Help, damaged windows installer service

Page 1 of 2 12 LastLast

  1. Posts : 92
    Windows 7 x64
       #1

    Help, damaged windows, frequent random BSODs


    Hello,
    probably my Windows installation service is broken or otherwise nonfunctional. Although the windows installer doesnot report anything wrong, I'm having many bluescreens in last days, mostly just when installing or uninstalling something via Windows Installer. No crash dumps. Any guide how to repair this or diagnose the problem?

    This is the code of most recent BSOD:
    STOP: 0x00000023 (0x00000000000E00E6, 0xFFFFF880035240B8, 0xFFFFF88003523910, 0xFFFFF800034A30D9)
    Last edited by Anakunda; 31 Jul 2012 at 13:48.
      My Computer


  2. Posts : 4,772
    Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
       #2

    Anakunda said:
    Hello,
    probably my Windows installation service is broken or otherwise nonfunctional. Although the windows installer doesnot report anything wrong, I'm having many bluescreens in last days, mostly just when installing or uninstalling something via Windows Installer. No crash dumps. Any guide how to repair this or diagnose the problem?

    This is the code of most recent BSOD:
    STOP: 0x00000023 (0x00000000000E00E6, 0xFFFFF880035240B8, 0xFFFFF88003523910, 0xFFFFF800034A30D9)

    Hello there!

    Please follow Blue Screen of Death (BSOD) Posting Instructions and post us the files even if the dump are missing we can take a look at other files.
      My Computer


  3. Posts : 92
    Windows 7 x64
    Thread Starter
       #3

    Thanks

    The problem is worse.
    I get random BSODs also by normal work with Windows (not running Installer) so that the system is unstable. Running the Installer only forces to invoke BSOD.
    Encountered crashes extend to:

    STOP: 0x000000023
    STOP: 0x000000024
    CACHE_MANAGER (STOP: 0x000000034)
    SYSTEM_SERVICE_EXCEPTION (STOP: 0x00000003B)

    What I've made:
    chkdsk /f /r to system and pagefile partition (they're separate) - passed without errors.
    System partition check by gparted - passed without errors.
    Deep drive test by SeaTools for internal HDD - passed without errors.
    1 round of memory tests by MemTest86+ - passed without errors.
    sfc /scannow - passed successfully.

    A reports from SF Diagnostic Tool are attached:

    Btw. C:\Windows\Minidump and C:\Windows\LiveKernelReports\WATCHDOG are empty despite to numerous BSODs
    I don't see anything suspicious in event logs at the times of crashes
    Last edited by Anakunda; 31 Jul 2012 at 15:59.
      My Computer


  4. Posts : 4,772
    Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
       #4

    Hello there!

    Download Malwarebytes and run a complete scan. Seems like your using pirated software on your PC. They often include Malware that could crash the PC.

    Snip of Host:

    Code:
    #127.0.0.1    www.bitsumactivationserver.com
    
    
    109.236.83.66    megaupload.com www.megaupload.com
    127.0.0.1    192.150.14.69 192.150.18.101 192.150.18.108 192.150.22.40
    127.0.0.1    192.150.8.100 192.150.8.118 209-34-83-73.ood.opsource.net
    127.0.0.1    3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com
    127.0.0.1    3dns-4.adobe.com 3dns.adobe.com 65.52.240.48
    127.0.0.1    CRL.VERISIGN.NET.* activate-sea.adobe.com
    127.0.0.1    activate-sjc0.adobe.com activate.adobe.com
    127.0.0.1    activate.wip.adobe.com activate.wip1.adobe.com
    127.0.0.1    activate.wip2.adobe.com activate.wip3.adobe.com
    127.0.0.1    activate.wip4.adobe.com activation.cloud.techsmith.com
    127.0.0.1    ad-emea.doubleclick.net adobe-dns-1.adobe.com
    127.0.0.1    adobe-dns-2.adobe.com adobe-dns-3.adobe.com
    127.0.0.1    adobe-dns-4.adobe.com adobe-dns.adobe.com adobe.activate.com
    127.0.0.1    adobeereg.com crl.verisign.net ereg.adobe.com
    127.0.0.1    ereg.wip.adobe.com ereg.wip1.adobe.com ereg.wip2.adobe.com
    127.0.0.1    ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com
    127.0.0.1    licensing.ultraedit.com lm.licenses.adobe.com
    127.0.0.1    lmlicenses.wip4.adobe.com ood.opsource.net practivate.adobe
    127.0.0.1    practivate.adobe.* practivate.adobe.com practivate.adobe.ipp
    127.0.0.1    practivate.adobe.newoa practivate.adobe.ntp
    127.0.0.1    tss-geotrust-crl.thawte.com wip.adobe.com wip1.adobe.com
    127.0.0.1    wip2.adobe.com wip3.adobe.com wip4.adobe.com
    127.0.0.1    wwis-dubc1-vip60.adobe.com www.adobeereg.com www.wip.adobe.com
    127.0.0.1    www.wip1.adobe.com www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com
    Event Log error

