locked
Problem installing FCS 1.0 on Windows 7 Enterprise delivered via WSUS RRS feed

  • Question

  • I've created a couple of physical machines using the RTM of Windows 7.  Both are installed with Windows 7 Enterprise; 1 * x86 & 1 * x64.  We have WSUS deployed and have been using FCS with XP and Vista for some time. 

    Once I domain join the PCs, WSUS kicks in and delivers 2 updates (Silverlight & Client Update for FCS (1.0.1703.0)).  Note: we did previously experience the "post-KB971026 FCS client re-offer" issue but that was resolved subsequently with the appropriate re-sync. 

    When Windows 7 attempts to install the FCS Client it fails.  Clientsetup.log reports that "AM Installation Failed. See FCSAM.log for details". Inspecting FCSAM.log relveals this error: "DIFXAPP: ERROR - The operating system you are running on is not supported. Only Windows 2000, Windows XP, Windows Server 2003 and Windows codenamed Longhorn are supported.".  The strange thing is that this install worked fine with Windows 7 Beta and Windows 7 RC (but those reported as Windows Vista Ultimate).

    It is also worth noting that Clientsetup.log reports that the version being installed was 1710.15 rather than 1703.0 as reported by Windows Update panel. And that the O/S was detected as Windows Vista Enterprise (a reasonable expectation).

    Can anyone offer any advice on how to get FCS installed?  I've checked WSUS and there products and classifications are as expected (our clients + all classifications).  I'm currently running a Server Cleanup Wizard to see if it needs to remove anything and will try again.  I also tried taking the CLIENT directory from the installation media and running CLIENTSETUP directly on the machine but with the same outcome.  What I would like to know is if there is a way of getting hold of the very latest full client installation package and trying that rather than the initial install + updates.
    Thursday, August 20, 2009 11:30 AM

Answers

  • Hi,

     

    Thank you for your update.

     

    Unfortunately, due to the complexity of this issue we are unable to effectively assist with this request in the forum.

     

    I would like to suggest that you contact Microsoft Product Support Services via telephone so that a dedicated Support Professional can assist with this request. Please be advised that contacting phone support will be a charged call. However, if you are simply requesting a hotfix be sent to you and no other support then charges are usually refunded or waived.

     

    To obtain the phone numbers for specific technology request please take a look at the web site listed below.

     

    http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS

     

    If you are outside the US please see http://support.microsoft.com for regional support phone numbers.

     

    Thank you for your patience and understanding.

     

    Regards,


    Nick Gu - MSFT
    • Marked as answer by Nick Gu - MSFT Thursday, September 3, 2009 1:30 AM
    Tuesday, September 1, 2009 2:35 AM
  • For the benefit of the community, with technical support from Microsoft we have identified that the problem relateds to the Group Policy (Not the FCS policy) being applied to domain joined PCs.

    We have not yet identified which setting is causing the MP_AMBITS.MSI to fail but we have a workaround that involves denying the computer and user account from applying the group policy, installing FCS and then removing the deny restriction to return back to a WSUS supported state.

    I will re-post an update as we learn more.
    • Proposed as answer by SPC1972 Monday, September 14, 2009 10:28 AM
    • Marked as answer by Leazes Monday, September 14, 2009 10:29 AM
    Monday, September 14, 2009 10:28 AM

All replies

  • By way of update, if  I don't domain join the PCs I can issue CLIENTSETUP /NOMOM and it installs OK.  So can anyone think of a reason why the WSUS install would fail on the AM install?
    Sunday, August 23, 2009 3:07 PM
  • Hi,

     

    Thank you for post.

     

    Based on my experience, this issue is usually either due to permissions of the user that is installing FCS on the server or some policy that is restricting scheduled tasks on the server. Would you please verify that the user you are using to install FCS had admin rights on the server? And you we also should check whether policy was preventing the DTS scheduled task from being created.

     

    To achieve this issue, we may change the following registry key which allowed the task to be created:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa

    disabledomaincreds value is set to 0.

     

    Meanwhile, this can also happen if the FCS client is already installed.  If it is, you must remove it and allow the FCS install to install it.

     

    Regards,


    Nick Gu - MSFT
    Monday, August 24, 2009 2:52 AM
  • Hi,

     

    I ‘d like to confirm whether there is any update about this issue. if the issue still retains, please perform the following steps:

    1.Please provide the setup logs

    2.Please confirm the sku of windows 7

    3.Have they modified any application compatibility (AppCompat) rules either manually or via policy?

     

    If anything unclear, please feel free to contact us.

     

    Regards,


    Nick Gu - MSFT
    Wednesday, August 26, 2009 1:59 AM
  • Hi Nick,

    Thank you for responding.  I've tried a couple more things... and to do so I've used some virtual PCs

    On a non-domain (home) joined PC using Windows Vista Ultimate + Virtual PC 2007 SP1, I created 1 * Windows 7 Ultimate and 1 * Windows 7 Enterprise VMs (so both x86).  Neither of these PCs were domain joined and so running CLIENTSETUP /NOMOM worked fine.

    I have just now, on a domain joined Windows 7 Enterprise x64 RTM with Windows Virtual PC RC, just built 1 * Windows Vista Business & 1 * Windows 7 Professional VMs.  Both were domain joined and subsequently offered FCS via Windows Update (stating that updates were "Managed by your system administrator -> WSUS).

    The Vista VM was able to install FCS client software just fine (please note with regard to your first post the issue is about getting the client bits onto end-user PCs, the server install is ok);  So I'm satisfied that the package coming from the WSUS server is not corrupted.

    The Windows 7 Professional VM failed the installation with the same error as previous tests on physical machines with Windows 7 Enterprise x86 & x64; So it seems that my issue is not SKU specific.  As far as I can tell the important difference appears to be that if it domain joined then something is causing a problem.  I've checked the default policy on the FCS Admin Console and there is nothing there out of the ordinary (in fact, I think I accepted the default settings anyway when it was created). 

    The following logs are for the most recent attempt, a cleant Win 7 Pro x86 VM domain joined, no other software installed, run Windows Update, select FCS client install and install updates.

    Clientsetup.log:

    2009-08-26 20:38:01  Microsoft Forefront Client Security (1.0.1710.15) -- Installation started
    2009-08-26 20:38:01  The total CPU speed of %dMHz is less than the minimum required speed of 500MHz.  The recommended CPU speed is 700MHz.
    2009-08-26 20:38:01  Hardware requirement check passed.
    2009-08-26 20:38:01  The OS version running on the system is Windows Vista Business Edition.
    2009-08-26 20:38:01  OS requirement check passed.
    2009-08-26 20:38:01  Software requirement check passed.
    2009-08-26 20:38:16  MOM Installation Completed Successfully.
    2009-08-26 20:38:21  SSA Installation Completed Successfully.
    2009-08-26 20:38:24  AM Installation Failed.  See FCSAM.log for details.
    2009-08-26 20:38:24  Microsoft Forefront Client Security -- Installation failed.

