Link to home
Start Free TrialLog in
Avatar of ekm51
ekm51Flag for United States of America

asked on

Need help enabling WMI in domain

I can't seem to enable WMI through GPO in my domain.  I've already enabled it under computer configuration\windows settings\security settings\system services\ but WMI is still not enabled.  I've disabled firewalls on clients as well.

I've attached a copy of my wmidiag log....
....1 15:01:53 (0) ** LOG file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50.LOG" created.
....2 15:01:53 (0) ** CSV file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50-STATISTICS.CSV" created.
....3 15:01:53 (0) ** TXT file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50-REPORT.TXT" created.
....4 15:01:53 (0) ** WMIDiag v2.0 started on Wednesday, February 18, 2009 at 15:01.
....5 15:01:53 (0) ** 
....6 15:01:53 (0) ** Copyright (c) Microsoft Corporation. All rights reserved - January 2007.
....7 15:01:53 (0) ** 
....8 15:01:53 (0) ** This script is not supported under any Microsoft standard support program or service.
....9 15:01:53 (0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
...10 15:01:53 (0) ** implied warranties including, without limitation, any implied warranties of merchantability
...11 15:01:53 (0) ** or of fitness for a particular purpose. The entire risk arising out of the use or performance
...12 15:01:53 (0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
...13 15:01:53 (0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
...14 15:01:53 (0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
...15 15:01:53 (0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
...16 15:01:53 (0) ** the use of or inability to use the script or documentation, even if Microsoft has been advised
...17 15:01:53 (0) ** of the possibility of such damages.
...18 15:01:53 (0) ** 
...19 15:01:53 (3)    NOECHO=True
...20 15:01:53 (3)    SILENT=False
...21 15:01:53 (3)    SMS=False
...22 15:01:53 (3)    FORCE=False
...23 15:01:53 (3)    NOWINZIP=False
...24 15:01:53 (3)    DEBUG=False
...25 15:01:53 (3)    STATISTICS=False
...26 15:01:53 (3)    RUNONCE=False
...27 15:01:53 (3)    DEPTH LEVEL=1
...28 15:01:53 (3)    LOGGINGLEVEL=0
...29 15:01:53 (3)    EVENTLOG=False
...30 15:01:53 (3)    EVENTLOGERRORS=False
...31 15:01:53 (3)    LOGWMISTATE=False
...32 15:01:53 (3)    ERRORPOPUP=False
...33 15:01:53 (3)    REQUESTALLINSTANCES=1
...34 15:01:53 (3)    WRITEINREPOSITORY=False
...35 15:01:53 (3)    CHECKCONSISTENCY=False
...36 15:01:53 (3)    SHOWMOFERRORS=False
...37 15:01:53 (3)    SHOWHIGHPRIVPROVIDERS=False
...38 15:01:53 (3)    CORRELATECLASSANDPROVIDER=False
...39 15:01:53 (3)    STRICT=False
...40 15:01:53 (3)    OLDESTLOGHISTORY=0
...41 15:01:53 (3)    OLDESTEVENTLOGHISTORY=20
...42 15:01:53 (3)    BASENAMESPACE=Root
...43 15:01:53 (0) ** Verifying last run of WMIDiag.
...44 15:01:53 (4)      Reading registry (REG_SZ) 'HKLM\Software\Microsoft\WMIDiag\LastRun'.
...45 15:01:53 (0) ** WMIDiag last run is 2/18/2009 2:51:36 PM.
...46 15:01:53 (2) !! WARNING: WMIDiag already started today.
...47 15:01:53 (0) ** Logging Run-time environment information.
...48 15:01:53 (3)    StartMenu=C:\DOCUMENTS AND SETTINGS\JONATHAN\START MENU\
...49 15:01:53 (3)    Desktop=\\WUYEE.ORG\GLOBAL\USER DIRECTORIES\JONATHAN\DESKTOP\
...50 15:01:53 (3)    Programs=C:\DOCUMENTS AND SETTINGS\JONATHAN\START MENU\PROGRAMS\
...51 15:01:53 (3)    SystemDrive=C:\
...52 15:01:53 (3)    SystemRoot=C:\WINDOWS\
...53 15:01:53 (3)    Path=C:\PROGRAM FILES\SUPPORT TOOLS\;C:\PROGRAM FILES\WINDOWS RESOURCE KITS\TOOLS\;C:\WINDOWS\SYSTEM32;C:\WINDOWS;C:\WINDOWS\SYSTEM32\WBEM;C:\PROGRAM FILES\IDM COMPUTER SOLUTIONS\ULTRAEDIT-32;C:\PROGRAM FILES\COMMON FILES\ADOBE\AGL;C:\PROGRAM FILES\QUICKTIME\QTSYSTEM\;C:\PROGRAM FILES\EXECUTIVE SOFTWARE\UNDELETE\;C:\PROGRAM FILES\MICROSOFT SQL SERVER\90\TOOLS\BINN\;C:\PROGRAM FILES\COMMON FILES\ROXIO SHARED\DLLSHARED\;C:\PROGRAM FILES\COMMON FILES\ROXIO SHARED\9.0\DLLSHARED\;C:\PROGRAM FILES\MKVTOOLNIX\
...54 15:01:53 (3)    UserTemp=C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\
...55 15:01:53 (3)    SystemTemp=C:\WINDOWS\TEMP\
...56 15:01:53 (3)    System32=C:\WINDOWS\SYSTEM32\
...57 15:01:53 (3)    System=C:\WINDOWS\SYSTEM\
...58 15:01:53 (3)    Wbem=C:\WINDOWS\SYSTEM32\WBEM\
...59 15:01:53 (3)    WbemLogs=C:\WINDOWS\SYSTEM32\WBEM\LOGS\
...60 15:01:53 (3)    CurrentDirectory=C:\WMIDIAG
...61 15:01:53 (3)    AllUsersStartMenu=C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\
...62 15:01:53 (3)    AllUsersDesktop=C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\
...63 15:01:53 (3)    AllUsersPrograms=C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\
...64 15:01:53 (3)    ScriptName=WMIDIAG.VBS
...65 15:01:53 (3)    ScriptFullName=C:\WMIDIAG\WMIDIAG.VBS
...66 15:01:53 (3)    ScriptingName=WINDOWS SCRIPT HOST
...67 15:01:53 (3)    EngineFullName=C:\WINDOWS\SYSTEM32\WSCRIPT.EXE
...68 15:01:53 (3)    CommandLine=C:\WMIDIAG\WMIDIAG.VBS 
...69 15:01:53 (3)    EnginePath=C:\WINDOWS\SYSTEM32
...70 15:01:53 (3)    EngineVersion=5.7
...71 15:01:53 (3)    DomainName=WUYEE
...72 15:01:53 (3)    UserName=JONATHAN
...73 15:01:53 (3)    UserDNSDomain=WUYEE.ORG
...74 15:01:53 (3)    LogonServerName=SCARESDC
...75 15:01:53 (3)    LocalComputerName=WADXJONM
...76 15:01:53 (3)    ProductName=Microsoft Windows XP
...77 15:01:53 (3)    Locale=
...78 15:01:53 (3)    IsServerOS=False
...79 15:01:53 (3)    Is64=False
...80 15:01:53 (3)    IsWow64=False
...81 15:01:53 (3)    ProcessorArchitecture=32-bit
...82 15:01:53 (3)    ProcessorIdentifier=x86 Family 15 Model 4 Stepping 9, GenuineIntel
...83 15:01:53 (3)    NTVersion=5.1
...84 15:01:53 (3)    NTBuild=2600
...85 15:01:53 (3)    NTServicePack=Service Pack 3
...86 15:01:53 (3)    FullName=Windows XP - No service pack - 32-bit
...87 15:01:53 (3)    ShortName=XP___.CLI.RTM.32
...88 15:01:53 (3)    SMSAgent=
...89 15:01:53 (3)    WinZIP=C:\PROGRA~1\WINZIP\winzip32.exe
...90 15:01:53 (0) ** Initializing WMI System Information.
...91 15:01:53 (0) ** Windows XP - No service pack - 32-bit (XP___.CLI.RTM.32).
...92 15:01:53 (4)      Reading registry (REG_BINARY) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Security\Security'.
...93 15:01:53 (0) ** Verifying computer environment.
...94 15:01:53 (3)    The SYSTEM32 folder IS in the PATH.
...95 15:01:53 (3)    The WBEM folder IS in the PATH.
...96 15:01:53 (3)    The PATH environment variable has a maximum length of 512 characters. Current PATH length is 503 characters.
...97 15:01:53 (4)      Reading registry (REG_DWORD) 'HKCU\Software\Microsoft\Windows Script Host\Settings\Timeout'.
...98 15:01:53 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings\Timeout'.
...99 15:01:53 (0) ** Verifying specific files presence.
..100 15:01:53 (3)    File 'C:\WINDOWS\WMIPRVSE.EXE' is MISSING, which is FINE.
..101 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WMIPRVSE.EXE' is MISSING, which is FINE.
..102 15:01:53 (3)    File 'C:\WINDOWS\WINMGNT.EXE' is MISSING, which is FINE.
..103 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WINMGNT.EXE' is MISSING, which is FINE.
..104 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WBEM\WINMGNT.EXE' is MISSING, which is FINE.
..105 15:01:53 (3)    File 'C:\WINDOWS\WMIPRV.EXE' is MISSING, which is FINE.
..106 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WMIPRV.EXE' is MISSING, which is FINE.
..107 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WBEM\WMIPRV.EXE' is MISSING, which is FINE.
..108 15:01:53 (3)    File 'C:\WINDOWS\WMIINF.EXE' is MISSING, which is FINE.
..109 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WMIINF.EXE' is MISSING, which is FINE.
..110 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WBEM\WMIINF.EXE' is MISSING, which is FINE.
..111 15:01:53 (3)    File 'C:\WINDOWS\WMINFO.EXE' is MISSING, which is FINE.
..112 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WMINFO.EXE' is MISSING, which is FINE.
..113 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WBEM\WMINFO.EXE' is MISSING, which is FINE.
..114 15:01:53 (3)    File 'C:\WINDOWS\WMIPRVSW.EXE' is MISSING, which is FINE.
..115 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WMIPRVSW.EXE' is MISSING, which is FINE.
..116 15:01:53 (3)    File 'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSW.EXE' is MISSING, which is FINE.
..117 15:01:53 (0) ** Verifying WMI System files presence at 'C:\WINDOWS\SYSTEM32\WBEM\'.
..118 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SMI2SMIR.EXE' is MISSING or is access DENIED but it is an OPTIONAL component.
..119 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE'.
..120 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MOFCOMP.EXE'.
..121 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SCRCONS.EXE'.
..122 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE'.
..123 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMTEST.EXE'.
..124 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WINMGMT.EXE'.
..125 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIADAP.EXE'.
..126 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE'.
..127 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.DLL'.
..128 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CMDEVTGPROV.DLL', is present but it is an OPTIONAL component.
..129 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.DLL'.
..130 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\ESSCLI.DLL'.
..131 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\EVNTRPRV.DLL'.
..132 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL'.
..133 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\FRAMEDYN.DLL'.
..134 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\FWDPROV.DLL'.
..135 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\KRNLPROV.DLL'.
..136 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MOFD.DLL'.
..137 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.DLL'.
..138 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NTEVT.DLL'.
..139 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\POLICMAN.DLL', is present but it is an OPTIONAL component.
..140 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\PROVTHRD.DLL'.
..141 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\REPDRVFS.DLL'.
..142 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.DLL'.
..143 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL'.
..144 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.DLL'.
..145 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.DLL'.
..146 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.DLL'.
..147 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\VIEWPROV.DLL'.
..148 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMADS.DLL'.
..149 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMADS.TLB'.
..150 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCNTL.DLL'.
..151 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCOMN.DLL'.
..152 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.DLL'.
..153 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL'.
..154 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL'.
..155 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.TLB'.
..156 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMESS.DLL'.
..157 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMPERF.DLL'.
..158 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL'.
..159 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL'.
..160 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WBEMUPGD.DLL'.
..161 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WINMGMTR.DLL'.
..162 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIAPRES.DLL'.
..163 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIAPRPL.DLL'.
..164 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMICOOKR.DLL'.
..165 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIDCPRV.DLL'.
..166 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL'.
..167 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.DLL'.
..168 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPDSKQ.DLL'.
..169 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPICMP.DLL'.
..170 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPIPRT.DLL'.
..171 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.DLL'.
..172 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPROV.DLL'.
..173 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSD.DLL'.
..174 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPSESS.DLL'.
..175 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMISVC.DLL'.
..176 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.DLL'.
..177 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIUTILS.DLL'.
..178 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MSIPROV.DLL'.
..179 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\XML\WMI2XML.DLL'.
..180 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\XML\CIM20.DTD'.
..181 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\XML\WMI20.DTD'.
..182 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\XSL-MAPPINGS.XML', is present but it is an OPTIONAL component.
..183 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CSV.XSL', is present but it is an OPTIONAL component.
..184 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\HFORM.XSL', is present but it is an OPTIONAL component.
..185 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\HTABLE-SORTBY.XSL', is present but it is an OPTIONAL component.
..186 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\HTABLE.XSL', is present but it is an OPTIONAL component.
..187 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MOF.XSL', is present but it is an OPTIONAL component.
..188 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\RAWXML.XSL', is present but it is an OPTIONAL component.
..189 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TEXTTABLE.XSL', is present but it is an OPTIONAL component.
..190 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TEXTTABLEWSYS.XSL', is present but it is an OPTIONAL component.
..191 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TEXTVALUELIST.XSL', is present but it is an OPTIONAL component.
..192 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMICLIMOFFORMAT.XSL', is present but it is an OPTIONAL component.
..193 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMICLITABLEFORMAT.XSL', is present but it is an OPTIONAL component.
..194 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMICLITABLEFORMATNOSYS.XSL', is present but it is an OPTIONAL component.
..195 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMICLIVALUEFORMAT.XSL', is present but it is an OPTIONAL component.
..196 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\XML.XSL', is present but it is an OPTIONAL component.
..197 15:01:53 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIC.EXE', is present but it is an OPTIONAL component.
..198 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SNMPCL.DLL' is MISSING or is access DENIED but it is an OPTIONAL component.
..199 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SNMPINCL.DLL' is MISSING or is access DENIED but it is an OPTIONAL component.
..200 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL' is MISSING or is access DENIED but it is an OPTIONAL component.
..201 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SNMPSTUP.DLL' is MISSING or is access DENIED but it is an OPTIONAL component.
..202 15:01:53 (2) !! WARNING: WMI System file 'C:\WINDOWS\SYSTEM32\WBEM\SNMPTHRD.DLL' is MISSING or is access DENIED but it is an OPTIONAL component.
..203 15:01:53 (0) ** Verifying WMI Repository files presence.
..204 15:01:53 (3)    'C:\WINDOWS\SYSTEM32\WBEM\Repository\FS' has a size of 9410268 bytes.
..205 15:01:53 (3)    'INDEX.BTR' has a size of 1835008 bytes (Created: 5/31/2006 9:08:10 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
..206 15:01:53 (3)    'INDEX.MAP' has a size of 940 bytes (Created: 5/31/2006 9:08:26 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
..207 15:01:53 (3)    'OBJECTS.DATA' has a size of 7561216 bytes (Created: 5/31/2006 9:08:10 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
..208 15:01:53 (3)    'OBJECTS.MAP' has a size of 3740 bytes (Created: 5/31/2006 9:08:25 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
..209 15:01:53 (0) ** Verifying additional binaries in WBEM folder.
..210 15:01:56 (0) ** Verifying Auto-Recovery MOF files presence.
..211 15:01:56 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Autorecover MOFs'.
..212 15:01:56 (0) ** Verifying MOF files in WBEM folder.
..213 15:01:57 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CLIEGALIASES.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..214 15:01:57 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CLIEGALIASES.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..215 15:01:57 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\EXMGMT.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..216 15:01:57 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\EXWMI.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..217 15:01:57 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FCONPROV.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..218 15:01:57 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FCONPROV.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..219 15:01:58 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\MSGTRK.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..220 15:01:58 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..221 15:01:58 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..222 15:01:58 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\OUTLOOK_01C6AB4D63F968DC.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..223 15:01:58 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\OUTLOOK_01C6AB5B841D66CC.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..224 15:01:58 (2) !! WARNING: 'C:\WINDOWS\SYSTEM32\WBEM\OUTLOOK_01C8D2390250F9C9.MOF' does exist but it is NOT LISTED in the 'Autorecover MOFs' registry key.
..225 15:01:58 (3)    'C:\WINDOWS\SYSTEM32\WBEM\SCRCONS.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..226 15:01:58 (3)    'C:\WINDOWS\SYSTEM32\WBEM\SCRCONS.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..227 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..228 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..229 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..230 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..231 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..232 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..233 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..234 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..235 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.MFL' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..236 15:01:59 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.MOF' does exist and is NOT LISTED BY DEFAULT in the 'Autorecover MOFs' registry key.
..237 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.MOF'.
..238 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.MFL'.
..239 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SYSTEM.MOF'.
..240 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.MOF'.
..241 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.MFL'.
..242 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\REGEVENT.MOF'.
..243 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\REGEVENT.MFL'.
..244 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NTEVT.MOF'.
..245 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NTEVT.MFL'.
..246 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SECRCW32.MOF'.
..247 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SECRCW32.MFL'.
..248 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.MOF'.
..249 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.MFL'.
..250 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MSI.MOF'.
..251 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MSI.MFL'.
..252 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\POLICMAN.MOF'.
..253 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\POLICMAN.MFL'.
..254 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SUBSCRPT.MOF'.
..255 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMI.MOF'.
..256 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMI.MFL'.
..257 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SCM.MOF'.
..258 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\FEVPROV.MOF'.
..259 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\FEVPROV.MFL'.
..260 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.MOF'.
..261 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.MFL'.
..262 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPDSKQ.MOF'.
..263 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPDSKQ.MFL'.
..264 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPICMP.MOF'.
..265 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPICMP.MFL'.
..266 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPIPRT.MOF'.
..267 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPIPRT.MFL'.
..268 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.MOF'.
..269 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.MFL'.
..270 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPSESS.MOF'.
..271 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WMIPSESS.MFL'.
..272 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\KRNLPROV.MOF'.
..273 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\KRNLPROV.MFL'.
..274 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CLI.MOF'.
..275 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TSCFGWMI.MOF'.
..276 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\TSCFGWMI.MFL'.
..277 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\LICWMI.MOF'.
..278 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\LICWMI.MFL'.
..279 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\EVNTRPRV.MOF'.
..280 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\HNETCFG.MOF'.
..281 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SR.MOF'.
..282 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\CMDEVTGPROV.MOF'.
..283 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\DGNET.MOF'.
..284 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WHQLPROV.MOF'.
..285 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\IEINFO5.MOF'.
..286 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\RSOP.MOF'.
..287 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\RSOP.MFL'.
..288 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\SCERSOP.MOF'.
..289 15:02:00 (1) !! ERROR: Unable to access or find file 'C:\4BC37DABAD59047BDAF228AE\I386\LICWMI.MOF' listed in 'Autorecover MOFs'.
..290 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\WSCENTER.MOF'.
..291 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\MOF\GOOD\MSIOFF10.MOF'.
..292 15:02:00 (3)    Found 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET.MOF'.
..293 15:02:00 (3)    Found 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\ASPNET.MOF'.
..294 15:02:00 (3)    Found 'C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\OINFOP11.MOF'.
..295 15:02:00 (3)    Found 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.0.3705\NETFXCFGPROV.MFL'.
..296 15:02:00 (3)    Found 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.0.3705\NETFXCFGPROVM.MOF'.
..297 15:02:00 (3)    Found 'C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\OINFOP11.MOF'.
..298 15:02:00 (1) !! ERROR: Unable to access or find file 'C:\WINDOWS\SYSTEM32\WBEM\IISWMI.MOF' listed in 'Autorecover MOFs'.
..299 15:02:00 (3)    Found 'C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\OINFOP12.MOF'.
..300 15:02:00 (3)    Found 'C:\PROGRA~1\COMMON~1\MICROS~1\MSINFO\OINFOP12.MOF'.
..301 15:02:00 (3)    Found 'C:\PROGRAM FILES\MICROSOFT SQL SERVER\90\SHARED\SQLMGMPROVIDERXPSP2UP.MOF'.
..302 15:02:00 (3)    Found 'C:\PROGRAM FILES\MICROSOFT SQL SERVER\90\SHARED\RESOURCES\1033\SQLMGMPROVIDER.MFL'.
..303 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NAPCLIENTPROV.MOF'.
..304 15:02:00 (3)    Found 'C:\WINDOWS\SYSTEM32\WBEM\NAPCLIENTSCHEMA.MOF'.
..305 15:02:00 (0) ** Verifying '#PRAGMA AUTORECOVER' statement in MOF files.
..306 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\EXMGMT.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..307 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\EXWMI.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..308 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\FCONPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..309 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\FCONPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..310 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\MSGTRK.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..311 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..312 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..313 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..314 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..315 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..316 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..317 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\SCRCONS.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..318 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\SCRCONS.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..319 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..320 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..321 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..322 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..323 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..324 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..325 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..326 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..327 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..328 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..329 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..330 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..331 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..332 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while NOT included in the AUTORECOVERY LIST, which could be FINE!
