21964 18:26:42 (0) ** WMIDiag v2.0 started on Tuesday, September 04,
2007 at 18:21.
21965 18:26:42 (0) **
21966 18:26:42 (0) ** Copyright (c) Microsoft Corporation. All rights
reserved - January 2007.
21967 18:26:42 (0) **
21968 18:26:42 (0) ** This script is not supported under any Microsoft
standard support program or service.
21969 18:26:42 (0) ** The script is provided AS IS without warranty of
any kind. Microsoft further disclaims all
21970 18:26:42 (0) ** implied warranties including, without
limitation, any implied warranties of merchantability
21971 18:26:42 (0) ** or of fitness for a particular purpose. The
entire risk arising out of the use or performance
21972 18:26:42 (0) ** of the scripts and documentation remains with
you. In no event shall Microsoft, its authors,
21973 18:26:42 (0) ** or anyone else involved in the creation,
production, or delivery of the script be liable for
21974 18:26:42 (0) ** any damages whatsoever (including, without
limitation, damages for loss of business profits,
21975 18:26:42 (0) ** business interruption, loss of business
information, or other pecuniary loss) arising out of
21976 18:26:42 (0) ** the use of or inability to use the script or
documentation, even if Microsoft has been advised
21977 18:26:42 (0) ** of the possibility of such damages.
21978 18:26:42 (0) **
21979 18:26:42 (0) **
21980 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
21981 18:26:42 (0) **
----------------------------------------------------- WMI REPORT:
BEGIN ----------------------------------------------------------
21982 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
21983 18:26:42 (0) **
21984 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
21985 18:26:42 (0) ** Windows XP - Service pack 2 - 32-bit (2600) -
User 'USR-B405AA75F52\USR' on computer 'USR-B405AA75F52'.
21986 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
21987 18:26:42 (0) ** INFO:
Environment: ..................................................................................................
1 ITEM(S)!
21988 18:26:42 (0) ** INFO: => 1 incorrect shutdown(s) detected on:
21989 18:26:42 (0) ** - Shutdown on 31 August 2007 14:55:45
(GMT+2).
21990 18:26:42 (0) **
21991 18:26:42 (0) ** System
drive: .......................................................................................................
C: (Disk #0 Partition #0).
21992 18:26:42 (0) ** Drive
type: .........................................................................................................
IDE (WDC WD4000AAKS-00TMA0).
21993 18:26:42 (0) ** There are no missing WMI system
files: ..............................................................................
OK.
21994 18:26:42 (0) ** There are no missing WMI repository
files: ..........................................................................
OK.
21995 18:26:42 (0) ** WMI repository
state: ...............................................................................................
NOT TESTED.
21996 18:26:42 (0) ** BEFORE running WMIDiag:
21997 18:26:42 (0) ** The WMI repository has a size
of: ...................................................................................
27 MB.
21998 18:26:42 (0) ** - Disk free space on
'C:': ..........................................................................................
33973 MB.
21999 18:26:42 (0) ** - INDEX.BTR, 2269184
bytes, 9/4/2007 6:20:47 PM
22000 18:26:42 (0) ** - INDEX.MAP, 1360
bytes, 9/4/2007 6:20:47 PM
22001 18:26:42 (0) ** - MAPPING.VER, 4
bytes, 9/4/2007 6:20:47 PM
22002 18:26:42 (0) ** - MAPPING1.MAP, 16172
bytes, 9/4/2007 6:20:47 PM
22003 18:26:42 (0) ** - MAPPING2.MAP, 16172
bytes, 9/4/2007 6:20:40 PM
22004 18:26:42 (0) ** - OBJECTS.DATA, 25845760
bytes, 9/4/2007 6:20:47 PM
22005 18:26:42 (0) ** - OBJECTS.MAP, 14832
bytes, 9/4/2007 6:20:47 PM
22006 18:26:42 (0) ** AFTER running WMIDiag:
22007 18:26:42 (0) ** The WMI repository has a size
of: ...................................................................................
27 MB.
22008 18:26:42 (0) ** - Disk free space on
'C:': ..........................................................................................
