Jump to content

Recommended Posts

  • Most Valued Members
Posted

Hi,

I'm trying to deploy the Eset Endpoint AV to a Windows 7 32bit system(I had to remove the agent and the current EEA due to the agent not contacting the Protect server).  I know for a fact v11 no longer work for Win7, and the last version I see from [1] is v9.  So I create a task that installs v9.1.2071.0 (from a local repo) and run it. 

However it fails. (Unfortunately, there's little to no info in PROTECT's Task Execution Fail reason).  So I went into the client and took a look at the task.log. 

I see the following:

2024-03-28 05:31:36 Error: CSystemConnectorModule [Thread 1150]: SoftwareInstallation: MsiInstallProduct: Received error with text: The app that you are trying to run is not supported on this version of Windows. See https://go.eset.com/acs23
2024-03-28 05:31:37 Error: CSystemConnectorModule [Thread 1150]: SoftwareInstallation: Installation failed with: Fatal error during installation. Error code: 0x643 (0x643), The app that you are trying to run is not supported on this version of Windows. See https://go.eset.com/acs23, see software-install.log for more information located at: C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs\

Then in the software-install.log:

=== Verbose logging started: 3/28/2024  14:19:46  Build type: SHIP UNICODE 5.00.7601.00  Calling process: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe ===
MSI (c) (38:CC) [14:19:46:868]: Resetting cached policy values
MSI (c) (38:CC) [14:19:46:884]: Machine policy value 'Debug' is 0
MSI (c) (38:CC) [14:19:46:900]: ******* RunEngine:
           ******* Product: C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi
           ******* Action: 
           ******* CommandLine: **********
MSI (c) (38:CC) [14:19:46:931]: Client-side and UI is none or basic: Running entire install on the server.
MSI (c) (38:CC) [14:19:46:946]: Grabbed execution mutex.
MSI (c) (38:CC) [14:19:47:492]: Cloaking enabled.
MSI (c) (38:CC) [14:19:47:508]: Attempting to enable all disabled privileges before calling Install on Server
MSI (c) (38:CC) [14:19:47:524]: Incrementing counter to disable shutdown. Counter after increment: 0
MSI (s) (7C:F4) [14:19:47:555]: Running installation inside multi-package transaction C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi
MSI (s) (7C:F4) [14:19:47:617]: Grabbed execution mutex.
MSI (s) (7C:04) [14:19:47:695]: Resetting cached policy values
MSI (s) (7C:04) [14:19:47:726]: Machine policy value 'Debug' is 0
MSI (s) (7C:04) [14:19:47:726]: ******* RunEngine:
           ******* Product: C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi
           ******* Action: 
           ******* CommandLine: **********
MSI (s) (7C:04) [14:19:47:758]: Machine policy value 'DisableUserInstalls' is 0
MSI (s) (7C:04) [14:19:47:789]: SRSetRestorePoint skipped for this transaction.
MSI (s) (7C:04) [14:19:47:805]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 3: 2 
MSI (s) (7C:04) [14:19:47:820]: File will have security applied from OpCode.
MSI (s) (7C:04) [14:19:47:898]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi' against software restriction policy
MSI (s) (7C:04) [14:19:47:945]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi has a digital signature
MSI (s) (7C:04) [14:19:47:961]: SOFTWARE RESTRICTION POLICY: C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi is permitted to run because the user token authorizes execution (system or service token).
MSI (s) (7C:04) [14:19:47:976]: End dialog not enabled
MSI (s) (7C:04) [14:19:47:992]: Original package ==> C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi
MSI (s) (7C:04) [14:19:48:007]: Package we're running from ==> C:\Windows\Installer\a2b0da.msi
MSI (s) (7C:04) [14:19:48:023]: APPCOMPAT: Compatibility mode property overrides found.
MSI (s) (7C:04) [14:19:48:039]: APPCOMPAT: looking for appcompat database entry with ProductCode '{6D643A4F-0D98-4DB9-B19D-9AF972E90458}'.
MSI (s) (7C:04) [14:19:48:039]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (7C:04) [14:19:48:070]: MSCOREE not loaded loading copy from system32
MSI (s) (7C:04) [14:19:48:085]: Machine policy value 'TransformsSecure' is 0
MSI (s) (7C:04) [14:19:48:085]: User policy value 'TransformsAtSource' is 0
MSI (s) (7C:04) [14:19:48:101]: Machine policy value 'DisablePatch' is 0
MSI (s) (7C:04) [14:19:48:117]: Machine policy value 'AllowLockdownPatch' is 0
MSI (s) (7C:04) [14:19:48:132]: Machine policy value 'DisableLUAPatching' is 0
MSI (s) (7C:04) [14:19:48:148]: Machine policy value 'DisableFlyWeightPatching' is 0
MSI (s) (7C:04) [14:19:48:148]: APPCOMPAT: looking for appcompat database entry with ProductCode '{6D643A4F-0D98-4DB9-B19D-9AF972E90458}'.
MSI (s) (7C:04) [14:19:48:163]: APPCOMPAT: no matching ProductCode found in database.
