Hello!
We have been seeing the Failed to install ntp64: general error in a lot of our machines since around November. Most of the computers affected were new machines we imaged with SCCM. I see that this error was common with Windows 7 due to an update and I was wondering if that is the case here. I believe all machines should be Windows 10 build version 2004.
Is there a fix, or do I need to reinstall? The last time I tried to uninstall it didn't, and then I was locked out of Tamper Protection and it was showing it was still on, even though I turned it off...
Thank you in advance!
James
Could you link an install log from a client? If AutoUpdate keeps retrying evert hour to install, which it should be, there will probably be quite a few under \windows\temp\
E.g.Sophos Network Threat Protection…
E.g.Sophos Network Threat Protection Install Log 20210203 150932.txt
Thanks.
Since I can't upload the text file, here is the log:
ProductSetup::ProductSetup: Begin product setupProductSetup::InstUninstEntry: Begin installsetup::TamperProtectionControl::TamperProtectionControl: Disabled tamper protection for component NTPsetup::TamperProtectionControl::TamperProtectionControl: Disabled tamper protection for service Sophos Network Threat Protectionsetup::TamperProtectionControl::TamperProtectionControl: Disabled tamper protection for service sntpProductSetup::InstUninstEntry: Show gui: falseProductSetup::InstUninstEntry: Existing product code: {4B1F9009-CD85-43C0-BCBD-D491908D5A52}ProductSetup::InstUninstEntry: Install from: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64ProductSetup::InstUninstEntry: Install to: <default>=== Verbose logging started: 2/14/2021 18:01:45 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\su-setup32.exe ===MSI (c) (F4:F0) [18:01:45:457]: Cloaking enabled.MSI (c) (F4:F0) [18:01:45:457]: Attempting to enable all disabled privileges before calling Install on ServerMSI (c) (F4:F0) [18:01:45:473]: End dialog not enabledMSI (c) (F4:F0) [18:01:45:473]: Original package ==> C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msiMSI (c) (F4:F0) [18:01:45:473]: Package we're running from ==> C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msiMSI (c) (F4:F0) [18:01:45:473]: Machine policy value 'DisableUserInstalls' is 0MSI (c) (F4:F0) [18:01:45:473]: APPCOMPAT: Compatibility mode property overrides found.MSI (c) (F4:F0) [18:01:45:473]: APPCOMPAT: looking for appcompat database entry with ProductCode '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'.MSI (c) (F4:F0) [18:01:45:473]: APPCOMPAT: no matching ProductCode found in database.MSI (c) (F4:F0) [18:01:45:488]: MSCOREE not loaded loading copy from system32MSI (c) (F4:F0) [18:01:45:488]: APPCOMPAT: looking for appcompat database entry with ProductCode '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'.MSI (c) (F4:F0) [18:01:45:488]: APPCOMPAT: no matching ProductCode found in database.MSI (c) (F4:F0) [18:01:45:488]: Transforms are not secure.MSI (c) (F4:F0) [18:01:45:488]: Note: 1: 2205 2: 3: Control MSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\WINDOWS\TEMP\Sophos Network Threat Protection Install Log 20210214 180145.txt'.MSI (c) (F4:F0) [18:01:45:488]: No Command Line.MSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{BDBDC64C-EB88-4135-BD3F-FE19CA9893E3}'.MSI (c) (F4:F0) [18:01:45:488]: Product Code passed to Engine.Initialize: '(none)'MSI (c) (F4:F0) [18:01:45:488]: Product Code from property table before transforms: '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'MSI (c) (F4:F0) [18:01:45:488]: Product Code from property table after transforms: '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'MSI (c) (F4:F0) [18:01:45:488]: Product not registered: beginning first-time installMSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.MSI (c) (F4:F0) [18:01:45:488]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2 MSI (c) (F4:F0) [18:01:45:488]: Entering CMsiConfigurationManager::SetLastUsedSource.MSI (c) (F4:F0) [18:01:45:488]: User policy value 'SearchOrder' is 'nmu'MSI (c) (F4:F0) [18:01:45:488]: Adding new sources is allowed.MSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:488]: Package name extracted from package path: 'Sophos Network Threat Protection.msi'MSI (c) (F4:F0) [18:01:45:488]: Package to be registered: 'Sophos Network Threat Protection.msi'MSI (c) (F4:F0) [18:01:45:488]: Note: 1: 2262 2: AdminProperties 3: -2147287038 MSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:488]: TRANSFORMS property is now: MSI (c) (F4:F0) [18:01:45:488]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '405'.MSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\RoamingMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\FavoritesMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network ShortcutsMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DocumentsMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer ShortcutsMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\RecentMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendToMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\TemplatesMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\ProgramDataMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\LocalMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PicturesMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\ProgramsMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start MenuMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\Users\Public\DesktopMSI (c) (F4:F0) [18:01:45:488]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start MenuMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DesktopMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\TemplatesMSI (c) (F4:F0) [18:01:45:504]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\FontsMSI (c) (F4:F0) [18:01:45:504]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 MSI (c) (F4:F0) [18:01:45:519]: MSI_LUA: Setting AdminUser property to 1 because this is the client or the user has already permitted elevationMSI (c) (F4:F0) [18:01:45:519]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:519]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'PBC-COM'.MSI (c) (F4:F0) [18:01:45:519]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'COMPHX'.MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi'.MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi'.MSI (c) (F4:F0) [18:01:45:519]: Machine policy value 'MsiDisableEmbeddedUI' is 0MSI (c) (F4:F0) [18:01:45:519]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UIMSI (c) (F4:F0) [18:01:45:519]: EEUI - Disabling MsiEmbeddedUI in quiet mode=== Logging started: 2/14/2021 18:01:45 ===MSI (c) (F4:F0) [18:01:45:519]: Machine policy value 'DisableRollback' is 0MSI (c) (F4:F0) [18:01:45:519]: User policy value 'DisableRollback' is 0MSI (c) (F4:F0) [18:01:45:519]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.MSI (c) (F4:F0) [18:01:45:519]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (c) (F4:F0) [18:01:45:519]: APPCOMPAT: [DetectVersionLaunchCondition] Launch condition already passes.MSI (c) (F4:F0) [18:01:45:519]: Creating MSIHANDLE (1) of type 790537 for thread 5616MSI (c) (F4:F0) [18:01:45:519]: MsiOpenPackageEx is returning 0MSI (c) (F4:F0) [18:01:45:519]: Closing MSIHANDLE (1) of type 790537 for thread 5616=== Verbose logging stopped: 2/14/2021 18:01:45 ===
setup::MsiInstaller::install: New version: {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}, version: 1.11.194.0=== Verbose logging started: 2/14/2021 18:01:45 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\su-setup32.exe ===MSI (c) (F4:F0) [18:01:45:551]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\WINDOWS\Installer\4978e5.msi' against software restriction policyMSI (c) (F4:F0) [18:01:45:551]: SOFTWARE RESTRICTION POLICY: C:\WINDOWS\Installer\4978e5.msi has a digital signatureMSI (c) (F4:F0) [18:01:45:551]: SOFTWARE RESTRICTION POLICY: C:\WINDOWS\Installer\4978e5.msi is permitted to run because the user token authorizes execution (system or service token).MSI (c) (F4:F0) [18:01:45:551]: Cloaking enabled.MSI (c) (F4:F0) [18:01:45:551]: Attempting to enable all disabled privileges before calling Install on ServerMSI (c) (F4:F0) [18:01:45:551]: End dialog not enabledMSI (c) (F4:F0) [18:01:45:551]: Original package ==> C:\WINDOWS\Installer\4978e5.msiMSI (c) (F4:F0) [18:01:45:551]: Package we're running from ==> C:\WINDOWS\Installer\4978e5.msiMSI (c) (F4:F0) [18:01:45:551]: APPCOMPAT: Uninstall Flags override found.MSI (c) (F4:F0) [18:01:45:551]: APPCOMPAT: Uninstall VersionNT override found.MSI (c) (F4:F0) [18:01:45:551]: APPCOMPAT: Uninstall ServicePackLevel override found.MSI (c) (F4:F0) [18:01:45:551]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (c) (F4:F0) [18:01:45:551]: APPCOMPAT: no matching ProductCode found in database.MSI (c) (F4:F0) [18:01:45:566]: MSCOREE not loaded loading copy from system32MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'DisablePatch' is 0MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'AllowLockdownPatch' is 0MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'DisableLUAPatching' is 0MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'DisableFlyWeightPatching' is 0MSI (c) (F4:F0) [18:01:45:566]: Enabling baseline caching for this transaction since all active patches are MSI 3.0 style MSPs or at least one MSI 3.0 minor update patch is activeMSI (c) (F4:F0) [18:01:45:566]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (c) (F4:F0) [18:01:45:566]: APPCOMPAT: no matching ProductCode found in database.MSI (c) (F4:F0) [18:01:45:566]: Transforms are not secure.MSI (c) (F4:F0) [18:01:45:566]: Note: 1: 2205 2: 3: Control MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\WINDOWS\TEMP\Sophos Network Threat Protection Install Log 20210214 180145.txt'.MSI (c) (F4:F0) [18:01:45:566]: No Command Line.MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{0B95A4E2-4953-4CE7-B8F7-53BB197E234A}'.MSI (c) (F4:F0) [18:01:45:566]: Product Code passed to Engine.Initialize: '(none)'MSI (c) (F4:F0) [18:01:45:566]: Product Code from property table before transforms: '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (c) (F4:F0) [18:01:45:566]: Product Code from property table after transforms: '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (c) (F4:F0) [18:01:45:566]: Product registered: entering maintenance modeMSI (c) (F4:F0) [18:01:45:566]: Determined that existing product (either this product or the product being upgraded with a patch) is installed per-machine.MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding ProductState property. Its value is '5'.MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:566]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2 MSI (c) (F4:F0) [18:01:45:566]: Package name retrieved from configuration data: 'Sophos Network Threat Protection.msi'MSI (c) (F4:F0) [18:01:45:566]: Note: 1: 2262 2: AdminProperties 3: -2147287038 MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'DisableMsi' is 0MSI (c) (F4:F0) [18:01:45:566]: Machine policy value 'AlwaysInstallElevated' is 0MSI (c) (F4:F0) [18:01:45:566]: User policy value 'AlwaysInstallElevated' is 0MSI (c) (F4:F0) [18:01:45:566]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is admin assigned: LocalSystem owns the publish key.MSI (c) (F4:F0) [18:01:45:566]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is managed.MSI (c) (F4:F0) [18:01:45:566]: Running product '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}' with elevated privileges: Product is assigned.MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:566]: TRANSFORMS property is now: MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding PRODUCTLANGUAGE property. Its value is '1033'.MSI (c) (F4:F0) [18:01:45:566]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '405'.MSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\RoamingMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\FavoritesMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network ShortcutsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DocumentsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer ShortcutsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\RecentMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendToMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\TemplatesMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramDataMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\LocalMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PicturesMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\ProgramsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start MenuMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\Users\Public\DesktopMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start MenuMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DesktopMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\TemplatesMSI (c) (F4:F0) [18:01:45:566]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\FontsMSI (c) (F4:F0) [18:01:45:566]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 MSI (c) (F4:F0) [18:01:45:582]: MSI_LUA: Setting AdminUser property to 1 because this is the client or the user has already permitted elevationMSI (c) (F4:F0) [18:01:45:582]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.MSI (c) (F4:F0) [18:01:45:582]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'PBC-COM'.MSI (c) (F4:F0) [18:01:45:582]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'COMPHX'.MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding Installed property. Its value is '00:00:00'.MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\WINDOWS\Installer\4978e5.msi'.MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\WINDOWS\Installer\4978e5.msi'.MSI (c) (F4:F0) [18:01:45:582]: Machine policy value 'MsiDisableEmbeddedUI' is 0MSI (c) (F4:F0) [18:01:45:582]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UIMSI (c) (F4:F0) [18:01:45:582]: EEUI - Disabling MsiEmbeddedUI in quiet mode=== Logging started: 2/14/2021 18:01:45 ===MSI (c) (F4:F0) [18:01:45:582]: Note: 1: 2205 2: 3: PatchPackage MSI (c) (F4:F0) [18:01:45:582]: Machine policy value 'DisableRollback' is 0MSI (c) (F4:F0) [18:01:45:582]: User policy value 'DisableRollback' is 0MSI (c) (F4:F0) [18:01:45:582]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.MSI (c) (F4:F0) [18:01:45:582]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (c) (F4:F0) [18:01:45:582]: APPCOMPAT: [DetectVersionLaunchCondition] Launch condition already passes.MSI (c) (F4:F0) [18:01:45:582]: Creating MSIHANDLE (2) of type 790537 for thread 5616MSI (c) (F4:F0) [18:01:45:582]: MsiOpenPackageEx is returning 0MSI (c) (F4:F0) [18:01:45:582]: MsiOpenPackage is returning 0MSI (c) (F4:F0) [18:01:45:582]: Closing MSIHANDLE (2) of type 790537 for thread 5616=== Verbose logging stopped: 2/14/2021 18:01:45 ===
setup::MsiInstaller::install: Installed version: {4B1F9009-CD85-43C0-BCBD-D491908D5A52}, version: 1.9.2235.0setup::MsiInstaller::install: Removing IPS rules registry values because the product code or version is differentsetup::MsiInstaller::install: Performing major upgradesetup::MsiInstaller::cleanInstall: Running clean installsetup::MsiInstaller::installOrUpgrade: Executing: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi INSTALLDIR="" REBOOT=ReallySuppress INSTALLINGVERSION="1.11.194.0" ARPSYSTEMCOMPONENT=1setup::MsiInstaller::tryRunMsi: Running MSI command, attempt (1 of 10)=== Verbose logging started: 2/14/2021 18:01:45 Build type: SHIP UNICODE 5.00.10011.00 Calling process: C:\ProgramData\Sophos\AutoUpdate\Cache\sophos_autoupdate1.dir\su-setup32.exe ===MSI (c) (F4:3C) [18:01:45:676]: Resetting cached policy valuesMSI (c) (F4:3C) [18:01:45:676]: Machine policy value 'Debug' is 0MSI (c) (F4:3C) [18:01:45:676]: ******* RunEngine: ******* Product: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi ******* Action: ******* CommandLine: **********MSI (c) (F4:3C) [18:01:45:676]: Client-side and UI is none or basic: Running entire install on the server.MSI (c) (F4:3C) [18:01:45:676]: Grabbed execution mutex.MSI (c) (F4:3C) [18:01:45:676]: Cloaking enabled.MSI (c) (F4:3C) [18:01:45:676]: Attempting to enable all disabled privileges before calling Install on ServerMSI (c) (F4:3C) [18:01:45:676]: Incrementing counter to disable shutdown. Counter after increment: 0MSI (s) (20:DC) [18:01:45:676]: Running installation inside multi-package transaction C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msiMSI (s) (20:DC) [18:01:45:676]: Grabbed execution mutex.MSI (s) (20:00) [18:01:45:691]: Resetting cached policy valuesMSI (s) (20:00) [18:01:45:691]: Machine policy value 'Debug' is 0MSI (s) (20:00) [18:01:45:691]: ******* RunEngine: ******* Product: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi ******* Action: ******* CommandLine: **********MSI (s) (20:00) [18:01:45:691]: Machine policy value 'DisableUserInstalls' is 0MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 00006109C80000000100000000F01FECMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 00006109C80000000100000000F01FECMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 00006109C80090400100000000F01FECMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 00006109C80090400100000000F01FECMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 00006109E70000000100000000F01FECMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 00006109E70000000100000000F01FECMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 12B8D03ED28D112328CCF0A0D541598EMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 12B8D03ED28D112328CCF0A0D541598EMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 1A9098E3DF554C64F80C06343133A12AMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 1A9098E3DF554C64F80C06343133A12AMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 30E9055DEC34B074CB47440033875276MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 30E9055DEC34B074CB47440033875276MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 44DB0475D85BA123FA0CD6D35465DDC6MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 44DB0475D85BA123FA0CD6D35465DDC6MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 51DDCFE42A4298D4484A58D7B16FF88AMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 51DDCFE42A4298D4484A58D7B16FF88AMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 5C793CEDE7B8FEA47894C96DDD001D0CMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 5C793CEDE7B8FEA47894C96DDD001D0CMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 61A5A901E90E28B47A481D87F011096DMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 61A5A901E90E28B47A481D87F011096DMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 68AB67CA7DA73301B744CAF070E41400MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 68AB67CA7DA73301B744CAF070E41400MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 71DCBBF1304249742B8A3ADADDB3A08FMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 71DCBBF1304249742B8A3ADADDB3A08FMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 7B31A6F17A59782499A4C68EC265845EMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 7B31A6F17A59782499A4C68EC265845EMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 810B660DB8445C04094352B9CB4C3915MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 810B660DB8445C04094352B9CB4C3915MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 8520DAD7C5154DD39846DB1714990E7FMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 8520DAD7C5154DD39846DB1714990E7FMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 89A6161325839E94DB6D771ABA5875A1MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 89A6161325839E94DB6D771ABA5875A1MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 96F071321C0420729100000010000000MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 96F071321C0420729100000010000000MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: 99E80CA9B0328e74791254777B1F42AEMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: 99E80CA9B0328e74791254777B1F42AEMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: A49D3069829097449B5C9CDB74DE89F0MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: A49D3069829097449B5C9CDB74DE89F0MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: AAB6F137689A4A549863C7A3AAAA67B0MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: AAB6F137689A4A549863C7A3AAAA67B0MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: AD8F0D823DBB4454492E8DBEA63BB91FMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: AD8F0D823DBB4454492E8DBEA63BB91FMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: C21BB7D84586FD646AD78FD277D8578CMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: C21BB7D84586FD646AD78FD277D8578CMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: C94587080FFC5C84B977B64AA84176D3MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: C94587080FFC5C84B977B64AA84176D3MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: CAFC5ACA99E946747ADAFAC53FAF51FBMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: CAFC5ACA99E946747ADAFAC53FAF51FBMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: CE6380BC270BD863282B3D74B09F7570MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: CE6380BC270BD863282B3D74B09F7570MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: D2821382915801943B93322048A0EB3FMSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: D2821382915801943B93322048A0EB3FMSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: DCDEC83B99B45A244A039364FFAC22A9MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: DCDEC83B99B45A244A039364FFAC22A9MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: DFDFBE4C55C0F5E39A913E5C949420A4MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: DFDFBE4C55C0F5E39A913E5C949420A4MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: F40B9456628EA0E4C8F38358040F5814MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: F40B9456628EA0E4C8F38358040F5814MSI (s) (20:00) [18:01:45:691]: Setting cached product context: machine assigned for product: FED6F71CC43D57B4791E8D012604B8A4MSI (s) (20:00) [18:01:45:691]: Using cached product context: machine assigned for product: FED6F71CC43D57B4791E8D012604B8A4MSI (s) (20:00) [18:01:45:691]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:00) [18:01:45:691]: SRSetRestorePoint skipped for this transaction.MSI (s) (20:00) [18:01:45:691]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2 MSI (s) (20:00) [18:01:45:691]: File will have security applied from OpCode.MSI (s) (20:00) [18:01:45:691]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi' against software restriction policyMSI (s) (20:00) [18:01:45:707]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi has a digital signatureMSI (s) (20:00) [18:01:45:707]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi is permitted to run because the user token authorizes execution (system or service token).MSI (s) (20:00) [18:01:45:707]: Creating MSIHANDLE (1) of type 790542 for thread 8960MSI (s) (20:00) [18:01:45:707]: MSCOREE not loaded loading copy from system32MSI (s) (20:00) [18:01:45:707]: End dialog not enabledMSI (s) (20:00) [18:01:45:707]: Original package ==> C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msiMSI (s) (20:00) [18:01:45:707]: Package we're running from ==> C:\WINDOWS\Installer\5e8d70f4.msiMSI (s) (20:00) [18:01:45:707]: APPCOMPAT: Compatibility mode property overrides found.MSI (s) (20:00) [18:01:45:707]: APPCOMPAT: looking for appcompat database entry with ProductCode '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'.MSI (s) (20:00) [18:01:45:707]: APPCOMPAT: no matching ProductCode found in database.MSI (s) (20:00) [18:01:45:723]: Machine policy value 'TransformsSecure' is 0MSI (s) (20:00) [18:01:45:723]: User policy value 'TransformsAtSource' is 0MSI (s) (20:00) [18:01:45:723]: Machine policy value 'DisablePatch' is 0MSI (s) (20:00) [18:01:45:723]: Machine policy value 'AllowLockdownPatch' is 0MSI (s) (20:00) [18:01:45:723]: Machine policy value 'DisableLUAPatching' is 0MSI (s) (20:00) [18:01:45:723]: Machine policy value 'DisableFlyWeightPatching' is 0MSI (s) (20:00) [18:01:45:723]: Enabling baseline caching for this transaction since all active patches are MSI 3.0 style MSPs or at least one MSI 3.0 minor update patch is activeMSI (s) (20:00) [18:01:45:723]: APPCOMPAT: looking for appcompat database entry with ProductCode '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'.MSI (s) (20:00) [18:01:45:723]: APPCOMPAT: no matching ProductCode found in database.MSI (s) (20:00) [18:01:45:723]: Transforms are not secure.MSI (s) (20:00) [18:01:45:723]: Note: 1: 2205 2: 3: Control MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\WINDOWS\TEMP\Sophos Network Threat Protection Install Log 20210214 180145.txt'.MSI (s) (20:00) [18:01:45:723]: Command Line: INSTALLDIR= REBOOT=ReallySuppress INSTALLINGVERSION=1.11.194.0 ARPSYSTEMCOMPONENT=1 CURRENTDIRECTORY=C:\WINDOWS\system32 CLIENTUILEVEL=3 MSICLIENTUSESEXTERNALUI=1 CLIENTPROCESSID=1012 MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{BDBDC64C-EB88-4135-BD3F-FE19CA9893E3}'.MSI (s) (20:00) [18:01:45:723]: Product Code passed to Engine.Initialize: ''MSI (s) (20:00) [18:01:45:723]: Product Code from property table before transforms: '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'MSI (s) (20:00) [18:01:45:723]: Product Code from property table after transforms: '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'MSI (s) (20:00) [18:01:45:723]: Product not registered: beginning first-time installMSI (s) (20:00) [18:01:45:723]: Product {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA} is not managed.MSI (s) (20:00) [18:01:45:723]: MSI_LUA: Credential prompt not required, user is an adminMSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.MSI (s) (20:00) [18:01:45:723]: Entering CMsiConfigurationManager::SetLastUsedSource.MSI (s) (20:00) [18:01:45:723]: User policy value 'SearchOrder' is 'nmu'MSI (s) (20:00) [18:01:45:723]: Adding new sources is allowed.