This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Update - Failed to install SAVXP: A previous version could not...

Hi...

I'm receving the following in SEC  "00000067 Failed to install SAVXP. A previous version could not be uninstalled"

and in the Sophos Antivirus uninstall log

CustomAction UninstallDriverFiles64Vista returned actual error code -1079 (note this may not be 100% accurate if translation happened inside sandbox)
MSI (s) (38:30) [10:10:19:389]: Product: Sophos Anti-Virus -- Error 1722.There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action UninstallDriverFiles64Vista, location: C:\Windows\SysWOW64\, command: "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF"

I read a post recommeding copying NATIVE.EXE from the CIDS directory because it was not there, however I receive the same results.

Any insight would be much appreciated!



This thread was automatically locked due to age.
Parents
  • Oh Crap Sorry!

    [Edit by QC] I've deleted the large post with the complete Sophos Anti-Virus Uninstall log.txt and instead posted the relevant lines here

    MSI (s) (10:40) [09:42:28:114]: Executing op: ActionStart(Name=UninstallDriverFiles64Vista,,)
    MSI (s) (10:40) [09:42:28:115]: Executing op: CustomActionSchedule(Action=UninstallDriverFiles64Vista,ActionType=1058,Source=C:\Windows\SysWOW64\,Target="C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF",)
    MSI (s) (10:40) [09:42:28:115]: Note: 1: 1721 2: UninstallDriverFiles64Vista 3: C:\Windows\SysWOW64\ 4: "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF"
    MSI (s) (10:40) [09:42:28:115]: Product: Sophos Anti-Virus -- Error 1721.There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: UninstallDriverFiles64Vista, location: C:\Windows\SysWOW64\, command: "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE" /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVONACCESSDRIV.INF"

    MSI (s) (10:40) [09:42:28:119]: User policy value 'DisableRollback' is 0
    MSI (s) (10:40) [09:42:28:119]: Machine policy value 'DisableRollback' is 0
    Action ended 9:42:28: InstallFinalize. Return value 3.

    [/Edit]

  • Hello BillFolger,

    guess the C:\Program Files (x86)\Sophos\Sophos Anti-Virus\ folder does exist but is pretty empty, isn't it?

    The following has helped in similar situations (coincidentally I had one case last week)

    • stop the Sophos AutopUpdate Service so that it won't interfere
    • copy native.exe from C:\ProgramData\Sophos\AutoUpdate\Cache\savxp\native\amd64\ to the above mentioned folder
    • do the same for the files in the ...\Cache\savxp\drivers\onaccess\win7_amd64\, ...\drivers\boottasks\, and ...\drivers\sdcfilter\win7_amd64\ folders (note: all files go to ...\Sophos Anti-Virus\ not to subfolders)
    • either uninstall Sophos Anti-Virus from the Control Panel's Programs and Features or simply start the AutoUpdate service, wait for or force an update which should then succeed

    Ideally you should use the files belonging to the installed version (BTW: the logs suggest it's 10.3.11 which is about a year old) but usually it works

    Christian

  • YES!

     

    It's up and working with 10.6.

     

    Thank You Christian!

  • Hi,

    Had a similar problem on a machine today. Followed you instructions as above and all okay (Thank you!), SAVXP error message disappeared but has now created a new error:

    Event Decode Unavailable (Event Number: "-2147024891" Message Code" "SAVXP.2147942405" Inserts: "Access is denied.","","","","" [0x80070005]

    I came across this link

    https://community.sophos.com/products/endpoint-security-control/f/sophos-endpoint-software/3934/event-decode-unavailable-event-number--2147024891-message-code-savxp-2147942404

    The version on the SEC is 10.7.2.46 and the one on the client is 10.7.2.49

    We are on SEC 5.5 and have over 4900 happy machines, so I am reluctant to role back the DLL on the SEC?

    Would I be better of uninstalling again and then copy the files above from a known working machine?

    Thanks

  • Hello pdturbo80,

    what's the corresponding event on the endpoint?
    As far as I can see the event number is not contained in SavRes.dll - neither 10.7.2.46 nor 10.7.2.49 (the message tables are identical so you don't have to copy anything). The message is just that, Access denied, the numbers are simply the int, uint, and hex representation of the same value.

    Christian

  • Hi Christian,

     

    Thanks for the reply. Looks like after I acknowledge the event as an error and leaving it over night, it has not appeared. So good news, thanks for the original post. Looks like I have to do this fix on a number of machines. Any reason why this sometimes happens?

    Thanks

    Peter

  • Sorry, Christian, one more on this. Do I have to copy the same files listed above into a 32 bit version of Windows 7 as I have the same issue on a a machine which is Windows 7 32 bit.

  • Hello Peter,

    I've also seen it on a small percentage of machines. Problem is to find the log from when "it" happened, if you can find it the question is whether the event is in the log, and then whether you can prevent it happening again.
    It might be that the install sequence isn't absolutely watertight and rollbacks aren't complete when there's an interruption (e.g. due to a shutdown) at an unfortunate moment.

    Christian

  • Hello Peter,

    same files but for 32bit from the _i386 directories.

    Christian

  • Hi,

    Thanks for this, I tried that and it appears to have failed:

     

