Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issues with Sophos Version 1.7.134 update and server losing network connection

HI, 

 

We recently had a 2008r2 server lose the network connection, a quick restart brought everything back up. (This is was a production line server so we did not investigate the nic, just restarted to get workers going again.)  I do know it was not hardware due to this being a VM and multiple VM's were running on the ESXi and had no issue.  

After reviewing the event viewer at the same time that this happened Sophos had finished installing the latest updates, I have checked all the event viewer logs for the same time and there is nothing else so I am thinking something with this update or install caused the issue.  Just wanted to see if anyone else has seen this or had similar issues.  I have pasted the event logs below.

 

Log Name: Application
Source: HitmanPro.Alert
Date: 5/8/2019 12:36:12 PM
Event ID: 101
Task Category: Broker
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
The hmpalertsvc broker service was successfully stopped.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="HitmanPro.Alert" />
<EventID Qualifiers="0">101</EventID>
<Level>4</Level>
<Task>2</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:12.000000000Z" />
<EventRecordID>609142</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
<Data>hmpalertsvc</Data>
</EventData>
</Event>

Log Name: Application
Source: VMTools
Date: 5/8/2019 12:36:12 PM
Event ID: 108
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
The service was stopped.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="VMTools" />
<EventID Qualifiers="0">108</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:12.000000000Z" />
<EventRecordID>609141</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
</EventData>
</Event>

Log Name: Application
Source: VMUpgradeHelper
Date: 5/8/2019 12:36:12 PM
Event ID: 272
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
Saved network configuration.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="VMUpgradeHelper" />
<EventID Qualifiers="0">272</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:12.000000000Z" />
<EventRecordID>609140</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
</EventData>
</Event>

Log Name: Application
Source: VMUpgradeHelper
Date: 5/8/2019 12:36:12 PM
Event ID: 280
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
Saving network configuration for adapter with MAC address 00:0C:29:5B:A4:87.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="VMUpgradeHelper" />
<EventID Qualifiers="0">280</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:12.000000000Z" />
<EventRecordID>609139</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
<Data>00:0C:29:5B:A4:87</Data>
</EventData>
</Event>

Log Name: Application
Source: VMUpgradeHelper
Date: 5/8/2019 12:36:12 PM
Event ID: 260
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
Saving network configuration.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="VMUpgradeHelper" />
<EventID Qualifiers="0">260</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:12.000000000Z" />
<EventRecordID>609138</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
</EventData>
</Event>

