I did run the WMI uility and here's the output of that:
(Its obvious that there are some WMI issues)
C:\WINDOWS\temp>WMIDiag.vbs
Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
(0) ** Retrieving Run-time environment information.
(0) ** LOG file "C:\WINDOWS\TEMP\WMIDIAG-V2.0_XP___.CLI.SP2.32_B2UVAM-PC1_2008.06.03_11.52.12.LOG" created.
(0) ** CSV file "C:\WINDOWS\TEMP\WMIDIAG-V2.0_XP___.CLI.SP2.32_B2UVAM-PC1_2008.06.03_11.52.12-STATISTICS.CSV" created.
(0) ** TXT file "C:\WINDOWS\TEMP\WMIDIAG-V2.0_XP___.CLI.SP2.32_B2UVAM-PC1_2008.06.03_11.52.12-REPORT.TXT" created.
(0) ** WMIDiag v2.0 started on Tuesday, June 03, 2008 at 11:52.
(0) **
(0) ** Copyright (c) Microsoft Corporation. All rights reserved - January 2007.
(0) **
(0) ** This script is not supported under any Microsoft standard support program or service.
(0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
(0) ** implied warranties including, without limitation, any implied warranties of merchantability
(0) ** or of fitness for a particular purpose. The entire risk arising out of the use or performance
(0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
(0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
(0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
(0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
(0) ** the use of or inability to use the script or documentation, even if Microsoft has been advised
(0) ** of the possibility of such damages.
(0) **
(0) ** Verifying last run of WMIDiag.
(0) ** WMIDiag last run is 6/3/2008 11:40:20 AM.
(0) ** Logging Run-time environment information.
(0) ** Initializing WMI System Information.
(0) ** Windows XP - Service pack 2 - 32-bit (XP___.CLI.SP2.32).
(0) ** Verifying computer environment.
(0) ** Verifying specific files presence.
(0) ** Verifying WMI System files presence at 'C:\WINDOWS\SYSTEM32\WBEM\'.
(0) ** Verifying WMI Repository files presence.
(0) ** Verifying additional binaries in WBEM folder.
(0) ** Verifying Auto-Recovery MOF files presence.
(0) ** Verifying MOF files in WBEM folder.
(0) ** Verifying '#PRAGMA AUTORECOVER' statement in MOF files.
(0) ** Verifying DCOM configuration.
(0) ** Verifying WMI DCOM component registrations.
(0) ** Verifying WMI DCOM component security.
(0) ** Verifying WMI ProgID registrations.
(0) ** Verifying Windows Firewall setup.
(0) ** Verifying WMI Core registry settings (WBEM).
(0) ** Verifying WMI Service registry settings (SVCHOST, WINMGMT).
(0) ** Verifying WMI Service known dependents.
(0) ** Verifying 'RPCSS' service status.
(0) ** Verifying 'WINMGMT' service status.
(0) ** Verifying WMI providers loaded BEFORE WMIDiag execution.
(0) ** Verifying WMI namespace 'Root' (L=1).
(0) ** Verifying WMI system settings.
(0) ** Verifying WMI namespace 'ROOT/SERVICEMODEL' (L=2).
(0) ** Verifying WMI namespace 'ROOT/SECURITY' (L=2).
(0) ** Verifying WMI namespace 'ROOT/CCM' (L=2).
(0) ** Verifying WMI namespace 'ROOT/CCM/VULNERABILITYASSESSMENT' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/EVENTS' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/INVAGT' (L=3).
(3) Busy (6/3/2008 11:54:01 AM) ...
(3) Busy (6/3/2008 11:55:02 AM) ...
