New
#11
Thanks for your efforts Noel. It is much appreciated!
Thanks for your efforts Noel. It is much appreciated!
Please open regedit
Navigate to the HKU Key and highlight the S-1-5-20 subkey.
Right-Click on it and select Permissions.
Take a screenshot and post it
Click on the Owner tab - who is the current owner?
Click on the Effective Permissions tab
Click object name box, enter 'Administrators' and click 'Check Names'
that should auto-enter the full username
click OK
now see what's UNticked in the listing, and post that
Click Cancel back to regedit, and exit regedit.
Here are screenshots of the S-1-5-20 subkey in regedit:
Permissions
03.30.2014-15.02.00 - SethLarrabee's library
03.30.2014-15.05.41 - SethLarrabee's library
Current Owner
03.30.2014-15.06.29 - SethLarrabee's library
Effective Permissions Tab - Administrators
03.30.2014-15.11.05 - SethLarrabee's library
Is that what you need?
The permissions there are very odd - there is no way that Users should have anything except Read permissions an that Key (in fact, they shouldn't even be listed!)
The NetworkServices account is missing - which would explain the problems updating it.
Let's first give the Network Service back its control.
Open Regedit, and navigate to the HKU hive
right-click on the S-1-5-20 key, and select Permissions
Click on the Advanced button.
in the Permissions tab, click on the Add... button
In the object name box, type NETWORK SERVICE - click on Check Names, and it should auto-enter the proper format.
Assuming it does, click OK once (otherwise, Cancel out to Windows, and let me know what happened)
Then highlight the new NETWORK SERVICE entry and select Edit
in the popup, set the 'Apply to' option to 'This Key and SubKeys' and make sure that all boxes are ticked.
click OK out to Windows and reboot.
Added NETWORK SERVICE:
03.30.2014-19.17.10 - SethLarrabee's library
Regedit S-1-5-20 key screenshot:
03.30.2014-19.18.34 - SethLarrabee's library
New MGADiag report and CMD check:
Code:Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 50 Cached Online Validation Code: N/A, hr = 0x80070005 Windows Product Key: *****-*****-4KFPV-X2G9G-WDDCP Windows Product Key Hash: uTRAZe1Vb2AXoWPB2HsUiho238I= Windows Product ID: 00371-OEM-9044675-37476 Windows Product ID Type: 3 Windows License Type: OEM System Builder Windows OS version: 6.1.7601.2.00010100.1.0.048 ID: {443BA590-0E48-4E1F-9F8F-AF96A9FBF34B}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Professional Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.130828-1532 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Users\Seth\AppData\Local\Google\Chrome\Application\chrome.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: <GenuineResults><MachineData><UGUID>{443BA590-0E48-4E1F-9F8F-AF96A9FBF34B}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-WDDCP</PKey><PID>00371-OEM-9044675-37476</PID><PIDType>3</PIDType><SID>S-1-5-21-2467563765-447062938-1869009075</SID><SYSTEM><Manufacturer>System manufacturer</Manufacturer><Model>System Product Name</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies, LTD</Manufacturer><Version>ASUS M3N78 PRO ACPI BIOS Revision 1402</Version><SMBIOSVersion major="2" minor="5"/><Date>20091204000000.000000+000</Date></BIOS><HWID>1B493507018400F2</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text. Error: 0x46 Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: N/A HealthStatus: 0x0000000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: PAAAAAIABAABAAIAAAAEAAAAAgABAAEAln0wkTyP9puEVkKZVhCWkt4GznA0pIIyAgczXc+qZvMgHtbH OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes, but no SLIC table Windows marker version: N/A OEMID and OEMTableID Consistent: N/A BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC Nvidia ASUSACPI FACP Nvidia ASUSACPI HPET Nvidia ASUSACPI MCFG Nvidia ASUSACPI Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Windows\system32>REG QUERY HKU HKEY_USERS\.DEFAULT HKEY_USERS\S-1-5-19 HKEY_USERS\S-1-5-21-2467563765-447062938-1869009075-1001 HKEY_USERS\S-1-5-21-2467563765-447062938-1869009075-1001_Classes HKEY_USERS\S-1-5-18 C:\Windows\system32>REG QUERY HKU\S-1-5-20 /S ERROR: The system was unable to find the specified registry key or value.