    FCSAM.log to follow...

    Wednesday, August 26, 2009 7:54 PM
  • FCSAM.log:

    === Verbose logging started: 26/08/2009  20:38:21  Build type: SHIP UNICODE 5.00.7600.00  Calling process: c:\5f163a548a4b5ca76e9357cda8e4b2a7\clientsetup.exe ===
    MSI (c) (DC:10) [20:38:21:581]: Resetting cached policy values
    MSI (c) (DC:10) [20:38:21:581]: Machine policy value 'Debug' is 0
    MSI (c) (DC:10) [20:38:21:581]: ******* RunEngine:
               ******* Product: c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi
               ******* Action:
               ******* CommandLine: **********
    MSI (c) (DC:10) [20:38:21:583]: Client-side and UI is none or basic: Running entire install on the server.
    MSI (c) (DC:10) [20:38:21:583]: Grabbed execution mutex.
    MSI (c) (DC:10) [20:38:21:620]: Cloaking enabled.
    MSI (c) (DC:10) [20:38:21:620]: Attempting to enable all disabled privileges before calling Install on Server
    MSI (c) (DC:10) [20:38:21:621]: Incrementing counter to disable shutdown. Counter after increment: 0
    MSI (s) (08:14) [20:38:21:642]: Running installation inside multi-package transaction c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi
    MSI (s) (08:14) [20:38:21:642]: Grabbed execution mutex.
    MSI (s) (08:F0) [20:38:21:648]: Resetting cached policy values
    MSI (s) (08:F0) [20:38:21:648]: Machine policy value 'Debug' is 0
    MSI (s) (08:F0) [20:38:21:648]: ******* RunEngine:
               ******* Product: c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi
               ******* Action:
               ******* CommandLine: **********
    MSI (s) (08:F0) [20:38:21:649]: Machine policy value 'DisableUserInstalls' is 0
    MSI (s) (08:F0) [20:38:21:662]: SRSetRestorePoint skipped for this transaction.
    MSI (s) (08:F0) [20:38:21:669]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2
    MSI (s) (08:F0) [20:38:21:678]: File will have security applied from OpCode.
    MSI (s) (08:F0) [20:38:21:753]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi' against software restriction policy
    MSI (s) (08:F0) [20:38:21:755]: SOFTWARE RESTRICTION POLICY: c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi has a digital signature
    MSI (s) (08:F0) [20:38:21:755]: SOFTWARE RESTRICTION POLICY: c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi is permitted to run because the user token authorizes execution (system or service token).
    MSI (s) (08:F0) [20:38:21:755]: End dialog not enabled
    MSI (s) (08:F0) [20:38:21:755]: Original package ==> c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi
    MSI (s) (08:F0) [20:38:21:755]: Package we're running from ==> c:\Windows\Installer\20761.msi
    MSI (s) (08:F0) [20:38:21:761]: APPCOMPAT: unable to initialize database.
    MSI (s) (08:F0) [20:38:21:772]: MSCOREE not loaded loading copy from system32
    MSI (s) (08:F0) [20:38:21:781]: Machine policy value 'TransformsSecure' is 0
    MSI (s) (08:F0) [20:38:21:781]: User policy value 'TransformsAtSource' is 0
    MSI (s) (08:F0) [20:38:21:781]: Machine policy value 'DisablePatch' is 0
    MSI (s) (08:F0) [20:38:21:781]: Machine policy value 'AllowLockdownPatch' is 0
    MSI (s) (08:F0) [20:38:21:781]: Machine policy value 'DisableLUAPatching' is 0
    MSI (s) (08:F0) [20:38:21:781]: Machine policy value 'DisableFlyWeightPatching' is 0
    MSI (s) (08:F0) [20:38:21:785]: APPCOMPAT: unable to initialize database.
    MSI (s) (08:F0) [20:38:21:785]: Transforms are not secure.
    MSI (s) (08:F0) [20:38:21:785]: Note: 1: 2205 2:  3: Control
    MSI (s) (08:F0) [20:38:21:785]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\Program Files\Microsoft Forefront\Client Security\Client\Logs\FCSAM.log'.
    MSI (s) (08:F0) [20:38:21:785]: Command Line: REBOOT=ReallySuppress INSTALLDIR=C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware CURRENTDIRECTORY=c:\5f163a548a4b5ca76e9357cda8e4b2a7 CLIENTUILEVEL=3 CLIENTPROCESSID=3804
    MSI (s) (08:F0) [20:38:21:785]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{5B8AF6DD-2FA2-41AB-89F0-591F35A3A665}'.
    MSI (s) (08:F0) [20:38:21:785]: Product Code passed to Engine.Initialize:           ''
    MSI (s) (08:F0) [20:38:21:785]: Product Code from property table before transforms: '{436028CD-6476-4224-9274-8F0320F30FD1}'
    MSI (s) (08:F0) [20:38:21:785]: Product Code from property table after transforms:  '{436028CD-6476-4224-9274-8F0320F30FD1}'
    MSI (s) (08:F0) [20:38:21:785]: Product not registered: beginning first-time install
    MSI (s) (08:F0) [20:38:21:785]: Product {436028CD-6476-4224-9274-8F0320F30FD1} is not managed.
    MSI (s) (08:F0) [20:38:21:785]: MSI_LUA: Credential prompt not required, user is an admin
    MSI (s) (08:F0) [20:38:21:785]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
    MSI (s) (08:F0) [20:38:21:785]: Entering CMsiConfigurationManager::SetLastUsedSource.
    MSI (s) (08:F0) [20:38:21:787]: User policy value 'SearchOrder' is 'nmu'
    MSI (s) (08:F0) [20:38:21:787]: Adding new sources is allowed.
    MSI (s) (08:F0) [20:38:21:787]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
    MSI (s) (08:F0) [20:38:21:787]: Package name extracted from package path: 'mp_ambits.msi'
    MSI (s) (08:F0) [20:38:21:787]: Package to be registered: 'mp_AMBits.MSI'
    MSI (s) (08:F0) [20:38:21:803]: Note: 1: 2262 2: AdminProperties 3: -2147287038
    MSI (s) (08:F0) [20:38:21:805]: Machine policy value 'DisableMsi' is 0
    MSI (s) (08:F0) [20:38:21:805]: Machine policy value 'AlwaysInstallElevated' is 0
    MSI (s) (08:F0) [20:38:21:805]: User policy value 'AlwaysInstallElevated' is 0
    MSI (s) (08:F0) [20:38:21:805]: Product installation will be elevated because user is admin and product is being installed per-machine.
    MSI (s) (08:F0) [20:38:21:805]: Running product '{436028CD-6476-4224-9274-8F0320F30FD1}' with elevated privileges: Product is assigned.
    MSI (s) (08:F0) [20:38:21:805]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
    MSI (s) (08:F0) [20:38:21:805]: PROPERTY CHANGE: Adding INSTALLDIR property. Its value is 'C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware'.
    MSI (s) (08:F0) [20:38:21:805]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'c:\5f163a548a4b5ca76e9357cda8e4b2a7'.
    MSI (s) (08:F0) [20:38:21:805]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
    MSI (s) (08:F0) [20:38:21:805]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '3804'.
    MSI (s) (08:F0) [20:38:21:805]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0
    MSI (s) (08:F0) [20:38:21:811]: PROPERTY CHANGE: Adding MsiRestartManagerSessionKey property. Its value is '88069cdd39d6e24cb82d03964b97c3df'.
    MSI (s) (08:F0) [20:38:21:811]: RESTART MANAGER: Session opened.
    MSI (s) (08:F0) [20:38:21:811]: TRANSFORMS property is now:
    MSI (s) (08:F0) [20:38:21:811]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '200'.
    MSI (s) (08:F0) [20:38:21:823]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming
    MSI (s) (08:F0) [20:38:21:826]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Favorites
    MSI (s) (08:F0) [20:38:21:829]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    MSI (s) (08:F0) [20:38:21:833]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Documents
    MSI (s) (08:F0) [20:38:21:836]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    MSI (s) (08:F0) [20:38:21:839]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent
    MSI (s) (08:F0) [20:38:21:843]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo
    MSI (s) (08:F0) [20:38:21:846]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates
    MSI (s) (08:F0) [20:38:21:846]: SHELL32::SHGetFolderPath returned: C:\ProgramData
    MSI (s) (08:F0) [20:38:21:849]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Local
    MSI (s) (08:F0) [20:38:21:852]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Pictures
    MSI (s) (08:F0) [20:38:21:858]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    MSI (s) (08:F0) [20:38:21:861]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    MSI (s) (08:F0) [20:38:21:863]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    MSI (s) (08:F0) [20:38:21:865]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu
    MSI (s) (08:F0) [20:38:21:872]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
    MSI (s) (08:F0) [20:38:21:881]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    MSI (s) (08:F0) [20:38:21:886]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    MSI (s) (08:F0) [20:38:21:889]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    MSI (s) (08:F0) [20:38:21:892]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu
    MSI (s) (08:F0) [20:38:21:895]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Desktop
