WMI Issue?

  • Thread starter Thread starter Travis
  • Start date Start date


I believe I am having an issue with WMI on my Windows Vista HP 32-bit. The
issue was found when I was checking my System Information in my System Tools
from the Start>Programs>Accessories menu. It states "Can't Collect
Information/ Cannot access Windows Management Instrumentation software.
Windows Management files may be moved or missing." When I ran the WMIDiag
tool I get this log in notepad:

25978 22:16:07 (0) ** WMIDiag v2.0 started on Monday, October 15, 2007 at
25979 22:16:07 (0) **
25980 22:16:07 (0) ** Copyright (c) Microsoft Corporation. All rights
reserved - January 2007.
25981 22:16:07 (0) **
25982 22:16:07 (0) ** This script is not supported under any Microsoft
standard support program or service.
25983 22:16:07 (0) ** The script is provided AS IS without warranty of any
kind. Microsoft further disclaims all
25984 22:16:07 (0) ** implied warranties including, without limitation, any
implied warranties of merchantability
25985 22:16:07 (0) ** or of fitness for a particular purpose. The entire
risk arising out of the use or performance
25986 22:16:07 (0) ** of the scripts and documentation remains with you. In
no event shall Microsoft, its authors,
25987 22:16:07 (0) ** or anyone else involved in the creation, production,
or delivery of the script be liable for
25988 22:16:07 (0) ** any damages whatsoever (including, without limitation,
damages for loss of business profits,
25989 22:16:07 (0) ** business interruption, loss of business information,
or other pecuniary loss) arising out of
25990 22:16:07 (0) ** the use of or inability to use the script or
documentation, even if Microsoft has been advised
25991 22:16:07 (0) ** of the possibility of such damages.
25992 22:16:07 (0) **
25993 22:16:07 (0) **
25994 22:16:07 (0) **
25995 22:16:07 (0) ** -----------------------------------------------------
WMI REPORT: BEGIN ----------------------------------------------------------
25996 22:16:07 (0) **
25997 22:16:07 (0) **
25998 22:16:07 (0) **
25999 22:16:07 (0) ** Windows Vista - No service pack - 32-bit (6000) - User
'R2D2\TRAVIS' on computer 'R2D2'.
26000 22:16:07 (0) **
26001 22:16:07 (0) ** Environment:
......................................................................................................... OK..
26002 22:16:07 (0) ** There are no missing WMI system files:
............................................................................... OK.
26003 22:16:07 (0) ** There are no missing WMI repository files:
........................................................................... OK.
26004 22:16:07 (0) ** WMI repository state:
................................................................................................ CONSISTENT.
26005 22:16:07 (0) ** BEFORE running WMIDiag:
26006 22:16:07 (0) ** The WMI repository has a size of:
.................................................................................... 23 MB.
26007 22:16:07 (0) ** - Disk free space on 'C:':
........................................................................................... 68148 MB.
26008 22:16:07 (0) ** - INDEX.BTR, 2326528 bytes,
10/15/2007 10:00:54 PM
26009 22:16:07 (0) ** - MAPPING1.MAP, 69084 bytes,
10/15/2007 10:00:55 PM
26010 22:16:07 (0) ** - MAPPING2.MAP, 69084 bytes,
10/15/2007 9:59:54 PM
26011 22:16:07 (0) ** - OBJECTS.DATA, 21553152 bytes,
10/15/2007 10:00:54 PM
26012 22:16:07 (0) ** AFTER running WMIDiag:
26013 22:16:07 (0) ** The WMI repository has a size of:
.................................................................................... 23 MB.
26014 22:16:07 (0) ** - Disk free space on 'C:':
........................................................................................... 68144 MB.
26015 22:16:07 (0) ** - INDEX.BTR, 2326528 bytes,
10/15/2007 10:12:24 PM
26016 22:16:07 (0) ** - MAPPING1.MAP, 69084 bytes,
10/15/2007 10:00:55 PM
26017 22:16:07 (0) ** - MAPPING2.MAP, 69084 bytes,
10/15/2007 9:59:54 PM
26018 22:16:07 (0) ** - OBJECTS.DATA, 21553152 bytes,
10/15/2007 10:12:24 PM
26019 22:16:07 (0) **
26020 22:16:07 (2) !! WARNING: Windows Firewall:
........................................................................................... DISABLED.
26021 22:16:07 (0) **
26022 22:16:07 (0) ** DCOM Status:
......................................................................................................... OK.
26023 22:16:07 (0) ** WMI registry setup:
.................................................................................................. OK.
26024 22:16:07 (0) ** INFO: WMI service has dependents:
.................................................................................... 2 SERVICE(S)!
26025 22:16:07 (0) ** - Security Center (WSCSVC, StartMode='Automatic')
26026 22:16:07 (0) ** - Internet Connection Sharing (ICS) (SHAREDACCESS,
26027 22:16:07 (0) ** => If the WMI service is stopped, the listed
service(s) will have to be stopped as well.
26028 22:16:07 (0) ** Note: If the service is marked with (*), it means
that the service/application uses WMI but
26029 22:16:07 (0) ** there is no hard dependency on WMI. However,
if the WMI service is stopped,
26030 22:16:07 (0) ** this can prevent the service/application to
work as expected.
