This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"You do not have sufficient privileges"

"You do not have sufficient privileges to run the Sophos Endpoint Security and Control main application"

Windows Security tray icon shows a white X on a red background stating that I currently have no antivirus loaded.

I can't access my Sophos Control panel, as it gives me the error in the subject line.  I can right-click on the tray icon and "Update Now" but cannot load the main program.

Taskmanager shows that SavService.exe is running, taking 120.192Megs of memory.

I checked the usergroups specified in the error message with the following command

"

>net localgroup

---------------------------------------------
*Administrators
*boinc_admins
*boinc_projects
*boinc_users
*Guests
*HelpServicesGroup
*SophosAdministrator
*SophosOnAccess
*SophosPowerUser
*SophosUser
*Users
The command completed successfully."

I was already in the group SophosAdministrator, but manually added myself to the other 3 Sophos groups (and have since rebooted my PC).

I am running WinXP home 32 bit, SP3.  Fully patched via windowsupdate.  Also running Ad-Aware (fully updated)

Before my sophos problem

Recently, I added about 3 programs to my PC.  A couple of days ago I had a BSOD-type error, which resulted in a reboot of my system.  I believe Sophos loaded properly after that point.  However, I elected to see which program had crashed my computer, which lead me to using the Windows (or Microsoft?) LiveCare through-the-web scanner.  Unfamiliar with the interface, I must have told it to make all recommended changes to my system - I do not know if this resulted in the removal of any Sophos-critical files.  In any case, at this time I also ran windowsupdate (which I ran about a week to 10 days prior), which had about 20 high priority updates available for me to download.  I installed these.  Upon the next reboot of the system sophos isn't working

Since my problem began

I added my username to other Sophos groups

I've downloaded and have run VundoFix (I had read that Vundo can knock out Sophos) - no infections found.

I ran the sav32cli from the sophos directory command line (no problems with executing that, but I'm not sure it scanned all files on all harddrives or anything, but it did scan 8 boot sectors.  It found no infections)

Possible resolutions?

The LiveCare antivirus program said that it created a system restore point.  Should I just roll back to that?

Do you need to see a dump from HijackThis?

Should I see if I have the installer for Sophos and reinstall that again?  Any idea what the installer exe is typically named?  I put this on my system a few years ago and have several hundred gigs of stuff:P

:3370


This thread was automatically locked due to age.
Parents
  • Following the advice in this thread:

    PsGetSid shows all usergroups are properly linked with machine.xml

    Sysinternals process monitor shows the following Access Denied messages associated with the restart of the service

    9:14:17.6472213 PM SavService.exe 3728 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:14:17.6475441 PM SavService.exe 3728 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:14:17.6494245 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:14:17.6503620 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:14:17.6513337 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:14:17.6514952 PM SavService.exe 3728 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:14:58.2215241 PM SavService.exe 3212 RegSetValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData ACCESS DENIED Type: REG_SZ, Length: 106, Data: C:\Documents and Settings\All Users\Application Data
    9:15:18.6274181 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6277040 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6297896 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6314310 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6323037 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.6324715 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:15:18.6727311 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6737879 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6759475 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6768282 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6776766 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.6778744 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:15:18.7044254 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.7047111 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.7064071 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.7077344 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.7085501 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.7087061 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key

    I'm confused as to what exactly to do for this step "7. Fix any permission problems on either the registry or files that are incorrect.  Ideally using a reference system to compare ACLs."

    I don't have a reference system.  How do I authorize SavService to make registry changes as well as QueryOpen file mods?

    :3371
Reply
  • Following the advice in this thread:

    PsGetSid shows all usergroups are properly linked with machine.xml

    Sysinternals process monitor shows the following Access Denied messages associated with the restart of the service

    9:14:17.6472213 PM SavService.exe 3728 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:14:17.6475441 PM SavService.exe 3728 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:14:17.6494245 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:14:17.6503620 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:14:17.6513337 PM SavService.exe 3728 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:14:17.6514952 PM SavService.exe 3728 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:14:58.2215241 PM SavService.exe 3212 RegSetValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData ACCESS DENIED Type: REG_SZ, Length: 106, Data: C:\Documents and Settings\All Users\Application Data
    9:15:18.6274181 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6277040 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6297896 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6314310 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6323037 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.6324715 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:15:18.6727311 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6737879 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.6759475 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6768282 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.6776766 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.6778744 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key
    9:15:18.7044254 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.7047111 PM SavService.exe 3212 RegCreateKey HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ACCESS DENIED Desired Access: Read/Write
    9:15:18.7064071 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.7077344 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp ACCESS DENIED 
    9:15:18.7085501 PM SavService.exe 3212 QueryOpen C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files ACCESS DENIED 
    9:15:18.7087061 PM SavService.exe 3212 RegOpenKey HKU\S-1-5-18 ACCESS DENIED Desired Access: Create Sub Key

    I'm confused as to what exactly to do for this step "7. Fix any permission problems on either the registry or files that are incorrect.  Ideally using a reference system to compare ACLs."

    I don't have a reference system.  How do I authorize SavService to make registry changes as well as QueryOpen file mods?

    :3371
Children
No Data