The system is XP SP2 with all latest updates.
The problem is with WMI.
Logs are here...
************* LOGS ************************
(Mon Sep 03 15:36:42 2007.546453) : Impersonation failed - Access
denied
(Mon Sep 03 15:57:40 2007.1804187) : WDM call returned error: 4200
(Mon Sep 03 18:43:19 2007.45750) : Unable to add definition query
SELECT * FROM IANet_802dot3TeamEvent to a provider proxy. Error code:
80041002
(Mon Sep 03 18:43:19 2007.45750) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3TeamEvent
failed to merge: 80041002
(Mon Sep 03 18:43:19 2007.45750) : Invalid event class
IANet_802dot3VlanEvent in provider registration
Query was: SELECT * FROM IANet_802dot3VlanEvent
(Mon Sep 03 18:43:19 2007.45765) : Unable to add definition query
SELECT * FROM IANet_802dot3VlanEvent to a provider proxy. Error code:
80041002
(Mon Sep 03 18:43:19 2007.45765) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3VlanEvent
failed to merge: 80041002
(Mon Sep 03 18:43:19 2007.45765) : Invalid event class
IANet_InternalErrorEvent in provider registration
Query was: SELECT * FROM IANet_InternalErrorEvent
(Mon Sep 03 18:43:19 2007.45765) : Unable to add definition query
SELECT * FROM IANet_InternalErrorEvent to a provider proxy. Error
code: 80041002
(Mon Sep 03 18:43:19 2007.45765) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_InternalErrorEvent
failed to merge: 80041002
(Mon Sep 03 18:44:23 2007.109953) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
A provider, Ncs2, has been registered in the WMI namespace, Root
\IntelNCS2, but did not specify the HostingModel property.
This provider will be run using the LocalSystem account. This
account is privileged and the provider may cause a
security violation if it does not correctly impersonate user
requests. Ensure that provider has been reviewed for
security behavior and update the HostingModel property of the provider
registration to an account with the least
privileges possible for the required functionality.
A provider, IntelEthernetDiag, has been registered in the WMI
namespace, Root\CIMv2, but did not specify the HostingModel
property. This provider will be run using the LocalSystem account.
This account is privileged and the provider may cause
a security violation if it does not correctly impersonate user
requests. Ensure that provider has been reviewed for
security behavior and update the HostingModel property of the provider
registration to an account with the least
privileges possible for the required functionality.
Event provider attempted to register query "SELECT * FROM
IANet_SessionEvent" whose target class "IANet_SessionEvent" does
not exist. The query will be ignored.
Event provider attempted to register query "SELECT * FROM
IANet_InternalErrorEvent" whose target class
"IANet_InternalErrorEvent" does not exist. The query will be ignored.
Event provider attempted to register query "SELECT * FROM
IANet_SessionEvent" whose target class "IANet_SessionEvent" does
not exist. The query will be ignored.
Event provider attempted to register query "SELECT * FROM
IANet_802dot3AdapterEvent" whose target class
"IANet_802dot3AdapterEvent" does not exist. The query will be ignored.
Event provider attempted to register query "SELECT * FROM
IANet_802dot3TeamEvent" whose target class
"IANet_802dot3TeamEvent" does not exist. The query will be ignored.
Event provider attempted to register query "SELECT * FROM
IANet_802dot3VlanEvent" whose target class
"IANet_802dot3VlanEvent" does not exist. The query will be ignored.
There appears to be impact made by any version of the intel drivers as
inspected with 8.4, 11.2, 12.2 versions.
It is sufficient to have them once installed and removed to have error
REMAIN. For version 8.4 that is chronologically ... logical. For
example I can see IntelNCS remaining in the security properties
page... But where and what is it really changed in windows and where
do we see those configuration files?
Since the system used to work well I suppose that microsoft something
changed via automatic updates and then the system became crappy.
I tried loosening security for everything in WMI properties except for
user "Everyone" but that had no result.
While the event viewer is printing same messages all the time (??) the
WBEM is printing logs like this...
******************* LOGS *******************************
errors after uninstalling driver and removing 98% of intel proset
rekated registry entries...