26031 22:16:07 (0) **
26032 22:16:07 (0) ** RPCSS service:
....................................................................................................... OK (Already started).
26033 22:16:07 (0) ** WINMGMT service:
..................................................................................................... OK (Already started).
26034 22:16:07 (0) **
26035 22:16:07 (0) ** WMI service DCOM setup:
.............................................................................................. OK.
26036 22:16:07 (0) ** WMI components DCOM registrations:
................................................................................... OK.
26037 22:16:07 (0) ** WMI ProgID registrations:
............................................................................................ OK.
26038 22:16:07 (0) ** WMI provider DCOM registrations:
..................................................................................... OK.
26039 22:16:07 (0) ** WMI provider CIM registrations:
...................................................................................... OK.
26040 22:16:07 (0) ** WMI provider CLSIDs:
................................................................................................. OK.
26041 22:16:07 (0) ** WMI providers EXE/DLL availability:
.................................................................................. OK.
26042 22:16:07 (0) **
26043 22:16:07 (0) ** INFO: User Account Control (UAC):
.................................................................................... DISABLED.
26044 22:16:07 (0) ** INFO: Local Account Filtering:
....................................................................................... ENABLED.
26045 22:16:07 (0) ** => WMI tasks remotely accessing WMI information on
this computer and requiring Administrative
26046 22:16:07 (0) ** privileges MUST use a DOMAIN account part of the
Local Administrators group of this computer
26047 22:16:07 (0) ** to ensure that administrative privileges are
granted. If a Local User account is used for remote
26048 22:16:07 (0) ** accesses, it will be reduced to a plain user
(filtered token), even if it is part of the Local Administrators group.
26049 22:16:07 (0) **
26050 22:16:07 (0) ** WMI namespace security for
............................................ MODIFIED.
26051 22:16:07 (1) !! ERROR: Default trustee 'EVERYONE' has been REMOVED!
26052 22:16:07 (0) ** - REMOVED ACE:
26053 22:16:07 (0) ** ACEType: &h0
26054 22:16:07 (0) ** ACCESS_ALLOWED_ACE_TYPE
26055 22:16:07 (0) ** ACEFlags: &h12
26056 22:16:07 (0) ** CONTAINER_INHERIT_ACE
26057 22:16:07 (0) ** INHERITED_ACE
26058 22:16:07 (0) ** ACEMask: &h1
26059 22:16:07 (0) ** WBEM_ENABLE
26060 22:16:07 (0) **
26061 22:16:07 (0) ** => The REMOVED ACE was part of the DEFAULT setup for
the trustee.
26062 22:16:07 (0) ** Removing default security will cause some
operations to fail!
26063 22:16:07 (0) ** It is possible to fix this issue by editing the
security descriptor and adding the ACE.
26064 22:16:07 (0) ** For WMI namespaces, this can be done with
26065 22:16:07 (0) **
26066 22:16:07 (0) **
26067 22:16:07 (0) ** DCOM security warning(s) detected:
................................................................................... 0.
26068 22:16:07 (0) ** DCOM security error(s) detected:
..................................................................................... 0.
26069 22:16:07 (0) ** WMI security warning(s) detected:
.................................................................................... 0.
26070 22:16:07 (0) ** WMI security error(s) detected:
...................................................................................... 1.
26071 22:16:07 (0) **
26072 22:16:07 (0) ** Overall DCOM security status:
........................................................................................ OK.
26073 22:16:07 (1) !! ERROR: Overall WMI security status:
.................................................................................. ERROR!
26074 22:16:07 (0) ** - Started at 'Root'
26075 22:16:07 (0) ** INFO: WMI permanent SUBSCRIPTION(S):
................................................................................. 1.
26076 22:16:07 (0) ** - ROOT/SUBSCRIPTION, NTEventLogEventConsumer.Name="SCM
Event Log Consumer".
26077 22:16:07 (0) ** 'select * from MSFT_SCMEventLogEvent'
26078 22:16:07 (0) **
26079 22:16:07 (0) ** WMI TIMER instruction(s):
............................................................................................ NONE.
26080 22:16:07 (0) ** INFO: WMI namespace(s) requiring PACKET PRIVACY:
..................................................................... 2
26081 22:16:07 (0) ** - ROOT/CIMV2/SECURITY/MICROSOFTTPM.
26082 22:16:07 (0) ** - ROOT/SERVICEMODEL.
26083 22:16:07 (0) ** => When remotely connecting, the namespace(s) listed
require(s) the WMI client to
26084 22:16:07 (0) ** use an encrypted connection by specifying the
PACKET PRIVACY authentication level.
26085 22:16:07 (0) ** (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy flags)
26086 22:16:07 (0) ** i.e. 'WMIC.EXE /NODE:"R2D2" /AUTHLEVEL:Pktprivacy
26087 22:16:07 (0) **
26088 22:16:07 (0) ** WMI MONIKER CONNECTIONS:
............................................................................................. OK.
26089 22:16:07 (0) ** WMI CONNECTIONS:
..................................................................................................... OK.