..333 15:02:03 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..334 15:02:03 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..335 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..336 15:02:03 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement.
..337 15:02:09 (2) !! WARNING: MOF file 'C:\WINDOWS\SYSTEM32\WBEM\SCM.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while included in the AUTORECOVERY LIST!
..338 15:02:09 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..339 15:02:09 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..340 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\FEVPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..341 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\FEVPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..342 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..343 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..344 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\EVNTRPRV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..345 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\CMDEVTGPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..346 15:02:10 (3)    MOF file 'C:\WINDOWS\SYSTEM32\WBEM\WHQLPROV.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it is included in the AUTORECOVERY LIST, which is FINE!
..347 15:02:11 (2) !! WARNING: MOF file 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.0.3705\NETFXCFGPROV.MFL' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while included in the AUTORECOVERY LIST!
..348 15:02:11 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..349 15:02:11 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..350 15:02:11 (2) !! WARNING: MOF file 'C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.0.3705\NETFXCFGPROVM.MOF' does NOT contain the '#PRAGMA AUTORECOVER' statement but it contains DELETE MOF statements while included in the AUTORECOVERY LIST!
..351 15:02:11 (3)    => Only the MOF statements and logic will determine if the MOF is a true UNINSTALL MOF.
..352 15:02:11 (3)       A true UNINSTALL MOF should NOT contain the '#PRAGMA AUTORECOVER' statement and should NOT be included in the AUTORECOVER LIST.
..353 15:02:12 (0) ** Verifying DCOM configuration.
..354 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM'.
..355 15:02:12 (3)    DCOM is ENABLED.
..356 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Microsoft\Ole\LegacyAuthenticationLevel'.
..357 15:02:12 (3)    DCOM IS set at the CONNECT authentication level.
..358 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Microsoft\Ole\LegacyImpersonationLevel'.
..359 15:02:12 (2) !! WARNING: DCOM is NOT set at the IDENTIFY impersonation level.
..360 15:02:12 (0) ** Verifying WMI DCOM component registrations.
..361 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\'.
..362 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..363 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel'.
..364 15:02:12 (3)    WMI registry key (REG_DWORD) 'AuthenticationLevel' is missing, which is FINE.
..365 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService'.
..366 15:02:12 (3)    WMI registry key (REG_SZ) 'LocalService' is correct.
..367 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\'.
..368 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..369 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppID'.
..370 15:02:12 (3)    WMI registry key (REG_SZ) 'AppID' is correct.
..371 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService'.
..372 15:02:12 (3)    WMI registry key (REG_SZ) 'LocalService' is correct.
..373 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\AppID\winmgmt\AppID'.
..374 15:02:12 (3)    WMI registry key (REG_SZ) 'AppID' is correct.
..375 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\'.
..376 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..377 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel'.
..378 15:02:12 (3)    WMI registry key (REG_DWORD) 'AuthenticationLevel' is missing, which is FINE.
..379 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\'.
..380 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..381 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID'.
..382 15:02:12 (3)    WMI registry key (REG_SZ) 'AppID' is correct.
..383 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Classes\AppID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\AuthenticationLevel'.
..384 15:02:12 (3)    WMI registry key (REG_DWORD) 'AuthenticationLevel' is missing, which is FINE.
..385 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\'.
..386 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..387 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Classes\AppID\{266C72E7-62E8-11D1-AD89-00C04FD8FDFF}\AuthenticationLevel'.
..388 15:02:12 (3)    WMI registry key (REG_DWORD) 'AuthenticationLevel' is missing, which is FINE.
..389 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{266C72E7-62E8-11D1-AD89-00C04FD8FDFF}\'.
..390 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..391 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\'.
..392 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..393 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\AppID'.
..394 15:02:12 (3)    WMI registry key (REG_SZ) 'AppID' is correct.
..395 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\LocalService'.
..396 15:02:12 (3)    WMI registry key (REG_SZ) 'LocalService' is correct.
..397 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\WINMGMTS\'.
..398 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..399 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\WINMGMTS\CLSID\'.
..400 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..401 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\WINMGMTS\CurVer\'.
..402 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..403 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\WINMGMTS.1\'.
..404 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..405 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\WINMGMTS.1\CLSID\'.
..406 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..407 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\ProgID\'.
..408 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..409 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Classes\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\VersionIndependentProgID\'.
..410 15:02:12 (3)    WMI registry key (REG_SZ) '(Default)' is correct.
..411 15:02:12 (3)    'Windows Management Instrumentation' DCOM application registered correctly ({8BC3F05E-D86B-11D0-A075-00C04FB68820}).
..412 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\'.
..413 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE' registered correctly (\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32).
..414 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\LocalServer32\'.
..415 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE' registered correctly (\CLSID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\LocalServer32).
..416 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{3DD82D10-E6F1-11D2-B139-00105A1F77A1}\InProcServer32\'.
..417 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.DLL' registered correctly (\CLSID\{3DD82D10-E6F1-11D2-B139-00105A1F77A1}\InProcServer32).
..418 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D31B6A3F-9350-40DE-A3FC-A7EDEB9B7C63}\InProcServer32\'.
..419 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.DLL' registered correctly (\CLSID\{D31B6A3F-9350-40DE-A3FC-A7EDEB9B7C63}\InProcServer32).
..420 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InProcServer32\'.
..421 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CIMWIN32.DLL' registered correctly (\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InProcServer32).
..422 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{797EF3B3-127B-4283-8096-1E8084BF67A6}\InProcServer32\'.
..423 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\CMDEVTGPROV.DLL' registered correctly (\CLSID\{797EF3B3-127B-4283-8096-1E8084BF67A6}\InProcServer32).
..424 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{1EF94880-01A8-11D2-A90B-00AA00BF3363}\InProcServer32\'.
..425 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.DLL' registered correctly (\CLSID\{1EF94880-01A8-11D2-A90B-00AA00BF3363}\InProcServer32).
..426 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{33831ED4-42B8-11D2-93AD-00805F853771}\InProcServer32\'.
..427 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.DLL' registered correctly (\CLSID\{33831ED4-42B8-11D2-93AD-00805F853771}\InProcServer32).
..428 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{AA527A40-4D9A-11D2-93AD-00805F853771}\InProcServer32\'.
..429 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\DSPROV.DLL' registered correctly (\CLSID\{AA527A40-4D9A-11D2-93AD-00805F853771}\InProcServer32).
..430 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6C19BE35-7500-11D1-AD94-00C04FD8FDFF}\InProcServer32\'.
..431 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\ESSCLI.DLL' registered correctly (\CLSID\{6C19BE35-7500-11D1-AD94-00C04FD8FDFF}\InProcServer32).
..432 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{DC923725-0FDD-45E1-AE74-EA09182E739B}\InProcServer32\'.
..433 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\ESSCLI.DLL' registered correctly (\CLSID\{DC923725-0FDD-45E1-AE74-EA09182E739B}\InProcServer32).
..434 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{9A5DD473-D410-11D1-B829-00C04F94C7C3}\InProcServer32\'.
..435 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\EVNTRPRV.DLL' registered correctly (\CLSID\{9A5DD473-D410-11D1-B829-00C04F94C7C3}\InProcServer32).
..436 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F95E1664-7979-44F2-A040-496E7F500043}\InProcServer32\'.
..437 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\EVNTRPRV.DLL' registered correctly (\CLSID\{F95E1664-7979-44F2-A040-496E7F500043}\InProcServer32).
..438 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32\'.
..439 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32).
..440 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InProcServer32\'.
..441 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InProcServer32).
..442 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{29B5828C-CAB9-11D2-B35C-00105A1F8177}\InProcServer32\'.
..443 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{29B5828C-CAB9-11D2-B35C-00105A1F8177}\InProcServer32).
..444 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InProcServer32\'.
..445 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InProcServer32).
..446 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32\'.
..447 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32).
..448 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcServer32\'.
..449 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcServer32).
..450 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7016F8FA-CCDA-11D2-B35C-00105A1F8177}\InProcServer32\'.
..451 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{7016F8FA-CCDA-11D2-B35C-00105A1F8177}\InProcServer32).
..452 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InProcServer32\'.
..453 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InProcServer32).
..454 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{78103FB7-AED7-4066-8BCD-30BB27B02331}\InProcServer32\'.
..455 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{78103FB7-AED7-4066-8BCD-30BB27B02331}\InProcServer32).
..456 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7A0227F6-7108-11D1-AD90-00C04FD8FDFF}\InProcServer32\'.
..457 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{7A0227F6-7108-11D1-AD90-00C04FD8FDFF}\InProcServer32).
..458 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{8D1C559D-84F0-4BB3-A7D5-56A7435A9BA6}\InProcServer32\'.
..459 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{8D1C559D-84F0-4BB3-A7D5-56A7435A9BA6}\InProcServer32).
..460 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{9A653086-174F-11D2-B5F9-00104B703EFD}\InProcServer32\'.
..461 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{9A653086-174F-11D2-B5F9-00104B703EFD}\InProcServer32).
..462 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C71566F2-561E-11D1-AD87-00C04FD8FDFF}\InProcServer32\'.
..463 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{C71566F2-561E-11D1-AD87-00C04FD8FDFF}\InProcServer32).
..464 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CC9072AB-C000-49D8-A5AA-00266C8DBB9B}\InProcServer32\'.
..465 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{CC9072AB-C000-49D8-A5AA-00266C8DBB9B}\InProcServer32).
..466 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CD1ABFC8-6C5E-4A8D-B90B-2A3B153B886D}\InProcServer32\'.
..467 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{CD1ABFC8-6C5E-4A8D-B90B-2A3B153B886D}\InProcServer32).
..468 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InProcServer32\'.
..469 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InProcServer32).
..470 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D71EE747-F455-4804-9DF6-2ED81025F2C1}\InProcServer32\'.
..471 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{D71EE747-F455-4804-9DF6-2ED81025F2C1}\InProcServer32).
..472 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{DCF33DF4-B510-439F-832A-16B6B514F2A7}\InProcServer32\'.
..473 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{DCF33DF4-B510-439F-832A-16B6B514F2A7}\InProcServer32).
..474 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{ED51D12E-511F-4999-8DCD-C2BAC91BE86E}\InProcServer32\'.
..475 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL' registered correctly (\CLSID\{ED51D12E-511F-4999-8DCD-C2BAC91BE86E}\InProcServer32).
..476 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7879E40D-9FB5-450A-8A6D-00C89F349FCE}\InProcServer32\'.
..477 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FWDPROV.DLL' registered correctly (\CLSID\{7879E40D-9FB5-450A-8A6D-00C89F349FCE}\InProcServer32).
..478 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{AD1B46E8-0AAC-401B-A3B8-FCDCF8186F55}\InProcServer32\'.
..479 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\FWDPROV.DLL' registered correctly (\CLSID\{AD1B46E8-0AAC-401B-A3B8-FCDCF8186F55}\InProcServer32).
..480 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{9877D8A7-FDA1-43F9-AEEA-F90747EA66B0}\InProcServer32\'.
..481 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\KRNLPROV.DLL' registered correctly (\CLSID\{9877D8A7-FDA1-43F9-AEEA-F90747EA66B0}\InProcServer32).
..482 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\TYPELIB\{6B100E1A-1385-4D1F-A02E-6E705A76BB6C}\1.0\'.
..483 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\KRNLPROV.DLL' registered correctly (\TYPELIB\{6B100E1A-1385-4D1F-A02E-6E705A76BB6C}\1.0).
..484 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6DAF9757-2E37-11D2-AEC9-00C04FB68820}\InProcServer32\'.
..485 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\MOFD.DLL' registered correctly (\CLSID\{6DAF9757-2E37-11D2-AEC9-00C04FB68820}\InProcServer32).
..486 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C10B4771-4DA0-11D2-A2F5-00C04F86FB7D}\InProcServer32\'.
..487 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\MOFD.DLL' registered correctly (\CLSID\{C10B4771-4DA0-11D2-A2F5-00C04F86FB7D}\InProcServer32).
..488 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{29F06F0C-FB7F-44A5-83CD-D41705D5C525}\InProcServer32\'.
..489 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.DLL' registered correctly (\CLSID\{29F06F0C-FB7F-44A5-83CD-D41705D5C525}\InProcServer32).
..490 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\TYPELIB\{5F099F16-6A6E-4BBC-8BD8-98F3221D58C4}\1.0\'.
..491 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NCPROV.DLL' registered correctly (\TYPELIB\{5F099F16-6A6E-4BBC-8BD8-98F3221D58C4}\1.0).
..492 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F55C5B4C-517D-11D1-AB57-00C04FD9159E}\InProcServer32\'.
..493 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NTEVT.DLL' registered correctly (\CLSID\{F55C5B4C-517D-11D1-AB57-00C04FD9159E}\InProcServer32).
..494 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{FD4F53E0-65DC-11D1-AB64-00C04FD9159E}\InProcServer32\'.
..495 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\NTEVT.DLL' registered correctly (\CLSID\{FD4F53E0-65DC-11D1-AB64-00C04FD9159E}\InProcServer32).
..496 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{69D76D1B-B12E-4913-8F48-671B90195A2B}\InProcServer32\'.
..497 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\POLICMAN.DLL' registered correctly (\CLSID\{69D76D1B-B12E-4913-8F48-671B90195A2B}\InProcServer32).
..498 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{AAEAE72F-0328-4763-8ECB-23422EDE2DB5}\InProcServer32\'.
..499 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\POLICMAN.DLL' registered correctly (\CLSID\{AAEAE72F-0328-4763-8ECB-23422EDE2DB5}\InProcServer32).
..500 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7998DC37-D3FE-487C-A60A-7701FCC70CC6}\InProcServer32\'.
..501 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\REPDRVFS.DLL' registered correctly (\CLSID\{7998DC37-D3FE-487C-A60A-7701FCC70CC6}\InProcServer32).
..502 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C7A3A54B-0250-11D3-9CD1-00105A1F4801}\InProcServer32\'.
..503 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.DLL' registered correctly (\CLSID\{C7A3A54B-0250-11D3-9CD1-00105A1F4801}\InProcServer32).
..504 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{72967901-68EC-11D0-B729-00AA0062CBB7}\InProcServer32\'.
..505 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL' registered correctly (\CLSID\{72967901-68EC-11D0-B729-00AA0062CBB7}\InProcServer32).
..506 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{72967903-68EC-11D0-B729-00AA0062CBB7}\InProcServer32\'.
..507 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL' registered correctly (\CLSID\{72967903-68EC-11D0-B729-00AA0062CBB7}\InProcServer32).
..508 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F00B4404-F8F1-11CE-A5B6-00AA00680C3F}\InProcServer32\'.
..509 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL' registered correctly (\CLSID\{F00B4404-F8F1-11CE-A5B6-00AA00680C3F}\InProcServer32).
..510 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{FA77A74E-E109-11D0-AD6E-00C04FD8FDFF}\InProcServer32\'.
..511 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL' registered correctly (\CLSID\{FA77A74E-E109-11D0-AD6E-00C04FD8FDFF}\InProcServer32).
..512 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{FE9AF5C0-D3B6-11CE-A5B6-00AA00680C3F}\InProcServer32\'.
..513 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\STDPROV.DLL' registered correctly (\CLSID\{FE9AF5C0-D3B6-11CE-A5B6-00AA00680C3F}\InProcServer32).
..514 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C486ABD2-27F6-11D3-865E-00C04F63049B}\InProcServer32\'.
..515 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TMPLPROV.DLL' registered correctly (\CLSID\{C486ABD2-27F6-11D3-865E-00C04F63049B}\InProcServer32).
..516 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{405595AA-1E14-11D3-B33D-00105A1F4AAF}\InProcServer32\'.
..517 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.DLL' registered correctly (\CLSID\{405595AA-1E14-11D3-B33D-00105A1F4AAF}\InProcServer32).
..518 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{405595AB-1E14-11D3-B33D-00105A1F4AAF}\InProcServer32\'.
..519 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\TRNSPROV.DLL' registered correctly (\CLSID\{405595AB-1E14-11D3-B33D-00105A1F4AAF}\InProcServer32).
..520 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{74E3B84C-C7BE-4E0A-9BD2-853CA72CD435}\InProcServer32\'.
..521 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.DLL' registered correctly (\CLSID\{74E3B84C-C7BE-4E0A-9BD2-853CA72CD435}\InProcServer32).
..522 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{A3A16907-227B-11D3-865D-00C04F63049B}\InProcServer32\'.
..523 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\UPDPROV.DLL' registered correctly (\CLSID\{A3A16907-227B-11D3-865D-00C04F63049B}\InProcServer32).
..524 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{AA70DDF4-E11C-11D1-ABB0-00C04FD9159E}\InProcServer32\'.
..525 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\VIEWPROV.DLL' registered correctly (\CLSID\{AA70DDF4-E11C-11D1-ABB0-00C04FD9159E}\InProcServer32).
..526 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F0975AFE-5C7F-11D2-8B74-00104B2AFB41}\InProcServer32\'.
..527 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMADS.DLL' registered correctly (\CLSID\{F0975AFE-5C7F-11D2-8B74-00104B2AFB41}\InProcServer32).
..528 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{5C659257-E236-11D2-8899-00104B2AFB46}\InProcServer32\'.
..529 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCNTL.DLL' registered correctly (\CLSID\{5C659257-E236-11D2-8899-00104B2AFB46}\InProcServer32).
..530 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{5C659258-E236-11D2-8899-00104B2AFB46}\InProcServer32\'.
..531 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCNTL.DLL' registered correctly (\CLSID\{5C659258-E236-11D2-8899-00104B2AFB46}\InProcServer32).
..532 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72D4-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..533 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCOMN.DLL' registered correctly (\CLSID\{266C72D4-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..534 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72E5-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..535 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCOMN.DLL' registered correctly (\CLSID\{266C72E5-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..536 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72E6-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..537 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCOMN.DLL' registered correctly (\CLSID\{266C72E6-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..538 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72D4-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..539 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.DLL' registered correctly (\CLSID\{266C72D4-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..540 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72E5-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..541 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.DLL' registered correctly (\CLSID\{266C72E5-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..542 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{266C72E6-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32\'.
..543 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCONS.DLL' registered correctly (\CLSID\{266C72E6-62E8-11D1-AD89-00C04FD8FDFF}\InProcServer32).
..544 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{1860E246-E924-4F73-B2C5-93E0577E3AA1}\InProcServer32\'.
..545 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{1860E246-E924-4F73-B2C5-93E0577E3AA1}\InProcServer32).
..546 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{1F0BC6AD-46D4-488B-BE1F-047FC7505E60}\InProcServer32\'.
..547 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{1F0BC6AD-46D4-488B-BE1F-047FC7505E60}\InProcServer32).
..548 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4FA18276-912A-11D1-AD9B-00C04FD8FDFF}\InProcServer32\'.
..549 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{4FA18276-912A-11D1-AD9B-00C04FD8FDFF}\InProcServer32).
..550 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6543D242-A80B-44A3-B828-95C1EC452423}\InProcServer32\'.
..551 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{6543D242-A80B-44A3-B828-95C1EC452423}\InProcServer32).
..552 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{A83EF168-CA8D-11D2-B33D-00104BCC4B4A}\InProcServer32\'.
..553 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{A83EF168-CA8D-11D2-B33D-00104BCC4B4A}\InProcServer32).
..554 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{ED999FF5-223A-4052-8ECE-0B10C8DBAA39}\InProcServer32\'.
..555 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMCORE.DLL' registered correctly (\CLSID\{ED999FF5-223A-4052-8ECE-0B10C8DBAA39}\InProcServer32).
..556 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32\'.
..557 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32).
..558 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{47DFBE54-CF76-11D3-B38F-00105A1F473A}\InProcServer32\'.
..559 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{47DFBE54-CF76-11D3-B38F-00105A1F473A}\InProcServer32).
..560 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{5791BC26-CE9C-11D1-97BF-0000F81E849C}\InProcServer32\'.
..561 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{5791BC26-CE9C-11D1-97BF-0000F81E849C}\InProcServer32).
..562 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{75718C9A-F029-11D1-A1AC-00C04FB6C223}\InProcServer32\'.
..563 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{75718C9A-F029-11D1-A1AC-00C04FB6C223}\InProcServer32).
..564 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}\InProcServer32\'.
..565 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}\InProcServer32).
..566 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{9AED384E-CE8B-11D1-8B05-00600806D9B6}\InProcServer32\'.
