locked
OEM Dell pc now says it's Window 7 is invalid. RRS feed

  • Question

  • Hi,

    About a 3 weeks ago one of my users started getting the notification that not genuine. I've tried a number of the suggestions in this forum to rectify this without any luck. When I try to go online to validate I never get past the "Please wait" screen. When I go to computer properties it says "status not available" and Product ID: not available. Here's the MGADiag result

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0x80070005
    Windows Product Key: N/A, hr=0x80070005
    Windows Product Key Hash: N/A, hr=0x80070005
    Windows Product ID: 00371-OEM-8992671-00524
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Basic 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>00371-OEM-8992671-00524</PID><PIDType>2</PIDType><SID>S-1-5-21-339256910-2476184951-1403849894</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>OptiPlex 780                 </Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A13</Version><SMBIOSVersion major="2" minor="5"/><Date>20120613000000.000000+000</Date></BIOS><HWID>7B593C07018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL  </OEMID><OEMTableID>B10K   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0013-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Basic 2007</Name><Ver>12</Ver><Val>48045204A6AADC2</Val><Hash>bsAetGN6mtH9Z63DYJIwQX2wFF0=</Hash><Pid>89445-OEM-6473762-03404</Pid><PidType>4</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
    Error: 0x46

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0001000000000000
    Event Time Stamp: 5:10:2012 19:54
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered Service: sppsvc


    HWID Data-->
    HWID Hash Current: LgAAAAEAAAABAAIAAQABAAAAAgABAAEA6GHWEohAfEimzHiEqOMeD+6r7dNGyg==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            DELL          B10K   
      FACP            DELL          B10K   
      HPET            DELL          B10K   
      BOOT            DELL          B10K   
      MCFG            DELL          B10K   
      SSDT            DELL        st_ex
      ASF!            DELL          B10K   
      TCPA            DELL          B10K   
      ____            DELL          B10K   
      SLIC            DELL          B10K   
      SSDT            DELL        st_ex
      SSDT            DELL        st_ex
      SSDT            DELL        st_ex

    I hope  you can help.

    Friday, August 10, 2012 8:26 PM

Answers

  • I have NEVER seen that error message before in a command prompt window

    C:\Windows\system32>ATTRIB -R C:\Windows\ServiceProfiles\NetworkService /s
    The request could not be performed because of an I/O device error.
    File not found - C:\Windows\ServiceProfiles\NetworkService

    It would tend to indicate that there are hardware problems. I can only really suggest that you take the machine to a competent tech for evalution, after backing up all data to external media.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Wednesday, August 22, 2012 4:03 PM
    Moderator

All replies

  • Click on Start

    in the Search box, type

    SERVICES.MSC

    and hit the Enter key - accept the UAC prompt if you get one.

    Look in the console for the Software Protection service, right-click on it and select Properties.

    make sure that the Startup Type is set to Automatic (Delayed Start), and click Apply.

     

    Try starting the service now - do you get an error message? Does it start? does it almost immediately stop again?

    Post back with your results, and a new MGADiag report.

     

    If it doesn't start, then please do the following...

    Please open an Elevated (Administrator) Command Prompt window and use the following commands....

     

    net start sppsvc

    sc qc sppsvc

    sc queryex sppsvc

    sc qprivs sppsvc

    sc qsidtype sppsvc

    sc sdshow sppsvc

     

     

     

      Here are some instructions to make life easier :)

    1) To open an Elevated Command Prompt Window (the CP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt. 

    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Windows, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once. 

    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.    


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 10, 2012 8:39 PM
    Moderator
  • Noel,

    C:\Windows\system32>net start sppsvc
    The requested service has already been started.

    More help is available by typing NET HELPMSG 2182.


    C:\Windows\system32>
    C:\Windows\system32>sc qc sppsvc
    [SC] QueryServiceConfig SUCCESS

    SERVICE_NAME: sppsvc
            TYPE               : 10  WIN32_OWN_PROCESS
            START_TYPE         : 2   AUTO_START  (DELAYED)
            ERROR_CONTROL      : 1   NORMAL
            BINARY_PATH_NAME   : C:\Windows\system32\sppsvc.exe
            LOAD_ORDER_GROUP   :
            TAG                : 0
            DISPLAY_NAME       : Software Protection
            DEPENDENCIES       : RpcSs
            SERVICE_START_NAME : NT AUTHORITY\NetworkService

    thanks for responding. Has alwwasy been running in this fashion throughout the issue..

    Here's the the new MGADiag.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 50
    Cached Online Validation Code: N/A, hr = 0x80070005
    Windows Product Key: N/A, hr=0x80070005
    Windows Product Key Hash: N/A, hr=0x80070005
    Windows Product ID: 00371-OEM-8992671-00524
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Basic 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>00371-OEM-8992671-00524</PID><PIDType>2</PIDType><SID>S-1-5-21-339256910-2476184951-1403849894</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>OptiPlex 780                 </Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A13</Version><SMBIOSVersion major="2" minor="5"/><Date>20120613000000.000000+000</Date></BIOS><HWID>7B593C07018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL  </OEMID><OEMTableID>B10K   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0013-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Basic 2007</Name><Ver>12</Ver><Val>48045204A6AADC2</Val><Hash>bsAetGN6mtH9Z63DYJIwQX2wFF0=</Hash><Pid>89445-OEM-6473762-03404</Pid><PidType>4</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/></Applications></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
    Error: 0x46

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 5:10:2012 19:54
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: LgAAAAEAAAABAAIAAQABAAAAAgABAAEA6GHWEohAfEimzHiEqOMeD+6r7dNGyg==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name OEMID Value OEMTableID Value
      APIC   DELL    B10K  
      FACP   DELL    B10K  
      HPET   DELL    B10K  
      BOOT   DELL    B10K  
      MCFG   DELL    B10K  
      SSDT   DELL  st_ex
      ASF!   DELL    B10K  
      TCPA   DELL    B10K  
      ____   DELL    B10K  
      SLIC   DELL    B10K  
      SSDT   DELL  st_ex
      SSDT   DELL  st_ex
      SSDT   DELL  st_ex

    Monday, August 13, 2012 4:07 PM
  • Open an Elevated Command Prompt, and run the following
    commands

    sc sdshow plugplay
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18" /S
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19" /S
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20" /S

    Copy and paste the results to your reply



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


    Monday, August 13, 2012 4:34 PM
    Moderator
  •   

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>sc sdshow plugplay

    D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCR
    RC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\HTML Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ITStorage
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScriptedDiagnosticsProvider
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Tablet PC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\TabletPC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Search

    C:\Windows\system32>NT\CurrentVersion\ProfileList\S-1-5-18" /S
    The system cannot find the path specified.

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\HTML Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ITStorage
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScriptedDiagnosticsProvider
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Tablet PC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\TabletPC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Search

    C:\Windows\system32>NT\CurrentVersion\ProfileList\S-1-5-19" /S
    The system cannot find the path specified.

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\HTML Help
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ITStorage
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScriptedDiagnosticsProvider
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Tablet PC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\TabletPC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Search

    C:\Windows\system32>NT\CurrentVersion\ProfileList\S-1-5-20" /S
    The system cannot find the path specified.

    Monday, August 13, 2012 5:29 PM
  • do I need to add these keys to the registry?