MSI (s) (7C:04) [14:19:48:195]: Transforms are not secure.
MSI (s) (7C:04) [14:19:48:210]: PROPERTY CHANGE: Adding MsiLogFileLocation property. Its value is 'C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs\software-install.log'.
MSI (s) (7C:04) [14:19:48:210]: Command Line: ALLUSERS=1 REBOOT=ReallySuppress CFG_POTENTIALLYUNWANTED_ENABLED=1 INSTALLED_BY_ERA=1 REBOOT_POSTPONE=30 PRODUCT_LANG_CODE=en-us CURRENTDIRECTORY=C:\Windows\system32 CLIENTUILEVEL=3 MSICLIENTUSESEXTERNALUI=1 CLIENTPROCESSID=1592 
MSI (s) (7C:04) [14:19:48:226]: PROPERTY CHANGE: Adding PackageCode property. Its value is '{2571B191-D282-48A4-9290-E57663186DDD}'.
MSI (s) (7C:04) [14:19:48:241]: Product Code passed to Engine.Initialize:           ''
MSI (s) (7C:04) [14:19:48:257]: Product Code from property table before transforms: '{6D643A4F-0D98-4DB9-B19D-9AF972E90458}'
MSI (s) (7C:04) [14:19:48:257]: Product Code from property table after transforms:  '{6D643A4F-0D98-4DB9-B19D-9AF972E90458}'
MSI (s) (7C:04) [14:19:48:273]: Product not registered: beginning first-time install
MSI (s) (7C:04) [14:19:48:288]: Product {6D643A4F-0D98-4DB9-B19D-9AF972E90458} is not managed.
MSI (s) (7C:04) [14:19:48:304]: MSI_LUA: Credential prompt not required, user is an admin
MSI (s) (7C:04) [14:19:48:319]: PROPERTY CHANGE: Adding ProductState property. Its value is '-1'.
MSI (s) (7C:04) [14:19:48:319]: Entering CMsiConfigurationManager::SetLastUsedSource.
MSI (s) (7C:04) [14:19:48:335]: User policy value 'SearchOrder' is 'nmu'
MSI (s) (7C:04) [14:19:48:351]: Adding new sources is allowed.
MSI (s) (7C:04) [14:19:48:366]: PROPERTY CHANGE: Adding PackagecodeChanging property. Its value is '1'.
MSI (s) (7C:04) [14:19:48:366]: Package name extracted from package path: 'eea_nt32.msi'
MSI (s) (7C:04) [14:19:48:382]: Package to be registered: 'eea_nt32.msi'
MSI (s) (7C:04) [14:19:48:397]: Note: 1: 2262 2: AdminProperties 3: -2147287038 
MSI (s) (7C:04) [14:19:48:413]: Machine policy value 'DisableMsi' is 0
MSI (s) (7C:04) [14:19:48:413]: Machine policy value 'AlwaysInstallElevated' is 0
MSI (s) (7C:04) [14:19:48:429]: User policy value 'AlwaysInstallElevated' is 0
MSI (s) (7C:04) [14:19:48:444]: Product installation will be elevated because user is admin and product is being installed per-machine.
MSI (s) (7C:04) [14:19:48:460]: Running product '{6D643A4F-0D98-4DB9-B19D-9AF972E90458}' with elevated privileges: Product is assigned.
MSI (s) (7C:04) [14:19:48:475]: PROPERTY CHANGE: Adding REBOOT property. Its value is 'ReallySuppress'.
MSI (s) (7C:04) [14:19:48:475]: PROPERTY CHANGE: Adding CFG_POTENTIALLYUNWANTED_ENABLED property. Its value is '1'.
MSI (s) (7C:04) [14:19:48:491]: PROPERTY CHANGE: Modifying INSTALLED_BY_ERA property. Its current value is '0'. Its new value: '1'.
MSI (s) (7C:04) [14:19:48:507]: PROPERTY CHANGE: Modifying REBOOT_POSTPONE property. Its current value is '0'. Its new value: '30'.
MSI (s) (7C:04) [14:19:48:522]: PROPERTY CHANGE: Adding PRODUCT_LANG_CODE property. Its value is 'en-us'.
MSI (s) (7C:04) [14:19:48:522]: PROPERTY CHANGE: Adding CURRENTDIRECTORY property. Its value is 'C:\Windows\system32'.
MSI (s) (7C:04) [14:19:48:538]: PROPERTY CHANGE: Adding CLIENTUILEVEL property. Its value is '3'.
MSI (s) (7C:04) [14:19:48:553]: PROPERTY CHANGE: Adding MSICLIENTUSESEXTERNALUI property. Its value is '1'.
MSI (s) (7C:04) [14:19:48:569]: PROPERTY CHANGE: Adding CLIENTPROCESSID property. Its value is '1592'.
MSI (s) (7C:04) [14:19:48:569]: Machine policy value 'DisableAutomaticApplicationShutdown' is 0
MSI (s) (7C:04) [14:19:48:585]: RESTART MANAGER: Disabled by MSIRESTARTMANAGERCONTROL property; Windows Installer will use the built-in FilesInUse functionality.
MSI (s) (7C:04) [14:19:48:600]: PROPERTY CHANGE: Adding MsiSystemRebootPending property. Its value is '1'.
MSI (s) (7C:04) [14:19:48:616]: TRANSFORMS property is now: 
MSI (s) (7C:04) [14:19:48:631]: PROPERTY CHANGE: Adding VersionDatabase property. Its value is '500'.
MSI (s) (7C:04) [14:19:48:631]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming
MSI (s) (7C:04) [14:19:48:663]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Favorites
MSI (s) (7C:04) [14:19:48:678]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts
MSI (s) (7C:04) [14:19:48:709]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Documents
MSI (s) (7C:04) [14:19:48:787]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
MSI (s) (7C:04) [14:19:48:897]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent
MSI (s) (7C:04) [14:19:48:975]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo
MSI (s) (7C:04) [14:19:49:021]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates
MSI (s) (7C:04) [14:19:49:037]: SHELL32::SHGetFolderPath returned: C:\ProgramData
MSI (s) (7C:04) [14:19:49:053]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Local