..567 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{9AED384E-CE8B-11D1-8B05-00600806D9B6}\InProcServer32).
..568 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C2FEEEAC-CFCD-11D1-8B05-00600806D9B6}\InProcServer32\'.
..569 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{C2FEEEAC-CFCD-11D1-8B05-00600806D9B6}\InProcServer32).
..570 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D269BF5C-D9C1-11D3-B38F-00105A1F473A}\InProcServer32\'.
..571 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\CLSID\{D269BF5C-D9C1-11D3-B38F-00105A1F473A}\InProcServer32).
..572 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{14D8250E-D9C2-11D3-B38F-00105A1F473A}\'.
..573 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{14D8250E-D9C2-11D3-B38F-00105A1F473A}).
..574 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{269AD56A-8A67-4129-BC8C-0506DCFE9880}\'.
..575 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{269AD56A-8A67-4129-BC8C-0506DCFE9880}).
..576 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{5AD4BF92-DAAB-11D3-B38F-00105A1F473A}\'.
..577 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{5AD4BF92-DAAB-11D3-B38F-00105A1F473A}).
..578 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{5E97458A-CF77-11D3-B38F-00105A1F473A}\'.
..579 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{5E97458A-CF77-11D3-B38F-00105A1F473A}).
..580 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{75718C9F-F029-11D1-A1AC-00C04FB6C223}\'.
..581 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{75718C9F-F029-11D1-A1AC-00C04FB6C223}).
..582 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{75718CA0-F029-11D1-A1AC-00C04FB6C223}\'.
..583 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{75718CA0-F029-11D1-A1AC-00C04FB6C223}).
..584 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{D2F68443-85DC-427E-91D8-366554CC754C}\'.
..585 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{D2F68443-85DC-427E-91D8-366554CC754C}).
..586 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{D962DB84-D4BB-11D1-8B09-00600806D9B6}\'.
..587 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\INTERFACE\{D962DB84-D4BB-11D1-8B09-00600806D9B6}).
..588 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\TYPELIB\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\'.
..589 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMDISP.DLL' registered correctly (\TYPELIB\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2).
..590 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{5D08B586-343A-11D0-AD46-00C04FD8FDFF}\InProcServer32\'.
..591 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMESS.DLL' registered correctly (\CLSID\{5D08B586-343A-11D0-AD46-00C04FD8FDFF}\InProcServer32).
..592 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32\'.
..593 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMESS.DLL' registered correctly (\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32).
..594 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{76A94DE3-7C26-44F5-8E98-C5AEA48186CB}\InProcServer32\'.
..595 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPERF.DLL' registered correctly (\CLSID\{76A94DE3-7C26-44F5-8E98-C5AEA48186CB}\InProcServer32).
..596 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{FF37A93C-C28E-11D1-AEB6-00C04FB68820}\InProcServer32\'.
..597 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPERF.DLL' registered correctly (\CLSID\{FF37A93C-C28E-11D1-AEB6-00C04FB68820}\InProcServer32).
..598 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{443E7B79-DE31-11D2-B340-00104BCC4B4A}\InProcServer32\'.
..599 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{443E7B79-DE31-11D2-B340-00104BCC4B4A}\InProcServer32).
..600 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcServer32\'.
..601 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcServer32).
..602 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4C6055D8-84B9-4111-A7D3-6623894EEDB3}\InProcServer32\'.
..603 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{4C6055D8-84B9-4111-A7D3-6623894EEDB3}\InProcServer32).
..604 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{A1044801-8F7E-11D1-9E7C-00C04FC324A8}\InProcServer32\'.
..605 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{A1044801-8F7E-11D1-9E7C-00C04FC324A8}\InProcServer32).
..606 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}\InProcServer32\'.
..607 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}\InProcServer32).
..608 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CD184336-9128-11D1-AD9B-00C04FD8FDFF}\InProcServer32\'.
..609 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{CD184336-9128-11D1-AD9B-00C04FD8FDFF}\InProcServer32).
..610 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}\InProcServer32\'.
..611 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL' registered correctly (\CLSID\{F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}\InProcServer32).
..612 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\'.
..613 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32).
..614 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\'.
..615 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}).
..616 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{07435309-D440-41B7-83F3-EB82DB6C622F}\'.
..617 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{07435309-D440-41B7-83F3-EB82DB6C622F}).
..618 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{0FC8C622-1728-4149-A57F-AD19D0970710}\'.
..619 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{0FC8C622-1728-4149-A57F-AD19D0970710}).
..620 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{11CAA957-4E80-474E-A819-7FD72148ADA9}\'.
..621 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{11CAA957-4E80-474E-A819-7FD72148ADA9}).
..622 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{1BE41571-91DD-11D1-AEB2-00C04FB68820}\'.
..623 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{1BE41571-91DD-11D1-AEB2-00C04FB68820}).
..624 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{1BE41572-91DD-11D1-AEB2-00C04FB68820}\'.
..625 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{1BE41572-91DD-11D1-AEB2-00C04FB68820}).
..626 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\'.
..627 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{1C1C45EE-4395-11D2-B60B-00104B703EFD}).
..628 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{1CFABA8C-1523-11D1-AD79-00C04FD8FDFF}\'.
..629 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{1CFABA8C-1523-11D1-AD79-00C04FD8FDFF}).
..630 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\'.
..631 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}).
..632 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{25411283-46FC-4326-8DF2-FF5D34B2DFEF}\'.
..633 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{25411283-46FC-4326-8DF2-FF5D34B2DFEF}).
..634 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{2A504CA2-CA90-4731-87BC-6E99CA2019AF}\'.
..635 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{2A504CA2-CA90-4731-87BC-6E99CA2019AF}).
..636 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{2B322B6E-A9DF-44E3-97BF-259E3583FDA4}\'.
..637 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{2B322B6E-A9DF-44E3-97BF-259E3583FDA4}).
..638 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{2C9273E0-1DC3-11D3-B364-00105A1F8177}\'.
..639 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{2C9273E0-1DC3-11D3-B364-00105A1F8177}).
..640 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{2DB9FA90-9973-46CF-B310-9865B644699D}\'.
..641 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{2DB9FA90-9973-46CF-B310-9865B644699D}).
..642 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{37196B38-CCCF-11D2-B35C-00105A1F8177}\'.
..643 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{37196B38-CCCF-11D2-B35C-00105A1F8177}).
..644 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{37196B39-CCCF-11D2-B35C-00105A1F8177}\'.
..645 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{37196B39-CCCF-11D2-B35C-00105A1F8177}).
..646 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{3AE0080A-7E3A-4366-BF89-0FEEDC931659}\'.
..647 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{3AE0080A-7E3A-4366-BF89-0FEEDC931659}).
..648 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{41AA40E6-2FBA-4E80-ADE9-34306567206D}\'.
..649 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{41AA40E6-2FBA-4E80-ADE9-34306567206D}).
..650 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{423EC01E-2E35-11D2-B604-00104B703EFD}\'.
..651 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{423EC01E-2E35-11D2-B604-00104B703EFD}).
..652 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{44ACA675-E8FC-11D0-A07C-00C04FB68820}\'.
..653 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{44ACA675-E8FC-11D0-A07C-00C04FB68820}).
..654 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{484E3ECE-1F81-4591-B9D4-943BA13B609D}\'.
..655 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{484E3ECE-1F81-4591-B9D4-943BA13B609D}).
..656 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{48FF3109-A366-4B56-B340-01FAE758BA64}\'.
..657 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{48FF3109-A366-4B56-B340-01FAE758BA64}).
..658 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{580ACAF8-FA1C-11D0-AD72-00C04FD8FDFF}\'.
..659 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{580ACAF8-FA1C-11D0-AD72-00C04FD8FDFF}).
..660 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{5FBA5051-3124-4112-B723-46BFBAF1D622}\'.
..661 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{5FBA5051-3124-4112-B723-46BFBAF1D622}).
..662 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{60E512D4-C47B-11D2-B338-00105A1F4AAF}\'.
..663 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{60E512D4-C47B-11D2-B338-00105A1F4AAF}).
..664 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{631F7D96-D993-11D2-B339-00105A1F4AAF}\'.
..665 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{631F7D96-D993-11D2-B339-00105A1F4AAF}).
..666 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{631F7D97-D993-11D2-B339-00105A1F4AAF}\'.
..667 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{631F7D97-D993-11D2-B339-00105A1F4AAF}).
..668 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{6919DD07-1637-4611-A8A7-C16FAC5B2D53}\'.
..669 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{6919DD07-1637-4611-A8A7-C16FAC5B2D53}).
..670 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{6963B029-B969-40AA-9180-2B2F84075973}\'.
..671 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{6963B029-B969-40AA-9180-2B2F84075973}).
..672 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{6B3FC272-BF37-4968-933A-6DF9222A2607}\'.
..673 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{6B3FC272-BF37-4968-933A-6DF9222A2607}).
..674 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{6C19BE32-7500-11D1-AD94-00C04FD8FDFF}\'.
..675 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{6C19BE32-7500-11D1-AD94-00C04FD8FDFF}).
..676 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{6C19BE34-7500-11D1-AD94-00C04FD8FDFF}\'.
..677 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{6C19BE34-7500-11D1-AD94-00C04FD8FDFF}).
..678 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{755F9DA7-7508-11D1-AD94-00C04FD8FDFF}\'.
..679 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{755F9DA7-7508-11D1-AD94-00C04FD8FDFF}).
..680 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{854D745C-6742-42C0-8BB9-01EC466B6E87}\'.
..681 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{854D745C-6742-42C0-8BB9-01EC466B6E87}).
..682 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{88F3781C-6902-4647-9A6B-A74F450AF861}\'.
..683 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{88F3781C-6902-4647-9A6B-A74F450AF861}).
..684 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{8A0DC377-A9D3-41CB-BD69-AE1FDAF2DC68}\'.
..685 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{8A0DC377-A9D3-41CB-BD69-AE1FDAF2DC68}).
..686 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{A210BFE9-C9F7-4919-B114-0D98B3D5341E}\'.
..687 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{A210BFE9-C9F7-4919-B114-0D98B3D5341E}).
..688 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}\'.
..689 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}).
..690 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{AC9EA02A-2C8A-4ACD-B562-D7E8EBEE8E8E}\'.
..691 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{AC9EA02A-2C8A-4ACD-B562-D7E8EBEE8E8E}).
..692 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{B1B55910-8BA0-47A5-A16E-2B733B1D987C}\'.
..693 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{B1B55910-8BA0-47A5-A16E-2B733B1D987C}).
..694 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{B60EF4F1-A411-462B-B51E-477CBDBB90B4}\'.
..695 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{B60EF4F1-A411-462B-B51E-477CBDBB90B4}).
..696 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\'.
..697 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{B7B31DF9-D515-11D3-A11C-00105A1F515A}).
..698 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{BAC6B661-167E-4957-AD77-286AB256585E}\'.
..699 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{BAC6B661-167E-4957-AD77-286AB256585E}).
..700 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{C49E32C7-BC8B-11D2-85D4-00105A1F8304}\'.
..701 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{C49E32C7-BC8B-11D2-85D4-00105A1F8304}).
..702 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{CE61E841-65BC-11D0-B6BD-00AA003240C7}\'.
..703 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{CE61E841-65BC-11D0-B6BD-00AA003240C7}).
..704 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\'.
..705 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}).
..706 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{D8EC9CB1-B135-4F10-8B1B-C7188BB0D186}\'.
..707 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{D8EC9CB1-B135-4F10-8B1B-C7188BB0D186}).
..708 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{DF2373F5-EFB2-475C-AD58-3102D61967D4}\'.
..709 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{DF2373F5-EFB2-475C-AD58-3102D61967D4}).
..710 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}\'.
..711 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}).
..712 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{E246107A-B06E-11D0-AD61-00C04FD8FDFF}\'.
..713 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{E246107A-B06E-11D0-AD61-00C04FD8FDFF}).
..714 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{E8107BDF-BAAF-4C7C-BB5F-9D732E8D8F07}\'.
..715 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{E8107BDF-BAAF-4C7C-BB5F-9D732E8D8F07}).
..716 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\'.
..717 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}).
..718 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{F0E4EDDE-475A-498A-93D7-D4347F68A8F3}\'.
..719 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{F0E4EDDE-475A-498A-93D7-D4347F68A8F3}).
..720 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{F1E9C5B2-F59B-11D2-B362-00105A1F8177}\'.
..721 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{F1E9C5B2-F59B-11D2-B362-00105A1F8177}).
..722 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{F309AD18-D86A-11D0-A075-00C04FB68820}\'.
..723 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{F309AD18-D86A-11D0-A075-00C04FB68820}).
..724 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\'.
..725 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}).
..726 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}\'.
..727 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}).
..728 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\INTERFACE\{FEC1B0AC-5808-4033-A915-C0185934581E}\'.
..729 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WBEMSVC.DLL' registered correctly (\INTERFACE\{FEC1B0AC-5808-4033-A915-C0185934581E}).
..730 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{B0A2AB46-F612-4469-BEC4-7AB038BC476C}\InProcServer32\'.
..731 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMICOOKR.DLL' registered correctly (\CLSID\{B0A2AB46-F612-4469-BEC4-7AB038BC476C}\InProcServer32).
..732 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4CFC7932-0F9D-4BEF-9C32-8EA2A6B56FCB}\InProcServer32\'.
..733 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIDCPRV.DLL' registered correctly (\CLSID\{4CFC7932-0F9D-4BEF-9C32-8EA2A6B56FCB}\InProcServer32).
..734 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F5F75737-2843-4F22-933D-C76A97CDA62F}\InProcServer32\'.
..735 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIDCPRV.DLL' registered correctly (\CLSID\{F5F75737-2843-4F22-933D-C76A97CDA62F}\InProcServer32).
..736 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{622D47B6-CEEC-4DE1-8056-B6D16F29BC97}\InProcServer32\'.
..737 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{622D47B6-CEEC-4DE1-8056-B6D16F29BC97}\InProcServer32).
..738 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{89F9F7B0-8DE3-4AE0-8B41-109ABAB32151}\InProcServer32\'.
..739 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{89F9F7B0-8DE3-4AE0-8B41-109ABAB32151}\InProcServer32).
..740 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{958C59A0-3670-4FE0-B893-6998BB494402}\InProcServer32\'.
..741 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{958C59A0-3670-4FE0-B893-6998BB494402}\InProcServer32).
..742 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{9F007F18-9C24-4630-8B3E-61F96280C593}\InProcServer32\'.
..743 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{9F007F18-9C24-4630-8B3E-61F96280C593}\InProcServer32).
..744 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C1692211-1EC1-4847-9C0D-D2F2D80D07CF}\InProcServer32\'.
..745 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{C1692211-1EC1-4847-9C0D-D2F2D80D07CF}\InProcServer32).
..746 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C169CC11-1EC1-4847-9C0D-D2F2D80D07CF}\InProcServer32\'.
..747 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{C169CC11-1EC1-4847-9C0D-D2F2D80D07CF}\InProcServer32).
..748 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CE69CC1E-1EC0-4847-9C0D-D2F2D80D07CF}\InProcServer32\'.
..749 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIMSG.DLL' registered correctly (\CLSID\{CE69CC1E-1EC0-4847-9C0D-D2F2D80D07CF}\InProcServer32).
..750 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InProcServer32\'.
..751 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.DLL' registered correctly (\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InProcServer32).
..752 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{A3E41207-BE04-492A-AFF0-19E880FF7545}\InProcServer32\'.
..753 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.DLL' registered correctly (\CLSID\{A3E41207-BE04-492A-AFF0-19E880FF7545}\InProcServer32).
..754 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{E2CBCB87-9C07-4523-A78F-061499C83987}\InProcServer32\'.
..755 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPCIMA.DLL' registered correctly (\CLSID\{E2CBCB87-9C07-4523-A78F-061499C83987}\InProcServer32).
..756 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4AF3F4A4-06C8-4B79-A523-633CC65CE297}\InProcServer32\'.
..757 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPDSKQ.DLL' registered correctly (\CLSID\{4AF3F4A4-06C8-4B79-A523-633CC65CE297}\InProcServer32).
..758 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{734AC5AE-68E1-4FB5-B8DA-1D92F7FC6661}\InProcServer32\'.
..759 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPICMP.DLL' registered correctly (\CLSID\{734AC5AE-68E1-4FB5-B8DA-1D92F7FC6661}\InProcServer32).
..760 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{23B77E99-5C2D-482D-A795-62CA3AE5B673}\InProcServer32\'.
..761 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPIPRT.DLL' registered correctly (\CLSID\{23B77E99-5C2D-482D-A795-62CA3AE5B673}\InProcServer32).
..762 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6D7A4B0E-66D5-4AC3-A7ED-0189E8CF5E77}\InProcServer32\'.
..763 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPIPRT.DLL' registered correctly (\CLSID\{6D7A4B0E-66D5-4AC3-A7ED-0189E8CF5E77}\InProcServer32).
..764 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6515834D-6125-4878-A3A3-6B0A73B809A2}\InProcServer32\'.
..765 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.DLL' registered correctly (\CLSID\{6515834D-6125-4878-A3A3-6B0A73B809A2}\InProcServer32).
..766 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7FB1D98A-F895-4761-8DC2-774969C84D10}\InProcServer32\'.
..767 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.DLL' registered correctly (\CLSID\{7FB1D98A-F895-4761-8DC2-774969C84D10}\InProcServer32).
..768 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{AB40A5C1-804B-40BD-9DFE-A640691C6956}\InProcServer32\'.
..769 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.DLL' registered correctly (\CLSID\{AB40A5C1-804B-40BD-9DFE-A640691C6956}\InProcServer32).
..770 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C0AA9D93-2EF5-47FB-960C-F90FC644B48E}\InProcServer32\'.
..771 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPJOBJ.DLL' registered correctly (\CLSID\{C0AA9D93-2EF5-47FB-960C-F90FC644B48E}\InProcServer32).
..772 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{0725C3CB-FEFB-11D0-99F9-00C04FC2F8EC}\InProcServer32\'.
..773 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPROV.DLL' registered correctly (\CLSID\{0725C3CB-FEFB-11D0-99F9-00C04FC2F8EC}\InProcServer32).
..774 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{35B78F79-B973-48C8-A045-CAEC732A35D5}\InProcServer32\'.
..775 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPROV.DLL' registered correctly (\CLSID\{35B78F79-B973-48C8-A045-CAEC732A35D5}\InProcServer32).
..776 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InProcServer32\'.
..777 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPROV.DLL' registered correctly (\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InProcServer32).
..778 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{4DE225BF-CF59-4CFC-85F7-68B90F185355}\InProcServer32\'.
..779 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSD.DLL' registered correctly (\CLSID\{4DE225BF-CF59-4CFC-85F7-68B90F185355}\InProcServer32).
..780 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{7F598975-37E0-4A67-A992-116680F0CEDA}\InProcServer32\'.
..781 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSD.DLL' registered correctly (\CLSID\{7F598975-37E0-4A67-A992-116680F0CEDA}\InProcServer32).
..782 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{8BEBCE8B-1AF0-4323-8B4D-36994567CAE1}\InProcServer32\'.
..783 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSD.DLL' registered correctly (\CLSID\{8BEBCE8B-1AF0-4323-8B4D-36994567CAE1}\InProcServer32).
..784 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{F5A55D36-8750-432C-AB52-AD49A016EABC}\InProcServer32\'.
..785 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSD.DLL' registered correctly (\CLSID\{F5A55D36-8750-432C-AB52-AD49A016EABC}\InProcServer32).
..786 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{6E78DAD9-E187-4D6E-BA63-760256D6F405}\InProcServer32\'.
..787 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIPSESS.DLL' registered correctly (\CLSID\{6E78DAD9-E187-4D6E-BA63-760256D6F405}\InProcServer32).
..788 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{C4819C8D-9AB8-4B2F-B8AE-C77DABF553D5}\InProcServer32\'.
..789 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMITIMEP.DLL' registered correctly (\CLSID\{C4819C8D-9AB8-4B2F-B8AE-C77DABF553D5}\InProcServer32).
..790 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InProcServer32\'.
..791 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIUTILS.DLL' registered correctly (\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InProcServer32).
..792 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{EAC8A024-21E2-4523-AD73-A71A0AA2F56A}\InProcServer32\'.
..793 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIUTILS.DLL' registered correctly (\CLSID\{EAC8A024-21E2-4523-AD73-A71A0AA2F56A}\InProcServer32).
..794 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}\InProcServer32\'.
..795 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\WMIUTILS.DLL' registered correctly (\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}\InProcServer32).
..796 15:02:12 (4)      Reading registry (REG_SZ) 'HKCR\CLSID\{BE0A9830-2B8B-11D1-A949-0060181EBBAD}\InProcServer32\'.
..797 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\MSIPROV.DLL' registered correctly (\CLSID\{BE0A9830-2B8B-11D1-A949-0060181EBBAD}\InProcServer32).
..798 15:02:12 (0) ** Verifying WMI DCOM component security.
..799 15:02:12 (3)    Deciphering DCOM security for 'My Computer' (Access Permissions/Edit Default)
..800 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Microsoft\Ole\DefaultAccessPermission'.
..801 15:02:12 (4)      +- Security Descriptor ------------------------------------------------------------------------------------------
..802 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
..803 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
..804 15:02:12 (4)      | Revision: .............................. 1
..805 15:02:12 (4)      | Control: ............................... &h8004
..806 15:02:12 (4)                                                 SE_DACL_PRESENT
..807 15:02:12 (4)                                                 SE_SELF_RELATIVE
..808 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..809 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..810 15:02:12 (4)      ||| Trustee: ............................. WUYEE\Administrator
..811 15:02:12 (4)      ||| AceType: ............................. &h0
