Endpoint protection incomplete installation and won't complete install
Symantec Endpoint Protection services crashed on Windows XP Pro machine SP3. Had to uninstall and re-install. Re-install won't complete but doesn't provide any real error message. Just that it was interrupted. I have the sep logs if I need to post them. I am posting just a portion here:
Property(S): MSIAddWFPAppException_RB.17E5C180_F281_4425_9348_3E891E7F8D1F = SMC Service;C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe;SNAC Service;C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE;Symantec Email;C:\Program Files\Common Files\Symantec Shared\ccApp.exe;
Property(S): MSIAddWFPAppException.17E5C180_F281_4425_9348_3E891E7F8D1F = SMC Service;C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe;SNAC Service;C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE;Symantec Email;C:\Program Files\Common Files\Symantec Shared\ccApp.exe;
Property(S): ProductToBeRegistered = 1
Property(S): MsiRebootActionScheduled = 1
Property(S): MsiFilterRebootMode_RebootAtEndModeBefore = 1
MSI (s) (E4:EC) [06:28:53:569]: Note: 1: 1708
MSI (s) (E4:EC) [06:28:53:569]: Product: Symantec Endpoint Protection -- Installation operation failed.
MSI (s) (E4:EC) [06:28:53:585]: MainEngineThread is returning 1603
MSI (s) (E4:E8) [06:28:53:585]: No System Restore sequence number for this installation.
=== Logging stopped: 9/16/2010 6:28:53 ===
MSI (s) (E4:E8) [06:28:53:600]: User policy value 'DisableRollback' is 0
MSI (s) (E4:E8) [06:28:53:600]: Machine policy value 'DisableRollback' is 0
MSI (s) (E4:E8) [06:28:53:600]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (E4:E8) [06:28:53:600]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (E4:E8) [06:28:53:600]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
MSI (s) (E4:E8) [06:28:53:600]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (s) (E4:E8) [06:28:53:600]: Restoring environment variables
MSI (c) (30:24) [06:28:53:600]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied. Counter after decrement: -1
MSI (c) (30:24) [06:28:53:600]: MainEngineThread is returning 1603
=== Verbose logging stopped: 9/16/2010 6:28:53 ===
Comments
hi
the log is incomplete please provide the complete log
look for return value 3; paste 50 lines above and belwo of that msg
if you have symantec LU installed. remove it from add/remove programs
install Liveupdate first
then install sep locally on the box
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Thanks for the reply. Here
Thanks for the reply. Here is more of the log. Also I did remove Live Update, install it and then tried, did cleanwipe, etc also, same results:
Module: ImagePath=C:\Program Files\Bonjour\mdnsNSP.dll
Module: ImagePath=C:\Program Files\Adenium Systems\DFS Remote Applications\DFS.Reports.dll
Module: ImagePath=C:\Program Files\UltraVNC\vnchooks.dll
Module: ImagePath=C:\Program Files\Adenium Systems\DFS Remote Applications\FarPoint.Win.Spread.dll
Module: ImagePath=C:\WINDOWS\system32\WINHTTP.dll
Module: ImagePath=C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll
Module: ImagePath=C:\WINDOWS\system32\uxtheme.dll
Module: ImagePath=C:\WINDOWS\system32\netapi32.dll
Module: ImagePath=C:\WINDOWS\system32\comctl32.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9732a7c993055f82040642966db07ccf\Microsoft.VisualBasic.ni.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll
Module: ImagePath=c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\ab688d0f9f333ba117832726bfb589c1\System.Configuration.ni.dll
Module: ImagePath=C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\f04ef00e652a8655a717639e8aeb7b63\System.Data.ni.dll
Module: ImagePath=C:\WINDOWS\system32\hnetcfg.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\15724a7517f939c9b300f341fb5620b8\System.EnterpriseServices.ni.dll
