Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to install sophos for server

Hello i'm unable to install sophos on my server this is my log for the installation:

Started C:\Users\ADMINI~1\AppData\Local\Temp\1\sfl-41203000\Setup.exe
2018-10-06T21:40:24.1738172Z INFO : Stage 1 command-line options:
2018-10-06T21:40:24.1738172Z INFO : ---
2018-10-06T21:40:24.1738172Z INFO : Quiet mode on: 0
2018-10-06T21:40:24.1738172Z INFO : Automatic Proxy detection disabled: 0
2018-10-06T21:40:24.1738172Z INFO : No feedback mode on: 0
2018-10-06T21:40:24.1738172Z INFO : Dump feedback enabled: 0
2018-10-06T21:40:24.1738172Z INFO : Bypass competitor removal: 0
2018-10-06T21:40:24.1738172Z INFO : Using CRT catalog file path: --
2018-10-06T21:40:24.1738172Z INFO : Only register endpoint with Central: 0
2018-10-06T21:40:24.1738172Z INFO : Log messages between endpoint and Central: 0
2018-10-06T21:40:24.1738172Z INFO : Log command-line passed to executables: 0
2018-10-06T21:40:24.1738172Z INFO : Using custom server: --
2018-10-06T21:40:24.1738172Z INFO : Using custom stage 2 filename: --
2018-10-06T21:40:24.1738172Z INFO : Using cloud user: --
2018-10-06T21:40:24.1738172Z INFO : Using cloud group: --
2018-10-06T21:40:24.1738172Z INFO : Overriding computer name: --
2018-10-06T21:40:24.1738172Z INFO : Overriding computer description: --
2018-10-06T21:40:24.1738172Z INFO : Overriding domain name: --
2018-10-06T21:40:24.1738172Z INFO : Language will be set to: --
2018-10-06T21:40:24.1738172Z INFO : Using message relays: --
2018-10-06T21:40:24.1894396Z INFO : Proxy address: --
2018-10-06T21:40:24.1894396Z INFO : Proxy user name: --
2018-10-06T21:40:24.1894396Z INFO : Using custom customer token: --
2018-10-06T21:40:24.1894396Z INFO : Using specified products: --
2018-10-06T21:40:24.1894396Z INFO : Using certificates from the MCS app data folder: 0
2018-10-06T21:40:24.1894396Z INFO : ---
2018-10-06T21:40:24.2050677Z INFO : Sending HTTP 'GET' request to: full/central/windows/business/installer/latest.tar.gz
2018-10-06T21:40:24.2050677Z WARNING : WinHttpGetProxyForUrl returned: 12180
2018-10-06T21:40:24.2050677Z INFO : Attempting to connect using proxy '' of type 'Empty Proxy'.
2018-10-06T21:40:24.2050677Z INFO : Set security protocol: 00000800
2018-10-06T21:40:24.2050677Z INFO : Opening connection to downloads.sophos.com
2018-10-06T21:40:24.2675673Z INFO : Request content size: 0
2018-10-06T21:40:25.7375371Z INFO : Sending request
2018-10-06T21:40:25.7684449Z INFO : Request sent
2018-10-06T21:40:26.6834565Z INFO : Response status code: 200
2018-10-06T21:40:26.6864576Z INFO : Response data size: 1722651
2018-10-06T21:40:26.6874576Z INFO : trySendRequestThroughPotentialProxy returning response with status code: 200
2018-10-06T21:40:26.7014569Z INFO : Extracting files:
2018-10-06T21:40:26.7034585Z INFO : integrity.dat
2018-10-06T21:40:26.7064577Z INFO : manifest.dat
2018-10-06T21:40:26.7084573Z INFO : rootca.crl
2018-10-06T21:40:26.7114566Z INFO : rootca.crt
2018-10-06T21:40:26.7149316Z INFO : scf.dat
2018-10-06T21:40:26.7174582Z INFO : sof.dat
2018-10-06T21:40:26.7196452Z INFO : SophosSetup_Stage2.exe
2018-10-06T21:40:26.7654571Z INFO : sul.dll
2018-10-06T21:40:26.8024593Z INFO : Management Certs/sophosca1.crl
2018-10-06T21:40:26.8117698Z INFO : Management Certs/sophosca1.crt
2018-10-06T21:40:26.8144595Z INFO : Management Certs/sophosca2.crl
2018-10-06T21:40:26.8189314Z INFO : Management Certs/sophosca2.crt
2018-10-06T21:40:26.8204592Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crl
2018-10-06T21:40:26.8236578Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA3_exp20380504.crt
2018-10-06T21:40:26.8254584Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
2018-10-06T21:40:26.8284592Z INFO : Management Certs/Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
2018-10-06T21:40:27.0714616Z INFO : Running setup.
Started C:\Program Files (x86)\Sophos\CloudInstaller\SophosSetup_Stage2.exe
2018-10-06T21:40:27.3284648Z INFO : Stage 2 command-line options:
2018-10-06T21:40:27.3304647Z INFO : ---
2018-10-06T21:40:27.3324650Z INFO : Parent PID: 8708
2018-10-06T21:40:27.3344653Z INFO : Server: mcs-cloudstation-us-east-2.prod.hydra.sophos.com