..812 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..813 15:02:12 (4)      ||| AceFlags: ............................ &h0
..814 15:02:12 (4)      ||| AccessMask: .......................... &h7
..815 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..816 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_LOCAL
..817 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_REMOTE
..818 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..819 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
..820 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\INTERACTIVE
..821 15:02:12 (4)      ||| AceType: ............................. &h0
..822 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..823 15:02:12 (4)      ||| AceFlags: ............................ &h0
..824 15:02:12 (4)      ||| AccessMask: .......................... &h3
..825 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..826 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_LOCAL
..827 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..828 15:02:12 (4)      ||+- ACE #03 ----------------------------------------------------------------------------------------------------
..829 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SELF
..830 15:02:12 (4)      ||| AceType: ............................. &h0
..831 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..832 15:02:12 (4)      ||| AceFlags: ............................ &h0
..833 15:02:12 (4)      ||| AccessMask: .......................... &h7
..834 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..835 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_LOCAL
..836 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_REMOTE
..837 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..838 15:02:12 (4)      ||+- ACE #04 ----------------------------------------------------------------------------------------------------
..839 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
..840 15:02:12 (4)      ||| AceType: ............................. &h0
..841 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..842 15:02:12 (4)      ||| AceFlags: ............................ &h0
..843 15:02:12 (4)      ||| AccessMask: .......................... &h3
..844 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..845 15:02:12 (4)                                                 DCOM_RIGHT_ACCESS_LOCAL
..846 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..847 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
..848 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
..849 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
..850 15:02:12 (2) !! WARNING: Actual trustee 'WUYEE\ADMINISTRATOR' has been ADDED for ACE #1.
..851 15:02:12 (2) !! WARNING: Actual trustee 'NT AUTHORITY\INTERACTIVE' has been ADDED for ACE #2.
..852 15:02:12 (2) !! WARNING: Actual trustee 'NT AUTHORITY\SELF' DOES NOT match corresponding expected trustee rights for ACE #3.
..853 15:02:12 (3)    The ACE has the right(s) '&h6,DCOM_RIGHT_ACCESS_LOCAL,DCOM_RIGHT_ACCESS_REMOTE' added!
..854 15:02:12 (2) !! WARNING: Actual trustee 'NT AUTHORITY\SYSTEM' DOES NOT match corresponding expected trustee rights for ACE #4.
..855 15:02:12 (3)    The ACE has the right(s) '&h2,DCOM_RIGHT_ACCESS_LOCAL' added!
..856 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
..857 15:02:12 (3)    
..858 15:02:12 (3)    Deciphering DCOM security for 'My Computer' (Launch & Activation Permissions/Edit Default)
..859 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Microsoft\Ole\DefaultLaunchPermission'.
..860 15:02:12 (4)      +- Security Descriptor ------------------------------------------------------------------------------------------
..861 15:02:12 (4)      | Owner: ................................. S-1-5-21-528768928-1231760990-50533070-500
..862 15:02:12 (4)      | Group: ................................. S-1-5-21-528768928-1231760990-50533070-500
..863 15:02:12 (4)      | Revision: .............................. 1
..864 15:02:12 (4)      | Control: ............................... &h8004
..865 15:02:12 (4)                                                 SE_DACL_PRESENT
..866 15:02:12 (4)                                                 SE_SELF_RELATIVE
..867 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..868 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..869 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
..870 15:02:12 (4)      ||| AceType: ............................. &h0
..871 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..872 15:02:12 (4)      ||| AceFlags: ............................ &h0
..873 15:02:12 (4)      ||| AccessMask: .......................... &h1
..874 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..875 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..876 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
..877 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\INTERACTIVE
..878 15:02:12 (4)      ||| AceType: ............................. &h0
..879 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..880 15:02:12 (4)      ||| AceFlags: ............................ &h0
..881 15:02:12 (4)      ||| AccessMask: .......................... &h1
..882 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..883 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..884 15:02:12 (4)      ||+- ACE #03 ----------------------------------------------------------------------------------------------------
..885 15:02:12 (4)      ||| Trustee: ............................. BUILTIN\Administrators
..886 15:02:12 (4)      ||| AceType: ............................. &h0
..887 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..888 15:02:12 (4)      ||| AceFlags: ............................ &h0
..889 15:02:12 (4)      ||| AccessMask: .......................... &h1
..890 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..891 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..892 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
..893 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
..894 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
..895 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
..896 15:02:12 (3)    
..897 15:02:12 (3)    Deciphering DCOM security for 'Windows Management Instrumentation' (Access Permissions)
..898 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AccessPermission'.
..899 15:02:12 (4)      +- Security Descriptor (DEFAULT) ---------------------------------------------------------------------------------
..900 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
..901 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
..902 15:02:12 (4)      | Revision: .............................. 1
..903 15:02:12 (4)      | Control: ............................... &h8004
..904 15:02:12 (4)                                                 SE_DACL_PRESENT
..905 15:02:12 (4)                                                 SE_SELF_RELATIVE
..906 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..907 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..908 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SELF
..909 15:02:12 (4)      ||| AceType: ............................. &h0
..910 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..911 15:02:12 (4)      ||| AceFlags: ............................ &h0
..912 15:02:12 (4)      ||| AccessMask: .......................... &h1
..913 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..914 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..915 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
..916 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
..917 15:02:12 (4)      ||| AceType: ............................. &h0
..918 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..919 15:02:12 (4)      ||| AceFlags: ............................ &h0
..920 15:02:12 (4)      ||| AccessMask: .......................... &h1
..921 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..922 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..923 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
..924 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
..925 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
..926 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
..927 15:02:12 (3)    
..928 15:02:12 (3)    Deciphering DCOM security for 'Windows Management Instrumentation' (Launch & Activation Permissions)
..929 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission'.
..930 15:02:12 (4)      +- Security Descriptor ------------------------------------------------------------------------------------------
..931 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
..932 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
..933 15:02:12 (4)      | Revision: .............................. 1
..934 15:02:12 (4)      | Control: ............................... &h8004
..935 15:02:12 (4)                                                 SE_DACL_PRESENT
..936 15:02:12 (4)                                                 SE_SELF_RELATIVE
..937 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..938 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..939 15:02:12 (4)      ||| Trustee: ............................. Everyone
..940 15:02:12 (4)      ||| AceType: ............................. &h0
..941 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..942 15:02:12 (4)      ||| AceFlags: ............................ &h0
..943 15:02:12 (4)      ||| AccessMask: .......................... &h1
..944 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..945 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..946 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
..947 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
..948 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
..949 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
..950 15:02:12 (3)    
..951 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WMI Provider Subsystem Host' (Access Permissions)
..952 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AccessPermission'.
..953 15:02:12 (4)      +- Security Descriptor (DEFAULT) ---------------------------------------------------------------------------------
..954 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
..955 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
..956 15:02:12 (4)      | Revision: .............................. 1
..957 15:02:12 (4)      | Control: ............................... &h8004
..958 15:02:12 (4)                                                 SE_DACL_PRESENT
..959 15:02:12 (4)                                                 SE_SELF_RELATIVE
..960 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..961 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..962 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SELF
..963 15:02:12 (4)      ||| AceType: ............................. &h0
..964 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..965 15:02:12 (4)      ||| AceFlags: ............................ &h0
..966 15:02:12 (4)      ||| AccessMask: .......................... &h1
..967 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..968 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..969 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
..970 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
..971 15:02:12 (4)      ||| AceType: ............................. &h0
..972 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..973 15:02:12 (4)      ||| AceFlags: ............................ &h0
..974 15:02:12 (4)      ||| AccessMask: .......................... &h1
..975 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
..976 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
..977 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
..978 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
..979 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
..980 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
..981 15:02:12 (3)    
..982 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WMI Provider Subsystem Host' (Launch & Activation Permissions)
..983 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission'.
..984 15:02:12 (4)      +- Security Descriptor ------------------------------------------------------------------------------------------
..985 15:02:12 (4)      | Owner: ................................. NT AUTHORITY\SYSTEM
..986 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
..987 15:02:12 (4)      | Revision: .............................. 1
..988 15:02:12 (4)      | Control: ............................... &h8004
..989 15:02:12 (4)                                                 SE_DACL_PRESENT
..990 15:02:12 (4)                                                 SE_SELF_RELATIVE
..991 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
..992 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
..993 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\INTERACTIVE
..994 15:02:12 (4)      ||| AceType: ............................. &h0
..995 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
..996 15:02:12 (4)      ||| AceFlags: ............................ &h3
..997 15:02:12 (4)                                                 OBJECT_INHERIT_ACE
..998 15:02:12 (4)                                                 CONTAINER_INHERIT_ACE
..999 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1000 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1001 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1002 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
.1003 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
.1004 15:02:12 (4)      ||| AceType: ............................. &h0
.1005 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1006 15:02:12 (4)      ||| AceFlags: ............................ &h3
.1007 15:02:12 (4)                                                 OBJECT_INHERIT_ACE
.1008 15:02:12 (4)                                                 CONTAINER_INHERIT_ACE
.1009 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1010 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1011 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1012 15:02:12 (4)      ||+- ACE #03 ----------------------------------------------------------------------------------------------------
.1013 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\LOCAL SERVICE
.1014 15:02:12 (4)      ||| AceType: ............................. &h0
.1015 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1016 15:02:12 (4)      ||| AceFlags: ............................ &h3
.1017 15:02:12 (4)                                                 OBJECT_INHERIT_ACE
.1018 15:02:12 (4)                                                 CONTAINER_INHERIT_ACE
.1019 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1020 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1021 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1022 15:02:12 (4)      ||+- ACE #04 ----------------------------------------------------------------------------------------------------
.1023 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\NETWORK SERVICE
.1024 15:02:12 (4)      ||| AceType: ............................. &h0
.1025 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1026 15:02:12 (4)      ||| AceFlags: ............................ &h3
.1027 15:02:12 (4)                                                 OBJECT_INHERIT_ACE
.1028 15:02:12 (4)                                                 CONTAINER_INHERIT_ACE
.1029 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1030 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1031 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1032 15:02:12 (4)      ||+- ACE #05 ----------------------------------------------------------------------------------------------------
.1033 15:02:12 (4)      ||| Trustee: ............................. BUILTIN\Administrators
.1034 15:02:12 (4)      ||| AceType: ............................. &h0
.1035 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1036 15:02:12 (4)      ||| AceFlags: ............................ &h3
.1037 15:02:12 (4)                                                 OBJECT_INHERIT_ACE
.1038 15:02:12 (4)                                                 CONTAINER_INHERIT_ACE
.1039 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1040 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1041 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1042 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
.1043 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
.1044 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
.1045 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
.1046 15:02:12 (3)    
.1047 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WBEM UnSecured Apartment' (Access Permissions)
.1048 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\AccessPermission'.
.1049 15:02:12 (4)      +- Security Descriptor (DEFAULT) ---------------------------------------------------------------------------------
.1050 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
.1051 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
.1052 15:02:12 (4)      | Revision: .............................. 1
.1053 15:02:12 (4)      | Control: ............................... &h8004
.1054 15:02:12 (4)                                                 SE_DACL_PRESENT
.1055 15:02:12 (4)                                                 SE_SELF_RELATIVE
.1056 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
.1057 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
.1058 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SELF
.1059 15:02:12 (4)      ||| AceType: ............................. &h0
.1060 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1061 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1062 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1063 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1064 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1065 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
.1066 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
.1067 15:02:12 (4)      ||| AceType: ............................. &h0
.1068 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1069 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1070 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1071 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1072 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1073 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
.1074 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
.1075 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
.1076 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
.1077 15:02:12 (3)    
.1078 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions)
.1079 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{49BD2028-1523-11D1-AD79-00C04FD8FDFF}\LaunchPermission'.
.1080 15:02:12 (4)      +- Security Descriptor ------------------------------------------------------------------------------------------
.1081 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
.1082 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
.1083 15:02:12 (4)      | Revision: .............................. 1
.1084 15:02:12 (4)      | Control: ............................... &h8004
.1085 15:02:12 (4)                                                 SE_DACL_PRESENT
.1086 15:02:12 (4)                                                 SE_SELF_RELATIVE
.1087 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
.1088 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
.1089 15:02:12 (4)      ||| Trustee: ............................. Everyone
.1090 15:02:12 (4)      ||| AceType: ............................. &h0
.1091 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1092 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1093 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1094 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1095 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1096 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
.1097 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
.1098 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
.1099 15:02:12 (2) !! WARNING: Actual trustee 'EVERYONE' has been ADDED for ACE #1.
.1100 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
.1101 15:02:12 (2) !! WARNING: Default trustee 'BUILTIN\ADMINISTRATORS' has been REMOVED!
.1102 15:02:12 (2) !! WARNING: Default trustee 'NT AUTHORITY\INTERACTIVE' has been REMOVED!
.1103 15:02:12 (2) !! WARNING: Default trustee 'NT AUTHORITY\SYSTEM' has been REMOVED!
.1104 15:02:12 (3)    
.1105 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WBEM Active Scripting Event Consumer Provider' (Access Permissions)
.1106 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{266C72E7-62E8-11D1-AD89-00C04FD8FDFF}\AccessPermission'.
.1107 15:02:12 (4)      +- Security Descriptor (DEFAULT) ---------------------------------------------------------------------------------
.1108 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
.1109 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
.1110 15:02:12 (4)      | Revision: .............................. 1
.1111 15:02:12 (4)      | Control: ............................... &h8004
.1112 15:02:12 (4)                                                 SE_DACL_PRESENT
.1113 15:02:12 (4)                                                 SE_SELF_RELATIVE
.1114 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
.1115 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
.1116 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SELF
.1117 15:02:12 (4)      ||| AceType: ............................. &h0
.1118 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1119 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1120 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1121 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1122 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1123 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
.1124 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
.1125 15:02:12 (4)      ||| AceType: ............................. &h0
.1126 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1127 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1128 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1129 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1130 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1131 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
.1132 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
.1133 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
.1134 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
.1135 15:02:12 (3)    
.1136 15:02:12 (3)    Deciphering DCOM security for 'Microsoft WBEM Active Scripting Event Consumer Provider' (Launch & Activation Permissions)
.1137 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SOFTWARE\Classes\AppID\{266C72E7-62E8-11D1-AD89-00C04FD8FDFF}\LaunchPermission'.
.1138 15:02:12 (4)      +- Security Descriptor (DEFAULT) ---------------------------------------------------------------------------------
.1139 15:02:12 (4)      | Owner: ................................. BUILTIN\Administrators
.1140 15:02:12 (4)      | Group: ................................. BUILTIN\Administrators
.1141 15:02:12 (4)      | Revision: .............................. 1
.1142 15:02:12 (4)      | Control: ............................... &h8004
.1143 15:02:12 (4)                                                 SE_DACL_PRESENT
.1144 15:02:12 (4)                                                 SE_SELF_RELATIVE
.1145 15:02:12 (4)      |+- DiscretionaryAcl --------------------------------------------------------------------------------------------
.1146 15:02:12 (4)      ||+- ACE #01 ----------------------------------------------------------------------------------------------------
.1147 15:02:12 (4)      ||| Trustee: ............................. BUILTIN\Administrators
.1148 15:02:12 (4)      ||| AceType: ............................. &h0
.1149 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1150 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1151 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1152 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1153 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1154 15:02:12 (4)      ||+- ACE #02 ----------------------------------------------------------------------------------------------------
.1155 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\INTERACTIVE
.1156 15:02:12 (4)      ||| AceType: ............................. &h0
.1157 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1158 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1159 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1160 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1161 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1162 15:02:12 (4)      ||+- ACE #03 ----------------------------------------------------------------------------------------------------
.1163 15:02:12 (4)      ||| Trustee: ............................. NT AUTHORITY\SYSTEM
.1164 15:02:12 (4)      ||| AceType: ............................. &h0
.1165 15:02:12 (4)                                                 ACCESS_ALLOWED_ACE_TYPE
.1166 15:02:12 (4)      ||| AceFlags: ............................ &h0
.1167 15:02:12 (4)      ||| AccessMask: .......................... &h1
.1168 15:02:12 (4)                                                 DCOM_RIGHT_EXECUTE
.1169 15:02:12 (4)      ||+--------------------------------------------------------------------------------------------------------------
.1170 15:02:12 (4)      |+---------------------------------------------------------------------------------------------------------------
.1171 15:02:12 (4)      +-----------------------------------------------------------------------------------------------------------------