(Tue Sep 04 17:09:46 2007.4008406) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008406) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008406) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008500) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008500) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008500) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008500) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008515) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008515) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008515) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008515) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008531) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008531) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008531) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:11:02 2007.41765) : Invalid event class
IANet_SessionEvent in provider registration
Query was: SELECT * FROM IANet_SessionEvent
(Tue Sep 04 17:11:02 2007.41781) : Unable to add definition query
SELECT * FROM IANet_SessionEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41781) : Skipping provider NcsCoreEvents
registration query SELECT * FROM IANet_SessionEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41781) : Invalid event class
IANet_InternalErrorEvent in provider registration
Query was: SELECT * FROM IANet_InternalErrorEvent
(Tue Sep 04 17:11:02 2007.41781) : Unable to add definition query
SELECT * FROM IANet_InternalErrorEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41781) : Skipping provider NcsCoreEvents
registration query SELECT * FROM IANet_InternalErrorEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41796) : Invalid event class
IANet_SessionEvent in provider registration
Query was: SELECT * FROM IANet_SessionEvent
(Tue Sep 04 17:11:02 2007.41796) : Unable to add definition query
SELECT * FROM IANet_SessionEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41796) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_SessionEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41796) : Invalid event class
IANet_802dot3AdapterEvent in provider registration
Query was: SELECT * FROM IANet_802dot3AdapterEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3AdapterEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3AdapterEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_802dot3TeamEvent in provider registration
Query was: SELECT * FROM IANet_802dot3TeamEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3TeamEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3TeamEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_802dot3VlanEvent in provider registration
Query was: SELECT * FROM IANet_802dot3VlanEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3VlanEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3VlanEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_InternalErrorEvent in provider registration
Query was: SELECT * FROM IANet_InternalErrorEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_InternalErrorEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_InternalErrorEvent
failed to merge: 80041002
(Tue Sep 04 17:12:05 2007.105343) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:05 2007.105343) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:06 2007.105859) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:06 2007.105859) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106718) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106781) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106781) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:09 2007.109171) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:10 2007.110656) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:10 2007.110656) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:13 2007.112890) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
errors after yet another INSTALL of 12.2 driver. it took 10 minutes to
complete, then I "REPAIRED" it later on one more time to record
logs... notice the moment with syntax error.
(Tue Sep 04 17:25:19 2007.898984) : Parsing MOF file: ICmLn.mof
(Tue Sep 04 17:25:19 2007.899187) : Finished compiling file:ICmLn.mof
(Tue Sep 04 17:25:19 2007.899187) : Parsing MOF file: ICmENU.mfl
(Tue Sep 04 17:25:19 2007.899421) : Finished compiling file:ICmENU.mfl
(Tue Sep 04 17:25:19 2007.899437) : Parsing MOF file: ICmENU.mfl
(Tue Sep 04 17:25:19 2007.899625) : Finished compiling file:ICmENU.mfl
(Tue Sep 04 17:25:19 2007.899625) : Parsing MOF file: ICoreLn.mof
(Tue Sep 04 17:25:20 2007.899765) : Finished compiling
file:ICoreLn.mof
(Tue Sep 04 17:25:20 2007.899765) : Parsing MOF file: ICoreENU.mfl
(Tue Sep 04 17:25:20 2007.899890) : Finished compiling
file:ICoreENU.mfl
(Tue Sep 04 17:25:20 2007.899890) : Parsing MOF file: ICoreENU.mfl
(Tue Sep 04 17:25:20 2007.900000) : Finished compiling
file:ICoreENU.mfl
(Tue Sep 04 17:25:20 2007.900015) : Parsing MOF file: IDiagLn.mof
(Tue Sep 04 17:25:20 2007.900031) : Finished compiling
file:IDiagLn.mof
(Tue Sep 04 17:25:20 2007.900046) : Parsing MOF file: IDiagENU.mfl
(Tue Sep 04 17:25:20 2007.900078) : Finished compiling
file:IDiagENU.mfl
(Tue Sep 04 17:25:20 2007.900093) : Parsing MOF file: IDiagENU.mfl
(Tue Sep 04 17:25:20 2007.900125) : Finished compiling
file:IDiagENU.mfl
(Tue Sep 04 17:25:20 2007.900125) : Parsing MOF file: IBootLn.mof
(Tue Sep 04 17:25:20 2007.900156) : Finished compiling
file:IBootLn.mof
