Sophos Endpoint for server, not updating and FIM service is not installing

Hi all,

I have a couple of issues:

Sophos failed to update, according to logs:
2022-01-11T11:39:53.683Z [ 9188:20292] E Failed to save subscriptions, error: Failed to set registry string value: Access is denied. (5)
2022-01-11T11:39:53.686Z [ 9188:20292] I Saving state to C:\ProgramData\Sophos\AutoUpdate\data\status\SophosUpdateStatus.xml
2022-01-11T11:39:53.715Z [ 9188:20292] E SophosUpdate is exiting with a failure: Failed to set registry value of type DWORD: Access is denied. (5) (exit 1).

As well, FIM service is stopped, and I can't start it, error comes up.

Does anyone have ideas?

Full Uninstalling sophos endpoint didn't help, did a couple of times.

Always failed on the registries.

Thanks,
Zair



Added TAGs
[edited by: Qoosh at 6:31 PM (GMT -8) on 18 Jan 2022]
  • Update: turned temper protection off, ran update again: new logs:

    2022-01-11T12:12:11.286Z [12764:21792] I Last update failed: forcing full decode.
    2022-01-11T12:13:07.384Z [17968: 9368] W Failed to install product 1129226C-32AB-4B72-85E1-A9CC8DFBC859.
    2022-01-11T12:13:07.394Z [17968: 9368] E su-setup32.exe has failed: Failed to set registry string value: Access is denied. (5).
    2022-01-11T12:13:07.404Z [12764:21792] E su-setup: exit 1
    2022-01-11T12:13:07.408Z [12764:21792] I Processing install failed Health event for: {1129226C-32AB-4B72-85E1-A9CC8DFBC859} (Sophos Endpoint Defense for Windows (64-bit))
    2022-01-11T12:13:07.408Z [12764:21792] E Could not create SOFTWARE\Sophos\AutoUpdate\UpdateStatus\HealthEvents with error: 5
    2022-01-11T12:13:07.413Z [12764:21792] E Failed to save subscriptions, error: Failed to set registry string value: Access is denied. (5)
    2022-01-11T12:13:07.417Z [12764:21792] I Saving state to C:\ProgramData\Sophos\AutoUpdate\data\status\SophosUpdateStatus.xml
    2022-01-11T12:13:07.442Z [12764:21792] I Installing component 3799FB3E-808A-4F7D-AC6A-0C74F931C386 (mcsep) 4.15.70.0
    2022-01-11T12:13:07.443Z [12764:21792] E UpdateLastInstallStartedTime: Failed to write LastInstallStartedTime: 5
    2022-01-11T12:13:07.448Z [12764:21792] I Checking manifest:C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\mcsep\flags_cepngsrv_manifest.dat
    2022-01-11T12:13:07.462Z [12764:21792] I Checking manifest:C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\mcsep\flags_cixsrv_manifest.dat
    2022-01-11T12:13:07.475Z [12764:21792] I Checking manifest:C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\mcsep\manifest.dat
    2022-01-11T12:13:07.609Z [12764:21792] I setupDll='C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\mcsep\setup.dll'; setupExe='C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\su-setup32.exe'.
    2022-01-11T12:13:07.610Z [12764:21792] E Exception thrown during installation: Failed to set registry multi-string value: Access is denied. (5).
    2022-01-11T12:13:07.615Z [12764:21792] E StoreUpdateDetails[0253775E-970D-4876-959C-21B422420E5A]: failed to save name: 5
    2022-01-11T12:13:07.618Z [12764:21792] E StoreUpdateDetails[0253775E-970D-4876-959C-21B422420E5A]: failed to save longName:5
    2022-01-11T12:13:07.620Z [12764:21792] E StoreUpdateDetails[0253775E-970D-4876-959C-21B422420E5A]: failed to save downloaded version: 5
    2022-01-11T12:13:07.623Z [12764:21792] E StoreUpdateDetails[1129226C-32AB-4B72-85E1-A9CC8DFBC859]: failed to save name: 5