.1172 15:02:12 (3)    Verifying actual trustees in ACEs against the default trustees in ACEs to locate actual trustee additions.
.1173 15:02:12 (3)    Verifying default trustee in ACEs against the actual trustees in ACEs to locate default trustee removals.
.1174 15:02:12 (3)    
.1175 15:02:12 (0) ** Verifying WMI ProgID registrations.
.1176 15:02:12 (3)    WMI object ProgID 'WBemscripting.SWBemlocator' instantiated'.
.1177 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemDateTime' instantiated'.
.1178 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemObjectPath' instantiated'.
.1179 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemSink' instantiated'.
.1180 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemLocator' instantiated'.
.1181 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemNamedValueSet' instantiated'.
.1182 15:02:12 (3)    WMI object ProgID 'WbemScripting.SWbemRefresher' instantiated'.
.1183 15:02:12 (3)    FW/ICS service is NOT INSTALLED.
.1184 15:02:12 (0) ** Verifying WMI Core registry settings (WBEM).
.1185 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\Scripting\Default Namespace'.
.1186 15:02:12 (3)    WMI registry key (REG_SZ) 'Default Namespace' is correct.
.1187 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Microsoft\WBEM\Scripting\Default Impersonation Level'.
.1188 15:02:12 (3)    WMI registry key (REG_DWORD) 'Default Impersonation Level' is correct.
.1189 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\ADAPDelay'.
.1190 15:02:12 (3)    WMI registry key (REG_DWORD) 'ADAPDelay' is correct.
.1191 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver'.
.1192 15:02:12 (3)    WMI registry key (REG_SZ) 'Default Repository Driver' is correct.
.1193 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents'.
.1194 15:02:12 (3)    WMI registry key (REG_SZ) 'EnableEvents' is correct.
.1195 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Logging'.
.1196 15:02:12 (3)    WMI registry key (REG_SZ) 'Logging' is correct.
.1197 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory'.
.1198 15:02:12 (3)    WMI registry key (REG_EXPAND_SZ) 'Logging Directory' is correct.
.1199 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory'.
.1200 15:02:12 (3)    WMI registry key (REG_EXPAND_SZ) 'Repository Directory' is correct.
.1201 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\TimeOutMs'.
.1202 15:02:12 (3)    WMI registry key (REG_SZ) 'TimeOutMs' is correct.
.1203 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\WMISetup'.
.1204 15:02:12 (3)    WMI registry key (REG_SZ) 'WMISetup' is correct.
.1205 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Autorecover MOFs'.
.1206 15:02:12 (3)    WMI registry hive (REG_SZ) 'Autorecover MOFs' is present.
.1207 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory'.
.1208 15:02:12 (3)    WMI registry key (REG_EXPAND_SZ) 'Working Directory' is correct.
.1209 15:02:12 (0) ** Verifying WMI Service registry settings (SVCHOST, WINMGMT).
.1210 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Start'.
.1211 15:02:12 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs'.
.1212 15:02:12 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\winmgmt'.
.1213 15:02:12 (3)    'Windows Management Instrumentation' (WINMGMT) is running as a SHARED HOST SERVICE.
.1214 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Type'.
.1215 15:02:12 (3)    WMI registry key (REG_DWORD) 'Type' is correct.
.1216 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Start'.
.1217 15:02:12 (3)    WMI registry key (REG_DWORD) 'Start' is correct.
.1218 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\ErrorControl'.
.1219 15:02:12 (3)    WMI registry key (REG_DWORD) 'ErrorControl' is correct.
.1220 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\ImagePath'.
.1221 15:02:12 (3)    WMI registry key (REG_EXPAND_SZ) 'ImagePath' is correct.
.1222 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\DisplayName'.
.1223 15:02:12 (3)    WMI registry hive (REG_SZ) 'DisplayName' is present.
.1224 15:02:12 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\DependOnService'.
.1225 15:02:12 (3)    WMI registry key (REG_MULTI_SZ) 'DependOnService' is correct.
.1226 15:02:12 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\DependOnGroup'.
.1227 15:02:12 (3)    WMI registry hive (REG_MULTI_SZ) 'DependOnGroup' is present.
.1228 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\ObjectName'.
.1229 15:02:12 (3)    WMI registry key (REG_SZ) 'ObjectName' is correct.
.1230 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\FailureActions'.
.1231 15:02:12 (3)    WMI registry hive (REG_BINARY) 'FailureActions' is present.
.1232 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Description'.
.1233 15:02:12 (3)    WMI registry hive (REG_SZ) 'Description' is present.
.1234 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Parameters\ServiceDll'.
.1235 15:02:12 (3)    WMI registry key (REG_EXPAND_SZ) 'ServiceDll' is correct.
.1236 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Parameters\ServiceMain'.
.1237 15:02:12 (3)    WMI registry key (REG_SZ) 'ServiceMain' is correct.
.1238 15:02:12 (4)      Reading registry (REG_BINARY) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Security\Security'.
.1239 15:02:12 (3)    WMI registry hive (REG_BINARY) 'Security' is present.
.1240 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Enum\0'.
.1241 15:02:12 (3)    WMI registry key (REG_SZ) '0' is correct.
.1242 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Enum\Count'.
.1243 15:02:12 (3)    WMI registry key (REG_DWORD) 'Count' is correct.
.1244 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Enum\NextInstance'.
.1245 15:02:12 (3)    WMI registry key (REG_DWORD) 'NextInstance' is correct.
.1246 15:02:12 (3)    'Windows Management Instrumentation' service registered correctly (WINMGMT).
.1247 15:02:12 (0) ** Verifying WMI Service known dependents.
.1248 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\CcmExec\DisplayName'.
.1249 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\6to4\DisplayName'.
.1250 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\MSExchangeMGMT\DisplayName'.
.1251 15:02:12 (4)      Reading registry (REG_MULTI_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\MSExchangeMGMT\DependOnService'.
.1252 15:02:12 (4)      Reading registry (REG_DWORD) 'HKLM\SYSTEM\CurrentControlSet\Services\MSExchangeMGMT\Start'.
.1253 15:02:12 (2) !! WARNING: 'Exchange Management Service' (MSEXCHANGEMGMT, StartMode='Automatic') is installed depends on WMI Service.
.1254 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\IIMFilter\DisplayName'.
.1255 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\RtcSrv\DisplayName'.
.1256 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\MngAgent\DisplayName'.
.1257 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\ADSBuilder\DisplayName'.
.1258 15:02:12 (4)      Reading registry (REG_SZ) 'HKLM\SYSTEM\CurrentControlSet\Services\ADSPXE\DisplayName'.
.1259 15:02:12 (0) ** Verifying 'RPCSS' service status.
.1260 15:02:12 (3)    Verifying 'RPCSS' service started state.
.1261 15:02:12 (3)    'RPCSS' service IS started.
.1262 15:02:12 (0) ** Verifying 'WINMGMT' service status.
.1263 15:02:12 (3)    Verifying 'WINMGMT' service started state.
.1264 15:02:12 (3)    'WINMGMT' service IS started.
.1265 15:02:12 (0) ** Verifying WMI providers loaded BEFORE WMIDiag execution.
.1266 15:02:12 (1) !! ERROR: (CheckWMIStaticData) : 0x80070005 - Access is denied.
.1267 15:02:12 (0) ** Verifying WMI namespace 'Root' (L=1).
.1268 15:02:12 (1) !! ERROR: (CheckWMIStaticData) : 0x46 - Permission denied
.1269 15:02:12 (1) !! ERROR: (CheckWMIStaticData) : 0x80070005 - Access is denied.
.1270 15:02:12 (0) ** Verifying WMI ADAP status.
.1271 15:02:12 (1) !! ERROR: (GetADAPStatus) : 0x80070005 - Access is denied.
.1272 15:02:12 (0) ** Verifying WMI features.
.1273 15:02:12 (3)    Opening WMI namespace 'Root'.
.1274 15:02:12 (1) !! ERROR: (CheckWMIFeatures) : 0x80070005 - Access is denied.
.1275 15:02:12 (3)    Opening WMI namespace 'Root/Default'.
.1276 15:02:12 (1) !! ERROR: (CheckWMIFeatures) : 0x80070005 - Access is denied.
.1277 15:02:12 (3)    Opening WMI namespace 'Root/CIMv2'.
.1278 15:02:12 (1) !! ERROR: (CheckWMIFeatures) : 0x80070005 - Access is denied.
.1279 15:02:12 (3)    Opening WMI namespace 'Root/WMI'.
.1280 15:02:12 (1) !! ERROR: (CheckWMIFeatures) : 0x80070005 - Access is denied.
.1281 15:02:12 (0) ** Collecting system information.
.1282 15:02:12 (1) !! ERROR: (CheckWMIInventory) : 0x80070005 - Access is denied.
.1283 15:02:12 (0) ** Verifying WMI providers loaded AFTER WMIDiag execution.
.1284 15:02:12 (1) !! ERROR: (CheckWMIStaticData) : 0x80070005 - Access is denied.
.1285 15:02:12 (0) ** Verifying WMI Repository files presence.
.1286 15:02:12 (3)    'C:\WINDOWS\SYSTEM32\WBEM\Repository\FS' has a size of 9410268 bytes.
.1287 15:02:12 (3)    'INDEX.BTR' has a size of 1835008 bytes (Created: 5/31/2006 9:08:10 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
.1288 15:02:12 (3)    'INDEX.MAP' has a size of 940 bytes (Created: 5/31/2006 9:08:26 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
.1289 15:02:12 (3)    'OBJECTS.DATA' has a size of 7561216 bytes (Created: 5/31/2006 9:08:10 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
.1290 15:02:12 (3)    'OBJECTS.MAP' has a size of 3740 bytes (Created: 5/31/2006 9:08:25 AM, Last Accessed: 2/18/2009 2:51:39 PM, Last Modified: 12/11/2008 12:33:52 PM).
.1291 15:02:12 (0) ** WMIDiag v2.0 completed.
.1292 15:02:12 (0) ** 
.1293 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1294 15:02:12 (0) ** ----------------------------------------------------- WMI REPORT: BEGIN ----------------------------------------------------------
.1295 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1296 15:02:12 (0) ** 
.1297 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1298 15:02:12 (0) ** Windows XP - No service pack - 32-bit (2600) - User 'WUYEE\JONATHAN' on computer 'WADXJONM'.
.1299 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1300 15:02:12 (0) ** Environment: ........................................................................................................ OK..
.1301 15:02:12 (0) ** There are no missing WMI system files: .............................................................................. OK.
.1302 15:02:12 (0) ** There are no missing WMI repository files: .......................................................................... OK.
.1303 15:02:12 (0) ** WMI repository state: ............................................................................................... N/A.
.1304 15:02:12 (0) ** BEFORE running WMIDiag:
.1305 15:02:12 (0) ** The WMI repository has a size of: ................................................................................... 9 MB.
.1306 15:02:12 (0) ** - Disk free space on 'C:': .......................................................................................... 16094 MB.
.1307 15:02:12 (0) **   - INDEX.BTR,                     1835008 bytes,      12/11/2008 12:33:52 PM
.1308 15:02:12 (0) **   - INDEX.MAP,                     940 bytes,          12/11/2008 12:33:52 PM
.1309 15:02:12 (0) **   - OBJECTS.DATA,                  7561216 bytes,      12/11/2008 12:33:52 PM
.1310 15:02:12 (0) **   - OBJECTS.MAP,                   3740 bytes,         12/11/2008 12:33:52 PM
.1311 15:02:12 (0) ** AFTER running WMIDiag:
.1312 15:02:12 (0) ** The WMI repository has a size of: ................................................................................... 9 MB.
.1313 15:02:12 (0) ** - Disk free space on 'C:': .......................................................................................... 16093 MB.
.1314 15:02:12 (0) **   - INDEX.BTR,                     1835008 bytes,      12/11/2008 12:33:52 PM
.1315 15:02:12 (0) **   - INDEX.MAP,                     940 bytes,          12/11/2008 12:33:52 PM
.1316 15:02:12 (0) **   - OBJECTS.DATA,                  7561216 bytes,      12/11/2008 12:33:52 PM
.1317 15:02:12 (0) **   - OBJECTS.MAP,                   3740 bytes,         12/11/2008 12:33:52 PM
.1318 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1319 15:02:12 (0) ** Windows Firewall: ................................................................................................... NOT INSTALLED.
.1320 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1321 15:02:12 (2) !! WARNING: DCOM Status: ............................................................................................... WARNING!
.1322 15:02:12 (2) !! WARNING: => The DCOM Default Impersonation is NOT set to 'Identify'.
.1323 15:02:12 (0) **    This could prevent WMI to work correctly.
.1324 15:02:12 (0) **    You can fix the DCOM configuration by:
.1325 15:02:12 (0) **    - Executing the 'DCOMCNFG.EXE' command.
.1326 15:02:12 (0) **    - Expanding 'Component Services' and 'Computers' nodes.
.1327 15:02:12 (0) **    - Editing properties of 'My Computer' node.
.1328 15:02:12 (0) **    - Editing the 'Default properties' tab.
.1329 15:02:12 (0) **    - Set the 'Default Impersonation level' listbox to 'Identify'.
.1330 15:02:12 (0) **    From the command line, the DCOM configuration can be corrected with the following command:
.1331 15:02:12 (0) **    i.e. 'REG.EXE Add HKLM\SOFTWARE\Microsoft\Ole /v LegacyImpersonationLevel /t REG_DWORD /d 2 /f'
.1332 15:02:12 (0) ** 
.1333 15:02:12 (0) ** WMI registry setup: ................................................................................................. OK.
.1334 15:02:12 (0) ** INFO: WMI service has dependents: ................................................................................... 1 SERVICE(S)!
.1335 15:02:12 (0) ** - Exchange Management Service (MSEXCHANGEMGMT, StartMode='Automatic')
.1336 15:02:12 (0) ** => If the WMI service is stopped, the listed service(s) will have to be stopped as well.
.1337 15:02:12 (0) **    Note: If the service is marked with (*), it means that the service/application uses WMI but
.1338 15:02:12 (0) **          there is no hard dependency on WMI. However, if the WMI service is stopped,
.1339 15:02:12 (0) **          this can prevent the service/application to work as expected.
.1340 15:02:12 (0) ** 
.1341 15:02:12 (0) ** RPCSS service: ...................................................................................................... OK (Already started).
.1342 15:02:12 (0) ** WINMGMT service: .................................................................................................... OK (Already started).
.1343 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1344 15:02:12 (0) ** WMI service DCOM setup: ............................................................................................. OK.
.1345 15:02:12 (0) ** WMI components DCOM registrations: .................................................................................. OK.
.1346 15:02:12 (0) ** WMI ProgID registrations: ........................................................................................... OK.
.1347 15:02:12 (0) ** WMI provider DCOM registrations: .................................................................................... OK.
.1348 15:02:12 (0) ** WMI provider CIM registrations: ..................................................................................... OK.
.1349 15:02:12 (0) ** WMI provider CLSIDs: ................................................................................................ OK.
.1350 15:02:12 (0) ** WMI providers EXE/DLL availability: ................................................................................. OK.
.1351 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1352 15:02:12 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1353 15:02:12 (1) !! ERROR: Default trustee 'BUILTIN\ADMINISTRATORS' has been REMOVED!
.1354 15:02:12 (0) **        - REMOVED ACE:
.1355 15:02:12 (0) **          ACEType:  &h0
.1356 15:02:12 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1357 15:02:12 (0) **          ACEFlags: &h0
.1358 15:02:12 (0) **          ACEMask:  &h1
.1359 15:02:12 (0) **                    DCOM_RIGHT_EXECUTE
.1360 15:02:12 (0) ** 
.1361 15:02:12 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1362 15:02:12 (0) **    Removing default security will cause some operations to fail!
.1363 15:02:12 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1364 15:02:12 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1365 15:02:12 (0) ** 
.1366 15:02:12 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1367 15:02:12 (1) !! ERROR: Default trustee 'NT AUTHORITY\INTERACTIVE' has been REMOVED!
.1368 15:02:12 (0) **        - REMOVED ACE:
.1369 15:02:12 (0) **          ACEType:  &h0
.1370 15:02:12 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1371 15:02:12 (0) **          ACEFlags: &h0
.1372 15:02:12 (0) **          ACEMask:  &h1
.1373 15:02:12 (0) **                    DCOM_RIGHT_EXECUTE
.1374 15:02:12 (0) ** 
.1375 15:02:12 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1376 15:02:12 (0) **    Removing default security will cause some operations to fail!
.1377 15:02:12 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1378 15:02:12 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1379 15:02:12 (0) ** 
.1380 15:02:12 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1381 15:02:12 (1) !! ERROR: Default trustee 'NT AUTHORITY\SYSTEM' has been REMOVED!
.1382 15:02:12 (0) **        - REMOVED ACE:
.1383 15:02:12 (0) **          ACEType:  &h0
.1384 15:02:12 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1385 15:02:12 (0) **          ACEFlags: &h0
.1386 15:02:12 (0) **          ACEMask:  &h1
.1387 15:02:12 (0) **                    DCOM_RIGHT_EXECUTE
.1388 15:02:12 (0) ** 
.1389 15:02:12 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1390 15:02:12 (0) **    Removing default security will cause some operations to fail!
.1391 15:02:12 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1392 15:02:12 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1393 15:02:12 (0) ** 
.1394 15:02:12 (0) ** 
.1395 15:02:12 (0) ** DCOM security warning(s) detected: .................................................................................. 0.
.1396 15:02:12 (0) ** DCOM security error(s) detected: .................................................................................... 3.
.1397 15:02:12 (0) ** WMI security warning(s) detected: ................................................................................... 0.
.1398 15:02:12 (0) ** WMI security error(s) detected: ..................................................................................... 0.
.1399 15:02:12 (0) ** 
.1400 15:02:12 (1) !! ERROR: Overall DCOM security status: ................................................................................ ERROR!
.1401 15:02:12 (0) ** Overall WMI security status: ........................................................................................ OK.
.1402 15:02:12 (0) ** - Started at 'Root' --------------------------------------------------------------------------------------------------------------
.1403 15:02:12 (0) ** WMI permanent SUBSCRIPTION(S): ...................................................................................... NONE.
.1404 15:02:12 (0) ** WMI TIMER instruction(s): ........................................................................................... NONE.
.1405 15:02:12 (1) !! ERROR: WMI ADAP status: ............................................................................................. NOT AVAILABLE.
.1406 15:02:12 (0) **    You can start the WMI AutoDiscovery/AutoPurge (ADAP) process to resynchronize
.1407 15:02:12 (0) **    the performance counters with the WMI performance classes with the following commands:
.1408 15:02:12 (0) **    i.e. 'WINMGMT.EXE /CLEARADAP'
.1409 15:02:12 (0) **    i.e. 'WINMGMT.EXE /RESYNCPERF'
.1410 15:02:12 (0) **    The ADAP process logs informative events in the Windows NT event log.
.1411 15:02:12 (0) **    More information can be found on MSDN at:
.1412 15:02:12 (0) **    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wmisdk/wmi/wmi_adap_event_log_events.asp
.1413 15:02:12 (1) !! ERROR: WMI MONIKER CONNECTION errors occured for the following namespaces: .......................................... 1 ERROR(S)!
.1414 15:02:12 (0) ** - Root, 0x46 - Permission denied.
.1415 15:02:12 (0) ** 
.1416 15:02:12 (1) !! ERROR: WMI CONNECTION errors occured for the following namespaces: .................................................. 5 ERROR(S)!
.1417 15:02:12 (0) ** - Root, 0x80070005 - Access is denied..
.1418 15:02:12 (0) ** - Root, 0x80070005 - Access is denied..
.1419 15:02:12 (0) ** - Root/Default, 0x80070005 - Access is denied..
.1420 15:02:12 (0) ** - Root/CIMv2, 0x80070005 - Access is denied..
.1421 15:02:12 (0) ** - Root/WMI, 0x80070005 - Access is denied..
.1422 15:02:12 (0) ** 
.1423 15:02:12 (0) ** WMI GET operations: ................................................................................................. OK.
.1424 15:02:12 (0) ** WMI MOF representations: ............................................................................................ OK.
.1425 15:02:12 (0) ** WMI QUALIFIER access operations: .................................................................................... OK.
.1426 15:02:12 (0) ** WMI ENUMERATION operations: ......................................................................................... OK.
.1427 15:02:12 (0) ** WMI EXECQUERY operations: ........................................................................................... OK.
.1428 15:02:12 (0) ** WMI GET VALUE operations: ........................................................................................... OK.
.1429 15:02:12 (0) ** WMI WRITE operations: ............................................................................................... NOT TESTED.
.1430 15:02:12 (0) ** WMI PUT operations: ................................................................................................. NOT TESTED.
.1431 15:02:12 (0) ** WMI DELETE operations: .............................................................................................. NOT TESTED.
.1432 15:02:12 (0) ** WMI static instances retrieved: ..................................................................................... 0.
.1433 15:02:12 (0) ** WMI dynamic instances retrieved: .................................................................................... 0.
.1434 15:02:12 (0) ** WMI instance request cancellations (to limit performance impact): ................................................... 0.
.1435 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1436 15:02:12 (0) ** 
.1437 15:02:12 (0) ** 1 error(s) 0x46 - (WBEM_UNKNOWN) This error code is external to WMI.
.1438 15:02:12 (0) ** 
.1439 15:02:12 (0) ** 5 error(s) 0x80070005 - (WBEM_UNKNOWN) This error code is external to WMI.
.1440 15:02:12 (0) ** => This error is not a WMI error. It is typically due to:
.1441 15:02:12 (0) **    - The DCOM security modifications.
.1442 15:02:12 (0) **      => Ensure that DCOM security configuration settings are not modified.
.1443 15:02:12 (0) **    - The user running WMIDiag has not enough privileges or rights to issue requests
.1444 15:02:12 (0) **      against software components exposing information through WMI.
.1445 15:02:12 (0) **      => Ensure that no third party applications installing additional WMI providers have
.1446 15:02:12 (0) **         specific security requirements (i.e. group membership, privileges, etc ...)
.1447 15:02:12 (0) ** => Errors starting with 0x8007 are Win32 errors, NOT WMI errors. More information can be found
.1448 15:02:12 (0) **    with the 'NET.EXE HELPMSG <dddd>' command, where <dddd> is the last four hex digits (0x0005) 
.1449 15:02:12 (0) **    converted in decimal (5).
.1450 15:02:12 (0) **    - NET HELPMSG 5
.1451 15:02:12 (0) ** 
.1452 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1453 15:02:12 (0) ** WMI Registry key setup: ............................................................................................. OK.
.1454 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1455 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1456 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1457 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1458 15:02:12 (0) ** 
.1459 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1460 15:02:12 (0) ** ------------------------------------------------------ WMI REPORT: END -----------------------------------------------------------
.1461 15:02:12 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1462 15:02:12 (0) ** 
.1463 15:02:12 (0) ** ERROR: WMIDiag detected issues that could prevent WMI to work properly!.  Check 'C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50.LOG' for details.
.1464 15:02:12 (0) ** 
.1465 15:02:12 (0) ** WMIDiag executed in 22 second(s).
.1466 15:02:12 (3)    
.1467 15:02:12 (3)    2.0,2/18/2009,3:01:53 PM,2/18/2009 2:51:36 PM,False,False,False,32-bit,x86 Family 15 Model 4 Stepping 9 GenuineIntel,5.1,2600,Service Pack 3,Windows XP - No service pack - 32-bit,XP___.CLI.RTM.32,,WADXJONM,WUYEE\JONATHAN,False,Root,0, ,0,0,0,0, ,9,16094,9,16093, , , ,1,0,1,0,0,0,0,0,0,0,0, , ,3,0,0,0,0,0,N/A,0,1,5,0,0,0,0,0,0,0,0,0, , , ,0,0,0, , , , , , ,2,24,0,29,2/18/2009,3:02:12 PM,0,0,0,22,47,19,1,WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50.LOG,C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50.LOG
.1468 15:02:12 (3)    
.1469 15:02:12 (0) ** WMIDiag v2.0 ended on Wednesday, February 18, 2009 at 15:02 (W:47 E:19 S:1).
.1659 15:02:12 (0) ** TXT file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50-REPORT.TXT" closed.
.1660 15:02:12 (0) ** CSV file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50-STATISTICS.CSV" closed.
.1661 15:02:12 (0) ** LOG file "C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.02.18_15.01.50.LOG" closed.

