[SOLVED] WIN 2019 physical server install update and rolls back after reboot continously KB5026362

tomekniemcy

Well-known member
Joined
Apr 20, 2022
Posts
72
Hello, Im trying to install update on physical server. During installation is no errors, but when servert is restarting update rolls back. I dont know why. Can You help me with this issue ? What logs will be needed ? CBS.log , components hive ? After confirm i will upload necessary logs
 
In setupapi.dev.log i can find many errors:
Code:
 Unable to open configuration key for driver package 'oem3.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'oem4.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'oem11.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'wpdfs.inf'.  Error = 0x00000002
!    sto: Unable to invalidate all dependent driver configurations. Error = 0x00000002
<<<  Section end 2023/03/16 23:48:59.559
<<<  [Exit status: SUCCESS (REBOOT_REQUIRED)]
 
Code:
 sto:      Filename = C:\Windows\System32\DriverStore\FileRepository\ntprint4.inf_amd64_f40805c7bb802e9f\ntprint4.inf
     sto: Driver update 'ntprint.inf' is already reflected.
     sto: Driver update 'uefi.inf' is already reflected.
     sto: Driver update 'tsprint.inf' is already reflected.
     sto: Driver update 'sdstor.inf' is already reflected.
     sto: Driver update 'sdbus.inf' is already reflected.
     sto: Driver update 'mshdc.inf' is already reflected.
     sto: Driver update 'machine.inf' is already reflected.
     sto: Driver update 'wdmvsc.inf' is already reflected.
     sto: Driver update 'usbaudio2.inf' is already reflected.
!    sto: Unable to open configuration key for driver package 'oem3.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'oem4.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'oem11.inf'.  Error = 0x00000002
!    sto: Unable to open configuration key for driver package 'wpdfs.inf'.  Error = 0x00000002
!    sto: Unable to invalidate all dependent driver configurations. Error = 0x00000002
<<<  Section end 2023/06/09 05:27:57.672
<<<  [Exit status: SUCCESS]
I dont have directory ntprint4.inf_amd64_f40805c7bb802e9f in C:\Windows\System32\DriverStore\FileRepository
 
Please note that no one will be able to provide any help if you don't follow the posting instructions.
 
Hello, sorry for the delay. I attached components hive, cbs log and setupapi.dev.log
LOGS

