Fix it now
Sophos setup stopped part way through fetching or applying its components and rolled itself back. Sophos publishes no meaning for 118, 122, 134 or 145, so the number tells you nothing you can act on. What it does not point at is your account or your licence, which are not checked at the stage where setup fails.
sc query msiserver
net start msiserver
- Remove any other antivirus or internet security suite, then restart. Two products that both load kernel-level filter drivers will not install alongside each other.
- Clear the leftovers with the previous vendor’s own removal tool rather than trusting Settings, Apps alone, which routinely leaves drivers and services in place.
- If Sophos has been installed here before, switch Tamper Protection off first from the console that manages the device, then run Sophos’s own removal utility obtained from Sophos.
- Download the installer again from your Sophos account rather than reusing an older copy, and run it as a local administrator.
- If setup fails at the same point on this network and completes on a phone hotspot, the download is being filtered. Allow the destinations Sophos documents, then retry.
0x80070641 is the one code here with a published meaning: it is Windows Installer error 1601, ERROR_INSTALL_SERVICE_FAILURE, the Windows Installer service could not be accessed. Start there and ignore the Sophos-specific number.
If setup completes and Sophos reports itself as protected, you are done. If not, the next section covers what the bootstrapper is doing at each stage and which of the four causes you are looking at.
Why it happens
The file you download is a bootstrapper, not the product. It authenticates to Sophos, works out which components your platform and entitlement cover, pulls them down, and installs them in sequence. The short numeric failure that comes out of that sequence is an internal identifier, and Sophos publishes no table that maps it to a cause. Treat 118, 122, 134 and 145 as markers that setup stopped, not as diagnoses.
Almost every stage depends on something outside the installer. The download needs the machine to reach Sophos over HTTPS without a proxy rewriting the traffic mid-stream. The install stage needs Windows Installer running, and needs no other security product holding the file system filter position Sophos is trying to take. The rollback stage is what turns a partial install into a clean failure, which is why you usually end up with nothing installed rather than something half-broken.
One thing worth settling before you start, because it changes what you expect to see. Microsoft’s compatibility guidance says Defender enters disabled mode on Windows client when a non-Microsoft antivirus is installed as the primary product, and its passive-mode guidance lists onboarding to Microsoft Defender for Endpoint as a prerequisite for passive mode. On an ordinary PC, expect disabled rather than a quiet second engine, which is why the window between removing one product and finishing the Sophos install matters. Get-MpComputerStatus | select AMRunningMode tells you which you have.
Because the numbers carry no published meaning, the productive method is elimination in a fixed order: another product, then the download path, then Windows Installer, then a previous Sophos installation. Each of those has a symptom that distinguishes it, and each is cheap to test.
A second security product is still on the machine
You have this one if Another suite appears in Settings, Apps, or its services are still listed in the Services console after you removed it.
- Uninstall the other product through Settings, Apps, then restart.
- Run that vendor’s own removal utility afterwards. It clears drivers and registry entries the uninstaller leaves behind.
- Open Windows Security, Virus & threat protection, Manage providers and confirm only one provider is registered.
- Restart again, then run the Sophos installer.
A preinstalled trial that expired months ago still counts. So does a management agent from an old managed service provider, even where the console it reported to no longer exists.
The download is being filtered or inspected
You have this one if The same stage fails repeatedly on the corporate network and works first time on a mobile hotspot.
- Get the current list of installation and update destinations from Sophos’s own documentation and allow them on the proxy, firewall and DNS filter. Do not guess at hostnames.
- Exempt that traffic from TLS interception. Certificate substitution mid-download is a common reason an installer rejects what it received.
- If the proxy needs credentials, run setup in a session that already holds them, or configure the proxy at machine scope rather than per user.
- Retry once the exclusions are live.
Windows Installer is unavailable, so nothing can be applied
You have this one if 0x80070641 in the dialog or the log, and other MSI-based installations on the same machine also fail.
- Check the service:
sc query msiserver. If it is stopped, runnet start msiserver. - Confirm its startup type is Manual rather than Disabled in the Services console.
- Restart to clear a pending file rename operation left by an earlier install or update.
- Confirm there is free space on the system drive and that the account running setup can write to
%TEMP%.
A previous Sophos installation was never fully removed
You have this one if Setup stops almost immediately with no meaningful download, or reports that an installation is already present.
- Turn Tamper Protection off for this device first, from whichever Sophos console manages it.
- Run the Sophos removal utility obtained from Sophos, not from a third-party download site.
- Restart so the drivers actually unload.
- Run the fresh installer.
Tamper Protection exists to stop exactly this kind of removal. If you cannot reach the console holding the setting, you will need whoever administers it before you get any further.
