New
#1
error code 2 when starting up windows update
Error Code 2: File not found.
The executable name is
C:\Windows\system32\svchost.exe -k netsvcs
Last edited by CrazyGuy2345; 12 Dec 2013 at 19:43. Reason: add file not found
Error Code 2: File not found.
The executable name is
C:\Windows\system32\svchost.exe -k netsvcs
Last edited by CrazyGuy2345; 12 Dec 2013 at 19:43. Reason: add file not found
Please download the Farbar Service Scanner from
http://www.bleepingcomputer.com/download/farbar-service-scanner/
Right-click on the saved file and select 'Run as Administrator', and tick all the options, then click on the Scan button - copy and paste the report to your response.
Also...
Please follow the Windows Update Posting Instructions and post the requested data
Farbar Service Scanner Version: 05-12-2013
Ran by removed (administrator) on 13-12-2013 at 18:00:14
Running from "C:\Users\removed\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
Unable to retrieve ServiceDll of wuauserv. The value does not exist.
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Windows defender is ok, i have Microsoft security essentials.
Last edited by CrazyGuy2345; 13 Dec 2013 at 18:01. Reason: censor usernames
Pretty much as expected, then -
Please open an Elevated Command Prompt, and run the following commands...
SC QUERYEX WUAUSERV
REG QUERY HKLM\SYSTEM\CurrentControlSet\Services\wuauserv /S
DIR C:\Windows\system32\wuaueng.dll
ICACLS C:\Windows\system32\wuaueng.dll
Post the results, and it should tell us exactly where the problem lies.
Here are some instructions to make life easier :)
1) To open an Elevated Command Prompt Window (the ECP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt.
2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Window, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once.
3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Windows\system32>SC QUERYEX WUAUSERV
SERVICE_NAME: WUAUSERV
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 1 STOPPED
WIN32_EXIT_CODE : 2 (0x2)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PID : 0
FLAGS :
C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Services\wuauserv /S
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv
PreshutdownTimeout REG_DWORD 0x36ee800
DisplayName REG_SZ Windows Update
ImagePath REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
Description REG_SZ Enables the detection, download, and installation o
f updates for Windows and other programs. If this service is disabled, users of
this computer will not be able to use Windows Update or its automatic updating f
eature, and programs will not be able to use the Windows Update Agent (WUA) API.
ObjectName REG_SZ LocalSystem
ErrorControl REG_DWORD 0x1
Start REG_DWORD 0x2
DelayedAutoStart REG_DWORD 0x1
Type REG_DWORD 0x20
DependOnService REG_MULTI_SZ rpcss
ServiceSidType REG_DWORD 0x1
RequiredPrivileges REG_MULTI_SZ SeAuditPrivilege\0SeCreateGlobalPrivil
ege\0SeCreatePageFilePrivilege\0SeTcbPrivilege\0SeAssignPrimaryTokenPrivilege\0S
eImpersonatePrivilege\0SeIncreaseQuotaPrivilege
FailureActions REG_BINARY 80510100000000000000000003000000140000000100
000060EA000000000000000000000000000000000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters
ServiceMain REG_SZ WUServiceMain
ServiceDllUnloadOnStop REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security
Security REG_BINARY 010014807800000084000000140000003000000002001C0001
00000002801400FF000F000101000000000001000000000200480003000000000014009D00020001
010000000000050B00000000001800FF010F000102000000000005200000002002000000001400FF
010F00010100000000000512000000010100000000000512000000010100000000000512000000
C:\Windows\system32>DIR C:\Windows\system32\wuaueng.dll
Volume in drive C is OS
Volume Serial Number is 2CDC-FF2B
Directory of C:\Windows\system32
06/02/2012 05:19 PM 2,428,952 wuaueng.dll
1 File(s) 2,428,952 bytes
0 Dir(s) 1,156,274,712,576 bytes free
C:\Windows\system32>ICACLS C:\Windows\system32\wuaueng.dll
C:\Windows\system32\wuaueng.dll NT SERVICE\TrustedInstallerF)
BUILTIN\AdministratorsRX)
NT AUTHORITY\SYSTEMRX)
BUILTIN\UsersRX)
Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>
Last edited by CrazyGuy2345; 21 Dec 2013 at 20:52.
Ah - the ServiceDll entry is missing for some reason (possibly enemy action )
I've uploaded a file - wuauengpar.zip - to my SkyDrive at Noel's SkyDrive
Please download and save it to your desktop.
Right-click on the saved file and select Extract all...
Save it to the default location
This should create a file wuauengpar.reg
right-click on the file, and select Merge
Accept the warnings, - you should then get a 'Success' message.
Close all windows, and reboot.
Now try Windows update