34017 MB.
22009 18:26:42 (0) ** - INDEX.BTR, 2269184
bytes, 9/4/2007 6:20:47 PM
22010 18:26:42 (0) ** - INDEX.MAP, 1360
bytes, 9/4/2007 6:20:47 PM
22011 18:26:42 (0) ** - MAPPING.VER, 4
bytes, 9/4/2007 6:20:47 PM
22012 18:26:42 (0) ** - MAPPING1.MAP, 16172
bytes, 9/4/2007 6:20:47 PM
22013 18:26:42 (0) ** - MAPPING2.MAP, 16172
bytes, 9/4/2007 6:20:40 PM
22014 18:26:42 (0) ** - OBJECTS.DATA, 25845760
bytes, 9/4/2007 6:20:47 PM
22015 18:26:42 (0) ** - OBJECTS.MAP, 14832
bytes, 9/4/2007 6:20:47 PM
22016 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22017 18:26:42 (0) ** INFO: Windows Firewall
status: ......................................................................................
ENABLED.
22018 18:26:42 (0) ** Windows Firewall
Profile: ...........................................................................................
STANDARD.
22019 18:26:42 (0) ** Windows Firewall 'RemoteAdmin'
status: ..............................................................................
DISABLED.
22020 18:26:42 (0) ** => This will prevent any WMI remote connectivity
to this machine.
22021 18:26:42 (0) ** - You can adjust the configuration by
executing the following command:
22022 18:26:42 (0) ** i.e. 'NETSH.EXE FIREWALL SET SERVICE
REMOTEADMIN ENABLE SUBNET'
22023 18:26:42 (0) **
22024 18:26:42 (0) ** Windows Firewall application exception for
'UNSECAPP.EXE': ..........................................................
MISSING.
22025 18:26:42 (0) ** => This will prevent any script and MMC
application asynchronous callbacks to this machine.
22026 18:26:42 (0) ** - You can adjust the configuration by
executing the following command:
22027 18:26:42 (0) ** i.e. 'NETSH.EXE FIREWALL SET ALLOWEDPROGRAM C:
\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE WMICALLBACKS ENABLE'
22028 18:26:42 (0) **
22029 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22030 18:26:42 (0) ** DCOM
Status: ........................................................................................................
OK.
22031 18:26:42 (0) ** WMI registry
setup: .................................................................................................
OK.
22032 18:26:42 (0) ** INFO: WMI service has
dependents: ...................................................................................
3 SERVICE(S)!
22033 18:26:42 (0) ** - Security Center (WSCSVC,
StartMode='Automatic')
22034 18:26:42 (0) ** - Windows Firewall/Internet Connection Sharing
(ICS) (SHAREDACCESS, StartMode='Automatic')
22035 18:26:42 (0) ** - IPv6 Helper Service (6TO4,
StartMode='Automatic')
22036 18:26:42 (0) ** => If the WMI service is stopped, the listed
service(s) will have to be stopped as well.
22037 18:26:42 (0) ** Note: If the service is marked with (*), it
means that the service/application uses WMI but
22038 18:26:42 (0) ** there is no hard dependency on WMI.
However, if the WMI service is stopped,
22039 18:26:42 (0) ** this can prevent the service/
application to work as expected.
22040 18:26:42 (0) **
22041 18:26:42 (0) ** RPCSS
service: ......................................................................................................
OK (Already started).
22042 18:26:42 (0) ** WINMGMT
service: ....................................................................................................
OK (Already started).
22043 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22044 18:26:42 (0) ** WMI service DCOM
setup: .............................................................................................
OK.
22045 18:26:42 (0) ** WMI components DCOM
registrations: ..................................................................................
OK.
22046 18:26:42 (0) ** WMI ProgID
registrations: ...........................................................................................
OK.
22047 18:26:42 (2) !! WARNING: WMI provider DCOM registrations missing
for the following provider(s): ..................................... 1
WARNING(S)!
22048 18:26:42 (0) ** - ROOT/CIMV2, NcsWmiEventProv
({E4E01430-7348-467D-B2B8-170D716EF5C4})
22049 18:26:42 (0) ** Provider DLL: 'WMI information not available
(This could be the case for an external application or a third party
WMI provider)'
22050 18:26:42 (0) ** => This is an issue because there are still some
WMI classes referencing this list of providers
22051 18:26:42 (0) ** while the DCOM registration is wrong or
missing. This can be due to:
22052 18:26:42 (0) ** - a de-installation of the software.
22053 18:26:42 (0) ** - a deletion of some registry key data.
22054 18:26:42 (0) ** - a registry corruption.
22055 18:26:42 (0) ** => You can correct the DCOM configuration by:
22056 18:26:42 (0) ** - Executing the 'REGSVR32.EXE <Provider.DLL>'
command.
22057 18:26:42 (0) ** Note: You can build a list of classes in
relation with their WMI provider and MOF file with WMIDiag.