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18]

    "Flags"=dword:0000000c
    "State"=dword:00000000
    "RefCount"=dword:00000001
    "Sid"=hex:01,01,00,00,00,00,00,05,12,00,00,00
    "ProfileImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
      00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
      5c,00,63,00,6f,00,6e,00,66,00,69,00,67,00,5c,00,73,00,79,00,73,00,74,00,65,\
      00,6d,00,70,00,72,00,6f,00,66,00,69,00,6c,00,65,00,00,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19]
    "ProfileImagePath"=hex(2):43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,\
      00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,50,00,72,00,6f,00,\
      66,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,\
      00,72,00,76,00,69,00,63,00,65,00,00,00
    "Flags"=dword:00000000
    "State"=dword:00000000

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20]
    "ProfileImagePath"=hex(2):43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,\
      00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,50,00,72,00,6f,00,\
      66,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,\
      00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00
    "Flags"=dword:00000000
    "State"=dword:00000000

    Monday, August 13, 2012 5:32 PM
  • Lets see what's reallly there - I've corrected the fomatting errors in my earlier response - please repeat the commands and post the new results

    (sorry - but this appears to have been brought about by a forum bug)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, August 13, 2012 5:39 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>sc sdshow plugplay

    D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCR
    RC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5-18" /S

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-18
        Flags    REG_DWORD    0xc
        State    REG_DWORD    0x0
        RefCount    REG_DWORD    0x1
        Sid    REG_BINARY    010100000000000512000000
        ProfileImagePath    REG_EXPAND_SZ    %systemroot%\system32\config\systemprof
    ile


    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5-19" /S

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-19
        ProfileImagePath    REG_EXPAND_SZ    C:\Windows\ServiceProfiles\LocalService

        Flags    REG_DWORD    0x0
        State    REG_DWORD    0x0

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5

    It freezes at this command

    Tuesday, August 14, 2012 2:11 PM
  • It shouldn't - hit the Enter key, and it should run happily enough?

    The rest of it looks fine so we'll have to look elsewhere for the problem anyhow.

    Run the following commands, and post the results.

    REG QUERY HKU
    REG QUERY HKU\S-1-5-20
    REG QUERY HKU\S-1-5-20\Environment
    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"
    DIR C:\Windows\ServiceProfiles\NetworkService
    DIR C:\Windows\ServiceProfiles\NetworkService\AppData
    DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft
    DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


    Tuesday, August 14, 2012 3:56 PM
    Moderator
  • C:\Windows\system32>REG QUERY HKU

    HKEY_USERS\.DEFAULT
    HKEY_USERS\S-1-5-19
    HKEY_USERS\S-1-5-21-2582632990-2024588849-3415106840-3123
    HKEY_USERS\S-1-5-21-2582632990-2024588849-3415106840-3123_Classes
    HKEY_USERS\S-1-5-21-2582632990-2024588849-3415106840-3207
    HKEY_USERS\S-1-5-21-2582632990-2024588849-3415106840-3207_Classes
    HKEY_USERS\S-1-5-18

    C:\Windows\system32>REG QUERY HKU\S-1-5-20
    ERROR: The system was unable to find the specified registry key or value.

    C:\Windows\system32>REG QUERY HKU\S-1-5-20\Environment
    ERROR: The system was unable to find the specified registry key or value.

    C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
    \ProfileList\S-1-5-20"

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-20
        ProfileImagePath    REG_EXPAND_SZ    C:\Windows\ServiceProfiles\NetworkServi
    ce
        Flags    REG_DWORD    0x0
        State    REG_DWORD    0x0


    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    05/08/2012  04:10 PM    <DIR>          .

    and again it froze despite hitting the enter key.

    I'm sorry about the dlay's but this is the companies accountant and I only have short windows to do the testing

    Tuesday, August 14, 2012 6:48 PM
  • it does eventuall run but it's exceeding the buffer with its reply