    2022-01-11T12:13:07.625Z [12764:21792] E StoreUpdateDetails[1129226C-32AB-4B72-85E1-A9CC8DFBC859]: failed to save longName:5
    2022-01-11T12:13:07.628Z [12764:21792] E StoreUpdateDetails[1129226C-32AB-4B72-85E1-A9CC8DFBC859]: failed to save downloaded version: 5
    2022-01-11T12:13:07.631Z [12764:21792] E StoreUpdateDetails[1FE3E7DF-EFFA-408A-A1B0-89F15BA61F31]: failed to save name: 5
    2022-01-11T12:13:07.633Z [12764:21792] E StoreUpdateDetails[1FE3E7DF-EFFA-408A-A1B0-89F15BA61F31]: failed to save longName:5
    2022-01-11T12:13:07.636Z [12764:21792] E StoreUpdateDetails[1FE3E7DF-EFFA-408A-A1B0-89F15BA61F31]: failed to save downloaded version: 5
    2022-01-11T12:13:07.643Z [12764:21792] E StoreUpdateDetails[244E68BF-E1BB-4A6B-AC18-A492DE0134C0]: failed to save name: 5
    2022-01-11T12:13:07.646Z [12764:21792] E StoreUpdateDetails[244E68BF-E1BB-4A6B-AC18-A492DE0134C0]: failed to save longName:5
    2022-01-11T12:13:07.650Z [12764:21792] E StoreUpdateDetails[244E68BF-E1BB-4A6B-AC18-A492DE0134C0]: failed to save downloaded version: 5
    2022-01-11T12:13:07.653Z [12764:21792] E StoreUpdateDetails[3799FB3E-808A-4F7D-AC6A-0C74F931C386]: failed to save name: 5
    2022-01-11T12:13:07.656Z [12764:21792] E StoreUpdateDetails[3799FB3E-808A-4F7D-AC6A-0C74F931C386]: failed to save longName:5
    2022-01-11T12:13:07.659Z [12764:21792] E StoreUpdateDetails[3799FB3E-808A-4F7D-AC6A-0C74F931C386]: failed to save downloaded version: 5
    2022-01-11T12:13:07.662Z [12764:21792] E StoreUpdateDetails[3CE954A1-0F41-4D9B-B2F0-58AA75334DFD]: failed to save name: 5
    2022-01-11T12:13:07.665Z [12764:21792] E StoreUpdateDetails[3CE954A1-0F41-4D9B-B2F0-58AA75334DFD]: failed to save longName:5
    2022-01-11T12:13:07.667Z [12764:21792] E StoreUpdateDetails[3CE954A1-0F41-4D9B-B2F0-58AA75334DFD]: failed to save downloaded version: 5
    2022-01-11T12:13:07.670Z [12764:21792] E StoreUpdateDetails[3D8DC0A9-7F42-4CD5-AA7B-CF29296E7789]: failed to save name: 5
    2022-01-11T12:13:07.672Z [12764:21792] E StoreUpdateDetails[3D8DC0A9-7F42-4CD5-AA7B-CF29296E7789]: failed to save longName:5
    2022-01-11T12:13:07.675Z [12764:21792] E StoreUpdateDetails[3D8DC0A9-7F42-4CD5-AA7B-CF29296E7789]: failed to save downloaded version: 5
    2022-01-11T12:13:07.679Z [12764:21792] E StoreUpdateDetails[591706A7-9603-4255-A65F-EA49BB11E8AC]: failed to save name: 5
    2022-01-11T12:13:07.686Z [12764:21792] E StoreUpdateDetails[591706A7-9603-4255-A65F-EA49BB11E8AC]: failed to save longName:5
    2022-01-11T12:13:07.689Z [12764:21792] E StoreUpdateDetails[591706A7-9603-4255-A65F-EA49BB11E8AC]: failed to save downloaded version: 5
    2022-01-11T12:13:07.692Z [12764:21792] E StoreUpdateDetails[5CD1A7B6-812E-47A1-A986-3A6D5D5C19F5]: failed to save name: 5
    2022-01-11T12:13:07.695Z [12764:21792] E StoreUpdateDetails[5CD1A7B6-812E-47A1-A986-3A6D5D5C19F5]: failed to save longName:5
    2022-01-11T12:13:07.697Z [12764:21792] E StoreUpdateDetails[5CD1A7B6-812E-47A1-A986-3A6D5D5C19F5]: failed to save downloaded version: 5
    2022-01-11T12:13:07.702Z [12764:21792] E StoreUpdateDetails[642A6FD9-A9D6-482D-BD8C-46661F241A0E]: failed to save name: 5
    2022-01-11T12:13:07.705Z [12764:21792] E StoreUpdateDetails[642A6FD9-A9D6-482D-BD8C-46661F241A0E]: failed to save longName:5
    2022-01-11T12:13:07.708Z [12764:21792] E StoreUpdateDetails[642A6FD9-A9D6-482D-BD8C-46661F241A0E]: failed to save downloaded version: 5
    2022-01-11T12:13:07.711Z [12764:21792] E StoreUpdateDetails[70FDD40E-986A-44E5-9620-2B894A06702A]: failed to save name: 5
