Chris345 0 Posted September 1, 2016 Share Posted September 1, 2016 Hi, we have product Version 6.4.2014.2 of Endpoint Antivirus installed on Win7, 64 Bit Pro. I noticed in Ressource monitor that numerous ekrn processes are busy on the filesystem even though i disabled real time scanning. I assumed that disabling real time scan would stop ekrn.exe from ruinning. Even after restart of the machine there is no change. I verified that real time scan is still marked off. Am I missing something or is it a bug? Link to comment Share on other sites More sharing options...
Administrators Marcos 5,286 Posted September 1, 2016 Administrators Share Posted September 1, 2016 That's not a bug. Ekrn.exe is the service that is responsible (not only) for scanning files by various scanners (real-time, web, email, on-demand, etc.). By disabling real-time scanner you disable scanning files by real-time protection but that does not mean that HIPS and other protection modules will stop receiving information about file operations. Disabling automatic start of real-time protection would probably do the trick, however, also HIPS and other protection modules will stop receiving crucial information and may not provide sufficient protection then. If ekrn is constantly utilizing the cpu, create a complete application dump of ekrn (e.g. via the task manager but ideally through the MS tool procdump by running "procdump -ma ekrn") and provide it to me via a pm for further analysis. Also logs from ESET Log Collector might be helpful. Link to comment Share on other sites More sharing options...
Chris345 0 Posted September 2, 2016 Author Share Posted September 2, 2016 Hi, Thanks for the quick answer. Well, actually is both switched off: real time scan and hips. Only web and E-mail is active but that should not scan around in the system. My problem is not high CPU load but a busy hard disk. Answer times in ressource monitor are about 32 ms in average. Please see the screenshots attached. In the Resource monitor screenshot one can on hard disk 1 (C:, D:) the constantly high blue line, which is caused - as I interpret the graph, by ekrn process. The question is: How can i stop (temporarily) ekrn from doing anything, or at least that much, on the file system? If I deactive real-time scan I do not expect a busy hard disk by the ESET service. Link to comment Share on other sites More sharing options...
Recommended Posts