    07/13/2009  09:54 PM    <DIR>          wfp
    11/20/2010  05:17 AM           802,304 WFS.exe
    07/13/2009  06:11 PM           669,184 WFSR.dll
    07/13/2009  02:41 PM            12,704 WFWNET.DRV
    07/13/2009  06:16 PM            32,768 whealogr.dll
    07/13/2009  06:14 PM            35,328 where.exe
    07/13/2009  06:16 PM            14,848 whhelper.dll
    07/13/2009  06:14 PM            43,008 whoami.exe
    07/13/2009  06:14 PM            88,576 wiaacmgr.exe
    07/13/2009  06:16 PM           544,256 wiaaut.dll
    11/20/2010  05:21 AM           416,768 wiadefui.dll
    07/13/2009  06:16 PM           113,664 wiadss.dll
    11/20/2010  05:21 AM            33,280 wiarpc.dll
    07/13/2009  06:16 PM            87,552 wiascanprofiles.dll
    11/20/2010  05:21 AM           463,360 wiaservc.dll
    07/13/2009  06:16 PM           444,928 wiashext.dll
    07/13/2009  06:16 PM            12,800 wiatrace.dll
    11/20/2010  05:21 AM           109,568 wiavideo.dll 
    07/13/2009  02:41 PM             9,216 WIFEMAN.DLL
    11/20/2010  05:21 AM           406,528 wimgapi.dll
    11/20/2010  05:17 AM           327,680 wimserv.exe
    07/13/2009  04:20 PM             6,656 win.com
    05/14/2012  06:05 PM         2,343,936 win32k.sys
    11/20/2010  05:21 AM           492,032 win32spl.dll
    06/10/2009  02:42 PM            13,312 win87em.dll
    07/13/2009  06:16 PM            57,856 winbio.dll
    07/13/2009  09:52 PM    <DIR>          WinBioDatabase
    07/13/2009  09:56 PM    <DIR>          WinBioPlugIns
    07/13/2009  06:16 PM            12,800 winbrand.dll
    07/13/2009  06:16 PM            35,328 wincredprovider.dll
    08/11/1997  01:00 AM            30,720 WINDBVER.EXE
    11/20/2010  05:17 AM           257,536 WindowsAnytimeUpgrade.exe
    11/20/2010  05:17 AM           292,864 WindowsAnytimeUpgradeResults.exe
    07/13/2009  06:14 PM           376,832 WindowsAnytimeUpgradeui.exe
    11/20/2010  05:21 AM         1,010,688 WindowsCodecs.dll
    07/13/2009  06:16 PM           192,512 WindowsCodecsExt.dll
    07/13/2009  09:52 PM    <DIR>          WindowsPowerShell
    07/13/2009  06:16 PM            82,944 winethc.dll
    07/13/2009  07:37 PM    <DIR>          winevt
    07/13/2009  06:16 PM            27,648 WinFax.dll
    11/20/2010  05:21 AM           351,232 winhttp.dll
    05/14/2012  08:03 PM           981,504 wininet.dll
    07/13/2009  06:14 PM            96,256 wininit.exe
    07/13/2009  06:16 PM            70,144 winipsec.dll
    11/20/2010  05:24 AM           508,904 winload.exe
    11/20/2010  05:17 AM           286,720 winlogon.exe
    11/20/2010  05:21 AM           194,048 winmm.dll
    07/13/2009  02:41 PM             5,120 WINNLS.DLL
    07/13/2009  06:16 PM            16,896 winnsi.dll
    07/13/2009  02:41 PM             2,080 WINOLDAP.MOD
    11/20/2010  05:24 AM           442,720 winresume.exe
    07/13/2009  09:56 PM    <DIR>          winrm
    06/10/2009  02:40 PM                35 winrm.cmd
    06/10/2009  02:40 PM           201,034 winrm.vbs
    07/13/2009  06:16 PM            20,992 winrnr.dll
    07/13/2009  06:14 PM            39,936 winrs.exe
    07/13/2009  06:16 PM           240,128 winrscmd.dll
    07/13/2009  06:14 PM            20,480 winrshost.exe
    07/13/2009  06:11 PM             1,536 winrsmgr.dll
    07/13/2009  06:16 PM            10,752 winrssrv.dll
    11/20/2010  05:17 AM         3,367,424 WinSAT.exe
    11/20/2010  05:21 AM           335,872 WinSATAPI.dll
    11/20/2010  05:21 AM           134,656 WinSCard.dll
    07/13/2009  06:15 PM            11,264 winshfhc.dll
    07/13/2009  02:41 PM             2,864 WINSOCK.DLL
    07/13/2009  06:16 PM            68,608 winsockhc.dll
    11/20/2010  05:16 AM           320,000 winspool.drv
    07/13/2009  02:41 PM             2,112 WINSPOOL.EXE
    07/13/2009  06:16 PM            16,896 WINSRPC.DLL
    06/23/2011  09:27 PM           169,984 winsrv.dll
    11/20/2010  05:21 AM           156,672 winsta.dll
    07/13/2009  06:16 PM           296,960 WinSync.dll
    07/13/2009  06:16 PM           173,056 WinSyncMetastore.dll
    07/13/2009  06:16 PM           116,736 WinSyncProviders.dll
    02/29/2012  10:37 PM           172,544 wintrust.dll
    07/13/2009  06:16 PM            16,896 winusb.dll
    07/13/2009  06:14 PM            79,872 winver.exe
    11/20/2010  05:17 AM           334,336 wisptis.exe
    11/20/2010  05:21 AM            47,104 wkscli.dll
    11/20/2010  03:22 AM           223,232 wksprt.exe
    07/13/2009  06:16 PM            12,800 wksprtPS.dll
    11/20/2010  05:21 AM            84,480 wkssvc.dll
    07/13/2009  06:16 PM            81,408 wlanapi.dll
    07/13/2009  06:16 PM           177,152 wlancfg.dll
    07/13/2009  06:16 PM           669,696 WLanConn.dll
    07/13/2009  06:16 PM           505,856 wlandlg.dll
    07/13/2009  06:14 PM            77,312 wlanext.exe
    11/20/2010  05:21 AM           411,648 wlangpui.dll
    07/13/2009  06:16 PM           158,208 WLanHC.dll
    07/13/2009  06:16 PM            84,480 wlanhlp.dll
    07/13/2009  06:16 PM            16,896 wlaninst.dll
    07/13/2009  06:16 PM           748,544 WlanMM.dll
    11/20/2010  05:21 AM           428,032 wlanmsm.dll
    11/20/2010  05:21 AM         1,326,592 wlanpref.dll
    07/13/2009  06:16 PM           392,192 wlansec.dll
    07/13/2009  06:16 PM           829,440 wlansvc.dll
    11/20/2010  05:21 AM           410,112 wlanui.dll
    07/13/2009  06:16 PM             8,192 wlanutil.dll
    11/20/2010  05:21 AM           269,824 Wldap32.dll
    07/13/2009  06:16 PM           118,784 wlgpclnt.dll
    07/13/2009  06:14 PM            40,448 wlrmdr.exe
    07/13/2009  06:16 PM             8,704 WlS0WndH.dll
    11/20/2010  05:21 AM           902,656 WMADMOD.DLL
    07/13/2009  06:16 PM           812,032 WMADMOE.DLL
    07/13/2009  06:16 PM           237,568 WMASF.DLL
    07/13/2009  06:16 PM            53,760 wmcodecdspps.dll
    07/13/2009  06:16 PM            31,744 wmdmlog.dll
    07/13/2009  06:16 PM            36,864 wmdmps.dll
    11/20/2010  05:21 AM           507,392 wmdrmdev.dll
    11/20/2010  05:21 AM           436,736 wmdrmnet.dll
    11/20/2010  05:21 AM           616,960 wmdrmsdk.dll
    07/13/2009  06:11 PM             2,048 wmerror.dll
    02/29/2012  10:29 PM             5,120 wmi.dll
    11/20/2010  05:21 AM           351,232 wmicmiplugin.dll
    07/13/2009  06:16 PM           155,136 wmidx.dll
    06/10/2009  02:39 PM           144,673 WmiMgmt.msc
    07/13/2009  06:16 PM            23,040 wmiprop.dll
    11/20/2010  05:21 AM         1,003,008 WMNetMgr.dll
    11/20/2010  05:21 AM        11,410,432 wmp.dll
    07/13/2009  06:16 PM            22,528 wmpcm.dll
    07/13/2009  06:16 PM           170,496 WmpDui.dll
    11/20/2010  05:21 AM           299,520 wmpdxm.dll
    11/20/2010  05:21 AM           352,256 wmpeffects.dll
    11/20/2010  05:21 AM         1,624,064 WMPEncEn.dll
    11/20/2010  05:21 AM           318,464 WMPhoto.dll
    11/20/2010  05:08 AM        12,625,408 wmploc.DLL
    11/20/2010  05:21 AM           738,816 wmpmde.dll
    11/20/2010  05:21 AM           144,384 wmpps.dll
    11/20/2010  05:21 AM           105,472 wmpshell.dll
    11/20/2010  05:21 AM           182,272 wmpsrcwp.dll
    07/13/2009  06:16 PM            11,264 wmsgapi.dll
    11/20/2010  05:21 AM           739,328 WMSPDMOD.DLL
    07/13/2009  06:16 PM         1,325,056 WMSPDMOE.DLL
    11/20/2010  05:20 AM         2,504,192 WMVCORE.DLL