    2017-07-28 11:28:27 ERROR: GetVersion - Unable to load the new Factory file, path = C:\ProgramData\Sophos\Sophos Anti-Virus\Config\Factory.xml
    2017-07-28 11:28:27 ProductCode change detected
    2017-07-28 11:28:27 Info: Added SAVService to ServicesList.
    2017-07-28 11:28:27 Info: Added SAVAdminService to ServicesList.
    2017-07-28 11:28:27 Info: Added Sophos Device Control Service to ServicesList.
    2017-07-28 11:28:27 Info: Added SophosBootDriver to ServicesList.
    2017-07-28 11:28:27 Info: Added swi_service to ServicesList.
    2017-07-28 11:28:27 Info: Added swi_filter to ServicesList.
    2017-07-28 11:28:27 Info: Added Sophos Web Control Service to ServicesList.
    2017-07-28 11:28:27 Info: Added SAVOnAccess to ServicesList.
    2017-07-28 11:28:27 Info: Added SAV to ComponentList.
    2017-07-28 11:28:27 Info: component SDC is not registered - skipping.
    2017-07-28 11:28:27 Info: component SCS is not registered - skipping.
    2017-07-28 11:28:27 Info: Added SWI to ComponentList.
    2017-07-28 11:28:27 Info: Added SWC to ComponentList.
    2017-07-28 11:28:27 Info: Detected an older version of SAV, version 10.6. Doing a major update.
    2017-07-28 11:28:27 Info: Set Update Begin
    2017-07-28 11:28:57 Unable to create an instance of ComponentManager - SystemInformation will not be informed of the update (0x80080005)
    2017-07-28 11:28:57 Info: Added SAVService to ServicesList.
    2017-07-28 11:28:57 Info: Added SAVAdminService to ServicesList.
    2017-07-28 11:28:57 Info: Sophos Device Control Service was found to not be installed - skipping.
    2017-07-28 11:28:57 Info: SophosBootDriver was found to not be installed - skipping.
    2017-07-28 11:28:57 Info: swi_service was found to not be installed - skipping.
    2017-07-28 11:28:57 Info: swi_filter was found to not be installed - skipping.
    2017-07-28 11:28:57 Info: Added Sophos Web Control Service to ServicesList.
    2017-07-28 11:28:57 Info: All services reported they accept stop controls.
    2017-07-28 11:28:57 Info: Stop SAVService
    2017-07-28 11:28:57 Info: Convert boot tasks
    2017-07-28 11:28:57 Info: CopyFilesToTemp
    2017-07-28 11:28:57 ERROR: StoreTempFiles - failed to copy machine file - not present, hr = 0x0
    2017-07-28 11:28:57 Warning: configuration will not be preserved
    2017-07-28 11:28:57 Info: Reading overrides from registry
    2017-07-28 11:28:57 Info: Uninstall old SAV
    2017-07-28 11:28:57 Detected version of SAV with product code: {CA3CE456-B2D9-4812-8C69-17D6980432EF}
    2017-07-28 11:28:57 Info: Running Uninstall of previous version using command line: msiexec.exe /x {CA3CE456-B2D9-4812-8C69-17D6980432EF} REBOOT=ReallySuppress /qn UNINSTALLDRIVERS=0 UNINSTALLCLASSFILTER=0 UNINSTALLBOOTDRIVERS=1 UNINSTALLKMSDRIVERS=1 CHECKFORSCF=0 INSTALLINGVERSION="10.7.2.49" /Lvp "C:\Windows\TEMP\Sophos Anti-Virus Uninstall Log_170728_092857.txt"
    2017-07-28 11:29:41 Info: Finished waiting for Uninstallation of previous version. Status returned was 0l.
    2017-07-28 11:29:41 WARNING: SAV uninstall failed with error 1603
    2017-07-28 11:29:41 Detected version of SAV with product code: {CA3CE456-B2D9-4812-8C69-17D6980432EF}
    2017-07-28 11:29:41 Info: Detected version of SAV has major version number: 10
    2017-07-28 11:29:41 Info: Detected version of SAV has minor version number: 6
    2017-07-28 11:29:41 ERROR: Uninstall of SAV, version = 10.6.4, succeeded but IsSAVInstalled is true (10.6.4).
    2017-07-28 11:29:41 ERROR: Upgrade failure
    2017-07-28 11:29:41 Info: Added SAV to ComponentList.
    2017-07-28 11:29:41 Info: Added SWI to ComponentList.
    2017-07-28 11:29:41 Info: Added SWC to ComponentList.
    2017-07-28 11:29:41 Info: Set Update Failed
    2017-07-28 11:30:11 Unable to create an instance of ComponentManager - SystemInformation cannot be informed of end of update

  • Hello Peter,

    as the uninstall failed the error is in the Uninstall log, but likely it'll tell that a CustomAction failed so the CustomActions log is the one to check.

    Christian

  • Hi,

    Thanks for the help so far-its hugely appreciated.

     

    Check the file and it says the following

     

    2017-07-28 11:28:57 CheckUserIsSophosAdmin: Action started
    2017-07-28 11:28:57 CheckUserIsSophosAdmin: User is LocalSystem
    2017-07-28 11:28:57 CheckUserIsSophosAdmin: Action succeeded
    2017-07-28 11:28:57 IsSafeToDowngrade: Action started
    2017-07-28 11:28:57 IsSafeToDowngrade: Action succeeded
    2017-07-28 11:28:57 UninstallDowngradeCheck: Action started
    2017-07-28 11:28:57 UninstallDowngradeCheck: Action succeeded
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Action started
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Setting class filter present property to: 1
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Action succeeded
    2017-07-28 11:28:59 SetProcessorProperties: Action started
    2017-07-28 11:28:59 SetProcessorProperties: Action succeeded
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: Action started
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: SetRestoreExcludedProcessesProperty
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: PROCESSOR_ARCHITECTURE environment variable is: x86
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: Action succeeded
    2017-07-28 11:29:04 CheckRegForNullDACLs: Action started
    2017-07-28 11:29:04 CheckRegForNullDACLs: Action succeeded
    2017-07-28 11:29:04 CloseSavMainWindow: Action started
    2017-07-28 11:29:04 CloseSavMainWindow: Action succeeded
    2017-07-28 11:29:04 DisableServices: Action started
    2017-07-28 11:29:04 DisableServices: Action succeeded
    2017-07-28 11:29:05 ForceStopSAVService: Action started
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Stopping SAVService
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Checking if service is still running
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Stopping SAVAdminService
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Checking if service is still running
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopSAVService: Services have been stopped
    2017-07-28 11:29:05 ForceStopSAVService: Action succeeded
    2017-07-28 11:29:05 WaitForSAVService: Action started
    2017-07-28 11:29:05 WaitForSAVService: WaitForSAVService: Walking system processes...
    2017-07-28 11:29:05 WaitForSAVService: WaitForSAVService: Finished walking system processes.
    2017-07-28 11:29:05 WaitForSAVService: Action succeeded
    2017-07-28 11:29:10 RollbackDisableServices: Action started
    2017-07-28 11:29:10 RollbackDisableServices: Action succeeded
    2017-07-28 11:29:11 RunErrorScripts: Action started
    2017-07-28 11:29:11 RunErrorScripts: Action succeeded
    2017-07-28 11:29:11 RestoreMovedFiles: Action started
    2017-07-28 11:29:11 RestoreMovedFiles: Action succeeded
    2017-07-28 11:29:11 SetUpdateFailed: Action started
    2017-07-28 11:29:41 SetUpdateFailed: Unable to create an instance of ComponentManager - SystemInformation cannot be informed of end of update
    2017-07-28 11:29:41 SetUpdateFailed: Action succeeded

Reply
  • Hi,

    Thanks for the help so far-its hugely appreciated.

     

    Check the file and it says the following

     