Log Name: Application
Source: Desktop Window Manager
Date: 5/8/2019 12:36:10 PM
Event ID: 9009
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
The Desktop Window Manager has exited with code (0x40010004)
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="Desktop Window Manager" />
<EventID Qualifiers="16384">9009</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:36:10.000000000Z" />
<EventRecordID>609137</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
<Data>0x40010004</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:09:06 PM
Event ID: 1042
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Ending a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\sau\Sophos AutoUpdate.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1042</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:09:06.000000000Z" />
<EventRecordID>609136</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\sau\Sophos AutoUpdate.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:09:06 PM
Event ID: 1035
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer reconfigured the product. Product Name: Sophos AutoUpdate XG. Product Version: 6.0.457.0. Product Language: 1033. Manufacturer: Sophos Limited. Reconfiguration success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1035</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:09:06.000000000Z" />
<EventRecordID>609135</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos AutoUpdate XG</Data>
<Data>6.0.457.0</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B37324531333646372D333735312D343232452D414337412D3142324534363339313930397D3030303039613864633233343765653038653731623865353062376434613139383731343030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:09:06 PM
Event ID: 11728
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Product: Sophos AutoUpdate XG -- Configuration completed successfully.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">11728</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:09:06.000000000Z" />
<EventRecordID>609134</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Product: Sophos AutoUpdate XG -- Configuration completed successfully.</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B37324531333646372D333735312D343232452D414337412D3142324534363339313930397D</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:08:26 PM
Event ID: 1040
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Beginning a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\sau\Sophos AutoUpdate.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1040</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:26.000000000Z" />
<EventRecordID>609133</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\sau\Sophos AutoUpdate.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:08:26 PM
Event ID: 1033
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer installed the product. Product Name: Sophos AutoUpdate XG. Product Version: 6.0.457.0. Product Language: 1033. Manufacturer: Sophos Limited. Installation success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1033</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:26.000000000Z" />
<EventRecordID>609132</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos AutoUpdate XG</Data>
<Data>6.0.457.0</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B37324531333646372D333735312D343232452D414337412D3142324534363339313930397D3030303039613864633233343765653038653731623865353062376434613139383731343030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: HitmanPro.Alert
Date: 5/8/2019 12:08:19 PM
Event ID: 213
Task Category: Installer
Level: Information
Keywords: Classic
User: N/A
Computer: adfs01.dfllc.local
Description:
An update was succesfully downloaded and is pending to be installed at next reboot. New version 3.7.12.466.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="HitmanPro.Alert" />
<EventID Qualifiers="0">213</EventID>
<Level>4</Level>
<Task>1</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:19.000000000Z" />
<EventRecordID>609131</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security />
</System>
<EventData>
<Data>3.7.12.466</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:08:16 PM
Event ID: 1042
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Ending a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1042</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:16.000000000Z" />
<EventRecordID>609130</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:08:16 PM
Event ID: 1035
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer reconfigured the product. Product Name: Sophos Network Threat Protection. Product Version: 1.8.1555.0. Product Language: 1033. Manufacturer: Sophos Limited. Reconfiguration success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1035</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:16.000000000Z" />
<EventRecordID>609129</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Network Threat Protection</Data>
<Data>1.8.1555.0</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B36303433353042462D424539412D344637392D423045422D4231433232443838394532447D3030303033616531343862636262303831323134663362616537333938663831326133333030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:08:16 PM
Event ID: 11728
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Product: Sophos Network Threat Protection -- Configuration completed successfully.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">11728</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:08:16.000000000Z" />
<EventRecordID>609128</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Product: Sophos Network Threat Protection -- Configuration completed successfully.</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B36303433353042462D424539412D344637392D423045422D4231433232443838394532447D</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:53 PM
Event ID: 1040
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Beginning a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1040</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:53.000000000Z" />
<EventRecordID>609127</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:53 PM
Event ID: 1035
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer reconfigured the product. Product Name: Sophos Network Threat Protection. Product Version: 1.8.59.0. Product Language: 1033. Manufacturer: Sophos Limited. Reconfiguration success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1035</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:53.000000000Z" />
<EventRecordID>609126</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Network Threat Protection</Data>
<Data>1.8.59.0</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B36303433353042462D424539412D344637392D423045422D4231433232443838394532447D3030303062336165666531306336303862643036333731313236366638396536383933613030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:52 PM
Event ID: 1033
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer installed the product. Product Name: Sophos Network Threat Protection. Product Version: 1.8.1555.0. Product Language: 1033. Manufacturer: Sophos Limited. Installation success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1033</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:52.000000000Z" />
<EventRecordID>609125</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Network Threat Protection</Data>
<Data>1.8.1555.0</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B36303433353042462D424539412D344637392D423045422D4231433232443838394532447D3030303033616531343862636262303831323134663362616537333938663831326133333030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:49 PM
Event ID: 1042
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Ending a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\Sophos Anti-Virus.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1042</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:49.000000000Z" />
<EventRecordID>609124</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\Sophos Anti-Virus.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:48 PM
Event ID: 1033
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer installed the product. Product Name: Sophos Anti-Virus. Product Version: 10.8.4.227. Product Language: 1033. Manufacturer: Sophos Limited. Installation success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1033</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:48.000000000Z" />
<EventRecordID>609123</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Anti-Virus</Data>
<Data>10.8.4.227</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B30313432333836352D353531422D344335392D423434412D4343363034424332314146337D3030303065646632383565336665643762616235303331376131626535343936313431633030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:07:48 PM
Event ID: 11707
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Product: Sophos Anti-Virus -- Installation operation completed successfully.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">11707</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:07:48.000000000Z" />
<EventRecordID>609122</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Product: Sophos Anti-Virus -- Installation operation completed successfully.</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B30313432333836352D353531422D344335392D423434412D4343363034424332314146337D</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:06:17 PM
Event ID: 1040
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Beginning a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\Sophos Anti-Virus.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1040</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:06:17.000000000Z" />
<EventRecordID>609121</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\savxp\Sophos Anti-Virus.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:06:17 PM
Event ID: 1042
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Ending a Windows Installer transaction: {095BB5FF-C89D-449B-9D6D-3B9CCB3BEFD8}. Client Process Id: 6020.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1042</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:06:17.000000000Z" />
<EventRecordID>609120</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>{095BB5FF-C89D-449B-9D6D-3B9CCB3BEFD8}</Data>
<Data>6020</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:06:17 PM
Event ID: 1034
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer removed the product. Product Name: Sophos Anti-Virus. Product Version: 10.8.3.322. Product Language: 1033. Manufacturer: Sophos Limited. Removal success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1034</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:06:17.000000000Z" />
<EventRecordID>609119</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Anti-Virus</Data>
<Data>10.8.3.322</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B30393542423546462D433839442D343439422D394436442D3342394343423342454644387D3030303036636638373936613938663739303839386433373164323436383462633934653030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:06:17 PM
Event ID: 11724
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Product: Sophos Anti-Virus -- Removal completed successfully.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">11724</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:06:17.000000000Z" />
<EventRecordID>609118</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Product: Sophos Anti-Virus -- Removal completed successfully.</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B30393542423546462D433839442D343439422D394436442D3342394343423342454644387D</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:05:27 PM
Event ID: 1040
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Beginning a Windows Installer transaction: {095BB5FF-C89D-449B-9D6D-3B9CCB3BEFD8}. Client Process Id: 6020.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1040</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:05:27.000000000Z" />
<EventRecordID>609117</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>{095BB5FF-C89D-449B-9D6D-3B9CCB3BEFD8}</Data>
<Data>6020</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:59 PM
Event ID: 1042
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Ending a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ui64\Sophos UI.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1042</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:59.000000000Z" />
<EventRecordID>609116</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ui64\Sophos UI.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:59 PM
Event ID: 1035
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer reconfigured the product. Product Name: Sophos Endpoint. Product Version: 1.7.134. Product Language: 1033. Manufacturer: Sophos Limited. Reconfiguration success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1035</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:59.000000000Z" />
<EventRecordID>609115</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Endpoint</Data>
<Data>1.7.134</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B44323935343241452D323837432D343245342D414232382D3338353845313343314133457D3030303061376637346233323839313264313438333935383035653831616466326366393030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:59 PM
Event ID: 11728
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Product: Sophos Endpoint -- Configuration completed successfully.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">11728</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:59.000000000Z" />
<EventRecordID>609114</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Product: Sophos Endpoint -- Configuration completed successfully.</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B44323935343241452D323837432D343245342D414232382D3338353845313343314133457D</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:40 PM
Event ID: 1040
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Beginning a Windows Installer transaction: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ui64\Sophos UI.msi. Client Process Id: 10624.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1040</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:40.000000000Z" />
<EventRecordID>609113</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ui64\Sophos UI.msi</Data>
<Data>10624</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>(NULL)</Data>
<Data>
</Data>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:40 PM
Event ID: 1035
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer reconfigured the product. Product Name: Sophos Endpoint. Product Version: 1.7.24. Product Language: 1033. Manufacturer: Sophos Limited. Reconfiguration success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1035</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:40.000000000Z" />
<EventRecordID>609112</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Endpoint</Data>
<Data>1.7.24</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B44323935343241452D323837432D343245342D414232382D3338353845313343314133457D3030303062396462353866313261646665653266623561393531646634303330663632333030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: MsiInstaller
Date: 5/8/2019 12:04:40 PM
Event ID: 1033
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Windows Installer installed the product. Product Name: Sophos Endpoint. Product Version: 1.7.134. Product Language: 1033. Manufacturer: Sophos Limited. Installation success or error status: 0.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="MsiInstaller" />
<EventID Qualifiers="0">1033</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:40.000000000Z" />
<EventRecordID>609111</EventRecordID>
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>Sophos Endpoint</Data>
<Data>1.7.134</Data>
<Data>1033</Data>
<Data>0</Data>
<Data>Sophos Limited</Data>
<Data>(NULL)</Data>
<Data>
</Data>
<Binary>7B44323935343241452D323837432D343245342D414232382D3338353845313343314133457D3030303061376637346233323839313264313438333935383035653831616466326366393030303030393034</Binary>
</EventData>
</Event>