    11/20/2010  05:21 AM         1,619,456 WMVDECOD.DLL
    07/13/2009  06:16 PM           144,896 wmvdspa.dll
    07/13/2009  06:16 PM         1,568,768 WMVENCOD.DLL
    11/20/2010  05:21 AM           541,184 WMVSDECD.DLL
    07/13/2009  06:16 PM           358,400 WMVSENCD.DLL
    07/13/2009  06:16 PM           664,576 WMVXENCD.DLL
    07/13/2009  06:16 PM           282,112 wow32.dll
    07/13/2009  02:41 PM             2,864 WOWDEB.EXE
    07/13/2009  02:41 PM             8,960 WOWEXEC.EXE
    07/13/2009  06:16 PM           308,736 Wpc.dll
    07/13/2009  06:16 PM           128,512 wpcao.dll
    11/20/2010  05:21 AM           766,464 wpccpl.dll
    07/13/2009  06:16 PM            15,872 wpcmig.dll
    07/13/2009  06:16 PM            10,752 wpcsvc.dll
    07/13/2009  06:16 PM           179,200 wpcumi.dll
    11/20/2010  05:21 AM            85,504 wpdbusenum.dll
    07/13/2009  06:16 PM           229,376 WpdMtp.dll
    07/13/2009  06:16 PM            73,216 WpdMtpUS.dll
    11/20/2010  05:21 AM         2,311,168 wpdshext.dll
    07/13/2009  06:14 PM            30,208 WPDShextAutoplay.exe
    11/20/2010  05:21 AM           105,984 WPDShServiceObj.dll
    11/20/2010  05:21 AM           350,720 WPDSp.dll
    11/20/2010  05:21 AM           198,144 wpdwcn.dll
    11/20/2010  05:21 AM           577,024 wpd_ci.dll
    07/13/2009  06:14 PM            39,424 wpnpinst.exe
    07/13/2009  06:14 PM             9,216 write.exe
    07/13/2009  06:11 PM             4,608 ws2help.dll
    11/20/2010  05:21 AM           206,848 ws2_32.dll
    11/20/2010  05:21 AM            51,712 wscapi.dll
    07/13/2009  06:16 PM            95,744 wscinterop.dll
    07/13/2009  06:16 PM            18,944 wscisvif.dll
    07/13/2009  06:16 PM            56,832 wscmisetup.dll
    07/13/2009  06:16 PM             9,728 wscproxystub.dll
    07/13/2009  06:14 PM           141,824 wscript.exe
    07/13/2009  06:16 PM            73,728 wscsvc.dll
    07/13/2009  06:14 PM         1,140,736 wscui.cpl
    11/20/2010  05:21 AM           458,752 WSDApi.dll
    11/20/2010  05:21 AM            21,504 wsdchngr.dll
    07/13/2009  06:16 PM           185,344 WSDMon.dll
    07/13/2009  06:16 PM            57,856 WSDPrintProxy.DLL
    07/13/2009  06:16 PM            55,808 WSDScanProxy.dll
    07/13/2009  06:16 PM         1,294,336 wsecedit.dll
    07/13/2009  06:16 PM            27,136 wsepno.dll
    11/20/2010  05:21 AM            36,352 wshbth.dll
    07/13/2009  06:16 PM            25,600 wshcon.dll
    07/13/2009  06:16 PM            15,360 wshelper.dll
    07/13/2009  06:16 PM            80,896 wshext.dll
    07/13/2009  06:16 PM            10,752 wship6.dll
    11/20/2010  05:21 AM            11,264 wshirda.dll
    07/13/2009  06:16 PM            10,752 wshnetbs.dll
    07/13/2009  06:14 PM           122,368 wshom.ocx
    07/13/2009  06:16 PM            13,824 wshqos.dll
    07/13/2009  06:16 PM            14,848 wshrm.dll
    07/13/2009  06:16 PM             9,216 WSHTCPIP.DLL
    11/06/2009  12:27 PM           262,144 WSLCCOM.dll
    06/10/2009  02:40 PM             4,675 wsmanconfig_schema.xml
    07/13/2009  06:14 PM           198,144 WSManHTTPConfig.exe
    07/13/2009  06:16 PM           248,832 WSManMigrationPlugin.dll
    07/13/2009  06:16 PM           145,920 WsmAuto.dll
    07/13/2009  06:16 PM            10,752 wsmplpxy.dll
    07/13/2009  06:14 PM            12,288 wsmprovhost.exe
    06/10/2009  02:40 PM             1,559 WsmPty.xsl
    07/13/2009  06:11 PM            54,272 WsmRes.dll
    11/20/2010  05:21 AM         1,175,040 WsmSvc.dll
    06/10/2009  02:40 PM             2,426 WsmTxt.xsl
    07/13/2009  06:16 PM           213,504 WsmWmiPl.dll
    11/20/2010  05:21 AM            51,712 wsnmp32.dll
    07/13/2009  06:16 PM            15,360 wsock32.dll
    11/20/2010  05:18 AM           254,976 wsqmcons.exe
    11/20/2010  05:16 AM            68,608 WSTPager.ax
    11/20/2010  05:21 AM            40,448 wtsapi32.dll
    06/02/2012  03:19 PM           577,048 wuapi.dll
    06/02/2012  03:12 PM            33,792 wuapp.exe
    06/02/2012  03:19 PM            53,784 wuauclt.exe
    06/02/2012  03:19 PM         1,933,848 wuaueng.dll
    06/02/2012  03:12 PM         2,422,272 wucltux.dll
    11/20/2010  05:21 AM            39,936 WUDFCoinstaller.dll
    11/20/2010  05:18 AM           195,584 WUDFHost.exe
    11/20/2010  05:21 AM           162,304 WUDFPlatform.dll
    11/20/2010  05:21 AM            67,584 WUDFSvc.dll
    11/20/2010  05:21 AM           567,808 WUDFx.dll
    06/02/2012  03:12 PM            88,576 wudriver.dll
    06/02/2012  03:19 PM            35,864 wups.dll
    06/02/2012  03:19 PM            45,080 wups2.dll
    11/20/2010  05:18 AM           314,880 wusa.exe
    06/02/2012  03:19 PM           171,904 wuwebv.dll
    02/03/2010  10:59 AM         1,556,480 wvauth.dll
    11/20/2010  05:21 AM           444,928 wvc.dll
    02/03/2010  10:57 AM           774,144 WvCredProv.dll
    07/13/2009  06:16 PM           163,328 Wwanadvui.dll
    07/13/2009  06:16 PM           284,672 WWanAPI.dll
    07/13/2009  06:16 PM            42,496 wwancfg.dll
    11/20/2010  05:21 AM           196,608 wwanconn.dll
    07/13/2009  06:16 PM            56,320 WWanHC.dll
    07/13/2009  06:16 PM            13,312 wwaninst.dll
    07/13/2009  06:16 PM           674,304 wwanmm.dll
    07/13/2009  06:16 PM            39,424 Wwanpref.dll
    11/20/2010  05:21 AM            40,960 wwanprotdim.dll
    07/13/2009  06:16 PM           185,856 wwansvc.dll
    07/13/2009  06:16 PM            27,648 wwapi.dll
    01/19/2010  09:44 AM           249,856 wxvault.dll
    07/13/2009  06:16 PM            80,896 wzcdlg.dll
    07/13/2009  06:14 PM            36,864 xcopy.exe
    07/13/2009  06:16 PM            25,600 XInput9_1_0.dll
    03/25/2008  06:44 AM            25,824 xltccc.dll
    03/25/2008  06:45 AM             9,440 xltEvLog.dll
    03/25/2008  06:45 AM           103,648 xltGscProxy.dll
    03/25/2008  06:45 AM           308,448 xltIop.dll
    03/25/2008  06:45 AM           644,320 xltIRes.dll
    03/25/2008  06:46 AM            77,536 xltZlib.dll
    07/13/2009  06:16 PM            54,784 xmlfilter.dll
    07/13/2009  06:16 PM           180,224 xmllite.dll
    07/13/2009  06:16 PM            17,920 xmlprovi.dll
    07/13/2009  06:16 PM            47,616 xolehlp.dll
    07/13/2009  06:16 PM           601,600 XpsFilt.dll
    01/07/2011  12:46 AM           288,256 XpsGdiConverter.dll
    01/07/2011  12:46 AM           870,912 XpsPrint.dll
    11/20/2010  05:21 AM           135,168 XpsRasterService.dll
    07/13/2009  06:14 PM         3,405,312 xpsrchvw.exe
    06/10/2009  02:15 PM            76,060 xpsrchvw.xml
    11/20/2010  05:21 AM         1,712,640 xpsservices.dll
    07/13/2009  06:16 PM           443,904 XPSSHHDR.dll
    07/13/2009  06:16 PM           930,816 xpssvcs.dll
    06/10/2009  02:42 PM             4,041 xwizard.dtd
    07/13/2009  06:14 PM            41,472 xwizard.exe
    07/13/2009  06:16 PM           354,816 xwizards.dll
    07/13/2009  06:16 PM            85,504 xwreg.dll
    07/13/2009  06:16 PM           158,208 xwtpdui.dll
    07/13/2009  06:16 PM           107,520 xwtpw32.dll
    07/13/2009  07:37 PM    <DIR>          zh-CN
    07/13/2009  07:37 PM    <DIR>          zh-HK
    07/13/2009  07:37 PM    <DIR>          zh-TW
    11/20/2010  05:21 AM           327,680 zipfldr.dll
                2975 File(s)  1,108,035,127 bytes
                  96 Dir(s)  97,101,291,520 bytes free