Module: ImagePath=C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
Module: ImagePath=C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\26d5bf1f7e700c2c19aa9b1da5519b24\System.Transactions.ni.dll
Module: ImagePath=C:\WINDOWS\system32\rsaenh.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\b307acf63075b997d02a97a7492d0d9c\System.Design.ni.dll
Module: ImagePath=C:\WINDOWS\system32\mswsock.dll
Module: ImagePath=C:\WINDOWS\System32\wshtcpip.dll
Module: ImagePath=C:\WINDOWS\system32\WS2HELP.dll
Module: ImagePath=C:\WINDOWS\system32\WS2_32.dll
Module: ImagePath=C:\WINDOWS\system32\SensApi.dll
Module: ImagePath=C:\WINDOWS\system32\dciman32.dll
Module: ImagePath=C:\WINDOWS\system32\MSCTF.dll
Module: ImagePath=C:\WINDOWS\system32\msctfime.ime
Module: ImagePath=C:\WINDOWS\system32\cryptnet.dll
Module: ImagePath=C:\WINDOWS\system32\IMM32.DLL
Module: ImagePath=C:\WINDOWS\system32\shfolder.dll
Module: ImagePath=C:\WINDOWS\system32\cryptdll.dll
Module: ImagePath=C:\WINDOWS\system32\userenv.dll
Module: ImagePath=C:\WINDOWS\system32\WINMM.dll
Module: ImagePath=C:\WINDOWS\system32\PSAPI.DLL
Module: ImagePath=C:\WINDOWS\system32\WINTRUST.dll
Module: ImagePath=C:\WINDOWS\system32\IMAGEHLP.dll
Module: ImagePath=C:\WINDOWS\system32\Iphlpapi.dll
Module: ImagePath=C:\WINDOWS\system32\rtutils.dll
Module: ImagePath=C:\WINDOWS\system32\rasman.dll
Module: ImagePath=C:\WINDOWS\system32\TAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\rasapi32.dll
Module: ImagePath=C:\WINDOWS\system32\DNSAPI.dll
Module: ImagePath=C:\WINDOWS\system32\WLDAP32.dll
Module: ImagePath=C:\WINDOWS\System32\winrnr.dll
Module: ImagePath=C:\WINDOWS\system32\rasadhlp.dll
Module: ImagePath=C:\WINDOWS\system32\OLEAUT32.DLL
Module: ImagePath=C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
Module: ImagePath=C:\WINDOWS\system32\ole32.dll
Module: ImagePath=C:\WINDOWS\system32\CRYPT32.dll
Module: ImagePath=C:\WINDOWS\system32\MSASN1.dll
Module: ImagePath=C:\WINDOWS\system32\version.dll
Module: ImagePath=C:\WINDOWS\system32\msvcrt.dll
Module: ImagePath=C:\WINDOWS\system32\msv1_0.dll
Module: ImagePath=C:\WINDOWS\system32\ADVAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\RPCRT4.dll
Module: ImagePath=C:\WINDOWS\system32\GDI32.dll
Module: ImagePath=C:\WINDOWS\system32\SHLWAPI.dll
Module: ImagePath=C:\WINDOWS\system32\Secur32.dll
Module: ImagePath=C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
Module: ImagePath=C:\WINDOWS\system32\mscoree.dll
Module: ImagePath=c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll
Module: ImagePath=c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\dcc0244092fe52e6885b50be25ef3b31\System.Drawing.ni.dll
Module: ImagePath=C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\439c466b60614915587c5273eaf0ca7f\System.Windows.Forms.ni.dll
Module: ImagePath=C:\WINDOWS\system32\KERNEL32.dll
Module: ImagePath=C:\WINDOWS\system32\ntdll.dll
Module: ImagePath=C:\WINDOWS\system32\shell32.dll
Module: ImagePath=C:\WINDOWS\system32\USER32.dll
CollectProcessInfo: Dumping info for Pid=4048 ImagePath=C:\TEMP\Clt-Inst\vpremote.exe
Dumping module information for the process
Module: ImagePath=C:\WINDOWS\system32\IMM32.DLL
Module: ImagePath=C:\WINDOWS\system32\Apphelp.dll
Module: ImagePath=C:\WINDOWS\system32\VERSION.dll
Module: ImagePath=C:\WINDOWS\system32\ADVAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\RPCRT4.dll
Module: ImagePath=C:\WINDOWS\system32\GDI32.dll
Module: ImagePath=C:\WINDOWS\system32\Secur32.dll
Module: ImagePath=C:\WINDOWS\system32\kernel32.dll
Module: ImagePath=C:\WINDOWS\system32\ntdll.dll
Module: ImagePath=C:\WINDOWS\system32\USER32.dll
MSI (s) (E4:EC) [06:27:14:741]: User policy value 'DisableRollback' is 0
MSI (s) (E4:EC) [06:27:14:741]: Machine policy value 'DisableRollback' is 0
Action ended 6:27:14: InstallFinalize. Return value 3.
