Endpoint Protection

 View Only
Expand all | Collapse all

Liveupdate runs every few seconds

  • 1.  Liveupdate runs every few seconds

    Posted May 11, 2010 06:00 PM
    I've seen this on several of our machines over the last few months, but never had a chance to dig into it.  I've found that on some of our client machines, the system log shows an event for starting the liveupdate service very frequently.  In the case of the machine I'm looking at now, it seems to be about every 7 seconds. 

    I've found several old threads indicating this was fixed way back in MR1, but we've been past that for a long time.  In fact, this computer has had SEP removed/reinstalled within the last couple of weeks. Our server is on RU6, as are most of the clients.  (Some still haven't upgraded from RU5)

    The Liveupdate policy is set to use the default management server.  All the settings in the schedule and advanced settings section of the policy are greyed out.  This same policy is applied to all of our SEP clients except for 2 laptops that are almost never on the network.  


  • 2.  RE: Liveupdate runs every few seconds

    Posted May 11, 2010 10:38 PM
    Do you think you could post your liveupdate log so we could take a look at what is going on?

    Thanks
    Grant


  • 3.  RE: Liveupdate runs every few seconds

    Posted May 13, 2010 09:31 AM
    Here is the last 5 minutes worth:


    5/13/2010, 13:22:07 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:22:07 GMT -> LiveUpdate Language: English
    5/13/2010, 13:22:07 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:22:07 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:22:07 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:22:07 GMT -> IE 7 Support
    5/13/2010, 13:22:07 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:22:07 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:22:07 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:22:07 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:22:07 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:22:07 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:22:07 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:22:07 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:22:07 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:22:07 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:22:07 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:22:07 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:22:07 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:22:07 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:22:07 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:22:07 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:07 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:07 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:07 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:07 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:07 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:22:08 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:08 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:08 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:08 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:08 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:08 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:22:08 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:08 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:22:08 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:22:08 GMT -> ProductRegCom/luProductReg(PID=287252/TID=292996): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:08 GMT -> ProductRegCom/luProductReg(PID=287252/TID=292996): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:08 GMT -> ProductRegCom/luProductReg(PID=287252/TID=292996): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:08 GMT -> ProductRegCom/luProductReg(PID=287252/TID=292996): Destroyed luProductReg object.
    5/13/2010, 13:22:08 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:08 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:22:08 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:09 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:09 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:22:09 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:22:09 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:09 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:22:09 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:22:09 GMT -> ProductRegCom/luProductReg(PID=289024/TID=294224): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:09 GMT -> ProductRegCom/luProductReg(PID=289024/TID=294224): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:09 GMT -> ProductRegCom/luProductReg(PID=289024/TID=294224): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:09 GMT -> ProductRegCom/luProductReg(PID=289024/TID=294224): Destroyed luProductReg object.
    5/13/2010, 13:22:09 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:09 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:22:09 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:09 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:09 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:22:09 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:22:09 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:09 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:22:09 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:22:09 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:22:09 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:22:09 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:22:09 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:22:09 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:22:09 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:09 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:22:09 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:22:09 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:22:09 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:09 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\liveupdt.grd"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49", HR: 0x0       
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:09 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49", HR: 0x0       
    5/13/2010, 13:22:09 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\liveupdt.tri"
    5/13/2010, 13:22:09 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri49\syknapps_engine.zip.dat"
    5/13/2010, 13:22:09 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:22:09 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:22:09 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:22:09 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:22:09 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:09 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:09 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:09 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:09 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:09 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:09 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:22:09 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:09 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:09 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:09 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:09 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:22:10 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:22:21 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:22:21 GMT -> LiveUpdate Language: English
    5/13/2010, 13:22:21 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:22:21 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:22:21 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:22:21 GMT -> IE 7 Support
    5/13/2010, 13:22:21 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:22:21 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:22:21 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:22:21 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:22:21 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:22:21 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:22:21 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:22:21 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:22:21 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:22:21 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:22:21 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:22:21 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:22:21 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:22:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:22:21 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:22:21 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:21 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:21 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:21 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:21 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:22:21 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:21 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:21 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:21 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:21 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:22:22 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:22 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:22:22 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=293488/TID=293024): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=293488/TID=293024): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=293488/TID=293024): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=293488/TID=293024): Destroyed luProductReg object.
    5/13/2010, 13:22:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:22 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:22:22 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:22 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:22 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:22:22 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:22:22 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:22 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:22:22 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=292708/TID=292392): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=292708/TID=292392): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=292708/TID=292392): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:22 GMT -> ProductRegCom/luProductReg(PID=292708/TID=292392): Destroyed luProductReg object.
    5/13/2010, 13:22:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:22 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:22:22 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:22 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:22 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:22:22 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:22:22 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:22:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:22:22 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:22:22 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:22:22 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:22:22 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:22:22 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:22:22 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:22 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:22:22 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:22:22 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:22:22 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:22 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\liveupdt.grd"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92", HR: 0x0       
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:22 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92", HR: 0x0       
    5/13/2010, 13:22:22 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\liveupdt.tri"
    5/13/2010, 13:22:22 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri92\syknapps_engine.zip.dat"
    5/13/2010, 13:22:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:22:22 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:22:22 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:22:22 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:22:22 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:22 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:22 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:22 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:22 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:22 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:22:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:22 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:22 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:22 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:22 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:22:23 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:22:33 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:22:33 GMT -> LiveUpdate Language: English
    5/13/2010, 13:22:33 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:22:33 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:22:33 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:22:33 GMT -> IE 7 Support
    5/13/2010, 13:22:33 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:22:33 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:22:33 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:22:33 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:22:33 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:22:33 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:22:33 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:22:33 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:22:33 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:22:33 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:22:33 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:22:33 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:22:33 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:22:33 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:22:33 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:22:34 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:34 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:34 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:22:34 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:34 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:34 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:22:34 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:34 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:22:34 GMT -> ProductRegCom/luProductReg(PID=291704/TID=294240): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:34 GMT -> ProductRegCom/luProductReg(PID=291704/TID=294240): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:34 GMT -> ProductRegCom/luProductReg(PID=291704/TID=294240): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:34 GMT -> ProductRegCom/luProductReg(PID=291704/TID=294240): Destroyed luProductReg object.
    5/13/2010, 13:22:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:34 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:22:34 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:34 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:34 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:22:34 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:22:35 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:35 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:22:35 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:22:35 GMT -> ProductRegCom/luProductReg(PID=294336/TID=293284): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:35 GMT -> ProductRegCom/luProductReg(PID=294336/TID=293284): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:35 GMT -> ProductRegCom/luProductReg(PID=294336/TID=293284): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:35 GMT -> ProductRegCom/luProductReg(PID=294336/TID=293284): Destroyed luProductReg object.
    5/13/2010, 13:22:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:35 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:22:35 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:35 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:35 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:22:35 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:22:35 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:22:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:22:35 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:22:35 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:22:35 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:22:35 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:22:35 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:22:35 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:35 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:22:35 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:22:35 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:22:35 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:35 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\liveupdt.grd"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134", HR: 0x0       
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:35 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134", HR: 0x0       
    5/13/2010, 13:22:35 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\liveupdt.tri"
    5/13/2010, 13:22:35 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri134\syknapps_engine.zip.dat"
    5/13/2010, 13:22:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:22:35 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:22:35 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:22:35 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:22:35 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:35 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:35 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:35 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:35 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:35 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:22:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:35 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:35 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:35 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:35 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:22:35 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:22:46 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:22:46 GMT -> LiveUpdate Language: English
    5/13/2010, 13:22:46 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:22:46 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:22:46 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:22:46 GMT -> IE 7 Support
    5/13/2010, 13:22:46 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:22:46 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:22:46 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:22:46 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:22:46 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:22:46 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:22:46 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:22:46 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:22:46 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:22:46 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:22:46 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:22:46 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:22:46 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:22:46 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:22:46 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:22:46 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:46 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:46 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:47 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:47 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:22:47 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:47 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:47 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:47 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:22:47 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:22:47 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:22:47 GMT -> ProductRegCom/luProductReg(PID=292372/TID=293384): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:47 GMT -> ProductRegCom/luProductReg(PID=292372/TID=293384): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:47 GMT -> ProductRegCom/luProductReg(PID=292372/TID=293384): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:47 GMT -> ProductRegCom/luProductReg(PID=292372/TID=293384): Destroyed luProductReg object.
    5/13/2010, 13:22:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:47 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:22:47 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:48 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:48 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:22:48 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:22:48 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:22:48 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:22:48 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:22:48 GMT -> ProductRegCom/luProductReg(PID=293240/TID=289472): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:22:48 GMT -> ProductRegCom/luProductReg(PID=293240/TID=289472): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:22:48 GMT -> ProductRegCom/luProductReg(PID=293240/TID=289472): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:22:48 GMT -> ProductRegCom/luProductReg(PID=293240/TID=289472): Destroyed luProductReg object.
    5/13/2010, 13:22:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:48 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:22:48 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:22:48 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:48 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:22:48 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:22:48 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:22:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:22:48 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:22:48 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:22:48 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:22:48 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:22:48 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:22:48 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:22:48 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:22:48 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:22:48 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:22:48 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:48 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\liveupdt.grd"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177", HR: 0x0       
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:22:48 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177", HR: 0x0       
    5/13/2010, 13:22:48 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\liveupdt.tri"
    5/13/2010, 13:22:48 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri177\syknapps_engine.zip.dat"
    5/13/2010, 13:22:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:22:48 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:22:48 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:22:48 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:22:48 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:22:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:48 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:22:48 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:48 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:48 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:22:48 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:22:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:22:48 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:22:48 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:22:48 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:22:48 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:22:48 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:23:00 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:23:00 GMT -> LiveUpdate Language: English
    5/13/2010, 13:23:00 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:23:00 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:23:00 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:23:00 GMT -> IE 7 Support
    5/13/2010, 13:23:00 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:23:00 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:23:00 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:23:00 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:23:00 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:23:00 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:23:00 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:23:00 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:23:00 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:23:00 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:23:00 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:23:00 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:23:00 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:23:00 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:23:00 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:23:01 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:01 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:01 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:01 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:01 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:01 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:23:01 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:01 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:01 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:01 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:01 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:01 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:23:01 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:01 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:23:01 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:23:01 GMT -> ProductRegCom/luProductReg(PID=294164/TID=291804): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:01 GMT -> ProductRegCom/luProductReg(PID=294164/TID=291804): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:01 GMT -> ProductRegCom/luProductReg(PID=294164/TID=291804): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:01 GMT -> ProductRegCom/luProductReg(PID=294164/TID=291804): Destroyed luProductReg object.
    5/13/2010, 13:23:01 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:01 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:23:01 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:02 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:02 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:23:02 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:23:02 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:02 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:23:02 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:23:02 GMT -> ProductRegCom/luProductReg(PID=293328/TID=294704): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:02 GMT -> ProductRegCom/luProductReg(PID=293328/TID=294704): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:02 GMT -> ProductRegCom/luProductReg(PID=293328/TID=294704): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:02 GMT -> ProductRegCom/luProductReg(PID=293328/TID=294704): Destroyed luProductReg object.
    5/13/2010, 13:23:02 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:02 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:23:02 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:02 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:02 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:23:02 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:23:02 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:02 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:23:02 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:23:02 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:23:02 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:23:02 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:23:02 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:23:02 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:23:02 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:02 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:23:02 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:23:02 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:23:02 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:02 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\liveupdt.grd"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222", HR: 0x0       
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:02 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222", HR: 0x0       
    5/13/2010, 13:23:02 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\liveupdt.tri"
    5/13/2010, 13:23:02 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri222\syknapps_engine.zip.dat"
    5/13/2010, 13:23:02 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:23:02 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:23:02 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:23:02 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:23:02 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:02 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:02 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:02 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:02 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:02 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:02 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:23:02 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:02 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:02 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:02 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:02 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:23:02 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:23:13 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:23:13 GMT -> LiveUpdate Language: English
    5/13/2010, 13:23:13 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:23:13 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:23:13 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:23:13 GMT -> IE 7 Support
    5/13/2010, 13:23:13 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:23:13 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:23:13 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:23:13 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:23:13 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:23:13 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:23:13 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:23:13 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:23:13 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:23:13 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:23:13 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:23:13 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:23:13 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:23:13 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:23:13 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:23:13 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:13 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:13 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:13 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:13 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:13 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:23:13 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:13 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:13 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:14 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:14 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:14 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:23:14 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:14 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:23:14 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=294772/TID=293104): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=294772/TID=293104): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=294772/TID=293104): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=294772/TID=293104): Destroyed luProductReg object.
    5/13/2010, 13:23:14 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:14 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:23:14 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:14 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:14 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:23:14 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:23:14 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:14 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:23:14 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=291804/TID=291180): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=291804/TID=291180): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=291804/TID=291180): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:14 GMT -> ProductRegCom/luProductReg(PID=291804/TID=291180): Destroyed luProductReg object.
    5/13/2010, 13:23:14 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:14 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:23:14 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:15 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:15 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:23:15 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:23:15 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:15 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:23:15 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:23:15 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:23:15 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:23:15 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:23:15 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:23:15 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:23:15 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:15 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:23:15 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:23:15 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:23:15 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:15 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\liveupdt.grd"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265", HR: 0x0       
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:15 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265", HR: 0x0       
    5/13/2010, 13:23:15 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\liveupdt.tri"
    5/13/2010, 13:23:15 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri265\syknapps_engine.zip.dat"
    5/13/2010, 13:23:15 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:23:15 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:23:15 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:23:15 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:23:15 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:15 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:15 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:15 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:15 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:15 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:15 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:23:15 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:15 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:15 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:15 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:15 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:23:15 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:23:27 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:23:27 GMT -> LiveUpdate Language: English
    5/13/2010, 13:23:27 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:23:27 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:23:27 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:23:27 GMT -> IE 7 Support
    5/13/2010, 13:23:27 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:23:27 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:23:27 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:23:27 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:23:27 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:23:27 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:23:27 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:23:27 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:23:27 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:23:27 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:23:27 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:23:27 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:23:27 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:23:27 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:23:27 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:27 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:27 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:27 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:23:27 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:27 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:27 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:27 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:23:27 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:27 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:23:27 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293452/TID=292956): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293452/TID=292956): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293452/TID=292956): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293452/TID=292956): Destroyed luProductReg object.
    5/13/2010, 13:23:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:28 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:23:28 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:28 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:28 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:23:28 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:23:28 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:28 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:23:28 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293200/TID=293380): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293200/TID=293380): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293200/TID=293380): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:28 GMT -> ProductRegCom/luProductReg(PID=293200/TID=293380): Destroyed luProductReg object.
    5/13/2010, 13:23:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:28 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:23:28 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:28 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:28 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:23:28 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:23:28 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:28 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:23:28 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:23:28 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:23:28 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:23:28 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:23:28 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:23:28 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:23:28 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:28 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:23:28 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:23:28 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:23:28 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:28 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\liveupdt.grd"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307", HR: 0x0       
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:28 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307", HR: 0x0       
    5/13/2010, 13:23:28 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\liveupdt.tri"
    5/13/2010, 13:23:28 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri307\syknapps_engine.zip.dat"
    5/13/2010, 13:23:28 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:23:28 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:23:28 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:23:28 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:23:28 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:28 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:28 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:28 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:28 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:28 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:23:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:28 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:28 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:28 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:28 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:23:28 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:23:39 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:23:39 GMT -> LiveUpdate Language: English
    5/13/2010, 13:23:39 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:23:39 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:23:39 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:23:39 GMT -> IE 7 Support
    5/13/2010, 13:23:39 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:23:39 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:23:39 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:23:39 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:23:39 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:23:39 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:23:39 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:23:39 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:23:39 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:23:39 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:23:39 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:23:39 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:23:39 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:23:39 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:23:39 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:23:39 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:39 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:39 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:39 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:39 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:39 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:23:40 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:40 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:40 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:40 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:40 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:40 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:23:40 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:40 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:23:40 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=294780/TID=291500): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=294780/TID=291500): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=294780/TID=291500): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=294780/TID=291500): Destroyed luProductReg object.
    5/13/2010, 13:23:40 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:40 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:23:40 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:40 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:40 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:23:40 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:23:40 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:40 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:23:40 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=293512/TID=293580): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=293512/TID=293580): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=293512/TID=293580): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:40 GMT -> ProductRegCom/luProductReg(PID=293512/TID=293580): Destroyed luProductReg object.
    5/13/2010, 13:23:40 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:40 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:23:40 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:41 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:41 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:23:41 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:23:41 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:41 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:23:41 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:23:41 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:23:41 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:23:41 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:23:41 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:23:41 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:23:41 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:41 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:23:41 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:23:41 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:23:41 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:41 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\liveupdt.grd"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350", HR: 0x0       
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:41 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350", HR: 0x0       
    5/13/2010, 13:23:41 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\liveupdt.tri"
    5/13/2010, 13:23:41 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri350\syknapps_engine.zip.dat"
    5/13/2010, 13:23:41 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:23:41 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:23:41 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:23:41 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:23:41 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:41 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:41 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:41 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:41 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:41 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:41 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:23:41 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:41 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:41 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:41 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:41 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:23:41 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:23:52 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:23:52 GMT -> LiveUpdate Language: English
    5/13/2010, 13:23:52 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:23:52 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:23:52 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:23:52 GMT -> IE 7 Support
    5/13/2010, 13:23:52 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:23:52 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:23:52 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:23:52 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:23:52 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:23:52 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:23:52 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:23:52 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:23:52 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:23:52 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:23:52 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:23:52 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:23:52 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:23:52 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:23:52 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:23:52 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:52 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:52 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:52 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:52 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:52 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:23:52 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:52 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:52 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:53 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:53 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:53 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:23:53 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:53 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:23:53 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=281536/TID=165820): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=281536/TID=165820): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=281536/TID=165820): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=281536/TID=165820): Destroyed luProductReg object.
    5/13/2010, 13:23:53 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:53 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:23:53 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:53 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:53 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:23:53 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:23:53 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:23:53 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:23:53 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=293280/TID=294408): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=293280/TID=294408): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=293280/TID=294408): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:23:53 GMT -> ProductRegCom/luProductReg(PID=293280/TID=294408): Destroyed luProductReg object.
    5/13/2010, 13:23:53 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:53 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:23:53 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:23:53 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:53 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:23:53 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:23:53 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:53 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:23:53 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:23:53 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:23:53 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:23:53 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:23:53 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:23:53 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:23:53 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:23:53 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:23:53 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:23:53 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:23:53 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:53 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\liveupdt.grd"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389", HR: 0x0       
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:23:53 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389", HR: 0x0       
    5/13/2010, 13:23:53 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\liveupdt.tri"
    5/13/2010, 13:23:53 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri389\syknapps_engine.zip.dat"
    5/13/2010, 13:23:53 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:23:53 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:23:53 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:23:53 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:23:53 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:23:53 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:53 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:23:53 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:54 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:54 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:23:54 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:23:54 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:23:54 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:23:54 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:23:54 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:23:54 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:23:54 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:24:06 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:24:06 GMT -> LiveUpdate Language: English
    5/13/2010, 13:24:06 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:24:06 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:24:06 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:24:06 GMT -> IE 7 Support
    5/13/2010, 13:24:06 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:24:06 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:24:06 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:24:06 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:24:06 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:24:06 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:24:06 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:24:06 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:24:06 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:24:06 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:24:06 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:24:06 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:24:06 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:24:06 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:24:06 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:24:06 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:06 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:06 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:06 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:06 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:06 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:24:07 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:07 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:07 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:07 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:07 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:07 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:24:07 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:07 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:24:07 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:24:07 GMT -> ProductRegCom/luProductReg(PID=292284/TID=294080): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:07 GMT -> ProductRegCom/luProductReg(PID=292284/TID=294080): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:07 GMT -> ProductRegCom/luProductReg(PID=292284/TID=294080): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:07 GMT -> ProductRegCom/luProductReg(PID=292284/TID=294080): Destroyed luProductReg object.
    5/13/2010, 13:24:07 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:07 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:24:07 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:08 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:08 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:24:08 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:24:08 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:08 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:24:08 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:24:08 GMT -> ProductRegCom/luProductReg(PID=293648/TID=294660): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:08 GMT -> ProductRegCom/luProductReg(PID=293648/TID=294660): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:08 GMT -> ProductRegCom/luProductReg(PID=293648/TID=294660): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:08 GMT -> ProductRegCom/luProductReg(PID=293648/TID=294660): Destroyed luProductReg object.
    5/13/2010, 13:24:08 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:08 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:24:08 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:08 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:08 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:24:08 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:24:08 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:08 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:24:08 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:24:08 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:24:08 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:24:08 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:24:08 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:24:08 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:24:08 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:08 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:24:08 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:24:08 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:24:08 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:08 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\liveupdt.grd"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438", HR: 0x0       
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:08 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438", HR: 0x0       
    5/13/2010, 13:24:08 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\liveupdt.tri"
    5/13/2010, 13:24:08 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri438\syknapps_engine.zip.dat"
    5/13/2010, 13:24:08 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:24:08 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:24:08 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:24:08 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:24:08 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:08 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:08 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:08 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:08 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:08 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:08 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:24:08 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:08 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:08 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:08 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:08 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:24:08 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:24:20 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:24:20 GMT -> LiveUpdate Language: English
    5/13/2010, 13:24:20 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:24:20 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:24:20 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:24:20 GMT -> IE 7 Support
    5/13/2010, 13:24:20 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:24:20 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:24:20 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:24:20 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:24:20 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:24:20 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:24:20 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:24:20 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:24:20 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:24:20 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:24:20 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:24:20 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:24:20 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:24:20 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:24:20 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:24:20 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:20 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:20 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:21 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:21 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:24:21 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:21 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:21 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:21 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:24:21 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:21 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:24:21 GMT -> ProductRegCom/luProductReg(PID=291472/TID=290264): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:21 GMT -> ProductRegCom/luProductReg(PID=291472/TID=290264): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:21 GMT -> ProductRegCom/luProductReg(PID=291472/TID=290264): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:21 GMT -> ProductRegCom/luProductReg(PID=291472/TID=290264): Destroyed luProductReg object.
    5/13/2010, 13:24:21 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:21 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:24:21 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:21 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:24:21 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:24:21 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:21 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:24:21 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:24:22 GMT -> ProductRegCom/luProductReg(PID=294868/TID=294660): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:22 GMT -> ProductRegCom/luProductReg(PID=294868/TID=294660): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:22 GMT -> ProductRegCom/luProductReg(PID=294868/TID=294660): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:22 GMT -> ProductRegCom/luProductReg(PID=294868/TID=294660): Destroyed luProductReg object.
    5/13/2010, 13:24:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:22 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:24:22 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:22 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:22 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:24:22 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:24:22 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:24:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:24:22 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:24:22 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:24:22 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:24:22 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:24:22 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:24:22 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:22 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:24:22 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:24:22 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:24:22 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:22 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\liveupdt.grd"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484", HR: 0x0       
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:22 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484", HR: 0x0       
    5/13/2010, 13:24:22 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\liveupdt.tri"
    5/13/2010, 13:24:22 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri484\syknapps_engine.zip.dat"
    5/13/2010, 13:24:22 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:24:22 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:24:22 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:24:22 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:24:22 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:22 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:22 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:22 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:22 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:22 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:24:22 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:22 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:22 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:22 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:22 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:24:22 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:24:33 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:24:33 GMT -> LiveUpdate Language: English
    5/13/2010, 13:24:33 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:24:33 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:24:33 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:24:33 GMT -> IE 7 Support
    5/13/2010, 13:24:33 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:24:33 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:24:33 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:24:33 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:24:33 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:24:33 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:24:33 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:24:33 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:24:33 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:24:33 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:24:33 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:24:33 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:24:33 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:24:33 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:24:33 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:24:33 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:33 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:33 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:34 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:34 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:24:34 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:34 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:34 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:34 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:34 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:24:34 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:34 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:24:34 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:24:34 GMT -> ProductRegCom/luProductReg(PID=292900/TID=289332): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:34 GMT -> ProductRegCom/luProductReg(PID=292900/TID=289332): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:34 GMT -> ProductRegCom/luProductReg(PID=292900/TID=289332): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:34 GMT -> ProductRegCom/luProductReg(PID=292900/TID=289332): Destroyed luProductReg object.
    5/13/2010, 13:24:34 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:34 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:24:34 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:35 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:35 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:24:35 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:24:35 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:35 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:24:35 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:24:35 GMT -> ProductRegCom/luProductReg(PID=294096/TID=294340): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:35 GMT -> ProductRegCom/luProductReg(PID=294096/TID=294340): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:35 GMT -> ProductRegCom/luProductReg(PID=294096/TID=294340): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:35 GMT -> ProductRegCom/luProductReg(PID=294096/TID=294340): Destroyed luProductReg object.
    5/13/2010, 13:24:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:35 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:24:35 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:35 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:35 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:24:35 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:24:35 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:24:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:24:35 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:24:35 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:24:35 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:24:35 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:24:35 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:24:35 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:35 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:24:35 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:24:35 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:24:35 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:35 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\liveupdt.grd"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526", HR: 0x0       
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:35 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526", HR: 0x0       
    5/13/2010, 13:24:35 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\liveupdt.tri"
    5/13/2010, 13:24:35 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri526\syknapps_engine.zip.dat"
    5/13/2010, 13:24:35 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:24:35 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:24:35 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:24:35 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:24:35 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:35 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:35 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:35 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:35 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:35 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:24:35 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:35 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:35 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:35 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:35 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:24:35 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:24:46 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:24:46 GMT -> LiveUpdate Language: English
    5/13/2010, 13:24:46 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:24:46 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:24:46 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:24:46 GMT -> IE 7 Support
    5/13/2010, 13:24:46 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:24:46 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:24:46 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:24:46 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:24:46 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:24:46 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:24:46 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:24:46 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:24:46 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:24:46 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:24:46 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:24:46 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:24:46 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:24:46 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:24:46 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:24:47 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:47 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:24:47 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:47 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:24:47 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:24:47 GMT -> ProductRegCom/luProductReg(PID=292064/TID=294084): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:47 GMT -> ProductRegCom/luProductReg(PID=292064/TID=294084): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:47 GMT -> ProductRegCom/luProductReg(PID=292064/TID=294084): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:47 GMT -> ProductRegCom/luProductReg(PID=292064/TID=294084): Destroyed luProductReg object.
