We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Intego troubleshooting · checked August 7, 2026

Intego Not Working, High CPU or Scan Stuck? Diagnose It in Order

Don't start by deleting components. First prove whether Intego is busy with a real scan, stuck on one path, looping at idle, missing its background service or blocked in NetUpdate. Then change one variable and verify that protection returns.

ONE + X9 separated10.9.102 checkedNo invented CPU limitsLogs before reset

Quick answer: High CPU during a progressing Full Scan can be normal. High CPU at idle, a missing `integod` process, a scan that repeatedly stops at the same path, or NetUpdate trapped in a loop needs diagnosis. Record ONE/X9 and component versions, observe the exact process, preserve the log, update, run one narrow test, isolate one conflict, and reinstall only if the official branch calls for it.

Two-minute triage: route the symptom before changing anything

What you seeFirst evidenceFirst safe moveNext guide if needed
Window won't open or buttons do nothingONE/X9, version, `integod`, exact macOS messageUpdate every component, quit, restartCompatibility and permissions
Full or Quick Scan stopsLast path, file count, process/disk activity, sleep eventControlled narrow scan; archives change firstScans and schedules
High CPU while scan runsProcess maps to active job and progress continuesLet it run on power; watch for post-scan dropThis page
High CPU while Mac is idleExact process, duration, Memory Pressure, disk/networkCapture baseline, update, restart, isolate one conflictThis page
Definitions or apps won't updateExact NetUpdate/ONE error, versions, time, network scopeQuit updater/apps, retry, restartNetwork and NetBarrier
Internet fails after install/updateWhole Mac or one app; filter/VPN stateDon't reset everything; use network symptom routerBlocked app or internet

Don't begin by uninstalling, deleting preferences or force-quitting the process at the top of Activity Monitor. Those moves can erase the stopping point, interrupt an update and create a second permissions problem. Start with identity and scope: which generation, which module, what exact state, and whether the work is tied to a visible scan or update.

The quick distinction is active versus idle. A process using the Mac hard while a Full Scan visibly advances isn't the same incident as the same process returning to the top of the CPU list after the scan has ended. This guide treats the first as workload management and the second as a diagnostic case.

First identify ONE, X9 and the failing module

Intego ONE is a unified application, while X9 is a set of separate apps and shared services. A reader saying “Intego is broken” may mean ONE Antivirus, VirusBarrier X9, NetUpdate, NetBarrier, the shared `integod` process or even the separately installed VPN. Each has a different log, permission and recovery path.

On X9, open the Intego menu and choose About your Intego Software to record every installed component. That inventory matters because the current VirusBarrier X9 release notes pair version 10.9.102 with Common Services 10.9.44 and NetUpdate 10.9.40. The March release added strict Audit Token validation to the XPC communication boundary; the label “X9” alone can't prove those shared pieces are current.

Also record macOS, Mac model, Intel or Apple silicon, the user account and what changed: app update, macOS update, new cleaner, second antivirus, VPN, external disk or restored backup. The ONE versus X9 map can resolve product ownership before a troubleshooting instruction is applied to the wrong generation.

High CPU during a scan can be normal; high CPU at idle is different

Observed stateLikely interpretationWhat to watchEscalate when
Full Scan visibly advancesExpected file and archive analysisPath/count changes, disk reads, completionProgress and activity stop or app freezes
First scan after install/updateLarge initial workloadPower, ventilation, other open workloadsRepeat is identical after clean restart/update
CPU remains high after scan completesPossible loop, follow-up task or conflictExact process, network/disk, time to settleNo visible job explains sustained activity
`kernel_task` rises with fansMay be thermal response, not root causeOther process load, ventilation, ambient heatWarmth/fans persist at idle after restart
Memory Pressure turns yellow/redSystem-wide RAM pressureBrowser tabs, cleaners, swap, process memoryNarrow Intego test still exhausts memory

There isn't a universal “normal” percentage, and we don't publish an invented threshold. On a multi-core Mac, Activity Monitor can show a process above 100%, and the same scan can behave differently with archives, an external drive or thousands of tiny files. A number without task, duration and progress isn't a diagnosis.

Version history also rules out lazy assumptions about every build behaving alike. VirusBarrier 10.9.95 addressed excessive memory use, while later releases changed scan, archive and Tahoe behavior. Verify the installed build before treating a historical symptom as a current defect.

