This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Endpoint Agent Failing on Windows Server 2003

Hi,

We have an issue with an installation of Sophos Endpoint Security And Control on one of our servers.

  1. The Sophos Anti-Virus service is not running and will not start (results in Error 1053)
  2. There are a large number of repeating errors in the Windows Event Log (EventID 13 - ICManager is in a failure state)
  3. The Endpoint software update fails when run

We have other Server 2003 servers running the Endpoint software without issue.

We would like to avoid rebooting the server, if possible, so I'm hoping someone may be able to suggest a course of action?

Many thanks,

Adam.



This thread was automatically locked due to age.
  • Hello Adam,

    the registry keys it mentions do not exist
    HKLM\SYSTEM\CurrentControlSet\Services\SAVOnAccessControl
    ? 0x80070002 is a not found, did you also get the mentioned Event ID 43?

    Sophos Anti-Virus has seemingly been successfully installed? I fear there is no workaround, won't suggest anything I can't test (no more 2003 or XP at hand), especially with a server.

    Christian

  • Hi Christian

    HKLM\SYSTEM\CurrentControlSet\Services\SAVOnAccessControl?

    Correct, the only SAV... keys in that location are SAVAdminService, SAVRKBootTasks and SAVService. There is no corresponding EventID 43 in the Event Log.

    Sophos Anti-Virus has seemingly been successfully installed?

    It would appear so. Everything apart from on-access scanning seems to be working (I can manually scan files, for example).

    won't suggest anything I can't test

    That sounds wise to me, thanks for taking the time to reply anyway. I think the best option may now be to remove the software and reinstall manually (at least the prior work should now allow an uninstall so wasn't wasted effort).

    Adam.

  • Hello Adam,

    does the key perhaps exist in one of the previous ControlSets? Is the SAVOnAccess driver loaded (driverquery /v | find /i "SAVOnAccess" and fltmc instances | find /i "SAVOnAccess")?

    Christian

  • Hi Christian

    It does appear in a few other areas:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESSCONTROL

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessControl

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESSCONTROL

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessControl

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESSCONTROL

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessControl

    Both driver searches return nothing.

    Adam

  • Hello Adam,

    so it's uninstall → reboot → install. Hopefully this will resolve the issues.
    Do not forget to stop at least the AutoUpdate service before you uninstall. Make sure it doesn't start until after the reboot.

    Christian

  • Hi Christian

    That did the trick, thank you. Sophos is now back up-and-running with on-access scanning working as normal.

    Many thanks again for all your help.

    Adam