(Tue Sep 04 17:25:20 2007.900171) : Parsing MOF file: IBootENU.mfl
(Tue Sep 04 17:25:20 2007.900218) : Finished compiling
file:IBootENU.mfl
(Tue Sep 04 17:25:20 2007.900218) : Parsing MOF file: IBootENU.mfl
(Tue Sep 04 17:25:20 2007.900250) : Finished compiling
file:IBootENU.mfl
(Tue Sep 04 17:25:20 2007.900296) : Parsing MOF file: C2CmLn.mof
(Tue Sep 04 17:25:20 2007.900328) : Finished compiling file:C2CmLn.mof
(Tue Sep 04 17:25:20 2007.900328) : Parsing MOF file: C2CmENU.mfl
(Tue Sep 04 17:25:20 2007.900359) : Finished compiling
file:C2CmENU.mfl
(Tue Sep 04 17:25:20 2007.900375) : Parsing MOF file: C2CmENU.mfl
(Tue Sep 04 17:25:20 2007.900390) : Finished compiling
file:C2CmENU.mfl
(Tue Sep 04 17:25:20 2007.900406) : Parsing MOF file: C2CdLn.mof
(Tue Sep 04 17:25:20 2007.900437) : Finished compiling file:C2CdLn.mof
(Tue Sep 04 17:25:20 2007.900437) : Parsing MOF file: C2CdENU.mfl
(Tue Sep 04 17:25:20 2007.900484) : Finished compiling
file:C2CdENU.mfl
(Tue Sep 04 17:25:20 2007.900484) : Parsing MOF file: C2CdENU.mfl
(Tue Sep 04 17:25:20 2007.900546) : Finished compiling
file:C2CdENU.mfl
(Tue Sep 04 17:25:20 2007.900546) : Parsing MOF file: C2ICdLn.mof
(Tue Sep 04 17:25:20 2007.900609) : Finished compiling
file:C2ICdLn.mof
(Tue Sep 04 17:25:20 2007.900609) : Parsing MOF file: C2ICdENU.mfl
(Tue Sep 04 17:25:20 2007.900640) : Finished compiling
file:C2ICdENU.mfl
(Tue Sep 04 17:25:20 2007.900640) : Parsing MOF file: C2ICdENU.mfl
(Tue Sep 04 17:25:21 2007.900671) : Finished compiling
file:C2ICdENU.mfl
(Tue Sep 04 17:25:21 2007.900671) : Parsing MOF file: C2ICrLn.mof
(Tue Sep 04 17:25:21 2007.900734) : Finished compiling
file:C2ICrLn.mof
(Tue Sep 04 17:25:21 2007.900750) : Parsing MOF file: C2ICrENU.mfl
(Tue Sep 04 17:25:21 2007.900812) : Finished compiling
file:C2ICrENU.mfl
(Tue Sep 04 17:25:21 2007.900812) : Parsing MOF file: C2ICrENU.mfl
(Tue Sep 04 17:25:21 2007.901140) : Finished compiling
file:C2ICrENU.mfl
(Tue Sep 04 17:35:58 2007.1538640) : (1): error SYNTAX 0X8004401e:
This is not a valid MOF file
(Tue Sep 04 17:35:58 2007.1538640) : (1): error SYNTAX 0X8004401e:
This is not a valid MOF file
(Tue Sep 04 17:36:05 2007.1545031) : Parsing MOF file: ICmLn.mof
(Tue Sep 04 17:36:05 2007.1545156) : Finished compiling file:ICmLn.mof
(Tue Sep 04 17:36:05 2007.1545156) : Parsing MOF file: ICmENU.mfl
(Tue Sep 04 17:36:05 2007.1545406) : Finished compiling
file:ICmENU.mfl
(Tue Sep 04 17:36:05 2007.1545406) : Parsing MOF file: ICmENU.mfl
(Tue Sep 04 17:36:05 2007.1545593) : Finished compiling
file:ICmENU.mfl
(Tue Sep 04 17:36:05 2007.1545625) : Parsing MOF file: ICoreLn.mof
(Tue Sep 04 17:36:06 2007.1545718) : Finished compiling
file:ICoreLn.mof
(Tue Sep 04 17:36:06 2007.1545718) : Parsing MOF file: ICoreENU.mfl
(Tue Sep 04 17:36:06 2007.1545843) : Finished compiling
file:ICoreENU.mfl
(Tue Sep 04 17:36:06 2007.1545859) : Parsing MOF file: ICoreENU.mfl
(Tue Sep 04 17:36:06 2007.1545968) : Finished compiling
file:ICoreENU.mfl
(Tue Sep 04 17:36:06 2007.1545984) : Parsing MOF file: IDiagLn.mof
(Tue Sep 04 17:36:06 2007.1546000) : Finished compiling
file:IDiagLn.mof
(Tue Sep 04 17:36:06 2007.1546000) : Parsing MOF file: IDiagENU.mfl
(Tue Sep 04 17:36:06 2007.1546046) : Finished compiling
file:IDiagENU.mfl
(Tue Sep 04 17:36:06 2007.1546062) : Parsing MOF file: IDiagENU.mfl
(Tue Sep 04 17:36:06 2007.1546109) : Finished compiling
file:IDiagENU.mfl
(Tue Sep 04 17:36:06 2007.1546109) : Parsing MOF file: IBootLn.mof
(Tue Sep 04 17:36:06 2007.1546140) : Finished compiling
file:IBootLn.mof
(Tue Sep 04 17:36:06 2007.1546140) : Parsing MOF file: IBootENU.mfl
(Tue Sep 04 17:36:06 2007.1546234) : Finished compiling
file:IBootENU.mfl
(Tue Sep 04 17:36:06 2007.1546234) : Parsing MOF file: IBootENU.mfl
(Tue Sep 04 17:36:06 2007.1546265) : Finished compiling
file:IBootENU.mfl
(Tue Sep 04 17:36:06 2007.1546312) : Parsing MOF file: C2CmLn.mof
(Tue Sep 04 17:36:06 2007.1546328) : Finished compiling
file:C2CmLn.mof
(Tue Sep 04 17:36:06 2007.1546343) : Parsing MOF file: C2CmENU.mfl
(Tue Sep 04 17:36:06 2007.1546375) : Finished compiling
file:C2CmENU.mfl
(Tue Sep 04 17:36:06 2007.1546375) : Parsing MOF file: C2CmENU.mfl
(Tue Sep 04 17:36:06 2007.1546406) : Finished compiling
file:C2CmENU.mfl
(Tue Sep 04 17:36:06 2007.1546406) : Parsing MOF file: C2CdLn.mof
(Tue Sep 04 17:36:06 2007.1546437) : Finished compiling
file:C2CdLn.mof
(Tue Sep 04 17:36:06 2007.1546437) : Parsing MOF file: C2CdENU.mfl
(Tue Sep 04 17:36:06 2007.1546500) : Finished compiling
file:C2CdENU.mfl
(Tue Sep 04 17:36:06 2007.1546500) : Parsing MOF file: C2CdENU.mfl
(Tue Sep 04 17:36:06 2007.1546546) : Finished compiling
file:C2CdENU.mfl
(Tue Sep 04 17:36:06 2007.1546546) : Parsing MOF file: C2ICdLn.mof
(Tue Sep 04 17:36:06 2007.1546609) : Finished compiling
file:C2ICdLn.mof
(Tue Sep 04 17:36:06 2007.1546609) : Parsing MOF file: C2ICdENU.mfl
(Tue Sep 04 17:36:06 2007.1546640) : Finished compiling
file:C2ICdENU.mfl
(Tue Sep 04 17:36:06 2007.1546640) : Parsing MOF file: C2ICdENU.mfl
(Tue Sep 04 17:36:07 2007.1546671) : Finished compiling
file:C2ICdENU.mfl
(Tue Sep 04 17:36:07 2007.1546671) : Parsing MOF file: C2ICrLn.mof
(Tue Sep 04 17:36:07 2007.1546734) : Finished compiling
file:C2ICrLn.mof
(Tue Sep 04 17:36:07 2007.1546734) : Parsing MOF file: C2ICrENU.mfl
(Tue Sep 04 17:36:07 2007.1546812) : Finished compiling
file:C2ICrENU.mfl
(Tue Sep 04 17:36:07 2007.1546812) : Parsing MOF file: C2ICrENU.mfl
(Tue Sep 04 17:36:07 2007.1546875) : Finished compiling
file:C2ICrENU.mfl