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.MSI (s) (20:00) [18:01:45:723]: Package name extracted from package path: 'Sophos Network Threat Protection.msi'MSI (s) (20:00) [18:01:45:723]: Package to be registered: 'Sophos Network Threat Protection.msi'MSI (s) (20:00) [18:01:45:723]: Note: 1: 2262 2: AdminProperties 3: -2147287038 MSI (s) (20:00) [18:01:45:723]: Machine policy value 'DisableMsi' is 0MSI (s) (20:00) [18:01:45:723]: Machine policy value 'AlwaysInstallElevated' is 0MSI (s) (20:00) [18:01:45:723]: User policy value 'AlwaysInstallElevated' is 0MSI (s) (20:00) [18:01:45:723]: Product installation will be elevated because user is admin and product is being installed per-machine.MSI (s) (20:00) [18:01:45:723]: Running product '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}' with elevated privileges: Product is assigned.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding INSTALLINGVERSION property. Its value is '1.11.194.0'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding ARPSYSTEMCOMPONENT property. Its value is '1'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\WINDOWS\system32'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding MSICLIENTUSESEXTERNALUI property. Its value is '1'.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '1012'.MSI (s) (20:00) [18:01:45:723]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0MSI (s) (20:00) [18:01:45:723]: RESTART MANAGER: Disabled by MSIRESTARTMANAGERCONTROL property; Windows Installer will use the built-in FilesInUse functionality.MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.MSI (s) (20:00) [18:01:45:723]: TRANSFORMS property is now: MSI (s) (20:00) [18:01:45:723]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '405'.MSI (s) (20:00) [18:01:45:723]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\RoamingMSI (s) (20:00) [18:01:45:723]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\FavoritesMSI (s) (20:00) [18:01:45:723]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network ShortcutsMSI (s) (20:00) [18:01:45:723]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DocumentsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer ShortcutsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\RecentMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendToMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\TemplatesMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramDataMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\LocalMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PicturesMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\ProgramsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start MenuMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\Users\Public\DesktopMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start MenuMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DesktopMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\TemplatesMSI (s) (20:00) [18:01:45:738]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\FontsMSI (s) (20:00) [18:01:45:738]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 MSI (s) (20:00) [18:01:45:754]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.MSI (s) (20:00) [18:01:45:754]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'PBC-COM'.MSI (s) (20:00) [18:01:45:754]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'COMPHX'.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\WINDOWS\Installer\5e8d70f4.msi'.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msi'.MSI (s) (20:00) [18:01:45:754]: Machine policy value 'MsiDisableEmbeddedUI' is 0MSI (s) (20:00) [18:01:45:754]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UIMSI (s) (20:00) [18:01:45:754]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic installMSI (s) (20:00) [18:01:45:754]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:00) [18:01:45:754]: Machine policy value 'DisableRollback' is 0MSI (s) (20:00) [18:01:45:754]: User policy value 'DisableRollback' is 0MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.=== Logging started: 2/14/2021 18:01:45 ===MSI (s) (20:00) [18:01:45:754]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:00) [18:01:45:754]: APPCOMPAT: [DetectVersionLaunchCondition] Launch condition already passes.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.MSI (s) (20:00) [18:01:45:754]: Doing action: INSTALLMSI (s) (20:00) [18:01:45:754]: Note: 1: 2205 2: 3: ActionText Action start 18:01:45: INSTALL.MSI (s) (20:00) [18:01:45:754]: Running ExecuteSequenceMSI (s) (20:00) [18:01:45:754]: Doing action: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92CMSI (s) (20:00) [18:01:45:754]: Note: 1: 2205 2: 3: ActionText MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C property. Its value is 'C:\WINDOWS\system32\'.Action start 18:01:45: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C.MSI (s) (20:00) [18:01:45:754]: Doing action: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FAMSI (s) (20:00) [18:01:45:754]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C. Return value 1.MSI (s) (20:00) [18:01:45:754]: PROPERTY CHANGE: Adding SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA property. Its value is 'C:\WINDOWS\SysWOW64\'.Action start 18:01:45: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA.MSI (s) (20:00) [18:01:45:754]: Doing action: FindRelatedProductsMSI (s) (20:00) [18:01:45:754]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA. Return value 1.MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525Action start 18:01:45: FindRelatedProducts.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding WIX_UPGRADE_DETECTED property. Its value is '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding MIGRATE property. Its value is '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:769]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:00) [18:01:45:769]: Doing action: AppSearchMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: FindRelatedProducts. Return value 1.Action start 18:01:45: AppSearch.MSI (s) (20:00) [18:01:45:769]: Note: 1: 2262 2: Signature 3: -2147287038 MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding INSTALLTYPE_IS_CENTRAL property. Its value is '#1'.MSI (s) (20:00) [18:01:45:769]: Doing action: LaunchConditionsMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: AppSearch. Return value 1.Action start 18:01:45: LaunchConditions.MSI (s) (20:00) [18:01:45:769]: Doing action: ValidateProductIDMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: LaunchConditions. Return value 1.Action start 18:01:45: ValidateProductID.MSI (s) (20:00) [18:01:45:769]: Skipping action: TamperProtectionCheckRemove (condition is false)MSI (s) (20:00) [18:01:45:769]: Doing action: CostInitializeMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: ValidateProductID. Return value 1.MSI (s) (20:00) [18:01:45:769]: Machine policy value 'MaxPatchCacheSize' is 10MSI (s) (20:00) [18:01:45:769]: Baseline: Sorting baselines for {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}.MSI (s) (20:00) [18:01:45:769]: Baseline: New baseline 1.11.194 from transaction.MSI (s) (20:00) [18:01:45:769]: Baseline: Sorted order Native: Order 0.MSI (s) (20:00) [18:01:45:769]: Baseline Data Table:MSI (s) (20:00) [18:01:45:769]: ProductCode: {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA} Version: 1.11.194 Attributes: 0 PatchId: Native BaselineId: -2147483648 Order: 0MSI (s) (20:00) [18:01:45:769]: Baseline File Table:MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'C:\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Patch MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: MsiPatchHeaders MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: __MsiPatchFileList MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:00) [18:01:45:769]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId` MSI (s) (20:00) [18:01:45:769]: Delta compression fallback method for this product transaction is 'MSI 2.0 legacy obsolescence'MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Patch Action start 18:01:45: CostInitialize.MSI (s) (20:00) [18:01:45:769]: Doing action: FileCostMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: CostInitialize. Return value 1.MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: MsiAssembly MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Class MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Extension MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: TypeLib Action start 18:01:45: FileCost.MSI (s) (20:00) [18:01:45:769]: Doing action: CostFinalizeMSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: FileCost. Return value 1.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Patch MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: Condition MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'C:\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 property. Its value is 'C:\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SophosAppData property. Its value is 'C:\ProgramData\Sophos\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding HeartbeatData property. Its value is 'C:\ProgramData\Sophos\Heartbeat\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding HeartbeatPersist property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Persist\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding HeartbeatLogs property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Logs\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding HeartbeatConfig property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Config\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding ProductData property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SnortData property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding Logs property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding Config property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding Status property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding Sophos property. Its value is 'C:\Program Files\Sophos\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding INSTALLDIR property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding plugins property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SnortConfDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SnortPreProcDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SnortDynModulesDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\'.MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding SophosNTPLWFDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\'.MSI (s) (20:00) [18:01:45:769]: Target path resolution complete. Dumping Directory table...MSI (s) (20:00) [18:01:45:769]: Note: target paths subject to change (via custom actions or browsing)MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: TARGETDIR , Object: C:\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: WindowsFolder , Object: C:\WINDOWS\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: System64Folder , Object: C:\WINDOWS\system32\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C , Object: C:\WINDOWS\system32\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SystemFolder , Object: C:\WINDOWS\SysWOW64\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA , Object: C:\WINDOWS\SysWOW64\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 , Object: C:\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: CommonAppDataFolder , Object: C:\ProgramData\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SophosAppData , Object: C:\ProgramData\Sophos\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: HeartbeatData , Object: C:\ProgramData\Sophos\Heartbeat\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: HeartbeatPersist , Object: C:\ProgramData\Sophos\Heartbeat\Persist\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: HeartbeatLogs , Object: C:\ProgramData\Sophos\Heartbeat\Logs\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: HeartbeatConfig , Object: C:\ProgramData\Sophos\Heartbeat\Config\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: ProductData , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SnortData , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: Logs , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: Config , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: Status , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: ProgramFiles64Folder , Object: C:\Program Files\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: Sophos , Object: C:\Program Files\Sophos\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: INSTALLDIR , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: plugins , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SnortConfDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SnortPreProcDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SnortDynModulesDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\MSI (s) (20:00) [18:01:45:769]: Dir (target): Key: SophosNTPLWFDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\MSI (s) (20:00) [18:01:45:769]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.MSI (s) (20:00) [18:01:45:769]: Note: 1: 2205 2: 3: MsiAssembly MSI (s) (20:00) [18:01:45:769]: Note: 1: 2228 2: 3: MsiAssembly 4: SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`, `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ? MSI (s) (20:00) [18:01:45:769]: Disallowing installation of component: {14E8634F-8AEA-4CD1-AC48-BEBFDA18523A} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:785]: Disallowing installation of component: {570C624B-D57C-4CD1-9013-1B80C800093B} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:785]: Disallowing installation of component: {E5B92048-5859-4AF1-AEAD-B97EBF00B087} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:785]: Disallowing installation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:785]: Disallowing installation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:785]: Disallowing installation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:801]: Disallowing installation of component: {4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1} since the keyfile exists and the component is marked to never overwrite existing installationsAction start 18:01:45: CostFinalize.MSI (s) (20:00) [18:01:45:801]: Doing action: MigrateFeatureStatesMSI (s) (20:00) [18:01:45:801]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: CostFinalize. Return value 1.MSI (s) (20:00) [18:01:45:801]: Migrating feature settings from product(s) '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (s) (20:00) [18:01:45:816]: MigrateFeatureStates: based on existing product, setting feature 'AllComponents' to 'Local' state.MSI (s) (20:00) [18:01:45:816]: Disallowing installation of component: {4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1} since the keyfile exists and the component is marked to never overwrite existing installationsMSI (s) (20:00) [18:01:45:832]: Disallowing installation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:832]: Disallowing installation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:832]: Disallowing installation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:832]: Disallowing installation of component: {E5B92048-5859-4AF1-AEAD-B97EBF00B087} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:832]: Disallowing installation of component: {570C624B-D57C-4CD1-9013-1B80C800093B} since the same component with higher versioned keyfile existsMSI (s) (20:00) [18:01:45:847]: Disallowing installation of component: {14E8634F-8AEA-4CD1-AC48-BEBFDA18523A} since the same component with higher versioned keyfile existsAction start 18:01:45: MigrateFeatureStates.MSI (s) (20:00) [18:01:45:847]: Doing action: InstallValidateMSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:45: MigrateFeatureStates. Return value 1.MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: Dialog MSI (s) (20:00) [18:01:45:847]: Feature: AllComponents; Installed: Absent; Request: Local; Action: LocalMSI (s) (20:00) [18:01:45:847]: Component: InstallationFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ProductDataFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ConfigDataFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: StatusFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: LogsDataFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortDataFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatProductDataFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatConfigFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatLogsFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatPersistFolder; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: Driver; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: LWF; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: navl.dll; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: integrity.dat; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ProductInformation; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ServiceInstallWin8Plus; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ServiceInstallWin7Only; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ServiceCommon; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: NTPAdapter; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: Heartbeat.dll; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatRegistry; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HeartbeatNativeRegistry; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: Heartbeat.xml; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: Notice.txt; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HealthApi; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: HbtAdapter; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SspInterface; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: Telemetry.exe; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: TelemetryRegistry; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: RemoveObsoleteAutoUpdateRegistration; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: ScfDat; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SofDat; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortExe; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortDynModules; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortDynPreProc; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortConf; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: SnortDefaultRules; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_40D84364EA842FA136B8FD13DDC0D56B; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_39878D1E6847FC98DBBF4DBC681E5084; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_915D4DE5AC2958F4E9E11A531B9EA835; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_9E6863D5DA03BD69631F202C92D19A60; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_71A947406F71D3B309E337B64A7F7832; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_E78A19C76D60702926ABE2296C875F1E; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_4C8A5B3AC90DB17E9DA4ED49BAD39538; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_8ECE5DB0F042F762611EBFD2289574C7; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_CEECECE51D82B086879DBF78B65862E7; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_7CF78A9132C1A81C68F7ABC5FDF24E2A; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_DA1F2B183C5BCE4FD603A6EC3B54243A; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_28A5FAF0643E13309FAFC807839EC90D; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_B661BE2CDE2C76B03E876B04E7FB2B12; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_3893BC5956C7BE355DDE9E37446A6D03; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_EBDC9486A0E1230D5EC092D7E8CBB4BC; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_1C9216A348BA2BDC09A1060BA5F72823; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_7ADD905B2E5619CCA9D17EEC5053A4A6; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_14CC9F77B2DFDC9FD42754DAA16F7D2C; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_52DCF994F3D451DE25E6C6175FA8A569; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_3D360AE2084BA5DD98F03E35FC2A4426; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_16CE291FE9D32F0D2F408BCBC247D190; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_8AF263AEF732721ECE1F45C4D699210A; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_9AF859CEDF9D329E2E6CD220D4A89A0C; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_B688306A458B84E28816F8D6778A34E1; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_A3F6487E5CC9E500FA56EEAB3F26C1C8; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_7AEC367EBDB5BF4C39E3667551695B48; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_E7E3239C29419031F40F31EABB9C5C5A; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_D089A4389D1A4310245EFD436E285512; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_13CF16406E509062B6836D9F815D988F; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_0C0C9CFE97F0C684A8B464A70B0DB6D3; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_3AE2E2073BC5F8F5B9E80E6F52F9EE7C; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_BF934AA7F81A8CB8E376BAB607CA930F; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_B52FC07FFE74FDCB8247ACBE7F11134A; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_13497740688A2F012E248B466BEDADA8; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_12A8AFCDF13801350D980FEC432E08AB; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_B4FFE1991E42464048BC746529DD8726; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_B1BC50FE23021C628A3A572821D40D62; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_0EBC8368A1140301A827EFC762022373; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_2E9EA86FD6182A7FC5F64866BE3922CB; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_5BF7215406895F158FD7F8CD49117FB7; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_C76CDD15946ADD012F33BACEBF54EBBD; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_F36646D6066C98ADFB776FB7983F5D92; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_D6ED6891FB6E750E41BCBFA158FE52AB; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_E04EEE8DCDEFB517011CE58E0BB9CD09; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_CC76C1F8918257084D13AF2045641E6E; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: cmp64_792D7E761DFC7E91E500387604E2A68D; Installed: Absent; Request: Local; Action: Local; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_msvcr120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_msvcp120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_vccorlib120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_msvcr120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_msvcp120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: C_CENTRAL_vccorlib120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Absent; Request: Local; Action: Null; Client State: UnknownMSI (s) (20:00) [18:01:45:847]: Component: __ServiceCommon65; Installed: Null; Request: Local; Action: Local; Client State: NullMSI (s) (20:00) [18:01:45:847]: Component: __TelemetryRegistry65; Installed: Null; Request: Local; Action: Local; Client State: NullMSI (s) (20:00) [18:01:45:847]: Component: __ProductInformation65; Installed: Null; Request: Local; Action: Local; Client State: NullMSI (s) (20:00) [18:01:45:847]: Component: __HeartbeatRegistry65; Installed: Null; Request: Local; Action: Local; Client State: NullMSI (s) (20:00) [18:01:45:847]: Component: __HeartbeatNativeRegistry65; Installed: Null; Request: Local; Action: Local; Client State: NullMSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: BindImage MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: ProgId MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: PublishComponent MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: SelfReg MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: Extension MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: Font MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: Shortcut MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: Class MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: TypeLib Action start 18:01:45: InstallValidate.MSI (s) (20:00) [18:01:45:847]: Note: 1: 2205 2: 3: _RemoveFilePath MSI (s) (20:00) [18:01:46:207]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: BindImage MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: ProgId MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: PublishComponent MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: SelfReg MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: Extension MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: Font MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: Shortcut MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: Class MSI (s) (20:00) [18:01:46:207]: Note: 1: 2205 2: 3: TypeLib MSI (s) (20:00) [18:01:46:207]: Note: 1: 2727 2: MSI (s) (20:00) [18:01:47:019]: Note: 1: 2727 2: MSI (s) (20:00) [18:01:47:019]: Doing action: RemoveExistingProductsMSI (s) (20:00) [18:01:47:019]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: InstallValidate. Return value 1.Action start 18:01:47: RemoveExistingProducts.MSI (s) (20:4C) [18:01:47:035]: Resetting cached policy valuesMSI (s) (20:4C) [18:01:47:035]: Machine policy value 'Debug' is 0MSI (s) (20:4C) [18:01:47:035]: ******* RunEngine: ******* Product: {4B1F9009-CD85-43C0-BCBD-D491908D5A52} ******* Action: ******* CommandLine: **********MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: SRSetRestorePoint skipped for this transaction.MSI (s) (20:4C) [18:01:47:035]: Creating MSIHANDLE (2) of type 790542 for thread 8012MSI (s) (20:4C) [18:01:47:035]: End dialog not enabledMSI (s) (20:4C) [18:01:47:035]: Original package ==> C:\WINDOWS\Installer\4978e5.msiMSI (s) (20:4C) [18:01:47:035]: Package we're running from ==> C:\WINDOWS\Installer\4978e5.msiMSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: Uninstall Flags override found.MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: Uninstall VersionNT override found.MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: Uninstall ServicePackLevel override found.MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: no matching ProductCode found in database.MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'DisablePatch' is 0MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'AllowLockdownPatch' is 0MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'DisableLUAPatching' is 0MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'DisableFlyWeightPatching' is 0MSI (s) (20:4C) [18:01:47:035]: Enabling baseline caching for this transaction since all active patches are MSI 3.0 style MSPs or at least one MSI 3.0 minor update patch is activeMSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: looking for appcompat database entry with ProductCode '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'.MSI (s) (20:4C) [18:01:47:035]: APPCOMPAT: no matching ProductCode found in database.MSI (s) (20:4C) [18:01:47:035]: Transforms are not secure.MSI (s) (20:4C) [18:01:47:035]: Note: 1: 2205 2: 3: Control MSI (s) (20:4C) [18:01:47:035]: Command Line: UPGRADINGPRODUCTCODE={2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA} CLIENTPROCESSID=1012 CLIENTUILEVEL=3 MSICLIENTUSESEXTERNALUI=1 REMOVE=ALL MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{0B95A4E2-4953-4CE7-B8F7-53BB197E234A}'.MSI (s) (20:4C) [18:01:47:035]: Product Code passed to Engine.Initialize: '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (s) (20:4C) [18:01:47:035]: Product Code from property table before transforms: '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (s) (20:4C) [18:01:47:035]: Product Code from property table after transforms: '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}'MSI (s) (20:4C) [18:01:47:035]: Product registered: entering maintenance modeMSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Determined that existing product (either this product or the product being upgraded with a patch) is installed per-machine.MSI (s) (20:4C) [18:01:47:035]: MSI_LUA: Nested installation UAC elevation tracks that of parent (is not elevated)MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is admin assigned: LocalSystem owns the publish key.MSI (s) (20:4C) [18:01:47:035]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is managed.MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: MSI_LUA: Credential prompt not required, user is an adminMSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding ProductState property. Its value is '5'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding ProductToBeRegistered property. Its value is '1'.MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Package name retrieved from configuration data: 'Sophos Network Threat Protection.msi'MSI (s) (20:4C) [18:01:47:035]: Note: 1: 2262 2: AdminProperties 3: -2147287038 MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'DisableMsi' is 0MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'AlwaysInstallElevated' is 0MSI (s) (20:4C) [18:01:47:035]: User policy value 'AlwaysInstallElevated' is 0MSI (s) (20:4C) [18:01:47:035]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:035]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is admin assigned: LocalSystem owns the publish key.MSI (s) (20:4C) [18:01:47:035]: Product {4B1F9009-CD85-43C0-BCBD-D491908D5A52} is managed.MSI (s) (20:4C) [18:01:47:035]: Running product '{4B1F9009-CD85-43C0-BCBD-D491908D5A52}' with elevated privileges: Product is assigned.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding UPGRADINGPRODUCTCODE property. Its value is '{2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '1012'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding MSICLIENTUSESEXTERNALUI property. Its value is '1'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding REMOVE property. Its value is 'ALL'.MSI (s) (20:4C) [18:01:47:035]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0MSI (s) (20:4C) [18:01:47:035]: RESTART MANAGER: Disabled by MSIRESTARTMANAGERCONTROL property; Windows Installer will use the built-in FilesInUse functionality.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.MSI (s) (20:4C) [18:01:47:035]: TRANSFORMS property is now: MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding PRODUCTLANGUAGE property. Its value is '1033'.MSI (s) (20:4C) [18:01:47:035]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '405'.MSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\RoamingMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\FavoritesMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network ShortcutsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DocumentsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer ShortcutsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\RecentMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendToMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\TemplatesMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramDataMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\LocalMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\PicturesMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\ProgramsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start MenuMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\Users\Public\DesktopMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start MenuMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\system32\config\systemprofile\DesktopMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\TemplatesMSI (s) (20:4C) [18:01:47:035]: SHELL32::SHGetFolderPath returned: C:\WINDOWS\FontsMSI (s) (20:4C) [18:01:47:035]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 MSI (s) (20:4C) [18:01:47:050]: MSI_LUA: Setting AdminUser property to 1 because the product is already installed managed and per-machineMSI (s) (20:4C) [18:01:47:050]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.MSI (s) (20:4C) [18:01:47:050]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:050]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'PBC-COM'.MSI (s) (20:4C) [18:01:47:050]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding COMPANYNAME property. Its value is 'COMPHX'.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding Installed property. Its value is '00:00:00'.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\WINDOWS\Installer\4978e5.msi'.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\WINDOWS\Installer\4978e5.msi'.MSI (s) (20:4C) [18:01:47:050]: Machine policy value 'MsiDisableEmbeddedUI' is 0MSI (s) (20:4C) [18:01:47:050]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UIMSI (s) (20:4C) [18:01:47:050]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic installMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:4C) [18:01:47:050]: Machine policy value 'DisableRollback' is 0MSI (s) (20:4C) [18:01:47:050]: User policy value 'DisableRollback' is 0MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.MSI (s) (20:4C) [18:01:47:050]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding Preselected property. Its value is '1'.MSI (s) (20:4C) [18:01:47:050]: APPCOMPAT: [DetectVersionLaunchCondition] Launch condition already passes.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.MSI (s) (20:4C) [18:01:47:050]: Doing action: INSTALLMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action start 18:01:47: INSTALL.MSI (s) (20:4C) [18:01:47:050]: Running ExecuteSequenceMSI (s) (20:4C) [18:01:47:050]: Doing action: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92CMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C property. Its value is 'C:\WINDOWS\system32\'.Action start 18:01:47: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C.MSI (s) (20:4C) [18:01:47:050]: Doing action: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FAMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C. Return value 1.MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA property. Its value is 'C:\WINDOWS\SysWOW64\'.Action start 18:01:47: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA.MSI (s) (20:4C) [18:01:47:050]: Doing action: FindRelatedProductsMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA. Return value 1.MSI (s) (20:4C) [18:01:47:050]: Skipping FindRelatedProducts action: not run in maintenance modeAction start 18:01:47: FindRelatedProducts.MSI (s) (20:4C) [18:01:47:050]: Doing action: AppSearchMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: FindRelatedProducts. Return value 0.Action start 18:01:47: AppSearch.MSI (s) (20:4C) [18:01:47:050]: Note: 1: 2262 2: Signature 3: -2147287038 MSI (s) (20:4C) [18:01:47:050]: PROPERTY CHANGE: Adding INSTALLTYPE_IS_CENTRAL property. Its value is '#1'.MSI (s) (20:4C) [18:01:47:050]: Doing action: LaunchConditionsMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: AppSearch. Return value 1.Action start 18:01:47: LaunchConditions.MSI (s) (20:4C) [18:01:47:050]: Doing action: ValidateProductIDMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: LaunchConditions. Return value 1.Action start 18:01:47: ValidateProductID.MSI (s) (20:4C) [18:01:47:050]: Skipping action: TamperProtectionCheckRemove (condition is false)MSI (s) (20:4C) [18:01:47:050]: Doing action: CostInitializeMSI (s) (20:4C) [18:01:47:050]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: ValidateProductID. Return value 1.MSI (s) (20:4C) [18:01:47:066]: Machine policy value 'MaxPatchCacheSize' is 10MSI (s) (20:4C) [18:01:47:066]: Baseline: Sorting baselines for {4B1F9009-CD85-43C0-BCBD-D491908D5A52}.MSI (s) (20:4C) [18:01:47:066]: Baseline: New baseline 1.9.2235 from transaction.MSI (s) (20:4C) [18:01:47:066]: Baseline: Sorted order Native: Order 0.MSI (s) (20:4C) [18:01:47:066]: Baseline Data Table:MSI (s) (20:4C) [18:01:47:066]: ProductCode: {4B1F9009-CD85-43C0-BCBD-D491908D5A52} Version: 1.9.2235 Attributes: 0 PatchId: Native BaselineId: -2147483648 Order: 0MSI (s) (20:4C) [18:01:47:066]: Baseline File Table:MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'C:\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Patch MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: MsiPatchHeaders MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: __MsiPatchFileList MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: PatchPackage MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2228 2: 3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId` MSI (s) (20:4C) [18:01:47:066]: Delta compression fallback method for this product transaction is 'MSI 2.0 legacy obsolescence'MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Patch Action start 18:01:47: CostInitialize.MSI (s) (20:4C) [18:01:47:066]: Doing action: FileCostMSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: CostInitialize. Return value 1.MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: MsiAssembly MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Class MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Extension MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: TypeLib Action start 18:01:47: FileCost.MSI (s) (20:4C) [18:01:47:066]: Doing action: CostFinalizeMSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: FileCost. Return value 1.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: MsiAssembly MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2228 2: 3: MsiAssembly 4: SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`, `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ? MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding INSTALLDIR property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding ProductData property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding Config property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding Status property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding Logs property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SnortData property. Its value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding HeartbeatData property. Its value is 'C:\ProgramData\Sophos\Heartbeat'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding HeartbeatConfig property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Config'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding HeartbeatLogs property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Logs'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding HeartbeatPersist property. Its value is 'C:\ProgramData\Sophos\Heartbeat\Persist'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'C:'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA property. Its current value is 'C:\WINDOWS\SysWOW64\'. Its new value: 'C:\Windows\SysWOW64'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C property. Its current value is 'C:\WINDOWS\system32\'. Its new value: 'C:\Windows\system32'.MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Patch MSI (s) (20:4C) [18:01:47:066]: Note: 1: 2205 2: 3: Condition MSI (s) (20:4C) [18:01:47:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:066]: Machine policy value 'DisableUserInstalls' is 0MSI (s) (20:4C) [18:01:47:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying TARGETDIR property. Its current value is 'C:'. Its new value: 'C:\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C property. Its current value is 'C:\Windows\system32'. Its new value: 'C:\Windows\system32\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA property. Its current value is 'C:\Windows\SysWOW64'. Its new value: 'C:\Windows\SysWOW64\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 property. Its value is 'C:\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SophosAppData property. Its value is 'C:\ProgramData\Sophos\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying HeartbeatData property. Its current value is 'C:\ProgramData\Sophos\Heartbeat'. Its new value: 'C:\ProgramData\Sophos\Heartbeat\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying HeartbeatPersist property. Its current value is 'C:\ProgramData\Sophos\Heartbeat\Persist'. Its new value: 'C:\ProgramData\Sophos\Heartbeat\Persist\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying HeartbeatLogs property. Its current value is 'C:\ProgramData\Sophos\Heartbeat\Logs'. Its new value: 'C:\ProgramData\Sophos\Heartbeat\Logs\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying HeartbeatConfig property. Its current value is 'C:\ProgramData\Sophos\Heartbeat\Config'. Its new value: 'C:\ProgramData\Sophos\Heartbeat\Config\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying ProductData property. Its current value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection'. Its new value: 'C:\ProgramData\Sophos\Sophos Network Threat Protection\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying SnortData property. Its current value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS'. Its new value: 'C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying Logs property. Its current value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs'. Its new value: 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying Config property. Its current value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config'. Its new value: 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying Status property. Its current value is 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status'. Its new value: 'C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding Sophos property. Its value is 'C:\Program Files\Sophos\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Modifying INSTALLDIR property. Its current value is 'C:\Program Files\Sophos\Sophos Network Threat Protection'. Its new value: 'C:\Program Files\Sophos\Sophos Network Threat Protection\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SnortConfDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SnortPreProcDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SnortDynModulesDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding plugins property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\'.MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding SophosNTPLWFDir property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\'.MSI (s) (20:4C) [18:01:47:066]: Target path resolution complete. Dumping Directory table...MSI (s) (20:4C) [18:01:47:066]: Note: target paths subject to change (via custom actions or browsing)MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: TARGETDIR , Object: C:\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: WindowsFolder , Object: C:\WINDOWS\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: System64Folder , Object: C:\WINDOWS\system32\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C , Object: C:\Windows\system32\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SystemFolder , Object: C:\WINDOWS\SysWOW64\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA , Object: C:\Windows\SysWOW64\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 , Object: C:\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: CommonAppDataFolder , Object: C:\ProgramData\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SophosAppData , Object: C:\ProgramData\Sophos\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: HeartbeatData , Object: C:\ProgramData\Sophos\Heartbeat\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: HeartbeatPersist , Object: C:\ProgramData\Sophos\Heartbeat\Persist\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: HeartbeatLogs , Object: C:\ProgramData\Sophos\Heartbeat\Logs\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: HeartbeatConfig , Object: C:\ProgramData\Sophos\Heartbeat\Config\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: ProductData , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SnortData , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: Logs , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: Config , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: Status , Object: C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: ProgramFiles64Folder , Object: C:\Program Files\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: Sophos , Object: C:\Program Files\Sophos\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: INSTALLDIR , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SnortConfDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SnortPreProcDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SnortDynModulesDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: plugins , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\MSI (s) (20:4C) [18:01:47:066]: Dir (target): Key: SophosNTPLWFDir , Object: C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\MSI (s) (20:4C) [18:01:47:066]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.MSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {14E8634F-8AEA-4CD1-AC48-BEBFDA18523A} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {14E8634F-8AEA-4CD1-AC48-BEBFDA18523A} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {570C624B-D57C-4CD1-9013-1B80C800093B} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {570C624B-D57C-4CD1-9013-1B80C800093B} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {E5B92048-5859-4AF1-AEAD-B97EBF00B087} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {E5B92048-5859-4AF1-AEAD-B97EBF00B087} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {63B83B20-1AB9-4F49-B0B2-4489724CA96C} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {74260D9F-D644-423B-B2D4-0291EA4BA8BE} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {0835C947-D6D2-4E52-AF14-0231D04E88EA} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1} since another client existsMSI (s) (20:4C) [18:01:47:066]: Disallowing uninstallation of component: {4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1} since another client existsAction start 18:01:47: CostFinalize.MSI (s) (20:4C) [18:01:47:082]: Doing action: MigrateFeatureStatesMSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: CostFinalize. Return value 1.MSI (s) (20:4C) [18:01:47:082]: Skipping MigrateFeatureStates action: not run in maintenance modeAction start 18:01:47: MigrateFeatureStates.MSI (s) (20:4C) [18:01:47:082]: Doing action: InstallValidateMSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:47: MigrateFeatureStates. Return value 0.MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: Dialog MSI (s) (20:4C) [18:01:47:082]: Feature: AllComponents; Installed: Local; Request: Absent; Action: AbsentMSI (s) (20:4C) [18:01:47:082]: Component: InstallationFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ProductDataFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ConfigDataFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: StatusFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: LogsDataFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: SnortDataFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatProductDataFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatConfigFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatLogsFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatPersistFolder; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: Driver; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: LWF; Installed: Local; Request: Absent; Action: Null; Client State: Not UsedMSI (s) (20:4C) [18:01:47:082]: Component: navl.dll; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: integrity.dat; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ProductInformation; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ServiceInstallWin8Plus; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ServiceInstallWin7Only; Installed: Local; Request: Absent; Action: Null; Client State: Not UsedMSI (s) (20:4C) [18:01:47:082]: Component: ServiceCommon; Installed: Local; Request: Absent; Action: Absent; Client State: AbsentMSI (s) (20:4C) [18:01:47:082]: Component: NTPAdapter; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: Heartbeat.dll; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatRegistry; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HeartbeatNativeRegistry; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: Heartbeat.xml; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: Notice.txt; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HealthApi; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: HbtAdapter; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: SspInterface; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: Telemetry.exe; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: TelemetryRegistry; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: RemoveObsoleteAutoUpdateRegistration; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: ScfDat; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: SofDat; Installed: Local; Request: Absent; Action: Absent; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_msvcr120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_msvcp120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_vccorlib120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_msvcr120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_msvcp120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: C_CENTRAL_vccorlib120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C; Installed: Local; Request: Absent; Action: Null; Client State: LocalMSI (s) (20:4C) [18:01:47:082]: Component: __ServiceCommon65; Installed: Null; Request: Absent; Action: Absent; Client State: NullMSI (s) (20:4C) [18:01:47:082]: Component: __TelemetryRegistry65; Installed: Null; Request: Absent; Action: Absent; Client State: NullMSI (s) (20:4C) [18:01:47:082]: Component: __ProductInformation65; Installed: Null; Request: Absent; Action: Absent; Client State: NullMSI (s) (20:4C) [18:01:47:082]: Component: __HeartbeatRegistry65; Installed: Null; Request: Absent; Action: Absent; Client State: NullMSI (s) (20:4C) [18:01:47:082]: Component: __HeartbeatNativeRegistry65; Installed: Null; Request: Absent; Action: Absent; Client State: NullMSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: BindImage MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: ProgId MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: PublishComponent MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: SelfReg MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: Extension MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: Font MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: Shortcut MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: Class MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: TypeLib Action start 18:01:47: InstallValidate.MSI (s) (20:4C) [18:01:47:082]: Note: 1: 2205 2: 3: _RemoveFilePath MSI (s) (20:4C) [18:01:47:410]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: BindImage MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: ProgId MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: PublishComponent MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: SelfReg MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: Extension MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: Font MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: Shortcut MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: Class MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2205 2: 3: TypeLib MSI (s) (20:4C) [18:01:47:410]: Note: 1: 2727 2: MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2727 2: MSI (s) (20:4C) [18:01:48:066]: Doing action: RemoveExistingProductsMSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: InstallValidate. Return value 1.MSI (s) (20:4C) [18:01:48:066]: Skipping RemoveExistingProducts action: current configuration is maintenance mode or an uninstallAction start 18:01:48: RemoveExistingProducts.MSI (s) (20:4C) [18:01:48:066]: Doing action: InstallInitializeMSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveExistingProducts. Return value 0.MSI (s) (20:4C) [18:01:48:066]: Machine policy value 'AlwaysInstallElevated' is 0MSI (s) (20:4C) [18:01:48:066]: User policy value 'AlwaysInstallElevated' is 0MSI (s) (20:4C) [18:01:48:066]: BeginTransaction: Locking ServerMSI (s) (20:4C) [18:01:48:066]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:4C) [18:01:48:066]: SRSetRestorePoint skipped for this transaction.MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2203 2: C:\WINDOWS\Installer\inprogressinstallinfo.ipi 3: -2147287038 MSI (s) (20:4C) [18:01:48:066]: Server not locked: locking for product {4B1F9009-CD85-43C0-BCBD-D491908D5A52}MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText Action start 18:01:48: InstallInitialize.MSI (s) (20:4C) [18:01:48:066]: PROPERTY CHANGE: Deleting ProductToBeRegistered property. Its current value is '1'.MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: Class MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2228 2: 3: Class 4: SELECT `CLSID` FROM `Class` WHERE `Icon_`=? AND `Class`.