MSI (s) (E4:EC) [06:27:14:850]: Executing op: Header(Signature=1397708873,Version=405,Timestamp=1026568901,LangId=1033,Platform=0,ScriptType=2,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: DialogInfo(Type=1,Argument=Symantec Endpoint Protection)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: RollbackInfo(,RollbackAction=Rollback,RollbackDescription=Rolling back action:,RollbackTemplate=[1],CleanupAction=RollbackCleanup,CleanupDescription=Removing backup files,CleanupTemplate=File: [1])
MSI (s) (E4:EC) [06:27:14:850]: Executing op: ActionStart(Name=CcSetMgrStart.D3A883B9_8F94_4E7D_96B6_852388CE5647,,)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: ProductInfo(ProductKey={2EFCC193-D915-4CCB-9201-31773A27BC06},ProductName=Symantec Endpoint Protection,PackageName=Symantec AntiVirus.msi,Language=1033,Version=184554378,Assignment=1,ObsoleteArg=0,ProductIcon=ARPPRODUCTICON.exe,,PackageCode={F62D9433-DFA4-4A64-A178-6FFB9D82148A},,,InstanceType=0,LUASetting=0,RemoteURTInstalls=0,ProductDeploymentFlags=3)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: ActionStart(Name=CcSetMgrStart_Rol.D3A883B9_8F94_4E7D_96B6_852388CE5647,,)
MSI (s) (E4:EC) [06:27:14:850]: Executing op: CustomActionRollback(Action=CcSetMgrStart_Rol.D3A883B9_8F94_4E7D_96B6_852388CE5647,ActionType=3329,Source=BinaryData,Target=_CcSetMgrShutdown@4,)
MSI (s) (E4:8C) [06:27:14:882]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI96.tmp, Entrypoint: _CcSetMgrShutdown@4
2010-09-16-06-27-14-944 : cc::StopServiceAndDepAtAnyCost(380) : The service ccSetMgr is already stopped. Current state=1
MSIRESULT PASS - CcSetMgrShutdown: Able to successfully stop ccSetMgr:
MSIASSERT - 2010-09-16-06-27-14-944 : CMutex::Open() : OpenMutex() == NULL, Global\ccSetMgr_Single_Instance_Lock, 0x00000002
:
CcSetMgrShutdown:
MSI (s) (E4:EC) [06:27:14:944]: Executing op: ActionStart(Name=SevInstUninstallWorkAround.93C43188_D2F5_461E_B42B_C3A2A318345C,Description=Configuring SymEvent,)
MSI (s) (E4:EC) [06:27:14:944]: Executing op: ActionStart(Name=MsiInstallWps.AFD7E729_F6AF_4E0F_912C_CF8E6A1326EF,Description=Installing Firewall drivers,)
MSI (s) (E4:EC) [06:27:14:944]: Executing op: ActionStart(Name=MsiInstallWps_RB.AFD7E729_F6AF_4E0F_912C_CF8E6A1326EF,,)
MSI (s) (E4:EC) [06:27:14:944]: Executing op: CustomActionRollback(Action=MsiInstallWps_RB.AFD7E729_F6AF_4E0F_912C_CF8E6A1326EF,ActionType=3329,Source=BinaryData,Target=MsiUninstallWps,CustomActionData=C:\Program Files\Symantec\Symantec Endpoint Protection\)
MSI (s) (E4:B8) [06:27:14:975]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI97.tmp, Entrypoint: MsiUninstallWps
FWMainCA: Wps successfully uninstalled.