26090 22:16:07 (1) !! ERROR: WMI GET operation errors reported:
10 ERROR(S)!
26091 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26092 22:16:07 (0) ** MOF Registration:
26093 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26094 22:16:07 (0) ** MOF Registration:
26095 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26096 22:16:07 (0) ** MOF Registration:
26097 22:16:07 (0) ** - Root/CIMV2, Win32_Service='WSCSVC', 0x80070005 -
Access is denied..
26098 22:16:07 (0) ** MOF Registration:
26099 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26100 22:16:07 (0) ** MOF Registration:
26101 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26102 22:16:07 (0) ** MOF Registration:
26103 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=5128, 0x80070005 -
Access is denied..
26104 22:16:07 (0) ** MOF Registration:
26105 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=1164, 0x80070005 -
Access is denied..
26106 22:16:07 (0) ** MOF Registration:
26107 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=5128, 0x80070005 -
Access is denied..
26108 22:16:07 (0) ** MOF Registration:
26109 22:16:07 (0) ** - Root/CIMv2, Win32_Process.Handle=5128, 0x80070005 -
Access is denied..
26110 22:16:07 (0) ** MOF Registration:
26111 22:16:07 (0) **
26112 22:16:07 (0) ** WMI MOF representations:
............................................................................................. OK.
26113 22:16:07 (0) ** WMI QUALIFIER access operations:
..................................................................................... OK.
26114 22:16:07 (1) !! ERROR: WMI ENUMERATION operation errors reported:
.................................................................... 24
26115 22:16:07 (0) ** - ROOT/CIMV2, InstancesOfAsync, 'CIM_USBDevice',
0x80070005 - .
26116 22:16:07 (0) ** MOF Registration: 'WMI information not available
(This could be the case for an external application or a third party WMI
26117 22:16:07 (0) ** - ROOT/CIMV2, InstancesOfAsync, 'CIM_USBHub',
0x80070005 - .
26118 22:16:07 (0) ** MOF Registration: 'WMI information not available
(This could be the case for an external application or a third party WMI
26119 22:16:07 (0) ** - ROOT/CIMV2, InstancesOfAsync, 'CIM_StorageVolume',
0x80070005 - .
26120 22:16:07 (0) ** MOF Registration: 'WMI information not available
(This could be the case for an external application or a third party WMI
26121 22:16:07 (0) ** - Root/CIMV2, InstancesOf, 'Win32_ComputerSystem',
0x80070005 - Access is denied..
26122 22:16:07 (0) ** MOF Registration:
26123 22:16:07 (0) ** - Root/CIMV2, InstancesOf, 'Win32_Service', 0x80070005
- Access is denied..
26124 22:16:07 (0) ** MOF Registration:
26125 22:16:07 (0) ** - Root/CIMV2, InstancesOf, 'Win32_Process', 0x80070005
- Access is denied..
26126 22:16:07 (0) ** MOF Registration:
26127 22:16:07 (0) ** - Root/CIMV2, InstancesOf, 'Win32_OperatingSystem',
0x80070005 - Access is denied..
26128 22:16:07 (0) ** MOF Registration:
26129 22:16:07 (0) ** - Root/CIMV2, InstancesOf, 'Win32_BIOS', 0x80070005 -
Access is denied..
26130 22:16:07 (0) ** MOF Registration:
26131 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Cache', 0x80070005 - Access is denied..
26132 22:16:07 (0) ** MOF Registration:
26133 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Memory', 0x80070005 - Access is denied..
26134 22:16:07 (0) ** MOF Registration:
26135 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Objects', 0x80070005 - Access is denied..
26136 22:16:07 (0) ** MOF Registration:
26137 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_PagingFile', 0x80070005 - Access is denied..
26138 22:16:07 (0) ** MOF Registration:
26139 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Processor', 0x80070005 - Access is denied..
26140 22:16:07 (0) ** MOF Registration:
26141 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_System', 0x80070005 - Access is denied..
26142 22:16:07 (0) ** MOF Registration:
26143 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfProc_Process', 0x80070005 - Access is denied..
26144 22:16:07 (0) ** MOF Registration:
26145 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfProc_Thread', 0x80070005 - Access is denied..
26146 22:16:07 (0) ** MOF Registration:
26147 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_ICMP', 0x80070005 - Access is denied..
26148 22:16:07 (0) ** MOF Registration:
26149 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_ICMPv6', 0x80070005 - Access is denied..
26150 22:16:07 (0) ** MOF Registration:
26151 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_IPv4', 0x80070005 - Access is denied..
26152 22:16:07 (0) ** MOF Registration:
26153 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_IPv6', 0x80070005 - Access is denied..
26154 22:16:07 (0) ** MOF Registration:
26155 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_TCPv4', 0x80070005 - Access is denied..
26156 22:16:07 (0) ** MOF Registration:
26157 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_TCPv6', 0x80070005 - Access is denied..
26158 22:16:07 (0) ** MOF Registration:
26159 22:16:07 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_UDPv4', 0x80070005 - Access is denied..