Apple notes that fans and warmth can be normal during intensive computation. Its current Mac temperature guidance recommends Activity Monitor when fans run for a long time while the laptop isn't doing intensive work. That's our dividing line too: measure the unexplained idle behavior, not just the loudest moment of a legitimate scan.

Use Activity Monitor as evidence, not a kill switch

Intego troubleshooting route from symptom and scope through evidence, a safe test, verification and support
Editorial diagnostic route, not an Intego or macOS screen. Scan, CPU, update and startup incidents use the same evidence-first sequence before support escalation.

Open Applications → Utilities → Activity Monitor, choose View → All Processes, click CPU to sort and search for “intego.” Apple's Activity Monitor guide explains the user, system and idle totals. Watch the process across several refreshes and record whether its movement follows a visible scan or updater.

Then check Memory and the Memory Pressure graph rather than treating free RAM as the only signal. Disk reads can prove a scanner is still moving through data; Network can show an updater is communicating; Energy Impact and 12hr Power help distinguish a brief spike from a long laptop drain. Capture the time, process name and state, but crop usernames and private paths before sharing a screenshot publicly.

Force Quit is a recovery tool for an unresponsive visible app, not the first interpretation of high CPU. Save work and preserve the evidence first. A background protection service can relaunch automatically, and repeatedly killing it may only hide the cause while leaving protection unstable.

If the dashboard won't open, check protection separately

A missing window doesn't automatically mean real-time protection stopped, and an open window doesn't prove the background engine is healthy. Try the menu-bar entry and Applications folder once, record any macOS alert, then look for the expected process and status. Avoid launching several copies or adding the app manually to Open at Login.

If the button issue started on an older X9 build after Tahoe, version history matters. VirusBarrier 10.9.100 specifically fixed scan buttons that didn't respond on Tahoe, while 10.9.102 is the current March 2026 release and includes an XPC security fix. Updating is therefore a functional and security step, not a generic ritual.

When macOS says the application is damaged, don't drag only that app to Trash and leave shared components behind. Intego's current damaged-app guidance routes outdated components to a proper full-package uninstall and reinstall. Preserve your version list and restart through the official sequence.

“Daemon is not running” points to shared X9 components

Intego says its X9 products share `integod`, a background process that handles work such as filtering and virus scanning. Its daemon error article names incompatible product/macOS versions and manually added Startup or Login Items as common causes. All installed Intego products need compatible shared components.

Remove Intego applications from the user-managed Open at Login list if you added them there; the installed background services start without those entries. Then update all X9 pieces, restart and search Activity Monitor for `integod`. Don't paste old `launchctl` load/unload commands into Terminal—the service layout and macOS security model have changed across releases.

If the process is still absent, keep the exact error and versions. A proper reinstall can replace the daemon and shared services, but doing it after logging the state gives support something to compare if the failure returns. This also prevents a mixed old/new installation from being mistaken for a fresh one.

A scan is stuck when progress and work both stop—not at a magic percentage

Scan percentage can pause while one large archive or package expands, so the number alone is weak evidence. Watch the current path or file count, Activity Monitor CPU and disk activity, and responsiveness over a defined interval. A repeatable stop at the same location is stronger evidence than “it felt slow.”

Intego's May 2026 ONE scanner troubleshooting begins with the current app, then tests scan settings in order: disable archive scanning first, rerun, and only then test Windows-malware detection if needed. It also calls out too many apps/tabs, multiple security or cleaner tools and hardware/overheating under scan load.

Keep the Mac awake and on stable power for a controlled rerun. If the whole interface freezes, capture the path if visible, use macOS Force Quit for the frozen app, restart normally and repeat a narrow known-folder scan before launching another full disk pass. A hard power hold belongs only to a Mac that's completely unresponsive.