2018-10-06T21:40:27.3364656Z INFO : Message relays: --
2018-10-06T21:40:27.3384654Z INFO : Suppressing feedback: 0
2018-10-06T21:40:27.3414651Z INFO : Dump feedback to disk: 0
2018-10-06T21:40:27.3434654Z INFO : Register only: 0
2018-10-06T21:40:27.3454653Z INFO : Trail logging: 0
2018-10-06T21:40:27.3484656Z INFO : Command-line logging: 0
2018-10-06T21:40:27.3504654Z INFO : Bypassing competitor removal: 0
2018-10-06T21:40:27.3514651Z INFO : CRT catalog: --
2018-10-06T21:40:27.3534651Z INFO : Language: --
2018-10-06T21:40:27.3554654Z INFO : Log files: C:\\ProgramData\\Sophos\\CloudInstaller\\Logs\\SophosCloudInstaller_20181006_214024.log
2018-10-06T21:40:27.3574654Z INFO : User: --
2018-10-06T21:40:27.3594651Z INFO : Group: --
2018-10-06T21:40:27.3604657Z INFO : Quiet: 0
2018-10-06T21:40:27.3634654Z INFO : Virtual appliance: 0
2018-10-06T21:40:27.3654658Z INFO : Proxy address: --
2018-10-06T21:40:27.3674660Z INFO : Proxy user: --
2018-10-06T21:40:27.3694659Z INFO : Overriding computer name: --
2018-10-06T21:40:27.3714663Z INFO : Overriding computer description: --
2018-10-06T21:40:27.3734654Z INFO : Overriding domain: --
2018-10-06T21:40:27.3754652Z INFO : Disable proxy detection: 0
2018-10-06T21:40:27.3774656Z INFO : Customer Token Specified: 8e404e9d-355d-4ece-b674-deb93a54ef18
2018-10-06T21:40:27.3794656Z INFO : Products: all
2018-10-06T21:40:27.3814667Z INFO : Pipe write handle: 1480
2018-10-06T21:40:27.3834659Z INFO : MCS Certificates Folder: 0
2018-10-06T21:40:27.3864660Z INFO : MCS Customer Id: 92ff269c-7227-04c1-b9b3-04da02a6df7d
2018-10-06T21:40:27.3884662Z INFO : Partner Id: --
2018-10-06T21:40:27.3914662Z INFO : Customer Estate Id: --
2018-10-06T21:40:27.3934660Z INFO : ---
2018-10-06T21:40:27.4004665Z INFO : User name: Administrator
2018-10-06T21:40:27.4024658Z INFO : NameDnsDomain:
2018-10-06T21:40:27.4044662Z INFO : dnsDomain: 
2018-10-06T21:40:28.4644728Z INFO : lpProfilePath:
2018-10-06T21:40:28.4874735Z INFO : User profile loaded
2018-10-06T21:40:28.4894735Z INFO : Net API buffer freed
2018-10-06T21:40:28.4914739Z INFO : Model::server value changed to: mcs-cloudstation-us-east-2.prod.hydra.sophos.com
2018-10-06T21:40:28.4944734Z INFO : Model::messageRelays value changed to be size: 0
2018-10-06T21:40:28.4964742Z INFO : Model::user value changed to:
2018-10-06T21:40:28.4984739Z INFO : Model::group value changed to:
2018-10-06T21:40:28.5004736Z INFO : Model::parentPid value changed to: 8708
2018-10-06T21:40:28.5034737Z INFO : Model::products changed to: all
2018-10-06T21:40:28.5154773Z INFO : Model::customer token value changed to: 8e404e9d-355d-4ece-b674-deb93a54ef18
2018-10-06T21:40:28.5184746Z INFO : MCS Crts: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crt,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crt
2018-10-06T21:40:28.5204737Z INFO : MCS CRLs: C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca1.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\sophosca2.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA3_exp20380504.crl,C:\\Program Files (x86)\\Sophos\\CloudInstaller\\Management Certs\\Sophos_SHA256_MCS_Root_CA4_exp20390504.crl
2018-10-06T21:40:28.5234738Z INFO : Model:: MCS customer id value changed to: 92ff269c-7227-04c1-b9b3-04da02a6df7d
2018-10-06T21:40:28.5264741Z INFO : Sophos Endpoint Defense is not installed
2018-10-06T21:40:28.5774736Z INFO : detectedMsiInstalledMcs.installed: 0
2018-10-06T21:40:28.5824740Z INFO : Beginning command definition.
2018-10-06T21:40:28.5844749Z INFO : Adding competitor detection command.
2018-10-06T21:40:28.5874738Z INFO : Adding command to register with Sophos cloud.
2018-10-06T21:40:28.5904744Z INFO : Adding command to download product suite.
2018-10-06T21:40:28.5944743Z INFO : User profile unloaded
2018-10-06T21:40:28.5964741Z ERROR : Stage 2 error: RegQueryValueExW failed. Error: 2. Value name='UninstallString'.
2018-10-06T21:40:28.6044752Z INFO : Cleaning up extracted files
2018-10-06T21:40:35.1991605Z INFO : FindMainWindow: pid=9300
2018-10-06T21:40:35.2001599Z INFO : ::EnumWindows enumerated to end; window not found
2018-10-06T21:40:35.2011597Z INFO : _bestHandle=00000000
2018-10-06T21:40:35.2111572Z ERROR : Exception: ReadFile failed: 109