26160 22:16:08 (0) ** MOF Registration:
26161 22:16:08 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_UDPv6', 0x80070005 - Access is denied..
26162 22:16:08 (0) ** MOF Registration:
26163 22:16:08 (0) **
26164 22:16:08 (1) !! ERROR: WMI EXECQUERY operation errors reported:
...................................................................... 17
26165 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_LogicalDisk WHERE
FreeSpace > 10000000 AND DriveType = 3, 0x80070005 - Access is denied..
26166 22:16:08 (0) ** - Root/CIMV2, Select DriveType From Win32_LogicalDisk
WHERE Name='C:', 0x80070005 - Access is denied..
26167 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_Service, 0x80070005
- Access is denied..
26168 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_PageFileUsage,
0x80070005 - Access is denied..
26169 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_BIOS WHERE Version
IS NOT NULL, 0x80070005 - Access is denied..
26170 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_NetworkAdapter WHERE
AdapterType IS NOT NULL AND AdapterType != "Wide Area Network (WAN)" AND
Description != "Packet Scheduler Miniport", 0x80070005 - Access is denied..
26171 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_Processor WHERE Name
IS NOT NULL, 0x80070005 - Access is denied..
26172 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_DiskDrive,
0x80070005 - Access is denied..
26173 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_ComputerSystem,
0x80070005 - Access is denied..
26174 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_DiskPartition,
0x80070005 - Access is denied..
26175 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_LogicalDisk WHERE
Description != "Network Connection", 0x80070005 - Access is denied..
26176 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_VideoController,
0x80070005 - Access is denied..
26177 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_USBController,
0x80070005 - Access is denied..
26178 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_DesktopMonitor,
0x80070005 - Access is denied..
26179 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_PointingDevice WHERE
Status = "OK", 0x80070005 - Access is denied..
26180 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_Keyboard, 0x80070005
- Access is denied..
26181 22:16:08 (0) ** - Root/CIMV2, Select * From Win32_SystemDriver WHERE
StartMode != "Disabled", 0x80070005 - Access is denied..
26182 22:16:08 (0) **
26183 22:16:08 (0) ** WMI GET VALUE operations:
............................................................................................ OK.
26184 22:16:08 (0) ** WMI WRITE operations:
................................................................................................ NOT TESTED.
26185 22:16:08 (0) ** WMI PUT operations:
.................................................................................................. NOT TESTED.
26186 22:16:08 (0) ** WMI DELETE operations:
............................................................................................... NOT TESTED.
26187 22:16:08 (0) ** WMI static instances retrieved:
...................................................................................... 1539.
26188 22:16:08 (0) ** WMI dynamic instances retrieved:
..................................................................................... 0.
26189 22:16:08 (0) ** WMI instance request cancellations (to limit
performance impact): ................................................... 1.
26190 22:16:08 (0) **
26191 22:16:08 (0) ** # of Event Log events BEFORE WMIDiag execution since
the last 20 day(s):
26192 22:16:08 (0) ** DCOM:
.............................................................................................................. ERROR!
26193 22:16:08 (0) ** WINMGMT:
........................................................................................................... ERROR!
26194 22:16:08 (0) ** WMIADAPTER:
........................................................................................................ ERROR!
26195 22:16:08 (0) **
26196 22:16:08 (0) ** # of additional Event Log events AFTER WMIDiag
26197 22:16:08 (0) ** DCOM:
.............................................................................................................. ERROR!
26198 22:16:08 (0) ** WINMGMT:
........................................................................................................... ERROR!
26199 22:16:08 (0) ** WMIADAPTER:
........................................................................................................ ERROR!
26200 22:16:08 (0) **
26201 22:16:08 (0) ** 51 error(s) 0x80070005 - (WBEM_UNKNOWN) This error
code is external to WMI.
26202 22:16:08 (0) ** => This error is not a WMI error. It is typically due
26203 22:16:08 (0) ** - The DCOM security modifications.
26204 22:16:08 (0) ** => Ensure that DCOM security configuration
settings are not modified.
26205 22:16:08 (0) ** - The user running WMIDiag has not enough
privileges or rights to issue requests
26206 22:16:08 (0) ** against software components exposing information
through WMI.
26207 22:16:08 (0) ** => Ensure that no third party applications
installing additional WMI providers have
26208 22:16:08 (0) ** specific security requirements (i.e. group
membership, privileges, etc ...)
26209 22:16:08 (0) ** - The 'Impersonate Client after authentication'
Local Policy is disabled or the
26210 22:16:08 (0) ** 'SERVICE' account has been removed from that
Local Policy.
26211 22:16:08 (0) ** => You must add the 'SERVICE' account to the
'Impersonate Client after authentication'
26212 22:16:08 (0) ** Local Policy in the 'Local Policies/User Right
Assignments' MMC snap-in (GPEDIT.MSC).
26213 22:16:08 (0) ** By default, this Local Policy includes the
'SERVICE' account.
26214 22:16:08 (0) **
26215 22:16:08 (0) ** => Errors starting with 0x8007 are Win32 errors, NOT
WMI errors. More information can be found
26216 22:16:08 (0) ** with the 'NET.EXE HELPMSG <dddd>' command, where
<dddd> is the last four hex digits (0x0005)
26217 22:16:08 (0) ** converted in decimal (5).