Still a permission denied error, and the 0x46 error
Maybe it's the file/folder at fault?
Please open an Elevated Command Prompt, and run the following commands
ICACLS C:\Windows\ServiceProfiles\NetworkService
ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG
ATTRIB C:\Windows\ServiceProfiles\NetworkService\NTUSER.*
Post the results
Here is part one of the results (there was too much text to post the entire thing in one post)
Running the following commands:
ICACLS C:\Windows\ServiceProfiles\NetworkService
ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG
Code:Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM:(OI)(CI)(F) BUILTIN\Administrators:(OI)(CI)(F) NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(F) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT NT AUTHORITY\SYSTEM:(I)(F) BUILTIN\Administrators:(I)(F) NT AUTHORITY\NETWORK SERVICE:(I)(F) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG NT AUTHORITY\SYSTEM:(I)(F) BUILTIN\Administrators:(I)(F) NT AUTHORITY\NETWORK SERVICE:(I)(F) Successfully processed 1 files; Failed processing 0 files
Here is part two of the results (there was too much text to post the entire thing in one post)
Running the following command:
ATTRIB C:\Windows\ServiceProfiles\NetworkService\NTUSER.*
What's next?Code:Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Windows\system32>ATTRIB C:\Windows\ServiceProfiles\NetworkService\NTUSER.* A SH I C:\Windows\ServiceProfiles\NetworkService\ntuser.dat A H C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG A H C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 A H C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 A SH C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{13be311f-200c-11e2-a590-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{13be311f-200c-11e2-a590-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{13be311f-200c-11e2-a590-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{257e64bc-fdee-11e2-a9aa-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{257e64bc-fdee-11e2-a9aa-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{257e64bc-fdee-11e2-a9aa-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{262d9337-fb07-11e2-b04f-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{262d9337-fb07-11e2-b04f-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{262d9337-fb07-11e2-b04f-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{272daf0b-c44c-11e2-b1fc-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{272daf0b-c44c-11e2-b1fc-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{272daf0b-c44c-11e2-b1fc-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{2e186875-8a7e-11e2-b014-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{2e186875-8a7e-11e2-b014-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{2e186875-8a7e-11e2-b014-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{31d81076-3278-11e2-ad31-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{31d81076-3278-11e2-ad31-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{31d81076-3278-11e2-ad31-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3a941c45-1318-11e2-a5ab-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3a941c45-1318-11e2-a5ab-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3a941c45-1318-11e2-a5ab-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3b2db48f-86f6-11e2-a0f7-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3b2db48f-86f6-11e2-a0f7-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{3b2db48f-86f6-11e2-a0f7-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{40becb71-d41c-11e1-af62-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{40becb71-d41c-11e1-af62-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{40becb71-d41c-11e1-af62-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{4297344d-3838-11e3-a954-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{4297344d-3838-11e3-a954-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{4297344d-3838-11e3-a954-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{51e47b1a-21bb-11e3-a81a-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{51e47b1a-21bb-11e3-a81a-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{51e47b1a-21bb-11e3-a81a-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{520f8967-128f-11e3-a5a3-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{520f8967-128f-11e3-a5a3-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{520f8967-128f-11e3-a5a3-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{581be972-3e50-11e3-abb5-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{581be972-3e50-11e3-abb5-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{581be972-3e50-11e3-abb5-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{5d93a319-7d27-11e3-b400-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{5d93a319-7d27-11e3-b400-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{5d93a319-7d27-11e3-b400-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{6011cca7-c556-11e1-a3af-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{6011cca7-c556-11e1-a3af-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{6011cca7-c556-11e1-a3af-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{62c96e6f-a4a2-11e3-9fa9-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{62c96e6f-a4a2-11e3-9fa9-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{62c96e6f-a4a2-11e3-9fa9-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{776c6ee8-f024-11e2-a95e-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{776c6ee8-f024-11e2-a95e-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{776c6ee8-f024-11e2-a95e-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7b845f06-c44b-11e2-b000-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7b845f06-c44b-11e2-b000-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7b845f06-c44b-11e2-b000-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7dbe7c53-812a-11e3-93cd-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7dbe7c53-812a-11e3-93cd-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{7dbe7c53-812a-11e3-93cd-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{84bbaa37-70a8-11e2-b177-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{84bbaa37-70a8-11e2-b177-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{84bbaa37-70a8-11e2-b177-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