MSI (s) (E4:EC) [06:27:15:069]: Executing op: ActionStart(Name=InstallSysPlant.CE633825_BB8F_4C40_8B94_769CF5D8253E,Description=Installing Device Protection driver,)
MSI (s) (E4:EC) [06:27:15:069]: Executing op: ActionStart(Name=InstallSysPlant_RB.CE633825_BB8F_4C40_8B94_769CF5D8253E,,)
MSI (s) (E4:EC) [06:27:15:069]: Executing op: CustomActionRollback(Action=InstallSysPlant_RB.CE633825_BB8F_4C40_8B94_769CF5D8253E,ActionType=3329,Source=BinaryData,Target=UninstallSysPlant,)
MSI (s) (E4:B0) [06:27:15:069]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI98.tmp, Entrypoint: UninstallSysPlant
SPAMAINCA: DeleteDriverService DeleteService worked for service SysPlant.
MSI (s) (E4:EC) [06:27:15:100]: Executing op: ActionStart(Name=WGXInstallHelper.D8CB2A9F_8EC6_4EF2_B650_B6951138D94F,Description=Installing NAC driver,)
MSI (s) (E4:EC) [06:27:15:100]: Executing op: ActionStart(Name=StartEventLogService.03FE01CF_295E_4354_A292_7DC4A810E0DA,,)
MSI (s) (E4:EC) [06:27:15:100]: Executing op: ActionStart(Name=StartEventLogService_Rol.03FE01CF_295E_4354_A292_7DC4A810E0DA,,)
MSI (s) (E4:EC) [06:27:15:100]: Executing op: CustomActionRollback(Action=StartEventLogService_Rol.03FE01CF_295E_4354_A292_7DC4A810E0DA,ActionType=1281,Source=BinaryData,Target=_StartEventLogService_Rol@4,)
MSI (s) (E4:18) [06:27:15:116]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI99.tmp, Entrypoint: _StartEventLogService_Rol@4
MSIRESULT PASS - MsiHelper::CMsiDefRegArchive::Init: Start Initialization:
MSIRESULT PASS - MsiHelper::CMsiDefRegArchive::Init: Getting custom action data:
MSIRESULT PASS - MsiHelper::CMsiDefRegArchive::Init: szFileName == '':
StartEventLogService_Rol: Skipping custom action
MSI (s) (E4:EC) [06:27:15:147]: Executing op: ActionStart(Name=WriteCcServiceRegistry.D9F570F7_4F5A_41B0_9D99_89851EE85080,,)
MSI (s) (E4:EC) [06:27:15:147]: Executing op: ActionStart(Name=WriteCcServiceRegistryRol.D9F570F7_4F5A_41B0_9D99_89851EE85080,,)
MSI (s) (E4:EC) [06:27:15:147]: Executing op: CustomActionRollback(Action=WriteCcServiceRegistryRol.D9F570F7_4F5A_41B0_9D99_89851EE85080,ActionType=3329,Source=BinaryData,Target=_DeleteCcServiceEntries@4,CustomActionData=C:\WINDOWS\TEMP\CCI4B.tmp)
MSI (s) (E4:30) [06:27:15:163]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI9A.tmp, Entrypoint: _DeleteCcServiceEntries@4
MSIRESULT PASS - ccMSIUtil::GetSettingsFromFile: strFileName == 'C:\WINDOWS\TEMP\CCI4B.tmp':
2010-09-16-06-27-15-178 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {740AB61D-8B4A-46CC-9D82-86F72E055477} (use count 1)
2010-09-16-06-27-15-194 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {9958D891-C319-4C6C-BEB9-F9BFB37EA493} (use count 1)
2010-09-16-06-27-15-194 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {3F05A321-43B7-4578-93C8-CDC5F64A149A} (use count 1)
2010-09-16-06-27-15-194 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {31324564-3B13-4533-8999-33990688F5A9} (use count 1)
2010-09-16-06-27-15-194 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
MSIASSERT - DeleteServiceEntries: No running instance. hr == 0x80040200:
MSIASSERT - DeleteServiceEntries: No running instance. hr == 0x80040200:
MSIASSERT - DeleteServiceEntries: No running instance. hr == 0x80040200:
MSI (s) (E4:EC) [06:27:15:257]: Executing op: ActionStart(Name=WriteCcServiceRegistryRepair.D9F570F7_4F5A_41B0_9D99_89851EE85080,,)