    C:\Windows\system32>"C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\M
    icrosoft\Software ProtectionPlatform"
    '"C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Software P
    rotectionPlatform"' is not recognized as an internal or external command,
    operable program or batch file.

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roa
    ming\Microsoft
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft NT AUTHORITY
    \SYSTEM:(I)(OI)(CI)(F)
                                                                        BUILTIN\Admi
    nistrators:(I)(OI)(CI)(F)
                                                                        NT AUTHORITY
    \NETWORK SERVICE:(I)(OI)(CI)(F)
                                                                        ATLAS-LIZ\jo
    hn:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS "C:\Windows\ServiceProfiles\NetworkService\AppData\Ro
    aming\Microsoft\Software ProtectionPlatform"
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Software Pro
    tectionPlatform: The system cannot find the file specified.
    Successfully processed 0 files; Failed processing 1 files

    Tuesday, August 14, 2012 7:02 PM
  • This looks like a serious problem - I'll have to review it in the morning.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Tuesday, August 14, 2012 9:56 PM
    Moderator
  • Any progress?
    Thursday, August 16, 2012 2:26 PM
  • Oooops! sorry!  I got side-tracked. :(

    Is this machine on a Domain network??

    Please run the following command and post the results

    DIR C:\Windows\ *.* /al


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Thursday, August 16, 2012 3:46 PM
    Moderator
  • C:\>DIR C:\Windows\ *.* /al
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows

    File Not Found

     Directory of C:\

    07/13/2009  09:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
                   0 File(s)              0 bytes
                   1 Dir(s)  96,153,882,624 bytes free

    Thursday, August 16, 2012 5:50 PM
  • Hmmm - please repeat that, using an ELevated Command Prompt window, and the dollowing command

    DIR   C:\Windows\*.*   /AL /S

    (note there is no space in C:\Windows\*.*)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


    Thursday, August 16, 2012 10:40 PM
    Moderator
  • C:\Windows\system32>DIR C:\Windows\*.* /AL /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF
    File Not Found

    C:\Windows\system32>

    Friday, August 17, 2012 2:36 PM
  • That is very surprising!

    I was certain we'd see something there.

    let's widen the search, then

    DIR C:\*.* /AL /S


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 17, 2012 3:02 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\*.* /AL /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\

    07/13/2009  09:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
                   0 File(s)              0 bytes

     Directory of C:\ProgramData

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\*.* /AL /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\

    07/13/2009  09:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
                   0 File(s)              0 bytes

     Directory of C:\ProgramData

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users

    07/13/2009  09:53 PM    <SYMLINKD>     All Users [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Default User [C:\Users\Default]
                   0 File(s)              0 bytes

     Directory of C:\Users\All Users

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppDat
    a\Roaming]
    07/13/2009  09:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\
    Local]
    07/13/2009  09:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]

    07/13/2009  09:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming
    \Microsoft\Windows\Network Shortcuts]
    07/13/2009  09:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roami
    ng\Microsoft\Windows\Printer Shortcuts]
    07/13/2009  09:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\
    Microsoft\Windows\Recent]
    07/13/2009  09:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\
    Microsoft\Windows\SendTo]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roam
    ing\Microsoft\Windows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roami
    ng\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default\AppData\Local

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppDat
    a\Local]
    07/13/2009  09:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\M
    icrosoft\Windows\History]
    07/13/2009  09:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Defaul
    t\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default\Documents

    07/13/2009  09:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
    07/13/2009  09:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
    07/13/2009  09:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin

    08/16/2010  12:46 PM    <JUNCTION>     Application Data [C:\Users\hdadmin\AppDat
    a\Roaming]
    08/16/2010  12:46 PM    <JUNCTION>     Cookies [C:\Users\hdadmin\AppData\Roaming
    \Microsoft\Windows\Cookies]
    08/16/2010  12:46 PM    <JUNCTION>     Local Settings [C:\Users\hdadmin\AppData\
    Local]
    08/16/2010  12:46 PM    <JUNCTION>     My Documents [C:\Users\hdadmin\Documents]

    08/16/2010  12:46 PM    <JUNCTION>     NetHood [C:\Users\hdadmin\AppData\Roaming
    \Microsoft\Windows\Network Shortcuts]
    08/16/2010  12:46 PM    <JUNCTION>     PrintHood [C:\Users\hdadmin\AppData\Roami
    ng\Microsoft\Windows\Printer Shortcuts]
    08/16/2010  12:46 PM    <JUNCTION>     Recent [C:\Users\hdadmin\AppData\Roaming\
    Microsoft\Windows\Recent]
    08/16/2010  12:46 PM    <JUNCTION>     SendTo [C:\Users\hdadmin\AppData\Roaming\
    Microsoft\Windows\SendTo]
    08/16/2010  12:46 PM    <JUNCTION>     Start Menu [C:\Users\hdadmin\AppData\Roam
    ing\Microsoft\Windows\Start Menu]
    08/16/2010  12:46 PM    <JUNCTION>     Templates [C:\Users\hdadmin\AppData\Roami
    ng\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin\AppData\Local

    08/16/2010  12:46 PM    <JUNCTION>     Application Data [C:\Users\hdadmin\AppDat
    a\Local]
    08/16/2010  12:46 PM    <JUNCTION>     History [C:\Users\hdadmin\AppData\Local\M
    icrosoft\Windows\History]
    08/16/2010  12:46 PM    <JUNCTION>     Temporary Internet Files [C:\Users\hdadmi
    n\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin\Documents

    08/16/2010  12:46 PM    <JUNCTION>     My Music [C:\Users\hdadmin\Music]
    08/16/2010  12:46 PM    <JUNCTION>     My Pictures [C:\Users\hdadmin\Pictures]
    08/16/2010  12:46 PM    <JUNCTION>     My Videos [C:\Users\hdadmin\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\liz

    08/16/2010  02:08 PM    <JUNCTION>     Application Data [C:\Users\liz\AppData\Ro
    aming]
    08/16/2010  02:08 PM    <JUNCTION>     Cookies [C:\Users\liz\AppData\Roaming\Mic
    rosoft\Windows\Cookies]
    08/16/2010  02:08 PM    <JUNCTION>     Local Settings [C:\Users\liz\AppData\Loca
    l]
    08/16/2010  02:08 PM    <JUNCTION>     My Documents [C:\Users\liz\Documents]
    08/16/2010  02:08 PM    <JUNCTION>     NetHood [C:\Users\liz\AppData\Roaming\Mic
    rosoft\Windows\Network Shortcuts]
    08/16/2010  02:08 PM    <JUNCTION>     PrintHood [C:\Users\liz\AppData\Roaming\M
    icrosoft\Windows\Printer Shortcuts]
    08/16/2010  02:08 PM    <JUNCTION>     Recent [C:\Users\liz\AppData\Roaming\Micr
    osoft\Windows\Recent]
    08/16/2010  02:08 PM    <JUNCTION>     SendTo [C:\Users\liz\AppData\Roaming\Micr
    osoft\Windows\SendTo]
    08/16/2010  02:08 PM    <JUNCTION>     Start Menu [C:\Users\liz\AppData\Roaming\
    Microsoft\Windows\Start Menu]
    08/16/2010  02:08 PM    <JUNCTION>     Templates [C:\Users\liz\AppData\Roaming\M
    icrosoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\liz\AppData\Local

    08/16/2010  02:08 PM    <JUNCTION>     Application Data [C:\Users\liz\AppData\Lo
    cal]
    08/16/2010  02:08 PM    <JUNCTION>     History [C:\Users\liz\AppData\Local\Micro
    soft\Windows\History]
    08/16/2010  02:08 PM    <JUNCTION>     Temporary Internet Files [C:\Users\liz\Ap
    pData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\Public\Documents

    07/13/2009  09:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
    07/13/2009  09:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
    07/13/2009  09:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20

    10/25/2010  02:05 PM    <JUNCTION>     Application Data [C:\Users\QBDataServiceU
    ser20\AppData\Roaming]
    10/25/2010  02:05 PM    <JUNCTION>     Cookies [C:\Users\QBDataServiceUser20\App
    Data\Roaming\Microsoft\Windows\Cookies]
    10/25/2010  02:05 PM    <JUNCTION>     Local Settings [C:\Users\QBDataServiceUse
    r20\AppData\Local]
    10/25/2010  02:05 PM    <JUNCTION>     My Documents [C:\Users\QBDataServiceUser2
    0\Documents]
    10/25/2010  02:05 PM    <JUNCTION>     NetHood [C:\Users\QBDataServiceUser20\App
    Data\Roaming\Microsoft\Windows\Network Shortcuts]
    10/25/2010  02:05 PM    <JUNCTION>     PrintHood [C:\Users\QBDataServiceUser20\A
    ppData\Roaming\Microsoft\Windows\Printer Shortcuts]
    10/25/2010  02:05 PM    <JUNCTION>     Recent [C:\Users\QBDataServiceUser20\AppD
    ata\Roaming\Microsoft\Windows\Recent]
    10/25/2010  02:05 PM    <JUNCTION>     SendTo [C:\Users\QBDataServiceUser20\AppD
    ata\Roaming\Microsoft\Windows\SendTo]
    10/25/2010  02:05 PM    <JUNCTION>     Start Menu [C:\Users\QBDataServiceUser20\
    AppData\Roaming\Microsoft\Windows\Start Menu]
    10/25/2010  02:05 PM    <JUNCTION>     Templates [C:\Users\QBDataServiceUser20\A
    ppData\Roaming\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20\AppData\Local