Open in new window

Avatar of Netman66
Netman66
Flag of Canada image

Is there a valid reason why you have no Service Pack on the XP workstation?

I suspect, since we are at SP3 for XP, that there is a mismatch somewhere at the Client side extensions and/or policy templates because you have no Service Packs installed.
Avatar of ekm51

ASKER

Thats strange, I do have sp3 installed on the workstation.  SP2 is also depolyed through the domain.

Yes, actually, it is weird:

NTVersion=5.1
...84 15:01:53 (3)    NTBuild=2600
...85 15:01:53 (3)    NTServicePack=Service Pack 3
...86 15:01:53 (3)    FullName=Windows XP - No service pack - 32-bit
...87 15:01:53 (3)    ShortName=XP___.CLI.RTM.32
...88 15:01:53 (3)    SMSAgent=
...89 15:01:53 (3)    WinZIP=C:\PROGRA~1\WINZIP\winzip32.exe
...90 15:01:53 (0) ** Initializing WMI System Information.
...91 15:01:53 (0) ** Windows XP - No service pack - 32-bit (XP___.CLI.RTM.32).
...92 15:01:53 (4)      Reading registry (REG_BINARY) 'HKLM\SYSTEM\CurrentControlSet\Services\winmgmt\Security\Security'.


It seems to be contradicting itself.
Avatar of ekm51

ASKER

any idea's how to resolve this?  I actually deployed sp3 through out our domain but still no luck.
Ok, tell me what - exactly you are attempting.

Is it only to turn on the Windows Management Instrumentation service by policy?

Try making the setting change from a Workstation running XP SP3 and the Adminpak installed with GPMC installed also.

Log into this workstation as a Domain Admin.
Launch GPMC.msc
Find your GPO.
Edit it.
Make the setting change - if it's already set, then unset it and close the GPO then reopen it and set it again.

Sometimes a new template needs to be copied up to the server (it does this automatically when you open a policy from a workstation with newer templates) and the setting modified, saved and remodified to fix any corruption issues.

Just also thinking ---  if this policy was already modified using the above method, then it's possible (because this is a Service we're touching) that the GPO must be created and set from the console of the server using the GPMC locally.