    MSI (s) (08:F0) [20:38:21:898]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
    MSI (s) (08:F0) [20:38:21:900]: SHELL32::SHGetFolderPath returned: C:\Windows\Fonts
    MSI (s) (08:F0) [20:38:21:901]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16
    MSI (s) (08:F0) [20:38:21:911]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
    MSI (s) (08:F0) [20:38:21:911]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
    MSI (s) (08:F0) [20:38:21:911]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
    MSI (s) (08:F0) [20:38:21:911]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
    MSI (s) (08:F0) [20:38:21:911]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'Authorised User'.
    MSI (s) (08:F0) [20:38:21:911]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2
    MSI (s) (08:F0) [20:38:21:911]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'c:\Windows\Installer\20761.msi'.
    MSI (s) (08:F0) [20:38:21:911]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'c:\5f163a548a4b5ca76e9357cda8e4b2a7\mp_ambits.msi'.
    MSI (s) (08:F0) [20:38:21:911]: Machine policy value 'MsiDisableEmbeddedUI' is 0
    MSI (s) (08:F0) [20:38:21:911]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic install
    MSI (s) (08:F0) [20:38:21:914]: Note: 1: 2205 2:  3: PatchPackage
    MSI (s) (08:F0) [20:38:21:914]: Machine policy value 'DisableRollback' is 0
    MSI (s) (08:F0) [20:38:21:914]: User policy value 'DisableRollback' is 0
    MSI (s) (08:F0) [20:38:21:914]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
    === Logging started: 26/08/2009  20:38:21 ===
    MSI (s) (08:F0) [20:38:21:919]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
    MSI (s) (08:F0) [20:38:21:919]: Doing action: INSTALL
    Action start 20:38:21: INSTALL.
    MSI (s) (08:F0) [20:38:21:922]: Running ExecuteSequence
    MSI (s) (08:F0) [20:38:21:922]: Doing action: AppSearch
    Action start 20:38:21: AppSearch.
    MSI (s) (08:F0) [20:38:21:925]: PROPERTY CHANGE: Adding MSI_INSTALLED property. Its value is 'c:\Windows\system32\msi.dll'.
    MSI (s) (08:F0) [20:38:21:928]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB914811 3: 2
    MSI (s) (08:F0) [20:38:21:929]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB914882 3: 2
    MSI (s) (08:F0) [20:38:21:931]: PROPERTY CHANGE: Adding DRWATSON20PATH property. Its value is '**********'.
    MSI (s) (08:F0) [20:38:21:934]: Doing action: FindRelatedProducts
    Action ended 20:38:21: AppSearch. Return value 1.
    Action start 20:38:21: FindRelatedProducts.
    MSI (s) (08:F0) [20:38:21:938]: Doing action: LaunchConditions
    Action ended 20:38:21: FindRelatedProducts. Return value 1.
    Action start 20:38:21: LaunchConditions.
    MSI (s) (08:F0) [20:38:21:950]: Doing action: ValidateProductID
    Action ended 20:38:21: LaunchConditions. Return value 1.
    Action start 20:38:21: ValidateProductID.
    MSI (s) (08:F0) [20:38:21:955]: Doing action: CostInitialize
    Action ended 20:38:21: ValidateProductID. Return value 1.
    MSI (s) (08:F0) [20:38:21:963]: Machine policy value 'MaxPatchCacheSize' is 10
    MSI (s) (08:F0) [20:38:21:970]: PROPERTY CHANGE: Adding ROOTDRIVE property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:972]: PROPERTY CHANGE: Adding CostingComplete property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: Patch
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: PatchPackage
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: MsiPatchHeaders
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: __MsiPatchFileList
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: PatchPackage
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2228 2:  3: PatchPackage 4: SELECT `DiskId`, `PatchId`, `LastSequence` FROM `Media`, `PatchPackage` WHERE `Media`.`DiskId`=`PatchPackage`.`Media_` ORDER BY `DiskId` 
    MSI (s) (08:F0) [20:38:21:974]: Note: 1: 2205 2:  3: Patch
    Action start 20:38:21: CostInitialize.
    MSI (s) (08:F0) [20:38:21:977]: Doing action: FileCost
    Action ended 20:38:21: CostInitialize. Return value 1.
    MSI (s) (08:F0) [20:38:21:979]: Note: 1: 2205 2:  3: MsiAssembly
    MSI (s) (08:F0) [20:38:21:982]: Note: 1: 2205 2:  3: Class
    MSI (s) (08:F0) [20:38:21:982]: Note: 1: 2205 2:  3: Extension
    MSI (s) (08:F0) [20:38:21:982]: Note: 1: 2205 2:  3: TypeLib
    Action start 20:38:21: FileCost.
    MSI (s) (08:F0) [20:38:21:984]: Doing action: CostFinalize
    Action ended 20:38:21: FileCost. Return value 1.
    MSI (s) (08:F0) [20:38:21:988]: PROPERTY CHANGE: Adding OutOfDiskSpace property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:988]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:988]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceAvailable property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:988]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRequired property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:988]: PROPERTY CHANGE: Adding PrimaryVolumeSpaceRemaining property. Its value is '0'.
    MSI (s) (08:F0) [20:38:21:988]: Note: 1: 2205 2:  3: Patch
    MSI (s) (08:F0) [20:38:21:988]: Note: 1: 2205 2:  3: Condition
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Adding TARGETDIR property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Adding USERPROFILE property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Adding ALLUSERSPROFILE property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Modifying TempFolder property. Its current value is 'C:\Windows\TEMP\'. Its new value: 'c:\Windows\TEMP\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Adding System64Folder property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Modifying System16Folder property. Its current value is 'C:\Windows\system\'. Its new value: 'c:\Windows\system\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Modifying StartMenuFolder property. Its current value is 'C:\ProgramData\Microsoft\Windows\Start Menu\'. Its new value: 'c:\ProgramData\Microsoft\Windows\Start Menu\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Adding ProgramFiles64Folder property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:990]: PROPERTY CHANGE: Modifying LocalAppDataFolder property. Its current value is 'C:\Windows\system32\config\systemprofile\AppData\Local\'. Its new value: 'c:\Windows\system32\config\systemprofile\AppData\Local\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Modifying CommonFilesFolder property. Its current value is 'C:\Program Files\Common Files\'. Its new value: 'c:\Program Files\Common Files\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding CommonFiles64Folder property. Its value is 'c:\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Modifying AppDataFolder property. Its current value is 'C:\Windows\system32\config\systemprofile\AppData\Roaming\'. Its new value: 'c:\Windows\system32\config\systemprofile\AppData\Roaming\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Modifying WindowsFolder property. Its current value is 'C:\Windows\'. Its new value: 'c:\Windows\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding InfFolder property. Its value is 'c:\Windows\Inf\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding WindowsPolicyFolder property. Its value is 'c:\Windows\Inf\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding WindowsTasksFolder property. Its value is 'c:\Windows\Tasks\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Modifying SystemFolder property. Its current value is 'C:\Windows\system32\'. Its new value: 'c:\Windows\system32\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding DriverFolder property. Its value is 'c:\Windows\system32\Drivers\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Modifying CommonAppDataFolder property. Its current value is 'C:\ProgramData\'. Its new value: 'c:\ProgramData\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding CommonAppDataMicrosoftFolder property. Its value is 'c:\ProgramData\Microsoft\'.