26218 22:16:08 (0) ** - NET HELPMSG 5
26219 22:16:08 (0) **
26220 22:16:08 (0) **
26221 22:16:08 (0) ** WMI Registry key setup:
.............................................................................................. OK.
26222 22:16:08 (0) **
26223 22:16:08 (0) **
26224 22:16:08 (0) **
26225 22:16:08 (0) **
26226 22:16:08 (0) **
26227 22:16:08 (0) **
26228 22:16:08 (0) ** ------------------------------------------------------
WMI REPORT: END -----------------------------------------------------------
26229 22:16:08 (0) **
26230 22:16:08 (0) **
26231 22:16:08 (0) ** ERROR: WMIDiag detected issues that could prevent WMI
to work properly!. Check
'C:\USERS\TRAVIS\APPDATA\LOCAL\TEMP\WMIDIAG-V2.0_VISTA.CLI.RTM.32_R2D2_2007.10.15_22.08.29.LOG' for details.
26232 22:16:08 (0) **
26233 22:16:08 (0) ** WMIDiag v2.0 ended on Monday, October 15, 2007 at
22:16 (W:64 E:81 S:1).

I've also noticed my system information doesn't generate when I view the
specs from My Computer>Properties window. Any assistance on this would be
helpful. So far I've tried stopping the service and deleting the repository
to let Windows replace it automatically (and it does), and upon startup after
rebooting it attempts to populate the information of System Information
window but then just keeps trying to "gather" the information but generates
nothing. Thank you for your time.
It sounds like the log is reporting the info you require:

> ----------------------------------------------------------------------------------------------------------------------------------
> 26043 22:16:07 (0) ** INFO: User Account Control (UAC):
> ...................................................................................

> 26051 22:16:07 (1) !! ERROR: Default trustee 'EVERYONE' has been REMOVED!
> 26061 22:16:07 (0) ** => The REMOVED ACE was part of the DEFAULT setup for
> the trustee.
> 26062 22:16:07 (0) ** Removing default security will cause some
> operations to fail!

Firstly, you disabled UAC - which isn't necessarily a problem but it makes
you vulnerable to strange security side-effects. Applications which have a
manifest setting to elevate, cannot elevate if UAC is disabled so you might
get plain "access denied" errors instead of normal function.

Secondly, it looks like the Everyone ACE has been removed. The log then
tells us "Removing default security will cause some operations to fail".

Plus there are a lot of 0x80070005 "Access Denied" errors reading the MOF
files. I'm not sure if that's a real access denied on the objects or
whether you're running WMIDiag in a security context which doesn't have
access (safest thing is to run as Administrator, on the local box, not

So it sounds like you need to find ways to work around these two problems -
either by rolling back the changes (re-enabling UAC, adding the Everyone
Trustee) or by further modifying security, to the point things start
working again. Or is there something I'm missing?

Hope it helps,
Andrew McLaren
amclar (at) optusnet dot com dot au
Try adding the NETWORK SERVICE account to you local Adminstrators. This
fixed the WMI problem for me. However, I'm still still getting access
problems from SQL Server Configuration Manager and SQL Server Reporting
Services. WMIDiag output is as follows (can anyone help?), turned on
UAC to gett a better error output:

34343 13:29:29 (0) ** WMIDiag v2.0 started on 17 October 2007 at
34344 13:29:29 (0) **
34345 13:29:29 (0) ** Copyright (c) Microsoft Corporation. All rights
reserved - January 2007.
34346 13:29:29 (0) **
34347 13:29:29 (0) ** This script is not supported under any Microsoft
standard support program or service.
34348 13:29:29 (0) ** The script is provided AS IS without warranty of
any kind. Microsoft further disclaims all
34349 13:29:29 (0) ** implied warranties including, without limitation,
any implied warranties of merchantability
34350 13:29:29 (0) ** or of fitness for a particular purpose. The
entire risk arising out of the use or performance
34351 13:29:29 (0) ** of the scripts and documentation remains with
you. In no event shall Microsoft, its authors,
34352 13:29:29 (0) ** or anyone else involved in the creation,
production, or delivery of the script be liable for
34353 13:29:29 (0) ** any damages whatsoever (including, without
limitation, damages for loss of business profits,
34354 13:29:29 (0) ** business interruption, loss of business
information, or other pecuniary loss) arising out of
34355 13:29:29 (0) ** the use of or inability to use the script or
documentation, even if Microsoft has been advised
34356 13:29:29 (0) ** of the possibility of such damages.
34357 13:29:29 (0) **
34358 13:29:29 (0) **
34359 13:29:29 (0) **
34360 13:29:29 (0) **
----------------------------------------------------- WMI REPORT: BEGIN
34361 13:29:29 (0) **
34362 13:29:29 (0) **
34363 13:29:29 (0) **
34364 13:29:29 (0) ** Windows Vista - No service pack - 32-bit (6000) -
User 'CKISH-PC\CKISH' on computer 'CKISH-PC'.