    2017-07-28 11:28:57 CheckUserIsSophosAdmin: Action started
    2017-07-28 11:28:57 CheckUserIsSophosAdmin: User is LocalSystem
    2017-07-28 11:28:57 CheckUserIsSophosAdmin: Action succeeded
    2017-07-28 11:28:57 IsSafeToDowngrade: Action started
    2017-07-28 11:28:57 IsSafeToDowngrade: Action succeeded
    2017-07-28 11:28:57 UninstallDowngradeCheck: Action started
    2017-07-28 11:28:57 UninstallDowngradeCheck: Action succeeded
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Action started
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Setting class filter present property to: 1
    2017-07-28 11:28:59 SetClassFilterPresentProperty: Action succeeded
    2017-07-28 11:28:59 SetProcessorProperties: Action started
    2017-07-28 11:28:59 SetProcessorProperties: Action succeeded
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: Action started
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: SetRestoreExcludedProcessesProperty
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: PROCESSOR_ARCHITECTURE environment variable is: x86
    2017-07-28 11:28:59 SetRestoreExcludedProcessesProperty: Action succeeded
    2017-07-28 11:29:04 CheckRegForNullDACLs: Action started
    2017-07-28 11:29:04 CheckRegForNullDACLs: Action succeeded
    2017-07-28 11:29:04 CloseSavMainWindow: Action started
    2017-07-28 11:29:04 CloseSavMainWindow: Action succeeded
    2017-07-28 11:29:04 DisableServices: Action started
    2017-07-28 11:29:04 DisableServices: Action succeeded
    2017-07-28 11:29:05 ForceStopSAVService: Action started
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Stopping SAVService
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Checking if service is still running
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Stopping SAVAdminService
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopService: Checking if service is still running
    2017-07-28 11:29:05 ForceStopSAVService: ForceStopSAVService: Services have been stopped
    2017-07-28 11:29:05 ForceStopSAVService: Action succeeded
    2017-07-28 11:29:05 WaitForSAVService: Action started
    2017-07-28 11:29:05 WaitForSAVService: WaitForSAVService: Walking system processes...
    2017-07-28 11:29:05 WaitForSAVService: WaitForSAVService: Finished walking system processes.
    2017-07-28 11:29:05 WaitForSAVService: Action succeeded
    2017-07-28 11:29:10 RollbackDisableServices: Action started
    2017-07-28 11:29:10 RollbackDisableServices: Action succeeded
    2017-07-28 11:29:11 RunErrorScripts: Action started
    2017-07-28 11:29:11 RunErrorScripts: Action succeeded
    2017-07-28 11:29:11 RestoreMovedFiles: Action started
    2017-07-28 11:29:11 RestoreMovedFiles: Action succeeded
    2017-07-28 11:29:11 SetUpdateFailed: Action started
    2017-07-28 11:29:41 SetUpdateFailed: Unable to create an instance of ComponentManager - SystemInformation cannot be informed of end of update
    2017-07-28 11:29:41 SetUpdateFailed: Action succeeded

Children
  • Hello Peter,

    hah, likely isn't always - in this case it's the Uninstall log that has the error, sorry. Looks like it is between 11:29:05 and 11:29:10.

    Christian

  • Hi,

    No worries, here is a copy of the time period you mentioned

     

    Thanks

     