When every scan stops at the same file, turn the path into a test

Stopping cluePossible causeControlled testDon't conclude
Large archive or packageDecompression, corruption, nested contentDisable archives once; scan parent and known folderThat every archive is unsafe
Time Machine or backup pathHuge history, special layout, changing dataScan current data separately; use documented exclusionThat backup should be deleted
External/network volumeDisconnect, latency, filesystem issueDirect local folder and stable cable/mount comparisonThat the scanner engine alone failed
Same ordinary fileCorruption, access, active writer, detection actionQuit owning app; preserve log/path; narrow scanThat exclusion is a permanent fix
Different path each runResource pressure or broader conflictClean restart, smaller scope, one conflict isolatedThat a single file owns the incident

Intego suggests excluding the specific folder when a scan repeatedly freezes there, but the exclusion is a diagnostic probe. Note exactly what was omitted, complete the rest of the scan, inspect the item through an appropriate safe route and remove the gap after the cause is known. Our false-positive and trusted-file guide covers evidence before allowing a detected item.

Don't exclude an entire home folder, external drive or backup set simply to make the progress bar green. A broad exclusion changes the security promise more than the test requires. The best test is the smallest parent folder or file class that reliably flips the result.

Sleep, archives, external drives and changing data alter scan behavior

VirusBarrier X9 release 10.9.97 fixed scans that could crash during a sleep event, and older releases addressed external volumes, Time Machine data and archive performance. That history is useful because it proves the environment can trigger real bugs, but it isn't permission to assume an old bug survives in the current build. Record the version and reproduce while the Mac stays awake.

Archives can contain many nested files and require decompression before scanning. An encrypted or corrupt archive may behave differently from an ordinary document, while a cloud folder or active backup can change underneath the scanner. Quit the app writing the repeated path and rerun the smallest stable scope.

For an external drive, verify power, cable, mount state and filesystem health before blaming the engine. Don't erase a disk or Time Machine destination to “unstick” one scan. Scan a small local folder and a small folder on the external volume to separate scanner behavior from destination behavior.

Sustained high CPU at idle needs a repeatable baseline

Wait until no Full, Quick or Custom scan is active and NetUpdate has finished. Close the Intego dashboard without disabling protection, let the Mac settle, then observe all related processes across several minutes. Repeat after a normal restart with the same account and comparable open apps.

If the load appears only after login, inspect General → Login Items & Extensions and remove manually added Intego applications from Open at Login while leaving required background activity and extensions approved. Apple's current settings guide distinguishes user login items, app background activity, endpoint-security extensions and network extensions. Turning all of them off would destroy that distinction.

Next compare with one competing real-time antivirus or cleaner paused or properly uninstalled—not five utilities disabled together. If CPU settles, reinstall or reconfigure the conflict rather than running two live scanners. If it does not, re-enable the control and preserve the negative result; a failed hypothesis is useful evidence.

Separate CPU load, memory pressure and hardware symptoms

A warm case or loud fan doesn't identify the process, and a process percentage doesn't measure temperature. Apple says `kernel_task` can reduce CPU availability in response to thermal conditions; it may appear busy because something else made the machine hot. Keep the laptop on a stable ventilated surface and use current macOS updates.

Memory Pressure is the better whole-system signal than “free RAM.” Close browser tabs and heavy creative or virtual-machine workloads before a controlled scan, then compare. If the problem disappears only when every other app is closed, the scanner may be the trigger without being the only cause.

If the Mac freezes under several unrelated heavy workloads, unexpectedly restarts or remains hot and loud at idle after a clean restart, move beyond antivirus settings. Apple's Diagnostics guidance can check internal hardware, but it doesn't diagnose software or extension conflicts. Preserve backups before hardware testing or service.

NetUpdate errors have distinct branches

Message or stateWhat Intego says it can meanSafe sequenceEscalation
Background update is runningRunning, finished without closing, or halted processQuit NetUpdate/apps; reopen; restartReinstall current bundle, then support
Background process not runningKnown post-update service issueReinstall same bundle; install all updatesSupport if it returns
Prerequisite/update loopComponents require one another in a failed orderRecord versions/error; reinstall latest packageTicket with repeat evidence
Can't replace outdated componentOld shared piece can't be replacedOfficial reinstall and complete update passTicket, no manual component deletion
Download not permittedFirewall/network blocks download or authenticationRestart; check exact network/NetBarrier ruleNetwork guide or reinstall after connectivity proof

The NetUpdate manual says the app updates software and support files such as malware definitions and content filters. It can check automatically or manually, and background updates may quit apps and require a restart. Fast User Switching allows NetUpdate to be open for only one user at a time.