    MSI (s) (08:F0) [20:38:21:992]: PROPERTY CHANGE: Adding AppDataFolder1 property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding AppDataFolder2 property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding AppDataFolder3 property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding MsMpAppDataFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding LocalCopyFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\LocalCopy\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding SupportFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Support\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ScanLocationFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ScanHistoryFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ScanResultsFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ResultsSystemFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\System\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ScanResourceFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Resource\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding QuickResultsFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Quick\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding ScanContextsFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Contexts\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding QuarantineLocationFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Quarantine\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding SignatureRootFolder property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding Updates property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Updates\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding Default property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Default\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding Backup property. Its value is 'c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Backup\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Modifying ProgramMenuFolder property. Its current value is 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\'. Its new value: 'c:\ProgramData\Microsoft\Windows\Start Menu\Programs\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding StartMenuShortcutFolder property. Its value is 'c:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Forefront\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Modifying ProgramFilesFolder property. Its current value is 'C:\Program Files\'. Its new value: 'c:\Program Files\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding HomeDir1 property. Its value is 'c:\Program Files\Microsoft Forefront\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding HomeDir2 property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding HomeDir3 property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\Client\'.
    MSI (s) (08:F0) [20:38:21:994]: PROPERTY CHANGE: Adding HomeDir property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\'.
    MSI (s) (08:F0) [20:38:21:996]: PROPERTY CHANGE: Modifying INSTALLDIR property. Its current value is 'C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware'. Its new value: 'c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\'.
    MSI (s) (08:F0) [20:38:21:996]: PROPERTY CHANGE: Adding Symbols property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Symbols\'.
    MSI (s) (08:F0) [20:38:21:996]: PROPERTY CHANGE: Adding DRIVERS property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\'.
    MSI (s) (08:F0) [20:38:21:996]: PROPERTY CHANGE: Adding MPFILTER property. Its value is 'c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\mpfilter\'.
    MSI (s) (08:F0) [20:38:21:996]: Target path resolution complete. Dumping Directory table...
    MSI (s) (08:F0) [20:38:21:996]: Note: target paths subject to change (via custom actions or browsing)
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: TARGETDIR , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: USERPROFILE , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: ALLUSERSPROFILE , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: TempFolder , Object: c:\Windows\TEMP\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: System64Folder , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: System16Folder , Object: c:\Windows\system\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: StartMenuFolder , Object: c:\ProgramData\Microsoft\Windows\Start Menu\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: ProgramFiles64Folder , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: LocalAppDataFolder , Object: c:\Windows\system32\config\systemprofile\AppData\Local\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: CommonFilesFolder , Object: c:\Program Files\Common Files\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: CommonFiles64Folder , Object: c:\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: AppDataFolder , Object: c:\Windows\system32\config\systemprofile\AppData\Roaming\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: WindowsFolder , Object: c:\Windows\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: InfFolder , Object: c:\Windows\Inf\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: WindowsPolicyFolder , Object: c:\Windows\Inf\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: WindowsTasksFolder , Object: c:\Windows\Tasks\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: SystemFolder , Object: c:\Windows\system32\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: DriverFolder , Object: c:\Windows\system32\Drivers\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: CommonAppDataFolder , Object: c:\ProgramData\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: CommonAppDataMicrosoftFolder , Object: c:\ProgramData\Microsoft\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: AppDataFolder1 , Object: c:\ProgramData\Microsoft\Microsoft Forefront\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: AppDataFolder2 , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: AppDataFolder3 , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: MsMpAppDataFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: LocalCopyFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\LocalCopy\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: SupportFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Support\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: ScanLocationFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\
    MSI (s) (08:F0) [20:38:21:996]: Dir (target): Key: ScanHistoryFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ScanResultsFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ResultsSystemFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\System\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ScanResourceFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Resource\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: QuickResultsFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Quick\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ScanContextsFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Contexts\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: QuarantineLocationFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Quarantine\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: SignatureRootFolder , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: Updates , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Updates\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: Default , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Default\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: Backup , Object: c:\ProgramData\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Backup\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ProgramMenuFolder , Object: c:\ProgramData\Microsoft\Windows\Start Menu\Programs\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: StartMenuShortcutFolder , Object: c:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Forefront\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: ProgramFilesFolder , Object: c:\Program Files\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: HomeDir1 , Object: c:\Program Files\Microsoft Forefront\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: HomeDir2 , Object: c:\Program Files\Microsoft Forefront\Client Security\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: HomeDir3 , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: HomeDir , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: INSTALLDIR , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: Symbols , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Symbols\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: DRIVERS , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\
    MSI (s) (08:F0) [20:38:21:998]: Dir (target): Key: MPFILTER , Object: c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\mpfilter\
    MSI (s) (08:F0) [20:38:21:998]: PROPERTY CHANGE: Adding INSTALLLEVEL property. Its value is '1'.
    MSI (s) (08:F0) [20:38:22:002]: Note: 1: 2205 2:  3: MsiAssembly
    MSI (s) (08:F0) [20:38:22:002]: Note: 1: 2228 2:  3: MsiAssembly 4:  SELECT `MsiAssembly`.`Attributes`, `MsiAssembly`.`File_Application`, `MsiAssembly`.`File_Manifest`,  `Component`.`KeyPath` FROM `MsiAssembly`, `Component` WHERE  `MsiAssembly`.`Component_` = `Component`.`Component` AND `MsiAssembly`.`Component_` = ?
    Action start 20:38:21: CostFinalize.