    MSI (s) (0C:60) [11:29:04:848]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=1300000)
    MSI (s) (0C:60) [11:29:04:848]: Executing op: ServiceControl(,Name=Sophos Web Control Service,Action=2,Wait=1,)
    MSI (s) (0C:60) [11:29:05:877]: Executing op: ActionStart(Name=ForceStopSAVService,,)
    MSI (s) (0C:60) [11:29:05:877]: Executing op: CustomActionSchedule(Action=ForceStopSAVService,ActionType=1025,Source=BinaryData,Target=ForceStopSAVService,)
    MSI (s) (0C:5C) [11:29:05:877]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI518.tmp, Entrypoint: ForceStopSAVService
    MSI (s) (0C:60) [11:29:05:877]: Executing op: ActionStart(Name=WaitForSAVService,,)
    MSI (s) (0C:60) [11:29:05:877]: Executing op: CustomActionSchedule(Action=WaitForSAVService,ActionType=1025,Source=BinaryData,Target=WaitForSAVService,)
    MSI (s) (0C:68) [11:29:05:893]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI519.tmp, Entrypoint: WaitForSAVService
    MSI (s) (0C:60) [11:29:05:893]: Executing op: ActionStart(Name=CleanUpSsspUserAccountRollback,,)
    MSI (s) (0C:60) [11:29:05:893]: Executing op: CustomActionSchedule(Action=CleanUpSsspUserAccountRollback,ActionType=1345,Source=BinaryData,Target=SetupSspUserAccount,CustomActionData=NT SERVICE\SAVService)
    MSI (s) (0C:60) [11:29:05:893]: Executing op: ActionStart(Name=CleanUpSsspUserAccount,,)
    MSI (s) (0C:60) [11:29:05:893]: Executing op: CustomActionSchedule(Action=CleanUpSsspUserAccount,ActionType=1089,Source=BinaryData,Target=CleanUpSsspUserAccount,CustomActionData=NT SERVICE\SAVService)
    MSI (s) (0C:5C) [11:29:05:893]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI52A.tmp, Entrypoint: CleanUpSsspUserAccount
    MSI (s) (0C:60) [11:29:05:909]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccount,,)
    CleanUpSsspUserAccount:  Initialized.
    MSI (s) (0C:60) [11:29:05:909]: Executing op: CustomActionSchedule(Action=RemoveSIPSSubmitterUserAccount,ActionType=1025,Source=BinaryData,Target=RemoveSIPSManagementUser,CustomActionData=NT SERVICE\SAVService)
    MSI (s) (0C:88) [11:29:05:909]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI53A.tmp, Entrypoint: RemoveSIPSManagementUser
    RemoveSIPSManagementUser Enter (290)
    Failed to delete value from the registry (319)
    CustomAction RemoveSIPSSubmitterUserAccount returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
    MSI (s) (0C:60) [11:29:05:909]: User policy value 'DisableRollback' is 0
    MSI (s) (0C:60) [11:29:05:909]: Machine policy value 'DisableRollback' is 0
    Aktion beendet um 11:29:05: InstallFinalize. R�ckgabewert 3.
    MSI (s) (0C:60) [11:29:05:909]: Executing op: Header(Signature=1397708873,Version=500,Timestamp=1258052515,LangId=1031,Platform=0,ScriptType=2,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
    MSI (s) (0C:60) [11:29:05:909]: Executing op: DialogInfo(Type=0,Argument=1031)
    MSI (s) (0C:60) [11:29:05:909]: Executing op: DialogInfo(Type=1,Argument=Sophos Anti-Virus)
    MSI (s) (0C:60) [11:29:05:909]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Aktion wird r�ckg�ngig gemacht:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Sicherungsdateien werden entfernt,CleanupTemplate=Datei: [1])
    MSI (s) (0C:60) [11:29:05:909]: Executing op: ActionStart(Name=RemoveSIPSSubmitterUserAccount,,)
    MSI (s) (0C:60) [11:29:05:909]: Executing op: ProductInfo(ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductName=Sophos Anti-Virus,PackageName=Sophos Anti-Virus.msi,Language=1031,Version=168165380,Assignment=1,ObsoleteArg=0,ProductIcon=ARPPRODUCTICON.exe,,PackageCode={A6DB9994-D66F-4F1A-82F4-4CE42F87BF6B},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)
    MSI (s) (0C:60) [11:29:05:924]: Executing op: ActionStart(Name=CleanUpSsspUserAccount,,)
    MSI (s) (0C:60) [11:29:05:924]: Executing op: ActionStart(Name=CleanUpSsspUserAccountRollback,,)
    MSI (s) (0C:60) [11:29:05:924]: Executing op: CustomActionRollback(Action=CleanUpSsspUserAccountRollback,ActionType=1345,Source=BinaryData,Target=SetupSspUserAccount,CustomActionData=NT SERVICE\SAVService)
    MSI (s) (0C:A0) [11:29:05:924]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI54B.tmp, Entrypoint: SetupSspUserAccount
    SetupSspUserAccount:  Initialized.
    SetupSspUserAccount:  LoadAccount(SophosSSPUser) failed (error 1332)
    SetupSspUserAccount:  Granting permissions to user "NT SERVICE\SAVService"
    SetupSspUserAccount:  Service has stopped, now starting.
    MSI (s) (0C:60) [11:29:09:653]: Executing op: ActionStart(Name=WaitForSAVService,,)
    MSI (s) (0C:60) [11:29:09:653]: Executing op: ActionStart(Name=ForceStopSAVService,,)
    MSI (s) (0C:60) [11:29:09:653]: Executing op: ActionStart(Name=StopServices,Description=Dienst werden angehalten,Template=Dienst: [1])
    MSI (s) (0C:60) [11:29:09:653]: Executing op: ServiceControl(,Name=Sophos Web Control Service,Action=1,Wait=1,)
    MSI (s) (0C:60) [11:29:10:698]: Executing op: ActionStart(Name=SwiServiceUnregister.11DACB83_28A7_4FA6_AF5B_C006E340C101,,)
    MSI (s) (0C:60) [11:29:10:698]: Executing op: ActionStart(Name=DisableServices,,)
    MSI (s) (0C:60) [11:29:10:698]: Executing op: ActionStart(Name=RollbackDisableServices,,)
    MSI (s) (0C:60) [11:29:10:698]: Executing op: CustomActionRollback(Action=RollbackDisableServices,ActionType=1281,Source=BinaryData,Target=RollbackDisableServices,)
    MSI (s) (0C:FC) [11:29:10:698]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI17F2.tmp, Entrypoint: RollbackDisableServices
    MSI (s) (0C:60) [11:29:10:838]: Executing op: ActionStart(Name=UnpublishFeatures,Description=Ver�ffentlichung von Produkt-Features wird r�ckg�ngig gemacht,Template=Feature: [1])
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegAddValue(Name=ServiceComponents,Value=$F{Ui&C@BA*({-6m[ch8p?)^w@e]UAE]BB3c*I*do@7Qx%PKO?85?S]XG3,D9KPh4p4=u81r0`5Z%KKf*4{_51qQk@}W4suJ[ne,G^v$Vge{j=K&,t!^5*Mi~6vnip]lZAXhRoGd`)XUAFE-^v6t19m$IYK.oBOCyahe_Zx!K?'y}5Ig!$BNy,+MB3~Y*?G~Ah8_5C}MBd@$xK(o09zh6`MQ(R{l,aP=7z70[AT9MABI({,J=WuylnAOV?34xJHfz?(+u-wad?0e&9%E!Luxt8XRTob_fH,I{8(Z=_&^1utaAby.bX73p8rbSi$X0e..p[V+2@fOV@F-nf0ls)yhmsZ]`L$A$?Qk2anN=CKd@My_H289H9mW{@KX%g5vJu7y]L1CP?T$id028`0I6H,PUK7f3@kH!TUL9s[t[C3,h`]lT?EJF$PimCc63j6qDn0?}8K'2@LrMX]QT(wJNxo}r=Aa1+{q^7]s%@'hq^'O4A-}$ldrqg8pLwL(Z*c*[?'8ZTpRVOFBy[K&H=HsY?D$Rz-=k%gS)uR}y6KQr8}{TV'JOMVMMkOqQ&~UM@v[@@StB[?a&,PX,iFM*?3D},350cKc~d4ZO,bq79rbveSUbkN4u'7?W&A3!=}IPYO,^%9R0)H5gnJbt?&aP^pI?z+.,0!}]4a3^97NiX,q))gOag+{VP_w*9G3Q?fJV.@PGS8o$t3oo97FwL*$$e~8VYV.u1uG]=c{r}UlZn~W-KC{C2*vdAOVt1eKP'Y947r*a5ZbO=$HMH,7*d.XnzL)u,Hdc?]a)EPrh`jb.[5%X5&s+?PS22)2-+.h6_6?FQmY'@qdd*i!qk'PrA]SLe.da=vV3%?$]&7'3P2drzji3AH[@ClJU7.u!BlV0Lfv~9(NetU}4xgcY[.'Z?5fe=p$$Yb2nRZWT5eA[fE5dAMbCr]yATI'Xv.ur?~hE=P!VBN-CjLjsh26&fuCD?lEVp^5krd1hNpir]'l-?*5?AZf&felb)]^u?gNH?Lv
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:838]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegAddValue(Name=EngineFiles,Value=B'H[7pbT+9RjCb&klv}8,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:838]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegAddValue(Name=Resources,Value=?$?&&WFt`8a&B`.f~7`u_]K_ZW!6z80Rb{`RtQmA0+I,2M+*^A!Oq7j8fv8[[8{xvmn[n?.$('%+n--*-sHCP?+VPAT[pV7l2WvBA}i^0rrH]A}6D?S^U0!+AoHV?%BO+Ax]wSB,NiBp894@j@v_X9Lho`OH@bm-ZC2`yuZ(!9[(i}FzduNl_75Lwf^?_8F?@W!i)M`''iRkI*ZWY@ft]q_=8`d`,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:838]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegAddValue(Name=ConfigFiles,Value=4Q3DKM`l9A^xRd=eqM,.LIz+m4,=2=2?zF=(m^gksjInj%8FeAn!zWF}kRS@A)FtjR108A*(6`pbXBO!%zt'$rt(_8i9+@Q5xX.&DIo{]xCw0AjQL2FV)9'Qfz'*@uFg,=P&HPAg@f&rs6z_KG$7Z@Sm_2qnJf=FmP^U*n,r*AemwXRtQkiz,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:838]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:838]: Executing op: RegAddValue(Name=HomeEdition,Value=vj+?00,@p95P54q'~A4U,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:854]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegAddValue(Name=MainComponents,Value=sprrGUM,$=-[&ltw@0PwS8t,d=~Bl9Fx7YP,u$!XuVIhIE`XT9{hbt=DY3el!u'`3%hL'9TN*q9fia6pkA-3_~J9{8b$sHYm,bPO%5~xceiij94Rl(R5pfNMHu=b?x[T=?&(TgtXr(ePa51?rAl)p?9r`WW.X!oX,nM~fFRY(=0)(^yUawLfIg4)*$6]?A*cZjw=iOw]r_+~b3xUW9^OEK$,mX3l?`F[h.Ao!=51B3@Gk2]!Owe)[k}X,=T~aALA_N=_[ziyG.*7m@0YWkq*u5KmK^*jLJ.H`=j_S*QxCz4u[_K,qqU-'A.F2oSSV*E6!74S*H6)+=e{gOXz0{PE-Y+q]$R(J9'{&'-Q7RWDrZ071RO5w8eQM8B6g[Ar2tKQZzrNe=e0XoLr^TT5njbNC9aEZ=x`[}V?Mso^X]TF@BT25??u7=dxHrNhM'a+c-A@{9+R'~g*HXdm-3}-^=I[U=^Re^!fg^eqeAKBxLonMArnQchEI]z_?D.L.W=Wo?rr$(Q`6ruqi-.Req^wl9'V]Mbj3*fXH4ae7oue2=PMw%wY~RkBbO-^6@b!'94G3'UC$q~JS)7jPz^Og@jsO(bn!(dDVnWISNc$I@6$d5A'(PvkniW1sZCsY@ZHrL_y+BuIWwYuotW3{8gIL]KAx^qU.&snxj(gt9uepMv~]sub2fonKb6Co@8p)6O4OT3W1eHFT1F(8=9Sz(.0g8wR3{7nvCI'+@y6-W^D@g&5F'6awnl-a@t)Mfu2`)61Uhw!21{rk8%JJbBjqW-LQ=-MB[klXA*AIw8je{CjS`,Y!pof.@FbG2PW5zxY=x+TBXgS,@rmm-6clM~o1`pwbhn]J9&X%8dyoeq@]K]bE2]-,@UVVE1TTBS[@bG'a`Qf.=YJMgGLi!y,7j`pGRu}s9ouEqYKARJWnu5k%Gx7WAm(R^3)SbDRdz5(j}o8E@],@9a-NusZuOUVhu2'39I6S$?'=W4A~Zn*G,E04=mP*fR)9L8o$rWo2yTh*@FvTbT
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:854]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\654EC3AC9D2B2184C896716D894023FE\Features,SecurityDescriptor=BinaryData,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegAddValue(Name=SAVService,Value=Vg@q[]0GO?nmG^LCD4kt2y1ew`QzF9TS&39+j5vrAFB8?=f[z8nmu`RXU$4SaNyflE0OU?cWtkY2sAg*CJv{jz)vo=.&s7Mw}i@@*4tG&LM6_=rZL8sao&W+L}RJ_nt0v=b&X9K@)_4CmDhxkHF`F?_BRZ7dn2pUY~GizzPss89K7$F=-b!1e0]64Kvq$@L-_er4aQk!,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE,,BinaryType=0,,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegRemoveKey()
    MSI (s) (0C:60) [11:29:10:854]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\654EC3AC9D2B2184C896716D894023FE 3: 2 