For the “background update is running” message, Intego's current order is deliberately simple: quit NetUpdate and other Intego apps, retry, save work and restart, then reinstall if it returns. A download/authentication error also introduces network scope; Intego documents outbound ports 80 and 8079. Use the NetBarrier troubleshooting guide rather than leaving the whole firewall disabled.

Apps missing from NetUpdate may be normal current behavior

Older NetUpdate screens listed every installed product, so a shorter list looks broken to long-time users. Intego's February 2026 listing explanation says NetUpdate 10.5.11, 10.7 and 10.9 show installed apps and components when updates are available. Subscription-based definitions and filters remain visible so expiry can be checked.

Use About your Intego Software from the tower menu for the installed inventory and versions. A gray definition/filter entry can mean it's already installed, not failed. The real failure signal is an old definition date, explicit error, missing background process or a version that doesn't change after a confirmed update.

This distinction prevents an unnecessary reinstall. It also gives a cleaner support ticket: “VirusBarrier 10.9.102 and NetUpdate 10.9.40, definitions dated X, error Y at Z time” is actionable; “my apps disappeared” without the version inventory isn't.

Two real-time scanners can turn a diagnostic test into a deadlock

Intego's ONE scanner article explicitly lists multiple security or cleaner apps as a source of interference and system hangs. Two products can inspect the same opened or unpacked file, monitor each other's temporary data and compete for disk, CPU and extension hooks. The symptom may surface only during a full scan.

Inventory active antivirus, cleaner, VPN, network/content filters, backup tools and cloud sync before changing anything. Isolate one at a time with a timestamp and restore the intended control after the test. If the other antivirus lacks a supported pause, use its official uninstaller rather than dragging the app to Trash.

Don't count XProtect as a second consumer antivirus to remove; it's part of macOS. Don't permanently exclude the other product's entire data folder without vendor guidance. The clean outcome is one chosen real-time antivirus plus deliberate on-demand tools that don't fight over live scanning.

Permissions can stop protection, but resetting all permissions isn't a fix

Full Disk Access, background items, endpoint-security extensions and network extensions are different approvals. Antivirus scanning can fail without file access, while NetBarrier can fail without its network filter. A blanket permission reset turns one symptom into several and makes the original state impossible to reconstruct.

Use our Intego compatibility and Full Disk Access guide to match the prompt to ONE or X9 and the installed macOS release. Record which item is approved before toggling it, change only the module-relevant control and restart only when macOS or Intego requires it.

After any permission change, verify the outcome that permission exists to support: real-time protection reports healthy, a narrow scan can read the test folder, or the network filter operates without cutting off the Mac. A checkbox alone isn't the end of the test.

Preserve the last path, log and update history before repair

VirusBarrier X9 exposes scan logs from Scan Overview → Logs, Window → Logs or Command-Option-L. Intego's log guide says completed entries can be expanded to show details such as the location of an infected or corrupt file. Copy the relevant text or screenshot the entry before another run changes the context.

If support needs deeper data, Option-click Help and enable Verbose Logging, reproduce once, build the report, then disable verbose logging as Intego instructs. The Log Reporter creates a `.tgz` on the Desktop after administrator authorization. Treat it as private because it contains detailed system information and paths.

NetUpdate also keeps an Installed Updates log with version entries and comments. Pair that history with the exact error and clock time. Logs are most valuable when they answer “what happened immediately before the failure?” rather than when they're collected days after repeated resets.

Reinstall when shared components are broken—not as the first reflex

Reinstallation is justified when the app is damaged, the background process remains absent, NetUpdate can't replace a component, prerequisite loops repeat or the official scanner path still fails after update and a controlled test. Before uninstalling, save the component inventory, relevant logs, license/account route, screenshots and any exclusions or scheduled settings you need to recreate.

Use the current official installer and its uninstall option. Select the complete bundle when Intego's error article calls for replacing shared components, restart as instructed, reinstall and run every offered update before testing. Our installation and setup guide covers the clean ONE/X9 paths without mixing installers.

Then prove the repair: About shows the intended versions, `integod` or the ONE background service is present, definitions update, protection is enabled, a small scan completes and CPU settles afterward. Reinstalling without post-install verification only changes the date of the unknown state.

Avoid broad resets and manual daemon surgery

Don't run `tccutil reset All`, delete arbitrary launch daemons, unload services, remove system extensions by hand or erase every Intego preference from a search result. Those instructions often target old OS X releases and can affect unrelated applications, privacy approvals or shared products. They also remove the evidence support needs.