    5/13/2010, 13:24:47 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:47 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:24:47 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:47 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:24:47 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:24:47 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:24:47 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:24:47 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:24:48 GMT -> ProductRegCom/luProductReg(PID=293580/TID=291136): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:24:48 GMT -> ProductRegCom/luProductReg(PID=293580/TID=291136): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:24:48 GMT -> ProductRegCom/luProductReg(PID=293580/TID=291136): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:24:48 GMT -> ProductRegCom/luProductReg(PID=293580/TID=291136): Destroyed luProductReg object.
    5/13/2010, 13:24:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:48 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:24:48 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:24:48 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:48 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:24:48 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:24:48 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:24:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:24:48 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:24:48 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:24:48 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:24:48 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:24:48 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:24:48 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:24:48 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:24:48 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:24:48 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:24:48 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:48 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\liveupdt.grd"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569", HR: 0x0       
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:24:48 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569", HR: 0x0       
    5/13/2010, 13:24:48 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\liveupdt.tri"
    5/13/2010, 13:24:48 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri569\syknapps_engine.zip.dat"
    5/13/2010, 13:24:48 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:24:48 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:24:48 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:24:48 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:24:48 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:24:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:48 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:24:48 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:48 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:48 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:24:48 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:24:48 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:24:48 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:24:48 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:24:48 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:24:48 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:24:48 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:25:00 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:25:00 GMT -> LiveUpdate Language: English
    5/13/2010, 13:25:00 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:25:00 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:25:00 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:25:00 GMT -> IE 7 Support
    5/13/2010, 13:25:00 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:25:00 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:25:00 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:25:00 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:25:00 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:25:00 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:25:00 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:25:00 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:25:00 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:25:00 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:25:00 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:25:00 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:25:00 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:25:00 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:25:00 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:25:00 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:00 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:00 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:00 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:00 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:00 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:25:00 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:00 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:00 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:01 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:01 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:01 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:25:03 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:03 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:25:03 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=293624/TID=293820): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=293624/TID=293820): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=293624/TID=293820): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=293624/TID=293820): Destroyed luProductReg object.
    5/13/2010, 13:25:03 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:03 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:25:03 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:03 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:03 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:25:03 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:25:03 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:03 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:25:03 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=294240/TID=294440): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=294240/TID=294440): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=294240/TID=294440): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:03 GMT -> ProductRegCom/luProductReg(PID=294240/TID=294440): Destroyed luProductReg object.
    5/13/2010, 13:25:03 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:03 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:25:03 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:03 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:03 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:25:03 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:25:03 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:03 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:25:03 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:25:03 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:25:03 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:25:03 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:25:03 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:25:03 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:25:03 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:03 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:25:03 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:25:03 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:25:03 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:03 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\liveupdt.grd"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618", HR: 0x0       
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:03 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618", HR: 0x0       
    5/13/2010, 13:25:03 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\liveupdt.tri"
    5/13/2010, 13:25:03 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri618\syknapps_engine.zip.dat"
    5/13/2010, 13:25:03 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:25:03 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:25:03 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:25:03 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:25:03 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:03 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:03 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:03 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:03 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:03 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:03 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:25:03 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:03 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:03 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:04 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:04 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:25:04 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:25:16 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:25:16 GMT -> LiveUpdate Language: English
    5/13/2010, 13:25:16 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:25:16 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:25:16 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:25:16 GMT -> IE 7 Support
    5/13/2010, 13:25:16 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:25:16 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:25:16 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:25:16 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:25:16 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:25:16 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:25:16 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:25:16 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:25:16 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:25:16 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:25:16 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:25:16 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:25:16 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:25:16 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:25:16 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:25:16 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:16 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:16 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:16 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:16 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:16 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:25:17 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:17 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:17 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:17 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:17 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:17 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:25:17 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:17 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:25:17 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=293896/TID=292940): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=293896/TID=292940): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=293896/TID=292940): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=293896/TID=292940): Destroyed luProductReg object.
    5/13/2010, 13:25:17 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:17 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:25:17 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:17 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:17 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:25:17 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:25:17 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:17 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:25:17 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=291456/TID=294188): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=291456/TID=294188): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=291456/TID=294188): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:17 GMT -> ProductRegCom/luProductReg(PID=291456/TID=294188): Destroyed luProductReg object.
    5/13/2010, 13:25:17 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:17 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:25:17 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:17 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:17 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:25:17 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:25:17 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:17 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:25:17 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:25:17 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:25:17 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:25:17 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:25:17 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:25:17 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:25:17 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:17 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:25:17 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:25:17 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:25:17 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:17 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\liveupdt.grd"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663", HR: 0x0       
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:25:17 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:18 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663", HR: 0x0       
    5/13/2010, 13:25:18 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\liveupdt.tri"
    5/13/2010, 13:25:18 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri663\syknapps_engine.zip.dat"
    5/13/2010, 13:25:18 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:25:18 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:25:18 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:25:18 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:25:18 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:18 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:18 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:18 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:18 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:18 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:18 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:25:18 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:18 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:18 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:18 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:18 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:25:18 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:25:29 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:25:29 GMT -> LiveUpdate Language: English
    5/13/2010, 13:25:29 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:25:29 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:25:29 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:25:29 GMT -> IE 7 Support
    5/13/2010, 13:25:29 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:25:29 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:25:29 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:25:29 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:25:29 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:25:29 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:25:29 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:25:29 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:25:29 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:25:29 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:25:29 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:25:29 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:25:29 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:25:29 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:25:29 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:25:29 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:29 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:29 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:29 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:29 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:29 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:25:29 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:29 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:29 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:30 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:30 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:30 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:25:30 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:30 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:25:30 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295404/TID=295424): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295404/TID=295424): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295404/TID=295424): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295404/TID=295424): Destroyed luProductReg object.
    5/13/2010, 13:25:30 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:30 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:25:30 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:30 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:30 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:25:30 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:25:30 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:30 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:25:30 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295448/TID=295468): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295448/TID=295468): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295448/TID=295468): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:30 GMT -> ProductRegCom/luProductReg(PID=295448/TID=295468): Destroyed luProductReg object.
    5/13/2010, 13:25:30 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:30 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:25:30 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:30 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:30 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:25:30 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:25:30 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:30 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:25:30 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:25:30 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:25:30 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:25:30 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:25:30 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:25:30 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:25:30 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:30 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:25:30 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:25:30 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:25:30 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:30 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\liveupdt.grd"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706", HR: 0x0       
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:30 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706", HR: 0x0       
    5/13/2010, 13:25:30 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\liveupdt.tri"
    5/13/2010, 13:25:30 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri706\syknapps_engine.zip.dat"
    5/13/2010, 13:25:30 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:25:30 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:25:30 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:25:30 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:25:30 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:30 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:30 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:30 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:31 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:31 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:31 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:25:31 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:31 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:31 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:31 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:31 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:25:31 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:25:44 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:25:44 GMT -> LiveUpdate Language: English
    5/13/2010, 13:25:44 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:25:44 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:25:44 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:25:44 GMT -> IE 7 Support
    5/13/2010, 13:25:44 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:25:44 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:25:44 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:25:44 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:25:44 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:25:44 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:25:44 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:25:44 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:25:44 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:25:44 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:25:44 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:25:44 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:25:44 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:25:44 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:25:44 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:44 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:44 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:44 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:25:44 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:44 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:44 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:44 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:25:44 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:44 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:25:44 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=295956/TID=296036): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=295956/TID=296036): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=295956/TID=296036): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=295956/TID=296036): Destroyed luProductReg object.
    5/13/2010, 13:25:45 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:45 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:25:45 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:45 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:45 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:25:45 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:25:45 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:45 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:25:45 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=296064/TID=296084): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=296064/TID=296084): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=296064/TID=296084): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:45 GMT -> ProductRegCom/luProductReg(PID=296064/TID=296084): Destroyed luProductReg object.
    5/13/2010, 13:25:45 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:45 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:25:45 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:45 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:45 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:25:45 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:25:45 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:45 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:25:45 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:25:45 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:25:45 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:25:45 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:25:45 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:25:45 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:25:45 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:45 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:25:45 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:25:45 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:25:45 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:45 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\liveupdt.grd"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755", HR: 0x0       
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:45 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755", HR: 0x0       
    5/13/2010, 13:25:45 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\liveupdt.tri"
    5/13/2010, 13:25:45 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri755\syknapps_engine.zip.dat"
    5/13/2010, 13:25:45 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:25:45 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:25:45 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:25:45 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:25:45 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:45 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:45 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:45 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:45 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:45 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:45 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:25:45 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:45 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:45 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:25:46 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:46 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:25:46 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:25:58 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:25:58 GMT -> LiveUpdate Language: English
    5/13/2010, 13:25:58 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:25:58 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:25:58 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:25:58 GMT -> IE 7 Support
    5/13/2010, 13:25:58 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:25:58 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:25:58 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:25:58 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:25:58 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:25:58 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:25:58 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:25:58 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:25:58 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:25:58 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:25:58 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:25:58 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:25:58 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:25:58 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:25:58 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:25:58 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:58 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:58 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:58 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:58 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:58 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:25:58 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:58 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:58 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:25:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:59 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:25:59 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:25:59 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:59 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:25:59 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296788/TID=296808): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296788/TID=296808): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296788/TID=296808): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296788/TID=296808): Destroyed luProductReg object.
    5/13/2010, 13:25:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:59 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:25:59 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:59 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:59 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:25:59 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:25:59 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:25:59 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:25:59 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296832/TID=296852): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296832/TID=296852): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296832/TID=296852): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:25:59 GMT -> ProductRegCom/luProductReg(PID=296832/TID=296852): Destroyed luProductReg object.
    5/13/2010, 13:25:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:59 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:25:59 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:25:59 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:25:59 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:25:59 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:25:59 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:59 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:25:59 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:25:59 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:25:59 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:25:59 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:25:59 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:25:59 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:25:59 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:25:59 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:25:59 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:25:59 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:59 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:25:59 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\liveupdt.grd"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801", HR: 0x0       
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:25:59 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801", HR: 0x0       
    5/13/2010, 13:25:59 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\liveupdt.tri"
    5/13/2010, 13:25:59 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri801\syknapps_engine.zip.dat"
    5/13/2010, 13:25:59 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:25:59 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:25:59 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:25:59 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:25:59 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:25:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:25:59 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:25:59 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:00 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:00 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:00 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:26:00 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:00 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:00 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:00 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:00 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:26:00 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:26:11 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:26:11 GMT -> LiveUpdate Language: English
    5/13/2010, 13:26:11 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:26:11 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:26:11 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:26:11 GMT -> IE 7 Support
    5/13/2010, 13:26:11 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:26:11 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:26:11 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:26:11 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:26:11 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:26:11 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:26:11 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:26:11 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:26:11 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:26:11 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:26:11 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:26:11 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:26:11 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:26:11 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:26:11 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:26:12 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:12 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:12 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:12 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:26:12 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:12 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:12 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:12 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:26:12 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:12 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:26:12 GMT -> ProductRegCom/luProductReg(PID=294952/TID=294972): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:12 GMT -> ProductRegCom/luProductReg(PID=294952/TID=294972): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:12 GMT -> ProductRegCom/luProductReg(PID=294952/TID=294972): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:12 GMT -> ProductRegCom/luProductReg(PID=294952/TID=294972): Destroyed luProductReg object.
    5/13/2010, 13:26:12 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:12 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:26:12 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:12 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:12 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:26:12 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:26:13 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:13 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:26:13 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:26:13 GMT -> ProductRegCom/luProductReg(PID=294976/TID=295004): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:13 GMT -> ProductRegCom/luProductReg(PID=294976/TID=295004): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:13 GMT -> ProductRegCom/luProductReg(PID=294976/TID=295004): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:13 GMT -> ProductRegCom/luProductReg(PID=294976/TID=295004): Destroyed luProductReg object.
    5/13/2010, 13:26:13 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:13 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:26:13 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:13 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:13 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:26:13 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:26:13 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:13 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:26:13 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:26:13 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:26:13 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:26:13 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:26:13 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:26:13 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:13 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:26:13 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:26:13 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:26:13 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846"
    5/13/2010, 13:26:13 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:13 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\liveupdt.grd"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846", HR: 0x0       
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:13 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846", HR: 0x0       
    5/13/2010, 13:26:13 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\liveupdt.tri"
    5/13/2010, 13:26:13 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri846\syknapps_engine.zip.dat"
    5/13/2010, 13:26:13 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:26:13 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:26:13 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:26:13 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:26:13 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:13 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:13 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:13 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:13 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:13 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:13 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:26:13 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:13 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:13 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:13 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:13 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:26:13 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:26:25 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:26:25 GMT -> LiveUpdate Language: English
    5/13/2010, 13:26:25 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:26:25 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:26:25 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:26:25 GMT -> IE 7 Support
    5/13/2010, 13:26:25 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:26:25 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:26:25 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:26:25 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:26:25 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:26:25 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:26:25 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:26:25 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:26:25 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:26:25 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:26:25 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:26:25 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:26:25 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:26:25 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:26:25 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:26:25 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:25 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:25 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:25 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:25 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:25 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:26:25 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:25 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:25 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:26 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:26 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:26 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:26:26 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:26 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:26:26 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295572/TID=295588): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295572/TID=295588): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295572/TID=295588): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295572/TID=295588): Destroyed luProductReg object.
    5/13/2010, 13:26:26 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:26 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:26:26 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:26 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:26 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:26:26 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:26:26 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:26 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:26:26 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295612/TID=295636): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295612/TID=295636): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295612/TID=295636): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:26 GMT -> ProductRegCom/luProductReg(PID=295612/TID=295636): Destroyed luProductReg object.
    5/13/2010, 13:26:26 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:26 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:26:26 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:26 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:26 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:26:26 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:26:26 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:26 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:26:26 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:26:26 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:26:26 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:26:26 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:26:26 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:26:26 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:26:26 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:26 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:26:26 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:26:26 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:26:26 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:26 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\liveupdt.grd"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889", HR: 0x0       
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:26 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889", HR: 0x0       
    5/13/2010, 13:26:27 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\liveupdt.tri"
    5/13/2010, 13:26:27 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri889\syknapps_engine.zip.dat"
    5/13/2010, 13:26:27 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:26:27 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:26:27 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:26:27 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:26:27 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:27 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:27 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:27 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:27 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:27 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:27 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:26:27 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:27 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:27 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:27 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:27 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:26:27 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:26:41 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:26:41 GMT -> LiveUpdate Language: English
    5/13/2010, 13:26:41 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:26:41 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:26:41 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:26:41 GMT -> IE 7 Support
    5/13/2010, 13:26:41 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:26:41 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:26:41 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:26:41 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:26:41 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:26:41 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:26:41 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:26:41 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:26:41 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:26:41 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:26:41 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:26:41 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:26:41 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:26:41 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:26:41 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:26:41 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:41 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:41 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:41 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:41 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:41 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:26:41 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:41 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:41 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:42 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:42 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:42 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:26:42 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:42 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:26:42 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=293424/TID=296336): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=293424/TID=296336): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=293424/TID=296336): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=293424/TID=296336): Destroyed luProductReg object.
    5/13/2010, 13:26:42 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:42 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:26:42 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:42 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:42 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:26:42 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:26:42 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:42 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:26:42 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=295816/TID=296388): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=295816/TID=296388): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=295816/TID=296388): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:42 GMT -> ProductRegCom/luProductReg(PID=295816/TID=296388): Destroyed luProductReg object.
    5/13/2010, 13:26:42 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:42 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:26:42 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:42 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:42 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:26:42 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:26:42 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:42 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:26:42 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:26:42 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:26:42 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:26:42 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:26:42 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:26:42 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:26:42 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:42 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:26:42 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:26:42 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:26:42 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:42 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\liveupdt.grd"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941", HR: 0x0       
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:42 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941", HR: 0x0       
    5/13/2010, 13:26:42 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\liveupdt.tri"
    5/13/2010, 13:26:42 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri941\syknapps_engine.zip.dat"
    5/13/2010, 13:26:42 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:26:42 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:26:42 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:26:42 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:26:42 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:42 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:42 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:42 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:43 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:43 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:43 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:26:43 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:43 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:43 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:43 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:43 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:26:43 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:26:54 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:26:54 GMT -> LiveUpdate Language: English
    5/13/2010, 13:26:54 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:26:54 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:26:54 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:26:54 GMT -> IE 7 Support
    5/13/2010, 13:26:54 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:26:54 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:26:54 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:26:54 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:26:54 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:26:54 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:26:54 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:26:54 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:26:54 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:26:54 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:26:54 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:26:54 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:26:54 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:26:54 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:26:54 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:26:54 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:54 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:54 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:54 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:54 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:54 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:26:54 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:54 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:54 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:54 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:54 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:54 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:26:55 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:55 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:26:55 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=296776/TID=294376): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=296776/TID=294376): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=296776/TID=294376): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=296776/TID=294376): Destroyed luProductReg object.
    5/13/2010, 13:26:55 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:55 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:26:55 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:55 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:55 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:26:55 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:26:55 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:26:55 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:26:55 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=294260/TID=294440): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=294260/TID=294440): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=294260/TID=294440): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:26:55 GMT -> ProductRegCom/luProductReg(PID=294260/TID=294440): Destroyed luProductReg object.
    5/13/2010, 13:26:55 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:55 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:26:55 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:26:56 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:56 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:26:56 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:26:56 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:56 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:26:56 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:26:56 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:26:56 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:26:56 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:26:56 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:26:56 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:26:56 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:26:56 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:26:56 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:26:56 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:26:56 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:56 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\liveupdt.grd"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987", HR: 0x0       
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:26:56 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987", HR: 0x0       
    5/13/2010, 13:26:56 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\liveupdt.tri"
    5/13/2010, 13:26:56 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri987\syknapps_engine.zip.dat"
    5/13/2010, 13:26:56 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:26:56 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:26:56 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:26:56 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:26:56 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:26:56 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:56 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:26:56 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:56 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:56 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:26:56 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:26:56 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:26:56 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:26:56 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:26:56 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:26:56 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:26:56 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:27:09 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:27:09 GMT -> LiveUpdate Language: English
    5/13/2010, 13:27:09 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:27:09 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:27:09 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:27:09 GMT -> IE 7 Support
    5/13/2010, 13:27:09 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:27:09 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:27:09 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:27:09 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:27:09 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:27:09 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:27:09 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:27:09 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:27:09 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:27:09 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:27:09 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:27:09 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:27:09 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:27:09 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:27:09 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:27:09 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:09 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:09 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:09 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:09 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:09 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:27:09 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:09 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:09 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:10 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:10 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:10 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:27:10 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:10 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:27:10 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=293808/TID=293396): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=293808/TID=293396): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=293808/TID=293396): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=293808/TID=293396): Destroyed luProductReg object.
    5/13/2010, 13:27:10 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:10 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:27:10 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:10 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:10 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:27:10 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:27:10 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:10 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:27:10 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=295548/TID=295500): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=295548/TID=295500): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=295548/TID=295500): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:10 GMT -> ProductRegCom/luProductReg(PID=295548/TID=295500): Destroyed luProductReg object.
    5/13/2010, 13:27:10 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:10 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:27:10 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:11 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:11 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:27:11 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:27:11 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:11 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:27:11 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:27:11 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:27:11 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:27:11 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:27:11 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:27:11 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:27:11 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:11 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:27:11 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:27:11 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:27:11 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:11 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\liveupdt.grd"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36", HR: 0x0       
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:11 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36", HR: 0x0       
    5/13/2010, 13:27:11 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\liveupdt.tri"
    5/13/2010, 13:27:11 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri36\syknapps_engine.zip.dat"
    5/13/2010, 13:27:11 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:27:11 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:27:11 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:27:11 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:27:11 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:11 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:11 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:11 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:11 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:11 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:11 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:27:11 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:11 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:11 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:11 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:11 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:27:11 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:27:23 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:27:23 GMT -> LiveUpdate Language: English
    5/13/2010, 13:27:23 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:27:23 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:27:23 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:27:23 GMT -> IE 7 Support
    5/13/2010, 13:27:23 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:27:23 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:27:23 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:27:23 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:27:23 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:27:23 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:27:23 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:27:23 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:27:23 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:27:23 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:27:23 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:27:23 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:27:23 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:27:23 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:27:23 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:27:23 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:23 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:23 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:23 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:23 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:23 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:27:24 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:24 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:24 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:24 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:24 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:24 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:27:24 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:24 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:27:24 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:27:24 GMT -> ProductRegCom/luProductReg(PID=296092/TID=295908): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:24 GMT -> ProductRegCom/luProductReg(PID=296092/TID=295908): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:24 GMT -> ProductRegCom/luProductReg(PID=296092/TID=295908): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:24 GMT -> ProductRegCom/luProductReg(PID=296092/TID=295908): Destroyed luProductReg object.
    5/13/2010, 13:27:24 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:24 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:27:24 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:24 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:24 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:27:24 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:27:24 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:25 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:27:25 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:27:25 GMT -> ProductRegCom/luProductReg(PID=295936/TID=295836): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:25 GMT -> ProductRegCom/luProductReg(PID=295936/TID=295836): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:25 GMT -> ProductRegCom/luProductReg(PID=295936/TID=295836): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:25 GMT -> ProductRegCom/luProductReg(PID=295936/TID=295836): Destroyed luProductReg object.
    5/13/2010, 13:27:25 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:25 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:27:25 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:25 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:25 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:27:25 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:27:25 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:25 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:27:25 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:27:25 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:27:25 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:27:25 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:27:25 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:27:25 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:27:25 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:25 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:27:25 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:27:25 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:27:25 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:25 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\liveupdt.grd"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81", HR: 0x0       
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:25 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81", HR: 0x0       
    5/13/2010, 13:27:25 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\liveupdt.tri"
    5/13/2010, 13:27:25 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri81\syknapps_engine.zip.dat"
    5/13/2010, 13:27:25 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:27:25 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:27:25 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:27:25 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:27:25 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:25 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:25 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:25 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:25 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:25 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:25 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:27:25 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:25 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:25 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:25 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:25 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:27:25 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:27:36 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:27:36 GMT -> LiveUpdate Language: English
    5/13/2010, 13:27:36 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:27:36 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:27:36 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:27:36 GMT -> IE 7 Support
    5/13/2010, 13:27:36 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:27:36 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:27:36 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:27:36 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:27:36 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:27:36 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:27:36 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:27:36 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:27:36 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:27:36 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:27:36 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:27:36 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:27:36 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:27:36 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:27:36 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:27:37 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:37 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:37 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:37 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:27:37 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:37 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:37 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:37 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:27:37 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:37 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:27:37 GMT -> ProductRegCom/luProductReg(PID=296176/TID=296144): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:37 GMT -> ProductRegCom/luProductReg(PID=296176/TID=296144): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:37 GMT -> ProductRegCom/luProductReg(PID=296176/TID=296144): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:37 GMT -> ProductRegCom/luProductReg(PID=296176/TID=296144): Destroyed luProductReg object.
    5/13/2010, 13:27:37 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:37 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:27:37 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:37 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:37 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:27:37 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:27:38 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:38 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:27:38 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:27:38 GMT -> ProductRegCom/luProductReg(PID=296592/TID=296596): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:38 GMT -> ProductRegCom/luProductReg(PID=296592/TID=296596): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:38 GMT -> ProductRegCom/luProductReg(PID=296592/TID=296596): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:38 GMT -> ProductRegCom/luProductReg(PID=296592/TID=296596): Destroyed luProductReg object.
    5/13/2010, 13:27:38 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:38 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:27:38 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:38 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:38 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:27:38 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:27:38 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:38 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:27:38 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:27:38 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:27:38 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:27:38 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:27:38 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:27:38 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:27:38 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:38 GMT -> Progress Update: HOST_SELECTED: Host IP: "192.168.252.247" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    5/13/2010, 13:27:38 GMT -> Attempting to load SymCrypt...
    5/13/2010, 13:27:38 GMT -> SymCrypt.dll does not exist.
    5/13/2010, 13:27:38 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:38 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\liveupdt.grd"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124", HR: 0x0       
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    5/13/2010, 13:27:38 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124", HR: 0x0       
    5/13/2010, 13:27:38 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\liveupdt.tri"
    5/13/2010, 13:27:38 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri124\syknapps_engine.zip.dat"
    5/13/2010, 13:27:38 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    5/13/2010, 13:27:38 GMT -> ********* Finished Finding Available Updates *********
     