(Tue Sep 04 17:09:46 2007.4008406) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008406) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008406) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008421) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008421) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008421) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008421) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008500) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008500) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008500) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008500) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008515) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008515) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008515) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008515) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008515) : Failed the first attempt to
retrieve the sink to deliver an event to event consumer
NTEventLogEventConsumer="SCM Event Log Consumer" with error code
80041001.
WMI will reload and retry.
(Tue Sep 04 17:09:46 2007.4008531) : Unable to register event source
'Service Control Manager' on server ''. Error code: 6B5
(Tue Sep 04 17:09:46 2007.4008531) : Event consumer provider is unable
to instantiate event consumer NTEventLogEventConsumer="SCM Event Log
Consumer": error code 0x80041001
(Tue Sep 04 17:09:46 2007.4008531) : Failed the second attempt to
deliver an event to event consumer NTEventLogEventConsumer="SCM Event
Log Consumer" with error code 80041001.
This event is dropped for this consumer.
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:09:46 2007.4008531) : Dropping event destined for event
consumer NTEventLogEventConsumer="SCM Event Log Consumer" in
namespace //./root/subscription
(Tue Sep 04 17:11:02 2007.41765) : Invalid event class
IANet_SessionEvent in provider registration
Query was: SELECT * FROM IANet_SessionEvent
(Tue Sep 04 17:11:02 2007.41781) : Unable to add definition query
SELECT * FROM IANet_SessionEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41781) : Skipping provider NcsCoreEvents
registration query SELECT * FROM IANet_SessionEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41781) : Invalid event class
IANet_InternalErrorEvent in provider registration
Query was: SELECT * FROM IANet_InternalErrorEvent
(Tue Sep 04 17:11:02 2007.41781) : Unable to add definition query
SELECT * FROM IANet_InternalErrorEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41781) : Skipping provider NcsCoreEvents
registration query SELECT * FROM IANet_InternalErrorEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41796) : Invalid event class
IANet_SessionEvent in provider registration
Query was: SELECT * FROM IANet_SessionEvent
(Tue Sep 04 17:11:02 2007.41796) : Unable to add definition query
SELECT * FROM IANet_SessionEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41796) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_SessionEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41796) : Invalid event class
IANet_802dot3AdapterEvent in provider registration
Query was: SELECT * FROM IANet_802dot3AdapterEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3AdapterEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3AdapterEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_802dot3TeamEvent in provider registration
Query was: SELECT * FROM IANet_802dot3TeamEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3TeamEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3TeamEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_802dot3VlanEvent in provider registration
Query was: SELECT * FROM IANet_802dot3VlanEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_802dot3VlanEvent to a provider proxy. Error code:
80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_802dot3VlanEvent
failed to merge: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Invalid event class
IANet_InternalErrorEvent in provider registration
Query was: SELECT * FROM IANet_InternalErrorEvent
(Tue Sep 04 17:11:02 2007.41812) : Unable to add definition query
SELECT * FROM IANet_InternalErrorEvent to a provider proxy. Error
code: 80041002
(Tue Sep 04 17:11:02 2007.41812) : Skipping provider NcsWmiEventProv
registration query SELECT * FROM IANet_InternalErrorEvent
failed to merge: 80041002
(Tue Sep 04 17:12:05 2007.105343) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:05 2007.105343) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:06 2007.105859) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:06 2007.105859) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106718) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106781) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:07 2007.106781) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:09 2007.109171) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:10 2007.110656) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:10 2007.110656) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:12:13 2007.112890) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:24:26 2007.845843) : NT Event Log Consumer: could not
retrieve sid, 0x80041002
(Tue Sep 04 17:11:56 2007.95984) : ConnectViaDCOM, CoCreateInstanceEx
resulted in hr = 0x80010002
(Tue Sep 04 17:12:01 2007.101078) : ConnectViaDCOM, CoCreateInstanceEx
resulted in hr = 0x80010002
(Tue Sep 04 17:24:50 2007.870031) : NTLMLogin resulted in hr =
0x8004100e