34365 13:29:29 (0) **
34366 13:29:29 (0) ** INFO: Environment:
1 ITEM(S)!
34367 13:29:29 (0) ** INFO: => 4 incorrect shutdown(s) detected on:
34368 13:29:29 (0) ** - Shutdown on 17 September 2007 06:46:11
34369 13:29:29 (0) ** - Shutdown on 30 July 2007 20:31:49
34370 13:29:29 (0) ** - Shutdown on 29 July 2007 06:16:41
34371 13:29:29 (0) ** - Shutdown on 26 July 2007 07:54:36
34372 13:29:29 (0) **
34373 13:29:29 (0) ** System drive:
C: (Disk #0 Partition #2).
34374 13:29:29 (0) ** Drive type:
IDE (WDC WD1200BEVS-75RST0 ATA Device).
34375 13:29:29 (0) ** There are no missing WMI system files:
34376 13:29:29 (0) ** There are no missing WMI repository files:
34377 13:29:29 (0) ** WMI repository state:
34378 13:29:29 (0) ** BEFORE running WMIDiag:
34379 13:29:29 (0) ** The WMI repository has a size of:
26 MB.
34380 13:29:29 (0) ** - Disk free space on 'C:':
27050 MB.
34381 13:29:29 (0) ** - INDEX.BTR, 2990080 bytes,
17/10/2007 13:19:54
34382 13:29:29 (0) ** - MAPPING1.MAP, 75916 bytes,
17/10/2007 13:19:54
34383 13:29:29 (0) ** - MAPPING2.MAP, 75916 bytes,
17/10/2007 13:19:24
34384 13:29:29 (0) ** - OBJECTS.DATA, 23740416
bytes, 17/10/2007 13:19:53
34385 13:29:29 (0) ** AFTER running WMIDiag:
34386 13:29:29 (0) ** The WMI repository has a size of:
26 MB.
34387 13:29:29 (0) ** - Disk free space on 'C:':
27045 MB.
34388 13:29:29 (0) ** - INDEX.BTR, 2990080 bytes,
17/10/2007 13:19:54
34389 13:29:29 (0) ** - MAPPING1.MAP, 75916 bytes,
17/10/2007 13:19:54
34390 13:29:29 (0) ** - MAPPING2.MAP, 75916 bytes,
17/10/2007 13:19:24
34391 13:29:29 (0) ** - OBJECTS.DATA, 23740416
bytes, 17/10/2007 13:19:53
34392 13:29:29 (0) **
34393 13:29:29 (0) ** INFO: Windows Firewall status:
34394 13:29:29 (0) ** Windows Firewall Profile:
34395 13:29:29 (0) ** Inbound connections that do not match a rule
34396 13:29:29 (0) ** => This will prevent any WMI remote connectivity
to this computer except
34397 13:29:29 (0) ** if the following three inbound rules are
34398 13:29:29 (0) ** - 'Windows Management Instrumentation
34399 13:29:29 (0) ** - 'Windows Management Instrumentation
34400 13:29:29 (0) ** - 'Windows Management Instrumentation
34401 13:29:29 (0) ** Verify the reported status for each of these
three inbound rules below.
34402 13:29:29 (0) **
34403 13:29:29 (0) ** Windows Firewall 'Windows Management
Instrumentation (WMI)' group rule:
............................................. DISABLED.
34404 13:29:29 (0) ** => This will prevent any WMI remote connectivity
to/from this machine.
34405 13:29:29 (0) ** - You can adjust the configuration by
executing the following command:
GROUP="Windows Management Instrumentation (WMI)" NEW ENABLE=YES'
34407 13:29:29 (0) ** Note: With this command all inbound and outbound
WMI rules are activated at once!
34408 13:29:29 (0) ** You can also enable each individual rule
instead of activating the group rule.
34409 13:29:29 (0) **
34410 13:29:29 (0) ** Windows Firewall 'Windows Management
Instrumentation (ASync-In)' rule:
.............................................. DISABLED.
34411 13:29:29 (0) ** => This will prevent any WMI asynchronous inbound
connectivity to this machine.
34412 13:29:29 (0) ** - You can adjust the configuration of this
rule by executing the following command:
NAME="Windows Management Instrumentation (ASync-In)" NEW ENABLE=YES'
34414 13:29:29 (0) **
34415 13:29:29 (0) ** Windows Firewall 'Windows Management
Instrumentation (WMI-Out)' rule:
............................................... DISABLED.
34416 13:29:29 (0) ** => This will prevent any WMI asynchronous
outbound connectivity from this machine.
34417 13:29:29 (0) ** - You can adjust the configuration of this
rule by executing the following command:
NAME="Windows Management Instrumentation (WMI-Out)" NEW ENABLE=YES'
34419 13:29:29 (0) **
34420 13:29:29 (0) ** Windows Firewall 'Windows Management
Instrumentation (WMI-In)' rule:
................................................ DISABLED.
34421 13:29:29 (0) ** => This will prevent any WMI inbound connectivity
to this machine.
