cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 11 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

This would be my analysis (in order of what I looked at, which may help you in the future)

McAfee_Common_Bootstrapper_23012020102022294.log:

23/01/2020 10:20:29.279 [6312] [BootstrapperMain] RunCommandLine: "C:\NEC\Mc_Upgd_All\b\\mfehidin.exe" -installcab:"vscore_all.cab" -guid:{EA334ECD-7513-486B-A265-0C698FACBB06} -log:"c:\temp\McAfee_Common_VSCore_Install_All_23012020102029263.log" -etl:"c:\temp\McAfee_Common_VSCore_Install_All_23012020102029263.etl"
23/01/2020 10:20:30.638 [6312] [BootstrapperMain] RunCommandLine: Process return code : 0
23/01/2020 10:20:30.638 [6312] [BootstrapperMain] VSCore Installation Return value : 0
23/01/2020 10:20:30.638 [6312] [BootstrapperMain] VSCore install successful

> so where it was failing before, is now successful 🙂 (at least something!)

But...

23/01/2020 10:20:32.951 [6312] [BootstrapperMain] msiexec.exe /i"C:\NEC\Mc_Upgd_All\b\McAfee_Common_x64.msi" TRANSFORMS="C:\WINDOWS\Temp\McAfeeTmpMSTPath\1033.mst" CUSTOMLOGDIR_INSTALLER="c:\temp" /qn /norestart BOOTSTRAPPERCALL=1 QUARANTINEFOLDER=NOTPROVIDED /l* "c:\temp\McAfee_Common_Install_23012020102022294.log" INSTALLDIR="C:\Program Files\McAfee\Endpoint Security" PACKAGEDVSCORE=19.7.0.182.4
23/01/2020 10:20:32.951 [6312] [BootstrapperMain] Installing module
23/01/2020 10:20:49.93 [6312] [BootstrapperMain] installation failed!! return code : 1603


-----------------------------
McAfee_Common_Install_23012020102022294.log

10:20:42:45 - Service could not be open. Service does not exist and will be created newly
10:20:42:45 - Error : Could not create the service. Last error : 5
CustomAction CreateAndStartService_x64 returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
Action ended 10:20:42: InstallFinalize. Return value 3.


I've only seen this occur twice - once it was due to a corrupt Windows Installer, can you try repairing this on your machine? Even maybe running a sfc /scannow to check all is fine?

And the other time there was something called "Baidu" running on the machine. Are you running this software?

Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Highlighted
Level 8
Report Inappropriate Content
Message 12 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

I'll admit that I don't know how to repair windows installer, but I did run a sfc /scannow. It found some corrupt files, but was unable to fix.them. 

There is nothing called "Baidu" running on the machine.

I can install this module successfully from an elevated command prompt directly on the machine. Would the logs from a "good" install help for comparison?

I'm about at the point of re-imaging the machine, but this would not be a practical solution for the ~1,000 other machines having this issue.

Thanks.

P

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 13 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

Interesting find but that's actually helpful! For the installation to be successful it needs to have sufficient permissions > admin permissions. In the previous logs you shared you can see in the extract I shared the following entry "Last error : 5", this means access denied and can happy for many reasons.

Can you elevate the permissions that the installer is running with via Powershell? (I will admit to not being very good with Powershell :-))

Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Highlighted
Level 8
Report Inappropriate Content
Message 14 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

Yeah. PowerShell is definitely running with elevated privileges on the machine...

PS C:\> invoke-command -ComputerName PICANB20152063 -ScriptBlock { whoami /priv }

PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
========================================= 
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Enabled
SeSecurityPrivilege Manage auditing and security log Enabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Enabled
SeLoadDriverPrivilege Load and unload device drivers Enabled
SeSystemProfilePrivilege Profile system performance Enabled
SeSystemtimePrivilege Change the system time Enabled
SeProfileSingleProcessPrivilege Profile single process Enabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Enabled
SeCreatePagefilePrivilege Create a pagefile Enabled
SeBackupPrivilege Back up files and directories Enabled
SeRestorePrivilege Restore files and directories Enabled
SeShutdownPrivilege Shut down the system Enabled
SeDebugPrivilege Debug programs Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Enabled
SeUndockPrivilege Remove computer from docking station Enabled
SeManageVolumePrivilege Perform volume maintenance tasks Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
SeTimeZonePrivilege Change the time zone Enabled
SeCreateSymbolicLinkPrivilege Create symbolic links Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled

I also tried something like this.

Invoke-Command -cn PICANB20152063 -ScriptBlock {start-process C:\NEC\Mc_Upgd_All\b\SetupCC.exe -verb runAs -workingdirectory C:\NEC\Mc_Upgd_All\b -wait}

The -verb runAS should force it to be elevated.

I also tried psexec with the -s switch to run as SYSTEM.  No luck.

I checked for errors in the windows event log, but nothing there was helpful.

I found this in the log...

12:26:48:409 - McAfee CustomAction : Begin Start_All_ENS_Services
12:26:48:409 - Starting service mfeesp
12:26:48:425 - Service not found on target system. Continue with install
12:26:48:425 - Starting service mfefw
12:26:48:425 - Service not found on target system. Continue with install
12:26:48:425 - Starting service mfetp
12:26:48:440 - Service not found on target system. Continue with install
12:26:48:440 - Starting service mfetie
12:26:48:440 - Service not found on target system. Continue with install
12:26:48:440 - Starting service mfeatp
12:26:48:456 - Service not found on target system. Continue with install
12:26:48:471 - OpenService failed : 1060

Do you know what service this is?

P

 

Highlighted
Level 8
Report Inappropriate Content
Message 15 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

I just tried a completely clean install. I removed all modules with the removal tool, rebooted, then tried just installing the Platform module.

It still did not install, but the logs show a different error. 

Could you take a look at the attached?

Thanks again.

P

Highlighted
Level 8
Report Inappropriate Content
Message 16 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

OK, so what I thought was a clean install wasn't really. Even after the Removal program said it finished successfully, the McAfee services are still there.  I tried stopping one, but I got the same error code as listed above (1060). So how can I get rid of these services?

ScreenShot.jpg

Level 8
Report Inappropriate Content
Message 17 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

Never mind that last post. I was looking on the wrong system.

So it looks like we are back to the original issue with running the mfehidin.exe file to install vscore_all.cab.

I think the issue is that when you run that program, it temporarily knocks off remote sessions and the process is killed. Could this possibly be that mfehindin.exe temporarily disrupts network connectivity? I don't know, but almost as soon as you run it, the process disappears.

If I run it as a background job, it just might complete. I will try that next.

 

Highlighted
Level 8
Report Inappropriate Content
Message 18 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

There is definitely a problem with mfehidin.exe knocking off all remote connections to system on which it is run. I remote-controlled a laptop using DameWare and ran mfehidin.exe and it knocked me right out. Is it possible you could ask a developer why this happens and if there is a way around it?

 

 

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 19 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution
During the installation of ENS we install a network driver. We shouldn't see a network interruption that impacts the system however it even though MS advertises NDIS 6+ can insert a filter driver without rebuilding the network stack if it's marked as "optional", it doesn't seem to be the case. This is a topic that MS would need to address I'm afraid, we have no control over it.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Highlighted
Level 8
Report Inappropriate Content
Message 20 of 20

Re: Error When Installing Endpoint Security Platform Remotely

Jump to solution

Any idea why, then, that it happens on some systems and not others? I'm really not familiar with the NDIS 6.0 specification.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community