(Tue Sep 04 17:24:50 2007.870046) : NTLMLogin resulted in hr =
0x8004100e
Login Warning - provider with that name already existed,
overridden with latest provider login (root
\cimv2:Win32_ComputerSystemWindowsProductActivationSetting) 09/04/2007
17:30:49.765 thread:3136 [d:\xpsprtm\admin\wmi\wbem\sdk\framedyn
\wbemglue.cpp.2252]
08/04/2004 02:56 AM 1,352,192 cimwin32.dll
08/04/2004 02:56 AM 45,568 CmdEvTgProv.dll
08/23/2001 04:00 PM 120,320 dsprov.dll
08/04/2004 02:56 AM 247,808 esscli.dll
08/04/2004 02:56 AM 22,016 evntrprv.dll
08/04/2004 02:56 AM 472,064 fastprox.dll
08/04/2004 02:56 AM 185,856 framedyn.dll
08/23/2001 04:00 PM 53,248 fwdprov.dll
08/04/2004 02:56 AM 24,576 krnlprov.dll
08/04/2004 02:56 AM 123,904 mofd.dll
08/23/2001 04:00 PM 273,920 msiprov.dll
08/04/2004 02:56 AM 47,104 ncprov.dll
08/04/2004 02:56 AM 212,992 ntevt.dll
08/04/2004 02:56 AM 92,672 policman.dll
08/04/2004 02:56 AM 237,056 provthrd.dll
08/04/2004 02:56 AM 177,152 repdrvfs.dll
08/23/2001 04:00 PM 40,960 smtpcons.dll
08/04/2004 02:56 AM 86,528 stdprov.dll
08/23/2001 04:00 PM 61,952 tmplprov.dll
08/23/2001 04:00 PM 59,904 trnsprov.dll
08/23/2001 04:00 PM 116,224 updprov.dll
08/04/2004 02:56 AM 131,584 viewprov.dll
08/23/2001 04:00 PM 12,288 wbemads.dll
08/04/2004 02:56 AM 196,608 wbemcntl.dll
08/04/2004 02:56 AM 214,528 wbemcomn.dll
08/04/2004 02:56 AM 71,680 wbemcons.dll
08/04/2004 02:56 AM 530,944 wbemcore.dll
08/04/2004 02:56 AM 178,176 wbemdisp.dll
08/04/2004 02:56 AM 273,920 wbemess.dll
08/04/2004 02:56 AM 43,008 wbemperf.dll
08/04/2004 02:56 AM 18,944 wbemprox.dll
08/04/2004 02:56 AM 43,520 wbemsvc.dll
08/04/2004 02:56 AM 197,120 wbemupgd.dll
08/23/2001 04:00 PM 16,384 winmgmtr.dll
08/04/2004 02:56 AM 6,656 wmiapres.dll
08/04/2004 02:56 AM 89,088 wmiaprpl.dll
08/04/2004 02:56 AM 60,928 wmicookr.dll
08/04/2004 02:56 AM 140,800 wmidcprv.dll
08/23/2001 04:00 PM 61,440 wmimsg.dll
08/04/2004 02:56 AM 156,672 wmipcima.dll
08/04/2004 02:56 AM 132,096 wmipdskq.dll
08/23/2001 04:00 PM 75,264 wmipicmp.dll
08/04/2004 02:56 AM 62,464 wmipiprt.dll
08/04/2004 02:56 AM 62,976 wmipjobj.dll
08/04/2004 02:56 AM 144,896 wmiprov.dll
08/04/2004 02:56 AM 437,248 wmiprvsd.dll
08/04/2004 02:56 AM 41,472 wmipsess.dll
08/04/2004 02:56 AM 144,896 wmisvc.dll
08/23/2001 04:00 PM 52,224 wmitimep.dll
08/04/2004 02:56 AM 95,232 wmiutils.dll
50 File(s) 7,747,072 bytes
0 Dir(s) 35,704,152,064 bytes free
C:\WINDOWS\system32\wbem>REGSVR32.EXE cimwin32.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE CmdEvTgProv.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE dsprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE esscli.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE evntrprv.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE fastprox.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE framedyn.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE fwdprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE krnlprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE mofd.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE msiprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE ncprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE ntevt.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE policman.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE provthrd.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE repdrvfs.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE smtpcons.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE stdprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE tmplprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE trnsprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE updprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE viewprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemads.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemcntl.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemcomn.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemcons.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemcore.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemdisp.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemess.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemperf.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemprox.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemsvc.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wbemupgd.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE winmgmtr.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmiapres.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmiaprpl.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmicookr.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmidcprv.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmimsg.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipcima.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipdskq.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipicmp.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipiprt.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipjobj.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmiprov.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmiprvsd.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmipsess.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmisvc.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmitimep.dll
C:\WINDOWS\system32\wbem>REGSVR32.EXE wmiutils.dll
Setting environment for using Microsoft Visual Studio 2005 x86 tools.
