Dear
I have problem that one of computer cannot get installing Sophos antivirus for Windows 2000+ , can someone guide me how to fix it ?
I have check the Sophos Anti Virus install log found error the following:
Sophos Anti-Virus Major Install Log_171025_044105.txt
2017-10-25 05:41:07 ExtractClassicConfig: Action started 2017-10-25 05:41:07 ExtractClassicConfig: Action succeeded 2017-10-25 05:41:07 PreInstallChecks: Action started 2017-10-25 05:41:07 PreInstallChecks: Action succeeded 2017-10-25 05:41:07 SetBootDriverStartupProperty: Action started 2017-10-25 05:41:07 SetBootDriverStartupProperty: Boot driver: not installed. 2017-10-25 05:41:07 SetBootDriverStartupProperty: Action succeeded 2017-10-25 05:41:07 SetClassFilterPresentProperty: Action started 2017-10-25 05:41:07 SetClassFilterPresentProperty: Setting class filter present property to: 1 2017-10-25 05:41:07 SetClassFilterPresentProperty: Action succeeded 2017-10-25 05:41:07 SetDriverProperty: Action started 2017-10-25 05:41:07 SetDriverProperty: PROCESSOR_ARCHITECTURE environment variable is: AMD64 2017-10-25 05:41:07 SetDriverProperty: Action succeeded 2017-10-25 05:41:07 SetProcessorProperties: Action started 2017-10-25 05:41:07 SetProcessorProperties: Action succeeded 2017-10-25 05:41:07 SetRestoreExcludedProcessesProperty: Action started 2017-10-25 05:41:07 SetRestoreExcludedProcessesProperty: SetRestoreExcludedProcessesProperty 2017-10-25 05:41:07 SetRestoreExcludedProcessesProperty: PROCESSOR_ARCHITECTURE environment variable is: AMD64 2017-10-25 05:41:07 SetRestoreExcludedProcessesProperty: Action succeeded 2017-10-25 05:41:14 CheckRegForNullDACLs: Action started 2017-10-25 05:41:14 CheckRegForNullDACLs: Action succeeded 2017-10-25 05:41:14 SetUpdateBegin: Action started 2017-10-25 05:41:14 SetUpdateBegin: Unable to create an instance of ComponentManager - SystemInformation will not be informed of the update (0x80040154) 2017-10-25 05:41:14 SetUpdateBegin: Action succeeded 2017-10-25 05:41:14 CloseSavMainWindow: Action started 2017-10-25 05:41:14 CloseSavMainWindow: CloseSavMainWindow: failed to open Software\Sophos\SAVUI 2 2017-10-25 05:41:14 CloseSavMainWindow: Action succeeded 2017-10-25 05:41:14 DisableServices: Action started 2017-10-25 05:41:14 DisableServices: SetServiceStartMode failed: Unable to get a handle to requested service SAVAdminService, error 1060. 2017-10-25 05:41:14 DisableServices: DisableServices failed to disable SAVAdminService 2017-10-25 05:41:14 DisableServices: Action succeeded 2017-10-25 05:41:14 ForceStopSAVService: Action started 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Stopping SAVService 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Checking if service is still running 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Stopping SAVAdminService 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: service failed to stop, hr=0x80070424 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Terminating the service 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Terminate failed, hr=0x80070424 2017-10-25 05:41:14 ForceStopSAVService: ForceStopService: Checking if service is still running 2017-10-25 05:41:14 ForceStopSAVService: ForceStopSAVService: Services have been stopped 2017-10-25 05:41:14 ForceStopSAVService: Action succeeded 2017-10-25 05:41:14 WaitForSAVService: Action started 2017-10-25 05:41:14 WaitForSAVService: WaitForSAVService: Walking system processes... 2017-10-25 05:41:14 WaitForSAVService: WaitForSAVService: Finished walking system processes. 2017-10-25 05:41:14 WaitForSAVService: Action succeeded 2017-10-25 05:41:15 CheckUninstallDrivers: Action started 2017-10-25 05:41:15 CheckUninstallDrivers: IsServiceInstalled: Unable to get a handle to requested service SAVOnAccess control. Returning false. 2017-10-25 05:41:15 CheckUninstallDrivers: IsServiceInstalled: Unable to get a handle to requested service SAVOnAccess filter. Returning false. 2017-10-25 05:41:15 CheckUninstallDrivers: Action succeeded 2017-10-25 05:41:15 RollbackDisableServices: Action started 2017-10-25 05:41:15 RollbackDisableServices: SetServiceStartMode failed: Unable to get a handle to requested service SAVAdminService, error 1060. 2017-10-25 05:41:15 RollbackDisableServices: RollbackDisableServices failed to enable SAVAdminService 2017-10-25 05:41:15 RollbackDisableServices: Action succeeded 2017-10-25 05:41:16 RunErrorScripts: Action started 2017-10-25 05:41:16 RunErrorScripts: Action succeeded 2017-10-25 05:41:16 RestoreMovedFiles: Action started 2017-10-25 05:41:16 RestoreMovedFiles: RestoreMovedFiles(): Unexpected error 0x00000003 when looking for temporary files 2017-10-25 05:41:16 RestoreMovedFiles: Action succeeded 2017-10-25 05:41:16 SetUpdateFailed: Action started 2017-10-25 05:41:16 SetUpdateFailed: Unable to create an instance of ComponentManager - SystemInformation cannot be informed of end of update 2017-10-25 05:41:16 SetUpdateFailed: Action succeeded
MSI (s) (18:64) [05:41:15:012]: Executing op: ActionStart(Name=UninstallDriverFiles64OnUpdate,,)
MSI (s) (18:64) [05:41:15:012]: Executing op: CustomActionSchedule(Action=UninstallDriverFiles64OnUpdate,ActionType=1058,Source=C:\Windows\SysWOW64\,Target="C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF",)
MSI (s) (18:64) [05:41:15:013]: Note: 1: 1721 2: UninstallDriverFiles64OnUpdate 3: C:\Windows\SysWOW64\ 4: "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF"
MSI (s) (18:64) [05:41:15:013]: Product: Sophos Anti-Virus -- Error 1721.There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: UninstallDriverFiles64OnUpdate, location: C:\Windows\SysWOW64\, command: "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF"
MSI (s) (18:64) [05:41:15:021]: User policy value 'DisableRollback' is 0
MSI (s) (18:64) [05:41:15:021]: Machine policy value 'DisableRollback' is 0
Action ended 5:41:15: InstallFinalize. Return value 3.
Is the error. I'm a little confused given this is an install where the following line is present:
2017-10-25 05:41:04 Info: SAV is not installed. Installing to {InstallToPath}
It seems like it should be a fresh install so why it it uninstalling drivers?
On the computer after the failed install has rolled back, do you have files under:
C:\program files (x86)\sophos\sophos anti-virus\
Was SAV once installed and ripped off in some way leaving behind some files?
I would initially run Process Monitor while performing an install to see what is going on when the above line in the logs is thrown. Does it fail to find Native.exe in:
C:\program files (x86)\sophos\sophos anti-virus\ or fail to find it?
If so, maybe copy if from:
C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\native\amd64
to
C:\program files (x86)\sophos\sophos anti-virus\
and try again? Does it fail at another step?
Maybe also it's also missing: savonaccessdriv.inf, sdcfilter.inf and SophosBootDriver.inf from C:\program files (x86)\sophos\sophos anti-virus\ These could also be copied from
C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\drivers\onaccess\win7_amd64\
C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\drivers\sdcfilter\win7_amd64\
C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\drivers\boottasks\win7_amd64
Hope it helps.
Regards,
Jak