This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hopelessly Broken

Sorry about the sensationalist headline!!, but this issue has had me running round in circles for the best part of a wewek now, with no hope of resolution in sight.

I have been trying to update my PC to use SAV 10.3. I first updated our management console server to 5.2.1. I then created a new subscription to download the 10.3 version. I then attempted to deploy it to my PC. I noticed that the console reported the statius of my PC as 'this computer is protected but has not yet reported it's status'.....since then I have been on an endless loop of uninstalling, reinstalling, tearing out a few more hairs, following the 'completely remove SAV' instructions provided by Sophos support, rebooting, rebooting, sacrificing a goat or two, then rinse and repeat ad-nauseum. So far NOTHING has helped.....

anyway, here's a list of the things I have tried all to no avail.

1. After initially contacting Sophos support, and getting the instructions for completely deleting SAV, and following those instructions, I started with what should have been considered a clean PC.

2. Deployed SAV from the management server to my PC. The 'setup.exe' process only ran for a few seconds, and at the end of it I had a Sophos icon in my system tray, but the 'open Sophos Endpoint protection' item was greyed out. The only available choices were 'update now', which did nothing....no 'update progress' dialog, zilch, zip, nada. I checked the Services on my PC and all I had was the Sophos Auto Update service. Tried rebooting, still nothing hapening.

3. Manually connected to the CID on our network and ran setup. Got a message indicating that SAV was being uninstalled.

4. Cleaned up my PC as perthe removal instructions....rebooted....sacrificed a goat

5. Connected to the CID on the LAN. Ran installed. This gave me the Sophos Agent, Auto Updater and Message Router in my Services panel, but still no SAV. Same deal with the tray icon. Rebooted....

6. Went to the CID on the lan, navigated down to the 'savxp' folder and ran 'sophos anti-virus.msi'. This appeared to work, and I thought I may have experienced the sweet taste of success.....however.....even though I was now able to open the SAV interface, there was no 'version' information, no 'last updated' information, and all the clickable links (update, scan, etc) were greyed out. Reboot again, sacrifice a chicken this time.....

7. After reboot, still no change. Also, NO updating logs available.....no 'alc.log' to be found anywhere on my PC. Also noticed at this stage that the Sophos Agent service was no longer present....also, clicking Update Now still does nothing.

8. Thought I'd try installing the standalone 10.3 installer downloaded from Sophos web site, but unsurprisingly this failed (I had forgotten a fresh sacrifice before trying this one...). Also noticed that after this the Sophos Remote Management service was now gone from my PC.

9. Uninstalled everything again, cleaned up as per instructions.....kicked the cat a few times

10. ran the standalone installer again. This installed this time. When I put in the details for updating, and then clicked Update Now, nothing happened. Tried both our Sophos credentials, and the local CID credentials, but nothing would trigger an update. Also, still no alc.log to be found anywhere, and 'last updated' in the Interface still showing 'unknown'

11. Killed the cat, ate the goat, installed Kaspersky

12. Only kidding.....didn't kill the cat.

13. Didn't really install Kaspersky.....but at the moment I still appear to have a completely non-functional SAV on my PC.I have also noticed that there are a couple more PCs with the 'protected but havent phoned home yet' status showing inthe management server.

I have an open case with support regarding this, but just thought I'd throw it out there to see if anyone has experienced similar, or can offer any suggestions. My PC has been unprotected for a few days now - well, I'm not sure if it's unprotected or not - and I'm starting to get a bit nervous...

:50486


This thread was automatically locked due to age.
Parents
  • Hello Doctor-Gerry,

    it looks indeed pretty broken. The log shows that AutoUpdate starts, collects the list of products but fails before it completes this step - probably when accessing the key HKLM\SOFTWARE\Sophos\AutoUpdate\Products\. The message in the log you've posted is:

    Trace(2014-Jun-03 16:11:50): ALUpdate::main: terminal problem!

    whereas normally it should say

    Trace(2014-Jun-04 16:25:13): Considering subscribed products.

    Dunno if it is an issue with this key though. It should contain a subkey {9BF40A4E-23AE-48be-9974-5A1F261DBEE8} with two values, Full control permissions for SYSTEM and Administrators.

    As AutoUpdate miserably fails with this ALUpdate::main: terminal problem! it never completes normally (with either success or failure) and consequently doesn't inform RMS of the outcome. Therefore the not yet reported status in SEC.

    Did you (before or after eating the goat) try the Fix-It mentioned in Troubleshooting and resolving problematic Sophos endpoint upgrade and uninstall issues? I know this is not a solution you can apply remotely (at least I don't know whether one can script the Fix-It tool).

    Christian

    :50640
Reply
  • Hello Doctor-Gerry,

    it looks indeed pretty broken. The log shows that AutoUpdate starts, collects the list of products but fails before it completes this step - probably when accessing the key HKLM\SOFTWARE\Sophos\AutoUpdate\Products\. The message in the log you've posted is:

    Trace(2014-Jun-03 16:11:50): ALUpdate::main: terminal problem!

    whereas normally it should say

    Trace(2014-Jun-04 16:25:13): Considering subscribed products.

    Dunno if it is an issue with this key though. It should contain a subkey {9BF40A4E-23AE-48be-9974-5A1F261DBEE8} with two values, Full control permissions for SYSTEM and Administrators.

    As AutoUpdate miserably fails with this ALUpdate::main: terminal problem! it never completes normally (with either success or failure) and consequently doesn't inform RMS of the outcome. Therefore the not yet reported status in SEC.

    Did you (before or after eating the goat) try the Fix-It mentioned in Troubleshooting and resolving problematic Sophos endpoint upgrade and uninstall issues? I know this is not a solution you can apply remotely (at least I don't know whether one can script the Fix-It tool).

    Christian

    :50640
Children
No Data