    5/13/2010, 13:27:38 GMT -> LiveUpdate did not find any new updates for the given products.
    5/13/2010, 13:27:38 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    5/13/2010, 13:27:38 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:38 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:38 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:38 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:38 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:38 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:38 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    5/13/2010, 13:27:38 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:38 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:38 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    5/13/2010, 13:27:38 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:38 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    5/13/2010, 13:27:38 GMT -> ***********************           End of LU Session           ***********************
    5/13/2010, 13:27:50 GMT -> LuComServer version: 3.3.0.96
    5/13/2010, 13:27:50 GMT -> LiveUpdate Language: English
    5/13/2010, 13:27:50 GMT -> LuComServer Sequence Number: 20091211
    5/13/2010, 13:27:50 GMT -> OS: Windows XP Professional, Service Pack: 3, Major: 5, Minor: 1, Build: 2600 (32-bit)
    5/13/2010, 13:27:50 GMT -> System Language:[0x0409], User Language:[0x0409]
    5/13/2010, 13:27:50 GMT -> IE 7 Support
    5/13/2010, 13:27:50 GMT -> ComCtl32 version: 6.0
    5/13/2010, 13:27:50 GMT -> IP Addresses: 192.168.252.247
    5/13/2010, 13:27:50 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    5/13/2010, 13:27:50 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    5/13/2010, 13:27:50 GMT -> Account launching LiveUpdate is not a logged in user's account
    5/13/2010, 13:27:50 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    5/13/2010, 13:27:50 GMT -> LiveUpdate flag value for this run is 0
    5/13/2010, 13:27:50 GMT -> **** Starting a Silent LiveUpdate Session ****
    5/13/2010, 13:27:50 GMT -> ***********************        Start of New LU Session        ***********************
    5/13/2010, 13:27:50 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    5/13/2010, 13:27:50 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    5/13/2010, 13:27:50 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    5/13/2010, 13:27:50 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    5/13/2010, 13:27:50 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    5/13/2010, 13:27:50 GMT -> Starting Callback Proxy Worker thread.
    5/13/2010, 13:27:50 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:50 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:50 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    5/13/2010, 13:27:50 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:50 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    5/13/2010, 13:27:50 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    5/13/2010, 13:27:50 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:50 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:50 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    5/13/2010, 13:27:51 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:51 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    5/13/2010, 13:27:51 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    5/13/2010, 13:27:51 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:51 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    5/13/2010, 13:27:51 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295116/TID=295136): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295116/TID=295136): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295116/TID=295136): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295116/TID=295136): Destroyed luProductReg object.
    5/13/2010, 13:27:51 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:51 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    5/13/2010, 13:27:51 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:51 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:51 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    5/13/2010, 13:27:51 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    5/13/2010, 13:27:51 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    5/13/2010, 13:27:51 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    5/13/2010, 13:27:51 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295164/TID=291668): Successfully created an instance of an luProductReg object!
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295164/TID=291668): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295164/TID=291668): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100512017
    5/13/2010, 13:27:51 GMT -> ProductRegCom/luProductReg(PID=295164/TID=291668): Destroyed luProductReg object.
    5/13/2010, 13:27:51 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    5/13/2010, 13:27:51 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    5/13/2010, 13:27:51 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    5/13/2010, 13:27:51 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    5/13/2010, 13:27:51 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    5/13/2010, 13:27:51 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    5/13/2010, 13:27:51 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    5/13/2010, 13:27:51 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    5/13/2010, 13:27:51 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1 Downloading Mini-TRI files
    5/13/2010, 13:27:51 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    5/13/2010, 13:27:51 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    5/13/2010, 13:27:51 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    5/13/2010, 13:27:51 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    5/13/2010, 13:27:51 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    5/13/2010, 13:27:51 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri166\symantec$20known$20applica