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ActionStart(Name=ProcessComponents,Description=Registrierung der Komponente(n) wird aktualisiert,)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={8B4CB61B-B986-4851-A3A8-8A29B744166F},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\integrity.dat,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={266D54B1-B706-4CCD-9C0A-01C33A70F79B},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={759C3654-CC88-4826-A930-E0BFB04EBD6B},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={BDE220A0-D203-449C-8A3F-648E1C889744},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={B9056343-C8F6-454A-AAF5-DBA44FC0E1F5},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={A154E863-F3EA-44EA-B782-B241DECCC60B},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={62922683-34EB-46E1-8AF4-E9D59E61833E},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={606B5C5C-66C9-490B-BBC3-77BFF00880E5},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_update.exe,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegisterSharedComponentProvider(,,File=SwiUpdate_32.11DACB83_28A7_4FA6_AF5B_C006E340C101,Component={606B5C5C-66C9-490B-BBC3-77BFF00880E5},ComponentVersion=3.6.0.1332,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: ComponentRegister(ComponentId={3630E612-875A-427A-8A2A-2708A9B24393},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:854]: Executing op: RegisterSharedComponentProvider(,,File=SwiService_32.11DACB83_28A7_4FA6_AF5B_C006E340C101,Component={3630E612-875A-427A-8A2A-2708A9B24393},ComponentVersion=3.6.0.1332,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={26BAD5C1-B5B8-4E0A-888F-A4AD4B1095AE},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={533F61E5-9143-4664-8DD0-02E1DACF312D},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={A871FD4C-242A-4F0A-B4AC-74BE34EC1BA0},,State=-7,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={DBD323D5-758C-4D26-BD2E-E46EB73EAC11},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={15A3052C-E1D6-4ADE-9DF2-DAAF479F9A7B},KeyPath=02:\Software\Sophos\SAVService\SAVUI\plugins\WebControlPlugin.WebControlUIPlugin,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={B9CA91A9-8C87-4CCA-AA1A-73DFA321CE92},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={3570C981-DCAC-4D6C-AEB0-8D4943972259},KeyPath=02:\Software\Sophos\Web Intelligence\WebControlAvailable,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: ComponentRegister(ComponentId={AEF7CD44-576B-4841-A0B4-58CEF190AFC5},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResCht.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:869]: Executing op: RegisterSharedComponentProvider(,,File=WCMResCht.92A5750A_B99C_4D18_8E96_314353D4097A,Component={AEF7CD44-576B-4841-A0B4-58CEF190AFC5},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:885]: Executing op: ComponentRegister(ComponentId={6C6EA6F0-CE05-4D37-8F3F-A957850E1AC6},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResChs.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:885]: Executing op: RegisterSharedComponentProvider(,,File=WCMResChs.92A5750A_B99C_4D18_8E96_314353D4097A,Component={6C6EA6F0-CE05-4D37-8F3F-A957850E1AC6},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:885]: Executing op: ComponentRegister(ComponentId={56B38697-86C5-4537-92A0-F2E6CEF972B7},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResIt.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:885]: Executing op: RegisterSharedComponentProvider(,,File=WCMResIt.92A5750A_B99C_4D18_8E96_314353D4097A,Component={56B38697-86C5-4537-92A0-F2E6CEF972B7},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:885]: Executing op: ComponentRegister(ComponentId={8BD71FEA-7E62-46B4-BBB2-19D4D3706BEE},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResEsp.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:901]: Executing op: RegisterSharedComponentProvider(,,File=WCMResEsp.92A5750A_B99C_4D18_8E96_314353D4097A,Component={8BD71FEA-7E62-46B4-BBB2-19D4D3706BEE},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:901]: Executing op: ComponentRegister(ComponentId={2E247D31-0A06-4AF5-ACE4-018BA1A73978},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResJap.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:901]: Executing op: RegisterSharedComponentProvider(,,File=WCMResJap.92A5750A_B99C_4D18_8E96_314353D4097A,Component={2E247D31-0A06-4AF5-ACE4-018BA1A73978},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:901]: Executing op: ComponentRegister(ComponentId={60BD5635-B25C-450A-9E36-EA84EDB18BDA},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResDeu.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:901]: Executing op: RegisterSharedComponentProvider(,,File=WCMResDeu.92A5750A_B99C_4D18_8E96_314353D4097A,Component={60BD5635-B25C-450A-9E36-EA84EDB18BDA},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:916]: Executing op: ComponentRegister(ComponentId={C5B8B969-E83E-41E3-820E-9E47E219644E},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResFra.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:916]: Executing op: RegisterSharedComponentProvider(,,File=WCMResFra.92A5750A_B99C_4D18_8E96_314353D4097A,Component={C5B8B969-E83E-41E3-820E-9E47E219644E},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:916]: Executing op: ComponentRegister(ComponentId={CA6E867B-7D76-4BBE-B278-04AFA8C84F9E},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCMResEng.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:916]: Executing op: RegisterSharedComponentProvider(,,File=WCMResEng.92A5750A_B99C_4D18_8E96_314353D4097A,Component={CA6E867B-7D76-4BBE-B278-04AFA8C84F9E},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: ComponentRegister(ComponentId={08A57BC6-9561-4F83-B710-A130F47DBA83},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WebControlMessaging.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: RegisterSharedComponentProvider(,,File=WebControlMessaging_dll.92A5750A_B99C_4D18_8E96_314353D4097A,Component={08A57BC6-9561-4F83-B710-A130F47DBA83},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: ComponentRegister(ComponentId={63138B11-92E8-4415-8064-1B9BC3A17F93},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResJap.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: RegisterSharedComponentProvider(,,File=WCPResJap.92A5750A_B99C_4D18_8E96_314353D4097A,Component={63138B11-92E8-4415-8064-1B9BC3A17F93},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: ComponentRegister(ComponentId={AE660058-42CE-44E1-8D2E-BD62AD69EE1E},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResIt.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:932]: Executing op: RegisterSharedComponentProvider(,,File=WCPResIt.92A5750A_B99C_4D18_8E96_314353D4097A,Component={AE660058-42CE-44E1-8D2E-BD62AD69EE1E},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:947]: Executing op: ComponentRegister(ComponentId={5C56F239-F279-4B01-879F-8729A44D44A0},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResFra.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:947]: Executing op: RegisterSharedComponentProvider(,,File=WCPResFra.92A5750A_B99C_4D18_8E96_314353D4097A,Component={5C56F239-F279-4B01-879F-8729A44D44A0},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:947]: Executing op: ComponentRegister(ComponentId={B43C5DBE-50BB-429B-B447-4EB82AD8554D},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResEsp.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:947]: Executing op: RegisterSharedComponentProvider(,,File=WCPResEsp.92A5750A_B99C_4D18_8E96_314353D4097A,Component={B43C5DBE-50BB-429B-B447-4EB82AD8554D},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:963]: Executing op: ComponentRegister(ComponentId={5282C6CF-9946-4B05-B59F-6638E098E3DC},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResEng.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:963]: Executing op: RegisterSharedComponentProvider(,,File=WCPResEng.92A5750A_B99C_4D18_8E96_314353D4097A,Component={5282C6CF-9946-4B05-B59F-6638E098E3DC},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:963]: Executing op: ComponentRegister(ComponentId={01CC3BCC-55E1-4B1A-906A-FB7CE1A4629B},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResDeu.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:963]: Executing op: RegisterSharedComponentProvider(,,File=WCPResDeu.92A5750A_B99C_4D18_8E96_314353D4097A,Component={01CC3BCC-55E1-4B1A-906A-FB7CE1A4629B},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:963]: Executing op: ComponentRegister(ComponentId={524153EC-3AC1-4F92-B7F5-18415FD243CB},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResCht.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:979]: Executing op: RegisterSharedComponentProvider(,,File=WCPResCht.92A5750A_B99C_4D18_8E96_314353D4097A,Component={524153EC-3AC1-4F92-B7F5-18415FD243CB},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:979]: Executing op: ComponentRegister(ComponentId={2B97F024-FE76-40AC-9D67-FF52C6A46570},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WCPResChs.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:979]: Executing op: RegisterSharedComponentProvider(,,File=WCPResChs.92A5750A_B99C_4D18_8E96_314353D4097A,Component={2B97F024-FE76-40AC-9D67-FF52C6A46570},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:979]: Executing op: ComponentRegister(ComponentId={F4BF2F3A-652E-4CBA-8B19-B7EE4E251C29},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\WebControlPlugin.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:979]: Executing op: RegisterSharedComponentProvider(,,File=WebControlPlugin.92A5750A_B99C_4D18_8E96_314353D4097A,Component={F4BF2F3A-652E-4CBA-8B19-B7EE4E251C29},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:994]: Executing op: ComponentRegister(ComponentId={F21CB2A2-E3F4-4AF7-AC06-A1A66ACA0735},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\SWCAdapter.dll,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:994]: Executing op: RegisterSharedComponentProvider(,,File=SWCAdapter.92A5750A_B99C_4D18_8E96_314353D4097A,Component={F21CB2A2-E3F4-4AF7-AC06-A1A66ACA0735},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)
    MSI (s) (0C:60) [11:29:10:994]: Executing op: ComponentRegister(ComponentId={8A03894B-68DA-452F-A18A-712256FA8A85},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\integrity.dat,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:994]: Executing op: ComponentRegister(ComponentId={6F7485F9-659C-4D3F-9EA4-017A31D3CD92},KeyPath=C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe,State=3,ProductKey={CA3CE456-B2D9-4812-8C69-17D6980432EF},,SharedDllRefCount=0,BinaryType=0)
    MSI (s) (0C:60) [11:29:10:994]: Executing op: RegisterSharedComponentProvider(,,File=swc_service.92A5750A_B99C_4D18_8E96_314353D4097A,Component={6F7485F9-659C-4D3F-9EA4-017A31D3CD92},ComponentVersion=1.5.778.0,ProductCode={CA3CE456-B2D9-4812-8C69-17D6980432EF},ProductVersion=10.6.4,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)