(0) ** Verifying WMI namespace 'ROOT/CCM/SOFTMGMTAGENT' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/LOCATIONSERVICES' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/DATATRANSFERSERVICE' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/MESSAGING' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_2975769861_1472507233_1889847546_500' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_2975769861_1472507233_1889847546_500/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_2975769861_1472507233_1889847546_500/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTUSER' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTUSER/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTUSER/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/MACHINE' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/MACHINE/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/MACHINE/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1844237615_583907252_725345543_500' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1844237615_583907252_725345543_500/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1844237615_583907252_725345543_500/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_282250' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_282250/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_282250/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_136180' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_136180/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_136180/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTMACHINE' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTMACHINE/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/DEFAULTMACHINE/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_310576' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_310576/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_310576/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_224827' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_224827/REQUESTEDCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/POLICY/S_1_5_21_1614895754_823518204_725345543_224827/ACTUALCONFIG' (L=5).
(0) ** Verifying WMI namespace 'ROOT/CCM/SOFTWAREMETERINGAGENT' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/CONTENTTRANSFERMANAGER' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CCM/SCHEDULER' (L=3).
(0) ** Verifying WMI namespace 'ROOT/RSOP' (L=2).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER' (L=3).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_2975769861_1472507233_1889847546_500' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_1844237615_583907252_725345543_500' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_1614895754_823518204_725345543_282250' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_1614895754_823518204_725345543_136180' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_1614895754_823518204_725345543_310576' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/USER/S_1_5_21_1614895754_823518204_725345543_224827' (L=4).
(0) ** Verifying WMI namespace 'ROOT/RSOP/COMPUTER' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CLI' (L=2).
(0) ** Verifying WMI namespace 'ROOT/ASPNET' (L=2).
(0) ** Verifying WMI namespace 'ROOT/SECURITYCENTER' (L=2).
(0) ** Verifying WMI namespace 'ROOT/WMI' (L=2).
(0) ** Verifying WMI namespace 'ROOT/CIMV2' (L=2).
(3) Busy (6/3/2008 11:59:09 AM) ...
(0) ** Verifying WMI namespace 'ROOT/CIMV2/SMS' (L=3).
(3) Busy (6/3/2008 11:59:57 AM) ...
(0) ** Verifying WMI namespace 'ROOT/CIMV2/SMS/DELTA' (L=4).
(0) ** Verifying WMI namespace 'ROOT/CIMV2/APPLICATIONS' (L=3).
(0) ** Verifying WMI namespace 'ROOT/CIMV2/APPLICATIONS/MICROSOFTIE' (L=4).
(0) ** Verifying WMI namespace 'ROOT/POLICY' (L=2).
(0) ** Verifying WMI namespace 'ROOT/SMSDM' (L=2).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT' (L=2).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT/HOMENET' (L=3).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT/SQLSERVER' (L=3).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT/SQLSERVER/COMPUTERMANAGEMENT' (L=4).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT/SQLSERVER/SERVEREVENTS' (L=4).
(0) ** Verifying WMI namespace 'ROOT/MICROSOFT/SQLSERVER/SERVEREVENTS/MSSQLSERVER' (L=5).
(0) ** Verifying WMI namespace 'ROOT/DEFAULT' (L=2).
(0) ** Verifying WMI namespace 'ROOT/DIRECTORY' (L=2).
(0) ** Verifying WMI namespace 'ROOT/DIRECTORY/LDAP' (L=3).
(0) ** Verifying WMI namespace 'ROOT/SUBSCRIPTION' (L=2).
(0) ** Verifying WMI namespace 'ROOT/MSAPPS11' (L=2).
(0) ** Verifying WMI ADAP status.
(0) ** Verifying WMI features.
(0) ** Verifying SMS Agent v2.50.4253 WMI features.
(0) ** Collecting system information.
(0) ** - Disk information
(0) ** - Network information
(0) ** - IRQ resource usage
(0) ** - DMA resource usage
(0) ** - Memory information
(0) ** - Processor information
(0) ** - Operating System information
(0) ** - Services information
(0) ** - WMI Binary files information
(0) ** - NT Event Log information
(0) ** Verifying WMI providers loaded AFTER WMIDiag execution.
(0) ** Verifying WMI Repository files presence.
(0) ** WMIDiag v2.0 completed.