  • 4.  RE: Liveupdate runs every few seconds

    Posted Jun 04, 2010 07:07 PM

    I seem to be having this on a few of my servers as well...  Although I can't seem to find the log to look into this problem myself.

    Right now, the machines affected seem to be polling every 5-7 minutes with liveupdate and I know the packages I made did not have a liveupdate scheduling set.


  • 5.  RE: Liveupdate runs every few seconds

    Posted Jun 05, 2010 09:16 PM
    Yeah this is very strange indeed. The only issue I have ever heard regarding this was that fix in MR1 that you mentioned. I can't seem to find any other info. Maybe we should start by just trying to reinstall liveupdate to see if that helps. Consult this guide to do so:



    How to Uninstall and Reinstall LiveUpdate When a Symantec Endpoint Protection Manager or Symantec Endpoint Protection Client is Installed

    http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/1c20d369605a3d248825736f004fb402?OpenDocument

    Cheers
    Grant




  • 6.  RE: Liveupdate runs every few seconds

    Posted Jun 07, 2010 11:38 AM

    I tried reinstalling Liveupdate as suggested above.  Unfortunately, the problem still exists on the server I tried doing this on.


  • 7.  RE: Liveupdate runs every few seconds

    Posted Jun 07, 2010 11:44 AM
    Have you attempted to update a couple clients to see if its related to the use of RU5 with RU6 manager. Even though this should work it may be a defect


  • 8.  RE: Liveupdate runs every few seconds

    Posted Jun 07, 2010 11:49 AM

    Not exactly sure what you mean.  Right now, we are using the RU5 Manager with RU5 clients.  If you mean push update content, yes., but does not resolve the problem.


  • 9.  RE: Liveupdate runs every few seconds

    Posted Jun 09, 2010 01:28 PM

    Trying to still find out if anyone else has any recommendations for this.


  • 10.  RE: Liveupdate runs every few seconds

    Posted Jun 09, 2010 05:17 PM

    - What's the heartbeat for the client?  (Even though definitions are retrieved through the SEPM, LiveUpdate is still utilized for content delivery, which is what the "TempHostEx" mode means.)

    - Are there any error messages related to this that are noted in the Windows event log?

    - Are you seeing anything like 'waiting for updates' or something similar in the client-side SEP GUI?  If so, for which component?

    - Are there any other Symantec products on the client machines that might be trying to run LiveUpdate?

    Thanks,
    sandra


  • 11.  RE: Liveupdate runs every few seconds

    Posted Jun 09, 2010 05:43 PM
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    // Start LuComServer
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    6/9/2010, 21:14:58 GMT -> LuComServer version: 3.3.0.92
    6/9/2010, 21:14:58 GMT -> LiveUpdate Language: English
    6/9/2010, 21:14:58 GMT -> LuComServer Sequence Number: 20090713
    6/9/2010, 21:14:58 GMT -> OS: Windows 2003 Standard, Service Pack: 2, Major: 5, Minor: 2, Build: 3790 (32-bit)
    6/9/2010, 21:14:58 GMT -> System Language:[0x0409], User Language:[0x0409]
    6/9/2010, 21:14:58 GMT -> IE 7 Support
    6/9/2010, 21:14:58 GMT -> ComCtl32 version: 6.0
    6/9/2010, 21:14:58 GMT -> IP Addresses: x.x.x.16
    6/9/2010, 21:14:58 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    6/9/2010, 21:14:58 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    6/9/2010, 21:14:58 GMT -> Account launching LiveUpdate is not a logged in user's account
    6/9/2010, 21:14:58 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    6/9/2010, 21:14:58 GMT -> LiveUpdate flag value for this run is 0
    6/9/2010, 21:14:58 GMT -> **** Starting a Silent LiveUpdate Session ****
    6/9/2010, 21:14:58 GMT -> ***********************        Start of New LU Session        ***********************
    6/9/2010, 21:14:58 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    6/9/2010, 21:14:58 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    6/9/2010, 21:14:58 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    6/9/2010, 21:14:58 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    6/9/2010, 21:14:58 GMT -> Starting Callback Proxy Worker thread.
    6/9/2010, 21:14:58 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    6/9/2010, 21:14:58 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:14:58 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:14:58 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    6/9/2010, 21:14:58 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    6/9/2010, 21:14:58 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    6/9/2010, 21:14:58 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:14:58 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    6/9/2010, 21:14:58 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    6/9/2010, 21:14:58 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    6/9/2010, 21:14:58 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=980/TID=144): Successfully created an instance of an luProductReg object!
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=980/TID=144): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=980/TID=144): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100609018
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=980/TID=144): Destroyed luProductReg object.
    6/9/2010, 21:14:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:14:59 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    6/9/2010, 21:14:59 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    6/9/2010, 21:14:59 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:14:59 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    6/9/2010, 21:14:59 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    6/9/2010, 21:14:59 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    6/9/2010, 21:14:59 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    6/9/2010, 21:14:59 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=3628/TID=3940): Successfully created an instance of an luProductReg object!
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=3628/TID=3940): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=3628/TID=3940): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100609018
    6/9/2010, 21:14:59 GMT -> ProductRegCom/luProductReg(PID=3628/TID=3940): Destroyed luProductReg object.
    6/9/2010, 21:14:59 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:14:59 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    6/9/2010, 21:14:59 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    6/9/2010, 21:14:59 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:14:59 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    6/9/2010, 21:14:59 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    6/9/2010, 21:14:59 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    6/9/2010, 21:14:59 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    6/9/2010, 21:14:59 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1    Downloading Mini-TRI files
    6/9/2010, 21:14:59 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    6/9/2010, 21:14:59 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    6/9/2010, 21:14:59 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    6/9/2010, 21:14:59 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    6/9/2010, 21:14:59 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    6/9/2010, 21:14:59 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    6/9/2010, 21:14:59 GMT -> Progress Update: HOST_SELECTED: Host IP: "x.x.x.16" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    6/9/2010, 21:14:59 GMT -> Attempting to load SymCrypt...
    6/9/2010, 21:14:59 GMT -> SymCrypt.dll does not exist.
    6/9/2010, 21:14:59 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    6/9/2010, 21:14:59 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\liveupdt.grd"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157", HR: 0x0       
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    6/9/2010, 21:14:59 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157", HR: 0x0       
    6/9/2010, 21:15:00 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\liveupdt.tri"
    6/9/2010, 21:15:00 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri157\syknapps_engine.zip.dat"
    6/9/2010, 21:15:00 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    6/9/2010, 21:15:00 GMT -> ********* Finished Finding Available Updates *********

    6/9/2010, 21:15:00 GMT -> LiveUpdate did not find any new updates for the given products.
    6/9/2010, 21:15:00 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    6/9/2010, 21:15:00 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:15:00 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:15:00 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    6/9/2010, 21:15:00 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    6/9/2010, 21:15:00 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:15:00 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    6/9/2010, 21:15:00 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    6/9/2010, 21:15:00 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:15:00 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    6/9/2010, 21:15:00 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    6/9/2010, 21:15:00 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:15:00 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    6/9/2010, 21:15:00 GMT -> ***********************           End of LU Session           ***********************
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    // End LuComServer
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////