  • Hello Peter,

    thanks. It says:
    MSI (s) (0C:60) [11:29:05:909]: Executing op: CustomActionSchedule(Action=RemoveSIPSSubmitterUserAccount,ActionType=1025,Source=BinaryData,Target=RemoveSIPSManagementUser,CustomActionData=NT SERVICE\SAVService)
    MSI (s) (0C:88) [11:29:05:909]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI53A.tmp, Entrypoint: RemoveSIPSManagementUser
    RemoveSIPSManagementUser Enter (290)
    Failed to delete value from the registry (319)
    The value in question is at HKLM\SOFTWARE\Wow6432Node\Sophos\SAVClients\SIPSEventSubmitters named and "valued" NT SERVICE\SAVService (I have another one named NT SERVICE\SntpService). If it's there (after the rollback) it might be registry permissions (SAVService and SntpService read, SYSTEM and admin full), otherwise try to add the key/value (although I'm not sure that a failed deletion will be reported if it's not there).

    Christian

  • Hi Christian,

    Thank you. Looks like that key is there and the service is NT\SntpService. I checked the permissions SYSTEMS and Administrators have Full Control, SntPService has read but SAVService is not listed..

  • Hello Peter,

    guess the SAVService permission isn't required at this point but maybe the value is. Please add it and give it a try.

    Christian

  • Hi,

    I'll give it a try.

    Thanks

    Peter

  • Hi QC,

     

    I've the same issue here and will attach my log files here from one of the User's Machine.

    2017-11-01 12:50:52 ExtractClassicConfig: Action started
    
    2017-11-01 12:50:52 ExtractClassicConfig: Action succeeded
    
    2017-11-01 12:50:52 PreInstallChecks: Action started
    
    2017-11-01 12:50:52 PreInstallChecks: Action succeeded
    
    2017-11-01 12:50:52 SetClassFilterPresentProperty: Action started
    
    2017-11-01 12:50:52 SetClassFilterPresentProperty: Setting class filter present property to: 1
    
    2017-11-01 12:50:52 SetClassFilterPresentProperty: Action succeeded
    
    2017-11-01 12:50:52 SetDriverProperty: Action started
    
    2017-11-01 12:50:52 SetDriverProperty: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:50:52 SetDriverProperty: Action succeeded
    
    2017-11-01 12:50:52 SetProcessorProperties: Action started
    
    2017-11-01 12:50:52 SetProcessorProperties: Action succeeded
    
    2017-11-01 12:50:52 SetRestoreExcludedProcessesProperty: Action started
    
    2017-11-01 12:50:52 SetRestoreExcludedProcessesProperty: SetRestoreExcludedProcessesProperty
    
    2017-11-01 12:50:52 SetRestoreExcludedProcessesProperty: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:50:52 SetRestoreExcludedProcessesProperty: Action succeeded
    
