This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows Error 0x80041f08 When Uninstalling 9.5

Hi All,

I am attempting to upgrade a number of installations from 9.5 to 10.0. One Windows 7 Enterprise machine is throwing errors when the install package attenpts to uninstall 9.5. 

error 0x80041f08

Any advice on how to proceed?

Thanks,

Jason

:39389


This thread was automatically locked due to age.
  • Hello Jason,

    while this is a specific error code (namely, Uninstalling an older Sophos product failed) it does not tell you the specific reason for the failure to uninstall. Please check the Sophos Anti-Virus Uninstall log.txt if present in \Windows\TEMP. (search for Return value 3) or the ALUpdate log in ProgramData\Sophos\AutoUpdate\Logs. There's a number of possible reasons so I can't say what exactly to look for. 

    Christian 

    :39391
  • Hi Christian,

    I have grabbed the Sophos Anti-Virus Uninstall log.txt (about 11Mb). There was no log in \ProgramData\Sophos\AutoUpdate\Logs. I searched "Return value 3" and there were two instances. What should I be looking for now?

    Thanks,

    Jason

    :39621
  • Hello Jason,

    Return value 3 - usually one of the preceding lines contains the relevant error message, if not then at least they should tell which action encountered the error. If you are not sure please just post the snippets (about a dozen lines or so) up to and including the Return value 3

    There was no log in \ProgramData\Sophos\AutoUpdate\Logs - strange, if the folder exists there should be logs ...

    Christian

    :39623
  • Here are the preceeding lines:

    [code]

    MSI (s) (40:F0) [15:32:12:719]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages,,BinaryType=1,,)
    MSI (s) (40:F0) [15:32:12:720]: Executing op: RegRemoveValue(Name=C:\Windows\Installer\2b49d6ea.msi,Value=#0,)
    MSI (s) (40:F0) [15:32:12:720]: Executing op: RegRemoveKey()
    MSI (s) (40:F0) [15:32:12:720]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages 3: 2
    MSI (s) (40:F0) [15:32:12:721]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D414BCA974396B044A35E5BFD25BD9AF\Transforms,,BinaryType=1,,)
    MSI (s) (40:F0) [15:32:12:721]: Executing op: RegRemoveKey()
    MSI (s) (40:F0) [15:32:12:722]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D414BCA974396B044A35E5BFD25BD9AF\Transforms 3: 2
    MSI (s) (40:F0) [15:32:12:722]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=0)
    MSI (s) (40:F0) [15:32:12:722]: Error in rollback skipped. Return: 5
    MSI (s) (40:F0) [15:32:12:728]: Note: 1: 2318 2:
    MSI (s) (40:F0) [15:32:12:729]: No System Restore sequence number for this installation.
    MSI (s) (40:F0) [15:32:12:729]: Unlocking Server
    MSI (s) (40:F0) [15:32:12:780]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
    Action ended 15:32:12: INSTALL. Return value 3.[/code]

    Is this indicating a registry problem?

    :39645
  • Hello Jason,

    Is this indicating a registry problem?

    Can't say - the RegRemoveKey() operations fail because the keys do not exist but that might be normal, this seems to be the rollback and might just try to delete all potential leftover keys.

    You said you see two Return value 3 in the logs - what about the first (earlier) one - I assume this one is from near the end?

    Christian

    :39649
  • Here is the previous instance of return value 3:

    MSI (s) (40:F0) [15:31:23:408]: Note: 1: 1402 2: UNKNOWN32\BHOManagement.BHOManager.1 3: 2
    MSI (s) (40:F0) [15:31:23:408]: Note: 1: 1402 2: UNKNOWN32\BHOManagement.BHOManager 3: 2
    MSI (s) (40:F0) [15:31:23:408]: Executing op: RegProgIdInfoUnregister(ProgId=BHOManagement.WebScanningProcessorFac.1,ClsId={CBF2C689-09FC-48E8-8AB7-2B1D33A6FD25},,Description=WebScanningProcessorFactory Class,,,VIProgId=BHOManagement.WebScanningProcessorFacto,VIProgIdDescription=WebScanningProcessorFactory Class,,)
    MSI (s) (40:F0) [15:31:23:409]: Note: 1: 1402 2: UNKNOWN32\BHOManagement.WebScanningProcessorFac.1 3: 2
    MSI (s) (40:F0) [15:31:23:409]: Note: 1: 1402 2: UNKNOWN32\BHOManagement.WebScanningProcessorFacto 3: 2
    MSI (s) (40:F0) [15:31:23:409]: Executing op: ActionStart(Name=RemoveShortcuts,Description=Removing shortcuts,Template=Shortcut: [1])
    MSI (s) (40:F0) [15:31:23:409]: Executing op: SetTargetFolder(Folder=23\Sophos\Sophos Endpoint Security and Control\)
    MSI (s) (40:F0) [15:31:23:415]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    MSI (s) (40:F0) [15:31:23:415]: Executing op: ShortcutRemove(Name=VISITW~1.COM|Visit www.sophos.com)
    MSI (s) (40:F0) [15:31:23:420]: Verifying accessibility of file: Visit www.sophos.com.lnk
    MSI (s) (40:F0) [15:31:23:421]: Using source file security for destination.
    MSI (s) (40:F0) [15:31:23:440]: Note: 1: 2318 2:
    MSI (s) (40:F0) [15:31:23:442]: Executing op: ShortcutRemove(Name=SOPHOS~1|Sophos Endpoint Security and Control)
    MSI (s) (40:F0) [15:31:23:447]: Verifying accessibility of file: Sophos Endpoint Security and Control.lnk
    MSI (s) (40:F0) [15:31:23:447]: Using source file security for destination.
    MSI (s) (40:F0) [15:31:23:463]: Note: 1: 2318 2:
    MSI (s) (40:F0) [15:31:23:467]: Executing op: ActionStart(Name=RevealMSXML4,,)
    MSI (s) (40:F0) [15:31:23:469]: Executing op: CustomActionSchedule(Action=RevealMSXML4,ActionType=1025,Source=BinaryData,Target=RevealMSXML4,)
    MSI (s) (40:BC) [15:31:23:476]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI3108.tmp, Entrypoint: RevealMSXML4
    MSI (s) (40:F0) [15:31:23:507]: Executing op: ActionStart(Name=RemoveSAVI,,)
    MSI (s) (40:F0) [15:31:23:508]: Executing op: CustomActionSchedule(Action=RemoveSAVI,ActionType=1025,Source=BinaryData,Target=RemoveSAVI,CustomActionData=C:\Program Files (x86)\Sophos\Sophos Anti-Virus\)
    MSI (s) (40:AC) [15:31:23:514]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI3129.tmp, Entrypoint: RemoveSAVI
    MSI (s) (40:F0) [15:31:23:551]: Executing op: ActionStart(Name=UninstallBootDriver64Vista,,)
    MSI (s) (40:F0) [15:31:23:552]: Executing op: CustomActionSchedule(Action=UninstallBootDriver64Vista,ActionType=1058,Source=C:\Windows\SysWOW64\,Target=C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOSBOOTDRIVER.INF",)
    MSI (s) (40:F0) [15:31:23:555]: Note: 1: 1721 2: UninstallBootDriver64Vista 3: C:\Windows\SysWOW64\ 4: C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOSBOOTDRIVER.INF"
    MSI (s) (40:F0) [15:31:23:556]: Product: Sophos Anti-Virus -- Error 1721.There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: UninstallBootDriver64Vista, location: C:\Windows\SysWOW64\, command: C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE /lhu "C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOSBOOTDRIVER.INF"

    MSI (s) (40:F0) [15:31:23:567]: User policy value 'DisableRollback' is 0
    MSI (s) (40:F0) [15:31:23:567]: Machine policy value 'DisableRollback' is 0
    Action ended 15:31:23: InstallFinalize. Return value 3.

    Thanks,

    Jason

    :39679
  • Hello Jason,

    looks like either C:\Program Files (x86)\Sophos\Sophos Anti-Virus\NATIVE.EXE or C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOSBOOTDRIVER.INF is missing.

    Christian

    :39711
  • Hi Christian,

    So if I replace those from an existing 9.5 install I should be able to do the reinstall on the problematic machine?

    Thanks,

    Jason

    :39759
  • Hello Jason,

    right - assuming it is the only issue. At least it won't make it worse :smileyhappy:

    Christian

    :39765
  • Hi Christian,

    I restored those two files (the NATIVE.EXE and the INF file) and it still would not complete the install. Here is the output of the uninstall log with the "return value 3" details:

    MSI (s) (40:F0) [15:32:12:720]: Executing op: RegRemoveValue(Name=C:\Windows\Installer\2b49d6ea.msi,Value=#0,)
    MSI (s) (40:F0) [15:32:12:720]: Executing op: RegRemoveKey()
    MSI (s) (40:F0) [15:32:12:720]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages 3: 2
    MSI (s) (40:F0) [15:32:12:721]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D414BCA974396B044A35E5BFD25BD9AF\Transforms,,BinaryType=1,,)
    MSI (s) (40:F0) [15:32:12:721]: Executing op: RegRemoveKey()
    MSI (s) (40:F0) [15:32:12:722]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D414BCA974396B044A35E5BFD25BD9AF\Transforms 3: 2
    MSI (s) (40:F0) [15:32:12:722]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=0)
    MSI (s) (40:F0) [15:32:12:722]: Error in rollback skipped. Return: 5
    MSI (s) (40:F0) [15:32:12:728]: Note: 1: 2318 2:
    MSI (s) (40:F0) [15:32:12:729]: No System Restore sequence number for this installation.
    MSI (s) (40:F0) [15:32:12:729]: Unlocking Server
    MSI (s) (40:F0) [15:32:12:780]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.
    Action ended 15:32:12: INSTALL. Return value 3.

    Any further suggestions?

    Thanks,

    Jason

    :39897