`Attributes`=1 MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: Shortcut MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2228 2: 3: Shortcut 4: SELECT `Component`,`Shortcut`,`Target` FROM `Component`,`Shortcut` WHERE `Component`=`Component_` AND `Icon_`=? AND (`Component`.`Installed` <> 0 AND `Component`.`Action` <> 0) MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: Class MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2228 2: 3: Class 4: SELECT `Component`,`CLSID` FROM `Component`,`Class` WHERE `Component`=`Component_` AND `Icon_`=? AND (`Component`.`Installed` <> 0 AND `Component`.`Action` <> 0) MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: Extension MSI (s) (20:4C) [18:01:48:066]: Note: 1: 2228 2: 3: Extension 4: SELECT `Component`,`Extension` FROM `Component`,`Extension`,`ProgId` WHERE `Component`.`Component`=`Extension`.`Component_` AND `ProgId`.`ProgId`=`Extension`.`ProgId_` AND `ProgId`.`Icon_`=? AND (`Component`.`Installed` <> 0 AND `Component`.`Action` <> 0) MSI (s) (20:4C) [18:01:48:066]: 'shield.ico' icon will be removed.MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:066]: Skipping action: CheckMaxNumFilters (condition is false)MSI (s) (20:4C) [18:01:48:066]: Doing action: ProcessComponentsMSI (s) (20:4C) [18:01:48:066]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: InstallInitialize. Return value 1.Action start 18:01:48: ProcessComponents.MSI (s) (20:4C) [18:01:48:081]: Doing action: UnpublishFeaturesMSI (s) (20:4C) [18:01:48:081]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: ProcessComponents. Return value 1.MSI (s) (20:4C) [18:01:48:081]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525Action start 18:01:48: UnpublishFeatures.MSI (s) (20:4C) [18:01:48:081]: Doing action: SchedSecureObjectsRollback_x64MSI (s) (20:4C) [18:01:48:081]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnpublishFeatures. Return value 1.MSI (s) (20:4C) [18:01:48:081]: Creating MSIHANDLE (3) of type 790542 for thread 8012MSI (s) (20:80) [18:01:48:081]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7A4C.tmp, Entrypoint: SchedSecureObjectsRollbackMSI (s) (20:78) [18:01:48:081]: Generating random cookie.MSI (s) (20:78) [18:01:48:081]: Created Custom Action Server with PID 7860 (0x1EB4).MSI (s) (20:20) [18:01:48:113]: Running as a service.MSI (s) (20:20) [18:01:48:128]: Hello, I'm your 64bit Elevated Non-remapped custom action server.MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (4) of type 790541 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (5) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (6) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (7) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (7) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (8) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (9) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (10) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (11) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (11) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (9) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (10) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (8) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:128]: PROPERTY CHANGE: Adding ExecSecureObjectsRollback_64 property. Its value is '**********'.MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (12) of type 790531 for thread 5044Action start 18:01:48: SchedSecureObjectsRollback_x64.MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (12) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Doing action: ExecSecureObjectsRollback_64MSI (s) (20!B4) [18:01:48:128]: Note: 1: 2205 2: 3: ActionText Action start 18:01:48: ExecSecureObjectsRollback_64.MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (6) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (13) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (14) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (14) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (15) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (16) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (17) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (18) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (18) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (16) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (17) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Closing MSIHANDLE (15) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:128]: Creating MSIHANDLE (19) of type 790531 for thread 5044Action ended 18:01:48: ExecSecureObjectsRollback_64. Return value 1.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (19) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Doing action: ExecSecureObjectsRollback_64MSI (s) (20!B4) [18:01:48:144]: Note: 1: 2205 2: 3: ActionText Action start 18:01:48: ExecSecureObjectsRollback_64.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (13) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (20) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (21) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (21) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (22) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (23) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (24) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (25) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (25) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (23) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (24) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (22) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (26) of type 790531 for thread 5044Action ended 18:01:48: ExecSecureObjectsRollback_64. Return value 1.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (26) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Doing action: ExecSecureObjectsRollback_64MSI (s) (20!B4) [18:01:48:144]: Note: 1: 2205 2: 3: ActionText Action start 18:01:48: ExecSecureObjectsRollback_64.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (20) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (27) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (28) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (28) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (29) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (30) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (31) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (32) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (32) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (30) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (31) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (29) of type 790540 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Creating MSIHANDLE (33) of type 790531 for thread 5044Action ended 18:01:48: ExecSecureObjectsRollback_64. Return value 1.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (33) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Doing action: ExecSecureObjectsRollback_64MSI (s) (20!B4) [18:01:48:144]: Note: 1: 2205 2: 3: ActionText Action start 18:01:48: ExecSecureObjectsRollback_64.MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (27) of type 790531 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (4) of type 790541 for thread 5044MSI (s) (20!B4) [18:01:48:144]: Closing MSIHANDLE (5) of type 790540 for thread 5044MSI (s) (20:80) [18:01:48:144]: Closing MSIHANDLE (3) of type 790542 for thread 8012Action ended 18:01:48: ExecSecureObjectsRollback_64. Return value 1.MSI (s) (20:4C) [18:01:48:144]: Doing action: SetUnregisterHbtManagementAdapterRollbackMSI (s) (20:4C) [18:01:48:144]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SchedSecureObjectsRollback_x64. Return value 1.MSI (s) (20:4C) [18:01:48:144]: PROPERTY CHANGE: Adding UnregisterHbtManagementAdapterRollback property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll'.Action start 18:01:48: SetUnregisterHbtManagementAdapterRollback.MSI (s) (20:4C) [18:01:48:144]: Doing action: UnregisterHbtManagementAdapterRollbackMSI (s) (20:4C) [18:01:48:144]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetUnregisterHbtManagementAdapterRollback. Return value 1.Action start 18:01:48: UnregisterHbtManagementAdapterRollback.MSI (s) (20:4C) [18:01:48:159]: Doing action: UnregisterHbtManagementAdapterMSI (s) (20:4C) [18:01:48:159]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterHbtManagementAdapterRollback. Return value 1.Action start 18:01:48: UnregisterHbtManagementAdapter.MSI (s) (20:4C) [18:01:48:175]: Doing action: SetUnregisterManagementAdapterRollbackMSI (s) (20:4C) [18:01:48:175]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterHbtManagementAdapter. Return value 1.MSI (s) (20:4C) [18:01:48:175]: PROPERTY CHANGE: Adding UnregisterManagementAdapterRollback property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll'.Action start 18:01:48: SetUnregisterManagementAdapterRollback.MSI (s) (20:4C) [18:01:48:175]: Doing action: UnregisterManagementAdapterRollbackMSI (s) (20:4C) [18:01:48:175]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetUnregisterManagementAdapterRollback. Return value 1.Action start 18:01:48: UnregisterManagementAdapterRollback.MSI (s) (20:4C) [18:01:48:175]: Doing action: UnregisterManagementAdapterMSI (s) (20:4C) [18:01:48:175]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterManagementAdapterRollback. Return value 1.Action start 18:01:48: UnregisterManagementAdapter.MSI (s) (20:4C) [18:01:48:191]: Doing action: StopServicesMSI (s) (20:4C) [18:01:48:191]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterManagementAdapter. Return value 1.Action start 18:01:48: StopServices.MSI (s) (20:4C) [18:01:48:191]: Doing action: UninstallSophosNTPLWF.PropertyMSI (s) (20:4C) [18:01:48:191]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: StopServices. Return value 1.MSI (s) (20:4C) [18:01:48:191]: PROPERTY CHANGE: Adding UninstallSophosNTPLWF property. Its value is '"C:\WINDOWS\system32\\netcfg.exe" /u SOPHOS_SOPHOSNTPLWF'.Action start 18:01:48: UninstallSophosNTPLWF.Property.MSI (s) (20:4C) [18:01:48:191]: Doing action: UninstallSophosNTPLWFMSI (s) (20:4C) [18:01:48:191]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UninstallSophosNTPLWF.Property. Return value 1.Action start 18:01:48: UninstallSophosNTPLWF.MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackRemoveTrustedPublisher.Property (condition is false)MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackRemoveTrustedPublisher (condition is false)MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackUninstallSophosNTPLWF.Property (condition is false)MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackUninstallSophosNTPLWF (condition is false)MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackAddTrustedPublisher.Property (condition is false)MSI (s) (20:4C) [18:01:48:191]: Skipping action: RollbackAddTrustedPublisher (condition is false)MSI (s) (20:4C) [18:01:48:191]: Doing action: CleanUpSsspUserAccount.SetPropertyMSI (s) (20:4C) [18:01:48:191]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UninstallSophosNTPLWF. Return value 1.MSI (s) (20:4C) [18:01:48:191]: PROPERTY CHANGE: Adding CleanUpSsspUserAccount property. Its value is 'NT SERVICE\sntpservice'.Action start 18:01:48: CleanUpSsspUserAccount.SetProperty.MSI (s) (20:4C) [18:01:48:191]: Doing action: CleanUpSsspUserAccountRollback.SetPropertyMSI (s) (20:4C) [18:01:48:191]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: CleanUpSsspUserAccount.SetProperty. Return value 1.MSI (s) (20:4C) [18:01:48:206]: PROPERTY CHANGE: Adding CleanUpSsspUserAccountRollback property. Its value is 'NT SERVICE\sntpservice'.Action start 18:01:48: CleanUpSsspUserAccountRollback.SetProperty.MSI (s) (20:4C) [18:01:48:206]: Doing action: CleanUpSsspUserAccountRollbackMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: CleanUpSsspUserAccountRollback.SetProperty. Return value 1.Action start 18:01:48: CleanUpSsspUserAccountRollback.MSI (s) (20:4C) [18:01:48:206]: Doing action: CleanUpSsspUserAccountMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: CleanUpSsspUserAccountRollback. Return value 1.Action start 18:01:48: CleanUpSsspUserAccount.MSI (s) (20:4C) [18:01:48:206]: Doing action: RemoveSIPSSubmitterUserAccount.SetPropertyMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: CleanUpSsspUserAccount. Return value 1.MSI (s) (20:4C) [18:01:48:206]: PROPERTY CHANGE: Adding RemoveSIPSSubmitterUserAccount property. Its value is 'NT SERVICE\SntpService'.Action start 18:01:48: RemoveSIPSSubmitterUserAccount.SetProperty.MSI (s) (20:4C) [18:01:48:206]: Doing action: RemoveSIPSSubmitterUserAccountRollback.SetPropertyMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveSIPSSubmitterUserAccount.SetProperty. Return value 1.MSI (s) (20:4C) [18:01:48:206]: PROPERTY CHANGE: Adding RemoveSIPSSubmitterUserAccountRollback property. Its value is 'NT SERVICE\SntpService'.Action start 18:01:48: RemoveSIPSSubmitterUserAccountRollback.SetProperty.MSI (s) (20:4C) [18:01:48:206]: Doing action: RemoveSIPSSubmitterUserAccountRollbackMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveSIPSSubmitterUserAccountRollback.SetProperty. Return value 1.Action start 18:01:48: RemoveSIPSSubmitterUserAccountRollback.MSI (s) (20:4C) [18:01:48:206]: Doing action: RemoveSIPSSubmitterUserAccountMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveSIPSSubmitterUserAccountRollback. Return value 1.Action start 18:01:48: RemoveSIPSSubmitterUserAccount.MSI (s) (20:4C) [18:01:48:206]: Doing action: SetUnregisterSntpEventManifestMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveSIPSSubmitterUserAccount. Return value 1.MSI (s) (20:4C) [18:01:48:206]: PROPERTY CHANGE: Adding UnregisterSntpEventManifest property. Its value is '"wevtutil.exe" um "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"'.Action start 18:01:48: SetUnregisterSntpEventManifest.MSI (s) (20:4C) [18:01:48:206]: Doing action: SetUnregisterSntpEventManifestRollbackMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetUnregisterSntpEventManifest. Return value 1.MSI (s) (20:4C) [18:01:48:206]: PROPERTY CHANGE: Adding UnregisterSntpEventManifestRollback property. Its value is '"wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"'.Action start 18:01:48: SetUnregisterSntpEventManifestRollback.MSI (s) (20:4C) [18:01:48:206]: Doing action: UnregisterSntpEventManifestRollbackMSI (s) (20:4C) [18:01:48:206]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetUnregisterSntpEventManifestRollback. Return value 1.Action start 18:01:48: UnregisterSntpEventManifestRollback.MSI (s) (20:4C) [18:01:48:222]: Doing action: UnregisterSntpEventManifestMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterSntpEventManifestRollback. Return value 1.Action start 18:01:48: UnregisterSntpEventManifest.MSI (s) (20:4C) [18:01:48:222]: Doing action: DeleteServicesMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: UnregisterSntpEventManifest. Return value 1.Action start 18:01:48: DeleteServices.MSI (s) (20:4C) [18:01:48:222]: Doing action: RemoveRegistryValuesMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: DeleteServices. Return value 1.Action start 18:01:48: RemoveRegistryValues.MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveLogFiles.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveLogFiles (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemovePolicyFile.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemovePolicyFile (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveStatusFile.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveStatusFile (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveReloadTrigger.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveReloadTrigger (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveIpsFiles.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: RemoveIpsFiles (condition is false)MSI (s) (20:4C) [18:01:48:222]: Doing action: RemoveFilesMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveRegistryValues. Return value 1.Action start 18:01:48: RemoveFiles.MSI (s) (20:4C) [18:01:48:222]: Doing action: RemoveFoldersMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveFiles. Return value 1.Action start 18:01:48: RemoveFolders.MSI (s) (20:4C) [18:01:48:222]: Doing action: CreateFoldersMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RemoveFolders. Return value 1.Action start 18:01:48: CreateFolders.MSI (s) (20:4C) [18:01:48:222]: Skipping action: FixupProductDataFiles.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: FixupProductDataFiles (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: FixupHeartbeatDataFiles.Property (condition is false)MSI (s) (20:4C) [18:01:48:222]: Skipping action: FixupHeartbeatDataFiles (condition is false)MSI (s) (20:4C) [18:01:48:222]: Doing action: InstallFilesMSI (s) (20:4C) [18:01:48:222]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: CreateFolders. Return value 1.MSI (s) (20:4C) [18:01:48:222]: The file represented by File table key 'Sntp.sys' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNTPLWF.sys' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'navl.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'integrity.dat' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNtpServiceExeWin8Plus' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNtpServiceExeWin7Only' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'NTPAdapter.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Heartbeat.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Heartbeat.xml' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Notice.txt' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'HealthApi.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'HbtAdapter.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'BPAIF.dll' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNtpTelemetry.exe' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'scf.dat' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'sof.dat' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Sntp.inf' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Sntp.cat' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'Sntp.man' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNTPLWF.inf' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'SophosNTPLWF.cat' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_msvcr120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_msvcp120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_vccorlib120_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_msvcr120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_msvcp120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: The file represented by File table key 'F_CENTRAL_vccorlib120_x64.05F0B5F5_44A8_3793_976B_A4F17AECF92C' has no eligible binary patchesMSI (s) (20:4C) [18:01:48:238]: Note: 1: 2205 2: 3: Patch MSI (s) (20:4C) [18:01:48:238]: Note: 1: 2228 2: 3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence` MSI (s) (20:4C) [18:01:48:238]: Note: 1: 2205 2: 3: MsiSFCBypass MSI (s) (20:4C) [18:01:48:238]: Note: 1: 2228 2: 3: MsiSFCBypass 4: SELECT `File_` FROM `MsiSFCBypass` WHERE `File_` = ? MSI (s) (20:4C) [18:01:48:238]: Note: 1: 2205 2: 3: MsiPatchHeaders MSI (s) (20:4C) [18:01:48:238]: Note: 1: 2228 2: 3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ? Action start 18:01:48: InstallFiles.MSI (s) (20:4C) [18:01:48:238]: Doing action: FixupDIFxAppRegistryMSI (s) (20:4C) [18:01:48:238]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: InstallFiles. Return value 1.MSI (s) (20:4C) [18:01:48:238]: Creating MSIHANDLE (34) of type 790542 for thread 8012MSI (s) (20:34) [18:01:48:238]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7AE9.tmp, Entrypoint: FixupDIFxAppRegistryMSI (s) (20!3C) [18:01:48:253]: Creating MSIHANDLE (35) of type 790541 for thread 9532MSI (s) (20!3C) [18:01:48:253]: Creating MSIHANDLE (36) of type 790531 for thread 9532Action start 18:01:48: FixupDIFxAppRegistry.MSI (s) (20!3C) [18:01:48:253]: Closing MSIHANDLE (36) of type 790531 for thread 9532MSI (s) (20!3C) [18:01:48:253]: Creating MSIHANDLE (37) of type 790531 for thread 9532FixupDIFxAppRegistry: FixupDIFxAppRegistry calledMSI (s) (20!3C) [18:01:48:253]: Closing MSIHANDLE (37) of type 790531 for thread 9532MSI (s) (20!3C) [18:01:48:253]: Creating MSIHANDLE (38) of type 790531 for thread 9532FixupDIFxAppRegistry: Failed to open registry key, err: 2, key: SOFTWARE\Microsoft\Windows\CurrentVersion\DIFxApp\Components\{76F354A6-97D5-4872-9781-2F2642A4F18A}MSI (s) (20!3C) [18:01:48:253]: Closing MSIHANDLE (38) of type 790531 for thread 9532MSI (s) (20!3C) [18:01:48:253]: Closing MSIHANDLE (35) of type 790541 for thread 9532MSI (s) (20:34) [18:01:48:253]: Closing MSIHANDLE (34) of type 790542 for thread 8012FixupDIFxAppRegistry: No registry key changes madeMSI (s) (20:4C) [18:01:48:253]: Doing action: MsiProcessDriversMSI (s) (20:4C) [18:01:48:253]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: FixupDIFxAppRegistry. Return value 1.MSI (s) (20:4C) [18:01:48:253]: Creating MSIHANDLE (39) of type 790542 for thread 8012MSI (s) (20:00) [18:01:48:253]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7AFA.tmp, Entrypoint: ProcessDriverPackagesMSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (40) of type 790531 for thread 9484Action start 18:01:48: MsiProcessDrivers.MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (40) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (41) of type 790541 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (42) of type 790540 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (43) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (44) of type 790531 for thread 9484DIFXAPP: ENTER: ProcessDriverPackages()MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (44) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (45) of type 790531 for thread 9484DIFXAPP: INFO: 'Component' is 'Driver'MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (45) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (46) of type 790541 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (47) of type 790540 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (48) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (48) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (47) of type 790540 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (46) of type 790541 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (49) of type 790531 for thread 9484DIFXAPP: INFO: Component state 0x3 -> 0x2MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (49) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (50) of type 790531 for thread 9484DIFXAPP: INFO: 'ComponentId' is {76F354A6-97D5-4872-9781-2F2642A4F18A}MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (50) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (51) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (52) of type 790531 for thread 9484DIFXAPP: INFO: 'Flags' is 21MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (52) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (53) of type 790531 for thread 9484DIFXAPP: INFO: component path is MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (53) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (54) of type 790531 for thread 9484DIFXAPP: INFO: user SID of user performing the install is 'S-1-5-18'.MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (54) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: PROPERTY CHANGE: Adding MsiUninstallDrivers property. Its value is '2.12{76F354A6-97D5-4872-9781-2F2642A4F18A}21Sophos Network Threat ProtectionSophos Limited'.MSI (s) (20!0C) [18:01:48:269]: Doing action: MsiUninstallDriversMSI (s) (20!0C) [18:01:48:269]: Note: 1: 2205 2: 3: ActionText DIFXAPP: INFO: creating HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\DIFxApp\Components\{76F354A6-97D5-4872-9781-2F2642A4F18A} (User's SID: 'S-1-5-18') ...Action start 18:01:48: MsiUninstallDrivers.MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (51) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (43) of type 790531 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (42) of type 790540 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (41) of type 790541 for thread 9484MSI (s) (20!0C) [18:01:48:269]: Creating MSIHANDLE (55) of type 790531 for thread 9484Action ended 18:01:48: MsiUninstallDrivers. Return value 1.MSI (s) (20!0C) [18:01:48:269]: Closing MSIHANDLE (55) of type 790531 for thread 9484MSI (s) (20:00) [18:01:48:269]: Closing MSIHANDLE (39) of type 790542 for thread 8012DIFXAPP: RETURN: ProcessDriverPackages() 0 (0x0)MSI (s) (20:4C) [18:01:48:269]: Doing action: SetRegisterSntpEventManifestRollbackMSI (s) (20:4C) [18:01:48:269]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: MsiProcessDrivers. Return value 1.MSI (s) (20:4C) [18:01:48:284]: PROPERTY CHANGE: Adding RegisterSntpEventManifestRollback property. Its value is '"wevtutil.exe" um "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"'.Action start 18:01:48: SetRegisterSntpEventManifestRollback.MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterSntpEventManifestRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: SetRegisterSntpEventManifestMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetRegisterSntpEventManifestRollback. Return value 1.MSI (s) (20:4C) [18:01:48:284]: PROPERTY CHANGE: Adding RegisterSntpEventManifest property. Its value is '"wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"'.Action start 18:01:48: SetRegisterSntpEventManifest.MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterSntpEventManifest (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: WriteRegistryValuesMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetRegisterSntpEventManifest. Return value 1.Action start 18:01:48: WriteRegistryValues.MSI (s) (20:4C) [18:01:48:284]: Doing action: InstallServicesMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: WriteRegistryValues. Return value 1.Action start 18:01:48: InstallServices.MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddSIPSSubmitterUserAccount.SetProperty (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddSIPSSubmitterUserAccountRollback.SetProperty (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddSIPSSubmitterUserAccountRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddSIPSSubmitterUserAccount (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SchedSecureObjects_x64 (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SchedServiceConfig (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SetupSspUserAccount.SetProperty (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SetupSspUserAccountRollback.SetProperty (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SetupSspUserAccountRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: SetupSspUserAccount (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: MsiConfigureServicesMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: InstallServices. Return value 1.Action start 18:01:48: MsiConfigureServices.MSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: MsiServiceConfigFailureActions MSI (s) (20:4C) [18:01:48:284]: Note: 1: 2228 2: 3: MsiServiceConfigFailureActions 4: SELECT `Name`, `Event`, `ResetPeriod`, `RebootMessage`,`Command`, `Actions`, `DelayActions`, `Action` FROM `MsiServiceConfigFailureActions`, `Component` WHERE `Component_` = `Component` AND (`Action` = 0 OR `Action` = 1 OR `Action` = 3) MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddTrustedPublisher.Property (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddTrustedPublisherRollback.Property (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddTrustedPublisherRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: AddTrustedPublisher (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: InstallSophosNTPLWF.Property (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: RollbackInstallSophosNTPLWF.Property (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: RollbackInstallSophosNTPLWF (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: InstallSophosNTPLWF (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: RemoveTrustedPublisher.Property (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: RemoveTrustedPublisher (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: StartServicesMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: MsiConfigureServices. Return value 1.Action start 18:01:48: StartServices.MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterHbtManagementAdapterRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: SetRegisterHbtManagementAdapterMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: StartServices. Return value 1.MSI (s) (20:4C) [18:01:48:284]: PROPERTY CHANGE: Adding RegisterHbtManagementAdapter property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll'.Action start 18:01:48: SetRegisterHbtManagementAdapter.MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterHbtManagementAdapter (condition is false)MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterManagementAdapterRollback (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: SetRegisterManagementAdapterMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetRegisterHbtManagementAdapter. Return value 1.MSI (s) (20:4C) [18:01:48:284]: PROPERTY CHANGE: Adding RegisterManagementAdapter property. Its value is 'C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll'.Action start 18:01:48: SetRegisterManagementAdapter.MSI (s) (20:4C) [18:01:48:284]: Skipping action: RegisterManagementAdapter (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: RegisterUserMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: SetRegisterManagementAdapter. Return value 1.Action start 18:01:48: RegisterUser.MSI (s) (20:4C) [18:01:48:284]: Doing action: RegisterProductMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RegisterUser. Return value 0.Action start 18:01:48: RegisterProduct.MSI (s) (20:4C) [18:01:48:284]: Doing action: PublishFeaturesMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: RegisterProduct. Return value 1.Action start 18:01:48: PublishFeatures.MSI (s) (20:4C) [18:01:48:284]: Doing action: PublishProductMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: PublishFeatures. Return value 1.MSI (s) (20:4C) [18:01:48:284]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:284]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525Action start 18:01:48: PublishProduct.MSI (s) (20:4C) [18:01:48:284]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:284]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:284]: Skipping action: WixFailWhenDeferred (condition is false)MSI (s) (20:4C) [18:01:48:284]: Doing action: InstallFinalizeMSI (s) (20:4C) [18:01:48:284]: Note: 1: 2205 2: 3: ActionText Action ended 18:01:48: PublishProduct. Return value 1.MSI (s) (20:4C) [18:01:48:284]: Running Script: C:\WINDOWS\Installer\MSI7A3B.tmpMSI (s) (20:4C) [18:01:48:284]: PROPERTY CHANGE: Adding UpdateStarted property. Its value is '1'.MSI (s) (20:4C) [18:01:48:300]: Note: 1: 2265 2: 3: -2147287035 MSI (s) (20:4C) [18:01:48:300]: Machine policy value 'DisableRollback' is 0MSI (s) (20:4C) [18:01:48:300]: Note: 1: 2318 2: MSI (s) (20:4C) [18:01:48:300]: Note: 1: 2318 2: MSI (s) (20:4C) [18:01:48:300]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2 MSI (s) (20:4C) [18:01:48:300]: Executing op: Header(Signature=1397708873,Version=500,Timestamp=1380880441,LangId=1033,Platform=589824,ScriptType=1,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)Action start 18:01:48: InstallFinalize.MSI (s) (20:4C) [18:01:48:300]: Executing op: ProductInfo(ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},ProductName=Sophos Network Threat Protection,PackageName=Sophos Network Threat Protection.msi,Language=1033,Version=17369275,Assignment=1,ObsoleteArg=0,ProductIcon=shield.ico,,PackageCode={0B95A4E2-4953-4CE7-B8F7-53BB197E234A},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)MSI (s) (20:4C) [18:01:48:300]: Executing op: DialogInfo(Type=0,Argument=1033)MSI (s) (20:4C) [18:01:48:300]: Executing op: DialogInfo(Type=1,Argument=Sophos Network Threat Protection)MSI (s) (20:4C) [18:01:48:300]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])MSI (s) (20:4C) [18:01:48:300]: Executing op: SetBaseline(Baseline=0,)MSI (s) (20:4C) [18:01:48:300]: Executing op: SetBaseline(Baseline=1,)MSI (s) (20:4C) [18:01:48:300]: Executing op: ActionStart(Name=InstallInitialize,,)MSI (s) (20:4C) [18:01:48:300]: Executing op: ProductUnregister(UpgradeCode={A6CF693D-C171-4DF5-AE49-223B66F65A1A})MSI (s) (20:4C) [18:01:48:300]: Note: 1: 1402 2: UNKNOWN\Products\9009F1B458DC0C34CBDB4D1909D8A525\Transforms 3: 2 MSI (s) (20:4C) [18:01:48:300]: Note: 1: 1402 2: UNKNOWN\Products\9009F1B458DC0C34CBDB4D1909D8A525\Transforms 3: 2 MSI (s) (20:4C) [18:01:48:300]: Scheduling file 'C:\WINDOWS\Installer\4978e5.msi' for deletion during post-install cleanup (not post-reboot).MSI (s) (20:4C) [18:01:48:316]: Note: 1: 1402 2: UNKNOWN\Products\9009F1B458DC0C34CBDB4D1909D8A525\Usage 3: 2 MSI (s) (20:4C) [18:01:48:316]: Executing op: ProductCPDisplayInfoUnregister()MSI (s) (20:4C) [18:01:48:316]: Executing op: ProductUnpublish(PackageKey={0B95A4E2-4953-4CE7-B8F7-53BB197E234A})MSI (s) (20:4C) [18:01:48:316]: Using cached product context: machine assigned for product: 9009F1B458DC0C34CBDB4D1909D8A525MSI (s) (20:4C) [18:01:48:316]: Executing op: UpgradeCodeUnpublish(UpgradeCode={A6CF693D-C171-4DF5-AE49-223B66F65A1A})MSI (s) (20:4C) [18:01:48:316]: Executing op: IconRemove(Icon=shield.ico,)MSI (s) (20:4C) [18:01:48:316]: Scheduling file 'C:\WINDOWS\Installer\{4B1F9009-CD85-43C0-BCBD-D491908D5A52}\shield.ico' for deletion during post-install cleanup (not post-reboot).MSI (s) (20:4C) [18:01:48:316]: Executing op: ProductUnpublishClient(,,)MSI (s) (20:4C) [18:01:48:316]: Note: 1: 1402 2: UNKNOWN\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525 3: 2 MSI (s) (20:4C) [18:01:48:316]: Executing op: SourceListUnpublish(,)MSI (s) (20:4C) [18:01:48:316]: Note: 1: 1402 2: UNKNOWN\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList 3: 2 MSI (s) (20:4C) [18:01:48:316]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)MSI (s) (20:4C) [18:01:48:316]: Executing op: ProgressTotal(Total=38,Type=1,ByteEquivalent=24000)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={07B90057-705F-44F2-8465-C2A4C77784E7},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={07B90057-705F-44F2-8465-C2A4C77784E7},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={E1E87C49-DD4A-4C77-8D42-3ACD20DBC536},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={E1E87C49-DD4A-4C77-8D42-3ACD20DBC536},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={4D81D62C-8373-45B8-ABF2-0C0D6ED2DE34},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={4D81D62C-8373-45B8-ABF2-0C0D6ED2DE34},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={74F91047-4C42-457F-B531-A83EF6EC85E2},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={74F91047-4C42-457F-B531-A83EF6EC85E2},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={F1B8B8D7-46D7-4CA9-B109-35931536EA8A},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={F1B8B8D7-46D7-4CA9-B109-35931536EA8A},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={270CF92A-C3C0-4385-B596-337555FE9560},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={270CF92A-C3C0-4385-B596-337555FE9560},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={8D83ACDA-6DCE-41F3-B5C1-7C01BD45026C},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={8D83ACDA-6DCE-41F3-B5C1-7C01BD45026C},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:316]: Executing op: UnregisterSharedComponentProvider(Component={14456086-9032-4E19-9F29-9F1F9DD21F4E},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:316]: Executing op: ComponentUnregister(ComponentId={14456086-9032-4E19-9F29-9F1F9DD21F4E},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={9DAD77F9-1B7B-4731-8A40-3EC32A42ACC7},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={9DAD77F9-1B7B-4731-8A40-3EC32A42ACC7},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={43CBB64E-B6FD-496B-8B4D-9D8842C8E5B2},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={43CBB64E-B6FD-496B-8B4D-9D8842C8E5B2},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={76F354A6-97D5-4872-9781-2F2642A4F18A},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={FC337C28-D909-4BF7-826A-F06F35C592F8},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={FC337C28-D909-4BF7-826A-F06F35C592F8},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={355DC0F9-A6B5-4FCA-8121-00847E59A436},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={355DC0F9-A6B5-4FCA-8121-00847E59A436},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={173F7C99-1A05-4365-B40A-D4EE897D94DE},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={173F7C99-1A05-4365-B40A-D4EE897D94DE},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={38879DEA-36FA-41BE-ACF3-B084CB40689B},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={38879DEA-36FA-41BE-ACF3-B084CB40689B},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={8E48EE2F-1444-46BF-BCD4-B5F66A4AFF10},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={8E48EE2F-1444-46BF-BCD4-B5F66A4AFF10},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={B7D2E43B-E8A6-4483-9BF7-5195F70225EF},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={B7D2E43B-E8A6-4483-9BF7-5195F70225EF},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={DF927ABB-6A5F-44F2-A430-137AAC79AA71},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={DF927ABB-6A5F-44F2-A430-137AAC79AA71},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={4E691ABE-115D-4721-9F9A-3547D17077C5},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={4E691ABE-115D-4721-9F9A-3547D17077C5},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={668853A5-00CE-412E-B21F-0721B6A8A0A9},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={668853A5-00CE-412E-B21F-0721B6A8A0A9},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={53CBCC30-891C-4EDC-9106-456F524A7547},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={53CBCC30-891C-4EDC-9106-456F524A7547},,BinaryType=0,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={B77F9317-494B-4351-897B-D7676F0A553D},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={B77F9317-494B-4351-897B-D7676F0A553D},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={D27928F9-1751-4CE1-817A-C94C9DDFA521},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={D27928F9-1751-4CE1-817A-C94C9DDFA521},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={1FCDB37D-595F-4837-919B-EC3B0753CEA3},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={1FCDB37D-595F-4837-919B-EC3B0753CEA3},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:331]: Executing op: UnregisterSharedComponentProvider(Component={BE16C094-CC09-4502-8856-ED495E915D2D},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:331]: Executing op: ComponentUnregister(ComponentId={BE16C094-CC09-4502-8856-ED495E915D2D},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={B9C8E32A-5EB9-4B7F-91AF-9FD883FB729C},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={B9C8E32A-5EB9-4B7F-91AF-9FD883FB729C},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={6EFE6551-BEDB-470F-9B98-4DD9D50BD010},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={6EFE6551-BEDB-470F-9B98-4DD9D50BD010},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={5FDACC4C-306D-434E-8DF0-F356318B9B39},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={5FDACC4C-306D-434E-8DF0-F356318B9B39},,BinaryType=0,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={1B63A9FF-509B-4CD9-BA54-256A7D62B724},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={1B63A9FF-509B-4CD9-BA54-256A7D62B724},,BinaryType=0,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={7C58F223-7247-466F-BFB7-7AFCF335E96D},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={7C58F223-7247-466F-BFB7-7AFCF335E96D},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={73F7BF07-5A6C-45CF-B42D-786698434BCA},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={73F7BF07-5A6C-45CF-B42D-786698434BCA},,BinaryType=1,)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={0835C947-D6D2-4E52-AF14-0231D04E88EA},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={0835C947-D6D2-4E52-AF14-0231D04E88EA},,BinaryType=0,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcr120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={74260D9F-D644-423B-B2D4-0291EA4BA8BE},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={74260D9F-D644-423B-B2D4-0291EA4BA8BE},,BinaryType=0,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcp120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={63B83B20-1AB9-4F49-B0B2-4489724CA96C},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={63B83B20-1AB9-4F49-B0B2-4489724CA96C},,BinaryType=0,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\vccorlib120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={E5B92048-5859-4AF1-AEAD-B97EBF00B087},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={E5B92048-5859-4AF1-AEAD-B97EBF00B087},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={570C624B-D57C-4CD1-9013-1B80C800093B},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={570C624B-D57C-4CD1-9013-1B80C800093B},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: Executing op: UnregisterSharedComponentProvider(Component={14E8634F-8AEA-4CD1-AC48-BEBFDA18523A},ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52})MSI (s) (20:4C) [18:01:48:347]: Executing op: ComponentUnregister(ComponentId={14E8634F-8AEA-4CD1-AC48-BEBFDA18523A},,BinaryType=1,PreviouslyPinned=1)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=0,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=1,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=1,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:01:48:347]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,,BinaryType=1,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: ProgressTick()MSI (s) (20:4C) [18:01:48:347]: Executing op: ActionStart(Name=UnpublishFeatures,Description=Unpublishing Product Features,Template=Feature: [1])MSI (s) (20:4C) [18:01:48:347]: Executing op: FeatureUnpublish(Feature=AllComponents,,Absent=2,Component=@p{P%*BW1=zd&z]$)mJsdaW[qjB%Y@U4ZzjvKD[5OsJv@s}cJ=1oT4'~aF~4CQXZM}~YD=K6f.8uiFmqd,Xcv8TA_@VbUBW=+!`T%nnV0vM_d9sEnaMsf]&GlD$QUD{d49sg^P!D(ceJiKkS)R0[+AZ!s1-[w=,A6.YbZ3{ss=JEohg_[p2i8w+l98ljZ?~=1vSw1@Rb4dZ7NP)4@?Ay3?02Rl`TRfq'zN,GK@vS'}KY[htxv%v05IXn_AO3,LR+RiW5?B,P*E21a9U[TiuMN_Upq)D26Y?%.9S)}_R4*WyYsY(gU,`eg=gKq@xBGEO(!Er)d%fi$=MA=~W3(2ru}Bhqp$+W1=1!z7OkB7ULd_*5ATP2r=0iFt=RAXOhfI)zHg2_y8x,@]-~5&T_DI6xBNcJEAusiiK'M1{=`Z{{cQL&_9mRpGI0qTe78f`d9~7Zy=A!C`^NHWEqA?u_ljl9e@6]gb@m*7n-F0p6-acr5?!O(=7Jl~_]RT$+fEcA3==X[i?MRDY2dmLeda@S=@3Gw]nbS$@ZL67bKoECp=)rPpn?oAJ(}f_mFWDe^9FoNyCexjS6Pt8m+6=Ld@rqk,J59'm.iy%{OBC6_=mqN0zSy_CKZL,?MY1.M==wExHp,N$jwf@_%sbe2Au(qh3f62HtpO'DMliL@9C'V[VqeV?fJ[7'H?Q~PAYa$-TR,SwJ+Skorl$F*@hZ~fPvko[S5W(}CCJ^c@h2e2Q1wj{6('3f)giZc@F=6^fRo9h6)MSI (s) (20:4C) [18:01:48:347]: Note: 1: 1402 2: UNKNOWN\Installer\Features\9009F1B458DC0C34CBDB4D1909D8A525 3: 2 MSI (s) (20:4C) [18:01:48:347]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:01:48:347]: Executing op: CustomActionSchedule(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:01:48:363]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:01:48:363]: Executing op: CustomActionSchedule(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:01:48:363]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:01:48:363]: Executing op: CustomActionSchedule(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:01:48:363]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:01:48:363]: Executing op: CustomActionSchedule(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:01:48:363]: Executing op: ActionStart(Name=UnregisterHbtManagementAdapterRollback,,)MSI (s) (20:4C) [18:01:48:363]: Executing op: CustomActionSchedule(Action=UnregisterHbtManagementAdapterRollback,ActionType=1345,Source=BinaryData,Target=RegisterHbtManagementAdapter,CustomActionData=C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll)MSI (s) (20:4C) [18:01:48:363]: Executing op: ActionStart(Name=UnregisterHbtManagementAdapter,,)MSI (s) (20:4C) [18:01:48:378]: Executing op: CustomActionSchedule(Action=UnregisterHbtManagementAdapter,ActionType=1089,Source=BinaryData,Target=UnregisterHbtManagementAdapter,)MSI (s) (20:4C) [18:01:48:378]: Creating MSIHANDLE (56) of type 790536 for thread 8012MSI (s) (20:CC) [18:01:48:378]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7B78.tmp, Entrypoint: UnregisterHbtManagementAdapterMSI (s) (20!30) [18:01:48:378]: Creating MSIHANDLE (57) of type 790531 for thread 9776MSI (s) (20!30) [18:01:48:394]: Closing MSIHANDLE (57) of type 790531 for thread 9776MSI (s) (20!30) [18:01:48:394]: Creating MSIHANDLE (58) of type 790531 for thread 9776UnregisterManagementAdapter: UnregisterManagementAdapter calledMSI (s) (20!30) [18:01:48:394]: Closing MSIHANDLE (58) of type 790531 for thread 9776MSI (s) (20!30) [18:01:48:394]: Creating MSIHANDLE (59) of type 790531 for thread 9776UnregisterManagementAdapter: Adapter = HBTMSI (s) (20!30) [18:01:48:394]: Closing MSIHANDLE (59) of type 790531 for thread 9776MSI (s) (20!30) [18:01:48:394]: Creating MSIHANDLE (60) of type 790531 for thread 9776UnregisterManagementAdapter: Management adapter successfully unregisteredMSI (s) (20!30) [18:01:48:394]: Closing MSIHANDLE (60) of type 790531 for thread 9776MSI (s) (20!30) [18:01:48:394]: Creating MSIHANDLE (61) of type 790531 for thread 9776UnregisterManagementAdapter: Waiting for adapter to be unloadedMSI (s) (20!30) [18:01:48:394]: Closing MSIHANDLE (61) of type 790531 for thread 9776MSI (s) (20!30) [18:02:48:403]: Creating MSIHANDLE (62) of type 790531 for thread 9776UnregisterManagementAdapter: Adapter path=C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dllMSI (s) (20!30) [18:02:48:403]: Closing MSIHANDLE (62) of type 790531 for thread 9776MSI (s) (20:CC) [18:02:48:403]: Closing MSIHANDLE (56) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:48:403]: Executing op: ActionStart(Name=UnregisterManagementAdapterRollback,,)UnregisterManagementAdapter: Failed to unload the adapter - continuing.MSI (s) (20:4C) [18:02:48:403]: Executing op: CustomActionSchedule(Action=UnregisterManagementAdapterRollback,ActionType=1345,Source=BinaryData,Target=RegisterManagementAdapter,CustomActionData=C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll)MSI (s) (20:4C) [18:02:48:403]: Executing op: ActionStart(Name=UnregisterManagementAdapter,,)MSI (s) (20:4C) [18:02:48:403]: Executing op: CustomActionSchedule(Action=UnregisterManagementAdapter,ActionType=1089,Source=BinaryData,Target=UnregisterManagementAdapter,)MSI (s) (20:4C) [18:02:48:418]: Creating MSIHANDLE (63) of type 790536 for thread 8012MSI (s) (20:80) [18:02:48:418]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI65E9.tmp, Entrypoint: UnregisterManagementAdapterMSI (s) (20!84) [18:02:48:418]: Creating MSIHANDLE (64) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:418]: Closing MSIHANDLE (64) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:418]: Creating MSIHANDLE (65) of type 790531 for thread 4740UnregisterManagementAdapter: UnregisterManagementAdapter calledMSI (s) (20!84) [18:02:48:418]: Closing MSIHANDLE (65) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:418]: Creating MSIHANDLE (66) of type 790531 for thread 4740UnregisterManagementAdapter: Adapter = NTPMSI (s) (20!84) [18:02:48:418]: Closing MSIHANDLE (66) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:418]: Creating MSIHANDLE (67) of type 790531 for thread 4740UnregisterManagementAdapter: Management adapter successfully unregisteredMSI (s) (20!84) [18:02:48:434]: Closing MSIHANDLE (67) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:434]: Creating MSIHANDLE (68) of type 790531 for thread 4740UnregisterManagementAdapter: Waiting for adapter to be unloadedMSI (s) (20!84) [18:02:48:434]: Closing MSIHANDLE (68) of type 790531 for thread 4740MSI (s) (20!84) [18:02:48:449]: Creating MSIHANDLE (69) of type 790531 for thread 4740UnregisterManagementAdapter: Adapter path=C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dllMSI (s) (20!84) [18:02:48:449]: Closing MSIHANDLE (69) of type 790531 for thread 4740MSI (s) (20:80) [18:02:48:449]: Closing MSIHANDLE (63) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:48:449]: Executing op: ActionStart(Name=StopServices,Description=Stopping services,Template=Service: [1])UnregisterManagementAdapter: Management adapter has been unloaded.MSI (s) (20:4C) [18:02:48:449]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=1300000)MSI (s) (20:4C) [18:02:48:449]: Executing op: ServiceControl(,Name=SntpService,Action=2,Wait=1,)MSI (s) (20:4C) [18:02:49:481]: Executing op: ActionStart(Name=UninstallSophosNTPLWF,,)MSI (s) (20:4C) [18:02:49:481]: Executing op: CustomActionSchedule(Action=UninstallSophosNTPLWF,ActionType=1089,Source=BinaryData,Target=WixQuietExec64,CustomActionData="C:\WINDOWS\system32\\netcfg.exe" /u SOPHOS_SOPHOSNTPLWF)MSI (s) (20:4C) [18:02:49:481]: Creating MSIHANDLE (70) of type 790536 for thread 8012MSI (s) (20:2C) [18:02:49:481]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI6A20.tmp, Entrypoint: WixQuietExec64MSI (s) (20:78) [18:02:49:481]: Generating random cookie.MSI (s) (20:78) [18:02:49:481]: Created Custom Action Server with PID 9668 (0x25C4).MSI (s) (20:20) [18:02:49:527]: Running as a service.MSI (s) (20:20) [18:02:49:527]: Hello, I'm your 32bit Elevated Non-remapped custom action server.MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (71) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (71) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (72) of type 790531 for thread 6252WixQuietExec64: Trying to uninstall SOPHOS_SOPHOSNTPLWF ...MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (72) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (73) of type 790531 for thread 6252WixQuietExec64:
MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (73) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (74) of type 790531 for thread 6252WixQuietExec64: ... SOPHOS_SOPHOSNTPLWF is not installed.MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (74) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (75) of type 790531 for thread 6252WixQuietExec64:
MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (75) of type 790531 for thread 6252MSI (s) (20!6C) [18:02:50:199]: Creating MSIHANDLE (76) of type 790531 for thread 6252WixQuietExec64: ... done.MSI (s) (20!6C) [18:02:50:199]: Closing MSIHANDLE (76) of type 790531 for thread 6252MSI (s) (20:2C) [18:02:50:199]: Closing MSIHANDLE (70) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:50:199]: Executing op: ActionStart(Name=CleanUpSsspUserAccountRollback,,)WixQuietExec64:
MSI (s) (20:4C) [18:02:50:199]: Executing op: CustomActionSchedule(Action=CleanUpSsspUserAccountRollback,ActionType=1281,Source=BinaryData,Target=SetupSspUserAccount,CustomActionData=NT SERVICE\sntpservice)MSI (s) (20:4C) [18:02:50:199]: Executing op: ActionStart(Name=CleanUpSsspUserAccount,,)MSI (s) (20:4C) [18:02:50:199]: Executing op: CustomActionSchedule(Action=CleanUpSsspUserAccount,ActionType=1025,Source=BinaryData,Target=CleanUpSsspUserAccount,CustomActionData=NT SERVICE\sntpservice)MSI (s) (20:4C) [18:02:50:199]: Creating MSIHANDLE (77) of type 790536 for thread 8012MSI (s) (20:10) [18:02:50:199]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI6CEF.tmp, Entrypoint: CleanUpSsspUserAccountMSI (s) (20!10) [18:02:50:214]: Creating MSIHANDLE (78) of type 790531 for thread 8464MSI (s) (20!10) [18:02:50:214]: Closing MSIHANDLE (78) of type 790531 for thread 8464MSI (s) (20:10) [18:02:50:214]: Closing MSIHANDLE (77) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:50:214]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccountRollback,,)CleanUpSsspUserAccount: Initialized.MSI (s) (20:4C) [18:02:50:214]: Executing op: CustomActionSchedule(Action=RemoveSIPSSubmitterUserAccountRollback,ActionType=1281,Source=BinaryData,Target=AddSIPSManagementUser,CustomActionData=NT SERVICE\SntpService)MSI (s) (20:4C) [18:02:50:214]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccount,,)MSI (s) (20:4C) [18:02:50:214]: Executing op: CustomActionSchedule(Action=RemoveSIPSSubmitterUserAccount,ActionType=1025,Source=BinaryData,Target=RemoveSIPSManagementUser,CustomActionData=NT SERVICE\SntpService)MSI (s) (20:4C) [18:02:50:214]: Creating MSIHANDLE (79) of type 790536 for thread 8012MSI (s) (20:74) [18:02:50:214]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI6D00.tmp, Entrypoint: RemoveSIPSManagementUserMSI (s) (20!1C) [18:02:50:214]: Creating MSIHANDLE (80) of type 790531 for thread 5404MSI (s) (20!1C) [18:02:50:214]: Closing MSIHANDLE (80) of type 790531 for thread 5404MSI (s) (20!1C) [18:02:50:230]: Creating MSIHANDLE (81) of type 790531 for thread 5404RemoveSIPSManagementUser Enter (290)MSI (s) (20!1C) [18:02:50:230]: Closing MSIHANDLE (81) of type 790531 for thread 5404MSI (s) (20:74) [18:02:50:230]: Closing MSIHANDLE (79) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:50:230]: Executing op: ActionStart(Name=UnregisterSntpEventManifestRollback,,)RemoveSIPSManagementUser Exit (338)MSI (s) (20:4C) [18:02:50:230]: Executing op: CustomActionSchedule(Action=UnregisterSntpEventManifestRollback,ActionType=3393,Source=BinaryData,Target=WixQuietExec,CustomActionData="wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man")MSI (s) (20:4C) [18:02:50:230]: Executing op: ActionStart(Name=UnregisterSntpEventManifest,,)MSI (s) (20:4C) [18:02:50:230]: Executing op: CustomActionSchedule(Action=UnregisterSntpEventManifest,ActionType=3137,Source=BinaryData,Target=WixQuietExec,CustomActionData="wevtutil.exe" um "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man")MSI (s) (20:4C) [18:02:50:230]: Creating MSIHANDLE (82) of type 790536 for thread 8012MSI (s) (20:AC) [18:02:50:230]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI6D11.tmp, Entrypoint: WixQuietExecMSI (s) (20:AC) [18:02:50:371]: Closing MSIHANDLE (82) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:50:371]: Executing op: ActionStart(Name=DeleteServices,Description=Deleting services,Template=Service: [1])MSI (s) (20:4C) [18:02:50:371]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=1300000)MSI (s) (20:4C) [18:02:50:371]: Executing op: ServiceControl(,Name=SntpService,Action=8,Wait=1,)MSI (s) (20:4C) [18:02:50:371]: Executing op: ActionStart(Name=RemoveRegistryValues,Description=Removing system registry values,Template=Key: [1], Name: [2])MSI (s) (20:4C) [18:02:50:371]: Executing op: ProgressTotal(Total=15,Type=1,ByteEquivalent=13200)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat\Status,,BinaryType=0,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat,,BinaryType=0,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Telemetry\Plugins\NTP,,BinaryType=0,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(Name=Path,Value=[INSTALLDIR]SophosNtpTelemetry.exe,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(Name=Cmd,Value=SophosNtpTelemetry.exe,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Application,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(Name=ProductCode,Value=[ProductCode],)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(Name=ProductVersion,Value=[ProductVersion],)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(Name=Path,Value=[INSTALLDIR],)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry\Heartbeat,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry\MTD,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: RegRemoveValue(,Value=service,)MSI (s) (20:4C) [18:02:50:371]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService 3: 2 MSI (s) (20:4C) [18:02:50:371]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat,,BinaryType=1,,)MSI (s) (20:4C) [18:02:50:371]: Executing op: ActionStart(Name=RemoveFiles,Description=Removing files,Template=File: [1], Directory: [9])MSI (s) (20:4C) [18:02:50:371]: Executing op: ProgressTotal(Total=16,Type=1,ByteEquivalent=175000)MSI (s) (20:4C) [18:02:50:371]: Executing op: SetTargetFolder(Folder=C:\Program Files\Sophos\Sophos Network Threat Protection\)MSI (s) (20:4C) [18:02:50:371]: Executing op: FileRemove(,FileName=Sntp.sys,,ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A})MSI (s) (20:4C) [18:02:50:371]: Verifying accessibility of file: Sntp.sysMSI (s) (20:4C) [18:02:50:386]: Executing op: FileRemove(,FileName=navl.dll,,ComponentId={355DC0F9-A6B5-4FCA-8121-00847E59A436})MSI (s) (20:4C) [18:02:50:386]: Verifying accessibility of file: navl.dllMSI (s) (20:4C) [18:02:50:589]: Executing op: FileRemove(,FileName=integrity.dat,,ComponentId={173F7C99-1A05-4365-B40A-D4EE897D94DE})MSI (s) (20:4C) [18:02:50:589]: Verifying accessibility of file: integrity.datMSI (s) (20:4C) [18:02:50:589]: Executing op: FileRemove(,FileName=SophosNtpService.exe,,ComponentId={8E48EE2F-1444-46BF-BCD4-B5F66A4AFF10})MSI (s) (20:4C) [18:02:50:605]: Verifying accessibility of file: SophosNtpService.exeMSI (s) (20:4C) [18:02:50:699]: Executing op: FileRemove(,FileName=NTPAdapter.dll,,ComponentId={4E691ABE-115D-4721-9F9A-3547D17077C5})MSI (s) (20:4C) [18:02:50:699]: Verifying accessibility of file: NTPAdapter.dllMSI (s) (20:4C) [18:02:50:714]: Executing op: FileRemove(,FileName=Heartbeat.dll,,ComponentId={668853A5-00CE-412E-B21F-0721B6A8A0A9})MSI (s) (20:4C) [18:02:50:730]: Verifying accessibility of file: Heartbeat.dllMSI (s) (20:4C) [18:02:50:839]: Executing op: FileRemove(,FileName=Notice.txt,,ComponentId={D27928F9-1751-4CE1-817A-C94C9DDFA521})MSI (s) (20:4C) [18:02:50:839]: Verifying accessibility of file: Notice.txtMSI (s) (20:4C) [18:02:50:839]: Executing op: FileRemove(,FileName=HealthApi.dll,,ComponentId={1FCDB37D-595F-4837-919B-EC3B0753CEA3})MSI (s) (20:4C) [18:02:50:855]: Verifying accessibility of file: HealthApi.dllMSI (s) (20:4C) [18:02:50:855]: Executing op: FileRemove(,FileName=HbtAdapter.dll,,ComponentId={BE16C094-CC09-4502-8856-ED495E915D2D})MSI (s) (20:4C) [18:02:50:855]: Verifying accessibility of file: HbtAdapter.dllMSI (s) (20:4C) [18:02:50:933]: Executing op: FileRemove(,FileName=BPAIF.dll,,ComponentId={B9C8E32A-5EB9-4B7F-91AF-9FD883FB729C})MSI (s) (20:4C) [18:02:50:933]: Verifying accessibility of file: BPAIF.dllMSI (s) (20:4C) [18:02:50:949]: Executing op: FileRemove(,FileName=SophosNtpTelemetry.exe,,ComponentId={6EFE6551-BEDB-470F-9B98-4DD9D50BD010})MSI (s) (20:4C) [18:02:50:949]: Verifying accessibility of file: SophosNtpTelemetry.exeMSI (s) (20:4C) [18:02:50:964]: Executing op: FileRemove(,FileName=scf.dat,,ComponentId={7C58F223-7247-466F-BFB7-7AFCF335E96D})MSI (s) (20:4C) [18:02:50:980]: Verifying accessibility of file: scf.datMSI (s) (20:4C) [18:02:50:980]: Executing op: FileRemove(,FileName=sof.dat,,ComponentId={73F7BF07-5A6C-45CF-B42D-786698434BCA})MSI (s) (20:4C) [18:02:50:980]: Verifying accessibility of file: sof.datMSI (s) (20:4C) [18:02:50:980]: Executing op: FileRemove(,FileName=Sntp.inf,,ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A})MSI (s) (20:4C) [18:02:50:980]: Verifying accessibility of file: Sntp.infMSI (s) (20:4C) [18:02:50:980]: Executing op: FileRemove(,FileName=Sntp.cat,,ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A})MSI (s) (20:4C) [18:02:50:980]: Verifying accessibility of file: Sntp.catMSI (s) (20:4C) [18:02:50:980]: Executing op: FileRemove(,FileName=Sntp.man,,ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A})MSI (s) (20:4C) [18:02:50:980]: Verifying accessibility of file: Sntp.manMSI (s) (20:4C) [18:02:50:996]: Executing op: ActionStart(Name=RemoveFolders,Description=Removing folders,Template=Folder: [1])MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\Program Files\Sophos\Sophos Network Threat Protection\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\Program Files\Sophos\Sophos Network Threat Protection\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Heartbeat\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Heartbeat\Config\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Heartbeat\Logs\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:50:996]: Executing op: FolderRemove(Folder=C:\ProgramData\Sophos\Heartbeat\Persist\,Foreign=0)MSI (s) (20:4C) [18:02:50:996]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:011]: Executing op: FolderRemove(Folder=C:\,Foreign=0)MSI (s) (20:4C) [18:02:51:011]: Executing op: ActionStart(Name=MsiUninstallDrivers,,)MSI (s) (20:4C) [18:02:51:011]: Executing op: CustomActionSchedule(Action=MsiUninstallDrivers,ActionType=3073,Source=BinaryData,Target=UninstallDriverPackages,CustomActionData=2.12{76F354A6-97D5-4872-9781-2F2642A4F18A}21Sophos Network Threat ProtectionSophos Limited)MSI (s) (20:4C) [18:02:51:011]: Creating MSIHANDLE (83) of type 790536 for thread 8012MSI (s) (20:8C) [18:02:51:011]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI701F.tmp, Entrypoint: UninstallDriverPackagesMSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (84) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (84) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (85) of type 790531 for thread 2632DIFXAPP: UninstallDriverPackages()MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (85) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (86) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'DIFxApp Version' is 2.1.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (86) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (87) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'UI Level' is 2.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (87) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (88) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'componentId' is {76F354A6-97D5-4872-9781-2F2642A4F18A}.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (88) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (89) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'flags' is 0x15.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (89) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (90) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'ProductName' is Sophos Network Threat Protection.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (90) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (91) of type 790531 for thread 2632DIFXAPP: 'CustomActionData' property 'ManufacturerName' is Sophos Limited.MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (91) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (92) of type 790531 for thread 2632DIFXAPP: ERROR 0x2 encountered while opening persistent-info key for component '{76F354A6-97D5-4872-9781-2F2642A4F18A}'MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (92) of type 790531 for thread 2632MSI (s) (20!48) [18:02:51:027]: Creating MSIHANDLE (93) of type 790531 for thread 2632DIFXAPP: UninstallDriverPackages failed with error 0x2MSI (s) (20!48) [18:02:51:027]: Closing MSIHANDLE (93) of type 790531 for thread 2632DIFXAPP: RETURN: UninstallDriverPackages() 2 (0x2)MSI (s) (20:8C) [18:02:51:027]: Closing MSIHANDLE (83) of type 790536 for thread 8012CustomAction MsiUninstallDrivers returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)MSI (s) (20:4C) [18:02:51:027]: Note: 1: 2265 2: 3: -2147287035 MSI (s) (20:4C) [18:02:51:027]: User policy value 'DisableRollback' is 0MSI (s) (20:4C) [18:02:51:027]: Machine policy value 'DisableRollback' is 0MSI (s) (20:4C) [18:02:51:027]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: Header(Signature=1397708873,Version=500,Timestamp=1380880441,LangId=1033,Platform=589824,ScriptType=2,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)MSI (s) (20:4C) [18:02:51:042]: Executing op: DialogInfo(Type=0,Argument=1033)MSI (s) (20:4C) [18:02:51:042]: Executing op: DialogInfo(Type=1,Argument=Sophos Network Threat Protection)MSI (s) (20:4C) [18:02:51:042]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70f8.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70f9.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70fa.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70fb.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70fc.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70fd.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70fe.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d70ff.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7100.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7101.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7102.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7103.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7104.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7105.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7106.rbf)MSI (s) (20:4C) [18:02:51:042]: Executing op: RegisterBackupFile(File=C:\Config.Msi\5e8d7107.rbf)Action ended 18:02:51: InstallFinalize. Return value 3.MSI (s) (20:4C) [18:02:51:042]: Executing op: ActionStart(Name=MsiUninstallDrivers,,)MSI (s) (20:4C) [18:02:51:042]: Executing op: ProductInfo(ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},ProductName=Sophos Network Threat Protection,PackageName=Sophos Network Threat Protection.msi,Language=1033,Version=17369275,Assignment=1,ObsoleteArg=0,ProductIcon=shield.ico,,PackageCode={0B95A4E2-4953-4CE7-B8F7-53BB197E234A},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)MSI (s) (20:4C) [18:02:51:042]: Executing op: ActionStart(Name=RemoveFolders,Description=Removing folders,Template=Folder: [1])MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Heartbeat\Persist\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Heartbeat\Logs\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Heartbeat\Config\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Heartbeat\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos Network Threat Protection\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\Program Files\Sophos\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:042]: Error in rollback skipped. Return: 3Info 1926.Could not set file security for file 'C:\Program Files\Sophos\'. Error: 0. Verify that you have sufficient privileges to modify the security permissions for this file.MSI (s) (20:4C) [18:02:51:042]: Executing op: FolderCreate(Folder=C:\Program Files\Sophos\Sophos Network Threat Protection\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:042]: Executing op: ActionStart(Name=RemoveFiles,Description=Removing files,Template=File: [1], Directory: [9])MSI (s) (20:4C) [18:02:51:042]: Executing op: SetTargetFolder(Folder=C:\Program Files\Sophos\Sophos Network Threat Protection\)MSI (s) (20:4C) [18:02:51:042]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7107.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man,Attributes=32800,FileSize=17080,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:042]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:042]: Verifying accessibility of file: 5e8d7107.rbfMSI (s) (20:4C) [18:02:51:058]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:058]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7106.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.cat,Attributes=32800,FileSize=19854,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:058]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.cat; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:058]: Verifying accessibility of file: 5e8d7106.rbfMSI (s) (20:4C) [18:02:51:058]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:058]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7105.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.inf,Attributes=32800,FileSize=1825,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:058]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.inf; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:058]: Verifying accessibility of file: 5e8d7105.rbfMSI (s) (20:4C) [18:02:51:058]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:058]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7104.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\sof.dat,Attributes=32800,FileSize=2916,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:058]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\sof.dat; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:058]: Verifying accessibility of file: 5e8d7104.rbfMSI (s) (20:4C) [18:02:51:058]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:058]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7103.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\scf.dat,Attributes=32800,FileSize=2884,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:058]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\scf.dat; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:058]: Verifying accessibility of file: 5e8d7103.rbfMSI (s) (20:4C) [18:02:51:058]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:058]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7102.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpTelemetry.exe,Attributes=32800,FileSize=454080,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:058]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpTelemetry.exe; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:058]: Verifying accessibility of file: 5e8d7102.rbfMSI (s) (20:4C) [18:02:51:089]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:089]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7101.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\BPAIF.dll,Attributes=32800,FileSize=312728,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:089]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\BPAIF.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:089]: Verifying accessibility of file: 5e8d7101.rbfMSI (s) (20:4C) [18:02:51:089]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:089]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d7100.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll,Attributes=32800,FileSize=2641728,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:089]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:089]: Verifying accessibility of file: 5e8d7100.rbfMSI (s) (20:4C) [18:02:51:121]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:121]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70ff.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\HealthApi.dll,Attributes=32800,FileSize=323088,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:121]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\HealthApi.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:121]: Verifying accessibility of file: 5e8d70ff.rbfMSI (s) (20:4C) [18:02:51:136]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:136]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70fe.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Notice.txt,Attributes=32800,FileSize=32245,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:136]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Notice.txt; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:136]: Verifying accessibility of file: 5e8d70fe.rbfMSI (s) (20:4C) [18:02:51:136]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:136]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70fd.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Heartbeat.dll,Attributes=32800,FileSize=6026256,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:136]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Heartbeat.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:136]: Verifying accessibility of file: 5e8d70fd.rbfMSI (s) (20:4C) [18:02:51:214]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:214]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70fc.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll,Attributes=32800,FileSize=1100816,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:214]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:214]: Verifying accessibility of file: 5e8d70fc.rbfMSI (s) (20:4C) [18:02:51:230]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:230]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70fb.