Windows Installer Service could not be accessed-Network wide error-error code 1601

Recieving the following error on every machine in domain "The Windows Installer Service could not be accessed.  This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed.  Contact support for assistance."  Windows is not in safe mode.  Even reinstalled Windows installer 3.1 and follwed recommendations from article 315346;en-us;315346  Anyone have any ideas.  Thank you for any suggestions.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

This sounds like a bad update from SUS or WSUS on the clients.
Is the Remote Registry service running? I've seen problems installing software on machines where the service was stopped/disabled.
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

nnelsonAuthor Commented:
Also found that WMI is not working properly on any machines.  Also, Microsoft had us pull a client machine off the domain, run secedit to reset the security templates and then the windows installer and WMI worked on the machine-It failed again though after rejoining the machine to the domain.  So, something must be coming from the domain controler.  Any ideas?
Security settings, like the one you reset after removing the client from the domain, can be configured with Group Policy.

If the computer account is in the default Computers container in AD (and not in a custom OU that has policies) then it must be either the Default Domain Policy, a Site policy, or a custom GPO at the domain level.

It's not too difficult to reset the Default domain policy to its original state, but that could just as easily break something else.

What version of Windows is running on your DCs?

Do you have the possibility to compare your current domain policies with a new domain, with GPMC? There aren't too many settings in a default domain policy.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Can you tell us which one it was? Thanks.
nnelsonAuthor Commented:
Thanks to all for your help.  

Used group policy management consol to help identify problem.  Problem found to be in the default domain controller policy

Problems were-- Receved Access Denied messages while accessing WMI, DCOM, Windows Installer services.

This seems to be resolved via changing the "Impersonate client after authentication" setting from Default policy to Not defined.  Run gpupdate /force and restart clents.  All is now working.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.