(0) **
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** ----------------------------------------------------- WMI REPORT: BEGIN -------------------------------------------------
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) **
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** Windows XP - Service pack 2 - 32-bit (2600) - User 'FANNIEMAE\B2UVAM' on computer 'B2UVAM-PC1'.
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** INFO: Environment: .................................................................................................. 1 I
(0) ** INFO: => 3 incorrect shutdown(s) detected on:
(0) ** - Shutdown on 29 May 2008 15:27:06 (GMT+4).
(0) ** - Shutdown on 30 May 2008 13:20:40 (GMT+4).
(0) ** - Shutdown on 01 June 2008 14:08:40 (GMT+4).
(0) **
(0) ** System drive: ....................................................................................................... C:
tition #0).
(0) ** Drive type: ......................................................................................................... IDE
S721060G9SA00).
(0) ** There are no missing WMI system files: .............................................................................. OK.
(0) ** There are no missing WMI repository files: .......................................................................... OK.
(0) ** WMI repository state: ............................................................................................... NOT
(0) ** BEFORE running WMIDiag:
(0) ** The WMI repository has a size of: ................................................................................... 54
(0) ** - Disk free space on 'C:': .......................................................................................... 711
(0) ** - INDEX.BTR, 10805248 bytes, 6/3/2008 11:52:04 AM
(0) ** - INDEX.MAP, 5780 bytes, 6/3/2008 11:52:04 AM
(0) ** - MAPPING.VER, 4 bytes, 6/3/2008 11:52:04 AM
(0) ** - MAPPING1.MAP, 32856 bytes, 6/3/2008 11:51:34 AM
(0) ** - MAPPING2.MAP, 32856 bytes, 6/3/2008 11:52:04 AM
(0) ** - OBJECTS.DATA, 46235648 bytes, 6/3/2008 11:52:04 AM
(0) ** - OBJECTS.MAP, 27320 bytes, 6/3/2008 11:52:04 AM
(0) ** AFTER running WMIDiag:
(0) ** The WMI repository has a size of: ................................................................................... 54
(0) ** - Disk free space on 'C:': .......................................................................................... 680
(0) ** - INDEX.BTR, 10805248 bytes, 6/3/2008 12:03:13 PM
(0) ** - INDEX.MAP, 5780 bytes, 6/3/2008 12:03:14 PM
(0) ** - MAPPING.VER, 4 bytes, 6/3/2008 12:03:14 PM
(0) ** - MAPPING1.MAP, 32856 bytes, 6/3/2008 12:03:14 PM
(0) ** - MAPPING2.MAP, 32856 bytes, 6/3/2008 12:03:05 PM
(0) ** - OBJECTS.DATA, 46235648 bytes, 6/3/2008 12:03:13 PM
(0) ** - OBJECTS.MAP, 27320 bytes, 6/3/2008 12:03:14 PM
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** INFO: Windows Firewall status: ...................................................................................... ENA
(0) ** Windows Firewall Profile: ........................................................................................... DOM
(0) ** -------------------------------------------------------------------------------------------------------------------------
(2) !! WARNING: DCOM Status: ............................................................................................... WAR
(2) !! WARNING: => The DCOM Default Impersonation is NOT set to 'Identify'.
(0) ** This could prevent WMI to work correctly.
(0) ** You can fix the DCOM configuration by:
(0) ** - Executing the 'DCOMCNFG.EXE' command.
(0) ** - Expanding 'Component Services' and 'Computers' nodes.
(0) ** - Editing properties of 'My Computer' node.
(0) ** - Editing the 'Default properties' tab.
(0) ** - Set the 'Default Impersonation level' listbox to 'Identify'.
(0) ** From the command line, the DCOM configuration can be corrected with the following command:
(0) ** i.e. 'REG.EXE Add HKLM\SOFTWARE\Microsoft\Ole /v LegacyImpersonationLevel /t REG_DWORD /d 2 /f'
(0) **
(0) ** WMI registry setup: ................................................................................................. OK.
