New
#11
When posting long lines of data click the (#) icon and
please paste text between these brackets as shown:
Attachment 239366
When posting long lines of data click the (#) icon and
please paste text between these brackets as shown:
Attachment 239366
Still the same error - please run the following commands.... no need to post the results, I just need to know the number of files and folders quoted in the summary at the end in each case
(so run each command seperately)
DIR C:\Windows\System32 /AR /S
DIR C:\Windows /AR /S
DIR C:\Windows\System32 /AR /S : 4 files, 3 dirs
DIR C:\Windows /AR /S : 1378 files, 219 dirs
Ah! interesting result, that.
1378 files in the Windows folder, but outside the System32 structure......
In a clean updated installation, I get 90, and 156 dirs
in my (very) dirty live install, I get 2279, and the same 156
So we need to hunt down a few folders and see if they are critical ones....
Open an Elevated Command Prompt, and rin the following commands.
DIR C:\WINDOWS\SoftwareDistribution /ar /s
DIR C:\WINDOWS\Servicing /AR /s
DIR C:\WINDOWS\SysWOW64 /AR /S
DIR C:\WINDOWS\inf /AR /S
DIR C:\WINDOWS\Prefetch /AR /S
DIR C:\WINDOWS\Temp /AR /S
DIR C:\WINDOWS\winsxs /ar /s
DIR C:\WINDOWS\Tasks /AR /s
DIR C:\WINDOWS\Registration /AR /S
I think just the number of files/dirs for each is all we need, for the moment
I dont get it... i get "No file found" for everything (checked, obviously, the folders/files are there and i am running cmd as an admin) but SysWOW64, which tells me:
- 1 file
- 60 dirs
Am i missing something here?
:)
The switches we're using are looking for files and directories tagged as 'Read-only' - try running one of them without the /AR switch and see how many you get!
It looks as if the problem may be in SysWOW64 - I only have 3 files and no directories
Please run this, and post the full results
CLS
DIR C:\Windows\SysWOW64 /AR /S
If you like, after that, compare it with
DIR C:\Windows\SysWOW64 /S
... or even just
DIR C:\Windows\SysWOW64
I see...here goes:
- SoftwareDistribution: 70 files, 149 dirs
- Servicing: 2045 files, 26 dirs
- inf: 1651 files, 779 dirs
- Prefetch: 131 files, 5 dirs
- Temp: 22 files, 8 dirs
- winsxs: 46865 files, 35366 dirs
- Tasks: 4 files, 2 dirs
- Registration: 1 file, 5 dirs
As for your last request:
Code:C:\Windows\system32>DIR C:\Windows\SysWOW64 /AR /S Volume in drive C is OS Volume Serial Number is C263-99FD Directory of C:\Windows\SysWOW64\config\systemprofile 31.10.2012 00:42 <DIR> Contacts 31.10.2012 00:42 <DIR> Desktop 31.10.2012 00:42 <DIR> Documents 31.10.2012 00:42 <DIR> Downloads 31.10.2012 00:42 <DIR> Favorites 31.10.2012 00:42 <DIR> Links 31.10.2012 00:42 <DIR> Music 31.10.2012 00:42 <DIR> Pictures 31.10.2012 00:42 <DIR> Saved Games 31.10.2012 00:42 <DIR> Searches 31.10.2012 00:42 <DIR> Videos 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\W indows\Burn 31.10.2012 00:42 <DIR> Burn 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\W indows\Burn\Burn 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows 31.10.2012 00:42 <DIR> Libraries 31.10.2012 00:42 <DIR> Recent 31.10.2012 00:42 <DIR> Start Menu 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Libraries 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Recent 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Start Menu 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 31.10.2012 00:42 <DIR> Programs 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Start Menu\Programs 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 31.10.2012 00:42 <DIR> Administrative Tools 31.10.2012 00:42 <DIR> Startup 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Start Menu\Programs\Administrative Tools 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft \Windows\Start Menu\Programs\Startup 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Contacts 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Desktop 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Documents 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Downloads 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Favorites 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Links 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Music 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 31.10.2012 00:42 <DIR> Playlists 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Music\Playlists 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Pictures 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 31.10.2012 00:42 <DIR> Slide Shows 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Pictures\Slide Shows 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Saved Games 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Searches 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\Videos 31.10.2012 00:42 <DIR> . 31.10.2012 00:42 <DIR> .. 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\Macromed\Flash 09.10.2012 08:48 9.641.400 Flash32_11_4_402_287.ocx 1 File(s) 9.641.400 bytes Total Files Listed: 1 File(s) 9.641.400 bytes 60 Dir(s) 158.830.350.336 bytes free C:\Windows\system32>
OK - let's try this....
