Hi,
Since moving our Win7SP1x64 machines to version 10.6.3 we found that the Anti-Virus service does not start. It returns the error code -2147467259 from the Services MMC window and an entry is also posted to the Application event log with an ID 0 and message CInfrastructureModule::PreMessageLoop.
I've searched various KB Articles and Forum posts and tried/checked out the follow solutions:
- SAVI.dll registration and registry entries - https://community.sophos.com/products/endpoint-security-control/f/3/t/3497
- Local Service account not a member of the Guests security group - https://www.sophos.com/en-us/support/knowledgebase/110683.aspx
- Ran reinstall/repair of MS VCReDist 2008 SP1, 2010 SP1 & 2012 as unable to find package in cache folder - https://www.sophos.com/support/knowledgebase/122899.aspx
- Checked that Windows Security Update KB3072630 has been installed (It was back in Sept 2015) - https://www.sophos.com/en-us/support/knowledgebase/124250.aspx
The end of the C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\Sophos Anti-Virus Start Log_yymmdd_hhmmss.txt file has the following lines:
2016-06-09 14:03:29 CStartupManager::RegisterComponents: Starting RegisterYourself on WebScanningProcessorFactory
2016-06-09 14:03:29 CStartupManager::RegisterComponents: Completed RegisterYourself on WebScanningProcessorFactory
2016-06-09 14:03:29 Entering CStartupManager::ConfigureComponentManager
2016-06-09 14:03:29 Leaving CStartupManager::ConfigureComponentManager
2016-06-09 14:03:29 Entering CStartupManager::BeginComponentManager
2016-06-09 14:03:44 CStartupManager::BeginComponentManager: m_CompMan->BeginProcessing() returned 0x80004005
2016-06-09 14:03:44 Leaving CStartupManager::BeginComponentManager
2016-06-09 14:03:44 Leaving CStartupManager::Start
2016-06-09 14:03:44 CMarshallingWrapper::CMarshallingWrapper: SM.Start( g_RegPath, pManager )() returned 0x80004005
2016-06-09 14:03:44 Exception caught in CInfrastructureModule::PreMessageLoop
2016-06-09 14:03:44 Leaving CInfrastructureModule::PreMessageLoop
2016-06-09 14:03:54 Leaving CInfrastructureModule::ServiceMain
2016-06-09 14:03:54 Leaving wWinMain
Thanks in advance :-)
Hugo
This thread was automatically locked due to age.