    2022-01-11T12:13:07.714Z [12764:21792] E StoreUpdateDetails[70FDD40E-986A-44E5-9620-2B894A06702A]: failed to save longName:5
    2022-01-11T12:13:07.716Z [12764:21792] E StoreUpdateDetails[70FDD40E-986A-44E5-9620-2B894A06702A]: failed to save downloaded version: 5
    2022-01-11T12:13:07.719Z [12764:21792] E StoreUpdateDetails[7F682906-6E49-481B-89C5-2DCA36720F4F]: failed to save name: 5
    2022-01-11T12:13:07.722Z [12764:21792] E StoreUpdateDetails[7F682906-6E49-481B-89C5-2DCA36720F4F]: failed to save longName:5
    2022-01-11T12:13:07.725Z [12764:21792] E StoreUpdateDetails[7F682906-6E49-481B-89C5-2DCA36720F4F]: failed to save downloaded version: 5
    2022-01-11T12:13:07.728Z [12764:21792] E StoreUpdateDetails[CD297D6B-58A5-474F-8A0D-0A15803B8B50]: failed to save name: 5
    2022-01-11T12:13:07.731Z [12764:21792] E StoreUpdateDetails[CD297D6B-58A5-474F-8A0D-0A15803B8B50]: failed to save longName:5
    2022-01-11T12:13:07.734Z [12764:21792] E StoreUpdateDetails[CD297D6B-58A5-474F-8A0D-0A15803B8B50]: failed to save downloaded version: 5
    2022-01-11T12:13:07.736Z [12764:21792] E StoreUpdateDetails[E17FE03B-0501-4aaa-BC69-0129D965F311]: failed to save name: 5
    2022-01-11T12:13:07.739Z [12764:21792] E StoreUpdateDetails[E17FE03B-0501-4aaa-BC69-0129D965F311]: failed to save longName:5
    2022-01-11T12:13:07.742Z [12764:21792] E StoreUpdateDetails[E17FE03B-0501-4aaa-BC69-0129D965F311]: failed to save downloaded version: 5
    2022-01-11T12:13:07.745Z [12764:21792] E StoreUpdateDetails[ENG]: failed to save name: 5
    2022-01-11T12:13:07.747Z [12764:21792] E StoreUpdateDetails[ENG]: failed to save longName:5
    2022-01-11T12:13:07.749Z [12764:21792] E StoreUpdateDetails[ENG]: failed to save downloaded version: 5
    2022-01-11T12:13:07.752Z [12764:21792] E StoreUpdateDetails[FileIntegrityMonitoring]: failed to save name: 5
    2022-01-11T12:13:07.755Z [12764:21792] E StoreUpdateDetails[FileIntegrityMonitoring]: failed to save longName:5
    2022-01-11T12:13:07.758Z [12764:21792] E StoreUpdateDetails[FileIntegrityMonitoring]: failed to save downloaded version: 5
    2022-01-11T12:13:07.761Z [12764:21792] E StoreUpdateDetails[NTP64]: failed to save name: 5
    2022-01-11T12:13:07.763Z [12764:21792] E StoreUpdateDetails[NTP64]: failed to save longName:5
    2022-01-11T12:13:07.766Z [12764:21792] E StoreUpdateDetails[NTP64]: failed to save downloaded version: 5
    2022-01-11T12:13:07.771Z [12764:21792] I Sending telemetry every 86400s
    2022-01-11T12:13:07.771Z [12764:21792] I Telemetry last ran at 2022-01-10 10:33:08Z; offset time 2022-01-10 12:06:32Z (offset 5604s)
    2022-01-11T12:13:07.771Z [12764:21792] I Telemetry schedule has elapsed.
    2022-01-11T12:13:07.771Z [12764:21792] I Gathering Telemetry
    2022-01-11T12:13:38.710Z [12764:21792] E SetUpdateStatus: Failed to write LastUpdateTime:5
    2022-01-11T12:13:38.713Z [12764:21792] E SetUpdateStatus: Failed to write Result:5
    2022-01-11T12:13:38.716Z [12764:21792] E SetUpdateStatus: Failed to write FirstFailedUpdateTime: 5
    2022-01-11T12:13:38.722Z [12764:21792] E Failed to save subscriptions, error: Failed to set registry string value: Access is denied. (5)
    2022-01-11T12:13:38.725Z [12764:21792] I Saving state to C:\ProgramData\Sophos\AutoUpdate\data\status\SophosUpdateStatus.xml
    2022-01-11T12:13:38.795Z [12764:21792] A SophosUpdate has completed (exit 4).

  • Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Paths paths was incorrect, volumes incorrect, fixed and volumes, all good.