> Source: [sk178308](https://support.checkpoint.com/results/sk/sk178308)

# sk178308 - Endpoint E85.10 - Driver interferes with Sophos

| Property | Value |
|----------|-------|
| Solution ID | sk178308 |
| Date Created | 2022-03-11 |
| Last Modified | 2025-06-02 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E88.X |

## Symptoms

- * Sophos services suffer constant spikes in power usage and CPU.
* An attempt to disable self-protection yield no results. Only after the Firewall and Application Control Blade is uninstalled does the Sophos product return to normal functionality.

## Cause

1. After an upgrade from E83.20 to E85.10 or later versions, the vsdatant.sys driver interferes with the Sophos Tamper Protection feature, which provides ransomware protection from removal. The driver prevents important software updates and communication to the Sophos Central cloud console.
2. The vsdatant.sys driver cannot register callback for SEDService.exe.

## Solution

1. Upgrade client to [Enterprise Endpoint Security Windows Client](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk177584&partition=Basic&product=Endpoint) E86.25 or later.
2. Use passdialogue.exe or hash.exe to disable Self-Protection and perform these registry edits:
   1. Create AppCacheDisable DWORD value under  
      *HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Parameters*
   2. Assign it the value of 1.
   3. Reboot the system.

For information about how to modify a registry entry or replace/install a file on Endpoint Security Client using the Compliance Blade, see [sk132932](https://support.checkpoint.com/results/sk/sk132932).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
