This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

On-access scanning disabled itself, will not allow me to turn it back on; on-demand scan not working

Hello and thank you in advance to anyone who can help me.  I have two issues:

(1) On-access scanning turned itself off and I am not able to turn it back on.  When I clicked on the button next to "the on-access scanner is off", it just says "Start scanning" and is greyed.

(2) When I try to do an on-demand scan, it scans for less than a second and stops.  Message says no threats but "issues detected".

Here is a log I came across if this helps:

Sophos Anti-Virus
Product version: 9.2.7
Copyright Copyright 1993-2012 Sophos Ltd. All rights reserved.

Scan name: "Scan Local Drives"
Scan items:
Configuration:
    Scan inside archives and compressed files: Yes
    Automatically clean up threats: Yes
    Action on infected files: Delete
    Live Protection enabled: Yes

Scan started at 2015-08-07 15:38:45 -0400

New volume detected at /
Unable to initialize threat detection engine: virus data missing or unusable.

Scan stopped at 2015-08-07 15:38:45 -0400.

:1021535


This thread was automatically locked due to age.
Parents
  • So what I've discovered while suffering the same issues, is that it seems that the definitions file (that is regularly updated from the sophos server) becomes unusable for some reason. Re-downloads from the server don't help, leading me to believe that the def file on the server is actually the problem. This has happened several times in the past, but eventually solves itself with the next iteration of the file.

    When the corrupted or blank def file is downloaded scanning goes offline due to an unusable file error when it's trying to use said def file.

    Sophos needs to look into their definition file distribution and close the loop on validating it post-distribution (i.e. test clients).
Reply
  • So what I've discovered while suffering the same issues, is that it seems that the definitions file (that is regularly updated from the sophos server) becomes unusable for some reason. Re-downloads from the server don't help, leading me to believe that the def file on the server is actually the problem. This has happened several times in the past, but eventually solves itself with the next iteration of the file.

    When the corrupted or blank def file is downloaded scanning goes offline due to an unusable file error when it's trying to use said def file.

    Sophos needs to look into their definition file distribution and close the loop on validating it post-distribution (i.e. test clients).
Children
  • Hey Jay,

    What you say makes sense, but we definitely validate the definition files before we distribute them. If we didn't, millions of users would be very unhappy with us!

    For some reason the file is becoming corrupt during the download. One thing you can try is forcing a cache update by running the below command:

    sudo rm -rf /Library/Caches/com.sophos.sau/ ; /usr/bin/SophosUpdate