MSI (s) (E4:EC) [06:27:15:257]: Executing op: CustomActionRollback(Action=WriteCcServiceRegistryRepair.D9F570F7_4F5A_41B0_9D99_89851EE85080,ActionType=3329,Source=BinaryData,Target=_WriteCcServiceRegistry@4,CustomActionData=C:\WINDOWS\TEMP\CCI4C.tmp)
MSI (s) (E4:DC) [06:27:15:272]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MSI9B.tmp, Entrypoint: _WriteCcServiceRegistry@4
MSIRESULT PASS - ccMSIUtil::GetSettingsFromFile: strFileName == 'C:\WINDOWS\TEMP\CCI4C.tmp':
2010-09-16-06-27-15-288 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {740AB61D-8B4A-46CC-9D82-86F72E055477} (use count 1)
2010-09-16-06-27-15-288 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {9958D891-C319-4C6C-BEB9-F9BFB37EA493} (use count 1)
2010-09-16-06-27-15-288 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {3F05A321-43B7-4578-93C8-CDC5F64A149A} (use count 1)
2010-09-16-06-27-15-303 : ccSym::CInstanceFactoryImpl::addFactory(1036) : Registered factory for {31324564-3B13-4533-8999-33990688F5A9} (use count 1)
MSIASSERT - 2010-09-16-06-27-15-303 : CFile::Read() : ReadFile() == FALSE, 0x00000000
:
MSIASSERT - 2010-09-16-06-27-15-303 : CStreamArchive::ReadEx() : m_pStream->Read() == false
:
MSIASSERT - 2010-09-16-06-27-15-303 : ccLib::CArchive::Read(1052) : ReadEx() == FALSE
:
MSIASSERT - 2010-09-16-06-27-15-303 : ccSym::CValueCollection::Load(3038) : Archive.Read() == FALSE
:
MSIASSERT - 2010-09-16-06-27-15-303 : ccSym::CIndexValueCollection::Load(499) : CValueCollection::Load() == false
:
MSIASSERT - 2010-09-16-06-27-15-303 : CSerialize::Load() : Load() == FALSE
:
MSIASSERT - ccMSIUtil::GetSettingsFromFile: Could not load collection.:
MSIASSERT - WriteServiceEntries: GetServiceConfigurations == false.:
MSIASSERT - WriteCcServiceRegistry: WriteServiceEntries == false, collecting info:
CheckServiceState: called for service 'ccSetMgr'
CheckServiceState: ServiceType=32
CurrentState=1
ControlAccepted=0
Win32ExitCode=0
ServiceSpecificExitCode=0
CheckPoint=0
WaitHint=0
CheckServiceState: Allocated 334 bytes
CheckServiceState: Details for service 'ccSetMgr'
ServiceType=32
StartType=2
ErrorControl=0
PathName="C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
LoadOrderGroup=Symantec Core Services
ServiceStartName=LocalSystem
DisplayName=Symantec Settings Manager
EnumerateServiceNames: Dependencies:
Service:RPCSS
EnumerateServiceNames: Enumeration of services complete
CheckServiceState: Allocated 232 bytes for dependent services
CheckServiceState: DependentServiceName:Symantec AntiVirus DependentServiceDisplayName:Symantec Endpoint Protection
CheckServiceState: ServiceType=16
CurrentState=1
ControlAccepted=0
Win32ExitCode=1077
ServiceSpecificExitCode=0
CheckPoint=0
WaitHint=0
CheckServiceState: DependentServiceName:ccEvtMgr DependentServiceDisplayName:Symantec Event Manager
CheckServiceState: ServiceType=32
CurrentState=1
ControlAccepted=0
Win32ExitCode=1068
ServiceSpecificExitCode=0
CheckPoint=0
WaitHint=0
CheckServiceState: exiting
CheckServiceState: called for service 'ccEvtMgr'
CheckServiceState: ServiceType=32
CurrentState=1
ControlAccepted=0
Win32ExitCode=1068
ServiceSpecificExitCode=0
CheckPoint=0
WaitHint=0
CheckServiceState: Allocated 346 bytes
CheckServiceState: Details for service 'ccEvtMgr'
ServiceType=32
StartType=2
ErrorControl=0
PathName="C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
LoadOrderGroup=Symantec Core Services
ServiceStartName=LocalSystem
DisplayName=Symantec Event Manager
EnumerateServiceNames: Dependencies:
Dependent Service:RPCSS
Service:ccSetMgr
EnumerateServiceNames: Enumeration of services complete