22058 18:26:42 (0) ** (This list can be built on a similar
and working WMI Windows installation)
22059 18:26:42 (0) ** The following command line must be
used:
22060 18:26:42 (0) ** i.e. 'WMIDiag
CorrelateClassAndProvider'
22061 18:26:42 (2) !! WARNING: Re-registering with REGSVR32.EXE all
DLL from 'C:\WINDOWS\SYSTEM32\WBEM\'
22062 18:26:42 (0) ** may not solve the problem as the DLL
supporting the WMI class(es)
22063 18:26:42 (0) ** can be located in a different folder.
22064 18:26:42 (0) ** You must refer to the class name to
determine the software delivering the related DLL.
22065 18:26:42 (0) ** => If the software has been de-installed
intentionally, then this information must be
22066 18:26:42 (0) ** removed from the WMI repository. You can use
the 'WMIC.EXE' command to remove
22067 18:26:42 (0) ** the provider registration data.
22068 18:26:42 (0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\CIMV2 path
__Win32Provider Where Name='NcsWmiEventProv' DELETE'
22069 18:26:42 (0) ** => If the namespace was ENTIRELY dedicated to
the intentionally de-installed software,
22070 18:26:42 (0) ** the namespace and ALL its content can be
ENTIRELY deleted.
22071 18:26:42 (0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT path
__NAMESPACE Where Name='CIMV2' DELETE'
22072 18:26:42 (0) ** - Re-installing the software.
22073 18:26:42 (0) **
22074 18:26:42 (0) ** WMI provider CIM
registrations: .....................................................................................
OK.
22075 18:26:42 (0) ** WMI provider
CLSIDs: ................................................................................................
OK.
22076 18:26:42 (0) ** WMI providers EXE/DLL
availability: .................................................................................
OK.
22077 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22078 18:26:42 (0) ** WMI namespace security for 'ROOT/
SERVICEMODEL': .....................................................................
MODIFIED.
22079 18:26:42 (1) !! ERROR: Actual trustee 'NT AUTHORITY\NETWORK
SERVICE' DOES NOT match corresponding expected trustee rights (Actual-
22080 18:26:42 (0) ** - ACTUAL ACE:
22081 18:26:42 (0) ** ACEType: &h0
22082 18:26:42 (0) ** ACCESS_ALLOWED_ACE_TYPE
22083 18:26:42 (0) ** ACEFlags: &h2
22084 18:26:42 (0) ** CONTAINER_INHERIT_ACE
22085 18:26:42 (0) ** ACEMask: &h1
22086 18:26:42 (0) ** WBEM_ENABLE
22087 18:26:42 (0) ** - EXPECTED ACE:
22088 18:26:42 (0) ** ACEType: &h0
22089 18:26:42 (0) ** ACCESS_ALLOWED_ACE_TYPE
22090 18:26:42 (0) ** ACEFlags: &h12
22091 18:26:42 (0) ** CONTAINER_INHERIT_ACE
22092 18:26:42 (0) ** INHERITED_ACE
22093 18:26:42 (0) ** ACEMask: &h13
22094 18:26:42 (0) ** WBEM_ENABLE
22095 18:26:42 (0) ** WBEM_METHOD_EXECUTE
22096 18:26:42 (0) ** WBEM_WRITE_PROVIDER
22097 18:26:42 (0) **
22098 18:26:42 (0) ** => The actual ACE has the right(s) '&h12
WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
22099 18:26:42 (0) ** This will cause some operations to fail!
22100 18:26:42 (0) ** It is possible to fix this issue by editing
the security descriptor and adding the removed right.
22101 18:26:42 (0) ** For WMI namespaces, this can be done with
'WMIMGMT.MSC'.
22102 18:26:42 (0) ** Note: WMIDiag has no specific knowledge of this
WMI namespace.
22103 18:26:42 (0) ** The security diagnostic is based on the
WMI namespace expected defaults.
22104 18:26:42 (0) ** A specific WMI application can always
require a security setup different
22105 18:26:42 (0) ** than the WMI security defaults.
22106 18:26:42 (0) **
22107 18:26:42 (0) ** WMI namespace security for 'ROOT/
SERVICEMODEL': .....................................................................
MODIFIED.
