Sophos Anti-Virus

The LiveVault Online Backup Service has been tested with Sophos Anti-Virus for Windows NT (from Sophos) and LiveVault Online Backup Service is known to run successfully with this product on a computer. The tested Sophos Anti-Virus for Windows NT version is 3.29. If you are using another version and require assistance, contact Customer Service.

There are additional configuration steps that you need to perform to run Sophos Anti-Virus software and LiveVault Online Backup Service on the same Agent computer.

Exclude LiveVault Online Backup Service directories from the anti-virus scan

When configuring Sophos Anti-Virus software, you need to exclude the following LiveVault Online Backup Service directories from the virus scanning; otherwise, the computer could hang:

  • Journal files (default is \LiveVault\Journals\)

  • Database files directories, both protected and unprotected (default is \LiveVault\Databases\ containing both subfolders \Protected and \Unprotected)

To identify the LiveVault Online Backup Service directories paths

To identify the full path of the directories to exclude on your computer:

  1. Using REGEDT32.EXE, open the registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\LiveVault Corporation\LiveVault\2.0

  2. Locate the JournalRoot value (for example, this is usually similar to E:\LiveVault\Journals)

  3. Locate the ProtectedDatasetDirectory value (for example, this is usually similar to E:\LiveVault\Databases\Protected)

  4. Locate the UnprotectedDatasetDirectory value (for example, this is usually similar to E:\LiveVault\Databases\Unprotected)

Exclude the anti-virus temporary files/directories from backup

Anti-virus software products generate temporary files or use temporary directories, for example, to unpack archives such as zipped files. These need to be excluded.

The Sophos AntiVirus temporary files directories are located in the Sophos SWEEP directory specified in the registry key:

HKLM\Software\Sophos\SweepNT value Path

For example, if the specified path is C:\Program Files\Sophos SWEEP for NT, append the temporary subdirectories \Temp and \~Temp to create the exclusions:

Exclude C:\Program Files\Sophos SWEEP for NT\Temp (plus subdirectories)
Exclude C:\Program Files\Sophos SWEEP for NT\~Temp (plus subdirectories)

LiveVault Online Backup Service Agent version 4.0 and later automatically excludes the Sophos Anti-Virus temporary directories and their subdirectories (as specified above). If you are running an earlier Agent version, you must manually create these exclusions.

In the tree view on the Files to Backup tab, you will see the icon for the automatically excluded directories and subdirectories. Parent directories of the automatically excluded directories are marked in MyLiveVault with one of the "partially excluded" icons, either (if a parent directory is selected), or (if a parent directory is not selected).

Check the Sophos Anti-Virus vendor documentation for whether the product uses other temporary files and directories.

Exclude additional anti-virus files/directories from backup

You also need to exclude the Sophos Anti-Virus infected files "Action" directory and its subdirectories from backup.

LiveVault Online Backup Service Agent version 4.0 and later automatically excludes the Sophos Anti-Virus "Action" directory and its subdirectories. If you are running an earlier Agent version, you must manually create this exclusion.

Important: This is a per-user setting, so it is possible that a user has specified a different path for the infected files storage directory. In this case, you must look at the Agent to identify that path and create the appropriate exclusion.

In the tree view on the Files to Backup tab, you will see the icon for the automatically excluded directory and subdirectories. Parent directories of the automatically excluded directory are marked in MyLiveVault with one of the "partially excluded" icons, either (if a parent directory is selected), or (if a parent directory is not selected).

The Sophos Anti-Virus infected files "Action" directory is located by default as a subdirectory in the Sophos SWEEP directory specified in the registry key:

HKLM\SOFTWARE\Sophos\SweepNT value Path

For example, if the specified directory path is C:\Program Files\Sophos SWEEP for NT, append the \infected subdirectory to create the exclusion:

Exclude C:\Program Files\Sophos Sweep for NT\infected\* (plus subdirectories)

If report and log changes are impacting backup

If the Sophos Anti-Virus reports and logs are changing so much that they are impacting your backup, you may want to create a separate Sophos database backup configuration that is scheduled to run once a day.

The reports and logs are located in the Sophos Sweep for NT directory, for example:

C:\Program Files\Sophos Sweep for NT\Reports\

C:\Program Files\Sophos Sweep for NT\Sweep.log

You can create a database backup configuration that includes all the data in the Sophos directory, for example:

Include C:\Program Files\Sophos Sweep for NT\* (plus subdirectories)

Important: If you are running Agent 4.0 or later on this computer, then the automatically excluded Sophos directories will continue to be excluded from backup. However, if you are running an earlier version of the Agent, you will need to manually create the exclusions specified earlier in this topic as part of your Sophos backup configuration; manually excluding them from the Files and Directories backup configuration only will not be sufficient.

Anti-virus process in LiveVault "suspect process" registry setting

The anti-virus process SweepSrv.SYS modifies a file's attributes. When LiveVault Online Backup Service recognizes that the file attributes are changed, it would determine that the file was changed and back up the file changes. This would result in unnecessarily high continuous backup activity which will negatively impact your computer operations.

To prevent this problem, LiveVault Online Backup Service Agent version 4.0 and later automatically includes this process in a LiveVault "suspect process" registry setting that enables the LiveVault Online Backup Service replication technology to identify the files whose attributes are modified by these processes, and thus avoid replicating the files unnecessarily. LiveVault Online Backup Service will continue to identify when the file content has actually changed and back it up appropriately.

If you are running an earlier Agent version, contact Customer Service for assistance.


Related Information

Anti-virus Software
Excluding Files from Backup
Automatic and Recommended Backup Exclusions