This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Autoupdate failed and insufficient rights to do anything with Sophos

Hi Sophos team,

I had to register as I have annoying problem with Sophos. The most I got from my IT admin (who is in Denmark while I am on a stay in China) is to uninstall it and instal something else. While that's the last option. I will give a last try to ask you.

I neither have the rights to manipulate with Sophos properly (it says "insufficient right"), nor the autoupdate funtion works. This is all from today when I tried to delete a virus or whatever was it from usb, and I noticed the first one. Once I tried to fix using your (increadibly confusing and overloaded) forums, the auto-update stoped working as well. Its a bit annoying and I got a bit frustrated.

1. I have tried to fix the "sufficient rights" issue by following your posted procedure i.e. updating the SID numbers using the SophosLocalGroups.txt file but it didn't work. I also downloaded some file, and than copied it in the indicated lcoation and run it (which was suppose to automatically updade the SIDS) but it was waste of time in both reading and doing it.

2. I have tried to fix the auto-update issue, i even don't remember what I did, but i stoped the Sophos virus protection and did what was written in your post and activated it again. It didn't work.

Is there any solution except spending hours and trying to understand what SID and DSN settings are or?

Thanks a lot,

Kiril

p.s. for the record, when I start up my pc, the notification appears with "Sophos Endpoing Secirity and Control updater has faild to download", and in the update log the following appears (the other updates seem to work properly- as it says in the log):

Time: 23-07-2012 23:37:14
Message: Could not connect to the server. Check that this computer is connected to the network and that Sophos AutoUpdate is configured to update from the correct location with the correct credentials and proxy details (if required)
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:13
Message: Downloading product Sophos AutoUpdate from server \\SOFUS\SophosUpdate\CIDs\S000\SAVSCFXP\
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:11
Message: Could not add a connection to server \\SOFUS\SophosUpdate; user djf\sophos; Windows error 53
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:09
Message: Could not connect to the server. Check that this computer is connected to the network and that Sophos AutoUpdate is configured to update from the correct location with the correct credentials and proxy details (if required)
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:08
Message: Downloading product SAVXP from server \\SOFUS\SophosUpdate\CIDs\S000\SAVSCFXP\
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:06
Message: Could not add a connection to server \\SOFUS\SophosUpdate; user djf\sophos; Windows error 53
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:04
Message: Could not connect to the server. Check that this computer is connected to the network and that Sophos AutoUpdate is configured to update from the correct location with the correct credentials and proxy details (if required)
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:03
Message: Downloading product RMSNT from server \\SOFUS\SophosUpdate\CIDs\S000\SAVSCFXP\
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:37:01
Message: Could not add a connection to server \\SOFUS\SophosUpdate; user djf\sophos; Windows error 53
Module: CIDUpdate
Process ID: 4808
Thread ID: 4412

Time: 23-07-2012 23:36:38
Message: *************** Sophos AutoUpdate started ***************
Module: ALUpdate
Process ID: 4808
Thread ID: 4412

:27249


This thread was automatically locked due to age.
Parents
  • Hi Christien,

    When I nslookup FQDN with VPN it gives me:

    Server: xtgc.sjziam.ac.cn

    Address: 159.xxx.xxx.x

    Non-authoritative answer:

    Name: FQDN.djf.agrsci.dk

    Address: 130.xxx.xxx.xxx

    When I nslookup FQDN without VPN it gives me slighty different:

    Server: ths.sjziam.ac.cn

    Address: 159.xxx.xxx.x

    Non-authoritative answer:

    Name: FQDN.agrsci.dk

    Address: 130.xxx.xxx.xxx

    Which means that its not the home network, right? The pc works very nice. All software works properly, no isses with viruses or similar. Chrome works normally, its my default browser. All is fine it seems to me. I have no strange behaviour or viruses reported.

    Regarding the SAV.txt file, it says (among many other stuff):

    20120723 094735Virus/spyware 'W32/AutoRun-MO' has been detected in "E:\Recycled.exe\FILE:0000".(FILE:0000 goes up to 9). This is the one I wrote about.

    (By the way, this: 

    20120725 030444 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
    20120725 050400 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
    20120725 050402 Using detection data version 4.77G (detection engine 3.31.1). This version can detect 3575645 items. 

    expected right?)

    It is funny because when I open Windows Security Center, it reports that all is fine, Sophos is up to date and works good and all is on. It only says in "Spyware and unwated software protection" that my pc uses both Windows defender and Sophos, and both works properly.

    Finally, I am Sophos user, not administrator.

    Kiril

    :27305
Reply
  • Hi Christien,

    When I nslookup FQDN with VPN it gives me:

    Server: xtgc.sjziam.ac.cn

    Address: 159.xxx.xxx.x

    Non-authoritative answer:

    Name: FQDN.djf.agrsci.dk

    Address: 130.xxx.xxx.xxx

    When I nslookup FQDN without VPN it gives me slighty different:

    Server: ths.sjziam.ac.cn

    Address: 159.xxx.xxx.x

    Non-authoritative answer:

    Name: FQDN.agrsci.dk

    Address: 130.xxx.xxx.xxx

    Which means that its not the home network, right? The pc works very nice. All software works properly, no isses with viruses or similar. Chrome works normally, its my default browser. All is fine it seems to me. I have no strange behaviour or viruses reported.

    Regarding the SAV.txt file, it says (among many other stuff):

    20120723 094735Virus/spyware 'W32/AutoRun-MO' has been detected in "E:\Recycled.exe\FILE:0000".(FILE:0000 goes up to 9). This is the one I wrote about.

    (By the way, this: 

    20120725 030444 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
    20120725 050400 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
    20120725 050402 Using detection data version 4.77G (detection engine 3.31.1). This version can detect 3575645 items. 

    expected right?)

    It is funny because when I open Windows Security Center, it reports that all is fine, Sophos is up to date and works good and all is on. It only says in "Spyware and unwated software protection" that my pc uses both Windows defender and Sophos, and both works properly.

    Finally, I am Sophos user, not administrator.

    Kiril

    :27305
Children
No Data