This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint Security and Control 10.6 - update problem

Hi 

we have 5000 with Sophos AV,

weekly we have user with update problem, the logs seems to be ok:

 

Ora: 14.02.2017 09:38:24

Messaggio: AutoUpdate terminato

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:24

Messaggio: Installazione di Sophos System Protection non eseguita

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:24

Messaggio: Installazione di Sophos AutoUpdate non eseguita

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:24

Messaggio: Installazione di Sophos Network Threat Protection non eseguita

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:24

Messaggio: Installazione di SAVXP non eseguita

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:24

Messaggio: Installazione del prodotto RMSNT non riuscita

Modulo: ALUpdate

ID processo: 11700

ID Thread: 17360

 

Ora: 14.02.2017 09:38:23

Messaggio: Installazione del prodotto RMSNT

Modulo: ALUpdate

ID processo: 11700

ID Thread: 17360

 

Ora: 14.02.2017 09:38:23

Messaggio: Download completato

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Aggiornamento della cache di prodotto dal server primario completato

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Download del prodotto Sophos System Protection dal server \\MyDomain\SophosDFS\CIDs\S000\SAVSCFXP\

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Aggiornamento della cache di prodotto dal server primario completato

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Download del prodotto Sophos AutoUpdate dal server \\MyDomain\SophosDFS\CIDs\S000\SAVSCFXP\

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Aggiornamento della cache di prodotto dal server primario completato

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Download del prodotto Sophos Network Threat Protection dal server \\MyDomain\SophosDFS\CIDs\S000\SAVSCFXP\

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Aggiornamento della cache di prodotto dal server primario completato

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Download del prodotto SAVXP dal server \\MyDomain\SophosDFS\CIDs\S000\SAVSCFXP\

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Aggiornamento della cache di prodotto dal server primario completato

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: Download del prodotto RMSNT dal server \\MyDomain\SophosDFS\CIDs\S000\SAVSCFXP\

Modulo: CIDUpdate

ID processo: 11700

ID Thread: 6872

 

Ora: 14.02.2017 09:38:23

Messaggio: ***************          Sophos AutoUpdate avviato          ***************

Modulo: ALUpdate

ID processo: 11700

ID Thread: 6872

 

On the computer tray taskbar sophos says "update failed" (red cross on the sophos icon).

I tried all procedure to remove and reinstall the software but the problem persists.

On the Sophos Enterprise Console I see the computer gray status with Error icon, Computer Details says "This computer is not yet managed. It is protected but has not reported back its status".

 

The telnet test port is ok.

 

Thanks for help me

Regards

FM

 

 

 

 



This thread was automatically locked due to age.
Parents
  • Hello FM,

    Installazione del prodotto RMSNT non riuscita
    Installation of RMS failed and as RMS is needed to communicate with SEC the computer is naturally grey. Apparently the failure is reproducible, the logs should give an insight. You should find them in %windir%\Temp\, Sophos RMS.... and ClientMRInit.... are the ones associated with the install.

    Christian

  • Hi Christian,

    thanks for your message!

    Log say:

     

    Install from:[C:\ProgramData\Sophos\AutoUpdate\cache\rms]
    Install to :[(null)]
    MsiPackagePath: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\Sophos Remote Management System.msi].
    Result of loading C:\Program Files (x86)\Sophos\AutoUpdate\SAUConfigDLL.dll is: [fd30000]
    LOGIC: Installed version is less than 4 (minor upgrade is n/a).
    LOGIC: Unistall needed
    Uninstallation of installed RMS required
    UNINSTALL: Using backup path C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup
    RMS-BACKUP: Starting back up...
    RMS-BACKUP: Get list of processes and services to stop.
    RMS-BACKUP: Retrieved [].
    RMS-BACKUP: Parsed WaitForProcesses and ListOfServices - OK.
    RMS-BACKUP: Try to stop services.
    RMS-BACKUP: Stopped services with ServiceController() - OK.
    RMS-BACKUP: Waiting for processes to disappear.
    RMS-BACKUP: Waited for processes - OK.
    RMS-BACKUP: Retrieving the CommonAppData folder.
    RMS-BACKUP: Retrieved source: [C:\ProgramData\Sophos\Remote Management System\3].
    RMS-BACKUP: Retrieved backup: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup].
    RMS-BACKUP: Directory: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup] existed.
    RMS-BACKUP: Backing up registry content
    Running Command: regedit /E "C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup_reg\rms_registry.reg" "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Remote Management System"
    Command returned 0
    Running Command: regedit /E "C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup_reg\messaging_registry.reg" "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Messaging System"
    Command returned 0
    UNINSTALL: Preserving cac.pem and mrinit.conf files
    UNINSTALL: cac.pem and mrinit.conf files preserved
    UNINSTALL: Removing RMS using cached msi with command: REBOOT=ReallySuppress SOPHOS_TP_TOKEN=1
    UNINSTALL: removing RMS using package msi by running MsiInstallProduct(C:\ProgramData\Sophos\AutoUpdate\cache\rms\Sophos Remote Management System.msi, "REBOOT=ReallySuppress REMOVE=ALL SOPHOS_TP_TOKEN=1")
    UNINSTALL: !RMS Setup plugin: Removal of old RMS returned exit code 1605

    Thanks

    Regards

    FM

Reply
  • Hi Christian,

    thanks for your message!

    Log say:

     

    Install from:[C:\ProgramData\Sophos\AutoUpdate\cache\rms]
    Install to :[(null)]
    MsiPackagePath: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\Sophos Remote Management System.msi].
    Result of loading C:\Program Files (x86)\Sophos\AutoUpdate\SAUConfigDLL.dll is: [fd30000]
    LOGIC: Installed version is less than 4 (minor upgrade is n/a).
    LOGIC: Unistall needed
    Uninstallation of installed RMS required
    UNINSTALL: Using backup path C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup
    RMS-BACKUP: Starting back up...
    RMS-BACKUP: Get list of processes and services to stop.
    RMS-BACKUP: Retrieved [].
    RMS-BACKUP: Parsed WaitForProcesses and ListOfServices - OK.
    RMS-BACKUP: Try to stop services.
    RMS-BACKUP: Stopped services with ServiceController() - OK.
    RMS-BACKUP: Waiting for processes to disappear.
    RMS-BACKUP: Waited for processes - OK.
    RMS-BACKUP: Retrieving the CommonAppData folder.
    RMS-BACKUP: Retrieved source: [C:\ProgramData\Sophos\Remote Management System\3].
    RMS-BACKUP: Retrieved backup: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup].
    RMS-BACKUP: Directory: [C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup] existed.
    RMS-BACKUP: Backing up registry content
    Running Command: regedit /E "C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup_reg\rms_registry.reg" "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Remote Management System"
    Command returned 0
    Running Command: regedit /E "C:\ProgramData\Sophos\AutoUpdate\cache\rms\installer_backup_reg\messaging_registry.reg" "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Messaging System"
    Command returned 0
    UNINSTALL: Preserving cac.pem and mrinit.conf files
    UNINSTALL: cac.pem and mrinit.conf files preserved
    UNINSTALL: Removing RMS using cached msi with command: REBOOT=ReallySuppress SOPHOS_TP_TOKEN=1
    UNINSTALL: removing RMS using package msi by running MsiInstallProduct(C:\ProgramData\Sophos\AutoUpdate\cache\rms\Sophos Remote Management System.msi, "REBOOT=ReallySuppress REMOVE=ALL SOPHOS_TP_TOKEN=1")
    UNINSTALL: !RMS Setup plugin: Removal of old RMS returned exit code 1605

    Thanks

    Regards

    FM

Children