Showing posts with label Sophos AV. Show all posts
Showing posts with label Sophos AV. Show all posts

Friday, 8 April 2022

Sophos Cloud AV fails update on ML Engine

If you seeing this error "Failed to install sme64: general error" when trying to update.

It can be due to a recent change by Sophos in there SSL signing on the DLL.

RESOLVED Advisory: Sophos Central Windows devices - Sophos ML Engine installation failure

The root SSL is now from these guys

https://trusted-root-g4.chain-demos.digicert.com

If you are getting an SSL error on this website you will need to install the root SSL in to your OS and then try again to install the update and it should work.


Wednesday, 23 June 2021

Sophos Universal Reader and Finder (SURF)

SURF, or the Sophos Universal Reader and Finder, is a fantastic troubleshooting tool for Sophos Endpoint and Firewall. SURF provides easy access to Sophos support log bundles contents, extracting summary data and providing a search capability for the contained logs. SURF also identifies known issues and serves up links to Sophos knowledge base articles with helpful instructions should an issue is discovered.

The tool was released today and it looks cool,  its available to Sophos Partners and it looks like it would cut down on 1st line support time as it can pick out all the errors and identify know issues / fix's.

Works on Sophos AV SDU logs and Sophos XG CTR files

Available from here Tech Tools (sophos.com)

More information here Introducing SURF! - Sophos Techvids

Tuesday, 2 February 2021

Sophos AV Cloud Clear local update cache and force an update

  1. Disable Tamper Protection
  2. Press the keys Windows + R.
  3. Type services.msc then press Enter.
  4. Stop Sophos AutoUpdate Service.
  5. Rename the following folders:
    C:\ProgramData\Sophos\AutoUpdate\Cache\decoded
    C:\ProgramData\Sophos\AutoUpdate\data\Warehouse

    to

    C:\ProgramData\Sophos\AutoUpdate\Cache\decoded_old
    C:\ProgramData\Sophos\AutoUpdate\data\Warehouse_old 
  6. Delete the file SophosUpdateStatus.xml that is located at

    C:\ProgramData\Sophos\AutoUpdate\data\status.

  7. Start Sophos AutoUpdate Service.
  8. Open the Sophos Endpoint Agent user interface.
  9. Click About followed by the Update Now button.
  10. Once the update is completed, confirm the Last update time has changed and that it shows a green checkmark.
Note: These steps will trigger a pending reboot alert for Sophos once completed.