CheckServiceState: Allocated 132 bytes for dependent services
CheckServiceState: DependentServiceName:Symantec AntiVirus DependentServiceDisplayName:Symantec Endpoint Protection
CheckServiceState: ServiceType=16
CurrentState=1
ControlAccepted=0
Win32ExitCode=1077
ServiceSpecificExitCode=0
CheckPoint=0
WaitHint=0
CheckServiceState: exiting
2010-09-16-06-27-15-319 : cc::GetServiceStatus(1027) : Able to query status for service ccSetMgr
LogStartServiceAttempt: Attempting to start ccSetMgr
2010-09-16-06-27-15-319 : ccLib::CRegistry::Open(101) : RegOpenKeyEx() != ERROR_SUCCESS, Software\Symantec\Common Client\Debug, 0x00000002
2010-09-16-06-27-15-428 : cc::StartServiceW(69) : Logging time before attempting to start service: ccSetMgr
cc::StartServiceW: :Attempting to start service ccSetMgr
2010-09-16-06-27-15-460 : Start() failed to StartService() on ccSetMgr. Error:1053
MSIASSERT - cc::StartServiceW: : Unable to start service ccSetMgr:
2010-09-16-06-27-15-460 : cc::StartServiceW(118) : Logging time after attempting to start service: ccSetMgr
MSIASSERT - LogStartServiceAttempt: StartService returned false:
2010-09-16-06-27-15-460 : ccMSIUtil::CAutoDebugOptions::RestorePreviousState(117) : Debug key deleted
2010-09-16-06-27-15-460 : cc::StopService(187) : The service ccSetMgr is already not running. Nothing to stop. service State=1
LogStartServiceAttempt: Logging complete - service ccSetMgr stopped
2010-09-16-06-27-15-460 : cc::GetServiceStatus(1027) : Able to query status for service ccEvtMgr
LogStartServiceAttempt: Attempting to start ccEvtMgr
2010-09-16-06-27-15-475 : ccLib::CRegistry::Open(101) : RegOpenKeyEx() != ERROR_SUCCESS, Software\Symantec\Common Client\Debug, 0x00000002
2010-09-16-06-27-15-569 : cc::StartServiceW(69) : Logging time before attempting to start service: ccEvtMgr
cc::StartServiceW: :Attempting to start service ccEvtMgr
2010-09-16-06-27-15-600 : Start() failed to StartService() on ccEvtMgr. Error:1068
MSIASSERT - cc::StartServiceW: : Unable to start service ccEvtMgr:
2010-09-16-06-27-15-600 : cc::StartServiceW(118) : Logging time after attempting to start service: ccEvtMgr
MSIASSERT - LogStartServiceAttempt: StartService returned false:
2010-09-16-06-27-15-600 : ccMSIUtil::CAutoDebugOptions::RestorePreviousState(117) : Debug key deleted
2010-09-16-06-27-15-600 : cc::StopService(187) : The service ccEvtMgr is already not running. Nothing to stop. service State=1
LogStartServiceAttempt: Logging complete - service ccEvtMgr stopped
MSIASSERT - 2010-09-16-06-27-15-600 : CMutex::Open() : OpenMutex() == NULL, Global\ccSetMgr_Running, 0x00000002
:
MSIASSERT - DisplayMutexInformation: Unable to open mutex ccSetMgr_Running. Error =2:
MSIASSERT - 2010-09-16-06-27-15-616 : CMutex::Open() : OpenMutex() == NULL, Global\ccEvtMgr_Running, 0x00000002
:
MSIASSERT - DisplayMutexInformation: Unable to open mutex ccEvtMgr_Running. Error =2:
2010-09-16-06-27-15-616 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
2010-09-16-06-27-15-616 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
2010-09-16-06-27-15-616 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
2010-09-16-06-27-15-632 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
2010-09-16-06-27-15-632 : CInstalledApps::GetInstAppsDirectory() : "Common Client", "C:\Program Files\Common Files\Symantec Shared"
2010-09-16-06-27-15-632 : CPrivilege::GrantThread() : GetLastError() == ERROR_NO_TOKEN
:
MSIASSERT - 2010-09-16-06-27-15-647 : ccLib::CSystemInfo::GetProcessInfoPSAPI(712) : GetModuleListPSAPI() == FALSE, 4
:
MSIASSERT - 2010-09-16-06-27-15-647 : ccLib::CSystemInfo::GetProcessImageFileNamePSAPI(1001) : m_PSAPI.GetProcessImageFileName() == 0, 0x0000012B
:
MSIASSERT - 2010-09-16-06-27-15-647 : ccLib::CSystemInfo::GetProcessInfoPSAPI(721) : GetProcessImageFileNamePSAPI() == FALSE, 4
:
MSIASSERT - 2010-09-16-06-27-15-647 : ccLib::CSystemInfo::GetProcessListPSAPI(884) : GetProcessInfoPSAPI() == FALSE
:
MSIASSERT - 2010-09-16-06-27-27-116 : ccLib::CSystemInfo::GetProcessList(598) : GetProcessListPSAPI() == FALSE
:
CollectProcessInfo: Dumping info for Pid=124 ImagePath=C:\WINDOWS\system32\locator.exe
Dumping module information for the process
Module: ImagePath=C:\WINDOWS\system32\UxTheme.dll
Module: ImagePath=C:\WINDOWS\system32\NETAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\ShimEng.dll
Module: ImagePath=C:\WINDOWS\system32\comctl32.dll
Module: ImagePath=C:\WINDOWS\AppPatch\AcGenral.DLL
Module: ImagePath=C:\WINDOWS\system32\IMM32.DLL
Module: ImagePath=C:\WINDOWS\system32\USERENV.dll
Module: ImagePath=C:\WINDOWS\system32\ATL.DLL
Module: ImagePath=C:\WINDOWS\system32\WINMM.dll
Module: ImagePath=C:\WINDOWS\system32\adsldpc.dll
Module: ImagePath=C:\WINDOWS\system32\WLDAP32.dll
Module: ImagePath=C:\WINDOWS\system32\OLEAUT32.dll
Module: ImagePath=C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
Module: ImagePath=C:\WINDOWS\system32\ole32.dll
Module: ImagePath=C:\WINDOWS\system32\MSACM32.dll
Module: ImagePath=C:\WINDOWS\system32\VERSION.dll
Module: ImagePath=C:\WINDOWS\system32\msvcrt.dll
Module: ImagePath=C:\WINDOWS\system32\ACTIVEDS.dll
Module: ImagePath=C:\WINDOWS\system32\ADVAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\RPCRT4.dll
Module: ImagePath=C:\WINDOWS\system32\GDI32.dll
Module: ImagePath=C:\WINDOWS\system32\SHLWAPI.dll
Module: ImagePath=C:\WINDOWS\system32\Secur32.dll
Module: ImagePath=C:\WINDOWS\system32\kernel32.dll
Module: ImagePath=C:\WINDOWS\system32\ntdll.dll
Module: ImagePath=C:\WINDOWS\system32\SHELL32.dll
Module: ImagePath=C:\WINDOWS\system32\USER32.dll
CollectProcessInfo: Dumping info for Pid=144 ImagePath=C:\Program Files\Java\jre6\bin\jqs.exe
Dumping module information for the process
Module: ImagePath=C:\WINDOWS\system32\odbcint.dll
Module: ImagePath=C:\WINDOWS\system32\COMCTL32.dll
Module: ImagePath=C:\WINDOWS\system32\perfos.dll
Module: ImagePath=C:\WINDOWS\system32\perfdisk.dll
Module: ImagePath=C:\WINDOWS\system32\hnetcfg.dll
Module: ImagePath=C:\WINDOWS\system32\odbcbcp.dll
Module: ImagePath=C:\WINDOWS\system32\mswsock.dll
Module: ImagePath=C:\WINDOWS\System32\wshtcpip.dll
Module: ImagePath=C:\WINDOWS\system32\WS2HELP.dll
Module: ImagePath=C:\WINDOWS\system32\WS2_32.dll
Module: ImagePath=C:\WINDOWS\system32\pdh.dll
Module: ImagePath=C:\WINDOWS\system32\ODBC32.dll
Module: ImagePath=C:\WINDOWS\system32\IMM32.DLL
Module: ImagePath=C:\WINDOWS\system32\comdlg32.dll
Module: ImagePath=C:\WINDOWS\system32\psapi.dll
Module: ImagePath=C:\WINDOWS\system32\OLEAUT32.dll
Module: ImagePath=C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
Module: ImagePath=C:\WINDOWS\system32\ole32.dll
Module: ImagePath=C:\WINDOWS\system32\CRYPT32.dll
Module: ImagePath=C:\WINDOWS\system32\MSASN1.dll
Module: ImagePath=C:\WINDOWS\system32\VERSION.dll
Module: ImagePath=C:\WINDOWS\system32\msvcrt.dll
Module: ImagePath=C:\WINDOWS\system32\ADVAPI32.dll
Module: ImagePath=C:\WINDOWS\system32\RPCRT4.dll