    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    // Start LuComServer
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    6/9/2010, 21:20:28 GMT -> LuComServer version: 3.3.0.92
    6/9/2010, 21:20:28 GMT -> LiveUpdate Language: English
    6/9/2010, 21:20:28 GMT -> LuComServer Sequence Number: 20090713
    6/9/2010, 21:20:28 GMT -> OS: Windows 2003 Standard, Service Pack: 2, Major: 5, Minor: 2, Build: 3790 (32-bit)
    6/9/2010, 21:20:28 GMT -> System Language:[0x0409], User Language:[0x0409]
    6/9/2010, 21:20:28 GMT -> IE 7 Support
    6/9/2010, 21:20:28 GMT -> ComCtl32 version: 6.0
    6/9/2010, 21:20:28 GMT -> IP Addresses: x.x.x.16
    6/9/2010, 21:20:28 GMT -> Loading C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
    6/9/2010, 21:20:28 GMT -> Opened the product inventory at "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate".
    6/9/2010, 21:20:28 GMT -> Account launching LiveUpdate is not a logged in user's account
    6/9/2010, 21:20:28 GMT -> Combined Product Inventory Flags 0, Permanent Flags 0, Permanent Flags Filter 0
    6/9/2010, 21:20:28 GMT -> LiveUpdate flag value for this run is 0
    6/9/2010, 21:20:28 GMT -> **** Starting a Silent LiveUpdate Session ****
    6/9/2010, 21:20:28 GMT -> ***********************        Start of New LU Session        ***********************
    6/9/2010, 21:20:28 GMT -> The command line is -S -temphostex "C:\Program Files\Symantec\Symantec Endpoint Protection\ContentCache\{C25CEA47-63E5-447b-8D95-C79CAE13FF79}\80929016" -M{C25CEA47-63E5-447b-8D95-C79CAE13FF79} -updateoptout=yes
    6/9/2010, 21:20:28 GMT -> ***** This LiveUpdate session is running in TempHostEx mode. *****
    6/9/2010, 21:20:28 GMT -> TempHostEx moniker is {C25CEA47-63E5-447B-8D95-C79CAE13FF79}
    6/9/2010, 21:20:28 GMT -> EVENT - SESSION START EVENT - The LiveUpdate session is running in Silent Mode.
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC Virus Definitions Win32 v11 with moniker {C60DC234-65F9-4674-94AE-62158EFCA433}.
    6/9/2010, 21:20:28 GMT -> Starting Callback Proxy Worker thread.
    6/9/2010, 21:20:28 GMT -> The callback proxy for moniker {C60DC234-65F9-4674-94AE-62158EFCA433} was successfully registered with LiveUpdate.
    6/9/2010, 21:20:28 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:20:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:28 GMT -> The PreSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to launch a new callback proxy process for product SESC IPS Signatures Win32 with moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3}.
    6/9/2010, 21:20:28 GMT -> The callback proxy for moniker {D3769926-05B7-4ad1-9DCF-23051EEE78E3} was successfully registered with LiveUpdate.
    6/9/2010, 21:20:28 GMT -> LiveUpdate successfully launched a new callback proxy process for product SESC IPS Signatures Win32.
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to execute a PreSession callback for product SESC IPS Signatures Win32.
    6/9/2010, 21:20:28 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:28 GMT -> The PreSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content B1 with moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522}.
    6/9/2010, 21:20:28 GMT -> The callback proxy for moniker {E5A3EBEE-D580-421e-86DF-54C0B3739522} was successfully registered with LiveUpdate.
    6/9/2010, 21:20:28 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content B1.
    6/9/2010, 21:20:28 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content B1.
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=3576/TID=3264): Successfully created an instance of an luProductReg object!
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=3576/TID=3264): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=3576/TID=3264): Setting property for Moniker = {E5A3EBEE-D580-421e-86DF-54C0B3739522}, PropertyName = SEQ.CURDEFS, Value = 100609018
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=3576/TID=3264): Destroyed luProductReg object.
    6/9/2010, 21:20:29 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:29 GMT -> The PreSession callback for product Symantec Security Content B1 completed with a result of 0x0       
    6/9/2010, 21:20:29 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    6/9/2010, 21:20:29 GMT -> LiveUpdate has called the last callback for product Symantec Security Content B1, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:20:29 GMT -> LiveUpdate is about to launch a new callback proxy process for product Symantec Security Content A1 with moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF}.
    6/9/2010, 21:20:29 GMT -> The callback proxy executable for product {E5A3EBEE-D580-421e-86DF-54C0B3739522} is exiting with no errors
    6/9/2010, 21:20:29 GMT -> The callback proxy for moniker {812CD25E-1049-4086-9DDD-A4FAE649FBDF} was successfully registered with LiveUpdate.
    6/9/2010, 21:20:29 GMT -> LiveUpdate successfully launched a new callback proxy process for product Symantec Security Content A1.
    6/9/2010, 21:20:29 GMT -> LiveUpdate is about to execute a PreSession callback for product Symantec Security Content A1.
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=2508/TID=616): Successfully created an instance of an luProductReg object!
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=2508/TID=616): Path for calling process executable is C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe.
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=2508/TID=616): Setting property for Moniker = {812CD25E-1049-4086-9DDD-A4FAE649FBDF}, PropertyName = SEQ.CURDEFS, Value = 100609018
    6/9/2010, 21:20:29 GMT -> ProductRegCom/luProductReg(PID=2508/TID=616): Destroyed luProductReg object.
    6/9/2010, 21:20:29 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:29 GMT -> The PreSession callback for product Symantec Security Content A1 completed with a result of 0x0       
    6/9/2010, 21:20:29 GMT -> Successfully released callback {6FDEE0F0-ECD7-423C-BD1C-525ECBAC7E1B}
    6/9/2010, 21:20:29 GMT -> LiveUpdate has called the last callback for product Symantec Security Content A1, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:20:29 GMT -> Progress Update: TRYING_HOST: HostName: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 0
    6/9/2010, 21:20:29 GMT -> In TempHostEx mode, LiveUpdate will retrieve updates from this location: C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016
    6/9/2010, 21:20:29 GMT -> Check for updates to:  Product: Symantec Known Application System, Version: 1.5.0, Language: SymAllLanguages.  Mini-TRI file name: symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    6/9/2010, 21:20:29 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "0"
    6/9/2010, 21:20:29 GMT -> Progress Update: TRIFILE_DOWNLOAD_START: Number of TRI files: 1    Downloading Mini-TRI files
    6/9/2010, 21:20:29 GMT -> Progress Update: DOWNLOAD_BATCH_START: Files to download: 1, Estimated total size: 0
    6/9/2010, 21:20:29 GMT -> Progress Update: DOWNLOAD_FILE_START: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Estimated Size: 0, Destination Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads"
    6/9/2010, 21:20:29 GMT -> The callback proxy executable for product {812CD25E-1049-4086-9DDD-A4FAE649FBDF} is exiting with no errors
    6/9/2010, 21:20:29 GMT -> Progress Update: DOWNLOAD_FILE_FINISH: URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Full Download Path: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip" HR: 0x0       
    6/9/2010, 21:20:29 GMT -> Progress Update: DOWNLOAD_BATCH_FINISH: HR: 0x0       , Num Successful: 1
    6/9/2010, 21:20:29 GMT -> LiveUpdate copied the Mini-TRI file from C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip to C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip
    6/9/2010, 21:20:29 GMT -> Progress Update: HOST_SELECTED: Host IP: "x.x.x.16" URL: "C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79}\80929016" HostNumber: 4294967295
    6/9/2010, 21:20:29 GMT -> Attempting to load SymCrypt...
    6/9/2010, 21:20:29 GMT -> SymCrypt.dll does not exist.
    6/9/2010, 21:20:29 GMT -> EVENT - SERVER SELECTION SUCCESSFUL EVENT - LiveUpdate connected to server C:\PROGRAM FILES\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\CONTENTCACHE\{C25CEA47-63E5-447B-8D95-C79CAE13FF79} at path C:\PROGRAM%20FILES\SYMANTEC\SYMANTEC%20ENDPOINT%20PROTECTION\CONTENTCACHE\%7BC25CEA47-63E5-447B-8D95-C79CAE13FF79%7D\80929016 via a LAN connection. The server connection connected with a return code of 200, Successfully download TRI file
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.grd"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.sig"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    6/9/2010, 21:20:29 GMT -> Progress Update: SECURITY_SIGNATURE_MATCHED: GuardFile: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\liveupdt.grd"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235", HR: 0x0       
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_START: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "liveupdt.tri"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_PROGRESS: Extracting file: "syknapps_engine.zip.dat"
    6/9/2010, 21:20:29 GMT -> Progress Update: UNZIP_FILE_FINISH: Zip File: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\symantec$20known$20application$20system_1.5.0_symalllanguages_livetri.zip", Dest Folder: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235", HR: 0x0       
    6/9/2010, 21:20:29 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\liveupdt.tri"
    6/9/2010, 21:20:29 GMT -> Progress Update: SECURITY_PACKAGE_TRUSTED: "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\Tri235\syknapps_engine.zip.dat"
    6/9/2010, 21:20:29 GMT -> Progress Update: TRIFILE_DOWNLOAD_END: Number of TRI files: "1"
    6/9/2010, 21:20:29 GMT -> ********* Finished Finding Available Updates *********

    6/9/2010, 21:20:29 GMT -> LiveUpdate did not find any new updates for the given products.
    6/9/2010, 21:20:29 GMT -> EVENT - SESSION END SUCCESSFUL EVENT - The LiveUpdate session ran in Silent Mode. LiveUpdate found 0 updates available, of which 0 were installed and 0 failed to install.  The LiveUpdate session exited with a return code of 100, LiveUpdate ran successfully.  There are no new updates to your products.
    6/9/2010, 21:20:29 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC Virus Definitions Win32 v11.
    6/9/2010, 21:20:29 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:29 GMT -> The PostSession callback for product SESC Virus Definitions Win32 v11 completed with a result of 0x0       
    6/9/2010, 21:20:29 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    6/9/2010, 21:20:30 GMT -> LiveUpdate has called the last callback for product SESC Virus Definitions Win32 v11, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:20:30 GMT -> LiveUpdate is about to execute a PostSession callback for product SESC IPS Signatures Win32.
    6/9/2010, 21:20:30 GMT -> The callback proxy executable for product {C60DC234-65F9-4674-94AE-62158EFCA433} is exiting with no errors
    6/9/2010, 21:20:30 GMT -> The callback proxy finished executing the callback with a result code of 0x0
    6/9/2010, 21:20:30 GMT -> The PostSession callback for product SESC IPS Signatures Win32 completed with a result of 0x0       
    6/9/2010, 21:20:30 GMT -> Successfully released callback {855BA5F4-6588-4F09-AE61-847E59D08CB0}
    6/9/2010, 21:20:30 GMT -> LiveUpdate has called the last callback for product SESC IPS Signatures Win32, so LiveUpdate is informing the callback proxy that it can exit.
    6/9/2010, 21:20:30 GMT -> The callback proxy executable for product {D3769926-05B7-4ad1-9DCF-23051EEE78E3} is exiting with no errors
    6/9/2010, 21:20:30 GMT -> ***********************           End of LU Session           ***********************
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////
    // End LuComServer
    ////////////////////////////////////////////////////////////////////////////////
    ////////////////////////////////////////////////////////////////////////////////



    I cannot see any errors.  Some of the other servers have it the 'early' LU updating (IE, it updates, then looks for updates again.)  This machine only had one bad report, citing non-criticals, but couldn't update but even after reinstalling LU to get rid of it, it still keeps re-running the service more times than it should.

    As for Waiting for updates, no signs of that on the client side SEP.

    Only other Symantec Product running, is the Veritas Back-Up Exec 9 Agent, which isn't really tied into Liveupdates (Or shouldn't be because this is an old version of Backup Exec, before Symantec acquired it.)


  • 12.  RE: Liveupdate runs every few seconds

    Posted Jun 15, 2010 11:42 AM

    Well, let's rephrase the question then... Is there a way to look at what is causing the Liveupdate to trigger off like it was scheduled to go off at certain time intervals or manually changing it?


  • 13.  RE: Liveupdate runs every few seconds

    Posted Jun 15, 2010 12:41 PM
    Unfortunately I just wiped out my test box and can't check the registry for entries for LiveUpdate schedule.  I found reference to a key here but I'm not sure this is where schedule information is kept.  HKLM\Software\Symantec\Symantec Endpoint Protection\Live Update\Schedule

    Another thought: is there plenty of hard drive space on the machines having this issue?

    sandra


  • 14.  RE: Liveupdate runs every few seconds

    Posted Jun 15, 2010 12:51 PM
      |   view attached

    There doesn't seem to be an issue with space at the moment, otherwise, the machines in question would not be getting updates and some might even have serious ability to function.  The one machine I pulled that information from has enough space for me to install Office 2007 at least 5+ times over if need be, so I know it is not a space issue.

    Here is what I seem to have for the registry, i exported it and changed it to a txt file.

    Attachment(s)

    txt
    SEPLUSced.txt   1 KB 1 version


  • 15.  RE: Liveupdate runs every few seconds

    Posted Jun 21, 2010 12:47 PM

    I'm revisiting this topic to see if anyone has any ideas?


  • 16.  RE: Liveupdate runs every few seconds

    Posted Jun 21, 2010 03:46 PM

    If I'm reading the registry information correctly, the schedule is showing as disabled:

    "Enabled"=dword:00000000

    Is the LiveUpdate service (in services.msc) set to Manual?  (It should be.)

    What is the heartbeat for this client?

    Maybe a SEP Support Tool is in order...  feel free to upload the results here.

    Title: 'The Symantec Endpoint Protection Support Tool'
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008071709480648

    sandra





  • 17.  RE: Liveupdate runs every few seconds

    Posted Jun 21, 2010 04:50 PM
      |   view attached

    The Service is set at manual.  SEP tool showed some errors.  Here is the result...

    Attachment(s)



  • 18.  RE: Liveupdate runs every few seconds

    Posted Jun 21, 2010 05:15 PM
    - It does indicate that a restart is required... has that been done recently? 

    - It's also indicating possible definition corruption, so I'd suggest trying using Intelligent Updater to clear that out.  You can get that here.  Just get the correct one for SEP, for 32-bit machines.

    - I would also suggest trying migrating to RU6.

    sandra


  • 19.  RE: Liveupdate runs every few seconds

    Posted Jun 22, 2010 11:32 PM
    Empty the corrupted definition,  and check the LU policy to see the LU scheduling. Make sure there is enough space to download definition


  • 20.  RE: Liveupdate runs every few seconds

    Posted Jun 23, 2010 07:31 PM

    The corrupted efinition was taken care of by the Liveupdate.  On the LU Scheduling, it has the following:

    Enable LU scheduled  - Not Checked.

    Under Server Settings - Use the default management server.  'Use a LiveUpdate Server' is not checked.


  • 21.  RE: Liveupdate runs every few seconds

    Posted Jun 23, 2010 10:41 PM
    The corrupted definition was taken care of by the Liveupdate.  
    ====================
    Not quite sure what this mean. Sometimes it should be cleaned manually. For example, go to Control panel, open Symantec Liveupdate, under Update Cache tab, click Remove all files from cache.


  • 22.  RE: Liveupdate runs every few seconds

    Posted Jun 24, 2010 12:30 PM

    What about the reboot, and trying the newest build?

    sandra


  • 23.  RE: Liveupdate runs every few seconds

    Posted Jun 24, 2010 02:25 PM

    I have rebooted a few times and the problem is still there.  I cannot get the latest build, the RU6 or RU6a at this time, as this is what the Campus (I work for UCSB) has at the moment as part of their thing.


  • 24.  RE: Liveupdate runs every few seconds

    Posted Jun 24, 2010 02:26 PM

    I have also did that as well as the recommended clearing of the corrupted definitions stated from the Septool.  Issue is still there, every 6 minutes for this server, Live Update kicks in.


  • 25.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 12:43 AM
    OK, have u installed other symantec products? such as SAV? And i think you said this occurred in client, would you please paste sylink monitor log here? it's better to have the log as the same time when LU started.


  • 26.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 10:13 AM
    Was non-console RDP used to connect to the SEPM when creating the installation package that was then used to install onto this affected machine?  How about during the process of installing SEP to this machine?

    sandra


  • 27.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 12:13 PM

    I was using RDP to the server when creating the packages on SEPM.  I believe I had to do a manual (Not through SEPM) install of the package due to many of the servers at the time had an older install of SEP on it, and I uninstalled the old one, along with Liveupdate just in case, to reinstall the SEP Client (Previous problem was either client did not talk with server for some, or would not update definitions and required SEPM to be reinstalled)

    SEP was also installed while using RDP.  This was not on the console or forcing a console connection.


  • 28.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 12:41 PM

    Non-console access can introduce issues that are difficult to trace, particularly if sessions terminate in a non-graceful way and the changes from the session's registry are not properly integrated into the console registry.  I'm not saying this is absolutely the cause, but you may want to take steps to eliminate this as a possibility--

    - repair installation of SEPM while in a console session
    - recreate the client install package while in a console session

    VNC (for example) always gives console access too, as does PC Anywhere.  I do not believe Dameware gives true console.

    For your information:

    Title: 'How to install or manage Symantec AntiVirus and Symantec Endpoint Protection components through Remote Desktop'
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008030509272248

    Title: 'How to repair the Symantec Endpoint Protection Manager installation through Add or Remove Programs'
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2009030414141748

    Thanks,
    sandra


  • 29.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 12:45 PM

    I believe I mentioned above that the only other "product" on the system would have been the Backup Exec Remote Server Agent, but this is Backup Exec 9, Veritas (Pre-Symantec Acquiring), so I doubt that counts as a symantec product that Liveupdate would be pinging off of.  There is also no Ghost client installed on this computer, pre or post Symantec, which I know we have Ghost, but checked that it does not have the ghost client on it.