Some services, when modified by a policy created from a workstation end up having incorrect permissions applied to the service - this was an issue when trying to work with the Server service on workstations and may also be the case with other services.


I'll see if I can dig up some documentation stating the same - in the meantime give the above a shot and let me know.
Avatar of ekm51

ASKER

I'm just trying to enable wmi throughout the domain, so yes - I'm just trying to turn on wmi through policy.

-Tried undoing the wmi policy then re-doing it but still no luck

-Tried re-installing wmi on the workstation but no luck - http://windowsxp.mvps.org/repairwmi.htm

Attached is another run at wmidiag

Any help would be greatly appreciated!
.1451 23:34:36 (0) ** WMIDiag v2.0 started on Tuesday, May 05, 2009 at 23:34.
.1452 23:34:36 (0) ** 
.1453 23:34:36 (0) ** Copyright (c) Microsoft Corporation. All rights reserved - January 2007.
.1454 23:34:36 (0) ** 
.1455 23:34:36 (0) ** This script is not supported under any Microsoft standard support program or service.
.1456 23:34:36 (0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
.1457 23:34:36 (0) ** implied warranties including, without limitation, any implied warranties of merchantability
.1458 23:34:36 (0) ** or of fitness for a particular purpose. The entire risk arising out of the use or performance
.1459 23:34:36 (0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
.1460 23:34:36 (0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
.1461 23:34:36 (0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
.1462 23:34:36 (0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
.1463 23:34:36 (0) ** the use of or inability to use the script or documentation, even if Microsoft has been advised
.1464 23:34:36 (0) ** of the possibility of such damages.
.1465 23:34:36 (0) ** 
.1466 23:34:36 (0) ** 
.1467 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1468 23:34:36 (0) ** ----------------------------------------------------- WMI REPORT: BEGIN ----------------------------------------------------------
.1469 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1470 23:34:36 (0) ** 
.1471 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1472 23:34:36 (0) ** Windows XP - No service pack - 32-bit (2600) - User 'WUYEE\JONATHAN' on computer 'WADXJONM'.
.1473 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1474 23:34:36 (0) ** Environment: ........................................................................................................ OK..
.1475 23:34:36 (0) ** There are no missing WMI system files: .............................................................................. OK.
.1476 23:34:36 (0) ** There are no missing WMI repository files: .......................................................................... OK.
.1477 23:34:36 (0) ** WMI repository state: ............................................................................................... N/A.
.1478 23:34:36 (0) ** BEFORE running WMIDiag:
.1479 23:34:36 (0) ** The WMI repository has a size of: ................................................................................... 7 MB.
.1480 23:34:36 (0) ** - Disk free space on 'C:': .......................................................................................... 14150 MB.
.1481 23:34:36 (0) **   - INDEX.BTR,                     1269760 bytes,      5/5/2009 11:23:17 PM
.1482 23:34:36 (0) **   - INDEX.MAP,                     644 bytes,          5/5/2009 11:23:17 PM
.1483 23:34:36 (0) **   - OBJECTS.DATA,                  6406144 bytes,      5/5/2009 11:23:17 PM
.1484 23:34:36 (0) **   - OBJECTS.MAP,                   3152 bytes,         5/5/2009 11:23:17 PM
.1485 23:34:36 (0) ** AFTER running WMIDiag:
.1486 23:34:36 (0) ** The WMI repository has a size of: ................................................................................... 7 MB.
.1487 23:34:36 (0) ** - Disk free space on 'C:': .......................................................................................... 14150 MB.
.1488 23:34:36 (0) **   - INDEX.BTR,                     1269760 bytes,      5/5/2009 11:23:17 PM
.1489 23:34:36 (0) **   - INDEX.MAP,                     644 bytes,          5/5/2009 11:23:17 PM
.1490 23:34:36 (0) **   - OBJECTS.DATA,                  6406144 bytes,      5/5/2009 11:23:17 PM
.1491 23:34:36 (0) **   - OBJECTS.MAP,                   3152 bytes,         5/5/2009 11:23:17 PM
.1492 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1493 23:34:36 (0) ** Windows Firewall: ................................................................................................... NOT INSTALLED.
.1494 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1495 23:34:36 (2) !! WARNING: DCOM Status: ............................................................................................... WARNING!
.1496 23:34:36 (2) !! WARNING: => The DCOM Default Impersonation is NOT set to 'Identify'.
.1497 23:34:36 (0) **    This could prevent WMI to work correctly.
.1498 23:34:36 (0) **    You can fix the DCOM configuration by:
.1499 23:34:36 (0) **    - Executing the 'DCOMCNFG.EXE' command.
.1500 23:34:36 (0) **    - Expanding 'Component Services' and 'Computers' nodes.
.1501 23:34:36 (0) **    - Editing properties of 'My Computer' node.
.1502 23:34:36 (0) **    - Editing the 'Default properties' tab.
.1503 23:34:36 (0) **    - Set the 'Default Impersonation level' listbox to 'Identify'.
.1504 23:34:36 (0) **    From the command line, the DCOM configuration can be corrected with the following command:
.1505 23:34:36 (0) **    i.e. 'REG.EXE Add HKLM\SOFTWARE\Microsoft\Ole /v LegacyImpersonationLevel /t REG_DWORD /d 2 /f'
.1506 23:34:36 (0) ** 
.1507 23:34:36 (0) ** WMI registry setup: ................................................................................................. OK.
.1508 23:34:36 (0) ** INFO: WMI service has dependents: ................................................................................... 1 SERVICE(S)!
.1509 23:34:36 (0) ** - Exchange Management Service (MSEXCHANGEMGMT, StartMode='Automatic')
.1510 23:34:36 (0) ** => If the WMI service is stopped, the listed service(s) will have to be stopped as well.
.1511 23:34:36 (0) **    Note: If the service is marked with (*), it means that the service/application uses WMI but
.1512 23:34:36 (0) **          there is no hard dependency on WMI. However, if the WMI service is stopped,
.1513 23:34:36 (0) **          this can prevent the service/application to work as expected.
.1514 23:34:36 (0) ** 
.1515 23:34:36 (0) ** RPCSS service: ...................................................................................................... OK (Already started).
.1516 23:34:36 (0) ** WINMGMT service: .................................................................................................... OK (Already started).
.1517 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1518 23:34:36 (0) ** WMI service DCOM setup: ............................................................................................. OK.
.1519 23:34:36 (0) ** WMI components DCOM registrations: .................................................................................. OK.
.1520 23:34:36 (0) ** WMI ProgID registrations: ........................................................................................... OK.
.1521 23:34:36 (0) ** WMI provider DCOM registrations: .................................................................................... OK.
.1522 23:34:36 (0) ** WMI provider CIM registrations: ..................................................................................... OK.
.1523 23:34:36 (0) ** WMI provider CLSIDs: ................................................................................................ OK.
.1524 23:34:36 (0) ** WMI providers EXE/DLL availability: ................................................................................. OK.
.1525 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1526 23:34:36 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1527 23:34:36 (1) !! ERROR: Default trustee 'BUILTIN\ADMINISTRATORS' has been REMOVED!
.1528 23:34:36 (0) **        - REMOVED ACE:
.1529 23:34:36 (0) **          ACEType:  &h0
.1530 23:34:36 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1531 23:34:36 (0) **          ACEFlags: &h0
.1532 23:34:36 (0) **          ACEMask:  &h1
.1533 23:34:36 (0) **                    DCOM_RIGHT_EXECUTE
.1534 23:34:36 (0) ** 
.1535 23:34:36 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1536 23:34:36 (0) **    Removing default security will cause some operations to fail!
.1537 23:34:36 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1538 23:34:36 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1539 23:34:36 (0) ** 
.1540 23:34:36 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1541 23:34:36 (1) !! ERROR: Default trustee 'NT AUTHORITY\INTERACTIVE' has been REMOVED!
.1542 23:34:36 (0) **        - REMOVED ACE:
.1543 23:34:36 (0) **          ACEType:  &h0
.1544 23:34:36 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1545 23:34:36 (0) **          ACEFlags: &h0
.1546 23:34:36 (0) **          ACEMask:  &h1
.1547 23:34:36 (0) **                    DCOM_RIGHT_EXECUTE
.1548 23:34:36 (0) ** 
.1549 23:34:36 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1550 23:34:36 (0) **    Removing default security will cause some operations to fail!
.1551 23:34:36 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1552 23:34:36 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1553 23:34:36 (0) ** 
.1554 23:34:36 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
.1555 23:34:36 (1) !! ERROR: Default trustee 'NT AUTHORITY\SYSTEM' has been REMOVED!
.1556 23:34:36 (0) **        - REMOVED ACE:
.1557 23:34:36 (0) **          ACEType:  &h0
.1558 23:34:36 (0) **                    ACCESS_ALLOWED_ACE_TYPE
.1559 23:34:36 (0) **          ACEFlags: &h0
.1560 23:34:36 (0) **          ACEMask:  &h1
.1561 23:34:36 (0) **                    DCOM_RIGHT_EXECUTE
.1562 23:34:36 (0) ** 
.1563 23:34:36 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
.1564 23:34:36 (0) **    Removing default security will cause some operations to fail!
.1565 23:34:36 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
.1566 23:34:36 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
.1567 23:34:36 (0) ** 
.1568 23:34:36 (0) ** 
.1569 23:34:36 (0) ** DCOM security warning(s) detected: .................................................................................. 0.
.1570 23:34:36 (0) ** DCOM security error(s) detected: .................................................................................... 3.
.1571 23:34:36 (0) ** WMI security warning(s) detected: ................................................................................... 0.
.1572 23:34:36 (0) ** WMI security error(s) detected: ..................................................................................... 0.
.1573 23:34:36 (0) ** 
.1574 23:34:36 (1) !! ERROR: Overall DCOM security status: ................................................................................ ERROR!
.1575 23:34:36 (0) ** Overall WMI security status: ........................................................................................ OK.
.1576 23:34:36 (0) ** - Started at 'Root' --------------------------------------------------------------------------------------------------------------
.1577 23:34:36 (0) ** WMI permanent SUBSCRIPTION(S): ...................................................................................... NONE.
.1578 23:34:36 (0) ** WMI TIMER instruction(s): ........................................................................................... NONE.
.1579 23:34:36 (1) !! ERROR: WMI ADAP status: ............................................................................................. NOT AVAILABLE.
.1580 23:34:36 (0) **    You can start the WMI AutoDiscovery/AutoPurge (ADAP) process to resynchronize
.1581 23:34:36 (0) **    the performance counters with the WMI performance classes with the following commands:
.1582 23:34:36 (0) **    i.e. 'WINMGMT.EXE /CLEARADAP'
.1583 23:34:36 (0) **    i.e. 'WINMGMT.EXE /RESYNCPERF'
.1584 23:34:36 (0) **    The ADAP process logs informative events in the Windows NT event log.
.1585 23:34:36 (0) **    More information can be found on MSDN at:
.1586 23:34:36 (0) **    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wmisdk/wmi/wmi_adap_event_log_events.asp
.1587 23:34:36 (1) !! ERROR: WMI MONIKER CONNECTION errors occured for the following namespaces: .......................................... 1 ERROR(S)!
.1588 23:34:36 (0) ** - Root, 0x1AD - ActiveX component can't create object.
.1589 23:34:36 (0) ** 
.1590 23:34:36 (1) !! ERROR: WMI CONNECTION errors occured for the following namespaces: .................................................. 5 ERROR(S)!
.1591 23:34:36 (0) ** - Root, 0x80040154 - Class not registered.
.1592 23:34:36 (0) ** - Root, 0x80040154 - Class not registered.
.1593 23:34:36 (0) ** - Root/Default, 0x80040154 - Class not registered.
.1594 23:34:36 (0) ** - Root/CIMv2, 0x80040154 - Class not registered.
.1595 23:34:36 (0) ** - Root/WMI, 0x80040154 - Class not registered.
.1596 23:34:36 (0) ** 
.1597 23:34:36 (0) ** WMI GET operations: ................................................................................................. OK.
.1598 23:34:36 (0) ** WMI MOF representations: ............................................................................................ OK.
.1599 23:34:36 (0) ** WMI QUALIFIER access operations: .................................................................................... OK.
.1600 23:34:36 (0) ** WMI ENUMERATION operations: ......................................................................................... OK.
.1601 23:34:36 (0) ** WMI EXECQUERY operations: ........................................................................................... OK.
.1602 23:34:36 (0) ** WMI GET VALUE operations: ........................................................................................... OK.
.1603 23:34:36 (0) ** WMI WRITE operations: ............................................................................................... NOT TESTED.
.1604 23:34:36 (0) ** WMI PUT operations: ................................................................................................. NOT TESTED.
.1605 23:34:36 (0) ** WMI DELETE operations: .............................................................................................. NOT TESTED.
.1606 23:34:36 (0) ** WMI static instances retrieved: ..................................................................................... 0.
.1607 23:34:36 (0) ** WMI dynamic instances retrieved: .................................................................................... 0.
.1608 23:34:36 (0) ** WMI instance request cancellations (to limit performance impact): ................................................... 0.
.1609 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1610 23:34:36 (0) ** 
.1611 23:34:36 (0) ** 1 error(s) 0x1AD - (WBEM_UNKNOWN) This error code is external to WMI.
.1612 23:34:36 (0) ** 
.1613 23:34:36 (0) ** 5 error(s) 0x80040154 - (WBEM_UNKNOWN) This error code is external to WMI.
.1614 23:34:36 (0) ** => This error is not a WMI error. This error is a DCOM component registration error.
.1615 23:34:36 (0) **    The registry information for DCOM to initialize a DCOM object is missing or wrongly configured.
.1616 23:34:36 (0) **    - An application has changed the COM/DCOM settings of OLE32.DLL and/or OLEAUT32.DLL.
.1617 23:34:36 (0) **    - The registry settings of COM/DCOM has been damage or wrongly modified.
.1618 23:34:36 (0) **    - The registry security settings of COM/DCOM has been damage or wrongly modified.
.1619 23:34:36 (0) ** => To correct this situation, you must re-register the original COM/DCOM DLLs with REGSVR32.EXE
.1620 23:34:36 (0) **    i.e. 'REGSVR32.EXE OLE32.DLL'
.1621 23:34:36 (0) **    i.e. 'REGSVR32.EXE OLEAUT32.DLL'
.1622 23:34:36 (0) ** => Verify WMIDiag report if ERRORS or WARNINGS are reported about the DCOM security for
.1623 23:34:36 (0) **    the following DCOM objects:
.1624 23:34:36 (0) **    - 'My Computer'
.1625 23:34:36 (0) **    - 'Windows Management Instrumentation'
.1626 23:34:36 (0) **    - 'Microsoft WMI Provider Subsystem Host'
.1627 23:34:36 (0) **    - 'Microsoft WBEM UnSecured Apartment'
.1628 23:34:36 (0) ** => You must also verify with 'REGEDIT.EXE', if the 'Users' builtin group is granted read access for
.1629 23:34:36 (0) **    the following registry hives:
.1630 23:34:36 (0) **    - HKCR\APPID
.1631 23:34:36 (0) **    - HKCR\CLSID
.1632 23:34:36 (0) **    - HKCR\APPID\{1BE1F766-5536-11D1-B726-00C04FB926AF} (WinMgmt EventSystem APPID keys)
.1633 23:34:36 (0) **    - HKCR\CLSID\{1BE1F766-5536-11D1-B726-00C04FB926AF} (WinMgmt EventSystem CLSID keys)
.1634 23:34:36 (0) **    - HKCR\APPID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} (WinMgmt APPID keys)
.1635 23:34:36 (0) **    - HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} (WinMgmt CLSID keys)
.1636 23:34:36 (0) ** 
.1637 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1638 23:34:36 (0) ** WMI Registry key setup: ............................................................................................. OK.
.1639 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1640 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1641 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1642 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1643 23:34:36 (0) ** 
.1644 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1645 23:34:36 (0) ** ------------------------------------------------------ WMI REPORT: END -----------------------------------------------------------
.1646 23:34:36 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1647 23:34:36 (0) ** 
.1648 23:34:36 (0) ** ERROR: WMIDiag detected issues that could prevent WMI to work properly!.  Check 'C:\DOCUMENTS AND SETTINGS\JONATHAN\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_WADXJONM_2009.05.05_23.34.20.LOG' for details.
.1649 23:34:36 (0) ** 
.1650 23:34:36 (0) ** WMIDiag v2.0 ended on Tuesday, May 05, 2009 at 23:34 (W:43 E:17 S:1).

Open in new window

Okay...

Have you attempted ALL the fixes suggested in that log beginning at the top?

One problem is that some ACEs have been removed - those of the Administrator - it's dangerous to arbitrarily remove permissions on things, so I'm not sure why this is the case.

So...here are the steps directly from the diag:

From a CMD prompt with local Admin rights:
REG.EXE Add HKLM\SOFTWARE\Microsoft\Ole /v LegacyImpersonationLevel /t REG_DWORD /d 2 /f

Run DCOMCNFG and drill down to 'Microsoft WBEM UnSecured Apartment' - under Component Services>Computers>My Computer>DCOM Config.
Right click the entry and select Properties.
Select the Security tab.
Select the Edit button under Launch and Activate Permissions.
Add > Administrators - Full Control, SYSTEM - Full Control and Interactive (you have to type that because you can't search it) - Full Control.

Next, run these commands:

WINMGMT.EXE /CLEARADAP
WINMGMT.EXE /RESYNCPERF

Next,

You must also verify with 'REGEDIT.EXE', if the 'Users' builtin group is granted read access for the following registry hives:
HKCR\APPID
HKCR\CLSID
HKCR\APPID\{1BE1F766-5536-11D1-B726-00C04FB926AF} (WinMgmt EventSystem APPID keys)
HKCR\CLSID\{1BE1F766-5536-11D1-B726-00C04FB926AF} (WinMgmt EventSystem CLSID keys)
HKCR\APPID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} (WinMgmt APPID keys)
HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} (WinMgmt CLSID keys)

Next, reboot the machine and run your WMIDIAG again.