22108 18:26:42 (1) !! ERROR: Actual trustee 'NT AUTHORITY\LOCAL
SERVICE' DOES NOT match corresponding expected trustee rights (Actual-
22109 18:26:42 (0) ** - ACTUAL ACE:
22110 18:26:42 (0) ** ACEType: &h0
22111 18:26:42 (0) ** ACCESS_ALLOWED_ACE_TYPE
22112 18:26:42 (0) ** ACEFlags: &h2
22113 18:26:42 (0) ** CONTAINER_INHERIT_ACE
22114 18:26:42 (0) ** ACEMask: &h1
22115 18:26:42 (0) ** WBEM_ENABLE
22116 18:26:42 (0) ** - EXPECTED ACE:
22117 18:26:42 (0) ** ACEType: &h0
22118 18:26:42 (0) ** ACCESS_ALLOWED_ACE_TYPE
22119 18:26:42 (0) ** ACEFlags: &h12
22120 18:26:42 (0) ** CONTAINER_INHERIT_ACE
22121 18:26:42 (0) ** INHERITED_ACE
22122 18:26:42 (0) ** ACEMask: &h13
22123 18:26:42 (0) ** WBEM_ENABLE
22124 18:26:42 (0) ** WBEM_METHOD_EXECUTE
22125 18:26:42 (0) ** WBEM_WRITE_PROVIDER
22126 18:26:42 (0) **
22127 18:26:42 (0) ** => The actual ACE has the right(s) '&h12
WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
22128 18:26:42 (0) ** This will cause some operations to fail!
22129 18:26:42 (0) ** It is possible to fix this issue by editing
the security descriptor and adding the removed right.
22130 18:26:42 (0) ** For WMI namespaces, this can be done with
'WMIMGMT.MSC'.
22131 18:26:42 (0) ** Note: WMIDiag has no specific knowledge of this
WMI namespace.
22132 18:26:42 (0) ** The security diagnostic is based on the
WMI namespace expected defaults.
22133 18:26:42 (0) ** A specific WMI application can always
require a security setup different
22134 18:26:42 (0) ** than the WMI security defaults.
22135 18:26:42 (0) **
22136 18:26:42 (0) ** WMI namespace security for 'ROOT/
SERVICEMODEL': .....................................................................
MODIFIED.
22137 18:26:42 (1) !! ERROR: Default trustee 'EVERYONE' has been
REMOVED!
22138 18:26:42 (0) ** - REMOVED ACE:
22139 18:26:42 (0) ** ACEType: &h0
22140 18:26:42 (0) ** ACCESS_ALLOWED_ACE_TYPE
22141 18:26:42 (0) ** ACEFlags: &h12
22142 18:26:42 (0) ** CONTAINER_INHERIT_ACE
22143 18:26:42 (0) ** INHERITED_ACE
22144 18:26:42 (0) ** ACEMask: &h13
22145 18:26:42 (0) ** WBEM_ENABLE
22146 18:26:42 (0) ** WBEM_METHOD_EXECUTE
22147 18:26:42 (0) ** WBEM_WRITE_PROVIDER
22148 18:26:42 (0) **
22149 18:26:42 (0) ** => The REMOVED ACE was part of the DEFAULT setup
for the trustee.
22150 18:26:42 (0) ** Removing default security will cause some
operations to fail!
22151 18:26:42 (0) ** It is possible to fix this issue by editing
the security descriptor and adding the ACE.
22152 18:26:42 (0) ** For WMI namespaces, this can be done with
'WMIMGMT.MSC'.
22153 18:26:42 (0) ** Note: WMIDiag has no specific knowledge of this
WMI namespace.
22154 18:26:42 (0) ** The security diagnostic is based on the
WMI namespace expected defaults.
22155 18:26:42 (0) ** A specific WMI application can always
require a security setup different
22156 18:26:42 (0) ** than the WMI security defaults.
22157 18:26:42 (0) **
22158 18:26:42 (0) **
22159 18:26:42 (0) ** DCOM security warning(s)
detected: ..................................................................................
0.
22160 18:26:42 (0) ** DCOM security error(s)
detected: ....................................................................................
0.
22161 18:26:42 (0) ** WMI security warning(s)
detected: ...................................................................................
0.
22162 18:26:42 (0) ** WMI security error(s)
detected: .....................................................................................
3.
22163 18:26:42 (0) **
22164 18:26:42 (0) ** Overall DCOM security
status: .......................................................................................
OK.
22165 18:26:42 (1) !! ERROR: Overall WMI security
status: .................................................................................
ERROR!
22166 18:26:42 (0) ** - Started at 'Root'
--------------------------------------------------------------------------------------------------------------
22167 18:26:42 (0) ** INFO: WMI permanent
SUBSCRIPTION(S): ................................................................................
2.
22168 18:26:42 (0) ** - ROOT/SUBSCRIPTION,
MSFT_UCScenarioControl.Name="Microsoft WMI Updating Consumer Scenario
Control".