    Code:
    DucatorEvent[1181]:
      Log Name: Application
      Source: Windows Error Reporting
      Date: 2011-12-29T01:23:01.000
      Event ID: 1001
      Task: N/A
      Level: Informace
      Opcode: Informace
      Keyword: Klasické nastavení
      User: N/A
      User Name: N/A
      Computer: ASUS
      Description: 
    Chybný blok 2651489300, typ 5
    Název události: BEX
    Reakce: Není k dispozici
    ID souboru CAB: 0
    
    Podpis problému:
    P1: Ducator.exe
    P2: 1.0.0.0
    P3: 4dbd7085
    P4: StackHash_0a9e
    P5: 0.0.0.0
    P6: 00000000
    P7: 00000000
    P8: c0000005
    P9: 00000008
    P10: 
    
    Připojené soubory:
    C:\Users\Petr\AppData\Local\Temp\WER40B5.tmp.WERInternalMetadata.xml
    
    Tyto soubory mohou být k dispozici zde:
    C:\Users\Petr\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Ducator.exe_d14c7f7070efc2c4cae489357cd66f31598ce368_020f5eb1
    
    Symbol analýzy: 
    Opětovné hledání řešení: 0
    ID hlášení: 3e166e70-31b3-11e1-871b-0002721e1243
    Stav hlášení: 0
    I'm not sure what Ducator.exe is since I saw quiet few crashes regards this application. Uninstall it if your not using it.

    Follow this article Perform a clean startup to determine whether background programs are interfering with your game or program and disable some startup items.

    Uninstall the following applcations

    Code:
    Start Menu\Programs\Wise Registry Cleaner    Public:Start Menu\Programs\Wise Registry Cleaner    Public
    Start Menu\Programs\ASUS Utility    Public:Start Menu\Programs\ASUS Utility    Public
    Start Menu\Programs\DAEMON Tools Lite    Public:Start Menu\Programs\DAEMON Tools Lite    Public
    The Windows your using is it a retail version or OEM version? Anyway run this update Description of the update for Windows Activation Technologies to see if there is any tampering happened with Windows activation technologies. Also follow this Windows Genuine and Activation Issue Posting Instructions. Post the results in your next post.

    BTW You have to run the MemTest86+ 7 to 8 passes to know the correct result.
      My Computer


  5. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #5

    If the OP Has used WiseFixer, a clean install may be necessary - it's that bad a registry cleaner!
      My Computer


  6. Posts : 92
    Windows 7 x64
    Thread Starter
       #6

    Capt.Jack Sparrow said:
    Hello there!

    Download Malwarebytes and run a complete scan. Seems like your using pirated software on your PC. They often include Malware that could crash the PC.
    Sure, I've run Malwarebytes + SAS test recently with negative result. I suppose I'm secured quite well against any malware. Also I'm watching any startup programs changes and there are none since the time my WIndows not crashed. I think this is not due any infection.

    Capt.Jack Sparrow said:
    Event Log error

    Code:
    DucatorEvent[1181]:
      Log Name: Application
      Source: Windows Error Reporting
      Date: 2011-12-29T01:23:01.000
      Event ID: 1001
      Task: N/A
      Level: Informace
      Opcode: Informace
      Keyword: Klasické nastavení
      User: N/A
      User Name: N/A
      Computer: ASUS
      Description: 
    Chybný blok 2651489300, typ 5
    Název události: BEX
    Reakce: Není k dispozici
    ID souboru CAB: 0
    
    Podpis problému:
    P1: Ducator.exe
    P2: 1.0.0.0
    P3: 4dbd7085
    P4: StackHash_0a9e
    P5: 0.0.0.0
    P6: 00000000
    P7: 00000000
    P8: c0000005
    P9: 00000008
    P10: 
    
    Připojené soubory:
    C:\Users\Petr\AppData\Local\Temp\WER40B5.tmp.WERInternalMetadata.xml
    
    Tyto soubory mohou být k dispozici zde:
    C:\Users\Petr\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Ducator.exe_d14c7f7070efc2c4cae489357cd66f31598ce368_020f5eb1
    
    Symbol analýzy: 
    Opětovné hledání řešení: 0
    ID hlášení: 3e166e70-31b3-11e1-871b-0002721e1243
    Stav hlášení: 0
    I'm not sure what Ducator.exe is since I saw quiet few crashes regards this application. Uninstall it if your not using it.
    I'm using it and I know it is a goodware.