    2017-11-01 12:50:58 CheckRegForNullDACLs: Action started
    
    2017-11-01 12:50:58 CheckRegForNullDACLs: Action succeeded
    
    2017-11-01 12:50:58 SetUpdateBegin: Action started
    
    2017-11-01 12:50:58 SetUpdateBegin: Action succeeded
    
    2017-11-01 12:50:58 CloseSavMainWindow: Action started
    
    2017-11-01 12:50:58 CloseSavMainWindow: Action succeeded
    
    2017-11-01 12:50:58 DisableServices: Action started
    
    2017-11-01 12:50:59 DisableServices: Action succeeded
    
    2017-11-01 12:51:00 ForceStopSAVService: Action started
    
    2017-11-01 12:51:00 ForceStopSAVService: ForceStopService: Stopping SAVService
    
    2017-11-01 12:51:01 ForceStopSAVService: ForceStopService: Checking if service is still running
    
    2017-11-01 12:51:01 ForceStopSAVService: ForceStopService: Stopping SAVAdminService
    
    2017-11-01 12:51:01 ForceStopSAVService: ForceStopService: Checking if service is still running
    
    2017-11-01 12:51:01 ForceStopSAVService: ForceStopSAVService: Services have been stopped
    
    2017-11-01 12:51:01 ForceStopSAVService: Action succeeded
    
    2017-11-01 12:51:01 WaitForSAVService: Action started
    
    2017-11-01 12:51:01 WaitForSAVService: WaitForSAVService: Walking system processes...
    
    2017-11-01 12:51:01 WaitForSAVService: WaitForSAVService: Finished walking system processes.
    
    2017-11-01 12:51:01 WaitForSAVService: Action succeeded
    
    2017-11-01 12:51:01 CheckUninstallDrivers: Action started
    
    2017-11-01 12:51:01 CheckUninstallDrivers: IsServiceInstalled: Unable to get a handle to requested service SAVOnAccess control. Returning false.
    
    2017-11-01 12:51:01 CheckUninstallDrivers: IsServiceInstalled: Unable to get a handle to requested service SAVOnAccess filter. Returning false.
    
    2017-11-01 12:51:01 CheckUninstallDrivers: Action succeeded
    
    2017-11-01 12:51:01 DeleteIDEs: Action started
    
    2017-11-01 12:51:01 DeleteIDEs: Action succeeded
    
    2017-11-01 12:51:01 DeleteBDLs: Action started
    
    2017-11-01 12:51:01 DeleteBDLs: Action succeeded
    
    2017-11-01 12:51:01 DeleteHIPSConfig: Action started
    
    2017-11-01 12:51:01 DeleteHIPSConfig: Action succeeded
    
    2017-11-01 12:51:01 RemoveFilesOnUpgrade: Action started
    
    2017-11-01 12:51:01 RemoveFilesOnUpgrade: Action succeeded
    
    2017-11-01 12:51:01 UpdateSavAdapterDll: Action started
    
    2017-11-01 12:51:11 UpdateSavAdapterDll: Action succeeded
    
    2017-11-01 12:51:11 UpdateDesktopMessaging: Action started
    
    2017-11-01 12:51:11 UpdateDesktopMessaging: UpdateDesktopMessaging: Could not delete SAVPlugin registry key(2)
    
    2017-11-01 12:51:11 UpdateDesktopMessaging: Action succeeded
    
    2017-11-01 12:51:11 CopyOtherFiles: Action started
    
    2017-11-01 12:51:11 CopyOtherFiles: CopyOtherFiles custom action - Copying other driver files
    
    2017-11-01 12:51:11 CopyOtherFiles: Copying class filter source: C:\ProgramData\Sophos\AutoUpdate\cache\savxp\drivers\sdcfilter\win7_amd64\SDCFILTER.INF, target: C:\Program Files (x86)\Sophos\Sophos Anti-Virus\
    
    2017-11-01 12:51:11 CopyOtherFiles: Copying boot driver source: C:\ProgramData\Sophos\AutoUpdate\cache\savxp\drivers\boottasks\win7_amd64\SOPHOSBOOTDRIVER.INF, target: C:\Program Files (x86)\Sophos\Sophos Anti-Virus\
    
    2017-11-01 12:51:11 CopyOtherFiles: GetRidOfExistingDetoured - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll detoured exists, proceeding to rename it & mark for delete.
    
    2017-11-01 12:51:11 CopyOtherFiles: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:11 CopyOtherFiles: GetRidOfExistingDetoured - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll detoured exists, proceeding to rename it & mark for delete.
    
    2017-11-01 12:51:11 CopyOtherFiles: Copying boot tasks source: C:\ProgramData\Sophos\AutoUpdate\cache\savxp\drivers\boottasks\win7_amd64\SophosBootTasks.exe, target: C:\Windows\system32\
    
    2017-11-01 12:51:11 CopyOtherFiles: Action succeeded
    
    2017-11-01 12:51:11 ForceDeleteUserPlugin: Action started
    
    2017-11-01 12:51:11 ForceDeleteUserPlugin: Error deleting DesktopMessaging registry key. Returned error was: The system cannot find the file specified.
    
    
    
    2017-11-01 12:51:11 ForceDeleteUserPlugin: Error deleting user pluging registry key. Returned error was: The system cannot find the file specified.
    
    
    
    2017-11-01 12:51:11 ForceDeleteUserPlugin: Action succeeded
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: Action started
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: BopsUnregister: could not get short path to DLL. It will not be unregistered.
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: GetRidOfExistingDetoured - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\detoured.dll does not exist, no further action.
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: BOPS path already exists
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: BOPS path already exists
    
    2017-11-01 12:51:11 RegisterBufferOverflowProtection: Action succeeded
    
    2017-11-01 12:51:11 RestoreExcludedProcesses: Action started
    
    2017-11-01 12:51:11 RestoreExcludedProcesses: RestoreExcludedProcesses
    
    2017-11-01 12:51:11 RestoreExcludedProcesses: Empty excluded processes property. Nothing to be done.
    
    2017-11-01 12:51:11 RestoreExcludedProcesses: Action succeeded
    
    2017-11-01 12:51:11 StartDriverServices: Action started
    
    2017-11-01 12:51:11 StartDriverServices: IsServiceRunning: Unable to get a handle to requested service skmscan. Returning false.
    
