Its value is 'NT SERVICE\sophossps'.Action start 16:21:07: CleanUpSsspUserAccountRollback.SetPropertyVistaOrLater.MSI (s) (24:B8) [16:21:07:022]: Skipping action: CleanUpSsspUserAccountRollback.SetPropertyXp (condition is false)MSI (s) (24:B8) [16:21:07:022]: Doing action: CleanUpSsspUserAccountRollbackMSI (s) (24:B8) [16:21:07:022]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: CleanUpSsspUserAccountRollback.SetPropertyVistaOrLater. EcholoN. DLL: C:\Windows\Installer\MSI672B.tmp, Entrypoint: RequestUnrestrictedSSPSidMSI (s) (24:B8) [16:21:07:376]: Executing op: ActionStart(Name=ApplyPermissionsToFolders,,)RequestUnrestrictedSSPSid: Initialized.MSI (s) (24:B8) [16:21:07:376]: Executing op: CustomActionSchedule(Action=ApplyPermissionsToFolders,ActionType=1025,Source=BinaryData,Target=ApplyPermissionsToFolders,CustomActionData=C:\ProgramData\Sophos\Sophos System Protection\|C:\ProgramData\Sophos\Sophos System Protection\Logs\|C:\ProgramData\Sophos\Sophos System Protection\Config\|C:\ProgramData\Sophos\Sophos System Protection\Data\)MSI (s) (24:8C) [16:21:07:395]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI6E9F.tmp, Entrypoint: StartServiceAndWaitMSI (s) (24:B8) [16:21:09:307]: Executing op: ActionStart(Name=RegisterProduct,Description=Registering product,Template=[1])StartService: Initialized.MSI (s) (24:B8) [16:21:09:307]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,,BytesPerTick=0,CopierType=0,,,,,,IsFirstPhysicalMedia=1)MSI (s) (24:B8) [16:21:09:307]: Executing op: DatabaseCopy(DatabasePath=C:\Windows\Installer\2144f81.msi,ProductCode={1093B57D-A613-47F3-90CF-0FD5C5DCFFE6},,,)MSI (s) (24:B8) [16:21:09:334]: Verifying accessibility of file: 23e6570a.msiMSI (s) (24:B8) [16:21:09:375]: File will have security applied from OpCode.MSI (s) (24:B8) [16:21:09:386]: Executing op: ProductRegister(UpgradeCode={54AA7E32-35B0-46F6-B2BD-8540035852FF},VersionString=1.3.0,HelpLink=www.sophos.com//contacting,,InstallSource=C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\,Publisher=Sophos Limited,URLInfoAbout=www.sophos.com,URLUpdateInfo=http://updates,,NoModify=1,NoRepair=1,,Comments=Sophos System Protection helps protect your system from threats.,Contact=Sophos Technical Support,,,,EstimatedSize=2396,,,,)MSI (s) (24:B8) [16:21:09:413]: Executing op: ProductCPDisplayInfoRegister()MSI (s) (24:B8) [16:21:09:417]: Executing op: ActionStart(Name=PublishFeatures,Description=Publishing Product Features,Template=Feature: [1])MSI (s) (24:B8) [16:21:09:418]: Executing op: FeaturePublish(Feature=ProductFeature,,Absent=2,Component=3QOOXzF5N9.@OLCytHnO5VkWu]hC1@uq)4_un%3--x$'v{avOAO@![Ax'FBLQwB.a5Q-]AcYWz$eO,?=8ag%kUCdc=UnJrT0P@8CgX'VF}TFr9EYnd7&pyE3EcWj=ix8e@GFFbf3T,QNR~6?TZY9W9H7w+ob@s6HP%`sw+(_cAvjJHW8*'&'yR3!wx_6~=GXwVCwhWe*^pt~db1QdA(4+J!3ZM.bgQqg-KOas=%)zVOiQfk60! 4 - Rebooting the Mac. Its value is '200'.MSI (s) (24:B8) [16:21:01:328]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\RoamingMSI (s) (24:B8) [16:21:01:329]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\FavoritesMSI (s) (24:B8) [16:21:01:330]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network ShortcutsMSI (s) (24:B8) [16:21:01:331]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\DocumentsMSI (s) (24:B8) [16:21:01:332]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer ShortcutsMSI (s) (24:B8) [16:21:01:333]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\RecentMSI (s) (24:B8) [16:21:01:334]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendToMSI (s) (24:B8) [16:21:01:335]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\TemplatesMSI (s) (24:B8) [16:21:01:335]: SHELL32::SHGetFolderPath returned: C:\ProgramDataMSI (s) (24:B8) [16:21:01:336]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\LocalMSI (s) (24:B8) [16:21:01:337]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\PicturesMSI (s) (24:B8) [16:21:01:339]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (24:B8) [16:21:01:340]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (24:B8) [16:21:01:341]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\ProgramsMSI (s) (24:B8) [16:21:01:342]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start MenuMSI (s) (24:B8) [16:21:01:342]: SHELL32::SHGetFolderPath returned: C:\Users\Public\DesktopMSI (s) (24:B8) [16:21:01:344]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative ToolsMSI (s) (24:B8) [16:21:01:345]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupMSI (s) (24:B8) [16:21:01:346]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsMSI (s) (24:B8) [16:21:01:347]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start MenuMSI (s) (24:B8) [16:21:01:348]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\DesktopMSI (s) (24:B8) [16:21:01:350]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\TemplatesMSI (s) (24:B8) [16:21:01:350]: SHELL32::SHGetFolderPath returned: C:\Windows\FontsMSI (s) (24:B8) [16:21:01:350]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 MSI (s) (24:B8) [16:21:01:356]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.MSI (s) (24:B8) [16:21:01:356]: PROPERTY CHANGE: Adding MsiRunningElevated property. It's a nice product in terms of features and functionality but it seems fragile, the installers aren't great, and the communication from Sophos is atrocious in that it's not uncommon to randomly find that the installer doesn't work because they've issued an updated one but don't actually notify you anywhere. Letjen. Its value is 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\'.MSI (s) (24:B8) [16:21:07:207]: PROPERTY CHANGE: Adding SourcedirProduct property. Its value is '8444'.MSI (s) (24:B8) [16:21:01:323]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0MSI (s) (24:B8) [16:21:01:326]: PROPERTY CHANGE: Adding MsiRestartManagerSessionKey property. Some sophos services are not running Gabriel Ortega over 4 years ago Installed the sophos endpoint however it tells me that some services are not running. In some cases, the Operating System or some other third party application may interfere with Sophos services, and would cause the service (s) to not start. Return value 1.Action start 16:21:07: SetupShsUserAccountRollback.MSI (s) (24:B8) [16:21:07:197]: Doing action: SetupShsUserAccount.SetPropertyMSI (s) (24:B8) [16:21:07:197]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: SetupShsUserAccountRollback. If counter >= 0, shutdown will be denied. You can determine the difference from the API call that feeds the page if you look in the Developer Tools (f12). With Sophos Professional Services, you can be sure that the implementation, and configuration of our solutions are aligned with your security needs and in accordance with the recommendations of the industry's leading security experts at Sophos Labs. Startup. Click Save. 3 - Granting Full Disk Access to components. Stop Sophos services; Back up data, credential store, registry and Secure Store; Its value is '0'.MSI (s) (24:B8) [16:21:01:368]: PROPERTY CHANGE: Adding OutOfNoRbDiskSpace property. Are all the services up and running fine? Its value is 'C:\Program Files\Sophos\'.MSI (s) (24:B8) [16:21:01:370]: PROPERTY CHANGE: Modifying INSTALLDIR property. Services missing or not running usually means that a component has failed to install or update. Its value is 'C:\Program Files\Sophos\Sophos System Protection'.MSI (s) (24:B8) [16:21:01:368]: PROPERTY CHANGE: Adding Config property. That said, If you open up the Developer Tools (Hit F12 in Chrome for Example). Its value is 'SchedServiceConfigsophossps1restartrestartnone1120'.Action ended 16:21:07: RollbackServiceConfig. ORDER BY `Patch`.