This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NEED HELP - "[19869] virus daemon error found in request" after License Update!

Hello Community, I need help immediately!

I updated the license for a Sophos SG450 running UTM 9.508-10. Licence now shows no more errors, but every web call fails with "Virus found - the web application firewall has found the following virus while downloading /: daemon error". We already use single engine scans with Avira. The only thing that helped was to disable av scans in the WAF.

The Log shows this: "2019:12:06-14:04:57 xxx.xxx httpd[19869]: [avscan:error] [pid 19869:tid 3734772592] [client xxx.xxx.xxx.xxx:35959] [19869] virus daemon error found in request /[...]
2019:12:06-14:04:57 xxx httpd: id="0299" srcip="xxx.xxx.xxx.xxx" localip="xxx.xxx.xxx.xxx" size="203" user="-" host="xxx.xxx.xxx.xxx" method="GET" statuscode="403" reason="av" extra="virus daemon error found" exceptions="-" time="10300" url="[...]" server="serveradress.com" port="443" query="" referer="-" cookie="-" set-cookie="-" uid="XepR@QrwBAEAAE2dtDgAAACT""

(masked for privacy reasons)

What is causing this?

Any help is much appreciated!

  Markus



This thread was automatically locked due to age.
Parents
  • Hi!

    Two more things I found out.

    First: the new license got sandstorm whereas the old didn't.

    Second: following can be seen in the fallback.log:

    2019:12:06-14:04:56 xxx.xxx [daemon:info] irqd[7350]:  rebalance started (every 5 sec)
    2019:12:06-14:04:56 xxx.xxx [daemon:notice] sandbox_reportd.plx[7316]:  [SANDBOX-REPORTD] Starting up
    2019:12:06-14:04:56 xxx.xxx [daemon:notice] sandbox_reportd.plx[7316]:  [SANDBOX-REPORTD] Reloaded configuration
    2019:12:06-14:04:56 xxx.xxx [daemon:info] cssd[7290]:  [     (nil)] avira_init (avira.c:79) failed to load Avira engine: aviraglue_init() failed to initialize SAVAPI: VDF file crc failed
    2019:12:06-14:04:56 xxx.xxx [daemon:info] cssd[7290]:  [     (nil)] main (cssd.c:434) virus scanner initialization finished
    2019:12:06-14:04:58 xxx.xxx [daemon:notice] sandbox_reportd.plx[7465]:  [SANDBOX-REPORTD] Starting up
    2019:12:06-14:04:58 xxx.xxx [daemon:notice] sandbox_reportd.plx[7465]:  [SANDBOX-REPORTD] Reloaded configuration

    Can the sandstorm feature break Avira? And how can I restart the Avira engine (I think this might solve the issue)?

    Man thanks in advance!

      Markus

     
  • don't know how to restart avira ... but try to use single-scan with sophos ...


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply Children
No Data