(0) ** INFO: WMI service has dependents: ................................................................................... 3 S
(0) ** - Security Center (WSCSVC, StartMode='Automatic')
(0) ** - Windows Firewall/Internet Connection Sharing (ICS) (SHAREDACCESS, StartMode='Automatic')
(0) ** - SMS Agent Host (CCMEXEC, StartMode='Automatic')
(0) ** => If the WMI service is stopped, the listed service(s) will have to be stopped as well.
(0) ** Note: If the service is marked with (*), it means that the service/application uses WMI but
(0) ** there is no hard dependency on WMI. However, if the WMI service is stopped,
(0) ** this can prevent the service/application to work as expected.
(0) **
(0) ** RPCSS service: ...................................................................................................... OK
rted).
(0) ** WINMGMT service: .................................................................................................... OK
rted).
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** WMI service DCOM setup: ............................................................................................. OK.
(2) !! WARNING: WMI DCOM components registration is missing for the following EXE/DLLs: .................................... 10
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPINCL.DLL (\CLSID\{19C813AC-FEE7-11D0-AB22-00C04FD9159E}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPINCL.DLL (\CLSID\{1F517A23-B29C-11CF-8C8D-00AA00A4086C}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPINCL.DLL (\CLSID\{70426720-F78F-11CF-9151-00AA00A4086C}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPINCL.DLL (\CLSID\{9D5BED16-0765-11D1-AB2C-00C04FD9159E}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{5009AB90-F9EE-11CF-AEC1-00AA00BDD7D1}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{5009AB92-F9EE-11CF-AEC1-00AA00BDD7D1}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{5009AB94-F9EE-11CF-AEC1-00AA00BDD7D1}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{5009AB9B-F9EE-11CF-AEC1-00AA00BDD7D1}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{B11B26AC-A791-11D0-AAEA-00A024E8AD1C}\InProcServer32)
(0) ** - C:\WINDOWS\SYSTEM32\WBEM\SNMPSMIR.DLL (\CLSID\{B11B26AE-A791-11D0-AAEA-00A024E8AD1C}\InProcServer32)
(0) ** => WMI System components are not properly registered as COM objects, which could make WMI to
(0) ** fail depending on the operation requested.
(0) ** => For a .DLL, you can correct the DCOM configuration by executing the 'REGSVR32.EXE ' command.
(0) **
(0) ** WMI ProgID registrations: ........................................................................................... OK.
(0) ** WMI provider DCOM registrations: .................................................................................... OK.
(2) !! WARNING: WMI provider CIM registrations missing for the following provider(s): ...................................... 3 W
(0) ** - ROOT/CIMV2/SMS, MS_VIEW_INSTANCE_PROVIDER (i.e. WMI Class 'Win32_USBDevice')
(0) ** MOF Registration: 'C:\WINDOWS\SYSTEM32\WBEM\IISWMI.MOF'
(0) ** - ROOT/CIMV2/SMS, SoftwareLicensingProduct_Provider (i.e. WMI Class 'SoftwareLicensingProduct')
(0) ** MOF Registration: 'WMI information not available (This could be the case for an external application or a third party W
'
(0) ** - ROOT/CIMV2/SMS, SoftwareLicensingService_Provider (i.e. WMI Class 'SoftwareLicensingService')
(0) ** MOF Registration: 'WMI information not available (This could be the case for an external application or a third party W
'
(0) ** => This is an issue because there are still some WMI classes referencing this list of providers
(0) ** while the CIM registration is wrong or missing. This can be due to:
(0) ** - a de-installation of the software.
(0) ** - a deletion of some CIM registration information.
(0) ** => You can correct the CIM configuration by:
(0) ** - Manually recompiling the MOF file(s) with the 'MOFCOMP ' command.
(0) ** Note: You can build a list of classes in relation with their WMI provider and MOF file with WMIDiag.
(0) ** (This list can be built on a similar and working WMI Windows installation)
(0) ** The following command line must be used:
(0) ** i.e. 'WMIDiag CorrelateClassAndProvider'
(0) ** - Re-installing the software.