Log Name: Application
Source: Microsoft-Windows-LoadPerf
Date: 5/8/2019 12:04:34 PM
Event ID: 1000
Task Category: None
Level: Information
Keywords:
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Performance counters for the {42ee8dc0-98ba-4455-a673-79bf514ff632} (Sophos Endpoint Defense) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="Microsoft-Windows-LoadPerf" Guid="{122EE297-BB47-41AE-B265-1CA8D1886D40}" />
<EventID>1000</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:34.028487900Z" />
<EventRecordID>609110</EventRecordID>
<Correlation />
<Execution ProcessID="9516" ThreadID="11480" />
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<UserData>
<EventXML xmlns:auto-ns2="schemas.microsoft.com/.../events" xmlns="LoadPerf">
<param1>{42ee8dc0-98ba-4455-a673-79bf514ff632}</param1>
<param2>Sophos Endpoint Defense</param2>
<binaryDataSize>0</binaryDataSize>
<binaryData>
</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: Application
Source: Microsoft-Windows-LoadPerf
Date: 5/8/2019 12:04:33 PM
Event ID: 1001
Task Category: None
Level: Information
Keywords:
User: SYSTEM
Computer: adfs01.dfllc.local
Description:
Performance counters for the {42ee8dc0-98ba-4455-a673-79bf514ff632} (Sophos Endpoint Defense) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
<System>
<Provider Name="Microsoft-Windows-LoadPerf" Guid="{122EE297-BB47-41AE-B265-1CA8D1886D40}" />
<EventID>1001</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2019-05-08T17:04:33.669687300Z" />
<EventRecordID>609109</EventRecordID>
<Correlation />
<Execution ProcessID="10956" ThreadID="9548" />
<Channel>Application</Channel>
<Computer>adfs01.dfllc.local</Computer>
<Security UserID="S-1-5-18" />
</System>
<UserData>
<EventXML xmlns:auto-ns2="schemas.microsoft.com/.../events" xmlns="LoadPerf">
<param1>{42ee8dc0-98ba-4455-a673-79bf514ff632}</param1>
<param2>Sophos Endpoint Defense</param2>
<binaryDataSize>0</binaryDataSize>
<binaryData>
</binaryData>
</EventXML>
</UserData>
</Event>



This thread was automatically locked due to age.