cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

High CPU load due to Antimalware process

Hi, we have problems with too high CPU load (~300%)-it's the mwg-antimalware process, which is causing the load.. it's just for about 30min and then ok again. There were no updates, I couldn't find any suspicious contents in the access or virus logs.  Could anyone tell me where the logfiles from antimalware engine are located? Couldn't find this in any manuals.

Thanks!!

KR

9 Replies
Highlighted
Level 12
Report Inappropriate Content
Message 2 of 10

Re: High CPU load due to Antimalware process

I have seen this when an archive containing thousands of files is being scanned.

I run this command:

while x=1; do echo `date` ; /opt/mwg/bin/mwg-antimalware -S threads | grep object ; sleep 5; x=1; done (use Control-C to cancel)

Then I look for objects that show up repeatedly. In many cases, I'll see repeated entries that look like this:

[status] working on command kExFuScanMemory with URL http://URL/filename (object name changes as MWG iterates through the objects)

Highlighted

Re: High CPU load due to Antimalware process

great, thanks. That's what I was looking for.

Highlighted

Re: High CPU load due to Antimalware process

Hi, how can I be sure, that the objects are responsible for the high load. I saw that after the objects were gone, load also went down, but is there a command which shows which object is responsible for which load?

Highlighted

Re: High CPU load due to Antimalware process

Hi there,

you can always check with the command line tools posted before what it is actually / right now "in" the engines:

[root@mwgappl ~]# /opt/mwg/bin/mwg-antimalware -S threads

It is often a problem if the download are containing multiple zip file or thousend of files in in, .jar files. that could lead to a higher load while the whole archive will be extracted scanned.

Highlighted
Level 10
Report Inappropriate Content
Message 6 of 10

Re: High CPU load due to Antimalware process

Since 2-3 month we have this characteristics too. Mostly when we download a Java application (it should be compressed files) then we see 100%CPU at the appliance. The applications we download are since 1-2 years nearly the same packages.

Is there somthing changed at the scan engines in the last month? We use MWG (7.2.0.1.0-13253)

Highlighted

Re: High CPU load due to Antimalware process

Is there an updated command. it looks like mwg-anti malware is no longer within /opt/mwg/bin/?

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 8 of 10

Re: High CPU load due to Antimalware process

Hi,

 

Hope you are doing well.

 

/opt/mwg/bin/mwg-core -S AMJobs

 

/opt/mwg/bin/mwg-core -S AMEngines
 
/opt/mwg/bin/mwg-core -S AMQueue
 
 
Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
 
 
Regards
Alok Sarda
Highlighted
Level 12
Report Inappropriate Content
Message 9 of 10

Re: High CPU load due to Antimalware process

I generally just look for an object that keeps showing up -- at that point I may go download the object and extract it to verify my suspicions that it's causing the problem. If the object has thousands of files (no matter how large or small it is), that's usually the culprit.

Most frequently seen with compressed source code, jar files, zip files, software distributions.

Highlighted

Re: High CPU load due to Antimalware process

ok, thanks!

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community