Finally found the log.

It is in programdata, sorry aligkhan I get paranoid this time of year.

I found this info in the autosandbox log. this is not telling me the HTTP information though. I’m still searching for that in the logs.

12/21/2013 2:28:58 PM Autosandbox candidate: C:\Windows\SoftwareDistribution\Download\Install\AM_Delta_Patch_1.165.346.0.exe
[Source: local://*C:\Windows\System32\svchost.exe ]
[Opened by: C:\Windows\System32\wuauclt.exe]
[Reason: 0x00020000]
→ Result: Not sandboxing (because the file is trusted).

When we get new laptop i will be going for full subscription.

EDIT: Here it is… 12/21/2013 2:25:20 PM FileRep: http:??download.windowsupdate.com/msdownload/update/software/defu/2013/12/am_delta_patch_1.165.346.0_4cb2aa0d327317dd698a6528c1a63cecc8740cbe.exe
[Downloaded by: C:\Windows\System32\svchost.exe]
has a poor reputation.
→ Result: Aborting download.