Module: ImagePath=C:\WINDOWS\system32\GDI32.dll
Module: ImagePath=C:\WINDOWS\system32\SHLWAPI.dll
Module: ImagePath=C:\WINDOWS\system32\Secur32.dll
Module: ImagePath=C:\Program Files\Java\jre6\bin\MSVCR71.dll
Module: ImagePath=C:\WINDOWS\system32\kernel32.dll
Module: ImagePath=C:\WINDOWS\system32\ntdll.dll
Module: ImagePath=C:\WINDOWS\system32\SHELL32.dll
Module: ImagePath=C:\WINDOWS\system32\USER32.dll
CollectProcessInfo: Dumping info for Pid=152 ImagePath=C:\WINDOWS\system32\svchost.exe
Check the following
Check the following article
Title: 'Symantec Endpoint Protection (SEP) 11 client installation fails with the message "Pending system changes that require a reboot have been detected"'
Web URL: http://service1.symantec.com/support/ent-security....
Thanks & Regards,
Mudit Kumar
Thanks for your reply. Tried
Thanks for your reply. Tried that as well but no success.
Try installing as
Try installing as unmanaged client
-VKalani
Thanks for the reply. We are
Thanks for the reply. We are actually trying as unmanaged. Pushing it to you didn't work either.
Run clean wipe and
try to install once again
If this Info helps to resolve the issue please Mark as Solution
Thanks
Thanks for the reply. We did
Thanks for the reply. We did run cleanwipe again but same result. I will try another option and let you know.
As per your log error
Start() failed to StartService() on ccSetMgr. Error:1053
in this its solved have look this KB
https://www-secure.symantec.com/connect/forums/another-install-issue#comment-3417141
If this Info helps to resolve the issue please Mark as Solution
Thanks
Run SFC in this client.It
Run SFC in this client.It will recover any OS files which is got corrupted /altered.After that try to install.If still fails with same error try by scanning Norton Power Eraser
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
I will try that and let you
I will try that and let you know. Thanks.
Contact your support for
Contact your support for obtain CleanWipe.
This is an Symantec product for uninstall SEP (and a little other Symantec product) with clean registry (in summary).
After have used this product with all option (it's a little long to execute) and restart your computer, it's possible of do execute this a second time (by security).
I think of you can install SEP after use this tool.
This thread is included in the "King for a Week" contest
Hi all,
This thread is now included in the Security Solutions Contest. Do your best to solve this thread, or any unsolved thread included in the contest, and you could be the "King for a Week" and win a weekly prize. Check out the details here:
https://www-secure.symantec.com/connect/blogs/security-solutions-contest-be-king-week
Best,
Eric
Subscribe to the upcoming Security Newsletter - Log in, visit your profile, and click on "Newsletter Subscriptions!"
Local Admin
Hello Robbie,
Did you try to user have administrative rights? and please try to install another user account.
Best regards.
FAtih
Everything works better when everything works together.
We ran cleanwipe again for
We ran cleanwipe again for the 4th time but did it as domain admin this time not local administrator. Then we re-installed and it worked correctly. Thanks for the extra step.
its good to heard :)
Hello Robbie,
It's good to heard. Thank you for mark as solution.
Best Regards.
Fatih
Everything works better when everything works together.
Would you like to reply?
Login or Register to post your comment.