    10/25/2010  02:05 PM    <JUNCTION>     Application Data [C:\Users\QBDataServiceU
    ser20\AppData\Local]
    10/25/2010  02:05 PM    <JUNCTION>     History [C:\Users\QBDataServiceUser20\App
    Data\Local\Microsoft\Windows\History]
    10/25/2010  02:05 PM    <JUNCTION>     Temporary Internet Files [C:\Users\QBData
    ServiceUser20\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20\Documents

    10/25/2010  02:05 PM    <JUNCTION>     My Music [C:\Users\QBDataServiceUser20\Mu
    sic]
    10/25/2010  02:05 PM    <JUNCTION>     My Pictures [C:\Users\QBDataServiceUser20
    \Pictures]
    10/25/2010  02:05 PM    <JUNCTION>     My Videos [C:\Users\QBDataServiceUser20\V
    ideos]
                   0 File(s)              0 bytes

    C:\Windows\system32>

    Friday, August 17, 2012 7:02 PM
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\*.* /AL /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\

    07/13/2009  09:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
                   0 File(s)              0 bytes

     Directory of C:\ProgramData

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\*.* /AL /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\

    07/13/2009  09:53 PM    <JUNCTION>     Documents and Settings [C:\Users]
                   0 File(s)              0 bytes

     Directory of C:\ProgramData

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users

    07/13/2009  09:53 PM    <SYMLINKD>     All Users [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Default User [C:\Users\Default]
                   0 File(s)              0 bytes

     Directory of C:\Users\All Users

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\ProgramData]
    07/13/2009  09:53 PM    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
    07/13/2009  09:53 PM    <JUNCTION>     Documents [C:\Users\Public\Documents]
    07/13/2009  09:53 PM    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Wind
    ows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windo
    ws\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppDat
    a\Roaming]
    07/13/2009  09:53 PM    <JUNCTION>     Local Settings [C:\Users\Default\AppData\
    Local]
    07/13/2009  09:53 PM    <JUNCTION>     My Documents [C:\Users\Default\Documents]

    07/13/2009  09:53 PM    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming
    \Microsoft\Windows\Network Shortcuts]
    07/13/2009  09:53 PM    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roami
    ng\Microsoft\Windows\Printer Shortcuts]
    07/13/2009  09:53 PM    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\
    Microsoft\Windows\Recent]
    07/13/2009  09:53 PM    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\
    Microsoft\Windows\SendTo]
    07/13/2009  09:53 PM    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roam
    ing\Microsoft\Windows\Start Menu]
    07/13/2009  09:53 PM    <JUNCTION>     Templates [C:\Users\Default\AppData\Roami
    ng\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default\AppData\Local

    07/13/2009  09:53 PM    <JUNCTION>     Application Data [C:\Users\Default\AppDat
    a\Local]
    07/13/2009  09:53 PM    <JUNCTION>     History [C:\Users\Default\AppData\Local\M
    icrosoft\Windows\History]
    07/13/2009  09:53 PM    <JUNCTION>     Temporary Internet Files [C:\Users\Defaul
    t\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\Default\Documents

    07/13/2009  09:53 PM    <JUNCTION>     My Music [C:\Users\Default\Music]
    07/13/2009  09:53 PM    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
    07/13/2009  09:53 PM    <JUNCTION>     My Videos [C:\Users\Default\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin

    08/16/2010  12:46 PM    <JUNCTION>     Application Data [C:\Users\hdadmin\AppDat
    a\Roaming]
    08/16/2010  12:46 PM    <JUNCTION>     Cookies [C:\Users\hdadmin\AppData\Roaming
    \Microsoft\Windows\Cookies]
    08/16/2010  12:46 PM    <JUNCTION>     Local Settings [C:\Users\hdadmin\AppData\
    Local]
    08/16/2010  12:46 PM    <JUNCTION>     My Documents [C:\Users\hdadmin\Documents]

    08/16/2010  12:46 PM    <JUNCTION>     NetHood [C:\Users\hdadmin\AppData\Roaming
    \Microsoft\Windows\Network Shortcuts]
    08/16/2010  12:46 PM    <JUNCTION>     PrintHood [C:\Users\hdadmin\AppData\Roami
    ng\Microsoft\Windows\Printer Shortcuts]
    08/16/2010  12:46 PM    <JUNCTION>     Recent [C:\Users\hdadmin\AppData\Roaming\
    Microsoft\Windows\Recent]
    08/16/2010  12:46 PM    <JUNCTION>     SendTo [C:\Users\hdadmin\AppData\Roaming\
    Microsoft\Windows\SendTo]
    08/16/2010  12:46 PM    <JUNCTION>     Start Menu [C:\Users\hdadmin\AppData\Roam
    ing\Microsoft\Windows\Start Menu]
    08/16/2010  12:46 PM    <JUNCTION>     Templates [C:\Users\hdadmin\AppData\Roami
    ng\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin\AppData\Local

    08/16/2010  12:46 PM    <JUNCTION>     Application Data [C:\Users\hdadmin\AppDat
    a\Local]
    08/16/2010  12:46 PM    <JUNCTION>     History [C:\Users\hdadmin\AppData\Local\M
    icrosoft\Windows\History]
    08/16/2010  12:46 PM    <JUNCTION>     Temporary Internet Files [C:\Users\hdadmi
    n\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\hdadmin\Documents

    08/16/2010  12:46 PM    <JUNCTION>     My Music [C:\Users\hdadmin\Music]
    08/16/2010  12:46 PM    <JUNCTION>     My Pictures [C:\Users\hdadmin\Pictures]
    08/16/2010  12:46 PM    <JUNCTION>     My Videos [C:\Users\hdadmin\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\liz

    08/16/2010  02:08 PM    <JUNCTION>     Application Data [C:\Users\liz\AppData\Ro
    aming]
    08/16/2010  02:08 PM    <JUNCTION>     Cookies [C:\Users\liz\AppData\Roaming\Mic
    rosoft\Windows\Cookies]
    08/16/2010  02:08 PM    <JUNCTION>     Local Settings [C:\Users\liz\AppData\Loca
    l]
    08/16/2010  02:08 PM    <JUNCTION>     My Documents [C:\Users\liz\Documents]
    08/16/2010  02:08 PM    <JUNCTION>     NetHood [C:\Users\liz\AppData\Roaming\Mic
    rosoft\Windows\Network Shortcuts]
    08/16/2010  02:08 PM    <JUNCTION>     PrintHood [C:\Users\liz\AppData\Roaming\M
    icrosoft\Windows\Printer Shortcuts]
    08/16/2010  02:08 PM    <JUNCTION>     Recent [C:\Users\liz\AppData\Roaming\Micr
    osoft\Windows\Recent]
    08/16/2010  02:08 PM    <JUNCTION>     SendTo [C:\Users\liz\AppData\Roaming\Micr
    osoft\Windows\SendTo]
    08/16/2010  02:08 PM    <JUNCTION>     Start Menu [C:\Users\liz\AppData\Roaming\
    Microsoft\Windows\Start Menu]
    08/16/2010  02:08 PM    <JUNCTION>     Templates [C:\Users\liz\AppData\Roaming\M
    icrosoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\liz\AppData\Local

    08/16/2010  02:08 PM    <JUNCTION>     Application Data [C:\Users\liz\AppData\Lo
    cal]
    08/16/2010  02:08 PM    <JUNCTION>     History [C:\Users\liz\AppData\Local\Micro
    soft\Windows\History]
    08/16/2010  02:08 PM    <JUNCTION>     Temporary Internet Files [C:\Users\liz\Ap
    pData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\Public\Documents