NetBarrier has a product reset, but it's destructive to rules and belongs to a confirmed firewall configuration incident after export/documentation—not to a scanner CPU problem. Likewise, a scan exclusion is a narrow diagnostic control, not an excuse to omit the entire home directory. Reset the smallest proven component, last.

If an official support agent gives a Terminal command for your build, keep the ticket, command, expected output and rollback instructions together. Don't generalize it into public advice. A command safe for one legacy component can be wrong for ONE, a different macOS release or a Mac with several Intego apps.

A support packet should make the failure reproducible

IncludeWhy it mattersPrivacy check
ONE/X9, module and every component versionSeparates product generations and mixed buildsDon't include serial/license key
macOS, Mac model/chip, account scopeMaps compatibility and one-user failuresUse model, not hardware serial
Timestamp/timezone and exact errorAligns logs with the incidentCrop unrelated notifications
Expected/actual and shortest reproductionMakes the case repeatableReplace private filenames where possible
Activity Monitor and last scan pathDistinguishes active work from idle loopCrop usernames and personal paths
Tests and results, one change per testPrevents support repeating blind stepsState how protection was restored
Intego Log Reporter `.tgz` when requestedProvides detailed system diagnosticsOfficial private ticket only

Write the case as a timeline: “22:05 Full Scan started; 22:18 path stopped changing; 22:23 process still active with no disk reads; 22:27 Force Quit after screenshot; clean restart; small folder passed; same parent folder failed.” That's more useful than “Intego froze again.” Include whether the failure survives a restart and whether one known change flips it.

Use Intego's official ticket route and keep the ticket identifier. Don't upload the `.tgz` to a public forum or file-sharing link. If the issue is whole-Mac overheating or instability across unrelated workloads, open a separate Apple/hardware case rather than asking an antivirus agent to diagnose the entire machine.

Ten-step Intego diagnostic workflow

  1. Name the exact symptom. Write down whether the app won't open, the dashboard is unresponsive, a scan stops, CPU remains high at idle, the background process is missing, or NetUpdate shows a specific error. Record the time and what changed immediately before it.
  2. Identify the generation and module. Open About your Intego Software when possible and record ONE or X9, the affected module, all component versions, macOS version and Mac model. Don't use an instruction for NetBarrier, VirusBarrier or NetUpdate interchangeably.
  3. Define the scope. Check whether the problem occurs only during a Full, Quick or Custom scan, only after login, only on one user account, only with an external volume, or even while the Mac is idle. Scope separates normal work from a persistent loop.
  4. Capture process evidence. In Activity Monitor, show all processes, sort CPU, search for the exact Intego process and record CPU behavior over several minutes, Memory Pressure, Energy Impact and whether disk or network activity matches a scan or update. Save a screenshot without exposing private filenames.
  5. Preserve logs and the stopping point. For X9, open VirusBarrier Logs and expand the affected entry; note the last path, result and definition time. If the issue is reproducible, enable verbose logging only when support needs it and disable it after building the official report.
  6. Update and restart cleanly. Save work, quit open Intego windows, install current app and shared-component updates through the correct ONE updater or X9 NetUpdate route, then restart if prompted. Confirm versions after restart instead of assuming the installer completed.
  7. Run one narrow safe test. Test a small known folder or repeat the same scan with one documented change, such as archives disabled first when Intego's current scanner guidance calls for it. Keep real-time protection enabled unless a tightly timed isolation test specifically requires otherwise.
  8. Isolate one conflict at a time. Pause or remove only one competing real-time antivirus, cleaner, VPN or network filter for a controlled comparison, then restore the intended protection. Don't disable several controls at once because the result won't identify the cause.
  9. Reinstall only after evidence. Use the official installer and its uninstall option after saving versions, logs, subscription details and the exact failure. Don't manually delete shared daemons, launch files, extensions or every folder containing the word Intego.
  10. Verify protection or escalate. After the change, confirm the app opens, the background service is present, definitions update, a narrow scan completes, CPU settles when idle and permissions remain approved. If it fails again, send the timestamp, reproduction steps and private Log Reporter archive through the official support ticket.