 

Can anyone please help me?



This thread was automatically locked due to age.
Parents
  • This looks like the error:

    ERROR : Stage 2 error: RegQueryValueExW failed. Error: 2. Value name='UninstallString'.

    I would suggest to run Process Monitor (Microsoft tool) when you re-run the installer.

    I assume you will see the Sophos installer process try to read an uninstallstring of a component it believes to be installed and fail with a not found message.

    I would expect that the key it it looking under will be the product it believes is installed under either of the following depending on the product in question:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Uninstall

    Given this, you could run the Process Conitor capture with a filter for:

    Path Contains CurrentVersion\uninstall

    Or just add that after capturing everything.

    This should narrow it down.  Either the product is installed but is missing the uninsallstring registry value or it's not installed at all, either way, I suspect you will have to manually correct a registry key.

    Regards,

    Jak

     

Reply
  • This looks like the error:

    ERROR : Stage 2 error: RegQueryValueExW failed. Error: 2. Value name='UninstallString'.

    I would suggest to run Process Monitor (Microsoft tool) when you re-run the installer.

    I assume you will see the Sophos installer process try to read an uninstallstring of a component it believes to be installed and fail with a not found message.

    I would expect that the key it it looking under will be the product it believes is installed under either of the following depending on the product in question:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Uninstall

    Given this, you could run the Process Conitor capture with a filter for:

    Path Contains CurrentVersion\uninstall

    Or just add that after capturing everything.

    This should narrow it down.  Either the product is installed but is missing the uninsallstring registry value or it's not installed at all, either way, I suspect you will have to manually correct a registry key.

    Regards,

    Jak

     

Children
No Data