This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

On-Access Scanning stays Disabled (Sophos 9.4 + Mac OSX 10.11)

Hi,

I’m having some issues concerning Sophos Antivirus for Mac Home Edition. I’m using a 2007 Macbook Pro (15”) and since the update to OSX 10.11 El Capitan, Sophos refuses to load correctly.

Especially, the “On-Access”  scanner refuses to start and the shield icon stays grey instead of turning black. After some time, the message "Sophos Anti-Virus is not running" appears.

After deleting the file cache.dat (size 0 kb) in the directory /Library/Caches/com.sophos.sav/ the on-access scanner starts and works as it should. However, after a reboot or after a Sophos Update (once an hour) the process of deleting the file needs to be done over again.

Before hanging, the following is mentioned in Console:

com.apple.xps.launchd: (com.sophos.intercheck) Service exited due to signal: Trace/BPT trap: 5

kernel: Sophos Anti-Virus on-access kext activated

The above message appears every few seconds and keeps looping. It stops when deleting said file above.

I’ve tried the following to resolve the problem:

1. Uninstalled Sophos using the “Remove Sophos Anti-Virus” program in Applications and re-installed using a fresh installer from the Sophos website. This didn’t solve my problem.

2. Completely re-installed Mac OSX 10.11 El Capitan from scratch, using a USB key which I prepared using the following KB article: https://support.apple.com/en-gb/HT201372

After installing from scratch I downloaded and installed Sophos right away. The strange thing is that sophos loads correctly after installing from scratch, but after downloading the first update (159.9 MB package) the above problem returns. This is exactly the same behaviour as before I did the clean install.

3. Completely re-installed using above procedure, after which I disabled system protection, and installed / updated Sophos. unfortunately also to no avail.

Could you please look into this? Thanks in advance!



This thread was automatically locked due to age.
  • I have exactly the same problem with an early 2010 iMac. I'm still waiting to hear from Tech Support.
  • Hey DHER,

    Sorry to hear you're having trouble. It seems like you've already done a lot of troubleshooting, so I've asked one of the developers if they might have any ideas what could be causing this. I'll let you know as soon as I hear back.

    Thanks for your patience!

    Cheers,
    Serra
  • Hi again DHER,

    Couple questions for you:

    1. Have you disabled El Capitan’s ‘rootless’ protection ?

    2. Do you run any third-party security software (other than Sophos?)

    3. Can you open up a terminal window, type the following command, and send the results back to me? (you can just post it here or email me directly, serra@sophos.com).

    shasum /usr/lib/system/libcommonCrypto.dylib

    Thanks very much!

  • Hi Serra,

    Thanks for your reply.

    1. I had disabled El Capitan's "Rootless" protection just to test if this was the source of the Sophos problems. However, also with rootless disabled, the on access scanner didn't start. After testing I re-enabled rootless, because this is the default configuration.

    2. I do not run any other third party security software. In fact, I did not run any other software besides the standard OSX El Capitan OS and Sophos for testing purposes.

    3. I will email you the output shortly.

    Thanks again!
  • I am also having the same issue on OS X Yosemite
  • Hi SteveGlass,

    That's great to hear! Thanks for all your patience with this.

    Hi DHER,

    Sorry for the slow reply on this, but I'm curious - did the 9.4.1 release help you with this issue at all? You should have gotten the update today.

    Cheers,
    Serra