(0) ** => If the software has been de-installed intentionally, then this information must be
(0) ** removed from the WMI repository. You can use the 'WMIC.EXE' command to remove the provider
(0) ** registration data and its set of associated classes.
(0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\CIMV2\SMS path __Win32Provider Where Name='SoftwareLicensingService_Provider' DELETE'
(0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\CIMV2\SMS Class SoftwareLicensingService DELETE'
(0) ** => If the namespace was ENTIRELY dedicated to the intentionally de-installed software,
(0) ** the namespace and ALL its content can be ENTIRELY deleted.
(0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\CIMV2 path __NAMESPACE Where Name='SMS' DELETE'
(0) **
(0) ** WMI provider CLSIDs: ................................................................................................ OK.
(0) ** WMI providers EXE/DLL availability: ................................................................................. OK.
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ..................................................................... MOD
(1) !! ERROR: Actual trustee 'NT AUTHORITY\NETWORK SERVICE' DOES NOT match corresponding expected trustee rights (Actual->Defaul
(0) ** - ACTUAL ACE:
(0) ** ACEType: &h0
(0) ** ACCESS_ALLOWED_ACE_TYPE
(0) ** ACEFlags: &h2
(0) ** CONTAINER_INHERIT_ACE
(0) ** ACEMask: &h1
(0) ** WBEM_ENABLE
(0) ** - EXPECTED ACE:
(0) ** ACEType: &h0
(0) ** ACCESS_ALLOWED_ACE_TYPE
(0) ** ACEFlags: &h12
(0) ** CONTAINER_INHERIT_ACE
(0) ** INHERITED_ACE
(0) ** ACEMask: &h13
(0) ** WBEM_ENABLE
(0) ** WBEM_METHOD_EXECUTE
(0) ** WBEM_WRITE_PROVIDER
(0) **
(0) ** => The actual ACE has the right(s) '&h12 WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
(0) ** This will cause some operations to fail!
(0) ** It is possible to fix this issue by editing the security descriptor and adding the removed right.
(0) ** For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
(0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
(0) ** The security diagnostic is based on the WMI namespace expected defaults.
(0) ** A specific WMI application can always require a security setup different
(0) ** than the WMI security defaults.
(0) **
(0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ..................................................................... MOD
(1) !! ERROR: Actual trustee 'NT AUTHORITY\LOCAL SERVICE' DOES NOT match corresponding expected trustee rights (Actual->Default)
(0) ** - ACTUAL ACE:
(0) ** ACEType: &h0
(0) ** ACCESS_ALLOWED_ACE_TYPE
(0) ** ACEFlags: &h2
(0) ** CONTAINER_INHERIT_ACE
(0) ** ACEMask: &h1
(0) ** WBEM_ENABLE
(0) ** - EXPECTED ACE:
(0) ** ACEType: &h0
(0) ** ACCESS_ALLOWED_ACE_TYPE
(0) ** ACEFlags: &h12
(0) ** CONTAINER_INHERIT_ACE
(0) ** INHERITED_ACE
(0) ** ACEMask: &h13
(0) ** WBEM_ENABLE
(0) ** WBEM_METHOD_EXECUTE
(0) ** WBEM_WRITE_PROVIDER
(0) **
(0) ** => The actual ACE has the right(s) '&h12 WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
(0) ** This will cause some operations to fail!
(0) ** It is possible to fix this issue by editing the security descriptor and adding the removed right.
(0) ** For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
(0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
(0) ** The security diagnostic is based on the WMI namespace expected defaults.
(0) ** A specific WMI application can always require a security setup different
(0) ** than the WMI security defaults.
(0) **
(0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ..................................................................... MOD
(1) !! ERROR: Default trustee 'EVERYONE' has been REMOVED!
(0) ** - REMOVED ACE:
(0) ** ACEType: &h0
(0) ** ACCESS_ALLOWED_ACE_TYPE
(0) ** ACEFlags: &h12
(0) ** CONTAINER_INHERIT_ACE
(0) ** INHERITED_ACE
(0) ** ACEMask: &h13
(0) ** WBEM_ENABLE
(0) ** WBEM_METHOD_EXECUTE
(0) ** WBEM_WRITE_PROVIDER
(0) **
(0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
(0) ** Removing default security will cause some operations to fail!