    Wednesday, August 26, 2009 7:56 PM
  • MSI (s) (08:F0) [20:38:22:006]: Skipping action: SetFindFileParams (condition is false)
    MSI (s) (08:F0) [20:38:22:006]: Skipping action: FindGDIPlusFile (condition is false)
    MSI (s) (08:F0) [20:38:22:006]: Skipping action: GDIPlusError (condition is false)
    MSI (s) (08:F0) [20:38:22:006]: Skipping action: MigrateFeatureStates (condition is false)
    MSI (s) (08:F0) [20:38:22:006]: Doing action: InstallValidate
    Action ended 20:38:22: CostFinalize. Return value 1.
    MSI (s) (08:F0) [20:38:22:014]: PROPERTY CHANGE: Deleting MsiRestartManagerSessionKey property. Its current value is '88069cdd39d6e24cb82d03964b97c3df'.
    MSI (s) (08:F0) [20:38:22:014]: Note: 1: 2205 2:  3: Dialog
    MSI (s) (08:F0) [20:38:22:014]: Feature: MSMPService; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MSASCuiExe; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: AVPlugin; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpEngine_Default; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpAS_Sigs_Base_Default; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpAS_Sigs_Delta_Default; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpAV_Sigs_Base_Default; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpAV_Sigs_Delta_Default; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: HelpFileChm; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpSoftExDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MsMpResDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MsMpComDllPreVista; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: EventDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MPFILTER; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: OfficeAVDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpRtMonDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:014]: Component: MpService; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpSvcDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpClientDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpUtilDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MsMpLicsDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpAsDescDll; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpCmdRunExe; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MpSigDwn; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: StartupKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: RtpEventSourceKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: RtpEventMessageFileRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: RtpParameterMessageFileRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: RtpEventTypeFlagRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersShellCommandObjectKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersLinkNameRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersInfoTipRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersLinkIconRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersCommandRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersAttributesRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersNamespaceKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: SoftwareExplorersNameRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:017]: Component: MsMpComDllVista; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: MsMpComAppIdRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: MalwareProtectionKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: InstallLocationRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: RealTimeProtectionKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: CheckpointsKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ScanKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: AutoCleanAfterScanRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: AutomaticUpdatesRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: QuarantineKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ReportingKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: SoftwareExplorersKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: SignatureUpdatesKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: SpyNetKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: SpyNetReportingRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: SpyNetReportingLocationRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ThreatsKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ThreatIDDefaultActionKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ThreatTypeDefaultActionKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ThreatSeverityDefaultActionKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ExclusionsKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ExclusionsExtensionsKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ExclusionsPathsKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: ExclusionsProcessesKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: UXConfigurationKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: MiscellaneousConfigurationKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: OfficeAV1Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: OfficeAV2Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: OfficeAV3Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:019]: Component: OfficeAV8Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:021]: Component: OfficeAV4Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: OfficeAV5Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: OfficeAV6Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: OfficeAV7Registry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: OfficeAvPolicyKeyRegistry_PreVista; Installed: Absent;   Request: Local;   Action: Null
    MSI (s) (08:F0) [20:38:22:023]: Component: OfficeAvPolicyKeyRegistry_Vista; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: SampleSubmissionEventKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: SampleSubmissionEventMessageFileRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: SampleSubmissionTypesSupportedRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MinimalSafeBootKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MinimalSafeBootEntryRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: NetworkSafeBootKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: NetworkSafeBootEntryRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: EventSourceKeyRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: ServiceEventMessageFileRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: ServiceParameterMessageFileRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: EventTypeFlagRegistry; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MSASCuiExeManifestRemoval; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpQuarantineLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpSupportLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpLocalCopyLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpScheduledJobs_Scan; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpScheduledJobs_SignatureUpdate; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: InstallDirLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpAppDataLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpSignatureLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpSignatureLocationBackup; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpSignatureLocationDefault; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpSignatureLocationUpdates; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: MpScanLocation; Installed: Absent;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: __MPFILTER65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: __MSASCuiExe65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:023]: Component: __StartupKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __RtpEventSourceKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __RtpEventMessageFileRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __RtpParameterMessageFileRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __RtpEventTypeFlagRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersShellCommandObjectKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersLinkNameRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersInfoTipRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersLinkIconRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersCommandRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersAttributesRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersNamespaceKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersNameRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MsMpComDllPreVista65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MsMpComDllVista65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MsMpComAppIdRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MalwareProtectionKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __InstallLocationRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __RealTimeProtectionKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __CheckpointsKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ScanKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __AutoCleanAfterScanRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __AutomaticUpdatesRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __QuarantineKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ReportingKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SoftwareExplorersKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SignatureUpdatesKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SpyNetKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SpyNetReportingRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SpyNetReportingLocationRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ThreatsKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ThreatIDDefaultActionKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ThreatTypeDefaultActionKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ThreatSeverityDefaultActionKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ExclusionsKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ExclusionsExtensionsKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ExclusionsPathsKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __ExclusionsProcessesKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __UXConfigurationKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MiscellaneousConfigurationKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAVDll65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV1Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV2Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV3Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV8Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV4Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV5Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV6Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAV7Registry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAvPolicyKeyRegistry_PreVista65; Installed: Null;   Request: Local;   Action: Null
    MSI (s) (08:F0) [20:38:22:025]: Component: __OfficeAvPolicyKeyRegistry_Vista65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SampleSubmissionEventKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SampleSubmissionEventMessageFileRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __SampleSubmissionTypesSupportedRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MinimalSafeBootKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:025]: Component: __MinimalSafeBootEntryRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __NetworkSafeBootKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __NetworkSafeBootEntryRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __EventSourceKeyRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __ServiceEventMessageFileRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __ServiceParameterMessageFileRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Component: __EventTypeFlagRegistry65; Installed: Null;   Request: Local;   Action: Local
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: BindImage
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: ProgId
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: PublishComponent
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: SelfReg
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: Extension
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: Font
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: Class
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: Icon
    MSI (s) (08:F0) [20:38:22:027]: Note: 1: 2205 2:  3: TypeLib
    Action start 20:38:22: InstallValidate.
    MSI (s) (08:F0) [20:38:22:028]: Note: 1: 2205 2:  3: _RemoveFilePath
    MSI (s) (08:F0) [20:38:22:334]: PROPERTY CHANGE: Modifying CostingComplete property. Its current value is '0'. Its new value: '1'.
    MSI (s) (08:F0) [20:38:22:334]: Note: 1: 2205 2:  3: BindImage
    MSI (s) (08:F0) [20:38:22:334]: Note: 1: 2205 2:  3: ProgId
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: PublishComponent
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: SelfReg
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: Extension
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: Font
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: Class
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: Icon
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2205 2:  3: TypeLib
    MSI (s) (08:F0) [20:38:22:335]: Note: 1: 2727 2: 
    MSI (s) (08:F0) [20:38:22:337]: Note: 1: 2205 2:  3: FilesInUse
    MSI (s) (08:F0) [20:38:22:352]: Note: 1: 2727 2: 
    MSI (s) (08:F0) [20:38:22:354]: Doing action: StopRunningProcessW
    Action ended 20:38:22: InstallValidate. Return value 1.
    MSI (s) (08:F0) [20:38:22:356]: Note: 1: 2235 2:  3: ExtendedType 4: SELECT `Action`,`Type`,`Source`,`Target`, NULL, `ExtendedType` FROM `CustomAction` WHERE `Action` = 'StopRunningProcessW'
    MSI (s) (08:78) [20:38:22:364]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI5504.tmp, Entrypoint: StopRunningProcessW
    MSI (s) (08:38) [20:38:22:367]: Generating random cookie.
    MSI (s) (08:38) [20:38:22:376]: Created Custom Action Server with PID 3120 (0xC30).
    MSI (s) (08:10) [20:38:22:552]: Running as a service.
    MSI (s) (08:10) [20:38:22:592]: Hello, I'm your 32bit Elevated custom action server.
    MSI (s) (08!18) [20:38:22:933]: PROPERTY CHANGE: Deleting StopProcessList property. Its current value is 'MSASCui.exe MpCmdRun.exe'.
    Action start 20:38:22: StopRunningProcessW.
    MSI (s) (08:F0) [20:38:22:971]: Skipping action: SaveRegKey (condition is false)
    MSI (s) (08:F0) [20:38:22:971]: Skipping action: RemoveExistingProducts (condition is false)
    MSI (s) (08:F0) [20:38:22:971]: Doing action: InstallInitialize
    Action ended 20:38:22: StopRunningProcessW. Return value 1.
    MSI (s) (08:F0) [20:38:22:973]: Machine policy value 'AlwaysInstallElevated' is 0
    MSI (s) (08:F0) [20:38:22:973]: User policy value 'AlwaysInstallElevated' is 0
    MSI (s) (08:F0) [20:38:22:973]: BeginTransaction: Locking Server
    MSI (s) (08:F0) [20:38:22:975]: SRSetRestorePoint skipped for this transaction.