Open Windows Explorer (Computer)
Navigate to the C:\Windows\SysWOW64 folder
Find the config sub-folder and right-click on it
select Properties
Clear the 'blob' from the 'Read-only (Only applies to files in folder)' box by clicking on it until it's plain white.
Click on Apply.
Make sure that the radio button for 'Apply changes to this folder, subfolders and files' is set, and click OK.
Accept the Administrator prompt. After a couple of seconds, you'll be told there is an error - click on the 'Ignore all' button.
Wait for it to finish - it could take a couple of minutes.
OK out, and exit Windows Explorer.
Reboot twice
Post a new MGADiag report.
Am...i un-checked, clicked Apply, no Admin prompt, no error... checkd properties again, it was marked again... well anywho, i rebooted twice, heres the report:
Code:Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 0x8004FE21 Cached Online Validation Code: N/A, hr = 0xc0000022 Windows Product Key: *****-*****-PGT9C-777KD-32W74 Windows Product Key Hash: aV31uNYFoD+TSoVOl0ildGR0O5M= Windows Product ID: 00359-OEM-8992687-00008 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 6.1.7601.2.00010300.1.0.003 ID: {F336A84C-3399-4C4A-A3FF-605C57615997}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Home Premium Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.120830-0333 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: <GenuineResults><MachineData><UGUID>{F336A84C-3399-4C4A-A3FF-605C57615997}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-32W74</PKey><PID>00359-OEM-8992687-00008</PID><PIDType>2</PIDType><SID>S-1-5-21-3183993076-1973787798-2123229371</SID><SYSTEM><Manufacturer>Alienware</Manufacturer><Model>M17xR3</Model></SYSTEM><BIOS><Manufacturer>Alienware</Manufacturer><Version>A08</Version><SMBIOSVersion major="2" minor="7"/><Date>20110729000000.000000+000</Date></BIOS><HWID>9E1B3107018400FE</HWID><UserLCID>0424</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Europe Standard Time(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ALWARE</OEMID><OEMTableID>ALIENWRE</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text. Error: 0x80070426 Windows Activation Technologies--> HrOffline: 0x8004FE21 HrOnline: N/A HealthStatus: 0x0001000000000000 Event Time Stamp: 10:31:2012 07:37 ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: Tampered Service: sppsvc HWID Data--> HWID Hash Current: NgAAAAIAAAABAAIAAQADAAAAAwABAAEAonYabHcWNoGuZJz3audEo2I9PIpcwx5RzPGWSC5z OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes Windows marker version: 0x20001 OEMID and OEMTableID Consistent: yes BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC ALWARE ALIENWRE FACP ALWARE ALIENWRE HPET ALWARE ALIENWRE BOOT ALWARE ALIENWRE MCFG ALWARE ALIENWRE SLIC ALWARE ALIENWRE OSFR ALWARE ALIENWRE ASF! ALWARE ALIENWRE SSDT INSYDE INSYDE ASPT ALWARE ALIENWRE SSDT INSYDE INSYDE SSDT INSYDE INSYDE SSDT INSYDE INSYDE WDTT ALWARE ALIENWRE
Yeah - the 'blob' always resets itself, because in theory, folders can't be marked as read-only or read (don't ask!)
The report hasn't change, but has the CMD output changed? (and we'll check a couple more things as well).
CLS
DIR C:\Windows\SysWOW64 /AR /S
ATTRIB C:\Windows\SysWOW64
ICACLS C:\Windows\SysWOW64
post the results.
Sorry - forgot a couple....
ICACLS C:\Windows\SysWOW64\config
ATTRIB C:\Windows\SysWOW64\config