This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No response of installing Sophos Endpoint Security and Control

Hi,

I am one of the network staff in our company, and we already installed Sophos Endpoint Security and Control to some PC of our employees. We had a virus outbreak with W32/Brontok-D and spread through-out the network, unfortunately some of the PC of our Programming dept. was infected because they asked not to put Sophos in there PC.

Then I tried to install sophos to their PC from our server, unfortunately when I run the setup.exe, entered the necessary details such as username and password and click OK. and... NOTHING HAPPENED.

I tried to run the setup.exe again and entered the details, click ok and .. still ..  NOTHING HAPPENED. No sign of installation or process in task manager that it is running. I assume that the virus caused that but we tried to install sophos to those PC who already have one to test if it will go through the installation, but still NOTHING HAPPENED.

Hoping for a kind response.

Thank you,

Dice

:46399


This thread was automatically locked due to age.
  • Hello Dice,

    to install sophos to their PC from our server [...] when I run the setup.exe

    I'm not sure I understand correctly what you mean by from our server. First I thought you tried Protect Computers from the console but as you mention setup.exe I assume you connected to the share and ran setup from there, correct?

    If run interactively, setup.exe should write to Sophos ES setup.log in the user's (i.e. your) %TEMP% directory - does this file exist?

    Christian

    :46401
  • Hi QC,

    I assume you connected to the share and ran setup from there, correct?

    Yes. the setup.exe installer is in our server and from the PC of our programmer, I accessed it through share folder.

    If run interactively, setup.exe should write to Sophos ES setup.log in the user's (i.e. your) %TEMP% directory - does this file exist?

    I have sophos in my laptop and the setup.log exist in my temp folder. I tried to look for the setup.log in our programmers PC but it doesn't exist.

    [Edit] This is my Sophos ES setup.log "1/9/2014,6:12:31 PM,ERROR,An unexpected error occurred, no translation available: utils::copy_file: "\\192.168.2.124\SophosUpdate\CIDs\S000\SAVSCFXP\sau\program files\Sophos\AutoUpdate\fr\fr.exe", "C:\Users\ZACCEL~1\AppData\Local\Temp\sophosa\program files\Sophos\AutoUpdate\fr\fr.exe": Access is denied.,"

    I tried to install it again but it still doesn't go through installation. Honestly, we don't have enough knowledge about the sophos console, only some of its basic features. It will be appreciated if you could give us some link that we can review about its features.

    Thanks,

    Dice

    :46425
  • Hello Dice,

    thanks for the log snippet. Indeed this indicates a much bigger problem.

    PM,ERROR [...] "\\192.168.2.124\SophosUpdate\CIDs\S000\SAVSCFXP\sau\program files\Sophos\AutoUpdate\fr\fr.exe"

    It fails to copy the file fr.exe. Now firstly, this file is not part of the package! The fr subfolder is for language support and only contains translation DLLs and a help file. Strangely enough the file has the same name as the containing folder. Looking at the SAV.txt in your Sophos Block Applications post there is a W32/Brontok-D detection for Shared Folder.exe in \Shared Folder - and the name of another flagged file is Data Other.exe which might as well be derived from a folder name.

    Thus I conclude fr.exe is a malicious file and the Access denied is the result of the file being blocked on the server (192.168.2.124).  So - please check the AV log on the server.

    Mote important - it looks like W32/Brontok has spread itself all over the place and might even be still active. As you are not familiar with Sophos and the forum is not the best place for walking you through the necessary steps to clean up the mess (partly because of the time lag) I urge you to contact Support ASAP

    As for the console - please see the Documentation section on the Support pages and visit the Endpoint Resource Center.

    Christian

    :46435
  • Hi QC,

    As we checked and observe some of the folders in our server where our sophos av is installed, It seems that it really is infected and the virus created an .exe file which hinders the sophos installation to execute and continue installing. We already contacted our support and they replaced the infected installation folder with a new one and created a package of installer for us to use. Thank you for your response, I have learned something new and useful.

    Best Regards,

    Dice

    -: Topic Closed :-

    :46491