22169 18:26:42 (0) ** 'SELECT * FROM __InstanceOperationEvent WHERE
TargetInstance ISA 'MSFT_UCScenario''
22170 18:26:42 (0) ** - ROOT/SUBSCRIPTION,
NTEventLogEventConsumer.Name="SCM Event Log Consumer".
22171 18:26:42 (0) ** 'select * from MSFT_SCMEventLogEvent'
22172 18:26:42 (0) **
22173 18:26:42 (0) ** WMI TIMER
instruction(s): ...........................................................................................
NONE.
22174 18:26:42 (0) ** WMI ADAP
status: ....................................................................................................
OK.
22175 18:26:42 (0) ** INFO: WMI namespace(s) requiring PACKET
PRIVACY: ....................................................................
1 NAMESPACE(S)!
22176 18:26:42 (0) ** - ROOT/SERVICEMODEL.
22177 18:26:42 (0) ** => When remotely connecting, the namespace(s)
listed require(s) the WMI client to
22178 18:26:42 (0) ** use an encrypted connection by specifying the
PACKET PRIVACY authentication level.
22179 18:26:42 (0) ** (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy
flags)
22180 18:26:42 (0) ** i.e. 'WMIC.EXE /NODE:"USR-B405AA75F52" /
AUTHLEVEL

ktprivacy /NAMESPACE:\\ROOT\SERVICEMODEL Class
__SystemSecurity'
22181 18:26:42 (0) **
22182 18:26:42 (0) ** WMI MONIKER
CONNECTIONS: ............................................................................................
OK.
22183 18:26:42 (0) ** WMI
CONNECTIONS: ....................................................................................................
OK.
22184 18:26:42 (0) ** WMI GET
operations: .................................................................................................
OK.
22185 18:26:42 (0) ** WMI MOF
representations: ............................................................................................
OK.
22186 18:26:42 (0) ** WMI QUALIFIER access
operations: ....................................................................................
OK.
22187 18:26:42 (0) ** WMI ENUMERATION
operations: .........................................................................................
OK.
22188 18:26:42 (0) ** WMI EXECQUERY
operations: ...........................................................................................
OK.
22189 18:26:42 (0) ** WMI GET VALUE
operations: ...........................................................................................
OK.
22190 18:26:42 (0) ** WMI WRITE
operations: ...............................................................................................
NOT TESTED.
22191 18:26:42 (0) ** WMI PUT
operations: .................................................................................................
NOT TESTED.
22192 18:26:42 (0) ** WMI DELETE
operations: ..............................................................................................
NOT TESTED.
22193 18:26:42 (0) ** WMI static instances
retrieved: .....................................................................................
746.
22194 18:26:42 (0) ** WMI dynamic instances
retrieved: ....................................................................................
0.
22195 18:26:42 (0) ** WMI instance request cancellations (to limit
performance
impact): ................................................... 0.
22196 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22197 18:26:42 (0) ** # of Event Log events BEFORE WMIDiag execution
since the last 20 day(s):
22198 18:26:42 (0) **
DCOM: .............................................................................................................
10.
22199 18:26:42 (0) **
WINMGMT: ..........................................................................................................
213.
22200 18:26:42 (0) **
WMIADAPTER: .......................................................................................................
0.
22201 18:26:42 (0) ** => Verify the WMIDiag LOG at line #20130 for
more details.
22202 18:26:42 (0) **
22203 18:26:42 (0) ** # of additional Event Log events AFTER WMIDiag
execution:
22204 18:26:42 (0) **
DCOM: .............................................................................................................
0.
22205 18:26:42 (0) **
WINMGMT: ..........................................................................................................
0.
22206 18:26:42 (0) **
WMIADAPTER: .......................................................................................................
0.
22207 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22208 18:26:42 (0) ** WMI Registry key
setup: .............................................................................................
OK.
22209 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22210 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22211 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22212 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22213 18:26:42 (0) **
22214 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22215 18:26:42 (0) **
------------------------------------------------------ WMI REPORT: END
-----------------------------------------------------------
22216 18:26:42 (0) **
----------------------------------------------------------------------------------------------------------------------------------
22217 18:26:42 (0) **
22218 18:26:42 (0) ** WARNING: WMIDiag determined that WMI works
CORRECTLY. HOWEVER, some issues were detected. Check 'C:\DOCUMENTS
AND SETTINGS\USR\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.SP2.32_USR-
B405AA75F52_2007.09.04_18.21.54.LOG' for details.
22219 18:26:42 (0) **
22220 18:26:42 (0) ** WMIDiag v2.0 ended on Tuesday, September 04,
2007 at 18:26 (W:111 E:5 S:2).