    MSI (s) (08:F0) [20:38:22:975]: Server not locked: locking for product {436028CD-6476-4224-9274-8F0320F30FD1}
    Action start 20:38:22: InstallInitialize.
    MSI (s) (08:F0) [20:38:23:299]: Doing action: AllocateRegistrySpace
    Action ended 20:38:23: InstallInitialize. Return value 1.
    Action start 20:38:23: AllocateRegistrySpace.
    MSI (s) (08:F0) [20:38:23:306]: Doing action: ProcessComponents
    Action ended 20:38:23: AllocateRegistrySpace. Return value 1.
    MSI (s) (08:F0) [20:38:23:308]: Note: 1: 2205 2:  3: MsiPatchCertificate
    MSI (s) (08:F0) [20:38:23:310]: LUA patching is disabled: missing MsiPatchCertificate table
    MSI (s) (08:F0) [20:38:23:310]: Resolving source.
    MSI (s) (08:F0) [20:38:23:310]: Resolving source to launched-from source.
    MSI (s) (08:F0) [20:38:23:310]: Setting launched-from source as last-used.
    MSI (s) (08:F0) [20:38:23:310]: PROPERTY CHANGE: Adding SourceDir property. Its value is 'c:\5f163a548a4b5ca76e9357cda8e4b2a7\'.
    MSI (s) (08:F0) [20:38:23:310]: PROPERTY CHANGE: Adding SOURCEDIR property. Its value is 'c:\5f163a548a4b5ca76e9357cda8e4b2a7\'.
    MSI (s) (08:F0) [20:38:23:310]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '{436028CD-6476-4224-9274-8F0320F30FD1}'.
    MSI (s) (08:F0) [20:38:23:310]: SOURCEDIR ==> c:\5f163a548a4b5ca76e9357cda8e4b2a7\
    MSI (s) (08:F0) [20:38:23:310]: SOURCEDIR product ==> {436028CD-6476-4224-9274-8F0320F30FD1}
    MSI (s) (08:F0) [20:38:23:310]: Determining source type
    MSI (s) (08:F0) [20:38:23:312]: Source type from package 'mp_AMBits.MSI': 2
    Wednesday, August 26, 2009 7:57 PM
  • Action start 20:38:23: ProcessComponents.
    MSI (s) (08:F0) [20:38:23:317]: Source path resolution complete. Dumping Directory table...
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: TARGETDIR , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath:  , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: USERPROFILE , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: UserProfile\ , ShortSubPath: UserProf\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: ALLUSERSPROFILE , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: All Users\ , ShortSubPath: AllUsers\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: TempFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Temp\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: System64Folder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: System64\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: System16Folder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: System\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: StartMenuFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Start Menu\ , ShortSubPath: StartMnu\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: ProgramFiles64Folder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\ , ShortSubPath: ProgramF\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: LocalAppDataFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\ , ShortSubPath: AppData\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: CommonFilesFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Common Files\ , ShortSubPath: CommonF\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: CommonFiles64Folder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Common Files\ , ShortSubPath: CommonF\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: AppDataFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\ , ShortSubPath: AppData\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: WindowsFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Windows\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: InfFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Windows\Inf\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: WindowsPolicyFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Windows\Inf\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: WindowsTasksFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Windows\Tasks\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: SystemFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: System32\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: DriverFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: System32\Drivers\ , ShortSubPath:
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: CommonAppDataFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\ , ShortSubPath: AppData\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: CommonAppDataMicrosoftFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\ , ShortSubPath: AppData\MsDir\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: AppDataFolder1 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\ , ShortSubPath: AppData\MsDir\Forefrnt\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: AppDataFolder2 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\
    MSI (s) (08:F0) [20:38:23:317]: Dir (source): Key: AppDataFolder3 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: MsMpAppDataFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: LocalCopyFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\LocalCopy\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\MpLclCpy\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: SupportFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Support\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Support\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ScanLocationFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ScanHistoryFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ScanResultsFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\Results\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ResultsSystemFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\System\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\Results\System\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ScanResourceFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Resource\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\Results\Resource\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: QuickResultsFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Results\Quick\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\Results\Quick\
    MSI (s) (08:F0) [20:38:23:319]: Dir (source): Key: ScanContextsFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Scans\History\Contexts\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\Scans\History\Contexts\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: QuarantineLocationFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Quarantine\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\MpQuar\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: SignatureRootFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\SigDir\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: Updates , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Updates\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\SigDir\Updates\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: Default , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Default\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\SigDir\Default\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: Backup , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Application Data\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Backup\ , ShortSubPath: AppData\MsDir\Forefrnt\ClientSc\Client\Antimlwr\SigDir\Backup\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: ProgramMenuFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Programs\ , ShortSubPath: ProgramM\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: StartMenuShortcutFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Programs\Microsoft Forefront\ , ShortSubPath: ProgramM\Forefrnt\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: ProgramFilesFolder , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\ , ShortSubPath: ProgramF\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: HomeDir1 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\ , ShortSubPath: ProgramF\Forefrnt\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: HomeDir2 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: HomeDir3 , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: HomeDir , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\Antimalware\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\Antimlwr\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: INSTALLDIR , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\Antimalware\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\Antimlwr\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: Symbols , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Symbols\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\Antimlwr\Symbols\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: DRIVERS , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\Antimlwr\Drivers\
    MSI (s) (08:F0) [20:38:23:321]: Dir (source): Key: MPFILTER , Object: c:\5f163a548a4b5ca76e9357cda8e4b2a7\ , LongSubPath: Program Files\Microsoft Forefront\Client Security\Client\Antimalware\Drivers\mpfilter\ , ShortSubPath: ProgramF\Forefrnt\ClientSc\Client\Antimlwr\Drivers\mpfilter\
    MSI (s) (08:F0) [20:38:23:514]: Doing action: UnpublishComponents
    Action ended 20:38:23: ProcessComponents. Return value 1.
    MSI (s) (08:F0) [20:38:23:518]: Note: 1: 2205 2:  3: PublishComponent
    MSI (s) (08:F0) [20:38:23:518]: Note: 1: 2228 2:  3: PublishComponent 4: SELECT `PublishComponent`.`ComponentId`, `PublishComponent`.`Qualifier`, `PublishComponent`.`AppData`, `Feature`, `Component`.`ComponentId`, `Component`.`RuntimeFlags` FROM `PublishComponent`, `Component`, `Feature`  WHERE `PublishComponent`.`Component_` = `Component`.`Component` AND `PublishComponent`.`Feature_` = `Feature`.`Feature` AND (`Feature`.`Action` = 0 OR ((`Feature`.`Action` = NULL OR `Feature`.`Action` = 3) AND `Component`.`Action` = 0 AND (`Feature`.`Installed` = 1 OR `Feature`.`Installed` = 2)))
    Action start 20:38:23: UnpublishComponents.
    MSI (s) (08:F0) [20:38:23:519]: Doing action: UnpublishFeatures
    Action ended 20:38:23: UnpublishComponents. Return value 0.
    Action start 20:38:23: UnpublishFeatures.
    MSI (s) (08:F0) [20:38:23:523]: Doing action: StopServices
    Action ended 20:38:23: UnpublishFeatures. Return value 1.
    Action start 20:38:23: StopServices.
    MSI (s) (08:F0) [20:38:23:536]: Skipping action: RemoveWSCInstancesProlog (condition is false)
    MSI (s) (08:F0) [20:38:23:536]: Doing action: DeleteServices
    Action ended 20:38:23: StopServices. Return value 1.
    Action start 20:38:23: DeleteServices.
    MSI (s) (08:F0) [20:38:23:541]: Doing action: RemoveRegistryValues
    Action ended 20:38:23: DeleteServices. Return value 1.
    Action start 20:38:23: RemoveRegistryValues.
    MSI (s) (08:F0) [20:38:23:554]: Doing action: RemoveShortcuts
    Action ended 20:38:23: RemoveRegistryValues. Return value 1.
    Action start 20:38:23: RemoveShortcuts.
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveScanDirProperty (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveScanDir (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveSigDirProperty (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveSigDir (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveLocalCopyDirProperty (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveLocalCopyDir (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveSupportDirProperty (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Skipping action: RemoveSupportDir (condition is false)
    MSI (s) (08:F0) [20:38:23:564]: Doing action: RemoveFiles
    Action ended 20:38:23: RemoveShortcuts. Return value 1.
    Action start 20:38:23: RemoveFiles.
    MSI (s) (08:F0) [20:38:23:571]: Doing action: RemoveFolders
    Action ended 20:38:23: RemoveFiles. Return value 1.
    Action start 20:38:23: RemoveFolders.
    MSI (s) (08:F0) [20:38:23:574]: Doing action: CreateFolders
    Action ended 20:38:23: RemoveFolders. Return value 1.
    MSI (s) (08:F0) [20:38:23:582]: Using well known SID for System
    MSI (s) (08:F0) [20:38:23:582]: Finished allocating new user SID
    MSI (s) (08:F0) [20:38:23:582]: Using well known SID for Administrators
    MSI (s) (08:F0) [20:38:23:582]: Finished allocating new user SID
    MSI (s) (08:F0) [20:38:23:582]: Using well known SID for System
    MSI (s) (08:F0) [20:38:23:582]: Finished allocating new user SID
    Action start 20:38:23: CreateFolders.
    MSI (s) (08:F0) [20:38:23:588]: Using well known SID for Everyone
    MSI (s) (08:F0) [20:38:23:588]: Finished allocating new user SID
    MSI (s) (08:F0) [20:38:23:611]: Doing action: InstallFiles
    Action ended 20:38:23: CreateFolders. Return value 1.
    Action start 20:38:23: InstallFiles.
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2205 2:  3: Patch
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2228 2:  3: Patch 4: SELECT `Patch`.`File_`, `Patch`.`Header`, `Patch`.`Attributes`, `Patch`.`Sequence`, `Patch`.`StreamRef_` FROM `Patch` WHERE `Patch`.`File_` = ? AND `Patch`.`#_MsiActive`=? ORDER BY `Patch`.`Sequence`
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2205 2:  3: MsiSFCBypass
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2228 2:  3: MsiSFCBypass 4: SELECT `File_` FROM `MsiSFCBypass` WHERE `File_` = ?
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2205 2:  3: MsiPatchHeaders
    MSI (s) (08:F0) [20:38:23:636]: Note: 1: 2228 2:  3: MsiPatchHeaders 4: SELECT `Header` FROM `MsiPatchHeaders` WHERE `StreamRef` = ?
    MSI (s) (08:F0) [20:38:23:643]: Note: 1: 2205 2:  3: PatchPackage
    MSI (s) (08:F0) [20:38:23:643]: Note: 1: 2205 2:  3: MsiPatchHeaders
    MSI (s) (08:F0) [20:38:23:643]: Note: 1: 2205 2:  3: PatchPackage
    MSI (s) (08:F0) [20:38:23:718]: Doing action: MsiProcessDrivers
    Action ended 20:38:23: InstallFiles. Return value 1.
    MSI (s) (08:F0) [20:38:23:722]: Note: 1: 2235 2:  3: ExtendedType 4: SELECT `Action`,`Type`,`Source`,`Target`, NULL, `ExtendedType` FROM `CustomAction` WHERE `Action` = 'MsiProcessDrivers'
    MSI (s) (08:A4) [20:38:23:734]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI5A58.tmp, Entrypoint: ProcessDriverPackages
    Action start 20:38:23: MsiProcessDrivers.
    DIFXAPP: ENTER: ProcessDriverPackages()
    DIFXAPP: ERROR - The operating system you are running on is not supported. Only Windows 2000, Windows XP, Windows Server 2003 and Windows codenamed Longhorn are supported.
    CustomAction MsiProcessDrivers returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
    MSI (s) (08:F0) [20:38:23:848]: Machine policy value 'DisableRollback' is 0
    MSI (s) (08:F0) [20:38:23:848]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    Action ended 20:38:23: MsiProcessDrivers. Return value 3.
    MSI (s) (08:F0) [20:38:23:851]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    MSI (s) (08:F0) [20:38:23:854]: No System Restore sequence number for this installation.
    MSI (s) (08:F0) [20:38:23:854]: Unlocking Server
    Action ended 20:38:23: INSTALL. Return value 3.
    MSI (s) (08:F0) [20:38:23:927]: Note: 1: 1708
    MSI (s) (08:F0) [20:38:23:927]: Product: Microsoft Forefront Client Security Antimalware Service -- Installation failed.