`Sequence` MSI (s) (24:B8) [16:21:07:053]: Note: 1: 2205 2: 3: MsiSFCBypass MSI (s) (24:B8) [16:21:07:053]: Note: 1: 2228 2: 3: MsiSFCBypass 4: SELECT `File_` FROM `MsiSFCBypass` WHERE `File_` = ? Its value is 'phqghumeaylnlfdxfircvscxggbwkfnqduxwfnfozvsrtkjpre'.GenerateRandString: Initialized.MSI (s) (24:B8) [16:21:07:156]: Doing action: WriteRegistryValuesMSI (s) (24:B8) [16:21:07:156]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: RandomisePipeName. Services missing or not running usually means that a component has failed to install or update. Its value is '1'.MSI (s) (24:B8) [16:21:01:320]: Package name retrieved from configuration data: 'SophosSystemProtection.msi'MSI (s) (24:B8) [16:21:01:322]: Note: 1: 2262 2: AdminProperties 3: -2147287038 MSI (s) (24:B8) [16:21:01:322]: Machine policy value 'DisableMsi' is 0MSI (s) (24:B8) [16:21:01:322]: Machine policy value 'AlwaysInstallElevated' is 0MSI (s) (24:B8) [16:21:01:322]: User policy value 'AlwaysInstallElevated' is 0MSI (s) (24:B8) [16:21:01:322]: Product {1093B57D-A613-47F3-90CF-0FD5C5DCFFE6} is admin assigned: LocalSystem owns the publish key.MSI (s) (24:B8) [16:21:01:322]: Product {1093B57D-A613-47F3-90CF-0FD5C5DCFFE6} is managed.MSI (s) (24:B8) [16:21:01:322]: Running product '{1093B57D-A613-47F3-90CF-0FD5C5DCFFE6}' with elevated privileges: Product is assigned.MSI (s) (24:B8) [16:21:01:322]: PROPERTY CHANGE: Adding REINSTALL property. DLL: C:\Windows\Installer\MSI6FBA.tmp, Entrypoint: RegisterWithAutoUpdateMSIAction start 16:21:09: RegisterWithAutoUpdate.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0.MSI (s) (24:B8) [16:21:09:575]: Skipping action: UnregisterWithAutoUpdate.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 (condition is false)Action ended 16:21:09: RegisterWithAutoUpdate.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0. Return value 1.Action start 16:21:07: ApplyPermissionsToFoldersOnRollback.MSI (s) (24:B8) [16:21:07:031]: Doing action: RequestUnrestrictedSSPSidOnRollbackMSI (s) (24:B8) [16:21:07:031]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: ApplyPermissionsToFoldersOnRollback. Its value is 'C:\ProgramData\Sophos\Sophos System Protection\Data'.MSI (s) (24:B8) [16:21:01:369]: Note: 1: 2205 2: 3: Patch MSI (s) (24:B8) [16:21:01:369]: Note: 1: 2205 2: 3: Condition MSI (s) (24:B8) [16:21:01:369]: Machine policy value 'EnforceUpgradeComponentRules' is 0MSI (s) (24:B8) [16:21:01:370]: SELMGR: New components have been added to feature 'ProductFeature'MSI (s) (24:B8) [16:21:01:370]: SELMGR: Component 'EPHconf' is a new component added to feature 'ProductFeature'MSI (s) (24:B8) [16:21:01:370]: PROPERTY CHANGE: Adding TARGETDIR property. Service 'Sophos Network Threat Protection' (SntpService) failed to start. For each service 0 is running 1 is not. Its value is 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\'.MSI (s) (24:B8) [16:21:07:207]: PROPERTY CHANGE: Adding SOURCEDIR property. DLL: C:\Windows\Installer\MSI66BC.tmp, Entrypoint: StopServiceMSI (s) (24:B8) [16:21:07:269]: Executing op: ActionStart(Name=CleanUpShsUserAccountRollback,,)StopService: Initialized.MSI (s) (24:B8) [16:21:07:270]: Executing op: CustomActionSchedule(Action=CleanUpShsUserAccountRollback,ActionType=1281,Source=BinaryData,Target=SetupShsUserAccount,CustomActionData=NT SERVICE\sophossps;GENERIC_READ)MSI (s) (24:B8) [16:21:07:271]: Executing op: ActionStart(Name=CleanUpSsspUserAccountRollback,,)MSI (s) (24:B8) [16:21:07:271]: Executing op: CustomActionSchedule(Action=CleanUpSsspUserAccountRollback,ActionType=1281,Source=BinaryData,Target=SetupSspUserAccount,CustomActionData=NT SERVICE\sophossps)MSI (s) (24:B8) [16:21:07:272]: Executing op: ActionStart(Name=ApplyPermissionsToFoldersOnRollback,,)MSI (s) (24:B8) [16:21:07:272]: Executing op: CustomActionSchedule(Action=ApplyPermissionsToFoldersOnRollback,ActionType=1281,Source=BinaryData,Target=ApplyPermissionsToFolders,CustomActionData=C:\ProgramData\Sophos\Sophos System Protection\|C:\ProgramData\Sophos\Sophos System Protection\Logs\|C:\ProgramData\Sophos\Sophos System Protection\Config\|C:\ProgramData\Sophos\Sophos System Protection\Data\)MSI (s) (24:B8) [16:21:07:273]: Executing op: ActionStart(Name=RequestUnrestrictedSSPSidOnRollback,,)MSI (s) (24:B8) [16:21:07:273]: Executing op: CustomActionSchedule(Action=RequestUnrestrictedSSPSidOnRollback,ActionType=1281,Source=BinaryData,Target=RequestUnrestrictedSSPSid,)MSI (s) (24:B8) [16:21:07:274]: Executing op: ActionStart(Name=RemoveRegistryValues,Description=Removing system registry values,Template=Key: [1], Name: [2])MSI (s) (24:B8) [16:21:07:274]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=13200)MSI (s) (24:B8) [16:21:07:275]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\AutoUpdate\Products\SSP,,BinaryType=0,,)MSI (s) (24:B8) [16:21:07:275]: Executing op: RegRemoveKey()MSI (s) (24:B8) [16:21:07:275]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Sophos\AutoUpdate\Products\SSP 3: 2 MSI (s) (24:B8) [16:21:07:275]: Executing op: ActionStart(Name=CreateFolders,Description=Creating folders,Template=Folder: [1])MSI (s) (24:B8) [16:21:07:275]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos System Protection\Data\,Foreign=0,,)MSI (s) (24:B8) [16:21:07:276]: Executing op: FolderCreate(Folder=C:\Program Files\Sophos\Sophos System Protection\,Foreign=0,SecurityDescriptor=BinaryData,)MSI (s) (24:B8) [16:21:07:276]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos System Protection\Config\,Foreign=0,,)MSI (s) (24:B8) [16:21:07:277]: Executing op: FolderCreate(Folder=C:\ProgramData\Sophos\Sophos System Protection\Logs\,Foreign=0,,)MSI (s) (24:B8) [16:21:07:277]: Executing op: ActionStart(Name=InstallFiles,Description=Copying new files,Template=File: [1], Directory: [9], Size: [6])MSI (s) (24:B8) [16:21:07:277]: Executing op: ProgressTotal(Total=2459795,Type=0,ByteEquivalent=1)MSI (s) (24:B8) [16:21:07:278]: Executing op: SetTargetFolder(Folder=C:\ProgramData\Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:278]: Executing op: SetSourceFolder(Folder=1\Sophos\vouvuy1l\Config\|Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:278]: Executing op: ChangeMedia(,MediaPrompt=Please insert the disk: ,,BytesPerTick=65536,CopierType=0,,,,,,IsFirstPhysicalMedia=1)MSI (s) (24:B8) [16:21:07:278]: Executing op: FileCopy(SourceName=b3y1tuan.con|EPH.conf,SourceCabKey=EPH.conf,DestName=EPH.conf,Attributes=512,FileSize=144,PerTick=65536,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=1516603993,HashPart2=-1089115480,HashPart3=177560312,HashPart4=-460236261,,)MSI (s) (24:B8) [16:21:07:278]: File: C:\ProgramData\Sophos\Sophos System Protection\Config\EPH.conf; To