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpService.exe,Attributes=32800,FileSize=4927592,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:230]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpService.exe; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:230]: Verifying accessibility of file: 5e8d70fb.rbfMSI (s) (20:4C) [18:02:51:277]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:277]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70fa.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\integrity.dat,Attributes=32800,FileSize=4086,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:277]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\integrity.dat; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:277]: Verifying accessibility of file: 5e8d70fa.rbfMSI (s) (20:4C) [18:02:51:292]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:292]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70f9.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\navl.dll,Attributes=32800,FileSize=10420880,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:292]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\navl.dll; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:292]: Verifying accessibility of file: 5e8d70f9.rbfMSI (s) (20:4C) [18:02:51:402]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:402]: Executing op: FileCopy(SourceName=C:\Config.Msi\5e8d70f8.rbf,,DestName=C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.sys,Attributes=32800,FileSize=227152,PerTick=0,,VerifyMedia=0,ElevateFlags=3,,,,,,,InstallMode=4194308,,,,,,,)MSI (s) (20:4C) [18:02:51:402]: File: C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.sys; To be installed; Won't patch; No existing fileMSI (s) (20:4C) [18:02:51:402]: Verifying accessibility of file: 5e8d70f8.rbfMSI (s) (20:4C) [18:02:51:402]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:51:402]: Executing op: ActionStart(Name=RemoveRegistryValues,Description=Removing system registry values,Template=Key: [1], Name: [2])MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService,,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:51:402]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService 3: 2 MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry\MTD,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Telemetry\Heartbeat,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Sophos Network Threat Protection\Application,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegAddValue(Name=Path,Value=C:\Program Files\Sophos\Sophos Network Threat Protection\,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegAddValue(Name=ProductVersion,Value=1.9.2235.0,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegAddValue(Name=ProductCode,Value={4B1F9009-CD85-43C0-BCBD-D491908D5A52},)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Telemetry\Plugins\NTP,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegAddValue(Name=Cmd,Value=SophosNtpTelemetry.exe,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegAddValue(Name=Path,Value=C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpTelemetry.exe,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\Heartbeat\Status,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:51:402]: Executing op: ActionStart(Name=DeleteServices,Description=Deleting services,Template=Service: [1])MSI (s) (20:4C) [18:02:51:402]: Executing op: ServiceInstall(Name=SntpService,DisplayName=Sophos Network Threat Protection,ImagePath="C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpService.exe",ServiceType=16,StartType=2,ErrorControl=1,,Dependencies=bfe[~]rpcss[~]sntp[~][~],TagId=0,StartName=NT AUTHORITY\LocalService,Password=**********,Description=Protects the computer against network-based threats.,SecurityDescriptor=BinaryData,)MSI (s) (20:4C) [18:02:51:417]: Executing op: ActionStart(Name=UnregisterSntpEventManifest,,)MSI (s) (20:4C) [18:02:51:417]: Executing op: ActionStart(Name=UnregisterSntpEventManifestRollback,,)MSI (s) (20:4C) [18:02:51:417]: Executing op: CustomActionRollback(Action=UnregisterSntpEventManifestRollback,ActionType=3393,Source=BinaryData,Target=WixQuietExec,CustomActionData="wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man")MSI (s) (20:4C) [18:02:51:417]: Creating MSIHANDLE (94) of type 790536 for thread 8012MSI (s) (20:9C) [18:02:51:417]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI71B6.tmp, Entrypoint: WixQuietExecMSI (s) (20:9C) [18:02:51:589]: Closing MSIHANDLE (94) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:51:589]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccount,,)MSI (s) (20:4C) [18:02:51:589]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccountRollback,,)MSI (s) (20:4C) [18:02:51:589]: Executing op: CustomActionRollback(Action=RemoveSIPSSubmitterUserAccountRollback,ActionType=1281,Source=BinaryData,Target=AddSIPSManagementUser,CustomActionData=NT SERVICE\SntpService)MSI (s) (20:4C) [18:02:51:605]: Creating MSIHANDLE (95) of type 790536 for thread 8012MSI (s) (20:DC) [18:02:51:605]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7263.tmp, Entrypoint: AddSIPSManagementUserMSI (s) (20!14) [18:02:51:605]: Creating MSIHANDLE (96) of type 790531 for thread 1044MSI (s) (20!14) [18:02:51:605]: Closing MSIHANDLE (96) of type 790531 for thread 1044MSI (s) (20!14) [18:02:51:605]: Creating MSIHANDLE (97) of type 790531 for thread 1044AddSIPSManagementUser Enter (234)MSI (s) (20!14) [18:02:51:605]: Closing MSIHANDLE (97) of type 790531 for thread 1044MSI (s) (20:DC) [18:02:51:605]: Closing MSIHANDLE (95) of type 790536 for thread 8012AddSIPSManagementUser Exit (283)MSI (s) (20:4C) [18:02:51:605]: Executing op: ActionStart(Name=CleanUpSsspUserAccount,,)MSI (s) (20:4C) [18:02:51:605]: Executing op: ActionStart(Name=CleanUpSsspUserAccountRollback,,)MSI (s) (20:4C) [18:02:51:605]: Executing op: CustomActionRollback(Action=CleanUpSsspUserAccountRollback,ActionType=1281,Source=BinaryData,Target=SetupSspUserAccount,CustomActionData=NT SERVICE\sntpservice)MSI (s) (20:4C) [18:02:51:605]: Creating MSIHANDLE (98) of type 790536 for thread 8012MSI (s) (20:44) [18:02:51:605]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7274.tmp, Entrypoint: SetupSspUserAccountMSI (s) (20!5C) [18:02:51:620]: Creating MSIHANDLE (99) of type 790531 for thread 6492MSI (s) (20!5C) [18:02:51:620]: Closing MSIHANDLE (99) of type 790531 for thread 6492MSI (s) (20!5C) [18:02:51:745]: Creating MSIHANDLE (100) of type 790531 for thread 6492SetupSspUserAccount: Initialized.MSI (s) (20!5C) [18:02:51:745]: Closing MSIHANDLE (100) of type 790531 for thread 6492MSI (s) (20!5C) [18:02:51:745]: Creating MSIHANDLE (101) of type 790531 for thread 6492SetupSspUserAccount: OLDUSERGROUP does not exist - not adding permissionsMSI (s) (20!5C) [18:02:51:745]: Closing MSIHANDLE (101) of type 790531 for thread 6492MSI (s) (20:44) [18:02:51:761]: Closing MSIHANDLE (98) of type 790536 for thread 8012SetupSspUserAccount: Granting permissions to user "NT SERVICE\sntpservice"MSI (s) (20:4C) [18:02:51:761]: Executing op: ActionStart(Name=UninstallSophosNTPLWF,,)MSI (s) (20:4C) [18:02:51:761]: Executing op: ActionStart(Name=StopServices,Description=Stopping services,Template=Service: [1])MSI (s) (20:4C) [18:02:51:761]: Executing op: ServiceControl(,Name=SntpService,Action=1,Wait=1,)MSI (s) (20:4C) [18:02:52:839]: Executing op: ActionStart(Name=UnregisterManagementAdapter,,)MSI (s) (20:4C) [18:02:52:839]: Executing op: ActionStart(Name=UnregisterManagementAdapterRollback,,)MSI (s) (20:4C) [18:02:52:839]: Executing op: CustomActionRollback(Action=UnregisterManagementAdapterRollback,ActionType=1345,Source=BinaryData,Target=RegisterManagementAdapter,CustomActionData=C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll)MSI (s) (20:4C) [18:02:52:839]: Creating MSIHANDLE (102) of type 790536 for thread 8012MSI (s) (20:84) [18:02:52:839]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7747.tmp, Entrypoint: RegisterManagementAdapterMSI (s) (20!68) [18:02:52:855]: Creating MSIHANDLE (103) of type 790531 for thread 9576MSI (s) (20!68) [18:02:52:855]: Closing MSIHANDLE (103) of type 790531 for thread 9576MSI (s) (20!68) [18:02:52:855]: Creating MSIHANDLE (104) of type 790531 for thread 9576RegisterManagementAdapter: RegisterManagementAdapter calledMSI (s) (20!68) [18:02:52:855]: Closing MSIHANDLE (104) of type 790531 for thread 9576MSI (s) (20!68) [18:02:52:855]: Creating MSIHANDLE (105) of type 790531 for thread 9576RegisterManagementAdapter: Adapter = NTP: C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dllMSI (s) (20!68) [18:02:52:855]: Closing MSIHANDLE (105) of type 790531 for thread 9576MSI (s) (20:84) [18:02:52:855]: Closing MSIHANDLE (102) of type 790536 for thread 8012RegisterManagementAdapter: Management adapter successfully registeredMSI (s) (20:4C) [18:02:52:855]: Executing op: ActionStart(Name=UnregisterHbtManagementAdapter,,)MSI (s) (20:4C) [18:02:52:855]: Executing op: ActionStart(Name=UnregisterHbtManagementAdapterRollback,,)MSI (s) (20:4C) [18:02:52:855]: Executing op: CustomActionRollback(Action=UnregisterHbtManagementAdapterRollback,ActionType=1345,Source=BinaryData,Target=RegisterHbtManagementAdapter,CustomActionData=C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll)MSI (s) (20:4C) [18:02:52:855]: Creating MSIHANDLE (106) of type 790536 for thread 8012MSI (s) (20:24) [18:02:52:855]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7758.tmp, Entrypoint: RegisterHbtManagementAdapterMSI (s) (20!88) [18:02:52:870]: Creating MSIHANDLE (107) of type 790531 for thread 9864MSI (s) (20!88) [18:02:52:870]: Closing MSIHANDLE (107) of type 790531 for thread 9864MSI (s) (20!88) [18:02:52:870]: Creating MSIHANDLE (108) of type 790531 for thread 9864RegisterManagementAdapter: RegisterManagementAdapter calledMSI (s) (20!88) [18:02:52:870]: Closing MSIHANDLE (108) of type 790531 for thread 9864MSI (s) (20!88) [18:02:52:870]: Creating MSIHANDLE (109) of type 790531 for thread 9864RegisterManagementAdapter: Adapter = HBT: C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dllMSI (s) (20!88) [18:02:52:870]: Closing MSIHANDLE (109) of type 790531 for thread 9864MSI (s) (20:24) [18:02:52:870]: Closing MSIHANDLE (106) of type 790536 for thread 8012RegisterManagementAdapter: Management adapter successfully registeredMSI (s) (20:4C) [18:02:52:870]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:02:52:870]: Executing op: CustomActionRollback(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:02:52:870]: Creating MSIHANDLE (110) of type 790536 for thread 8012MSI (s) (20:C4) [18:02:52:886]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7768.tmp, Entrypoint: ExecSecureObjectsRollbackMSI (s) (20:C4) [18:02:52:886]: Closing MSIHANDLE (110) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:52:886]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:02:52:886]: Executing op: CustomActionRollback(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:02:52:886]: Creating MSIHANDLE (111) of type 790536 for thread 8012MSI (s) (20:18) [18:02:52:886]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI7779.tmp, Entrypoint: ExecSecureObjectsRollbackMSI (s) (20:18) [18:02:52:901]: Closing MSIHANDLE (111) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:52:901]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:02:52:901]: Executing op: CustomActionRollback(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:02:52:901]: Creating MSIHANDLE (112) of type 790536 for thread 8012MSI (s) (20:04) [18:02:52:901]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI778A.tmp, Entrypoint: ExecSecureObjectsRollbackMSI (s) (20:04) [18:02:52:917]: Closing MSIHANDLE (112) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:52:917]: Executing op: ActionStart(Name=ExecSecureObjectsRollback_64,,)MSI (s) (20:4C) [18:02:52:917]: Executing op: CustomActionRollback(Action=ExecSecureObjectsRollback_64,ActionType=11521,Source=BinaryData,Target=**********,CustomActionData=**********)MSI (s) (20:4C) [18:02:52:917]: Creating MSIHANDLE (113) of type 790536 for thread 8012MSI (s) (20:1C) [18:02:52:917]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI779A.tmp, Entrypoint: ExecSecureObjectsRollbackMSI (s) (20:1C) [18:02:52:933]: Closing MSIHANDLE (113) of type 790536 for thread 8012MSI (s) (20:4C) [18:02:52:933]: Executing op: ActionStart(Name=UnpublishFeatures,Description=Unpublishing Product Features,Template=Feature: [1])MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Features,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegAddValue(Name=AllComponents,Value=@p{P%*BW1=zd&z]$)mJsdaW[qjB%Y@U4ZzjvKD[5OsJv@s}cJ=1oT4'~aF~4CQXZM}~YD=K6f.8uiFmqd,Xcv8TA_@VbUBW=+!`T%nnV0vM_d9sEnaMsf]&GlD$QUD{d49sg^P!D(ceJiKkS)R0[+AZ!s1-[w=,A6.YbZ3{ss=JEohg_[p2i8w+l98ljZ?~=1vSw1@Rb4dZ7NP)4@?Ay3?02Rl`TRfq'zN,GK@vS'}KY[htxv%v05IXn_AO3,LR+RiW5?B,P*E21a9U[TiuMN_Upq)D26Y?%.9S)}_R4*WyYsY(gU,`eg=gKq@xBGEO(!Er)d%fi$=MA=~W3(2ru}Bhqp$+W1=1!z7OkB7ULd_*5ATP2r=0iFt=RAXOhfI)zHg2_y8x,@]-~5&T_DI6xBNcJEAusiiK'M1{=`Z{{cQL&_9mRpGI0qTe78f`d9~7Zy=A!C`^NHWEqA?u_ljl9e@6]gb@m*7n-F0p6-acr5?!O(=7Jl~_]RT$+fEcA3==X[i?MRDY2dmLeda@S=@3Gw]nbS$@ZL67bKoECp=)rPpn?oAJ(}f_mFWDe^9FoNyCexjS6Pt8m+6=Ld@rqk,J59'm.iy%{OBC6_=mqN0zSy_CKZL,?MY1.M==wExHp,N$jwf@_%sbe2Au(qh3f62HtpO'DMliL@9C'V[VqeV?fJ[7'H?Q~PAYa$-TR,SwJ+Skorl$F*@hZ~fPvko[S5W(}CCJ^c@h2e2Q1wj{6('3f)giZc@F=6^fRo9h6,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\9009F1B458DC0C34CBDB4D1909D8A525,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:52:933]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\9009F1B458DC0C34CBDB4D1909D8A525 3: 2 MSI (s) (20:4C) [18:02:52:933]: Executing op: ActionStart(Name=ProcessComponents,Description=Updating component registration,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: RegOpenKey(Root=-2147483646,Key=SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: ComponentRegister(ComponentId={14E8634F-8AEA-4CD1-AC48-BEBFDA18523A},KeyPath=C:\Windows\system32\vccorlib120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=1)MSI (s) (20:4C) [18:02:52:933]: Executing op: ComponentRegister(ComponentId={570C624B-D57C-4CD1-9013-1B80C800093B},KeyPath=C:\Windows\system32\msvcp120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=1)MSI (s) (20:4C) [18:02:52:933]: Executing op: ComponentRegister(ComponentId={E5B92048-5859-4AF1-AEAD-B97EBF00B087},KeyPath=C:\Windows\system32\msvcr120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=1)MSI (s) (20:4C) [18:02:52:933]: Executing op: ComponentRegister(ComponentId={63B83B20-1AB9-4F49-B0B2-4489724CA96C},KeyPath=C:\Windows\SysWOW64\vccorlib120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=0)MSI (s) (20:4C) [18:02:52:933]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\vccorlib120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:933]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\vccorlib120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:933]: Executing op: RegisterSharedComponentProvider(,,,Component={63B83B20-1AB9-4F49-B0B2-4489724CA96C},,ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,,,,,)MSI (s) (20:4C) [18:02:52:933]: Executing op: ComponentRegister(ComponentId={74260D9F-D644-423B-B2D4-0291EA4BA8BE},KeyPath=C:\Windows\SysWOW64\msvcp120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=0)MSI (s) (20:4C) [18:02:52:933]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcp120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:933]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcp120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:933]: Executing op: RegisterSharedComponentProvider(,,,Component={74260D9F-D644-423B-B2D4-0291EA4BA8BE},,ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,,,,,)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={0835C947-D6D2-4E52-AF14-0231D04E88EA},KeyPath=C:\Windows\SysWOW64\msvcr120.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=0)MSI (s) (20:4C) [18:02:52:948]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcr120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:948]: WIN64DUALFOLDERS: 'C:\WINDOWS\system32\' will substitute 20 characters in 'C:\Windows\SysWOW64\msvcr120.dll' folder path. (mask argument = 1, the folder pair's iSwapAttrib member = 1).MSI (s) (20:4C) [18:02:52:948]: Executing op: RegisterSharedComponentProvider(,,,Component={0835C947-D6D2-4E52-AF14-0231D04E88EA},,ProductCode={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,,,,,)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={73F7BF07-5A6C-45CF-B42D-786698434BCA},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\sof.dat,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={7C58F223-7247-466F-BFB7-7AFCF335E96D},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\scf.dat,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={1B63A9FF-509B-4CD9-BA54-256A7D62B724},KeyPath=C:\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=0)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={5FDACC4C-306D-434E-8DF0-F356318B9B39},KeyPath=02:\Software\Sophos\Telemetry\Plugins\NTP\Path,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=0)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={6EFE6551-BEDB-470F-9B98-4DD9D50BD010},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpTelemetry.exe,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={B9C8E32A-5EB9-4B7F-91AF-9FD883FB729C},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\BPAIF.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={BE16C094-CC09-4502-8856-ED495E915D2D},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={1FCDB37D-595F-4837-919B-EC3B0753CEA3},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\HealthApi.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={D27928F9-1751-4CE1-817A-C94C9DDFA521},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\Notice.txt,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={4385E7B8-9B0B-4766-ACD7-EDA6DE4B1AE1},KeyPath=C:\ProgramData\Sophos\Heartbeat\Config\Heartbeat.xml,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={B77F9317-494B-4351-897B-D7676F0A553D},KeyPath=C:\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={53CBCC30-891C-4EDC-9106-456F524A7547},KeyPath=C:\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=0)MSI (s) (20:4C) [18:02:52:948]: Executing op: ComponentRegister(ComponentId={668853A5-00CE-412E-B21F-0721B6A8A0A9},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\Heartbeat.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={4E691ABE-115D-4721-9F9A-3547D17077C5},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={DF927ABB-6A5F-44F2-A430-137AAC79AA71},KeyPath=22:\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={B7D2E43B-E8A6-4483-9BF7-5195F70225EF},,State=-7,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={8E48EE2F-1444-46BF-BCD4-B5F66A4AFF10},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNtpService.exe,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={38879DEA-36FA-41BE-ACF3-B084CB40689B},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={173F7C99-1A05-4365-B40A-D4EE897D94DE},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\integrity.dat,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={355DC0F9-A6B5-4FCA-8121-00847E59A436},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\navl.dll,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=1,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={FC337C28-D909-4BF7-826A-F06F35C592F8},,State=-7,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={76F354A6-97D5-4872-9781-2F2642A4F18A},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.sys,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={43CBB64E-B6FD-496B-8B4D-9D8842C8E5B2},KeyPath=C:\ProgramData\Sophos\Heartbeat\Persist\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={9DAD77F9-1B7B-4731-8A40-3EC32A42ACC7},KeyPath=C:\ProgramData\Sophos\Heartbeat\Logs\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={14456086-9032-4E19-9F29-9F1F9DD21F4E},KeyPath=C:\ProgramData\Sophos\Heartbeat\Config\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={8D83ACDA-6DCE-41F3-B5C1-7C01BD45026C},KeyPath=C:\ProgramData\Sophos\Heartbeat\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={270CF92A-C3C0-4385-B596-337555FE9560},KeyPath=C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={F1B8B8D7-46D7-4CA9-B109-35931536EA8A},KeyPath=C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={74F91047-4C42-457F-B531-A83EF6EC85E2},KeyPath=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:964]: Executing op: ComponentRegister(ComponentId={4D81D62C-8373-45B8-ABF2-0C0D6ED2DE34},KeyPath=C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:979]: Executing op: ComponentRegister(ComponentId={E1E87C49-DD4A-4C77-8D42-3ACD20DBC536},KeyPath=C:\ProgramData\Sophos\Sophos Network Threat Protection\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:979]: Executing op: ComponentRegister(ComponentId={07B90057-705F-44F2-8465-C2A4C77784E7},KeyPath=C:\Program Files\Sophos\Sophos Network Threat Protection\,State=3,ProductKey={4B1F9009-CD85-43C0-BCBD-D491908D5A52},,SharedDllRefCount=0,BinaryType=1)MSI (s) (20:4C) [18:02:52:979]: Executing op: ActionStart(Name=InstallInitialize,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:52:979]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList 3: 2 MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:52:979]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525 3: 2 MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegRemoveValue(Name=C:\WINDOWS\Installer\{4B1F9009-CD85-43C0-BCBD-D491908D5A52}\shield.ico,Value=#1,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\UpgradeCodes\D396FC6A171C5FD4EA9422B3666FA5A1,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=9009F1B458DC0C34CBDB4D1909D8A525,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\9009F1B458DC0C34CBDB4D1909D8A525,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=AllComponents,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\9009F1B458DC0C34CBDB4D1909D8A525,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=AdvertiseFlags,Value=#388,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=Assignment,Value=#1,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=AuthorizedLUAApp,Value=#0,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=Clients,Value=[~]:[~],)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=DeploymentFlags,Value=#3,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=InstanceType,Value=#0,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=Language,Value=#1033,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=PackageCode,Value=2E4A59B035947EC48B7F35BB91E732A4,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=ProductIcon,Value=C:\WINDOWS\Installer\{4B1F9009-CD85-43C0-BCBD-D491908D5A52}\shield.ico,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=ProductName,Value=Sophos Network Threat Protection,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=Version,Value=#17369275,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:979]: Executing op: RegAddValue(Name=LastUsedSource,Value=#%n;1;C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=PackageName,Value=Sophos Network Threat Protection.msi,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList\Net,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=1,Value=#%C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525\SourceList\Media,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=1,Value=;,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Products\9009F1B458DC0C34CBDB4D1909D8A525,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B1F9009-CD85-43C0-BCBD-D491908D5A52},SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=DisplayName,Value=Sophos Network Threat Protection,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\InstallProperties,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=DisplayName,Value=Sophos Network Threat Protection,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\InstallProperties,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Usage,,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:52:995]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Usage 3: 2 MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Usage,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\D396FC6A171C5FD4EA9422B3666FA5A1,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=9009F1B458DC0C34CBDB4D1909D8A525,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B1F9009-CD85-43C0-BCBD-D491908D5A52},SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=Language,Value=#1033,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=Version,Value=#17369275,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=WindowsInstaller,Value=#1,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=VersionMinor,Value=#9,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=VersionMajor,Value=#1,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=URLUpdateInfo,Value=www.sophos.com/.../updates,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=URLInfoAbout,Value=http://www.sophos.com/,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=UninstallString,Value=#%MsiExec.exe /X{4B1F9009-CD85-43C0-BCBD-D491908D5A52},)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=SystemComponent,Value=#1,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=EstimatedSize,Value=#29481,)MSI (s) (20:4C) [18:02:52:995]: Executing op: RegAddValue(Name=Size,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Readme,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Publisher,Value=Sophos Limited,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=NoRepair,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=NoModify,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=ModifyPath,Value=#%MsiExec.exe /X{4B1F9009-CD85-43C0-BCBD-D491908D5A52},)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=InstallSource,Value=C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=InstallLocation,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=InstallDate,Value=20200515,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=HelpTelephone,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=HelpLink,Value=#%www.sophos.com/.../,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=DisplayVersion,Value=1.9.2235.0,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Contact,Value=Sophos Technical Support,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Comments,Value=Network threat protection,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=AuthorizedCDFPrefix,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\InstallProperties,SecurityDescriptor=BinaryData,BinaryType=1,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Language,Value=#1033,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Version,Value=#17369275,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=WindowsInstaller,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=VersionMinor,Value=#9,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=VersionMajor,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=URLUpdateInfo,Value=www.sophos.com/.../updates,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=URLInfoAbout,Value=http://www.sophos.com/,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=UninstallString,Value=#%MsiExec.exe /X{4B1F9009-CD85-43C0-BCBD-D491908D5A52},)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=SystemComponent,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=EstimatedSize,Value=#29481,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Size,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Readme,,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=Publisher,Value=Sophos Limited,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=NoRepair,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=NoModify,Value=#1,)MSI (s) (20:4C) [18:02:53:011]: Executing op: RegAddValue(Name=ModifyPath,Value=#%MsiExec.exe /X{4B1F9009-CD85-43C0-BCBD-D491908D5A52},)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=LocalPackage,Value=C:\WINDOWS\Installer\4978e5.msi,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegCreateKey()MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=InstallSource,Value=C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=InstallLocation,,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=InstallDate,Value=20200515,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=HelpTelephone,,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=HelpLink,Value=#%www.sophos.com/.../,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=DisplayVersion,Value=1.9.2235.0,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=Contact,Value=Sophos Technical Support,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=Comments,Value=Network threat protection,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegAddValue(Name=AuthorizedCDFPrefix,,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages,,BinaryType=1,,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegRemoveValue(Name=C:\WINDOWS\Installer\4978e5.msi,Value=#0,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:53:026]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages 3: 2 MSI (s) (20:4C) [18:02:53:026]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Transforms,,BinaryType=1,,)MSI (s) (20:4C) [18:02:53:026]: Executing op: RegRemoveKey()MSI (s) (20:4C) [18:02:53:026]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9009F1B458DC0C34CBDB4D1909D8A525\Transforms 3: 2 MSI (s) (20:4C) [18:02:53:026]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=0)MSI (s) (20:4C) [18:02:53:026]: Error in rollback skipped. Return: 5MSI (s) (20:4C) [18:02:53:026]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:53:026]: Note: 1: 2318 2: MSI (s) (20:4C) [18:02:53:026]: No System Restore sequence number for this installation.MSI (s) (20:4C) [18:02:53:026]: Unlocking ServerMSI (s) (20:4C) [18:02:53:026]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.Action ended 18:02:53: INSTALL. Return value 3.Property(N): UpgradeCode = {A6CF693D-C171-4DF5-AE49-223B66F65A1A}Property(N): INSTALLTYPE_IS_CENTRAL = #1Property(N): INSTALLDIR = C:\Program Files\Sophos\Sophos Network Threat Protection\Property(N): ProductData = C:\ProgramData\Sophos\Sophos Network Threat Protection\Property(N): Config = C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Property(N): Status = C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\Property(N): Logs = C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\Property(N): SnortData = C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\Property(N): HeartbeatData = C:\ProgramData\Sophos\Heartbeat\Property(N): HeartbeatConfig = C:\ProgramData\Sophos\Heartbeat\Config\Property(N): HeartbeatLogs = C:\ProgramData\Sophos\Heartbeat\Logs\Property(N): HeartbeatPersist = C:\ProgramData\Sophos\Heartbeat\Persist\Property(N): SophosNTPLWFDir = C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\Property(N): TARGETDIR = C:\Property(N): VersionNT64 = 603Property(N): RegisterSntpEventManifest = "wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"Property(N): RegisterSntpEventManifestRollback = "wevtutil.exe" um "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"Property(N): UnregisterSntpEventManifest = "wevtutil.exe" um "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"Property(N): UnregisterSntpEventManifestRollback = "wevtutil.exe" im "C:\Program Files\Sophos\Sophos Network Threat Protection\Sntp.man"Property(N): MsiUninstallDrivers = 2.12{76F354A6-97D5-4872-9781-2F2642A4F18A}21Sophos Network Threat ProtectionSophos LimitedProperty(N): UninstallSophosNTPLWF = "C:\WINDOWS\system32\\netcfg.exe" /u SOPHOS_SOPHOSNTPLWFProperty(N): ExecSecureObjectsRollback_64 = **********Property(N): UnregisterManagementAdapterRollback = C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dllProperty(N): RegisterManagementAdapter = C:\Program Files\Sophos\Sophos Network Threat Protection\NTPAdapter.dllProperty(N): UnregisterHbtManagementAdapterRollback = C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dllProperty(N): RegisterHbtManagementAdapter = C:\Program Files\Sophos\Sophos Network Threat Protection\HbtAdapter.dllProperty(N): CleanUpSsspUserAccount = NT SERVICE\sntpserviceProperty(N): CleanUpSsspUserAccountRollback = NT SERVICE\sntpserviceProperty(N): RemoveSIPSSubmitterUserAccount = NT SERVICE\SntpServiceProperty(N): RemoveSIPSSubmitterUserAccountRollback = NT SERVICE\SntpServiceProperty(N): plugins = C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\Property(N): SnortDynModulesDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\Property(N): SnortPreProcDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\Property(N): SnortConfDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\Property(N): Sophos = C:\Program Files\Sophos\Property(N): ProgramFiles64Folder = C:\Program Files\Property(N): SophosAppData = C:\ProgramData\Sophos\Property(N): CommonAppDataFolder = C:\ProgramData\Property(N): VersionNT = 603Property(N): Installed = 00:00:00Property(N): ALLUSERS = 1Property(N): MSIRESTARTMANAGERCONTROL = DisableProperty(N): ARPCOMMENTS = Network threat protectionProperty(N): ARPCONTACT = Sophos Technical SupportProperty(N): ARPHELPLINK = http://www.sophos.com/support/Property(N): ARPNOMODIFY = 1Property(N): ARPNOREPAIR = 1Property(N): ARPPRODUCTICON = shield.icoProperty(N): ARPURLINFOABOUT = http://www.sophos.com/Property(N): ARPURLUPDATEINFO = www.sophos.com/.../updatesProperty(N): Manufacturer = Sophos LimitedProperty(N): ProductCode = {4B1F9009-CD85-43C0-BCBD-D491908D5A52}Property(N): ProductLanguage = 1033Property(N): ProductName = Sophos Network Threat ProtectionProperty(N): ProductVersion = 1.9.2235.0Property(N): RegisterWithAutoUpdate = {8087796B-2289-4897-98A5-58FF23DAAFD0};ntp64Property(N): SecureCustomProperties = WIX_DOWNGRADE_DETECTED;WIX_UPGRADE_DETECTEDProperty(N): MsiHiddenProperties = ExecSecureObjects_64;ExecSecureObjectsRollback_64Property(N): INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 = C:\Property(N): SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA = C:\Windows\SysWOW64\Property(N): SystemFolder = C:\WINDOWS\SysWOW64\Property(N): DirectoryTable100_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA = DirectoryTableProperty(N): System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C = C:\Windows\system32\Property(N): System64Folder = C:\WINDOWS\system32\Property(N): DirectoryTable100_amd64.05F0B5F5_44A8_3793_976B_A4F17AECF92C = DirectoryTableProperty(N): PackageCode = {0B95A4E2-4953-4CE7-B8F7-53BB197E234A}Property(N): ProductState = 5Property(N): UPGRADINGPRODUCTCODE = {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}Property(N): CLIENTPROCESSID = 1012Property(N): CLIENTUILEVEL = 3Property(N): MSICLIENTUSESEXTERNALUI = 1Property(N): REMOVE = ALLProperty(N): MsiSystemRebootPending = 1Property(N): PRODUCTLANGUAGE = 1033Property(N): VersionDatabase = 405Property(N): VersionMsi = 5.00Property(N): WindowsBuild = 9600Property(N): ServicePackLevel = 0Property(N): ServicePackLevelMinor = 0Property(N): MsiNTProductType = 1Property(N): WindowsFolder = C:\WINDOWS\Property(N): WindowsVolume = C:\Property(N): RemoteAdminTS = 1Property(N): TempFolder = C:\WINDOWS\TEMP\Property(N): ProgramFilesFolder = C:\Program Files (x86)\Property(N): CommonFilesFolder = C:\Program Files (x86)\Common Files\Property(N): CommonFiles64Folder = C:\Program Files\Common Files\Property(N): AppDataFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Property(N): FavoritesFolder = C:\WINDOWS\system32\config\systemprofile\Favorites\Property(N): NetHoodFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Property(N): PersonalFolder = C:\WINDOWS\system32\config\systemprofile\Documents\Property(N): PrintHoodFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Property(N): RecentFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent\Property(N): SendToFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo\Property(N): TemplateFolder = C:\ProgramData\Microsoft\Windows\Templates\Property(N): LocalAppDataFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Local\Property(N): MyPicturesFolder = C:\WINDOWS\system32\config\systemprofile\Pictures\Property(N): AdminToolsFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Property(N): StartupFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Property(N): ProgramMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Property(N): StartMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Property(N): DesktopFolder = C:\Users\Public\Desktop\Property(N): FontsFolder = C:\WINDOWS\Fonts\Property(N): GPTSupport = 1Property(N): OLEAdvtSupport = 1Property(N): ShellAdvtSupport = 1Property(N): MsiAMD64 = 6Property(N): Msix64 = 6Property(N): Intel = 6Property(N): PhysicalMemory = 8074Property(N): VirtualMemory = 5598Property(N): AdminUser = 1Property(N): MsiTrueAdminUser = 1Property(N): LogonUser = SYSTEMProperty(N): UserSID = S-1-5-18Property(N): UserLanguageID = 1033Property(N): ComputerName = PBC-1ZHCPN2-LTProperty(N): SystemLanguageID = 1033Property(N): ScreenX = 1024Property(N): ScreenY = 768Property(N): CaptionHeight = 19Property(N): BorderTop = 1Property(N): BorderSide = 1Property(N): TextHeight = 16Property(N): TextInternalLeading = 3Property(N): ColorBits = 32Property(N): TTCSupport = 1Property(N): Time = 18:02:53Property(N): Date = 2/14/2021Property(N): MsiNetAssemblySupport = 4.8.4084.0Property(N): MsiWin32AssemblySupport = 6.3.19041.546Property(N): RedirectedDllSupport = 2Property(N): MsiRunningElevated = 1Property(N): Privileged = 1Property(N): USERNAME = PBC-COMProperty(N): COMPANYNAME = COMPHXProperty(N): DATABASE = C:\WINDOWS\Installer\4978e5.msiProperty(N): OriginalDatabase = C:\WINDOWS\Installer\4978e5.msiProperty(N): UILevel = 2Property(N): Preselected = 1Property(N): ACTION = INSTALLProperty(N): ROOTDRIVE = C:\Property(N): CostingComplete = 1Property(N): OutOfDiskSpace = 0Property(N): OutOfNoRbDiskSpace = 0Property(N): PrimaryVolumeSpaceAvailable = 0Property(N): PrimaryVolumeSpaceRequired = 0Property(N): PrimaryVolumeSpaceRemaining = 0MSI (s) (20:4C) [18:02:53:042]: Closing MSIHANDLE (2) of type 790542 for thread 8012Property(N): INSTALLLEVEL = 1CustomAction returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)MSI (s) (20:00) [18:02:53:042]: Note: 1: 2205 2: 3: Control Action ended 18:02:53: RemoveExistingProducts. Return value 3.Action ended 18:02:53: INSTALL. Return value 3.Property(S): UpgradeCode = {A6CF693D-C171-4DF5-AE49-223B66F65A1A}Property(S): INSTALLTYPE_IS_CENTRAL = #1Property(S): INSTALLDIR = C:\Program Files\Sophos\Sophos Network Threat Protection\Property(S): ProductData = C:\ProgramData\Sophos\Sophos Network Threat Protection\Property(S): Config = C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Property(S): Status = C:\ProgramData\Sophos\Sophos Network Threat Protection\Config\Status\Property(S): Logs = C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\Property(S): SnortData = C:\ProgramData\Sophos\Sophos Network Threat Protection\IPS\Property(S): HeartbeatData = C:\ProgramData\Sophos\Heartbeat\Property(S): HeartbeatConfig = C:\ProgramData\Sophos\Heartbeat\Config\Property(S): HeartbeatLogs = C:\ProgramData\Sophos\Heartbeat\Logs\Property(S): HeartbeatPersist = C:\ProgramData\Sophos\Heartbeat\Persist\Property(S): SophosNTPLWFDir = C:\Program Files\Sophos\Sophos Network Threat Protection\SophosNTPLWF\Property(S): TARGETDIR = C:\Property(S): VersionNT64 = 603Property(S): SnortDynModulesDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Modules\Property(S): SnortPreProcDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Dynamic Preprocessors\Property(S): SnortConfDir = C:\Program Files\Sophos\Sophos Network Threat Protection\IPS Configuration\Property(S): plugins = C:\Program Files\Sophos\Sophos Network Threat Protection\plugins\Property(S): Sophos = C:\Program Files\Sophos\Property(S): ProgramFiles64Folder = C:\Program Files\Property(S): SophosAppData = C:\ProgramData\Sophos\Property(S): CommonAppDataFolder = C:\ProgramData\Property(S): VersionNT = 603Property(S): ALLUSERS = 1Property(S): MSIRESTARTMANAGERCONTROL = DisableProperty(S): ARPCOMMENTS = Network threat protectionProperty(S): ARPCONTACT = Sophos Technical SupportProperty(S): ARPHELPLINK = http://www.sophos.com/support/Property(S): ARPNOMODIFY = 1Property(S): ARPNOREPAIR = 1Property(S): ARPPRODUCTICON = shield.icoProperty(S): ARPURLINFOABOUT = http://www.sophos.com/Property(S): ARPURLUPDATEINFO = www.sophos.com/.../updatesProperty(S): Manufacturer = Sophos LimitedProperty(S): ProductCode = {2D2A1891-4657-4E6F-9373-BFCE4C9AC5BA}Property(S): ProductLanguage = 1033Property(S): ProductName = Sophos Network Threat ProtectionProperty(S): ProductVersion = 1.11.194.0Property(S): RegisterWithAutoUpdate = {8087796B-2289-4897-98A5-58FF23DAAFD0};ntp64Property(S): SecureCustomProperties = WIX_DOWNGRADE_DETECTED;WIX_UPGRADE_DETECTEDProperty(S): MsiHiddenProperties = ExecSecureObjects_64;ExecSecureObjectsRollback_64Property(S): WIX_UPGRADE_DETECTED = {4B1F9009-CD85-43C0-BCBD-D491908D5A52}Property(S): INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 = C:\Property(S): SystemFolder_x86_VC.194841A2_D0F2_3B96_9F71_05BA91BEA0FA = C:\WINDOWS\SysWOW64\Property(S): SystemFolder = C:\WINDOWS\SysWOW64\Property(S): DirectoryTable100_x86.194841A2_D0F2_3B96_9F71_05BA91BEA0FA = DirectoryTableProperty(S): System64Folder_amd64_VC.05F0B5F5_44A8_3793_976B_A4F17AECF92C = C:\WINDOWS\system32\Property(S): System64Folder = C:\WINDOWS\system32\Property(S): DirectoryTable100_amd64.05F0B5F5_44A8_3793_976B_A4F17AECF92C = DirectoryTableProperty(S): MsiLogFileLocation = C:\WINDOWS\TEMP\Sophos Network Threat Protection Install Log 20210214 180145.txtProperty(S): PackageCode = {BDBDC64C-EB88-4135-BD3F-FE19CA9893E3}Property(S): ProductState = -1Property(S): PackagecodeChanging = 1Property(S): REBOOT = ReallySuppressProperty(S): INSTALLINGVERSION = 1.11.194.0Property(S): ARPSYSTEMCOMPONENT = 1Property(S): CURRENTDIRECTORY = C:\WINDOWS\system32Property(S): CLIENTUILEVEL = 3Property(S): MSICLIENTUSESEXTERNALUI = 1Property(S): CLIENTPROCESSID = 1012Property(S): MsiSystemRebootPending = 1Property(S): VersionDatabase = 405Property(S): VersionMsi = 5.00Property(S): WindowsBuild = 9600Property(S): ServicePackLevel = 0Property(S): ServicePackLevelMinor = 0Property(S): MsiNTProductType = 1Property(S): WindowsFolder = C:\WINDOWS\Property(S): WindowsVolume = C:\Property(S): RemoteAdminTS = 1Property(S): TempFolder = C:\WINDOWS\TEMP\Property(S): ProgramFilesFolder = C:\Program Files (x86)\Property(S): CommonFilesFolder = C:\Program Files (x86)\Common Files\Property(S): CommonFiles64Folder = C:\Program Files\Common Files\Property(S): AppDataFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Property(S): FavoritesFolder = C:\WINDOWS\system32\config\systemprofile\Favorites\Property(S): NetHoodFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts\Property(S): PersonalFolder = C:\WINDOWS\system32\config\systemprofile\Documents\Property(S): PrintHoodFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\Property(S): RecentFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent\Property(S): SendToFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo\Property(S): TemplateFolder = C:\ProgramData\Microsoft\Windows\Templates\Property(S): LocalAppDataFolder = C:\WINDOWS\system32\config\systemprofile\AppData\Local\Property(S): MyPicturesFolder = C:\WINDOWS\system32\config\systemprofile\Pictures\Property(S): AdminToolsFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Property(S): StartupFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Property(S): ProgramMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Property(S): StartMenuFolder = C:\ProgramData\Microsoft\Windows\Start Menu\Property(S): DesktopFolder = C:\Users\Public\Desktop\Property(S): FontsFolder = C:\WINDOWS\Fonts\Property(S): GPTSupport = 1Property(S): OLEAdvtSupport = 1Property(S): ShellAdvtSupport = 1Property(S): MsiAMD64 = 6Property(S): Msix64 = 6Property(S): Intel = 6Property(S): PhysicalMemory = 8074Property(S): VirtualMemory = 5605Property(S): AdminUser = 1Property(S): MsiTrueAdminUser = 1Property(S): LogonUser = SYSTEMProperty(S): UserSID = S-1-5-18Property(S): UserLanguageID = 1033Property(S): ComputerName = PBC-1ZHCPN2-LTProperty(S): SystemLanguageID = 1033Property(S): ScreenX = 1024Property(S): ScreenY = 768Property(S): CaptionHeight = 19Property(S): BorderTop = 1Property(S): BorderSide = 1Property(S): TextHeight = 16Property(S): TextInternalLeading = 3Property(S): ColorBits = 32Property(S): TTCSupport = 1Property(S): Time = 18:02:53Property(S): Date = 2/14/2021Property(S): MsiNetAssemblySupport = 4.8.4084.0Property(S): MsiWin32AssemblySupport = 6.3.19041.546Property(S): RedirectedDllSupport = 2Property(S): MsiRunningElevated = 1Property(S): Privileged = 1Property(S): USERNAME = PBC-COMProperty(S): COMPANYNAME = COMPHXProperty(S): DATABASE = C:\WINDOWS\Installer\5e8d70f4.msiProperty(S): OriginalDatabase = C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ntp64\Sophos Network Threat Protection.msiProperty(S): UILevel = 2Property(S): ACTION = INSTALLProperty(S): MIGRATE = {4B1F9009-CD85-43C0-BCBD-D491908D5A52}Property(S): ROOTDRIVE = C:\Property(S): CostingComplete = 1Property(S): OutOfDiskSpace = 0Property(S): OutOfNoRbDiskSpace = 0Property(S): PrimaryVolumeSpaceAvailable = 0Property(S): PrimaryVolumeSpaceRequired = 0Property(S): PrimaryVolumeSpaceRemaining = 0Property(S): INSTALLLEVEL = 1MSI (s) (20:00) [18:02:53:058]: Note: 1: 1708 MSI (s) (20:00) [18:02:53:058]: Product: Sophos Network Threat Protection -- Installation failed.
MSI (s) (20:00) [18:02:53:058]: Windows Installer installed the product. Product Name: Sophos Network Threat Protection. Product Version: 1.11.194.0. Product Language: 1033. Manufacturer: Sophos Limited. Installation success or error status: 1603.
MSI (s) (20:00) [18:02:53:058]: Closing MSIHANDLE (1) of type 790542 for thread 8960MSI (s) (20:00) [18:02:53:073]: Deferring clean up of packages/files, if any existMSI (s) (20:00) [18:02:53:073]: MainEngineThread is returning 1603MSI (s) (20:DC) [18:02:53:073]: No System Restore sequence number for this installation.=== Logging stopped: 2/14/2021 18:02:53 ===MSI (s) (20:DC) [18:02:53:073]: User policy value 'DisableRollback' is 0MSI (s) (20:DC) [18:02:53:073]: Machine policy value 'DisableRollback' is 0MSI (s) (20:DC) [18:02:53:073]: Incrementing counter to disable shutdown. Counter after increment: 0MSI (s) (20:DC) [18:02:53:073]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2 MSI (s) (20:DC) [18:02:53:073]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2 MSI (s) (20:DC) [18:02:53:073]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1MSI (s) (20:DC) [18:02:53:073]: Destroying RemoteAPI object.MSI (s) (20:78) [18:02:53:073]: Custom Action Manager thread ending.MSI (c) (F4:3C) [18:02:53:073]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1MSI (c) (F4:3C) [18:02:53:073]: MainEngineThread is returning 1603=== Verbose logging stopped: 2/14/2021 18:02:53 ===
setup::MsiInstaller::installOrUpgrade: Install/upgrade returned 1603`anonymous-namespace'::setResult: installation failedsetup::TamperProtectionControl::enable: Registered tamper protection integrity.dat for NTPsetup::TamperProtectionControl::enable: Enabled tamper protection for NTPProductSetup::~ProductSetup: End product setup
So am I reading this right that the tamper protection is causing the issue?
This appears to be the fatal event:
MSI (s) (20:4C) [18:02:51:011]: Executing op: ActionStart(Name=MsiUninstallDrivers,,)MSI (s) (20:4C) [18:02:51:011]: Executing op: CustomActionSchedule(Action=MsiUninstallDrivers,ActionType=3073,Source=BinaryData,Target=UninstallDriverPackages,CustomActionData=2.12{76F354A6-97D5-4872-9781-2F2642A4F18A}21Sophos Network Threat ProtectionSophos Limited)MSI (s) (20:4C) [18:02:51:011]: Creating MSIHANDLE (83) of type 790536 for thread 8012MSI (s) (20:8C) [18:02:51:011]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI701F.tmp, Entrypoint: UninstallDriverPackagesDIFXAPP: UninstallDriverPackages()DIFXAPP: 'CustomActionData' property 'DIFxApp Version' is 2.1.DIFXAPP: 'CustomActionData' property 'UI Level' is 2.DIFXAPP: 'CustomActionData' property 'componentId' is {76F354A6-97D5-4872-9781-2F2642A4F18A}.DIFXAPP: 'CustomActionData' property 'flags' is 0x15.DIFXAPP: 'CustomActionData' property 'ProductName' is Sophos Network Threat Protection.DIFXAPP: 'CustomActionData' property 'ManufacturerName' is Sophos Limited.DIFXAPP: ERROR 0x2 encountered while opening persistent-info key for component '{76F354A6-97D5-4872-9781-2F2642A4F18A}'DIFXAPP: UninstallDriverPackages failed with error 0x2DIFXAPP: RETURN: UninstallDriverPackages() 2 (0x2)CustomAction MsiUninstallDrivers returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
DIFX is a Microsoft Driver installer framework. Here the NTP MSI is running the MsiUninstallDrivers custom action. This appears to be failing to locate a registry key associated with the SNTP.sys driver component.
Looking at the MSI with Orca, here is the CA, it points at the code being utilized being in the standard Microsoft DIFX library DLL (can be exported from the Binary table if needed) so there isn't any specific Sophos code here to remove the driver.
I assume Googling for "difx" "UninstallDriverPackages" would return many examples of failure reason as it's quite a generic error for a common routine.
The error 2 is ERROR_FILE_NOT_FOUND. The 76F354A6-97D5-4872-9781-2F2642A4F18A component, according to the MSI log in the SNTP.sys driver, so this is the driver that is failing to uninstall.
I guess once approach is to run Process Monitor when perform an update, cross reference the new uninstall log for this custom action running and the same error code by DIFX and see the registry key (I think it's a reg key rather than a file given the name) that is not found. Maybe under: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DIFx\?
The other option might be be simply to run SophosZap - https://support.sophos.com/support/s/article/KB-000038989?language=en_US - on the computer, reboot as requested and then re-install. Does the same issue persist?
I suppose, if I had the issue on may computers, I might want to get to the bottom of it to apply a more surgical fix but if it's a one off, SophosZap as the first port of call would be my first choice.
Hope it helps.
Thank you for the reply, I ended up using SophosZap remove the client and reinstall it.
As to the issue, it was due to how our SCCM task sequence was created and most likely didn't get the correct permissions at the time it was installing Sophos and some how it was still not working even when I made sure the groups/etc was completed.