Web protection is no longer functional. The filtering driver has been bypassed or unloaded [0xa058000c] Windows 10 1703

I have an open ticket with Sophos about this issue popping up on about 17 machines that were just recently updated to Windows 10 1703 from Windows 10 1607. Tried the following KB 114350 with Zero luck in getting this resolved. I have tried Uninstalling and Reinstalling both manually on the console, and through the "Protect Computers" option within the Enterprise Console.  Even created a Group with the recommended policies as suggested within the KB article with no luck on that either. going to http://sophostest.com/malware/index.html to test and verify the machines are protected results in the website not being blocked. Looking for any ideas that might help resolve this issue once in for all. 

 

Thank you,

 

Jamie

  • In reply to Jamie Ojida:

    Jamie / JAK

     

    Thank you for sharing the details. I am setting it up now and will apply it to a subset of test systems. I will update later with results.

     

    thanks again

    -John

  • In reply to Jamie Ojida:

    Jamie / JAK

     

    Thank you for sharing the details. I set this up and applied it to a subset of test systems. Results are mixed. The issue with Web Protection appears to be resolved. No additional errors reported. However, Edge still does not correctly block SophoTest pages, yet Chrome and Firefox on the same system will block correctly

     

     

    -John

  • In reply to John Comes:

    If you look at the list of processes on the computer in Process Explorer, you should see the browser processes talking to swi_fc.exe.

    Looking at the TCP/IP tab of swi_fc.exe you should see the port swi_fc.exe is listening on, e.g. 12080

    In the case of Edge, the process talking to swi_fc.exe over loopback should be MicrosoftEdgeCP.exe. 

    To identify the process making the connection, if you open Edge, drag the cross-hair icon of Process Explorer onto the Edge Window it should focus in on one of the MicrosoftEdgeCP.exe processes in question. 

    If you look at the TCP/IP tab of that process, do you see it connecting to swi_fc.exe or straight out of the computer?  If it's not pointing to the port swi_fc.exe is listening on then the redirection is not working.

    Regards,

    Jak

  • In reply to jak:

    We have been getting these two from the first day we deployed SEC.

    I now have a Preview group setup but the issue for us is the W10 deployment not being done by department. so applying the preview is going to be kinda difficult.

    Has there been any know issues with 10.7.6?

  • In reply to Jamie Ojida:

    I have been also doing some testing with Windows 10 and Preview subscriptions.

    It works but there is a flaw with subscription.  You can't have an OU that has both Preview (newest version) and recommended (current version) AV software installed.

    This can be a real big problem if you have other application that use the OU structure.

    If you create an OU just for Preview the PCs in that OU can never move to an OU that has Recommended applied because preview will uninstall and recommended will install.

    This not good and what I would call a major flaw.

    So to add to this flaw, any time preview goes recommended any endpoints that have an issue with newest version will require you adjust your AD OU structure to apply the older version.

    Correct me if I am wrong.  And if I remember right you don't get to decide if you want preview to go recommended on your SEC, it will just happen as this is what happen to us when 10.7 replaced 10.6.