Post the new log.


Avatar of ekm51

ASKER

Completed the first step but when I use DCOMCNFG, 'Microsoft WBEM UnSecured Apartment' isn't anywhere to be found under DCOM Config.  I'm guessing thats my problem right there?


Skip that section - the version of WIMDiag you are using is not aware of SP3 for XP - just keep moving forward on the fixes while I see what I can find.

Avatar of ekm51

ASKER

Sorry, made a mistake in a previous comment:  I tried to rebuild wmi with a copy of xp sp3 and get this error:

napclientprov.mof on (unknown) is needed


Ok, create a new file in C:\Windows\System32\wbem - create it as a text file, but name it napclientprov.mof.
Open it for editting in Notepad.
Copy everything below the stars (do not include them) and paste it into this new file, save it and try again.

**************** Copy below *********************


//
// NapClientProv.MOF
//

#PRAGMA AUTORECOVER
#pragma namespace("\\\\.\\root")

instance of __namespace
{
    Name = "nap";
};

#pragma namespace("\\\\.\\root\\nap")

//
//  Registers Framework Provider
//
instance of __Win32Provider as $NapCliProv
{
   Name = "Nap_ClientProvider";
   ClsId = "{C330DE32-29C7-4cf2-9807-74BCB5486A37}";
   HostingModel = "NetworkServiceHost";
   PerUserInitialization = FALSE;
};

instance of __InstanceProviderRegistration
{
    Provider = $NAPCliProv;
    SupportsGet = TRUE;
    SupportsEnumeration = TRUE;    
    SupportsPut = FALSE;
    SupportsDelete = FALSE;
};
If everything fails, then try running this:

rundll32 wbemupgd, UpgradeRepository

Avatar of ekm51

ASKER

Ack, rebuilt WMI but still no luck.  Should I be looking harder at group policy?


No.  If your WMI is corrupt then Group Policy isn't going to help.

Have you checked other machines - not yours - since I see Exchange tools on yours?

Looking at a base user workstation with no additional tools and stuff on it would be a better test.

Avatar of ekm51

ASKER

Ok, here's a wmidiag log from a brand new laptop put on the domain.  

Also found this:

http://social.technet.microsoft.com/Forums/en-US/itproxpsp/thread/7c00d810-0ecd-48b9-862e-69efa29beace

i'll try some more but any ideas would be awesome.  Thanks
.1507 16:06:30 (0) ** WMIDiag v2.0 started on Wednesday, May 06, 2009 at 16:06.
.1508 16:06:30 (0) ** 
.1509 16:06:30 (0) ** Copyright (c) Microsoft Corporation. All rights reserved - January 2007.
.1510 16:06:30 (0) ** 
.1511 16:06:30 (0) ** This script is not supported under any Microsoft standard support program or service.
.1512 16:06:30 (0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
.1513 16:06:30 (0) ** implied warranties including, without limitation, any implied warranties of merchantability
.1514 16:06:30 (0) ** or of fitness for a particular purpose. The entire risk arising out of the use or performance
.1515 16:06:30 (0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
.1516 16:06:30 (0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
.1517 16:06:30 (0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
.1518 16:06:30 (0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
.1519 16:06:30 (0) ** the use of or inability to use the script or documentation, even if Microsoft has been advised
.1520 16:06:30 (0) ** of the possibility of such damages.
.1521 16:06:30 (0) ** 
.1522 16:06:30 (0) ** 
.1523 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1524 16:06:30 (0) ** ----------------------------------------------------- WMI REPORT: BEGIN ----------------------------------------------------------
.1525 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1526 16:06:30 (0) ** 
.1527 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1528 16:06:30 (0) ** Windows XP - Service pack 2 - 32-bit (2600) - User 'WUYEE\ADMINISTRATOR' on computer '706ADMIN01LPT'.
.1529 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1530 16:06:30 (0) ** Environment: ........................................................................................................ OK..
.1531 16:06:30 (0) ** There are no missing WMI system files: .............................................................................. OK.
.1532 16:06:30 (0) ** There are no missing WMI repository files: .......................................................................... OK.
.1533 16:06:30 (0) ** WMI repository state: ............................................................................................... NOT TESTED.
.1534 16:06:30 (0) ** BEFORE running WMIDiag:
.1535 16:06:30 (0) ** The WMI repository has a size of: ................................................................................... 8 MB.
.1536 16:06:30 (0) ** - Disk free space on 'C:': .......................................................................................... 129440 MB.
.1537 16:06:30 (0) **   - INDEX.BTR,                     1368064 bytes,      3/31/2009 10:20:35 AM
.1538 16:06:30 (0) **   - INDEX.MAP,                     692 bytes,          5/6/2009 4:01:53 PM
.1539 16:06:30 (0) **   - MAPPING.VER,                   4 bytes,            5/6/2009 4:01:53 PM
.1540 16:06:30 (0) **   - MAPPING1.MAP,                  4040 bytes,         5/6/2009 4:01:53 PM
.1541 16:06:30 (0) **   - MAPPING2.MAP,                  4040 bytes,         5/6/2009 3:40:30 PM
.1542 16:06:30 (0) **   - OBJECTS.DATA,                  6807552 bytes,      3/31/2009 10:17:28 AM
.1543 16:06:30 (0) **   - OBJECTS.MAP,                   3372 bytes,         5/6/2009 4:01:53 PM
.1544 16:06:30 (0) ** AFTER running WMIDiag:
.1545 16:06:30 (0) ** The WMI repository has a size of: ................................................................................... 8 MB.
.1546 16:06:30 (0) ** - Disk free space on 'C:': .......................................................................................... 129440 MB.
.1547 16:06:30 (0) **   - INDEX.BTR,                     1368064 bytes,      3/31/2009 10:20:35 AM
.1548 16:06:30 (0) **   - INDEX.MAP,                     692 bytes,          5/6/2009 4:01:53 PM
.1549 16:06:30 (0) **   - MAPPING.VER,                   4 bytes,            5/6/2009 4:01:53 PM
.1550 16:06:30 (0) **   - MAPPING1.MAP,                  4040 bytes,         5/6/2009 4:01:53 PM
.1551 16:06:30 (0) **   - MAPPING2.MAP,                  4040 bytes,         5/6/2009 3:40:30 PM
.1552 16:06:30 (0) **   - OBJECTS.DATA,                  6807552 bytes,      3/31/2009 10:17:28 AM
.1553 16:06:30 (0) **   - OBJECTS.MAP,                   3372 bytes,         5/6/2009 4:01:53 PM
.1554 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1555 16:06:30 (2) !! WARNING: Windows Firewall Service: .................................................................................. STOPPED.
.1556 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1557 16:06:30 (2) !! WARNING: DCOM Status: ............................................................................................... WARNING!
.1558 16:06:30 (2) !! WARNING: => The DCOM Default Impersonation is NOT set to 'Identify'.
.1559 16:06:30 (0) **    This could prevent WMI to work correctly.
.1560 16:06:30 (0) **    You can fix the DCOM configuration by:
.1561 16:06:30 (0) **    - Executing the 'DCOMCNFG.EXE' command.
.1562 16:06:30 (0) **    - Expanding 'Component Services' and 'Computers' nodes.
.1563 16:06:30 (0) **    - Editing properties of 'My Computer' node.
.1564 16:06:30 (0) **    - Editing the 'Default properties' tab.
.1565 16:06:30 (0) **    - Set the 'Default Impersonation level' listbox to 'Identify'.
.1566 16:06:30 (0) **    From the command line, the DCOM configuration can be corrected with the following command:
.1567 16:06:30 (0) **    i.e. 'REG.EXE Add HKLM\SOFTWARE\Microsoft\Ole /v LegacyImpersonationLevel /t REG_DWORD /d 2 /f'
.1568 16:06:30 (0) ** 
.1569 16:06:30 (0) ** WMI registry setup: ................................................................................................. OK.
.1570 16:06:30 (0) ** INFO: WMI service has dependents: ................................................................................... 2 SERVICE(S)!
.1571 16:06:30 (0) ** - Security Center (WSCSVC, StartMode='Automatic')
.1572 16:06:30 (0) ** - Windows Firewall/Internet Connection Sharing (ICS) (SHAREDACCESS, StartMode='Disabled')
.1573 16:06:30 (0) ** => If the WMI service is stopped, the listed service(s) will have to be stopped as well.
.1574 16:06:30 (0) **    Note: If the service is marked with (*), it means that the service/application uses WMI but
.1575 16:06:30 (0) **          there is no hard dependency on WMI. However, if the WMI service is stopped,
.1576 16:06:30 (0) **          this can prevent the service/application to work as expected.
.1577 16:06:30 (0) ** 
.1578 16:06:30 (0) ** RPCSS service: ...................................................................................................... OK (Already started).
.1579 16:06:30 (0) ** WINMGMT service: .................................................................................................... OK (Already started).
.1580 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1581 16:06:30 (0) ** WMI service DCOM setup: ............................................................................................. OK.
.1582 16:06:30 (0) ** WMI components DCOM registrations: .................................................................................. OK.
.1583 16:06:30 (0) ** WMI ProgID registrations: ........................................................................................... OK.
.1584 16:06:30 (0) ** WMI provider DCOM registrations: .................................................................................... OK.
.1585 16:06:30 (0) ** WMI provider CIM registrations: ..................................................................................... OK.
.1586 16:06:30 (0) ** WMI provider CLSIDs: ................................................................................................ OK.
.1587 16:06:30 (0) ** WMI providers EXE/DLL availability: ................................................................................. OK.
.1588 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1589 16:06:30 (0) ** Overall DCOM security status: ....................................................................................... OK.
.1590 16:06:30 (0) ** Overall WMI security status: ........................................................................................ OK.
.1591 16:06:30 (0) ** - Started at 'Root' --------------------------------------------------------------------------------------------------------------
.1592 16:06:30 (0) ** WMI permanent SUBSCRIPTION(S): ...................................................................................... NONE.
.1593 16:06:30 (0) ** WMI TIMER instruction(s): ........................................................................................... NONE.
.1594 16:06:30 (1) !! ERROR: WMI ADAP status: ............................................................................................. NOT AVAILABLE.
.1595 16:06:30 (0) **    You can start the WMI AutoDiscovery/AutoPurge (ADAP) process to resynchronize
.1596 16:06:30 (0) **    the performance counters with the WMI performance classes with the following commands:
.1597 16:06:30 (0) **    i.e. 'WINMGMT.EXE /CLEARADAP'
.1598 16:06:30 (0) **    i.e. 'WINMGMT.EXE /RESYNCPERF'
.1599 16:06:30 (0) **    The ADAP process logs informative events in the Windows NT event log.
.1600 16:06:30 (0) **    More information can be found on MSDN at:
.1601 16:06:30 (0) **    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wmisdk/wmi/wmi_adap_event_log_events.asp
.1602 16:06:30 (1) !! ERROR: WMI MONIKER CONNECTION errors occured for the following namespaces: .......................................... 1 ERROR(S)!
.1603 16:06:30 (0) ** - Root, 0x46 - Permission denied.
.1604 16:06:30 (0) ** 
.1605 16:06:30 (1) !! ERROR: WMI CONNECTION errors occured for the following namespaces: .................................................. 5 ERROR(S)!
.1606 16:06:30 (0) ** - Root, 0x80070005 - Access is denied..
.1607 16:06:30 (0) ** - Root, 0x80070005 - Access is denied..
.1608 16:06:30 (0) ** - Root/Default, 0x80070005 - Access is denied..
.1609 16:06:30 (0) ** - Root/CIMv2, 0x80070005 - Access is denied..
.1610 16:06:30 (0) ** - Root/WMI, 0x80070005 - Access is denied..
.1611 16:06:30 (0) ** 
.1612 16:06:30 (0) ** WMI GET operations: ................................................................................................. OK.
.1613 16:06:30 (0) ** WMI MOF representations: ............................................................................................ OK.
.1614 16:06:30 (0) ** WMI QUALIFIER access operations: .................................................................................... OK.
.1615 16:06:30 (0) ** WMI ENUMERATION operations: ......................................................................................... OK.
.1616 16:06:30 (0) ** WMI EXECQUERY operations: ........................................................................................... OK.
.1617 16:06:30 (0) ** WMI GET VALUE operations: ........................................................................................... OK.
.1618 16:06:30 (0) ** WMI WRITE operations: ............................................................................................... NOT TESTED.
.1619 16:06:30 (0) ** WMI PUT operations: ................................................................................................. NOT TESTED.
.1620 16:06:30 (0) ** WMI DELETE operations: .............................................................................................. NOT TESTED.
.1621 16:06:30 (0) ** WMI static instances retrieved: ..................................................................................... 0.
.1622 16:06:30 (0) ** WMI dynamic instances retrieved: .................................................................................... 0.
.1623 16:06:30 (0) ** WMI instance request cancellations (to limit performance impact): ................................................... 0.
.1624 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1625 16:06:30 (0) ** 
.1626 16:06:30 (0) ** 1 error(s) 0x46 - (WBEM_UNKNOWN) This error code is external to WMI.
.1627 16:06:30 (0) ** 
.1628 16:06:30 (0) ** 5 error(s) 0x80070005 - (WBEM_UNKNOWN) This error code is external to WMI.
.1629 16:06:30 (0) ** => This error is not a WMI error. It is typically due to:
.1630 16:06:30 (0) **    - The DCOM security modifications.
.1631 16:06:30 (0) **      => Ensure that DCOM security configuration settings are not modified.
.1632 16:06:30 (0) **    - The user running WMIDiag has not enough privileges or rights to issue requests
.1633 16:06:30 (0) **      against software components exposing information through WMI.
.1634 16:06:30 (0) **      => Ensure that no third party applications installing additional WMI providers have
.1635 16:06:30 (0) **         specific security requirements (i.e. group membership, privileges, etc ...)
.1636 16:06:30 (0) **    - The 'Impersonate Client after authentication' Local Policy is disabled or the 
.1637 16:06:30 (0) **      'SERVICE' account has been removed from that Local Policy.
.1638 16:06:30 (0) **      => You must add the 'SERVICE' account to the 'Impersonate Client after authentication'
.1639 16:06:30 (0) **         Local Policy in the 'Local Policies/User Right Assignments' MMC snap-in (GPEDIT.MSC).
.1640 16:06:30 (0) **         By default, this Local Policy includes the 'SERVICE' account.
.1641 16:06:30 (0) ** 
.1642 16:06:30 (0) ** => Errors starting with 0x8007 are Win32 errors, NOT WMI errors. More information can be found
.1643 16:06:30 (0) **    with the 'NET.EXE HELPMSG <dddd>' command, where <dddd> is the last four hex digits (0x0005) 
.1644 16:06:30 (0) **    converted in decimal (5).
.1645 16:06:30 (0) **    - NET HELPMSG 5
.1646 16:06:30 (0) ** 
.1647 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1648 16:06:30 (0) ** WMI Registry key setup: ............................................................................................. OK.
.1649 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1650 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1651 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1652 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1653 16:06:30 (0) ** 
.1654 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1655 16:06:30 (0) ** ------------------------------------------------------ WMI REPORT: END -----------------------------------------------------------
.1656 16:06:30 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
.1657 16:06:30 (0) ** 
.1658 16:06:30 (0) ** ERROR: WMIDiag detected issues that could prevent WMI to work properly!.  Check 'C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WUYEE\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.SP2.32_706ADMIN01LPT_2009.05.06_16.06.20.LOG' for details.
.1659 16:06:30 (0) ** 
.1660 16:06:30 (0) ** WMIDiag v2.0 ended on Wednesday, May 06, 2009 at 16:06 (W:29 E:14 S:1).

Open in new window

Are you running this script as a local Admin?

Remove the workstation from the domain.
Reboot it.
Delete the account from AD.
Rejoin it.

Is this an SBS domain?

Avatar of ekm51

ASKER

Naw, running it as domain admin.

It is a 2k3 domain.

Is the DA group in the local Administrators group?

So, your domain controller is NOT Small Business Server 2003?  It's important to the outcome of how you join the domain properly with the workstation.

Avatar of ekm51

ASKER

No, its enterprise 2003.  

Yes, the domain admin are in the local admin group.

Okay then, try removing one of those workstations from the domain, then re-joining it.

Let me know.
Avatar of ekm51

ASKER

Yea, I've tried that and still no luck.  

When I took it off the domain WMI didn't seem to be working either.
Were these all created from the same image?  

Is there a possibility the image wasn't created properly?

Avatar of ekm51

ASKER

No, the unit I'm testing on is a lenovo laptop and it came with xp installed.  I highly doubt that would be it since the other computers on the domain are having the same problem.
I'm having a tough time understanding how so many different builds (no similarity due to imaging) have the same problem.

Unless some Default Domain security settings have been modified, then I'm running out of things to look at.

I wouldn't be using an OEM build for a domain - but that's just me....

Avatar of ekm51

ASKER

Yea, I understand.  I imaged most of the machines on the domain but this particular laptop came oem... its cheaper for our organization to just use the OEM install rather than me searching for drivers 1/2 the day....

All computers seem to have the same problem however which makes me think it is a domain security setting.  Problem is previous admin kept NO documentation so its been a nightmare.


ASKER CERTIFIED SOLUTION
Avatar of Netman66
Netman66
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of ekm51

ASKER

i get an error trying to run gpresult

ERROR: unknown user name or bad password

I'm logged in as a domain admin....
Avatar of ekm51

ASKER

Just rebuilt the GP and its working fine.  I guess previous admin had some stuff in there that was messing with it.  Thx