(0) ** It is possible to fix this issue by editing the security descriptor and adding the ACE.
(0) ** For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
(0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
(0) ** The security diagnostic is based on the WMI namespace expected defaults.
(0) ** A specific WMI application can always require a security setup different
(0) ** than the WMI security defaults.
(0) **
(0) **
(0) ** DCOM security warning(s) detected: .................................................................................. 0.
(0) ** DCOM security error(s) detected: .................................................................................... 0.
(0) ** WMI security warning(s) detected: ................................................................................... 0.
(0) ** WMI security error(s) detected: ..................................................................................... 3.
(0) **
(0) ** Overall DCOM security status: ....................................................................................... OK.
(1) !! ERROR: Overall WMI security status: ................................................................................. ERR
(0) ** - Started at 'Root' -----------------------------------------------------------------------------------------------------
(0) ** INFO: WMI permanent SUBSCRIPTION(S): ................................................................................ 6.
(0) ** - ROOT/CCM/POLICY, CCM_PolicyReplicationConsumer.Id="{9099D177-1AD6-46e6-BBC0-70F460786953}".
(0) ** 'SELECT * FROM __ClassOperationEvent WHERE TargetClass ISA "CCM_Policy_Config"'
(0) ** - ROOT/CCM/POLICY, CCM_PolicyReplicationConsumer.Id="{9099D177-1AD6-46e6-BBC0-70F460786953}".
(0) ** 'SELECT * FROM __NamespaceCreationEvent'
(0) ** - ROOT/CCM/POLICY, CCM_PolicyReplicationConsumer.Id="{9099D177-1AD6-46e6-BBC0-70F460786953}".
(0) ** 'SELECT * FROM __ClassOperationEvent WHERE TargetClass ISA "CCM_Policy"'
(0) ** - ROOT/CCM/POLICY, CCM_PolicyReplicationConsumer.Id="{9099D177-1AD6-46e6-BBC0-70F460786953}".
(0) ** 'SELECT * FROM __ClassOperationEvent WHERE TargetClass ISA "CCM_Policy_EmbeddedObject"'
(0) ** - ROOT/SUBSCRIPTION, MSFT_UCScenarioControl.Name="Microsoft WMI Updating Consumer Scenario Control".
(0) ** 'SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'MSFT_UCScenario''
(0) ** - ROOT/SUBSCRIPTION, NTEventLogEventConsumer.Name="SCM Event Log Consumer".
(0) ** 'select * from MSFT_SCMEventLogEvent'
(0) **
(0) ** WMI TIMER instruction(s): ........................................................................................... NON
(0) ** INFO: WMI ADAP status: .............................................................................................. 2.
(0) ** => The WMI ADAP process is processing a performance library (2).
(0) ** Some WMI performance classes could be missing at the time WMIDiag was executed.
(0) ** INFO: WMI namespace(s) requiring PACKET PRIVACY: .................................................................... 1 N
(0) ** - ROOT/SERVICEMODEL.
(0) ** => When remotely connecting, the namespace(s) listed require(s) the WMI client to
(0) ** use an encrypted connection by specifying the PACKET PRIVACY authentication level.
(0) ** (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy flags)
(0) ** i.e. 'WMIC.EXE /NODE:"B2UVAM-PC1" /AUTHLEVEL:Pktprivacy /NAMESPACE:\\ROOT\SERVICEMODEL Class __SystemSecurity'
(0) **
(0) ** WMI MONIKER CONNECTIONS: ............................................................................................ OK.
(0) ** WMI CONNECTIONS: .................................................................................................... OK.