C:\Program Files\Microsoft Visual Studio 8\VC>NETSH.EXE FIREWALL SET
SERVICE REM
OTEADMIN ENABLE SUBNET
Ok.
C:\Program Files\Microsoft Visual Studio 8\VC>NETSH.EXE FIREWALL SET
ALLOWEDPROG
RAM C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE WMICALLBACKS ENABLE
Ok.
C:\Program Files\Microsoft Visual Studio 8\VC>WMIC.EXE /NAMESPACE:\
\ROOT\CIMV2 p
ath __Win32Provider Where Name='NcsWmiEventProv' DELETE
Deleting instance \\USR-B405AA75F52\ROOT
\cimv2:__Win32Provider.Name="NcsWmiEvent
Prov"
Instance deletion successful.
C:\Program Files\Microsoft Visual Studio 8\VC>WMIC.EXE /NAMESPACE:\
\ROOT path __
NAMESPACE Where Name='IntelNCS' DELETE
Deleting instance \\USR-B405AA75F52\ROOT:__NAMESPACE.Name="IntelNCS"
Instance deletion successful.
C:\Program Files\Microsoft Visual Studio 8\VC>WMIC.EXE /NAMESPACE:\
\ROOT path __
NAMESPACE Where Name='IntelNCS2' DELETE
Deleting instance \\USR-B405AA75F52\ROOT:__NAMESPACE.Name="IntelNCS2"
Instance deletion successful.
C:\Program Files\Microsoft Visual Studio 8\VC>WMIMGMT.MSC
C:\Program Files\Microsoft Visual Studio 8\VC>WMIMGMT.MSC
C:\Program Files\Microsoft Visual Studio 8\VC>WMIC.EXE /NODE:"USR-
B405AA75F52" /
AUTHLEVEL:Pktprivacy /NAMESPACE:\\ROOT\SERVICEMODEL Class
__SystemSecurity
<DIV CLASS="mofclass">
<SPAN CLASS="mofqualifierset"> <br /></SPAN>
<SPAN CLASS="mofkeyword">class</SPAN>
__SystemSecurity
<BR />
<SPAN CLASS="mofsymbol">{</SPAN><BR />
<DIV CLASS="mofmethod">
<SPAN CLASS="mofqualifierset"> </SPAN>
<SPAN CLASS="mofkeyword">uint32</SPAN>
<SPAN CLASS="mofmethod">GetSD</SPAN>
<SPAN CLASS="mofsymbol">(</SPAN>
<SPAN CLASS="mofsymbol">);</SPAN>
</DIV>
<DIV CLASS="mofmethod">
<SPAN CLASS="mofqualifierset"> </SPAN>
<SPAN CLASS="mofkeyword">uint32</SPAN>
<SPAN CLASS="mofmethod">Get9XUserList</SPAN>
<SPAN CLASS="mofsymbol">(</SPAN>
<SPAN CLASS="mofsymbol">);</SPAN>
</DIV>
<DIV CLASS="mofmethod">
<SPAN CLASS="mofqualifierset"> </SPAN>
<SPAN CLASS="mofkeyword">uint32</SPAN>
<SPAN CLASS="mofmethod">SetSD</SPAN>
<SPAN CLASS="mofsymbol">(</SPAN>
<SPAN CLASS="mofsymbol">);</SPAN>
</DIV>
<DIV CLASS="mofmethod">
<SPAN CLASS="mofqualifierset"> </SPAN>
<SPAN CLASS="mofkeyword">uint32</SPAN>
<SPAN CLASS="mofmethod">Set9XUserList</SPAN>
<SPAN CLASS="mofsymbol">(</SPAN>
<SPAN CLASS="mofsymbol">);</SPAN>
</DIV>
<DIV CLASS="mofmethod">
<SPAN CLASS="mofqualifierset"> </SPAN>
<SPAN CLASS="mofkeyword">uint32</SPAN>
<SPAN CLASS="mofmethod">GetCallerAccessRights</SPAN>
<SPAN CLASS="mofsymbol">(</SPAN>
<SPAN CLASS="mofsymbol">);</SPAN>
</DIV>
<SPAN CLASS="mofsymbol">};</SPAN>
</DIV>
we find some clues in the wmdiag2.0 log file (longest of three). This
is a small portion; comments follow.
