This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to prevent SophosHome from blocking USB Drives or alternatively stop service to allow safe eject ?

App: Sophos Home Free

OS: Windows 7

 

The subject says it all... I realize many apps and especially A/V's block disks (meaning they cannot be safely ejected). Most A/V's however have a suspend action that allows to quickly do operations that are otherwise prevented by A/V protection. Frankly I am taken aback by the very simple UI. It would be nice to look at settings, suspend, etc from the desktop (as opposed to the web app).

I see there are many services, is that the best way to stop SH ? Which one specifically?

Feature request: right click from sys tray > Suspend for 10 minutes

Thank you,

Simon



This thread was automatically locked due to age.
Parents
  • Its Sep 2020 and the issue still seems to be happening. Was wondering if anybody found a resolution for this? From event viewer, it clearly shows that Sophos is blocking safe removal of the USB drive. Event viewer message "The application \Device\HarddiskVolume4\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe with process id 3532 stopped the removal or ejection for the device USB\VID_1F75&PID_0621\20180507."

  • Hello Sophos User3153,

    as said, I suspect some other software to be involved (this is just an example but note the remarks under Besides).

    Christian

  • Hi Christian,

     

    thanks for your quick reply. Yes, there is one more entry showing in the event viewer as "The application System with process id 4 stopped the removal or ejection for the device USB\VID_1F75&PID_0621\20180507". This I believe is a common event when any third party app (in this case Sophos) is holding on to the external drive and prevents eject. So surely the culprit here should be Sophos.

     

    Thanks & Regards

    Arfath

  • Hello Arfath,

    System with process id 4 stopped the removal [...] is normally not a common event when any third party app returns BROADCAST_QUERY_DENY. If an application can't release a drive you get just one event naming this application.

    Normally Sophos is not holding on to the external drive. If it'd do this even only every 100th time I'd have heard - fifteen years, several thousand endpoints. I'm pretty sure it doesn't happen without a participating second (or fourth) party that's not a regular application but one that does some permissible low-level twiddling. Mind you, there's presumably not really a culprit. Fact is, two components simply don't go together.

    Christian

  • Thank you. Well noted.

Reply Children
No Data