    MSI (s) (08:F0) [20:38:23:934]: Windows Installer installed the product. Product Name: Microsoft Forefront Client Security Antimalware Service. Product Version: 1.5.1937.3. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1603.

    MSI (s) (08:F0) [20:38:23:949]: Deferring clean up of packages/files, if any exist
    MSI (s) (08:F0) [20:38:23:949]: MainEngineThread is returning 1603
    MSI (s) (08:14) [20:38:23:974]: RESTART MANAGER: Session closed.
    MSI (s) (08:14) [20:38:23:974]: No System Restore sequence number for this installation.
    === Logging stopped: 26/08/2009  20:38:23 ===
    MSI (s) (08:14) [20:38:23:982]: User policy value 'DisableRollback' is 0
    MSI (s) (08:14) [20:38:23:982]: Machine policy value 'DisableRollback' is 0
    MSI (s) (08:14) [20:38:23:982]: Incrementing counter to disable shutdown. Counter after increment: 0
    MSI (s) (08:14) [20:38:23:984]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    MSI (s) (08:14) [20:38:23:986]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    MSI (s) (08:14) [20:38:23:990]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied.  Counter after decrement: -1
    MSI (s) (08:14) [20:38:23:992]: Restoring environment variables
    MSI (s) (08:14) [20:38:23:999]: Destroying RemoteAPI object.
    MSI (s) (08:38) [20:38:24:000]: Custom Action Manager thread ending.
    MSI (c) (DC:10) [20:38:24:014]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied.  Counter after decrement: -1
    MSI (c) (DC:10) [20:38:24:019]: MainEngineThread is returning 1603
    === Verbose logging stopped: 26/08/2009  20:38:24 ===