16076 15:33:48 (0) ** Verifying WMI namespace 'ROOT/DIRECTORY/
LDAP' (L=3).
16077 15:33:48 (3) Retrieving WMI system class(es) static
information.
16078 15:33:49 (3) 45/45 system class(es) found.
16079 15:33:49 (3) Verifying Permanent subscription(s) for 'ROOT/
DIRECTORY/LDAP'.
16080 15:33:57 (3) 0 permanent subscription(s) in 'ROOT/DIRECTORY/
LDAP' namespace.
16081 15:33:57 (3) 0 Timer instruction(s) in 'ROOT/DIRECTORY/LDAP'
namespace.
16082 15:33:57 (3) Deciphering WMI namespace security for 'ROOT/
DIRECTORY/LDAP'
16083 15:33:57 (4) +- Security Descriptor
------------------------------------------------------------------------------------------
16084 15:33:57 (4) | Owner: .................................
BUILTIN\ADMINISTRATORS
16085 15:33:57 (4) | Group: .................................
BUILTIN\ADMINISTRATORS
16086 15:33:57 (4) | Revision: .............................. 1
16087 15:33:57 (4) | Control: ...............................
&h8004
16088 15:33:57 (4)
SE_DACL_PRESENT
16089 15:33:57 (4)
SE_SELF_RELATIVE
16090 15:33:57 (4) |+- DiscretionaryAcl
--------------------------------------------------------------------------------------------
16091 15:33:57 (4) ||+- ACE #01
----------------------------------------------------------------------------------------------------
16092 15:33:57 (4) ||| Trustee: .............................
BUILTIN\ADMINISTRATORS
16093 15:33:57 (4) ||| AceType: ............................. &h0
16094 15:33:57 (4)
ACCESS_ALLOWED_ACE_TYPE
16095 15:33:57 (4) ||| AceFlags: ............................
&h12
16096 15:33:57 (4)
CONTAINER_INHERIT_ACE
16097 15:33:57 (4)
INHERITED_ACE
16098 15:33:57 (4) ||| AccessMask: ..........................
&h6003F
16099 15:33:57 (4)
WBEM_ENABLE
16100 15:33:57 (4)
WBEM_METHOD_EXECUTE
16101 15:33:57 (4)
WBEM_FULL_WRITE_REP
16102 15:33:57 (4)
WBEM_PARTIAL_WRITE_REP
16103 15:33:57 (4)
WBEM_WRITE_PROVIDER
16104 15:33:57 (4)
WBEM_REMOTE_ACCESS
16105 15:33:57 (4)
WBEM_WRITE_DAC
16106 15:33:57 (4)
WBEM_READ_CONTROL
16107 15:33:57 (4) ||
+--------------------------------------------------------------------------------------------------------------
16108 15:33:57 (4) ||+- ACE #02
----------------------------------------------------------------------------------------------------
16109 15:33:57 (4) ||| Trustee: .............................
EVERYONE
16110 15:33:57 (4) ||| AceType: ............................. &h0
16111 15:33:57 (4)
ACCESS_ALLOWED_ACE_TYPE
16112 15:33:57 (4) ||| AceFlags: ............................
&h12
16113 15:33:57 (4)
CONTAINER_INHERIT_ACE
16114 15:33:57 (4)
INHERITED_ACE
16115 15:33:57 (4) ||| AccessMask: ..........................
&h6003F
16116 15:33:57 (4)
WBEM_ENABLE
16117 15:33:57 (4)
WBEM_METHOD_EXECUTE
16118 15:33:57 (4)
WBEM_FULL_WRITE_REP
16119 15:33:57 (4)
WBEM_PARTIAL_WRITE_REP
16120 15:33:57 (4)
WBEM_WRITE_PROVIDER
16121 15:33:57 (4)
WBEM_REMOTE_ACCESS
16122 15:33:57 (4)
WBEM_WRITE_DAC
16123 15:33:57 (4)
WBEM_READ_CONTROL
16124 15:33:57 (4) ||
+--------------------------------------------------------------------------------------------------------------
16125 15:33:57 (4) ||+- ACE #03
----------------------------------------------------------------------------------------------------
16126 15:33:57 (4) ||| Trustee: ............................. NT
AUTHORITY\LOCAL SERVICE
16127 15:33:57 (4) ||| AceType: ............................. &h0
16128 15:33:57 (4)
ACCESS_ALLOWED_ACE_TYPE
16129 15:33:57 (4) ||| AceFlags: ............................
&h12
16130 15:33:57 (4)
CONTAINER_INHERIT_ACE
16131 15:33:57 (4)
INHERITED_ACE
16132 15:33:57 (4) ||| AccessMask: ..........................
