at a specific time or only on weekends)
Scan Schedule - Hide the scan progress window during scheduled scans - OFF
Scan Settings - Scan archived files - OFF
Self Protection - Set to Minimum
Realtime Shield - Scan files when written or modified - OFF
Let me know if the policy is already configured this way I will need logs from the machine.
View originalBasic Configuration - Favor low disk usage over verbose logging - ON
Scan Schedule - Time - Choose a day and time that fits in with low disk io activity (i.e. every day at a specific time or only on weekends)
Scan Schedule - Hide the scan progress window during scheduled scans - OFF
Scan Settings - Scan archived files - OFF
Self Protection - Set to Minimum
Realtime Shield - Scan files when written or modified - OFF
Let me know if the policy is already configured this way I will need logs from the machine.
Reply
Rich Text Editor, editor1
Editor toolbars
Press ALT 0 for help
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.