    Capt.Jack Sparrow said:
    Uninstall the following applcations

    Code:
    Start Menu\Programs\Wise Registry Cleaner    Public:Start Menu\Programs\Wise Registry Cleaner    Public
    Start Menu\Programs\ASUS Utility    Public:Start Menu\Programs\ASUS Utility    Public
    Start Menu\Programs\DAEMON Tools Lite    Public:Start Menu\Programs\DAEMON Tools Lite    Public
    I'm afraid I can't uninstall them, at least Wise Registry Cleaner and DT Lite are necessary for me.

    Capt.Jack Sparrow said:
    The Windows your using is it a retail version or OEM version? Anyway run this update Description of the update for Windows Activation Technologies to see if there is any tampering happened with Windows activation technologies.
    I'm not sure I only know it's Ultimate 64bit. But genuine test at https://www.microsoft.com/genuine/validate/ passes successfully so I'm convinced the OS is activated properly.

    Capt.Jack Sparrow said:
    BTW You have to run the MemTest86+ 7 to 8 passes to know the correct result.
    OMG it would take more than 6 hours approximately.
      My Computer


  7. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #7

    Wise Registry Cleaner is probably the cause of your problems, not the cure - get rid of it NOW!
      My Computer


  8. Posts : 92
    Windows 7 x64
    Thread Starter
       #8

    Okay I uninstall it but that software I'm running daily for more than two years already, and never before now I got BSODs.
      My Computer


  9. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #9

    Just because you;ve been lucky for a while doesn't mean it'll continue.
    Please post an MGADiag report - it may show some of the damage it's done.

    we need to see a full copy of the report produced by the MGADiag tool
    (download and save to desktop - http://go.microsoft.com/fwlink/?linkid=52012 )
    Once saved, run the tool.
    Click on the Continue button, which will produce the report.
    To copy the report to your response, click on the Copy button in the tool (ignore any error messages at this point), and then paste (using either r-click/Paste, or Ctrl+V ) into your response.
      My Computer


  10. Posts : 92
    Windows 7 x64
    Thread Starter
       #10

    The MGADiag report:
    Code:
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    
    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-Q6MMK-KYK6X-VKM6G
    Windows Product Key Hash: 289NoAWl2ZoVfuieux/315WkDIc=
    Windows Product ID: 00426-OEM-8992662-00173
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.001
    ID: {3E1A859C-2789-4723-B832-8E80DE5B4FA5}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
    
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    
    File Scan Data-->
    
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{3E1A859C-2789-4723-B832-8E80DE5B4FA5}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-VKM6G</PKey><PID>00426-OEM-8992662-00173</PID><PIDType>2</PIDType><SID>S-1-5-21-2121438031-4036342592-2470101266</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc. </Manufacturer></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><SMBIOSVersion major="2" minor="5"/><Date>20110705000000.000000+000</Date></BIOS><HWID>4A603D07018400F8</HWID><UserLCID>0405</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Střední Evropa (běžný čas)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
    
    Spsys.log Content: 0x80070002
    
    Licensing Data-->
    Verze služby SLS (Software Licensing Service): 6.1.7601.17514
    
    Název: Windows(R) 7, Ultimate edition
    Popis: Windows Operating System - Windows(R) 7, OEM_SLP channel
    ID aktivace: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8
    ID aplikace: 55c92734-d682-4d71-983e-d6ec3f16059f
    Rozšířené PID: 00426-00178-926-600173-02-1029-7601.0000-0362011
    ID instalace: 020234103602444724572631089486940430412001068765428830
    Adresa URL certifikátu procesoru:   http://go.microsoft.com/fwlink/?LinkID=88338
    Adresa URL certifikátu počítače:     http://go.microsoft.com/fwlink/?LinkID=88339
    Adresa URL licence k použití:             http://go.microsoft.com/fwlink/?LinkID=88341
    Adresa URL certifikátu kódu Product Key: http://go.microsoft.com/fwlink/?LinkID=88340
    Část kódu Product Key: VKM6G
    Stav licence: Licencováno
    Zbývající počet obnovení aktivačního období Windows: 3
    Důvěryhodný čas: 31.7.2012 23:26:58
    
    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 5:20:2012 12:40
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    
    
    HWID Data-->
    HWID Hash Current: NgAAAAIAAQABAAEAAQABAAAABQABAAEA6GHatmkrwAq4USg1uA7zAFw24zbSalAzQgQgaUbK
    
    OEM Activation 1.0 Data-->
    N/A
    
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            _ASUS_        APIC1409
      FACP            _ASUS_        Notebook
      DBGP            _ASUS_        DBGP1409
      HPET            _ASUS_        OEMHPET0
      BOOT            _ASUS_        BOOT1409
      MCFG            _ASUS_        OEMMCFG 
      WDRT            _ASUS_        NV-WDRT 
      SLIC            _ASUS_        Notebook
      OEMX            _ASUS_        OEMX1409
      ECDT            _ASUS_        OEMECDT 
      OEMB            _ASUS_        OEMB1409
      SSDT            PmRef        CpuPm
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:15.
Find Us