34422 13:29:29 (0) ** Note: The rule 'Windows Management
Instrumentation (WMI-In)' rule must be ENABLED to allow incoming WMI
34423 13:29:29 (0) ** - You can adjust the configuration of this
rule by executing the following command:
NAME="Windows Management Instrumentation (WMI-In)" NEW ENABLE=YES'
34425 13:29:29 (0) **
34426 13:29:29 (0) ** Windows Firewall 'Windows Management
Instrumentation (DCOM-In)' rule:
............................................... DISABLED.
34427 13:29:29 (0) ** => This will prevent any DCOM WMI inbound
connectivity to this machine.
34428 13:29:29 (0) ** Note: The rule 'Windows Management
Instrumentation (DCOM-In)' rule must be ENABLED to allow incoming DCOM
WMI connectivity.
34429 13:29:29 (0) ** - You can adjust the configuration of this
rule by executing the following command:
NAME="Windows Management Instrumentation (DCOM-In)" NEW ENABLE=YES'
34431 13:29:29 (0) **
34432 13:29:29 (0) **
34433 13:29:29 (0) ** DCOM Status:
34434 13:29:29 (0) ** WMI registry setup:
34435 13:29:29 (0) ** INFO: WMI service has dependents:
34436 13:29:29 (0) ** - Security Center (WSCSVC,
34437 13:29:29 (0) ** - Internet Connection Sharing (ICS)
(SHAREDACCESS, StartMode='Manual')
34438 13:29:29 (0) ** => If the WMI service is stopped, the listed
service(s) will have to be stopped as well.
34439 13:29:29 (0) ** Note: If the service is marked with (*), it
means that the service/application uses WMI but
34440 13:29:29 (0) ** there is no hard dependency on WMI.
However, if the WMI service is stopped,
34441 13:29:29 (0) ** this can prevent the service/application
to work as expected.
34442 13:29:29 (0) **
34443 13:29:29 (0) ** RPCSS service:
OK (Already started).
34444 13:29:29 (0) ** WINMGMT service:
OK (Already started).
34445 13:29:29 (0) **
34446 13:29:29 (0) ** WMI service DCOM setup:
34447 13:29:29 (0) ** WMI components DCOM registrations:
34448 13:29:29 (0) ** WMI ProgID registrations:
34449 13:29:29 (0) ** WMI provider DCOM registrations:
34450 13:29:29 (0) ** WMI provider CIM registrations:
34451 13:29:29 (0) ** WMI provider CLSIDs:
34452 13:29:29 (0) ** WMI providers EXE/DLL availability:
34453 13:29:29 (0) **
34454 13:29:29 (0) ** INFO: User Account Control (UAC):
34455 13:29:29 (0) ** => WMI tasks requiring Administrative privileges
on this computer MUST run in an elevated context.
34456 13:29:29 (0) ** i.e. You can start your scripts or WMIC
commands from an elevated command
34457 13:29:29 (0) ** prompt by right clicking on the 'Command
Prompt' icon in the Start Menu and
34458 13:29:29 (0) ** selecting 'Run as Administrator'.
34459 13:29:29 (0) ** i.e. You can also execute the WMI scripts or
WMIC commands as a task
34460 13:29:29 (0) ** in the Task Scheduler within the right
security context.
34461 13:29:29 (0) **
34462 13:29:29 (0) ** INFO: Local Account Filtering:
34463 13:29:29 (0) ** => WMI tasks remotely accessing WMI information
on this computer and requiring Administrative
34464 13:29:29 (0) ** privileges MUST use a DOMAIN account part of
the Local Administrators group of this computer
34465 13:29:29 (0) ** to ensure that administrative privileges are
granted. If a Local User account is used for remote
34466 13:29:29 (0) ** accesses, it will be reduced to a plain user
(filtered token), even if it is part of the Local Administrators
34467 13:29:29 (0) **
34468 13:29:29 (0) ** Overall DCOM security status:
34469 13:29:29 (0) ** Overall WMI security status:
34470 13:29:29 (0) ** - Started at 'Root'
34471 13:29:29 (0) ** INFO: WMI permanent SUBSCRIPTION(S):
34472 13:29:29 (0) ** - ROOT/SUBSCRIPTION,
NTEventLogEventConsumer.Name="SCM Event Log Consumer".
34473 13:29:29 (0) ** 'select * from MSFT_SCMEventLogEvent'
34474 13:29:29 (0) **
34475 13:29:29 (0) ** WMI TIMER instruction(s):
34476 13:29:29 (0) ** INFO: WMI namespace(s) requiring PACKET PRIVACY:
.................................................................... 5
34477 13:29:29 (0) ** - ROOT/CIMV2/SECURITY/MICROSOFTTPM.
34479 13:29:29 (0) ** - ROOT/CIMV2/TERMINALSERVICES.
34480 13:29:29 (0) ** - ROOT/MICROSOFTIISV2.
34481 13:29:29 (0) ** - ROOT/SERVICEMODEL.
34482 13:29:29 (0) ** => When remotely connecting, the namespace(s)
listed require(s) the WMI client to
34483 13:29:29 (0) ** use an encrypted connection by specifying the
PACKET PRIVACY authentication level.