    What I have gotten from the Syslink is the following:

    06/25 09:19:54 [3464] <CExpBackoff::CExpBackoff()>
    06/25 09:19:54 [3464] </CExpBackoff::CExpBackoff()>
    06/25 09:19:54 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:19:54 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:20:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:20:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:21:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:21:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:22:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:22:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:23:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:23:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:24:14 [216] <MaintainPushConnection:>SMS return=200
    06/25 09:24:14 [216] <ParseHTTPStatusCode:>200=>200 OK
    06/25 09:24:14 [216] <MaintainPushConnection:>RECEIVE STAGE COMPLETED
    06/25 09:24:14 [216] <MaintainPushConnection:>COMPLETED
    06/25 09:24:14 [216] <ScheduleNextUpdate>Manually assigned heartbeat=5 seconds
    06/25 09:24:14 [216] HEARTBEAT: Check Point 8
    06/25 09:24:14 [216] <PostEvent>going to post event=EVENT_SERVER_DISCONNECTED
    06/25 09:24:14 [216] <PostEvent>done post event=EVENT_SERVER_DISCONNECTED, return=0
    06/25 09:24:14 [216] <IndexHeartbeatProc>====== IndexHeartbeat Procedure stops at 09:24:14 ======
    06/25 09:24:14 [216] <IndexHeartbeatProc>Set Heartbeat Result= 2
    06/25 09:24:14 [216] <IndexHeartbeatProc>Sylink Comm.Flags: 'Connection Failed' = 0, 'Using Backup Sylink' = 0, 'Using Location Config' = 0
    06/25 09:24:14 [216] Use new configuration
    06/25 09:24:14 [216] HEARTBEAT: Check Point Complete
    06/25 09:24:14 [216] <IndexHeartbeatProc>Done, Heartbeat=5seconds
    06/25 09:24:14 [216] </CSyLink::IndexHeartbeatProc()>
    06/25 09:24:14 [216] <CheckHeartbeatTimer>====== Heartbeat loop stops at 09:24:14 ======
    06/25 09:24:20 [216] <CheckHeartbeatTimer>====== Heartbeat loop starts at 09:24:20 ======
    06/25 09:24:20 [216] <GetOnlineNicInfo>:Netport Count=1
    06/25 09:24:20 [216] <GetOnlineNicInfo>:NicInfo<SSANICs><SSANIC Ip="x.x.x.16" Mac="00-0e-0c-84-a5-c0" Gateway="x.x.x.254" SubnetMask="255.255.255.0"/></SSANICs>
    06/25 09:24:20 [216] <CalcAgentHashKey>:CH=5488FBA7806FD61101304EF43821D6751RASgddomain.graddiv5723E45C87EA0A912B346D541A4C38F9
    06/25 09:24:20 [216] <CalcAgentHashKey>:CHKey=44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:24:20 [216] <CalcAgentHashKey>:C=5488FBA7806FD61101304EF43821D6751RASgddomain.graddiv
    06/25 09:24:20 [216] <CalcAgentHashKey>:CKey=5B2377063C0C6F0B557D48AE26E6851E
    06/25 09:24:20 [216] <CalcAgentHashKey>:UCH=5488FBA7806FD61101304EF43821D6750gdsaGDDOMAIN.GRADDIVRASgddomain.graddiv5723E45C87EA0A912B346D541A4C38F9
    06/25 09:24:20 [216] <CalcAgentHashKey>:UCHKey=F063BD9DC9BA63B48AFC1B96D1CEEA10
    06/25 09:24:20 [216] <CalcAgentHashKey>:UC=5488FBA7806FD61101304EF43821D6750gdsaGDDOMAIN.GRADDIVRASgddomain.graddiv
    06/25 09:24:20 [216] <CalcAgentHashKey>:UCKey=20601E3AA1773DF01FC86D101233FF65
    06/25 09:24:20 [216] <DoHeartbeat>HardwareID=5723E45C87EA0A912B346D541A4C38F9
    06/25 09:24:20 [216] <DoHeartbeat>CHKey=44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:24:20 [216] <DoHeartbeat>CKey=5B2377063C0C6F0B557D48AE26E6851E
    06/25 09:24:20 [216] <DoHeartbeat>UCHKey=F063BD9DC9BA63B48AFC1B96D1CEEA10
    06/25 09:24:20 [216] <DoHeartbeat>UCKey=20601E3AA1773DF01FC86D101233FF65
    06/25 09:24:20 [216] <DoHeartbeat> Set heartbeat event
    06/25 09:24:20 [216] Use new configuration
    06/25 09:24:20 [216] <CSyLink::IndexHeartbeatProc()>
    06/25 09:24:20 [216] <IndexHeartbeatProc> Got ConfigObject to proceed the operation.. pSylinkConfig: 01B7BAA8
    06/25 09:24:20 [216] <IndexHeartbeatProc>====== Reg Heartbeat loop starts at 09:24:20 ======
    06/25 09:24:21 [216] HEARTBEAT: Check Point 1
    06/25 09:24:21 [216] Get First Server!
    06/25 09:24:21 [216] HEARTBEAT: Check Point 2
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_SERVER_CONNECTING
    06/25 09:24:21 [216] <PostEvent>done post event=EVENT_SERVER_CONNECTING, return=0
    06/25 09:24:21 [216] HEARTBEAT: Check Point 3
    06/25 09:24:21 [216] <IndexHeartbeatProc>Setting the session timeout on Profile Session to 30000
    06/25 09:24:21 [216] HEARTBEAT: Check Point 4
    06/25 09:24:21 [216] <IndexHeartbeatProc>===Get Index STAGE===
    06/25 09:24:21 [216] ************CSN=11920
    06/25 09:24:21 [216] <mfn_MakeGetIndexUrl:>Request is: action=12&hostid=060582BA806FD6110021B42F4A1DA1B8&chk=44EAE74490FC19CB726769B2CB43EFD3&ck=5B2377063C0C6F0B557D48AE26E6851E&uchk=F063BD9DC9BA63B48AFC1B96D1CEEA10&uck=20601E3AA1773DF01FC86D101233FF65&hid=5723E45C87EA0A912B346D541A4C38F9&groupid=5488FBA7806FD61101304EF43821D675&mode=0&hbt=300&as=11920&cn=[hex]524153&lun=[hex]67647361&udn=[hex]4744444F4D41494E2E47524144444956
    06/25 09:24:21 [216] <GetIndexFileRequest:>http://x.x.x.17:80/secars/secars.dll?h=CF1411A06DE997CBFDF18A21DD59B1D59DAEB93B7704AF40928EB621ADC02CB9FD7B21625E43C261C3F926DD01F45928E68ACA761E975ECC0B8221FB49D92ED53749FBCA86A0988CF6AF00E0823A119928A385CC8D79CE457B9B7472AF580AF2C471189F4E1D7A799E67AA26F0E7BB4789BF81214B0DA8794CA9623A210911C081CC221135C49BE88B4A7EFB0CB2A0E097B6607BB61A345FB2A84C3B5BAE296431A4832A3444D4976CD8922ACB99AF57D23518011477E47391C9CE84182165529B7B47B55DDDAB55141480C82F021177B44E1167E262E9E0928740AFAC8676286653150761A4AF5FB7872687E2BE24833E81011FCA44512D87EB5CA96E34FA6E64CD4E0B081BA69D3A00D76CC3F7270D593E613EA1CB6AA17537BD1A22D477A16CB0B060DAF72D4E7A63E630623BBC18014CE60113657A5D736CBE954EE45D769CDFD232B252F5BE3068652A0422118FB8680959F3DBEE241B25FBEAB091C53EA7B609A3D01349DC274EF65C4B45C8574C7526726CCC0E92D4A48260F024A1AE
    06/25 09:24:21 [216] <GetIndexFileRequest:>SMS return=200
    06/25 09:24:21 [216] <ParseHTTPStatusCode:>200=>200 OK
    06/25 09:24:21 [216] <FindHeader>Sem-HashKey:=>44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:24:21 [216] <FindHeader>Sem-LANSensor:=>0
    06/25 09:24:21 [216] <FindHeader>Sem-Signatue:=>9015791799731CBA4527691A867D85EB36BE71744BF4F41FCC8458C972579D85AFBD6FBD164F8A2DD5D24D571D22E8C839E3D7FFEC27B98F1643804A36CECE6E716483740330F267DCD2E8491ABE4C1CB5BFD53C2AE879424C06030911C95ED4F641683A29FA4B9413B9885895DF88D52C46B0D06B8AF76659C093D2D16EA3D6
    06/25 09:24:21 [216] <mfn_DoGetIndexFile200>Content Lenght => 1351
    06/25 09:24:21 [216] SignIf::VerifySignature(data, dataLen, sig, sigLen) => Verification Successful..
    06/25 09:24:21 [216] <mfn_DoGetIndexFile200>Index File: <?xml version="1.0" encoding="UTF-8" ?><GroupIndex SiteID="F2C2A82A806FD61100F02DB78B240A35" ServerID="CA790D49806FD6110012429CEBE9B581" GroupID="648B0F5A806FD6110060A01F26A00514" GroupCheckSum="842CEA790A323210858413531" LastModifiedTime = "25/06/2010 02:37:35">    <Profile Checksum="D1496E3F7B515D2E766C2078A880CEAA" SerialNumber="648B-06/24/2010 09:52:06 562" LastModifiedTime="24/06/2010  09:52:16"/>    <ConfigFile Checksum="09C8EF2100A4E88CF5779B0F186B1975" LastModifiedTime="08/06/2010  11:38:45"/>    <IDSFile Checksum="703A0AE1B8EC84B36CDBAECB7E800283" LastModifiedTime="24/06/2010  09:52:16"/>    <SylinkFile Checksum="6630BBF3A4CC470DD0564FB7EA0A31E3" LastModifiedTime="24/06/2010  09:52:16"/>    <LSProfile Checksum="67EAF9E3996257EDCAAF0B0EF81C88B3" SerialNumber ="648B-06/24/2010 09:52:06 562" LastModifiedTime ="24/06/2010  09:52:16"/>
        <LiveUpdate>
            <File Checksum="8E1FC07E11FAC34877F87EA4FA17F75B" DeltaFlag="1" FullSize="81216345" LastModifiedTime="1277458618536" Moniker="{C60DC234-65F9-4674-94AE-62158EFCA433}" Seq="100624037"/>
             <File Checksum="D7ED056BE84712D8E392C3112591A62B" DeltaFlag="1" FullSize="82842392" LastModifiedTime="1277458516849" Moniker="{1CD85198-26C6-4bac-8C72-5D34B025DE35}" Seq="100624037"/>
             <File Checksum="E91F083A81FECE77FEC0AA041C8EB176" DeltaFlag="1" FullSize="898531" LastModifiedTime="1277444031604" Moniker="{42B17E5E-4E9D-4157-88CB-966FB4985928}" Seq="100624001"/>
             <File Checksum="FFEAB6ACB8002BF9A209BBAE083A0D8A" DeltaFlag="1" FullSize="879905" LastModifiedTime="1277444022197" Moniker="{D3769926-05B7-4ad1-9DCF-23051EEE78E3}" Seq="100624001"/>
             <File Checksum="109B0761C4CD1ABFCCD4B3064C1FD392" DeltaFlag="1" FullSize="669829" LastModifiedTime="1275513181228" Moniker="{C25CEA47-63E5-447b-8D95-C79CAE13FF79}" Seq="80929016"/>
             <File Checksum="E874F68328D8768FDCC5D322C503C49A" DeltaFlag="1" FullSize="650307" LastModifiedTime="1275513191961" Moniker="{ECCC5006-EF61-4c99-829A-417B6C6AD963}" Seq="2008021700"/>
             <File Checksum="3939756FEDEF3B7854CD20A8A1BBCC58" DeltaFlag="1" FullSize="88188" LastModifiedTime="1275513267314" Moniker="{EA960B33-2196-4d53-8AC4-D5043A5B6F9B}" Seq="80820001"/>
             <File Checksum="4FB84F424A4F21B7D1E35567E42A26D4" DeltaFlag="1" FullSize="6487" LastModifiedTime="1275513274304" Moniker="{4F889C4A-784D-40de-8539-6A29BAA43139}" Seq="91111048"/>
             <File Checksum="24F8567D0A1F78BC5B361756236E1AF5" DeltaFlag="1" FullSize="1662247" LastModifiedTime="1275513276364" Moniker="{DB206823-FFD2-440a-9B89-CCFD45F3F1CD}" Seq="80820001"/>
             <File Checksum="306D9137EB0DFE28D7CA4EC89A23370E" DeltaFlag="1" FullSize="1419193" LastModifiedTime="1275513283744" Moniker="{C13726A9-8DF7-4583-9B39-105B7EBD55E2}" Seq="80820001"/>
             <File Checksum="E1DD7A24147B04D4B19B999A93783989" DeltaFlag="1" FullSize="76809" LastModifiedTime="1277400463693" Moniker="{CC40C428-1830-44ef-B8B2-920A0B761793}" Seq="100624009"/>
             <File Checksum="42DC35B37B0C5C25A4D6FB3C96869241" DeltaFlag="1" FullSize="1200191" LastModifiedTime="1277400464912" Moniker="{812CD25E-1049-4086-9DDD-A4FAE649FBDF}" Seq="100624009"/>
             <File Checksum="876500689D6E818538EDE897B905C9D0" DeltaFlag="1" FullSize="1200230" LastModifiedTime="1277400467037" Moniker="{E1A6B4FF-6873-4200-B6F6-04C13BF38CF3}" Seq="100624009"/>
             <File Checksum="94D7ACA153301060C0BB32A475109AE2" DeltaFlag="1" FullSize="76786" LastModifiedTime="1277400468224" Moniker="{E5A3EBEE-D580-421e-86DF-54C0B3739522}" Seq="100624009"/>
        </LiveUpdate>
    </GroupIndex>
    06/25 09:24:21 [216] <GetIndexFileRequest:>RECEIVE STAGE COMPLETED
    06/25 09:24:21 [216] <GetIndexFileRequest:>COMPLETED
    06/25 09:24:21 [216] <IndexHeartbeatProc>GetIndexFile handling status: 0
    06/25 09:24:21 [216] <IndexHeartbeatProc>Switch Server flag=0
    06/25 09:24:21 [216] HEARTBEAT: Check Point 5.1
    06/25 09:24:21 [216] <IsInClientIPorOnLink> NextHop is OnLink with x.x.x.16,return TRUE
    06/25 09:24:21 [216] <mfn_GetOutIP> Out IP is:x.x.x.16
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:21 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:21 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:24:21 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {1CD85198-26C6-4bac-8C72-5D34B025DE35} Seq:100624037
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:21 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:24:21 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {42B17E5E-4E9D-4157-88CB-966FB4985928} Seq:100624001
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:21 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:21 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:24:26 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {DB206823-FFD2-440a-9B89-CCFD45F3F1CD} Seq:80820001
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:24:26 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {CC40C428-1830-44ef-B8B2-920A0B761793} Seq:100624009
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:24:26 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {E1A6B4FF-6873-4200-B6F6-04C13BF38CF3} Seq:100624009
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_SERVER_ONLINE
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_SERVER_ONLINE, return=0
    06/25 09:24:26 [216] <ScheduleNextUpdate>Reset Heartbeat factor index, hearbeat=300 seconds
    06/25 09:24:26 [216] HEARTBEAT: Check Point 6
    06/25 09:24:26 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: AVMan
    06/25 09:24:26 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: GUP
    06/25 09:24:26 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: LUMan
    06/25 09:24:26 [216] <mfn_PostAgentInfo>===REQUESTING CMC OP-STATE ===
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_SERVER_REQUIRES_CLIENT_SESTATE
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_SERVER_REQUIRES_CLIENT_SESTATE, return=0
    06/25 09:24:26 [216] ReasonDescForFailure*** = Host Integrity check is disabled.
    06/25 09:24:26 [216] ReasonDescForFailure*** = Host Integrity check is disabled.
    06/25 09:24:26 [216] *** = <SSAInfo NameSpace="rpc" AgentID="060582BA806FD6110021B42F4A1DA1B8" ComputerID="E4B311CA806FD6110021B42FF7E857A0" HardwareKey="5723E45C87EA0A912B346D541A4C38F9" GroupID="648B0F5A806FD6110060A01F26A00514">
    <AgentHIInfo Status="3" ReasonCode="105" ReasonDescForFailure="Host Integrity check is disabled."/>
    <SSAHostInfo>
    <NetworkIdentity UserDomain="GDDOMAIN.GRADDIV" LogonUser="gdsa" HostDomain="gddomain.graddiv" HostName="RAS" HostDesc=""/>
    <SSAProduct Version="11.0.5002.333"/>
    <SSAOS Version="5.2.3790" Desc="Windows Server 2003 family Standard Edition" Type="50659842" ServicePack="Service Pack 2" Language="9"/>
    <Processor ProcessorType="x86 Family 15 Model 4 Stepping 1" ProcessorClock="2800" ProcessorNum="2"/>
    <Memory Size="1072975872"/>
    <Disk Letter="C:\" Size="147816506368"/>
    <BIOS Version="DELL   - 1"/>
    <TpmDevice Id="0"/>
    <SSAProfile Version="5.0.0" SerialNumber="648B-06/24/2010 09:52:06 562"/>
    <SSAIDS Version="" SerialNumber=""/>
    <Deuce Signature="100624001"/>
    <SSAUTC Bias="480"/>
    <DNSs><DNS Address="x.x.x.4"/><DNS Address="x.x.x.5"/></DNSs>
    <WINSs><WINS Address="x.x.x.4"/><WINS Address="x.x.x.5"/></WINSs>
    <SSANICs><SSANIC Ip="x.x.x.16" Mac="00-0e-0c-84-a5-c0" Gateway="x.x.x.254" SubnetMask="255.255.255.0"/></SSANICs><Firewall OnOff="1" Installed="1"/>
    </SSAHostInfo>
    <RebootRequired Status="0"></RebootRequired>
    <InstalledFeatures><Feature Id ="256"/></InstalledFeatures>
    </SSAInfo>