(1) !! ERROR: WMI GET operation errors reported: ........................................................................... 4 E
(0) ** - Root/CIMv2, Win32_PerfRawData_PerfProc_Process, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
(0) ** MOF Registration: 'No located MOF file (exception)'
(0) ** - Root/CIMv2, Win32_PerfRawData_PerfProc_Thread, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
(0) ** MOF Registration: 'No located MOF file (exception)'
(0) ** - Root/CIMv2, Win32_PerfFormattedData_PerfProc_Process, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
(0) ** MOF Registration: 'C:\WINDOWS\SYSTEM32\WBEM\WMI.MOF'
(0) ** - Root/CIMv2, Win32_PerfFormattedData_PerfProc_Thread, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
(0) ** MOF Registration: 'C:\WINDOWS\SYSTEM32\WBEM\WMI.MOF'
(0) ** => When a WMI performance class is missing (i.e. 'Win32_PerfFormattedData_PerfProc_Thread'), it is generally due to
(0) ** a synchronization issue between the performance counters and WMI.
(0) ** The AutoDiscovery/AutoPurge (ADAP) process logs informative events in the Windows NT event log.
(0) ** More information can be found on MSDN at:
(0) **
(0) ** - The last time the ADAP process was STARTED was the '02 June 2008 20:30:05:062000 (GMT+5)'.
(0) ** - The last time the ADAP process was STOPPED was the '02 June 2008 12:19:30:484000 (GMT+5)'.
(0) ** - The latest ADAP process status is 'The WMI ADAP process is processing a performance library (2).'.
(0) **
(0) ** You can attempt to resynchronize the WMI performance classes with the existing Windows
(0) ** performance counters with the following commands:
(0) ** i.e. 'WINMGMT.EXE /CLEARADAP'
(0) ** i.e. 'WINMGMT.EXE /RESYNCPERF'
(0) **
(0) ** WMI MOF representations: ............................................................................................ OK.
(0) ** WMI QUALIFIER access operations: .................................................................................... OK.
(1) !! ERROR: WMI ENUMERATION operation errors reported: ................................................................... 1 E
(0) ** - ROOT/CIMV2/SMS, InstancesOfAsync, 'SMS_Class_Template', 0x80041011 - (WBEM_E_PROVIDER_NOT_FOUND) Provider referenced in
does not have a corresponding registration.
(0) ** MOF Registration: 'WMI information not available (This could be the case for an external application or a third party W
'
(0) **
(0) ** WMI EXECQUERY operations: ........................................................................................... OK.
(0) ** WMI GET VALUE operations: ........................................................................................... OK.
(0) ** WMI WRITE operations: ............................................................................................... NOT
(0) ** WMI PUT operations: ................................................................................................. NOT
(0) ** WMI DELETE operations: .............................................................................................. NOT
(0) ** WMI static instances retrieved: ..................................................................................... 515
(0) ** WMI dynamic instances retrieved: .................................................................................... 0.
(0) ** WMI instance request cancellations (to limit performance impact): ................................................... 2.
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** # of Event Log events BEFORE WMIDiag execution since the last 20 day(s):
(0) ** DCOM: ............................................................................................................. 18.
(0) ** WINMGMT: .......................................................................................................... 18.
(0) ** WMIADAPTER: ....................................................................................................... 0.
(0) ** => Verify the WMIDiag LOG at line #45031 for more details.
(0) **
(0) ** # of additional Event Log events AFTER WMIDiag execution:
(0) ** DCOM: ............................................................................................................. 0.
(0) ** WINMGMT: .......................................................................................................... 0.
(0) ** WMIADAPTER: ....................................................................................................... 0.
(0) **
(0) ** 4 error(s) 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found
(0) ** => This error is typically a WMI error. This WMI error is due to:
(0) ** - a missing WMI class definition or object.
(0) ** (See any GET, ENUMERATION, EXECQUERY and GET VALUE operation failures).
(0) ** You can correct the missing class definitions by:
(0) ** - Manually recompiling the MOF file(s) with the 'MOFCOMP ' command.
(0) ** Note: You can build a list of classes in relation with their WMI provider and MOF file with WMIDiag.