34484 13:29:29 (0) ** (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy
34485 13:29:29 (0) ** i.e. 'WMIC.EXE /NODE:"CKISH-PC"
34486 13:29:29 (0) **
34487 13:29:29 (0) ** WMI MONIKER CONNECTIONS:
34488 13:29:29 (0) ** WMI CONNECTIONS:
34489 13:29:29 (0) ** WMI GET operations:
34490 13:29:29 (0) ** WMI MOF representations:
34491 13:29:29 (0) ** WMI QUALIFIER access operations:
34492 13:29:29 (1) !! ERROR: WMI ENUMERATION operation errors reported:
................................................................... 16
34493 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Cache', 0x80004002 - No such interface
34494 13:29:29 (0) ** MOF Registration:
34495 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Memory', 0x80004002 - No such interface
34496 13:29:29 (0) ** MOF Registration:
34497 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Objects', 0x80004002 - No such
interface supported.
34498 13:29:29 (0) ** MOF Registration:
34499 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_PagingFile', 0x80004002 - No such
interface supported.
34500 13:29:29 (0) ** MOF Registration:
34501 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_Processor', 0x80004002 - No such
interface supported.
34502 13:29:29 (0) ** MOF Registration:
34503 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfOS_System', 0x80004002 - No such interface
34504 13:29:29 (0) ** MOF Registration:
34505 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfProc_Process', 0x80004002 - No such
interface supported.
34506 13:29:29 (0) ** MOF Registration:
34507 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_PerfProc_Thread', 0x80004002 - No such
interface supported.
34508 13:29:29 (0) ** MOF Registration:
34509 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_ICMP', 0x80004002 - No such interface
34510 13:29:29 (0) ** MOF Registration:
34511 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_ICMPv6', 0x80004002 - No such interface
34512 13:29:29 (0) ** MOF Registration:
34513 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_IPv4', 0x80004002 - No such interface
34514 13:29:29 (0) ** MOF Registration:
34515 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_IPv6', 0x80004002 - No such interface
34516 13:29:29 (0) ** MOF Registration:
34517 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_TCPv4', 0x80004002 - No such interface
34518 13:29:29 (0) ** MOF Registration:
34519 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_TCPv6', 0x80004002 - No such interface
34520 13:29:29 (0) ** MOF Registration:
34521 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_UDPv4', 0x80004002 - No such interface
34522 13:29:29 (0) ** MOF Registration:
34523 13:29:29 (0) ** - Root/CIMV2, InstancesOf,
'Win32_PerfFormattedData_Tcpip_UDPv6', 0x80004002 - No such interface
34524 13:29:29 (0) ** MOF Registration:
34525 13:29:29 (0) **
34526 13:29:29 (0) ** WMI EXECQUERY operations:
34527 13:29:29 (0) ** WMI GET VALUE operations:
34528 13:29:29 (0) ** WMI WRITE operations:
34529 13:29:29 (0) ** WMI PUT operations:
34530 13:29:29 (0) ** WMI DELETE operations:
34531 13:29:29 (0) ** WMI static instances retrieved:
34532 13:29:29 (0) ** WMI dynamic instances retrieved:
34533 13:29:29 (0) ** WMI instance request cancellations (to limit
performance impact):
................................................... 1.
34534 13:29:29 (0) **
34535 13:29:29 (0) ** # of Event Log events BEFORE WMIDiag execution
since the last 20 day(s):
34536 13:29:29 (0) ** DCOM:
34537 13:29:29 (0) ** WINMGMT:
34538 13:29:29 (0) ** WMIADAPTER:
34539 13:29:29 (0) **
34540 13:29:29 (0) ** # of additional Event Log events AFTER WMIDiag
34541 13:29:29 (0) ** DCOM:
34542 13:29:29 (0) ** WINMGMT:
34543 13:29:29 (0) ** WMIADAPTER:
34544 13:29:29 (0) **
34545 13:29:29 (0) ** 16 error(s) 0x80004002 - (WBEM_UNKNOWN) This
error code is external to WMI.
34546 13:29:29 (0) ** => This error is not a WMI error. It is a DCOM
error due to the following reasons:
34547 13:29:29 (0) ** - An application has changed the COM/DCOM
settings of OLE32.DLL and/or OLEAUT32.DLL.
34548 13:29:29 (0) ** - The registry settings of COM/DCOM has been
damage or wrongly modified.
34549 13:29:29 (0) ** => To correct this situation, you must
re-register the original COM/DCOM DLLs with REGSVR32.EXE
34550 13:29:29 (0) ** i.e. 'REGSVR32.EXE OLE32.DLL'
34551 13:29:29 (0) ** i.e. 'REGSVR32.EXE OLEAUT32.DLL'
34552 13:29:29 (0) **
34553 13:29:29 (0) **
34554 13:29:29 (0) ** WMI Registry key setup:
34555 13:29:29 (0) **
34556 13:29:29 (0) **
34557 13:29:29 (0) **
34558 13:29:29 (0) **
34559 13:29:29 (0) **
34560 13:29:29 (0) **

ColSchmoll's Profile: http://forums.techarena.in/member.php?userid=33155
View this thread: http://forums.techarena.in/showthread.php?t=834393