The sequence is deliberately evidence-first and reversible. It keeps one variable per test, preserves a clean comparison and places reinstall after version, process, log and conflict checks. That reduces the chance of a temporary improvement being mistaken for a root cause.

Run the verification step even when the symptom disappears. A quiet CPU graph isn't enough if definitions are stale or real-time protection is off; a completed scan isn't enough if the updater remains broken. The finished state must include both stability and protection.

Intego not working and high CPU FAQ

Why is Intego using so much CPU during a scan?

An active full scan can use substantial processor and disk resources because files and archives are being read and analyzed. The useful test is whether the process maps to the visible scan, makes progress and falls back after completion. Sustained high CPU while no scan or update is active needs Activity Monitor evidence and a controlled diagnostic pass; a single peak isn't enough to label it a fault.

How long should I wait before calling an Intego scan stuck?

There's no safe universal minute or percentage threshold because archives, external volumes, Time Machine data, file count and storage speed differ. Treat it as stuck when the file count/path and relevant process activity stop changing across an observed interval, the app becomes unresponsive, or the same path repeatedly blocks a clean rerun. Record the path and time rather than guessing from percentage alone.

What should I do if Intego won't open?

First decide whether only the window fails or the protection service also stopped. Record versions, check Activity Monitor for the relevant process, remove any manually added Intego Open at Login entry, update all shared components and restart. If macOS says the app is damaged or the background process is missing, use Intego's official uninstall/reinstall path instead of deleting components manually.

What does Intego's daemon isn't running error mean?

X9 applications share a background process named `integod` for filtering and scanning work. Intego says the error can occur with incompatible or mixed component versions and when its apps are manually added to Startup or Login Items. Update every installed Intego component, remove those manual login entries, restart and confirm the process; don't try random `launchctl` commands from old forum posts.

Can I force quit an Intego process in Activity Monitor?

Don't force quit it merely because it's using CPU during a scan or update. If the visible app is frozen, save other work, capture the process and stopping point, then use the normal quit or macOS Force Quit route for that app before restarting. A shared background daemon may immediately return and killing it without evidence can interrupt protection or corrupt an update state.

Why does a VirusBarrier scan stop on the same file or folder?

The repeated path is valuable evidence. Intego recommends testing archive scanning first and, when a scan always stops at one location, using a narrow folder exclusion to see whether the rest completes. The exclusion is diagnostic rather than permanent: inspect the item, preserve the log and remove the gap after the cause is understood.

Why are my Intego apps missing from NetUpdate?

Current NetUpdate 10.9 doesn't continuously list every installed application and component. Intego says applications appear when an update is available, while expiring definitions or filters remain visible; use the Intego menu's About your Intego Software view for the installed inventory. Missing names alone therefore don't prove an updater failure.

How do I fix NetUpdate stuck on a background update?

Quit NetUpdate and other open Intego applications, reopen it, then save work and restart the Mac if the message returns. Intego's current support path escalates recurring background-process, prerequisite-loop or outdated-component errors to reinstalling the current bundle and installing every offered update. Preserve the exact error before reinstalling so a repeat can be diagnosed.

Should I disable Full Disk Access or all Intego extensions to troubleshoot?

Not as a blanket first step. Antivirus and firewall modules depend on specific privacy and system or network-extension approvals, and removing them can create a second failure that looks like the first. Check the dedicated compatibility guide, change only the permission tied to the failed module, and verify that protection is restored immediately after a controlled test.

What should I send Intego Support?

Send the exact product/module, all component versions, macOS and Mac model, timestamp and timezone, expected versus actual result, minimal reproduction steps, Activity Monitor evidence, last scan path or NetUpdate error and the test already performed. Intego Log Reporter creates a detailed `.tgz`; upload it only through the official support ticket because it may contain usernames, paths and system information.

Bottom line: fix the observed failure and prove protection

An Intego process at the top of Activity Monitor during a progressing scan may be doing exactly what the user asked. The same load at idle, a missing shared daemon, a repeated stopping path or an explicit NetUpdate loop is a different case. Product generation, task scope and time-based evidence turn those symptoms into separate, solvable branches.

Update first, test narrowly, isolate one conflict at a time and preserve logs before reinstalling. Avoid broad permission resets and old daemon commands. The repair is complete only when the app opens, the service is present, definitions update, a controlled scan finishes, idle load settles and every required protection control is back on.