(0) ** (This list can be built on a similar and working WMI Windows installation)
(0) ** The following command line must be used:
(0) ** i.e. 'WMIDiag CorrelateClassAndProvider'
(0) ** Note: When a WMI performance class is missing, you can manually resynchronize performance counters
(0) ** with WMI by starting the ADAP process.
(0) ** - a WMI repository corruption.
(0) ** Under Windows XP SP2, you can validate the repository consistency
(0) ** by executing the following command:
(0) ** i.e. 'WMIDiag CheckConsistency'
(0) ** Note: Under Windows XP SP2, when the repository is checked and detected INCONSISTENT,
(0) ** a new repository is automatically re-created based on Auto-Recovery mechanism.
(0) ** Note that some information can be lost during this process (i.e. static data, CIM registration).
(0) ** However, the original repository is located at 'C:\WINDOWS\SYSTEM32\WBEM\Repository.001'.
(0) ** The computer must be rebooted for the system to work with the re-created repository.
(0) ** Note: The WMI repository reconstruction requires to locate all MOF files needed to rebuild the repository,
(0) ** otherwise some applications may fail after the reconstruction.
(0) ** This can be achieved with the following command:
(0) ** i.e. 'WMIDiag ShowMOFErrors'
(0) ** Note: The repository reconstruction must be a LAST RESORT solution and ONLY after executing
(0) ** ALL fixes previously mentioned.
(2) !! WARNING: Static information stored by external applications in the repository will be LOST! (i.e. SMS Inventory)
(0) **
(0) **
(0) ** 1 error(s) 0x80041011 - (WBEM_E_PROVIDER_NOT_FOUND) Provider referenced in the schema does not have a corresponding regis
(0) ** => This error is typically due to the following major reasons:
(0) ** - The application queried by the WMI provider is not installed, not available or not running
(0) ** at the time of the request was made. This error can also be generated because
(0) ** the application supporting the providers has been uninstalled.
(0) ** - Some WMI providers (i.e. RSOP Planning Mode, Exchange 2003) are implemented as a WMI service.
(0) ** Make sure the required services are successfully started.
(0) ** - The WMI provider binary files are not accessible (i.e. access denied ACL).
(0) ** - A WMI provider registration problem at the CIM level (MOFCOMP.EXE) or at the COM level (REGSVR32.EXE).
(0) ** You must re-register the WMI provider by recompiling its associated MOF file with MOFCOMP.EXE
(0) ** Note: - If the WMI provider DLL CIM and COM registrations are correct, this error can
(0) ** be returned because the provider has a dependency on another DLL that cannot be
(0) ** loaded (missing or bad DLL)
(0) ** - Dependencies can be found with the DEPENDS.EXE tool coming with the
(0) ** Windows XP and Windows 2003 Support Tools. The command line is as follows:
(0) ** i.e. DEPENDS.EXE
(0) ** => If the software has been de-installed intentionally, then this information must be
(0) ** removed from the WMI repository. You can use the 'WMIC.EXE' command to remove the provider
(0) ** registration data and its set of associated classes.
(0) ** => To correct this situation, you can:
(0) ** - Install or start the application supporting these providers.
(0) ** - Register the providers in CIM (MOFCOMP) or DCOM (REGSVR32).
(0) ** Note: In this case the provider should also be listed in the 'missing WMI
(0) ** provider DCOM registrations' or in the 'missing WMI provider files' section.
(2) !! WARNING: Re-registering with REGSVR32.EXE all DLL from 'C:\WINDOWS\SYSTEM32\WBEM\'
(0) ** may not solve the problem as the DLL supporting the WMI class(es)
(0) ** can be located in a different folder.
(0) ** You must refer to the class name to determine the software delivering the related DLL.
(0) **
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** WMI Registry key setup: ............................................................................................. OK.
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) **
(0) ** -------------------------------------------------------------------------------------------------------------------------
(0) ** ------------------------------------------------------ WMI REPORT: END --------------------------------------------------
(0) ** -------------------------------------------------------------------------------------------------------------------------