MSI (s) (7C:04) [14:19:49:068]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Pictures
MSI (s) (7C:04) [14:19:49:131]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (7C:04) [14:19:49:146]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (7C:04) [14:19:49:209]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs
MSI (s) (7C:04) [14:19:49:349]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Start Menu
MSI (s) (7C:04) [14:19:49:458]: SHELL32::SHGetFolderPath returned: C:\Users\Public\Desktop
MSI (s) (7C:04) [14:19:49:489]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
MSI (s) (7C:04) [14:19:49:505]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSI (s) (7C:04) [14:19:49:536]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
MSI (s) (7C:04) [14:19:49:552]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu
MSI (s) (7C:04) [14:19:49:567]: SHELL32::SHGetFolderPath returned: C:\Windows\system32\config\systemprofile\Desktop
MSI (s) (7C:04) [14:19:49:599]: SHELL32::SHGetFolderPath returned: C:\ProgramData\Microsoft\Windows\Templates
MSI (s) (7C:04) [14:19:49:614]: SHELL32::SHGetFolderPath returned: C:\Windows\Fonts
MSI (s) (7C:04) [14:19:49:645]: Note: 1: 2898 2: MS Sans Serif 3: MS Sans Serif 4: 0 5: 16 
MSI (s) (7C:04) [14:19:49:661]: MSI_LUA: Setting MsiRunningElevated property to 1 because the install is already running elevated.
MSI (s) (7C:04) [14:19:49:692]: PROPERTY CHANGE: Adding MsiRunningElevated property. Its value is '1'.
MSI (s) (7C:04) [14:19:49:708]: PROPERTY CHANGE: Adding Privileged property. Its value is '1'.
MSI (s) (7C:04) [14:19:49:739]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 
MSI (s) (7C:04) [14:19:49:755]: PROPERTY CHANGE: Adding USERNAME property. Its value is 'cc'.
MSI (s) (7C:04) [14:19:49:770]: Note: 1: 1402 2: HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info 3: 2 
MSI (s) (7C:04) [14:19:49:801]: PROPERTY CHANGE: Adding DATABASE property. Its value is 'C:\Windows\Installer\a2b0da.msi'.
MSI (s) (7C:04) [14:19:49:833]: PROPERTY CHANGE: Adding OriginalDatabase property. Its value is 'C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Data\install.cache\eea_nt32.msi'.
MSI (s) (7C:04) [14:19:49:879]: Machine policy value 'MsiDisableEmbeddedUI' is 0
MSI (s) (7C:04) [14:19:49:911]: EEUI - Disabling MsiEmbeddedUI due to existing external or embedded UI
MSI (s) (7C:04) [14:19:49:926]: EEUI - Disabling MsiEmbeddedUI for service because it's not a quiet/basic install
=== Logging started: 3/28/2024 14:19:49 ===
MSI (s) (7C:04) [14:19:49:973]: Note: 1: 2205 2:  3: PatchPackage 
MSI (s) (7C:04) [14:19:49:989]: Machine policy value 'DisableRollback' is 0
MSI (s) (7C:04) [14:19:50:004]: User policy value 'DisableRollback' is 0
MSI (s) (7C:04) [14:19:50:035]: PROPERTY CHANGE: Adding UILevel property. Its value is '2'.
MSI (s) (7C:04) [14:19:50:051]: PROPERTY CHANGE: Adding ACTION property. Its value is 'INSTALL'.
MSI (s) (7C:04) [14:19:50:067]: Doing action: INSTALL
Action start 14:19:50: INSTALL.
MSI (s) (7C:04) [14:19:50:113]: Running ExecuteSequence
MSI (s) (7C:04) [14:19:50:129]: Skipping action: SetEmptyREINSTALLMODE (condition is false)
MSI (s) (7C:04) [14:19:50:160]: Skipping action: Win64ErrorMessage (condition is false)
MSI (s) (7C:04) [14:19:50:176]: Doing action: InstSuppCheckSha2CodeSigningSupport
Action start 14:19:50: InstSuppCheckSha2CodeSigningSupport.
MSI (s) (7C:F8) [14:19:50:223]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIBA3D.tmp, Entrypoint: caCheckSha2CodeSigningSupport
MSI (s) (7C:88) [14:19:50:238]: Generating random cookie.
MSI (s) (7C:88) [14:19:50:269]: Created Custom Action Server with PID 6068 (0x17B4).
MSI (s) (7C:C0) [14:19:50:301]: Running as a service.
MSI (s) (7C:C0) [14:19:50:332]: Hello, I'm your 32bit Elevated Non-remapped custom action server.
Action ended 14:19:50: InstSuppCheckSha2CodeSigningSupport. Return value 1.
MSI (s) (7C:04) [14:19:50:410]: Doing action: InstSuppCheckAzureCodeSigningSupport
Action start 14:19:50: InstSuppCheckAzureCodeSigningSupport.
MSI (s) (7C:B0) [14:19:50:457]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIBB28.tmp, Entrypoint: caCheckAzureCodeSigningSupport
MSI (s) (7C!48) [14:19:50:503]: PROPERTY CHANGE: Adding AzureCodeSigningNotSupported property. Its value is '1'.
Action ended 14:19:50: InstSuppCheckAzureCodeSigningSupport. Return value 1.
MSI (s) (7C:04) [14:19:50:613]: Doing action: SetCLEANINSTALL
Action start 14:19:50: SetCLEANINSTALL.
MSI (s) (7C:04) [14:19:50:659]: PROPERTY CHANGE: Adding CLEANINSTALL property. Its value is '1'.
Action ended 14:19:50: SetCLEANINSTALL. Return value 1.
MSI (s) (7C:04) [14:19:50:706]: Doing action: LaunchConditions
Action start 14:19:50: LaunchConditions.
MSI (s) (7C:04) [14:19:50:909]: Product: ESET Endpoint Antivirus -- The app that you are trying to run is not supported on this version of Windows. See https://go.eset.com/acs23