    07/13/2009  09:53 PM    <JUNCTION>     My Music [C:\Users\Public\Music]
    07/13/2009  09:53 PM    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
    07/13/2009  09:53 PM    <JUNCTION>     My Videos [C:\Users\Public\Videos]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20

    10/25/2010  02:05 PM    <JUNCTION>     Application Data [C:\Users\QBDataServiceU
    ser20\AppData\Roaming]
    10/25/2010  02:05 PM    <JUNCTION>     Cookies [C:\Users\QBDataServiceUser20\App
    Data\Roaming\Microsoft\Windows\Cookies]
    10/25/2010  02:05 PM    <JUNCTION>     Local Settings [C:\Users\QBDataServiceUse
    r20\AppData\Local]
    10/25/2010  02:05 PM    <JUNCTION>     My Documents [C:\Users\QBDataServiceUser2
    0\Documents]
    10/25/2010  02:05 PM    <JUNCTION>     NetHood [C:\Users\QBDataServiceUser20\App
    Data\Roaming\Microsoft\Windows\Network Shortcuts]
    10/25/2010  02:05 PM    <JUNCTION>     PrintHood [C:\Users\QBDataServiceUser20\A
    ppData\Roaming\Microsoft\Windows\Printer Shortcuts]
    10/25/2010  02:05 PM    <JUNCTION>     Recent [C:\Users\QBDataServiceUser20\AppD
    ata\Roaming\Microsoft\Windows\Recent]
    10/25/2010  02:05 PM    <JUNCTION>     SendTo [C:\Users\QBDataServiceUser20\AppD
    ata\Roaming\Microsoft\Windows\SendTo]
    10/25/2010  02:05 PM    <JUNCTION>     Start Menu [C:\Users\QBDataServiceUser20\
    AppData\Roaming\Microsoft\Windows\Start Menu]
    10/25/2010  02:05 PM    <JUNCTION>     Templates [C:\Users\QBDataServiceUser20\A
    ppData\Roaming\Microsoft\Windows\Templates]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20\AppData\Local

    10/25/2010  02:05 PM    <JUNCTION>     Application Data [C:\Users\QBDataServiceU
    ser20\AppData\Local]
    10/25/2010  02:05 PM    <JUNCTION>     History [C:\Users\QBDataServiceUser20\App
    Data\Local\Microsoft\Windows\History]
    10/25/2010  02:05 PM    <JUNCTION>     Temporary Internet Files [C:\Users\QBData
    ServiceUser20\AppData\Local\Microsoft\Windows\Temporary Internet Files]
                   0 File(s)              0 bytes

     Directory of C:\Users\QBDataServiceUser20\Documents

    10/25/2010  02:05 PM    <JUNCTION>     My Music [C:\Users\QBDataServiceUser20\Mu
    sic]
    10/25/2010  02:05 PM    <JUNCTION>     My Pictures [C:\Users\QBDataServiceUser20
    \Pictures]
    10/25/2010  02:05 PM    <JUNCTION>     My Videos [C:\Users\QBDataServiceUser20\V
    ideos]
                   0 File(s)              0 bytes

    C:\Windows\system32>

    Friday, August 17, 2012 7:02 PM
  • One copy is enough :)

    That all looks normal - I don't understand the earlier result with C:\Windows\ServiceProfiles\NetworkService at all!

    It looks like it's redirecting to the C:\Windows\System32 folder

    try this

    DIR C:\Windows\ServiceProfiles\NetworkService\x*.*  /s

    ICACLS C:\Windows\ServiceProfiles\NetworkService

    let's see what happens...


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 17, 2012 7:25 PM
    Moderator
  • C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\x*.* /s
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF
    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService
    C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM:(OI)(CI)(F)
                                              BUILTIN\Administrators:(OI)(CI)(F)
                                              NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(F)
                                              ATLAS-LIZ\john:(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    Saturday, August 18, 2012 6:00 PM
  • 6 whisky-cokes are not condicive to a proper answer )

    Back in the morning :!


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 18, 2012 6:57 PM
    Moderator
  • That looks normal enough.

    Try this set

    DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\t*.* /S
    DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\t*.* /S

    DIR C:\Windows\ServiceProfiles\NetworkService\AppData\t*.* /S


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 19, 2012 5:40 AM
    Moderator
  • C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\t*.* /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform

    06/18/2012  09:32 AM         7,351,234 tokens.bar
                   1 File(s)      7,351,234 bytes

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows

    07/13/2009  09:34 PM    <DIR>          Templates
                   0 File(s)              0 bytes

         Total Files Listed:
                   1 File(s)      7,351,234 bytes
                   1 Dir(s)  97,043,460,096 bytes free

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\t*.* /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform

    06/18/2012  09:32 AM         7,351,234 tokens.bar
                   1 File(s)      7,351,234 bytes

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows

    07/13/2009  09:34 PM    <DIR>          Templates
                   0 File(s)              0 bytes

         Total Files Listed:
                   1 File(s)      7,351,234 bytes
                   1 Dir(s)  97,043,460,096 bytes free

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\AppData\t*.* /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Local

    06/16/2012  03:42 PM    <DIR>          Temp
                   0 File(s)              0 bytes

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform

    06/18/2012  09:32 AM         7,351,234 tokens.bar
                   1 File(s)      7,351,234 bytes

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows

    07/13/2009  09:34 PM    <DIR>          Templates
                   0 File(s)              0 bytes

         Total Files Listed:
                   1 File(s)      7,351,234 bytes
                   2 Dir(s)  97,043,460,096 bytes free

    C:\Windows\system32>

     

     

    Sunday, August 19, 2012 6:13 PM
  • OK - the Tokens.dat file is not being rebuilt, the eway it should be.

    this usually implies a problem with the Network Services profile, or the registry entries for it.

    Lets check both as far as we can at the same time....

    ICACLS "C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform" /T DIR "C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform" /S REG QUERY HKU\S-1-5-20\Software\Microsoft

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah

    Copy and  paste the results

    Please also open Regedit and navigate to the HKEY_Users hive, and export the whole S-1-5-20 Key, save  it as a '.reg' file and upload it to your public SkyDrive, and post a link in your reply. (it should be about 440KB - waaay too long to post here!)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 19, 2012 7:12 PM
    Moderator
  • Here's the whole Hkey users folder.

    https://skydrive.live.com/redir.aspx?cid=b9e71482cde1e86b&page=self&resid=B9E71482CDE1E86B!105&parid=B9E71482CDE1E86B!103&authkey=!Arha65Lsj_JPhd8&Bpub=SDX.SkyDrive&Bsrc=Share

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>ICACLS "C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform" /T
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F
    )
                                                                                                   BUILTIN\Administrators:(I)(OI)(CI
    )(F)
                                                                                                   NT AUTHORITY\NETWORK SERVICE:(I)(
    OI)(CI)(F)
                                                                                                   ATLAS-LIZ\john:(I)(OI)(CI)(F)

    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache NT AUTHORITY\SYSTEM:(OI)(CI
    )(F)
                                                                                                         BUILTIN\Administrators:(OI)
    (CI)(F)
                                                                                                         NT SERVICE\sppsvc:(OI)(CI)(
    R,W,D)
                                                                                                         Everyone:(OI)(CI)(R)

    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.bar NT AUTHORITY\SYSTEM:(I
    )(F)
                                                                                                              BUILTIN\Administrators
    :(I)(F)
                                                                                                              NT AUTHORITY\NETWORK S
    ERVICE:(I)(F)
                                                                                                              ATLAS-LIZ\john:(I)(F)

    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat NT AUTHORITY\SYST
    EM:(I)(F)
                                                                                                                   BUILTIN\Administr
    ators:(I)(F)
                                                                                                                   NT SERVICE\sppsvc
    :(I)(R,W,D)
                                                                                                                   Everyone:(I)(R)

    Successfully processed 4 files; Failed processing 0 files

    C:\Windows\system32>DIR "C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform" /S
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform

    08/03/2012  03:18 PM    <DIR>          .
    08/03/2012  03:18 PM    <DIR>          ..
    07/13/2009  09:34 PM    <DIR>          Cache
    06/18/2012  09:32 AM         7,351,234 tokens.bar
                   1 File(s)      7,351,234 bytes

     Directory of C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache

    07/13/2009  09:34 PM    <DIR>          .
    07/13/2009  09:34 PM    <DIR>          ..
    06/18/2012  09:51 AM           104,672 cache.dat
                   1 File(s)        104,672 bytes

         Total Files Listed:
                   2 File(s)      7,455,906 bytes
                   5 Dir(s)  97,082,535,936 bytes free

    C:\Windows\system32>REG QUERY HKU\S-1-5-20\Software\MicrosoftDIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah
    ERROR: Invalid syntax.
    Type "REG QUERY /?" for usage.