{86302be8-19ac-11e3-a4b8-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{86302be8-19ac-11e3-a4b8-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{86302be8-19ac-11e3-a4b8-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{90b7a86e-7099-11e1-afde-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{90b7a86e-7099-11e1-afde-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{90b7a86e-7099-11e1-afde-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9d5ca7f2-f59a-11e2-b664-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9d5ca7f2-f59a-11e2-b664-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9d5ca7f2-f59a-11e2-b664-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9ec79ada-dcc9-11e1-b052-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9ec79ada-dcc9-11e1-b052-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9ec79ada-dcc9-11e1-b052-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a023cbd8-f338-11e1-b23f-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a023cbd8-f338-11e1-b23f-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a023cbd8-f338-11e1-b23f-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a0f65f25-9cc2-11e3-ae3d-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a0f65f25-9cc2-11e3-ae3d-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a0f65f25-9cc2-11e3-ae3d-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8361528-c44b-11e2-b1e1-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8361528-c44b-11e2-b1e1-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8361528-c44b-11e2-b1e1-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8a37fd9-36ad-11e3-ab8a-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8a37fd9-36ad-11e3-ab8a-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{a8a37fd9-36ad-11e3-ab8a-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b01525b0-f59b-11e2-9165-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b01525b0-f59b-11e2-9165-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b01525b0-f59b-11e2-9165-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b47003eb-c44a-11e2-b7de-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b47003eb-c44a-11e2-b7de-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b47003eb-c44a-11e2-b7de-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b4b12af3-508c-11e3-b835-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b4b12af3-508c-11e3-b835-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{b4b12af3-508c-11e3-b835-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{bb7e478b-6774-11e1-9e23-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{bb7e478b-6774-11e1-9e23-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{bb7e478b-6774-11e1-9e23-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c03a8c6f-f599-11e2-b69e-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c03a8c6f-f599-11e2-b69e-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c03a8c6f-f599-11e2-b69e-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c77f395f-8576-11e1-a535-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c77f395f-8576-11e1-a535-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{c77f395f-8576-11e1-a535-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ce104f12-7099-11e1-a063-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ce104f12-7099-11e1-a063-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ce104f12-7099-11e1-a063-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d0f819fa-f338-11e1-a268-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d0f819fa-f338-11e1-a268-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d0f819fa-f338-11e1-a268-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d3e95de5-5516-11e2-a371-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d3e95de5-5516-11e2-a371-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{d3e95de5-5516-11e2-a371-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{db168394-5090-11e1-bed8-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{db168394-5090-11e1-bed8-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{db168394-5090-11e1-bed8-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{df6935e7-7334-11e2-b16c-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{df6935e7-7334-11e2-b16c-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{df6935e7-7334-11e2-b16c-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{e874aa84-d65d-11e1-affc-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{e874aa84-d65d-11e1-affc-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{e874aa84-d65d-11e1-affc-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ec419587-1318-11e2-b797-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ec419587-1318-11e2-b797-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ec419587-1318-11e2-b797-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ef37e03f-9087-11e3-bc01-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ef37e03f-9087-11e3-bc01-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{ef37e03f-9087-11e3-bc01-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f6a0ed71-30f3-11e2-a5f8-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f6a0ed71-30f3-11e2-a5f8-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f6a0ed71-30f3-11e2-a5f8-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f9bac9b5-972f-11e3-a879-806e6f6e6963}.TM.blf A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f9bac9b5-972f-11e3-a879-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms A SH C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{f9bac9b5-972f-11e3-a879-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
That all looks normal.
It's almost as if there's a typo in the registry key that's preventing it being read by the CMD prompt, but not by Windows.
I have no idea whether this will work, but it may be worth trying...
Open Regedit and navigate to the HKEY_USERS\S-1-5-20 key - highlight it and select Export
Change the Save as type option to 'Registry Hive files' and name it NPU - save it.
Compress the saved file, and post the compressed file.
I'll have a look at it and see if I can find out what's going on.
I'd have liked to export the whole HKU hive - but Windows won't do it
Ok here is the compressed HKEY_USERS\S-1-5-20 key saved as a Registry Hive file:
https://www.dropbox.com/s/4k7e1kgw1cb4vtn/NPU.zip