Action ended 14:19:50: LaunchConditions. Return value 3.
MSI (s) (7C:04) [14:19:50:940]: Doing action: InstSuppFailed
Action start 14:19:50: InstSuppFailed.
MSI (s) (7C:E4) [14:19:50:987]: Invoking remote custom action. DLL: C:\Windows\Installer\MSIBD3B.tmp, Entrypoint: caOnFailed
ESET: Entering CA InstSupp!caOnFailed (limited: no)
MSI (s) (7C!00) [14:19:51:081]: PROPERTY CHANGE: Adding INSTDATAFILE property. Its value is 'C:\Windows\TEMP\eset.temp\{02D83BBE-F1B6-F07A-C57A-B0CDF137A2EE}\_InstData.xml'.
ESET: Analytics Report - Disabled by conditions.
ESET: Failed to start InstHelper
ESET: output file : C:\Windows\Temp\eset\bts.stats\msi-20240328-061951.json
ESET: Failed to start InstHelper (-1).
ESET: Failed to start InstHelper (-1).
ESET: Returing from CA InstSupp!caOnFailed with status 0 (duration: 0.187)
Action ended 14:19:51: InstSuppFailed. Return value 1.
Action ended 14:19:51: INSTALL. Return value 3.
=== Logging stopped: 3/28/2024 14:19:51 ===
MSI (s) (7C:04) [14:19:51:346]: Note: 1: 1708 
MSI (s) (7C:04) [14:19:51:361]: Product: ESET Endpoint Antivirus -- Installation failed.