     

    Wednesday, August 26, 2009 7:57 PM
  • A further update...

    Using the domain joined VM and a locally copied version of the CLIENT directory from the FCS media, I was able to successfully install FCS using the command line so long as I specified the /MS /CG switches.  All aspects of the installation completed and I was able to load the FCS Client.

    WSUS then did a refresh and pushed KB971026 down to the VM.  When I tried to install it from Windows Update panel in Windows 7, it failed.

    I then downloaded the files from the Windows Update Catalog and attempted to run the exe file but it errored and pointed me at "mp_ambits.log".

    To the untrained eye that log looks a lot like the other log posted before when trying to install the initial package.

    So, I'm now stuck with a partial install of FCS but without a means to apply the latest client update.

    Does the input about getting it to install using the switches provide any further insight into my problem?
    Monday, August 31, 2009 5:57 PM
  • Hi,

     

    Thank you for your update.

     

    Unfortunately, due to the complexity of this issue we are unable to effectively assist with this request in the forum.

     

    I would like to suggest that you contact Microsoft Product Support Services via telephone so that a dedicated Support Professional can assist with this request. Please be advised that contacting phone support will be a charged call. However, if you are simply requesting a hotfix be sent to you and no other support then charges are usually refunded or waived.

     

    To obtain the phone numbers for specific technology request please take a look at the web site listed below.

     

    http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS

     

    If you are outside the US please see http://support.microsoft.com for regional support phone numbers.

     

    Thank you for your patience and understanding.

     

    Regards,


    Nick Gu - MSFT
    • Marked as answer by Nick Gu - MSFT Thursday, September 3, 2009 1:30 AM
    Tuesday, September 1, 2009 2:35 AM
  • For the benefit of the community, with technical support from Microsoft we have identified that the problem relateds to the Group Policy (Not the FCS policy) being applied to domain joined PCs.

    We have not yet identified which setting is causing the MP_AMBITS.MSI to fail but we have a workaround that involves denying the computer and user account from applying the group policy, installing FCS and then removing the deny restriction to return back to a WSUS supported state.

    I will re-post an update as we learn more.
    • Proposed as answer by SPC1972 Monday, September 14, 2009 10:28 AM
    • Marked as answer by Leazes Monday, September 14, 2009 10:29 AM
    Monday, September 14, 2009 10:28 AM