    06/25 09:24:26 [216] <mfn_PostAgentInfo>Volatile op-state damper: 0, Interval passed: 319
    06/25 09:24:26 [216] <mfn_PostAgentInfo>Free memory difference: 16130048, Threshold: 69905805
    06/25 09:24:26 [216] <mfn_PostAgentInfo>Free disk space difference: 12288, Threshold: 17258114445
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_SYLINK_QUERY_COMMANDSTATUS
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_SYLINK_QUERY_COMMANDSTATUS, return=0
    06/25 09:24:26 [216] <IndexHeartbeatProc>===UPLOAD STAGE===
    06/25 09:24:26 [216] <PostEvent>going to post event=EVENT_SERVER_READY_TO_UPLOAD_EVENT_LOG
    06/25 09:24:26 [216] <PostEvent>done post event=EVENT_SERVER_READY_TO_UPLOAD_EVENT_LOG, return=0
    06/25 09:24:26 [216] <IndexHeartbeatProc>===PREPARE EVENT LOG STAGE===
    06/25 09:24:26 [216] <PrepareEventLog>initialized technology extension processing ok
    06/25 09:24:26 [216] <PrepareEventLog>Allow total logs to send=0
    06/25 09:24:26 [216] <IndexHeartbeatProc>Communication Mode=0(Push Mode)
    06/25 09:24:26 [216] <IndexHeartbeatProc>Enter Push Session
    06/25 09:24:26 [216] <IndexHeartbeatProc>Setting the session timeout on Profile Session (for MaintainPushConnection) to 320000
    06/25 09:24:26 [216] <MaintainPushConnection:>Push Connecton!
    06/25 09:24:26 [216] ************CSN=11921
    06/25 09:24:26 [216] <mfn_MakeGetPushUrl:>Request is: action=128&hostid=060582BA806FD6110021B42F4A1DA1B8&chk=44EAE74490FC19CB726769B2CB43EFD3&ck=5B2377063C0C6F0B557D48AE26E6851E&uchk=F063BD9DC9BA63B48AFC1B96D1CEEA10&uck=20601E3AA1773DF01FC86D101233FF65&groupid=5488FBA7806FD61101304EF43821D675&mode=0&as=11921
    06/25 09:24:26 [216] <MaintainPushConnection:>http://x.x.x.17:80/secars/secars.dll?h=DC6DF1E03D6AF7571E253032AD762C79E1CB4A1F99BE37B8DDA63541E1F58D1E4ECF4C7E3D18FDD30B567977C6C8605B6FB5173B43B47A4AE4F41E66FBB136B7064810BC362E13F854FE0EA638E1FE007419A991EADAFD5445E1DCEDA3E35203A8C657E417123146B9085E2507B8DB093057E3475C04006E97FE4753C42AF98A7AE0938D3578052125C7C16C249E87AC9FCC0DC0352B874FC09B9E304E2FF398E274FCC663DC0AA30AC73932815C73B05C8FE23B389A57E43862165ABAAA0D9BDD3D94C93708CFBE84C8A54289649EF6C1A46337F59E778ECF314DDA57B9FC188A7E7226DECD781F3091AC17EAB22FC6A7124842C0D882E4F9AA2DECEC164644E05C98FFC3883850ACD9BE4E7B9A5F35
    06/25 09:24:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:24:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:25:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:25:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:26:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:26:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:27:55 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:27:55 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:28:56 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:28:56 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:29:44 [216] <MaintainPushConnection:>SMS return=200
    06/25 09:29:44 [216] <ParseHTTPStatusCode:>200=>200 OK
    06/25 09:29:44 [216] <MaintainPushConnection:>RECEIVE STAGE COMPLETED
    06/25 09:29:44 [216] <MaintainPushConnection:>COMPLETED
    06/25 09:29:44 [216] <ScheduleNextUpdate>Manually assigned heartbeat=5 seconds
    06/25 09:29:44 [216] HEARTBEAT: Check Point 8
    06/25 09:29:44 [216] <PostEvent>going to post event=EVENT_SERVER_DISCONNECTED
    06/25 09:29:44 [216] <PostEvent>done post event=EVENT_SERVER_DISCONNECTED, return=0
    06/25 09:29:44 [216] <IndexHeartbeatProc>====== IndexHeartbeat Procedure stops at 09:29:44 ======
    06/25 09:29:44 [216] <IndexHeartbeatProc>Set Heartbeat Result= 2
    06/25 09:29:44 [216] <IndexHeartbeatProc>Sylink Comm.Flags: 'Connection Failed' = 0, 'Using Backup Sylink' = 0, 'Using Location Config' = 0
    06/25 09:29:44 [216] Use new configuration
    06/25 09:29:44 [216] HEARTBEAT: Check Point Complete
    06/25 09:29:44 [216] <IndexHeartbeatProc>Done, Heartbeat=5seconds
    06/25 09:29:44 [216] </CSyLink::IndexHeartbeatProc()>
    06/25 09:29:44 [216] <CheckHeartbeatTimer>====== Heartbeat loop stops at 09:29:44 ======
    06/25 09:29:50 [216] <CheckHeartbeatTimer>====== Heartbeat loop starts at 09:29:50 ======
    06/25 09:29:50 [216] <GetOnlineNicInfo>:Netport Count=1
    06/25 09:29:50 [216] <GetOnlineNicInfo>:NicInfo<SSANICs><SSANIC Ip="x.x.x.16" Mac="00-0e-0c-84-a5-c0" Gateway="x.x.x.254" SubnetMask="255.255.255.0"/></SSANICs>
    06/25 09:29:50 [216] <CalcAgentHashKey>:CH=5488FBA7806FD61101304EF43821D6751RASgddomain.graddiv5723E45C87EA0A912B346D541A4C38F9
    06/25 09:29:50 [216] <CalcAgentHashKey>:CHKey=44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:29:50 [216] <CalcAgentHashKey>:C=5488FBA7806FD61101304EF43821D6751RASgddomain.graddiv
    06/25 09:29:50 [216] <CalcAgentHashKey>:CKey=5B2377063C0C6F0B557D48AE26E6851E
    06/25 09:29:50 [216] <CalcAgentHashKey>:UCH=5488FBA7806FD61101304EF43821D6750gdsaGDDOMAIN.GRADDIVRASgddomain.graddiv5723E45C87EA0A912B346D541A4C38F9
    06/25 09:29:50 [216] <CalcAgentHashKey>:UCHKey=F063BD9DC9BA63B48AFC1B96D1CEEA10
    06/25 09:29:50 [216] <CalcAgentHashKey>:UC=5488FBA7806FD61101304EF43821D6750gdsaGDDOMAIN.GRADDIVRASgddomain.graddiv
    06/25 09:29:50 [216] <CalcAgentHashKey>:UCKey=20601E3AA1773DF01FC86D101233FF65
    06/25 09:29:50 [216] <DoHeartbeat>HardwareID=5723E45C87EA0A912B346D541A4C38F9
    06/25 09:29:50 [216] <DoHeartbeat>CHKey=44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:29:50 [216] <DoHeartbeat>CKey=5B2377063C0C6F0B557D48AE26E6851E
    06/25 09:29:50 [216] <DoHeartbeat>UCHKey=F063BD9DC9BA63B48AFC1B96D1CEEA10
    06/25 09:29:50 [216] <DoHeartbeat>UCKey=20601E3AA1773DF01FC86D101233FF65
    06/25 09:29:50 [216] <DoHeartbeat> Set heartbeat event
    06/25 09:29:50 [216] Use new configuration
    06/25 09:29:50 [216] <CSyLink::IndexHeartbeatProc()>
    06/25 09:29:50 [216] <IndexHeartbeatProc> Got ConfigObject to proceed the operation.. pSylinkConfig: 01B7BAA8
    06/25 09:29:50 [216] <IndexHeartbeatProc>====== Reg Heartbeat loop starts at 09:29:50 ======
    06/25 09:29:51 [216] HEARTBEAT: Check Point 1
    06/25 09:29:51 [216] Get First Server!
    06/25 09:29:51 [216] HEARTBEAT: Check Point 2
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_SERVER_CONNECTING
    06/25 09:29:51 [216] <PostEvent>done post event=EVENT_SERVER_CONNECTING, return=0
    06/25 09:29:51 [216] HEARTBEAT: Check Point 3
    06/25 09:29:51 [216] <IndexHeartbeatProc>Setting the session timeout on Profile Session to 30000
    06/25 09:29:51 [216] HEARTBEAT: Check Point 4
    06/25 09:29:51 [216] <IndexHeartbeatProc>===Get Index STAGE===
    06/25 09:29:51 [216] ************CSN=11922
    06/25 09:29:51 [216] <mfn_MakeGetIndexUrl:>Request is: action=12&hostid=060582BA806FD6110021B42F4A1DA1B8&chk=44EAE74490FC19CB726769B2CB43EFD3&ck=5B2377063C0C6F0B557D48AE26E6851E&uchk=F063BD9DC9BA63B48AFC1B96D1CEEA10&uck=20601E3AA1773DF01FC86D101233FF65&hid=5723E45C87EA0A912B346D541A4C38F9&groupid=5488FBA7806FD61101304EF43821D675&mode=0&hbt=300&as=11922&cn=[hex]524153&lun=[hex]67647361&udn=[hex]4744444F4D41494E2E47524144444956
    06/25 09:29:51 [216] <GetIndexFileRequest:>http://x.x.x.17:80/secars/secars.dll?h=CF1411A06DE997CBFDF18A21DD59B1D59DAEB93B7704AF40928EB621ADC02CB9FD7B21625E43C261C3F926DD01F45928E68ACA761E975ECC0B8221FB49D92ED53749FBCA86A0988CF6AF00E0823A119928A385CC8D79CE457B9B7472AF580AF2C471189F4E1D7A799E67AA26F0E7BB4789BF81214B0DA8794CA9623A210911C081CC221135C49BE88B4A7EFB0CB2A0E097B6607BB61A345FB2A84C3B5BAE296431A4832A3444D4976CD8922ACB99AF57D23518011477E47391C9CE84182165529B7B47B55DDDAB55141480C82F021177B44E1167E262E9E0928740AFAC8676286653150761A4AF5FB7872687E2BE24833E81011FCA44512D87EB5CA96E34FA6E64CD4E0B081BA69D3A00D76CC3F7270D593E613EA1CB6AA17537BD1A22D477A16CB0B060DAF72D4E7A63E630623BBC18EE1AA51664846A75AAA57E2DC37C106B9CDFD232B252F5BE3068652A0422118FB8680959F3DBEE241B25FBEAB091C53EA7B609A3D01349DC274EF65C4B45C8574C7526726CCC0E92D4A48260F024A1AE
    06/25 09:29:51 [216] <GetIndexFileRequest:>SMS return=200
    06/25 09:29:51 [216] <ParseHTTPStatusCode:>200=>200 OK
    06/25 09:29:51 [216] <FindHeader>Sem-HashKey:=>44EAE74490FC19CB726769B2CB43EFD3
    06/25 09:29:51 [216] <FindHeader>Sem-LANSensor:=>0
    06/25 09:29:51 [216] <FindHeader>Sem-Signatue:=>9015791799731CBA4527691A867D85EB36BE71744BF4F41FCC8458C972579D85AFBD6FBD164F8A2DD5D24D571D22E8C839E3D7FFEC27B98F1643804A36CECE6E716483740330F267DCD2E8491ABE4C1CB5BFD53C2AE879424C06030911C95ED4F641683A29FA4B9413B9885895DF88D52C46B0D06B8AF76659C093D2D16EA3D6
    06/25 09:29:51 [216] <mfn_DoGetIndexFile200>Content Lenght => 1351
    06/25 09:29:51 [216] SignIf::VerifySignature(data, dataLen, sig, sigLen) => Verification Successful..
    06/25 09:29:51 [216] <mfn_DoGetIndexFile200>Index File: <?xml version="1.0" encoding="UTF-8" ?><GroupIndex SiteID="F2C2A82A806FD61100F02DB78B240A35" ServerID="CA790D49806FD6110012429CEBE9B581" GroupID="648B0F5A806FD6110060A01F26A00514" GroupCheckSum="842CEA790A323210858413531" LastModifiedTime = "25/06/2010 02:37:35">    <Profile Checksum="D1496E3F7B515D2E766C2078A880CEAA" SerialNumber="648B-06/24/2010 09:52:06 562" LastModifiedTime="24/06/2010  09:52:16"/>    <ConfigFile Checksum="09C8EF2100A4E88CF5779B0F186B1975" LastModifiedTime="08/06/2010  11:38:45"/>    <IDSFile Checksum="703A0AE1B8EC84B36CDBAECB7E800283" LastModifiedTime="24/06/2010  09:52:16"/>    <SylinkFile Checksum="6630BBF3A4CC470DD0564FB7EA0A31E3" LastModifiedTime="24/06/2010  09:52:16"/>    <LSProfile Checksum="67EAF9E3996257EDCAAF0B0EF81C88B3" SerialNumber ="648B-06/24/2010 09:52:06 562" LastModifiedTime ="24/06/2010  09:52:16"/>
        <LiveUpdate>
            <File Checksum="8E1FC07E11FAC34877F87EA4FA17F75B" DeltaFlag="1" FullSize="81216345" LastModifiedTime="1277458618536" Moniker="{C60DC234-65F9-4674-94AE-62158EFCA433}" Seq="100624037"/>
             <File Checksum="D7ED056BE84712D8E392C3112591A62B" DeltaFlag="1" FullSize="82842392" LastModifiedTime="1277458516849" Moniker="{1CD85198-26C6-4bac-8C72-5D34B025DE35}" Seq="100624037"/>
             <File Checksum="E91F083A81FECE77FEC0AA041C8EB176" DeltaFlag="1" FullSize="898531" LastModifiedTime="1277444031604" Moniker="{42B17E5E-4E9D-4157-88CB-966FB4985928}" Seq="100624001"/>
             <File Checksum="FFEAB6ACB8002BF9A209BBAE083A0D8A" DeltaFlag="1" FullSize="879905" LastModifiedTime="1277444022197" Moniker="{D3769926-05B7-4ad1-9DCF-23051EEE78E3}" Seq="100624001"/>
             <File Checksum="109B0761C4CD1ABFCCD4B3064C1FD392" DeltaFlag="1" FullSize="669829" LastModifiedTime="1275513181228" Moniker="{C25CEA47-63E5-447b-8D95-C79CAE13FF79}" Seq="80929016"/>
             <File Checksum="E874F68328D8768FDCC5D322C503C49A" DeltaFlag="1" FullSize="650307" LastModifiedTime="1275513191961" Moniker="{ECCC5006-EF61-4c99-829A-417B6C6AD963}" Seq="2008021700"/>
             <File Checksum="3939756FEDEF3B7854CD20A8A1BBCC58" DeltaFlag="1" FullSize="88188" LastModifiedTime="1275513267314" Moniker="{EA960B33-2196-4d53-8AC4-D5043A5B6F9B}" Seq="80820001"/>
             <File Checksum="4FB84F424A4F21B7D1E35567E42A26D4" DeltaFlag="1" FullSize="6487" LastModifiedTime="1275513274304" Moniker="{4F889C4A-784D-40de-8539-6A29BAA43139}" Seq="91111048"/>
             <File Checksum="24F8567D0A1F78BC5B361756236E1AF5" DeltaFlag="1" FullSize="1662247" LastModifiedTime="1275513276364" Moniker="{DB206823-FFD2-440a-9B89-CCFD45F3F1CD}" Seq="80820001"/>
             <File Checksum="306D9137EB0DFE28D7CA4EC89A23370E" DeltaFlag="1" FullSize="1419193" LastModifiedTime="1275513283744" Moniker="{C13726A9-8DF7-4583-9B39-105B7EBD55E2}" Seq="80820001"/>
             <File Checksum="E1DD7A24147B04D4B19B999A93783989" DeltaFlag="1" FullSize="76809" LastModifiedTime="1277400463693" Moniker="{CC40C428-1830-44ef-B8B2-920A0B761793}" Seq="100624009"/>
             <File Checksum="42DC35B37B0C5C25A4D6FB3C96869241" DeltaFlag="1" FullSize="1200191" LastModifiedTime="1277400464912" Moniker="{812CD25E-1049-4086-9DDD-A4FAE649FBDF}" Seq="100624009"/>
             <File Checksum="876500689D6E818538EDE897B905C9D0" DeltaFlag="1" FullSize="1200230" LastModifiedTime="1277400467037" Moniker="{E1A6B4FF-6873-4200-B6F6-04C13BF38CF3}" Seq="100624009"/>
             <File Checksum="94D7ACA153301060C0BB32A475109AE2" DeltaFlag="1" FullSize="76786" LastModifiedTime="1277400468224" Moniker="{E5A3EBEE-D580-421e-86DF-54C0B3739522}" Seq="100624009"/>
        </LiveUpdate>
    </GroupIndex>
    06/25 09:29:51 [216] <GetIndexFileRequest:>RECEIVE STAGE COMPLETED
    06/25 09:29:51 [216] <GetIndexFileRequest:>COMPLETED
    06/25 09:29:51 [216] <IndexHeartbeatProc>GetIndexFile handling status: 0
    06/25 09:29:51 [216] <IndexHeartbeatProc>Switch Server flag=0
    06/25 09:29:51 [216] HEARTBEAT: Check Point 5.1
    06/25 09:29:51 [216] <IsInClientIPorOnLink> NextHop is OnLink with x.x.x.16,return TRUE
    06/25 09:29:51 [216] <mfn_GetOutIP> Out IP is:x.x.x.16
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:51 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:51 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:29:51 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {1CD85198-26C6-4bac-8C72-5D34B025DE35} Seq:100624037
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:51 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:29:51 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {42B17E5E-4E9D-4157-88CB-966FB4985928} Seq:100624001
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:51 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:51 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:29:56 [2092] </CSyLink::mfn_DownloadNow()>
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:29:56 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {DB206823-FFD2-440a-9B89-CCFD45F3F1CD} Seq:80820001
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:29:56 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {CC40C428-1830-44ef-B8B2-920A0B761793} Seq:100624009
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=1
    06/25 09:29:56 [216] <mfn_LiveUpdate> EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content. Moniker: {E1A6B4FF-6873-4200-B6F6-04C13BF38CF3} Seq:100624009
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_LU_REQUIRE_STATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_LU_REQUIRE_STATUS, return=20
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_SERVER_ONLINE
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_SERVER_ONLINE, return=0
    06/25 09:29:56 [216] <ScheduleNextUpdate>Reset Heartbeat factor index, hearbeat=300 seconds
    06/25 09:29:56 [216] HEARTBEAT: Check Point 6
    06/25 09:29:56 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: AVMan
    06/25 09:29:56 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: GUP
    06/25 09:29:56 [216] <mfn_PostAgentInfo>===REQUESTING PLUG-IN OP-STATE: LUMan
    06/25 09:29:56 [216] <mfn_PostAgentInfo>===REQUESTING CMC OP-STATE ===
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_SERVER_REQUIRES_CLIENT_SESTATE
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_SERVER_REQUIRES_CLIENT_SESTATE, return=0
    06/25 09:29:56 [216] ReasonDescForFailure*** = Host Integrity check is disabled.
    06/25 09:29:56 [216] ReasonDescForFailure*** = Host Integrity check is disabled.
    06/25 09:29:56 [216] *** = <SSAInfo NameSpace="rpc" AgentID="060582BA806FD6110021B42F4A1DA1B8" ComputerID="E4B311CA806FD6110021B42FF7E857A0" HardwareKey="5723E45C87EA0A912B346D541A4C38F9" GroupID="648B0F5A806FD6110060A01F26A00514">
    <AgentHIInfo Status="3" ReasonCode="105" ReasonDescForFailure="Host Integrity check is disabled."/>
    <SSAHostInfo>
    <NetworkIdentity UserDomain="GDDOMAIN.GRADDIV" LogonUser="gdsa" HostDomain="gddomain.graddiv" HostName="RAS" HostDesc=""/>
    <SSAProduct Version="11.0.5002.333"/>
    <SSAOS Version="5.2.3790" Desc="Windows Server 2003 family Standard Edition" Type="50659842" ServicePack="Service Pack 2" Language="9"/>
    <Processor ProcessorType="x86 Family 15 Model 4 Stepping 1" ProcessorClock="2800" ProcessorNum="2"/>
    <Memory Size="1072975872"/>
    <Disk Letter="C:\" Size="147816506368"/>
    <BIOS Version="DELL   - 1"/>
    <TpmDevice Id="0"/>
    <SSAProfile Version="5.0.0" SerialNumber="648B-06/24/2010 09:52:06 562"/>
    <SSAIDS Version="" SerialNumber=""/>
    <Deuce Signature="100624001"/>
    <SSAUTC Bias="480"/>
    <DNSs><DNS Address="x.x.x.4"/><DNS Address="x.x.x.5"/></DNSs>
    <WINSs><WINS Address="x.x.x.4"/><WINS Address="x.x.x.5"/></WINSs>
    <SSANICs><SSANIC Ip="x.x.x.16" Mac="00-0e-0c-84-a5-c0" Gateway="x.x.x.254" SubnetMask="255.255.255.0"/></SSANICs><Firewall OnOff="1" Installed="1"/>
    </SSAHostInfo>
    <RebootRequired Status="0"></RebootRequired>
    <InstalledFeatures><Feature Id ="256"/></InstalledFeatures>
    </SSAInfo>