MSI (s) (7C:04) [14:19:51:393]: Windows Installer installed the product. Product Name: ESET Endpoint Antivirus. Product Version: 9.1.2071.0. Product Language: 1033. Manufacturer: ESET, spol. s r.o.. Installation success or error status: 1603.

Just in case it was getting the 64bit version, I took a look at the log for the local repository and it showed the following:

 

192.168.99.10 - - [28/Mar/2024:13:44:47 +0800] "GET /com/eset/apps/business/eea/windows/v9/9.1.2071.0/eea_nt32.msi HTTP/1.1" 200 45789184
^C

I noticed that 9.1.2071.1 is in the same directory as 9.1.2071.0, but that version isn't available in the list of versions when I created the Deploy task.

Before I do this manually, I'd like to point out what I might be doing wrong. 

 

Thanks

 

Ed

 

[1] -https://support-eol.eset.com/en/policy_business/os_support_charts.html#ms_overview

  • 3 weeks later...
Posted

Hi, same problem here with Win Server 2008 R2 x64

Both task and manual attempt fails

Posted

@ewong look at this line:
 

MSI (s) (7C:04) [14:19:50:909]: Product: ESET Endpoint Antivirus -- The app that you are trying to run is not supported on this version of Windows. See https://go.eset.com/acs23

Windows 7 doesn't support the new Code Signing platform (a.k.a. ACS / Trusted Signing) unless you have a ESU license and install KB5006743 or later as per here:

https://support.microsoft.com/en-au/topic/kb5022661-windows-support-for-the-trusted-signing-formerly-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4

Basically you're stuck to latest version that was released before 9.1.2066.0.

See also https://forum.eset.com/topic/38212-install-failing-on-2008r2-servers-with-acs-support/

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...