Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[9.100-8][QUESTION]On access checking

Hi,
I am trying to workout where I turn on 'on access' scanning. Both the W7 64 and W8 64 show on access scanning as disabled on the PC and nowhere on the UTM to enable it.
I am running a home user licence and wonder if this feature is not available to home users?

Ian


This thread was automatically locked due to age.
Parents
  • Neither UAC nor the firewall would make difference to on-access scanning. 

    Can you now get into the on-access settings or are they still grayed out?

    Can you complete the checks listed earlier?

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • On the new W8 64 PC, the on access is still greyed out.
    I will go through all the requested steps tonight my time.

    Ian

    Changed tamper protection for all PCs and was able to enable on demand scanning. Still leaves a question about it not being enabled by default on installation even though the installation shows it as being enabled?
  • Are we talking about on-access or on-demand scanning here?  Different things.

    To recap the problem (as I see it): The endpoint reports to the UTM that on-access is enabled but locally the OS/Sophos shield reports on-access is disabled.  In trying to get to the on-access settings (locally on the W8 computer) to confirm what is enabled the options appear grayed out and hence have so far hindered resolving the main problem.

    One thing you should know in tackling this problem: Tamper protection and/or the fact that SAV is not probably installed could be causing the grayed out menu options.  Equally you might have a problem with the GUI allowing the logged on account access (i.e., back to not being properly added to the 'SophosAdministrator' group from earlier in this thread).  Hence there are a few hurdles to clear (regarding getting to the settings screen) so you can see if on-access is enabled or not.

    To recap what the test is:  After an installation (and probably add a reboot to make sure all is OK) can you get to (and this is where I think you're stuck at the moment) the following screen and see what is enabled:

    enable_on-access_scanning.png

    If opening the settings is really causing a problem then I suggest opening:

    C:\ProgramData\Sophos\Sophos Anti-Virus\machine.xml


    ...and checking what the following section in the XML file says:


    -
    -

    true
    true
    true
    true
    false    
    false


     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi,
    no config.xml file on the W8 PC.

    You are correct I was typing the wrong thing, should have been on access. Since disabled tamper protection on the UTM, ticked the on access box on bot installations and re-eabled tamper protection the W8 and W7 PCs have stopped complaining about on access being disabled.
    I have added my userid to the w8 on access group.

    At this stage all seems to be working okay and I now have information on how to fix future installations.

    Thank you

    Ian
  • Hi,
    no config.xml file on the W8 PC.

    Ian


    Oops!  Meant to say 'machine.xml'.  Now changed.

     - - - - - - - - - - - -

    Communities Moderator, SOPHOS
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • I am glad I am a mind reader, you really meant to add another layer in the file structure of config.
    My machine.xml file doesn't look anything like the example you posted.

    I will log on from the PC and copy the section into a post.

    Ian

    I expect I should uninstall EP and then install it running as admin.
  • Laptop is back to complaining about on access being disabled.

    Anyway, here is the extract from thje machine.xml on hte W8 64 PC.



                    
                        
                            truetruetruetruefalsefalse
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                        
                        
                            
                                truefalsetruefalse
                                
                                ApplicationControl0PuaDetection1BehaviourSuspicious0
                            
                        
                        
                            
                                falsefalse
                                falsefalse
                        
                        
                            
                        
                    
                





            
                
                    
                        
                            
                                
                                
                            
                        
                        
                            
                                101101101101101101101101101101
                                
                                    
                                
                            
                        
                    
                



    Hope this helps.

    Ian
Reply
  • Laptop is back to complaining about on access being disabled.

    Anyway, here is the extract from thje machine.xml on hte W8 64 PC.



                    
                        
                            truetruetruetruefalsefalse
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                                
                            
                        
                        
                            
                        
                        
                            
                                truefalsetruefalse
                                
                                ApplicationControl0PuaDetection1BehaviourSuspicious0
                            
                        
                        
                            
                                falsefalse
                                falsefalse
                        
                        
                            
                        
                    
                





            
                
                    
                        
                            
                                
                                
                            
                        
                        
                            
                                101101101101101101101101101101
                                
                                    
                                
                            
                        
                    
                



    Hope this helps.

    Ian
Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?