&h6003F
16133 15:33:57 (4)
WBEM_ENABLE
16134 15:33:57 (4)
WBEM_METHOD_EXECUTE
16135 15:33:57 (4)
WBEM_FULL_WRITE_REP
16136 15:33:57 (4)
WBEM_PARTIAL_WRITE_REP
16137 15:33:57 (4)
WBEM_WRITE_PROVIDER
16138 15:33:57 (4)
WBEM_REMOTE_ACCESS
16139 15:33:57 (4)
WBEM_WRITE_DAC
16140 15:33:57 (4)
WBEM_READ_CONTROL
16141 15:33:57 (4) ||
+--------------------------------------------------------------------------------------------------------------
16142 15:33:57 (4) ||+- ACE #04
----------------------------------------------------------------------------------------------------
16143 15:33:57 (4) ||| Trustee: ............................. NT
AUTHORITY\NETWORK SERVICE
16144 15:33:57 (4) ||| AceType: ............................. &h0
16145 15:33:57 (4)
ACCESS_ALLOWED_ACE_TYPE
16146 15:33:57 (4) ||| AceFlags: ............................
&h12
16147 15:33:57 (4)
CONTAINER_INHERIT_ACE
16148 15:33:57 (4)
INHERITED_ACE
16149 15:33:57 (4) ||| AccessMask: ..........................
&h6003F
16150 15:33:57 (4)
WBEM_ENABLE
16151 15:33:57 (4)
WBEM_METHOD_EXECUTE
16152 15:33:57 (4)
WBEM_FULL_WRITE_REP
16153 15:33:57 (4)
WBEM_PARTIAL_WRITE_REP
16154 15:33:57 (4)
WBEM_WRITE_PROVIDER
16155 15:33:57 (4)
WBEM_REMOTE_ACCESS
16156 15:33:57 (4)
WBEM_WRITE_DAC
16157 15:33:57 (4)
WBEM_READ_CONTROL
16158 15:33:57 (4) ||
+--------------------------------------------------------------------------------------------------------------
16159 15:33:57 (4) |
+---------------------------------------------------------------------------------------------------------------
16160 15:33:57 (4)
+-----------------------------------------------------------------------------------------------------------------
16161 15:33:57 (3) Searching if namespace 'ROOT/DIRECTORY/LDAP'
security analysis must be SKIPPED ...
16162 15:33:57 (3) Searching if namespace 'ROOT/DIRECTORY/LDAP'
security settings use a SYSTEM specific security ...
16163 15:33:57 (3) Namespace 'ROOT/DIRECTORY/LDAP' uses a SYSTEM
specific namespace security.
16164 15:33:57 (3) Verifying actual trustees in ACEs against the
default trustees in ACEs to locate actual trustee additions.
16165 15:33:57 (2) !! WARNING: Actual trustee 'EVERYONE' DOES NOT
match corresponding expected trustee rights for ACE #2.
16166 15:33:57 (3) The ACE has the right(s)
'&h6002C,WBEM_FULL_WRITE_REP,WBEM_PARTIAL_WRITE_REP,WBEM_REMOTE_ACCESS,WBEM_WRITE_DAC,WBEM_READ_CONTROL'
added!
16167 15:33:57 (2) !! WARNING: Actual trustee 'NT AUTHORITY\LOCAL
SERVICE' DOES NOT match corresponding expected trustee rights for ACE
#3.
16168 15:33:57 (3) The ACE has the right(s)
'&h6002C,WBEM_FULL_WRITE_REP,WBEM_PARTIAL_WRITE_REP,WBEM_REMOTE_ACCESS,WBEM_WRITE_DAC,WBEM_READ_CONTROL'
added!
16169 15:33:57 (2) !! WARNING: Actual trustee 'NT AUTHORITY\NETWORK
SERVICE' DOES NOT match corresponding expected trustee rights for ACE
#4.
16170 15:33:57 (3) The ACE has the right(s)
'&h6002C,WBEM_FULL_WRITE_REP,WBEM_PARTIAL_WRITE_REP,WBEM_REMOTE_ACCESS,WBEM_WRITE_DAC,WBEM_READ_CONTROL'
added!
16171 15:33:57 (3) Verifying default trustee in ACEs against the
actual trustees in ACEs to locate default trustee removals.
16172 15:33:57 (3)
What we are seeing here is that I allowed all sort of permissions in
WMI properties - but which was done afterwards with no effect except
to see the same message. I don't understand what it means that "actual
trustee doesn't match expected trustee rights for ACE". I never messed
with anything to begin with so?
analyzed log entry:
#000915: DCOM (10016) - Error - 03 September 2007 01:19:18 (GMT+2)
19349 15:35:03 (3) The application-specific permission
settings do not grant Local Launch
19350 15:35:03 (3) permission for the COM Server
application with CLSID {D851F103-8C90-4321-AFF0-58BA5BD421C2}
19351 15:35:03 (3) to the user NT AUTHORITY\SYSTEM SID
(S-1-5-18). This security permission
19352 15:35:03 (3) can be modified using the Component
Services administrative tool.
....and DCOM security was loosened.... before I saw there is no such
application so the registry entry was removed. I don't know how
exactly to grant local launch.