Technical Support

Need help?

 

Performance issues and high CPU usage on Windows servers monitored by SysMon

Information applies to:

Products
Panda Adaptive Defense 360 on Aether PlatformPanda Adaptive Defense on Aether Platform
Panda Endpoint Protection on Aether PlatformPanda Endpoint Protection Plus on Aether Platform

Issue Status
Tracking ID: KER-608
Status: Resolved
Type of solution: Hotfix


Symptoms
High CPU usage on the System process and performance issues on Windows servers monitored by Sysmon.

Solution

  1. Download and save the hotfix file to the endpoint:
    hf-ker608-system_rules_consumption.exe
  2. Double-click the downloaded file.
  3. The hotfix installation does not require restarting the computer. However, under certain circumstances, you may be prompted to restart for the hotfix to be fully applied. If you cannot restart the computer right away, select No when prompted. This postpones the application of the hotfix until the next system restart.

    Note: To download an unattended or silent version of the hotfix, click here. The hotfix is applied after the next system restart.
Release Notes
Next, find all the changes the hotfix includes.

Affected versions

Protections between v8.00.22.0010 and v8.00.22.0022. To see your Adaptive Defense product version, see this article.

File Details

The hotfix updates the following file:

File nameLocationModified DateHotfix to be included in future versions?
00000014 C:\ProgramData\Panda Security\Security Protection\00000014December 1st, 2023Yes
v8.00.22.0023
00000021C:\ProgramData\Panda Security\Security Protection\00000021December 1st, 2023Yes
v8.00.22.0023
0x1000000D.DATC:\Program Files (x86)\Panda Security\WAC\Cache\0x1000000D.DATNovember 29th, 2023Yes
v8.00.22.0023
0x10000045.DATC:\Program Files (x86)\Panda Security\WAC\Cache\0x10000045.DATDecember 7th, 2023Yes
v8.00.22.0023

Verify Hotfix Application

To confirm the correct application of the hotfix, check the file version (in File Details section) or else, verify the values of these Registry keys:

32 bits Architecture64 bits Architecture
Registry KeyValueRegistry KeyValue
HKEY_LOCAL_MACHINE\SOFTWARE\Panda Software\Setup\Hotfix history\HF_SYSTEM_Rules_ConsumptionRevision [REG_DWORD] 1HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Panda Software\Setup\Hotfix history\HF_SYSTEM_Rules_Consumption

[REG_DWORD]

1

HKEY_LOCAL_MACHINE\SOFTWARE\Panda Software\Setup\Hotfix history\HF_SYSTEM_Rules_Consumption

Result [REG_DWORD]

0 = Success
1 = Not Applied
2 = Error
9 = On Reboot Operation

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Panda Software\Setup\Hotfix history\HF_SYSTEM_Rules_Consumption

[REG_DWORD]

0 = Success
1 = Not Applied
2 = Error
9 = On Reboot Operation

Help nº- 20240129 700178 EN
ALWAYS ONLINE TO HELP YOU TWITTER FORUM
ALWAYS ONLINE TO HELP YOU TWITTER FORUM