Full reference
Where the fault usually sits
| What you see | Where to look |
|---|---|
| Fails at the same point on every attempt, on every network | A conflicting product or a blocked installer service, not the download |
| Completes on a phone hotspot but not on the office network | HTTPS inspection or a web filter is breaking the download |
0x80070641 in the failure dialog |
The Windows Installer service could not be accessed |
| Stops immediately with no download | A previous Sophos installation, or Tamper Protection blocking removal |
| Different point each attempt | Disk space, %TEMP%, or a pending file rename operation |
The one code with a published meaning
0x80070641 is a HRESULT wrapper around Windows Installer error 1601, ERROR_INSTALL_SERVICE_FAILURE, published as the Windows Installer service not being accessible. It is a Windows fault rather than a Sophos one, and it will stop any MSI-based installation on the machine, which is the quickest way to confirm it: try installing something unrelated and see whether that fails too.
118, 122, 134 and 145 appear widely in community discussion with confident explanations attached. None of those explanations comes from Sophos, and they contradict each other. This article does not repeat them, because a wrong stage name sends you to the wrong place with more confidence than no name at all.
The gap while nothing is installed
Between removing the old product and finishing the Sophos install, the machine has no third-party protection. Microsoft documents Defender being re-enabled automatically once the other product is uninstalled, but confirm it on the Security providers page rather than assuming, and do not use that window to catch up on email.
Things not worth trying
- Deleting Sophos folders and registry keys by hand. Kernel drivers and service registrations are what block a reinstall, and hand-deleting files leaves those behind while removing what the official removal tool needs.
- Running the installer repeatedly without changing anything. The rollback is clean, so a second identical attempt produces an identical result.
- Disabling the other product’s real-time protection instead of removing it. It keeps its filter driver and its registration either way.
- Third-party ‘installer repair’ utilities. They change what the machine believes about installed products, which is a poor trade for a service that will not start.
Where a licence is and is not the answer
Your Sophos entitlement is not evaluated at the stage where setup fails, so a subscription problem does not produce an installer failure and buying a licence does not produce a successful install. What a licence does decide is the durable version of this problem: a machine that keeps two half-removed suites on it because nobody decided which product is the one being paid for. That decision is worth making once, for every device you own, rather than repeatedly at install time.
When a licence is the actual fix
The installer failure itself is a technical fault and no purchase fixes it, so treat this as a support job first. Where it keeps happening because there is already a security suite on the machine, the durable fix is to decide which product you are keeping and licence it for every device you own, rather than leaving a half-removed second suite to break the next installation too. Arco supplies Sophos Home Premium and can tell you how many devices a plan covers before you commit. Keeping the other product, or running Microsoft Defender on its own, are equally sound answers and cost you nothing.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
118 |
Setup stopped and rolled back. Sophos publishes no meaning for the number, so diagnose by stage and symptom rather than by the digits | not published by the vendor |
122 |
Another rollback identifier from the same install sequence, with no published meaning. Work the same checks | not published by the vendor |
0x80070641 |
Windows Installer error 1601, ERROR_INSTALL_SERVICE_FAILURE: the Windows Installer service could not be accessed | Microsoft Learn |
134 |
A further installer failure identifier with no published meaning; most often seen after an incomplete removal of a previous product | not published by the vendor |
145 |
Another rollback identifier with no published meaning. Read the installer log for the component that failed rather than the number | not published by the vendor |
Confirm the fix worked
- Windows Security, Virus & threat protection, Manage providers shows Sophos as the registered provider and no second suite.
- The Sophos interface reports itself as protected and up to date rather than still installing.
- Other MSI-based installations succeed, which rules 0x80070641 back out.
- Restart once and confirm protection comes back on its own without a prompt.
- No Sophos services are listed as stopped or failing in the Services console after that restart.
Questions people ask about this
Do I need to buy a new licence to get past error 118?
No. This is an installation fault, not a licensing one. Your entitlement is not even evaluated at the point where setup fails. A lapsed subscription is reported separately, once the product is installed and running.
What does error 118 actually mean?
Nothing published. Sophos does not release a table mapping these numbers to causes, and the confident explanations circulating in forums contradict each other. Diagnose from where setup stops and what else is on the machine.
Can I run Sophos alongside Microsoft Defender?
Not in the way people usually mean. Microsoft’s compatibility guidance describes Defender entering disabled mode on Windows client behind a non-Microsoft antivirus, and its passive-mode guidance lists Defender for Endpoint onboarding as a prerequisite for passive mode. Check with Get-MpComputerStatus | select AMRunningMode rather than assuming. Windows puts Defender back once the other product is removed.
Is it safe to delete Sophos folders and registry keys by hand?
It is a poor idea. Kernel drivers and service registrations are what block a reinstall, and hand-deleting files leaves those behind while removing what the official removal tool needs to work.
The install works at home but not in the office. Why?
Almost always a web filter, proxy or TLS inspection appliance between the machine and Sophos. The installer verifies what it downloads, and an inspected connection does not deliver the bytes it expected. The fix is a network exclusion, not an endpoint change.