    C:\Windows\system32>

    Monday, August 20, 2012 5:39 PM
  • Bother - missed the concatenation of the last two commands induced by  the forum software........

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah

    (the other one is embedded in your upload so we can ignore it here)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, August 20, 2012 6:59 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>

    Monday, August 20, 2012 8:15 PM
  • OK _ now we know where/what the root problem is  (I hope!) :)

    please run the following commands

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ar

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /as

    DIR C:\Windows\ServiceProfiles\NetworkService\NT*.*

    ICACLS C:\Windows\ServiceProfiles\NetworkService

    ATTRIB C:\Windows\ServiceProfiles\NetworkService

    and post the results - this will hopefully confirm it.

    then we need to out how to fix it :)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, August 20, 2012 8:40 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ah
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /ar
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\NT*.* /as
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\NT*.*
     Volume in drive C is OS
     Volume Serial Number is B6BB-4AEF

     Directory of C:\Windows\ServiceProfiles\NetworkService

    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService
    C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM:(OI)(CI)(F)
                                              BUILTIN\Administrators:(OI)(CI)(F)
                                              NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(F)
                                              ATLAS-LIZ\john:(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>
    C:\Windows\system32>ATTRIB C:\Windows\ServiceProfiles\NetworkService
                 C:\Windows\ServiceProfiles\NetworkService

    C:\Windows\system32>
    C:\Windows\system32>

    Monday, August 20, 2012 9:31 PM
  • OK - we need to repopulate the registry - which should then repopulate the ServiceProfiles folder.

    First copy everything (including the blank lines) in the box to Notepad, and save the file as 'HKUNWS.reg' to your desktop

    Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20] "ProfileImagePath"=hex(2):43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,\ 00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,50,00,72,00,6f,00,\ 66,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,\ 00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00 "Flags"=dword:00000000 "State"=dword:00000000


    now close all windows, and right-click on teh HKUNWS.reg file and select Merge - accept the warnings.

    You should get a 'Success' message - reboot.

    now run another MGADiag report, and post the results.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, August 20, 2012 9:45 PM
    Moderator
  • I'm still getting the calidation notice.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 50
    Cached Online Validation Code: N/A, hr = 0x80070005
    Windows Product Key: N/A, hr=0x80070005
    Windows Product Key Hash: N/A, hr=0x80070005
    Windows Product ID: 00371-OEM-8992671-00524
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Basic 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{784C8D0C-EBC9-4EBE-9943-B32AD85B6AA9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>00371-OEM-8992671-00524</PID><PIDType>2</PIDType><SID>S-1-5-21-339256910-2476184951-1403849894</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>OptiPlex 780                 </Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A13</Version><SMBIOSVersion major="2" minor="5"/><Date>20120613000000.000000+000</Date></BIOS><HWID>7B593C07018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL  </OEMID><OEMTableID>B10K   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0013-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Basic 2007</Name><Ver>12</Ver><Val>48045204A6AADC2</Val><Hash>bsAetGN6mtH9Z63DYJIwQX2wFF0=</Hash><Pid>89445-OEM-6473762-03404</Pid><PidType>4</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/></Applications></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
    Error: 0x46

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 5:10:2012 19:54
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: LAAAAAEAAAABAAIAAQABAAAAAQABAAEA6GHWEohAfEimzHiEqOMeD+6rRso=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name OEMID Value OEMTableID Value
      APIC   DELL    B10K  
      FACP   DELL    B10K  
      HPET   DELL    B10K  
      BOOT   DELL    B10K  
      MCFG   DELL    B10K  
      SSDT   DELL  st_ex
      ASF!   DELL    B10K  
      TCPA   DELL    B10K  
      ____   DELL    B10K  
      SLIC   DELL    B10K  
      SSDT   DELL  st_ex
      SSDT   DELL  st_ex
      SSDT   DELL  st_ex

    Tuesday, August 21, 2012 4:04 PM
  • The error codes have changed, though :)

    Please run

    DIR C:\Windows\ServiceProfiles\NetworkService\T*.* /s /b

    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"

    and post the results


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Tuesday, August 21, 2012 4:48 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService\T*.* /s /b
    File Not Found

    C:\Windows\system32>
    C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
        ProfileImagePath    REG_EXPAND_SZ    C:\Windows\ServiceProfiles\NetworkService
        Flags    REG_DWORD    0x0
        State    REG_DWORD    0x0


    C:\Windows\system32>

    Tuesday, August 21, 2012 6:46 PM
  • OK - it looks like permissions are screwed on the ServiceProfiles folders

    Please run the following commands.

    ATTRIB -R C:\Windows\ServiceProfiles\NetworkService /s
    ICACLS C:\Windows\ServiceProfiles\NetworkService
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform /T

    That should show us where the problem lies


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Wednesday, August 22, 2012 9:07 AM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>ATTRIB -R C:\Windows\ServiceProfiles\NetworkService /s
    The request could not be performed because of an I/O device error.
    File not found - C:\Windows\ServiceProfiles\NetworkService

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService
    C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM:(OI)(CI)(F)
                                              BUILTIN\Administrators:(OI)(CI)(F)
                                              NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(F)
                                              ATLAS-LIZ\john:(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData
    C:\Windows\ServiceProfiles\NetworkService\AppData NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
                                                      BUILTIN\Administrators:(I)(OI)(CI)(F)
                                                      NT AUTHORITY\NETWORK SERVICE:(I)(OI)(CI)(F)
                                                      ATLAS-LIZ\john:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
                                                              BUILTIN\Administrators:(I)(OI)(CI)(F)
                                                              NT AUTHORITY\NETWORK SERVICE:(I)(OI)(CI)(F)
                                                              ATLAS-LIZ\john:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
                                                                        BUILTIN\Administrators:(I)(OI)(CI)(F)
                                                                        NT AUTHORITY\NETWORK SERVICE:(I)(OI)(CI)(F)
                                                                        ATLAS-LIZ\john:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F
    )
                                                                                                   BUILTIN\Administrators:(I)(OI)(CI
    )(F)
                                                                                                   NT AUTHORITY\NETWORK SERVICE:(I)(
    OI)(CI)(F)
                                                                                                   ATLAS-LIZ\john:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>

    Wednesday, August 22, 2012 2:26 PM
  • I have NEVER seen that error message before in a command prompt window

    C:\Windows\system32>ATTRIB -R C:\Windows\ServiceProfiles\NetworkService /s
    The request could not be performed because of an I/O device error.
    File not found - C:\Windows\ServiceProfiles\NetworkService

    It would tend to indicate that there are hardware problems. I can only really suggest that you take the machine to a competent tech for evalution, after backing up all data to external media.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Wednesday, August 22, 2012 4:03 PM
    Moderator
  • I suspected as much but I was hoping to fix the validation issue and hten clone the drive.
    Wednesday, August 22, 2012 5:36 PM