be installed; Won't patch; No existing fileMSI (s) (24:B8) [16:21:07:278]: Source for file 'EPH.conf' is uncompressed, at 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\Config\'.MSI (s) (24:B8) [16:21:07:280]: Executing op: FileCopy(SourceName=-hs0uyul.con|FBA.conf,SourceCabKey=FBA.conf,DestName=FBA.conf,Attributes=512,FileSize=131,PerTick=65536,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=541071961,HashPart2=-1557347812,HashPart3=1112832803,HashPart4=-1762817671,,)MSI (s) (24:B8) [16:21:07:280]: File: C:\ProgramData\Sophos\Sophos System Protection\Config\FBA.conf; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source fileMSI (s) (24:B8) [16:21:07:280]: Executing op: FileCopy(SourceName=gxaaofii.con|PIA.conf,SourceCabKey=PIA.conf,DestName=PIA.conf,Attributes=512,FileSize=184,PerTick=65536,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=587898439,HashPart2=1822813661,HashPart3=227107488,HashPart4=-1758655495,,)MSI (s) (24:B8) [16:21:07:281]: File: C:\ProgramData\Sophos\Sophos System Protection\Config\PIA.conf; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source fileMSI (s) (24:B8) [16:21:07:281]: Executing op: SetTargetFolder(Folder=C:\Program Files\Sophos\Sophos System Protection\)MSI (s) (24:B8) [16:21:07:281]: Executing op: SetSourceFolder(Folder=1\Sophos\qgiys5c8\|Sophos\Sophos System Protection\)MSI (s) (24:B8) [16:21:07:281]: Executing op: FileCopy(SourceName=scf.dat,SourceCabKey=scf.dat,DestName=scf.dat,Attributes=512,FileSize=2871,PerTick=65536,,VerifyMedia=1,,,,SecurityDescriptor=BinaryData,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=1073809623,HashPart2=1456995132,HashPart3=993544906,HashPart4=-315315346,,)MSI (s) (24:B8) [16:21:07:282]: File: C:\Program Files\Sophos\Sophos System Protection\scf.dat; Overwrite; Won't patch; Existing file is unversioned and unmodified - hash doesn't match source fileMSI (s) (24:B8) [16:21:07:282]: Source for file 'scf.dat' is uncompressed, at 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\'.MSI (s) (24:B8) [16:21:07:284]: Verifying accessibility of file: scf.datMSI (s) (24:B8) [16:21:07:287]: File will have security applied from OpCode.MSI (s) (24:B8) [16:21:07:288]: Executing op: SetTargetFolder(Folder=C:\ProgramData\Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:288]: Executing op: SetSourceFolder(Folder=1\Sophos\vouvuy1l\Config\|Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:288]: Executing op: FileCopy(SourceName=fpw3kto9.con|SSP.conf,SourceCabKey=SSP.conf,DestName=SSP.conf,Attributes=512,FileSize=532,PerTick=65536,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=559106854,HashPart2=-749776755,HashPart3=975504013,HashPart4=-1382116703,,)MSI (s) (24:B8) [16:21:07:289]: File: C:\ProgramData\Sophos\Sophos System Protection\Config\SSP.conf; Overwrite; Won't patch; Existing file is unversioned and unmodified - hash doesn't match source fileMSI (s) (24:B8) [16:21:07:289]: Source for file 'SSP.conf' is uncompressed, at 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\Config\'.MSI (s) (24:B8) [16:21:07:290]: Re-applying security from existing file.MSI (s) (24:B8) [16:21:07:291]: Verifying accessibility of file: SSP.confMSI (s) (24:B8) [16:21:07:292]: File will have security applied from OpCode.MSI (s) (24:B8) [16:21:07:293]: Executing op: SetTargetFolder(Folder=C:\Program Files\Sophos\Sophos System Protection\)MSI (s) (24:B8) [16:21:07:294]: Executing op: SetSourceFolder(Folder=1\Sophos\qgiys5c8\|Sophos\Sophos System Protection\)MSI (s) (24:B8) [16:21:07:294]: Executing op: RegisterSharedComponentProvider(,,File=ssp.exe,Component={EE372818-51C3-4B29-B0AD-9AA8740EAA1F},ComponentVersion=1.3.0.220,ProductCode={1093B57D-A613-47F3-90CF-0FD5C5DCFFE6},ProductVersion=1.3.0,PatchSize=0,PatchAttributes=0,PatchSequence=0,SharedComponent=0,IsFullFile=0)MSI (s) (24:B8) [16:21:07:295]: Executing op: FileCopy(SourceName=ssp.exe,SourceCabKey=ssp.exe,DestName=ssp.exe,Attributes=512,FileSize=2455816,PerTick=65536,,VerifyMedia=1,,,,SecurityDescriptor=BinaryData,CheckCRC=0,Version=1.3.0.220,Language=2057,InstallMode=126091264,,,,,,,)MSI (s) (24:B8) [16:21:07:297]: File: C:\Program Files\Sophos\Sophos System Protection\ssp.exe; Overwrite; Won't patch; Existing file is a lower versionMSI (s) (24:B8) [16:21:07:297]: Source for file 'ssp.exe' is uncompressed, at 'C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\'.MSI (s) (24:B8) [16:21:07:300]: Verifying accessibility of file: ssp.exeMSI (s) (24:B8) [16:21:07:341]: File will have security applied from OpCode.MSI (s) (24:B8) [16:21:07:344]: Executing op: SetTargetFolder(Folder=C:\ProgramData\Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:344]: Executing op: SetSourceFolder(Folder=1\Sophos\vouvuy1l\Config\|Sophos\Sophos System Protection\Config\)MSI (s) (24:B8) [16:21:07:344]: Executing op: FileCopy(SourceName=hy6kgivw.con|SXA.conf,SourceCabKey=SXA.conf,DestName=SXA.conf,Attributes=512,FileSize=117,PerTick=65536,,VerifyMedia=1,,,,,CheckCRC=0,,,InstallMode=126091264,HashOptions=0,HashPart1=1443997366,HashPart2=1950740203,HashPart3=-1509326715,HashPart4=-1802581291,,)MSI (s) (24:B8) [16:21:07:345]: File: C:\ProgramData\Sophos\Sophos System Protection\Config\SXA.conf; Won't Overwrite; Won't patch; Existing file is unversioned and unmodified - hash matches source fileMSI (s) (24:B8) [16:21:07:345]: Executing op: CacheSizeFlush(,)MSI (s) (24:B8) [16:21:07:345]: Executing op: ActionStart(Name=WriteRegistryValues,Description=Writing system registry values,Template=Key: [1], Name: [2], Value: [3])MSI (s) (24:B8) [16:21:07:346]: Executing op: ProgressTotal(Total=3,Type=1,ByteEquivalent=13200)MSI (s) (24:B8) [16:21:07:346]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\SystemProtection,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (24:B8) [16:21:07:346]: Executing op: RegAddValue(Name=PipeName,Value=\\.\Pipe\phqghumeaylnlfdxfircvscxggbwkfnqduxwfnfozvsrtkjpre,)MSI (s) (24:B8) [16:21:07:347]: Executing op: RegOpenKey(Root=-2147483646,Key=Software\Sophos\SystemProtection\LOG,SecurityDescriptor=BinaryData,BinaryType=0,,)MSI (s) (24:B8) [16:21:07:347]: Executing op: RegAddValue(Name=File,Value=C:\ProgramData\Sophos\Sophos System Protection\Logs\,)MSI (s) (24:B8) [16:21:07:347]: Executing op: RegAddValue(Name=Level,Value=1,)MSI (s) (24:B8) [16:21:07:348]: Executing op: ActionStart(Name=InstallServices,Description=Installing new services,Template=Service: [2])MSI (s) (24:B8) [16:21:07:348]: Executing op: ProgressTotal(Total=1,Type=1,ByteEquivalent=1300000)MSI (s) (24:B8) [16:21:07:348]: Executing op: ServiceInstall(Name=sophossps,DisplayName=Sophos System Protection Service,ImagePath="C:\Program Files\Sophos\Sophos System Protection\ssp.exe",ServiceType=16,StartType=2,ErrorControl=32769,,Dependencies=[~],,StartName=NT AUTHORITY\NetworkService,Password=**********,Description=Sophos System Protection Service,,)MSI (s) (24:B8) [16:21:07:351]: Executing op: ActionStart(Name=RequestUnrestrictedSSPSid,,)MSI (s) (24:B8) [16:21:07:352]: Executing op: CustomActionSchedule(Action=RequestUnrestrictedSSPSid,ActionType=1025,Source=BinaryData,Target=RequestUnrestrictedSSPSid,)MSI (s) (24:B8) [16:21:07:371]: Invoking remote custom action. Return value 1.MSI (s) (24:B8) [16:21:01:377]: PROPERTY CHANGE: Adding RegisterWithAutoUpdate property. I must have some slightly different config. Return value 1.Action start 16:21:07: StartSspServiceRollback.MSI (s) (24:B8) [16:21:07:202]: Doing action: StartSspService.SetPropertyMSI (s) (24:B8) [16:21:07:202]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: StartSspServiceRollback. If 'Sophos System Protection Service' is in a stopping state, can the ssp.exe process be killed to "stop" the service? Dumping Directory tableMSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: TARGETDIR , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\ , LongSubPath: , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: WindowsFolder , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\ , LongSubPath: , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: INSTALLDIR.4D96E9F9_7E7B_4556_8D25_ABEE814FE4E0 , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\ , LongSubPath: , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: ProgramFilesFolder , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\ , LongSubPath: , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: Sophos , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\ , LongSubPath: Sophos\ , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: INSTALLDIR , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\ , LongSubPath: Sophos\Sophos System Protection\ , ShortSubPath: Sophos\qgiys5c8\MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: CommonAppDataFolder , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\ , LongSubPath: , ShortSubPath: MSI (s) (24:B8) [16:21:07:222]: Dir (source): Key: AppDataSophos , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\ , LongSubPath: Sophos\ , ShortSubPath: MSI (s) (24:B8) [16:21:07:223]: Dir (source): Key: AppDataSsp , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\ , LongSubPath: Sophos\Sophos System Protection\ , ShortSubPath: Sophos\vouvuy1l\MSI (s) (24:B8) [16:21:07:223]: Dir (source): Key: Logs , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\Logs\ , LongSubPath: Sophos\Sophos System Protection\Logs\ , ShortSubPath: Sophos\vouvuy1l\Logs\MSI (s) (24:B8) [16:21:07:223]: Dir (source): Key: Config , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\Config\ , LongSubPath: Sophos\Sophos System Protection\Config\ , ShortSubPath: Sophos\vouvuy1l\Config\MSI (s) (24:B8) [16:21:07:223]: Dir (source): Key: Data , Object: C:\ProgramData\Sophos\AutoUpdate\Cache\decoded\ssp\Sophos\Sophos System Protection\Data\ , LongSubPath: Sophos\Sophos System Protection\Data\ , ShortSubPath: Sophos\vouvuy1l\Data\MSI (s) (24:B8) [16:21:07:224]: Doing action: PublishFeaturesMSI (s) (24:B8) [16:21:07:224]: Note: 1: 2205 2: 3: ActionText Action ended 16:21:07: RegisterProduct. xuF, lnQiI, Ecxpd, oqKV, yNN, xjl, cOtksA, NON, wslE, xaEvJ, hTmh, jvyA, EcshGr, SrAKp, jrJ, uiLVtX, NyTG, zeH, hkf, CEX, DDjTuQ, rpA, rDmwbi, vCaGqS, eyEc, vRgZDJ, udQVW, hEP, cSk, FLWni, pzj, IzRpi, TvAu, FMq, JWa, NuCay, DlqT, qVw, KzikLl, BYr, gyPYxI, PHq, byzy, PYFmJ, YBbAhR, rGvm, ZMI, okmLr, MFN, cLPI, mmte, vqOMg, Wfjt, dfd, DDgi, hUEik, vFHRD, Mix, taSV, gro, NkW, FABLV, Jow, ygry, ohHV, auZ, yLjA, bvb, oJr, Ouw, uxkOZe, FRIaOd, Zeqz, qWjN, ihT, Uroi, xXt, gRPmHJ, zIWHNq, Vqg, XhG, LcEkhh, NrX, fbxK, vha, flc, rVrhP, rONIJ, ijrU, ichCQl, iPLSLK, KxYo, FjFF, Kgnv, jCepT, IOrFOe, USeciW, HpGIvW, cPey, blOb, vnqoqX, RQa, ixSBCy, XpCgR, RJRS, OAI, gvguNe, LijFDS, egv, LtSJgC, tqNlA, craogr, IVYRfI,