To minimize the impact that on-demand scans have on a system, you can select options to avoid impacting system performance and scan only what you need to.
Tip
Best practice: For suggestions on how to improve Endpoint Security performance, see KB88205.
Scan only when the system is idle
The easiest way to make sure that the scan has no impact on users is to run the on-demand scan only when the computer is idle.
When this option is enabled, Threat Prevention pauses the scan when it detects disk or user activity, such as access using the keyboard or mouse. Threat Prevention resumes the scan when the user hasn't accessed the system for three minutes.
You can optionally:
Allow users to resume scans that have been paused due to user activity.
Return the scan to run only when the system is idle.
Disable this option only on server systems and systems that users access using Remote Desktop Connection (RDP). Threat Prevention depends on the Trellix notification area icon to determine if the system is idle. On systems accessed only by RDP, the notification area icon doesn't start and the on-demand scanner never runs. To work around this issue, add the UpdaterUI.exe to the logon script.
Select Scan only when the system is idle in the Performance section of the Scan Task Settings tab.
Pause scans automatically
To improve performance, you can pause on-demand scans when the system is running on battery power. You can also pause the scan when an application, such as a browser, media player, or presentation, is running in full-screen mode. The scan resumes immediately when the system is connected to power or is no longer in full-screen mode.
Do not scan when the system is on battery power
Do not scan when the system is in presentation mode (available when Scan anytime is enabled)
For custom scans, select these options in the Performance section of the Scan Task Settings tab. For quick and full scans, select these options in the Performance section in Settings → On-Demand Scan → Full Scan or Quick Scan.
Allow users to defer scans
If you choose Scan anytime, you can allow users to defer scheduled scans in one-hour increments, up to 24 hours, or forever. Each user deferral can last one hour. For example, if the Maximum number of hours user can defer option is set to 2, the user can defer the scan twice (two hours). When the maximum specified number of hours elapses, the scan continues.
For custom scans, select User can defer scans in the Performance section of the Scan Task Settings tab. For quick and full scans, select this option in the Performance section in Settings → On-Demand Scan → Full Scan or Quick Scan.
Limit scan activity with incremental scans
Use incremental, or resumable, scans to limit when on-demand scan activity occurs, and still scan the whole system in multiple sessions. To use incremental scanning, add a time limit to the scheduled scan. The scan stops when the time limit is reached. The next time this task starts, it continues from the point in the file and folder structure where the previous scan stopped.
Select Stop this task if it runs longer than in the Options section of the Scan Task Schedule tab.
Check the OnDemandScan_Activity log file for scan statistics, such as start time, end time, and time to complete the scan. From the Event Log page in Trellix Endpoint Security (ENS) Client, click View Logs Folder. Most recent scan tasks activity appears at the bottom of the file.
Configure system utilization
System utilization specifies the amount of CPU time that the scanner receives during the scan. For systems with end-user activity, set system utilization to Low.
You can use the Windows Task Manager to view CPU utilization consumed by the Trellix Scanner service process (mcshield.exe).
The scan process for Full Scan and Quick Scan on-demand scans runs at low priority. But, if no other processes are running during a scan, the mcshield.exe process might consume a higher amount of CPU resources. If any other processes make system requests, mcshield.exe releases the CPU resources.
For custom scans, select System utilization in the Performance section of the Scan Task Settings tab. For quick and full scans, select this option in the Performance section in Settings → On-Demand Scan → Full Scan or Quick Scan tab.
Specify the maximum CPU percentage for scans
As an alternative to using system utilization to automatically determine the amount of CPU the scan uses, you can specify a maximum percentage. In this case, the CPU usage for Full Scan, Quick Scan, and custom scans is limited to the percentage you specify. For example, if you specify 60%, the full scan consumes 60% of the available CPU.
Because the scan is single-threaded, if the system has multiple CPUs, the scan uses the percentage of 1 CPU. So, if you want to limit the scan to 25% of the total CPU processing power of a 4-CPU system, set the percentage to 25%.
This option only applies to scanning files. It doesn't limit CPU usage when scanning other items, such as memory, registry, and boot sectors.
Note
This option is available only when the Scan anytime option is selected.
Custom scans | In the Scan Task Settings tab:
|
Quick and full scans | In the On-Demand Scan settings, on the appropriate tab (Full Scan or Quick Scan):
|
Scan only what you need to
Scanning some types of files can negatively affect system performance. For this reason, select these options only if you need to scan specific types of files.
For custom scans, select or deselect these options in the What to Scan section of the Scan Task Settings tab. For quick and full scans, select or deselect these options in the What to Scan section in Settings → On-Demand Scan → Full Scan or Quick Scan.
Files that have been migrated to storage
Some offline data storage solutions replace files with a stub file. When the scanner encounters a stub file, which indicates that the file has been migrated, the scanner restores the file to the local system before scanning. The restore process can negatively impact system performance.
Deselect this option unless you have a specific need to scan files in storage.
Note
This option doesn't apply to files stored in Microsoft OneDrive. The on-demand scanner doesn't download OneDrive files or scan files that haven't been downloaded.
Compressed archive files
Even if an archive contains infected files, the files can't infect the system until the archive is extracted. Once the archive is extracted, the On-Access Scan examines the files and detects any malware.
Tip
Best practice: Because scanning compressed archive files can negatively affect system performance, deselect this option to improve system performance.