    2017-11-01 12:51:11 StartDriverServices: Unable to get a handle to kms service - service will not be started until next reboot
    
    2017-11-01 12:51:11 StartDriverServices: Mini filter service is running
    
    2017-11-01 12:51:11 StartDriverServices: Action succeeded
    
    2017-11-01 12:51:14 CreateUserGroups: Action started
    
    2017-11-01 12:51:14 CreateUserGroups: Unable to create local SophosUserGroup
    
    2017-11-01 12:51:14 CreateUserGroups: Unable to create local SophosPowerGroup
    
    2017-11-01 12:51:14 CreateUserGroups: Unable to create local SophosAdminGroup
    
    2017-11-01 12:51:14 CreateUserGroups: Unable to create local OnAccessGroup
    
    2017-11-01 12:51:15 CreateUserGroups: Local name of well-known group Administrators is Administrators
    
    2017-11-01 12:51:15 CreateUserGroups: Local name of well-known group PowerUsers is Power Users
    
    2017-11-01 12:51:15 CreateUserGroups: Local name of well-known group Users is Users
    
    2017-11-01 12:51:15 CreateUserGroups: SophosUser already exists - skipped adding members
    
    2017-11-01 12:51:15 CreateUserGroups: SophosPowerUser already exists - skipped adding members
    
    2017-11-01 12:51:15 CreateUserGroups: SophosAdministrator already exists - skipped adding members
    
    2017-11-01 12:51:15 CreateUserGroups: Adding LOCAL SYSTEM to the SophosAdministrator role in the machine file
    
    2017-11-01 12:51:15 CreateUserGroups: No need to restart Sophos Agent service
    
    2017-11-01 12:51:15 CreateUserGroups: Action succeeded
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Action started
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Opened key name S-1-5-21-1645522239-287218729-682003330-465432\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Unable to remove Enum sub key: 0x2
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Opened key name S-1-5-21-1645522239-287218729-682003330-465432\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories64\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Unable to remove Enum sub key: 0x2
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:15 PurgeIOfficeAVCache: Action succeeded
    
    2017-11-01 12:51:15 EnableAttachmentScanning: Action started
    
    2017-11-01 12:51:15 EnableAttachmentScanning: ScanWithAntiVirus value is already set to 3
    
    2017-11-01 12:51:15 EnableAttachmentScanning: Action succeeded
    
    2017-11-01 12:51:15 AddDomainGroups: Action started
    
    2017-11-01 12:51:15 AddDomainGroups: Found SophosDomainUser group
    
    2017-11-01 12:51:15 AddDomainGroups: Found SophosDomainPowerUser group
    
    2017-11-01 12:51:15 AddDomainGroups: Found SophosDomainAdministrator group
    
    2017-11-01 12:51:15 AddDomainGroups: Added SophosDomainAdministrator group to SophosAdministrator group
    
    2017-11-01 12:51:15 AddDomainGroups: Added SophosDomainPowerUser group to SophosPowerUser group
    
    2017-11-01 12:51:15 AddDomainGroups: Added SophosDomainUser group to SophosUser group
    
    2017-11-01 12:51:15 AddDomainGroups: Action succeeded
    
    2017-11-01 12:51:17 UpdateSAVI: Action started
    
    2017-11-01 12:51:18 UpdateSAVI: About to wait for event Global\!$_SAVI_!$$!_EVENT_$!__ReadyForUpdate
    
    2017-11-01 12:51:18 UpdateSAVI: WaitForSAVIEvent: Could not open memory mapped file Global\!$_SAVI_!$$!_MMMF_$!__
    
    2017-11-01 12:51:18 UpdateSAVI: Successfully waited for event Global\!$_SAVI_!$$!_EVENT_$!__ReadyForUpdate
    
    2017-11-01 12:51:18 UpdateSAVI: UpdateRequest signalled
    
    2017-11-01 12:51:18 UpdateSAVI: About to wait for event Global\!$_SAVI_!$$!_EVENT_$!__Suspended
    
    2017-11-01 12:51:18 UpdateSAVI: WaitForSAVIEvent: Could not open memory mapped file Global\!$_SAVI_!$$!_MMMF_$!__
    
    2017-11-01 12:51:18 UpdateSAVI: Successfully waited for event Global\!$_SAVI_!$$!_EVENT_$!__Suspended
    
    2017-11-01 12:51:18 UpdateSAVI: MSCM version orig: 0.3.0.90 new: 0.3.0.90
    
    2017-11-01 12:51:19 UpdateSAVI: SAVI dll was installed successfully
    
    2017-11-01 12:51:19 UpdateSAVI: Action succeeded
    
    2017-11-01 12:51:19 SetFolderPermissions: Action started
    
    2017-11-01 12:51:19 SetFolderPermissions: We are running on XP or higher - adding LocalService to permissions on config files
    
    2017-11-01 12:51:19 SetFolderPermissions: We are running on XP or higher - adding LocalService to permissions on config files
    
    2017-11-01 12:51:19 SetFolderPermissions: Action succeeded
    
    2017-11-01 12:51:24 CreateTamperProtectionRegKey: Action started
    
    2017-11-01 12:51:24 CreateTamperProtectionRegKey: Action succeeded
    
    2017-11-01 12:51:24 SetServiceXP: Action started
    
    2017-11-01 12:51:24 SetServiceXP: Action succeeded
    
    2017-11-01 12:51:24 SetSAVServiceSID: Action started
    
    2017-11-01 12:51:24 SetSAVServiceSID: PROCESSOR_ARCHITECTURE environment variable is: AMD64
    
    2017-11-01 12:51:24 SetSAVServiceSID: Action succeeded
    
    2017-11-01 12:51:24 SetServiceSecurity: Action started
    
    2017-11-01 12:51:25 SetServiceSecurity: Adding SYSTEM_MANDATORY_LABEL_NO_EXECUTE_UP to SavService launch permissions
    
    2017-11-01 12:51:25 SetServiceSecurity: Adding SYSTEM_MANDATORY_LABEL_NO_EXECUTE_UP to SavService launch permissions
    
    2017-11-01 12:51:25 SetServiceSecurity: Action succeeded
    
    2017-11-01 12:51:25 SetServiceRecoveryActions: Action started
    
    2017-11-01 12:51:26 SetServiceRecoveryActions: Action succeeded
    
    2017-11-01 12:51:26 InstallDeviceControl: Action started
    
    2017-11-01 12:51:26 InstallDeviceControl: InstallDeviceControlInstallDeviceControl: Failed to copy sdcservice (0x80070020)
    
    2017-11-01 12:51:26 InstallDeviceControl: Action succeeded
    
    2017-11-01 12:51:26 RemoveTamperProtectionRegKey: Action started
    
    2017-11-01 12:51:26 RemoveTamperProtectionRegKey: Action succeeded
    
    2017-11-01 12:51:35 UpdateDesktopMessaging: Action started
    
    2017-11-01 12:51:35 UpdateDesktopMessaging: UpdateDesktopMessaging: Could not delete SAVPlugin registry key(2)
    
    2017-11-01 12:51:35 UpdateDesktopMessaging: Action succeeded
    
    2017-11-01 12:51:35 RollbackUpdateSavAdapterDll: Action started
    
    2017-11-01 12:51:35 RollbackUpdateSavAdapterDll: Action succeeded
    
    2017-11-01 12:51:40 RollbackDisableServices: Action started
    
    2017-11-01 12:51:40 RollbackDisableServices: Action succeeded
    
    2017-11-01 12:51:40 RunErrorScripts: Action started
    
    2017-11-01 12:51:40 RunErrorScripts: Action succeeded
    
    2017-11-01 12:51:40 RestoreMovedFiles: Action started
    
    2017-11-01 12:51:40 RestoreMovedFiles: Action succeeded
    
    2017-11-01 12:51:40 SetUpdateFailed: Action started
    
    2017-11-01 12:51:47 SetUpdateFailed: Action succeeded
    
    

    Please advise for solution.

    Regards.

  • Hello Faisal,

    hm, it's not obvious what failure has actually been considered as fatal. What does the corresponding Install (or uninstall) log say?

    Christian