    06/25 09:29:56 [216] <mfn_PostAgentInfo>Volatile op-state damper: 0, Interval passed: 330
    06/25 09:29:56 [216] <mfn_PostAgentInfo>Free memory difference: 18542592, Threshold: 69905805
    06/25 09:29:56 [216] <mfn_PostAgentInfo>Free disk space difference: 94208, Threshold: 17258114445
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_SYLINK_QUERY_COMMANDSTATUS
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_SYLINK_QUERY_COMMANDSTATUS, return=0
    06/25 09:29:56 [216] <IndexHeartbeatProc>===UPLOAD STAGE===
    06/25 09:29:56 [216] <PostEvent>going to post event=EVENT_SERVER_READY_TO_UPLOAD_EVENT_LOG
    06/25 09:29:56 [216] <PostEvent>done post event=EVENT_SERVER_READY_TO_UPLOAD_EVENT_LOG, return=0
    06/25 09:29:56 [216] <IndexHeartbeatProc>===PREPARE EVENT LOG STAGE===
    06/25 09:29:56 [216] <PrepareEventLog>initialized technology extension processing ok
    06/25 09:29:56 [216] <PrepareEventLog>Allow total logs to send=0
    06/25 09:29:56 [216] <IndexHeartbeatProc>Communication Mode=0(Push Mode)
    06/25 09:29:56 [216] <IndexHeartbeatProc>Enter Push Session
    06/25 09:29:56 [216] <IndexHeartbeatProc>Setting the session timeout on Profile Session (for MaintainPushConnection) to 320000
    06/25 09:29:56 [216] <MaintainPushConnection:>Push Connecton!
    06/25 09:29:57 [216] ************CSN=11923
    06/25 09:29:57 [216] <mfn_MakeGetPushUrl:>Request is: action=128&hostid=060582BA806FD6110021B42F4A1DA1B8&chk=44EAE74490FC19CB726769B2CB43EFD3&ck=5B2377063C0C6F0B557D48AE26E6851E&uchk=F063BD9DC9BA63B48AFC1B96D1CEEA10&uck=20601E3AA1773DF01FC86D101233FF65&groupid=5488FBA7806FD61101304EF43821D675&mode=0&as=11923
    06/25 09:29:57 [216] <MaintainPushConnection:>http://x.x.x.17:80/secars/secars.dll?h=DC6DF1E03D6AF7571E253032AD762C79E1CB4A1F99BE37B8DDA63541E1F58D1E4ECF4C7E3D18FDD30B567977C6C8605B6FB5173B43B47A4AE4F41E66FBB136B7064810BC362E13F854FE0EA638E1FE007419A991EADAFD5445E1DCEDA3E35203A8C657E417123146B9085E2507B8DB093057E3475C04006E97FE4753C42AF98A7AE0938D3578052125C7C16C249E87AC9FCC0DC0352B874FC09B9E304E2FF398E274FCC663DC0AA30AC73932815C73B05C8FE23B389A57E43862165ABAAA0D9BDD3D94C93708CFBE84C8A54289649EF6C1A46337F59E778ECF314DDA57B9FC188A7E7226DECD781F3091AC17EAB22FC6A7124842C0D882E4F9AA2DECEC1646443D2A11EE24ADB28CA6FAD4C046BA01BE
    06/25 09:30:56 [2092] <CSyLink::mfn_DownloadNow()>
    06/25 09:30:56 [2092] </CSyLink::mfn_DownloadNow()>




  • 30.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 01:34 PM

    From what I can tell, it is communicating and requesting content, but the "return=20" indicates the client thinks already has that content.  I.e. the client thinks what the SEPM has is the latest version and doesn't need to download anything.

    As for the "return=1" / "EVENT_LU_REQUIRE_STATUS returned ERROR_SYSTEM_UNKNOWN - Ignore LU content.", don't let this throw you:   The monikers for which this message appears is for 64-content, and this is a 32-bit system.  These messages would be expected.

    I did notice this in the information coming on the index file request.  Note the bolded as being the one that's out of date (8 June):

    <GroupIndex SiteID="F2C2A82A806FD61100F02DB78B240A35" ServerID="CA790D49806FD6110012429CEBE9B581" GroupID="648B0F5A806FD6110060A01F26A00514" GroupCheckSum="842CEA790A323210858413531" LastModifiedTime = "25/06/2010 02:37:35">    
    <Profile Checksum="D1496E3F7B515D2E766C2078A880CEAA" SerialNumber="648B-06/24/2010 09:52:06 562" LastModifiedTime="24/06/2010  09:52:16"/>    
    <ConfigFile Checksum="09C8EF2100A4E88CF5779B0F186B1975" LastModifiedTime="08/06/2010  11:38:45"/>    
    <IDSFile Checksum="703A0AE1B8EC84B36CDBAECB7E800283" LastModifiedTime="24/06/2010  09:52:16"/>    
    <SylinkFile Checksum="6630BBF3A4CC470DD0564FB7EA0A31E3" LastModifiedTime="24/06/2010  09:52:16"/>    
    <LSProfile Checksum="67EAF9E3996257EDCAAF0B0EF81C88B3" SerialNumber ="648B-06/24/2010 09:52:06 562" LastModifiedTime ="24/06/2010  09:52:16"/>

    The other "LastModifiedTime"s seem correct, but I have seen it before where damage to the database prevented the correct updating to the sylink file, so that when the client compares what it has to what the SEPM has, it can't see there is an update.

    With a console connection to the server, try validating the database to see if it fails.

    Title: 'How to use the Validation Tool for the Symantec Endpoint Protection Manager Database.'
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008050810375848

    sandra


  • 31.  RE: Liveupdate runs every few seconds

    Posted Jun 25, 2010 01:37 PM

    I did the repair of the SEPM at the console level.  And I did the export of the client packages as well at the console level.  However, it does not explain how on other clients (As I have about 40 computers), only 4 of them are having the constant triggering of LiveUpdate.


  • 32.  RE: Liveupdate runs every few seconds

    Posted Jun 27, 2010 11:44 PM
    some definition is out of date. Can you have client run liveupdate from default server rather than get def from SEPM? 


  • 33.  RE: Liveupdate runs every few seconds

    Posted Jun 27, 2010 11:45 PM
    Just to get the up-to-date definition, then can make client point back to SEPM


  • 34.  RE: Liveupdate runs every few seconds

    Posted Jun 28, 2010 01:12 PM

    I'm not quite sure what you are trying to say here? Is this in regards to the Definitions not being up to date in general or the fact that the Proactive Threat Protection is not working.


  • 35.  RE: Liveupdate runs every few seconds

    Posted Jun 28, 2010 11:00 PM
    Definition is too old, just update them to the newest then let's see if the issue still occurs.


  • 36.  RE: Liveupdate runs every few seconds

    Posted Jun 29, 2010 12:30 AM
    Sorry was out of the loop for a few days.  So after re-exporting the install package, did you remove and reinstall SEP?

    Just so I'm clear, here, are the affected clients in fact up to date with current content?  The most current revisions (for AV/AS, PTP and NTP) can all be found on this page.  The latter two are included under "Symantec Endpoint Protection Security Updates."  As I said, what the sylink log is telling me is that regardless of whatever the client interface says, the client believes it is in fact up to date with what the SEPM is serving.  (Here's a thought, too.  Is the SEPM itself up to date?)  That doesn't explain why it's happening every 5-7 minutes... baby steps. :)

    What do you mean when you say PTP is not working?  If you mean on the servers, it is by design that they will say "Off".  Commercial Application List (CAL) Scanning is the only supported scanning for PTP on server and 64 bit OSes.

    If it turns out to be an install package issue due to an RDP session at the time of creation, why some were affected and some not... I wish I had an answer.  The apparent correlation I have seen between non-console sessions of RDP and bizarre, unreproducible issues is just too high to ignore as a possibility.

    Also: did the database pass validation?

    Thanks,
    sandra


  • 37.  RE: Liveupdate runs every few seconds

    Posted Jun 30, 2010 12:16 PM

    Did not get a chance to reinstall the package yet, will do that next (Caught in the middle of a department transition, so I had to put this a little on hold.)

    On the three servers I was doing the 'purge the corrupted cache' bit, as indicated by the documents you linked, those three had the 'On' status for PTP until after went through those steps, then they flipped to 'Off' status.

    As for the answer to your earlier question with the Database Validation, it came up that the database is valid.  Only other thing would be where to look to see that SEPM is at where it should be as far as defs are concerned.


  • 38.  RE: Liveupdate runs every few seconds

    Posted Jun 30, 2010 12:56 PM

    Under Admin > Servers > Local site > Tasks > Show LiveUpdate Content, look at the revision date for PTP for 4 items:
    - whitelist Win32 and Win 64 11.0
    - commercial application list Win32 and Win 64 11.0

    Make sure it matches what the Security Response definitions page shows.  My SEPM shows yesterday, 29 June 2010 rev 50.  (Scan engine (32- and 64-bit), scan data, and commercial application engine have dates from 2008.)  ETA: the Security response Page says Proactive Threat Protection: 6/30/2010 rev. 16, which I clearly haven't downloaded yet. :)

    'Clearing corrupted cache' was in... which document?  Server OSes should never say 'On', even if it's green.

    sandra


  • 39.  RE: Liveupdate runs every few seconds

    Posted Jun 30, 2010 01:29 PM

    Perhaps I miss remembered that then.  As for what I see at the moment...

    Whitelists for 32 and 64 points to 2010-06-30 rev 016 at the moment
    Commercial Apps 32 and 64 also same.

    The  server which is literally DLing every 5 minutes is showing this as well.  As for the clearing the corrupted cache, I think, now, that is from the SEP tool for what it reccommended on doing, which was stopping the Symantec Management Client, then SEP, then deleting the files and modifying the registry before restarting Management client and sep to re-get those settings.