What do You thing about this errors in CBS ? It could be aproblem ?
Code:
Installer name: 'Per-User Registry Installer'
2023-06-09 19:17:44, Info                  CSI    000000b3 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14168
2023-06-09 19:17:44, Info                  CBS    Progress: UI message updated. Operation type: Update. Stage: 0 out of 0. Percent progress: 50.
2023-06-09 19:17:44, Info                  CSI    000000b4 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14169
2023-06-09 19:17:45, Info                  CSI    000000b5 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14170
2023-06-09 19:17:45, Info                  CSI    000000b6 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14180
2023-06-09 19:17:45, Info                  CSI    000000b7 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14181
2023-06-09 19:17:46, Info                  CSI    000000b8 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-14652
2023-06-09 19:17:49, Info                  CSI    000000b9 Loading user account SID S-1-5-21-2281769908-589326359-3636360395-24653
2023-06-09 19:17:53, Info                  CSI    000000ba Loading user account SID S-1-5-21-2281769908-589326359-3636360395-32558
2023-06-09 19:17:57, Error                 CSI    000000bb@2023/6/9:17:17:57.745 (F) internal\onecorebase\inc\auto_hive.h(235): Error STATUS_SHARING_VIOLATION originated in function Windows::Rtl::AutoHive::Load expression: Status
[gle=0x80004005]
2023-06-09 19:17:57, Info                  CBS    Could not get active session for current session file logging [HRESULT = 0x80004003 - E_POINTER]
2023-06-09 19:17:57, Info                  CBS    Could not get file name for current session file logging [HRESULT = 0x80004003 - E_POINTER]
2023-06-09 19:17:57, Info                  CBS    Added C:\Windows\Logs\CBS\CBS.log to WER report.
2023-06-09 19:17:57, Info                  CBS    Startup: Changing logon timeout to a static timeout: 10800000
2023-06-09 19:17:58, Info                  CBS    Added C:\Windows\Logs\CBS\CbsPersist_20230609062027.log to WER report.
2023-06-09 19:17:58, Info                  CBS    Added C:\Windows\Logs\CBS\CbsPersist_20230609045320.log to WER report.
2023-06-09 19:17:58, Info                  CBS    Added C:\Windows\Logs\CBS\CbsPersist_20230609020644.log to WER report.
2023-06-09 19:17:59, Info                  CBS    Added C:\Windows\Logs\CBS\CbsPersist_20230608235700.log to WER report.
2023-06-09 19:17:59, Info                  CBS    Added C:\Windows\Logs\CBS\CbsPersist_20230608215110.log to WER report.
2023-06-09 19:18:00, Info                  CBS    Not able to add pending.xml.bad to Windows Error Report. [HRESULT = 0x80070002 - ERROR_FILE_NOT_FOUND]
2023-06-09 19:18:00, Info                  CBS    Not able to add SCM.EVM to Windows Error Report. [HRESULT = 0x80070002 - ERROR_FILE_NOT_FOUND]
2023-06-09 19:18:02, Error                 CSI    000000bc (F) STATUS_SHARING_VIOLATION #22289# from Windows::COM::CQueueExecutor::ExecutePhase(Flags = 00000000, Progress = NULL, Phase = 31, NextIndex = 37, TotalItems = 129)
[gle=0xd0000043]
2023-06-09 19:18:02, Info                  CBS    Startup: Changing logon timeout to a sliding window timeout: 900000
2023-06-09 19:18:03, Error                 CSI    000000bd (F) HRESULT_FROM_WIN32(ERROR_SHARING_VIOLATION) #158# from Windows::COM::CComponentStore_IAdvancedInstallerAwareStore::ResolvePendingTransactions(dwFlags = (DontFailIfPrimitivesPending|IndicatePrimitiveRollback), Progress = NULL, Phase = 0, Disposition = (unknown enumerant 0)' | '0)[gle=0x80070020]
2023-06-09 19:18:03, Error                 CBS    Startup: Failed to process advanced operation queue, startupPhase: 0. [HRESULT = 0x80070020 - ERROR_SHARING_VIOLATION]
2023-06-09 19:18:03, Info                  CBS    Current global progress. Current: 25, Limit: 102, ExecuteState: CbsExecuteStateResolvePending
2023-06-09 19:18:03, Info                  CBS    Previous global progress. Current: 25, Limit: 102, ExecuteState: CbsExecuteStateResolvePending
2023-06-09 19:18:03, Error                 CBS    Startup: No progress detected while needing to process the advanced operation queue, rolling back and cancelling the transaction. [HRESULT = 0x80004005 - E_FAIL]
2023-06-09 19:18:03, Info                  CBS    Setting ExecuteState key to: CbsExecuteStateInitiateRollback | CbsExecuteStateFlagAdvancedInstallersFailed
2023-06-09 19:18:03, Info                  CBS    SetProgressMessage: progressMessageStage: -1, ExecuteState: CbsExecuteStateInitiateRollback | CbsExecuteStateFlagAdvancedInstallersFailed, SubStage: 0
2023-06-09 19:18:03, Info                  CBS    Progress: UI message updated. Operation type: Update. Stage: 0 out of 0. Rollback.
2023-06-09 19:18:03, Info                  CBS    Attempting to remove poqexec from SetupExecute
2023-06-09 19:18:03, Info                  CBS    Removed poqexec from SetupExecute.
2023-06-09 19:18:03, Info                  CBS    Configured poqexec to not pend to SetupExecute.
2023-06-09 19:18:03, Info                  CBS    Startup: Changing logon timeout to a static timeout: 10800000
2023-06-09 19:18:05, Info                  CSI    000000be Rolling back transactions...
 

Attachments

Were there any other CBS logs?

Could you please provide a copy of your USERS hive? You may use these instructions to do so:

Export USERS hive
  • Click on the Start button and in the search box, type regedit
  • When you see regedit on the list, right-click on it and select Run as administrator.
  • When regedit opens, using the left pane, navigate to the following registry key and select it by clicking on it once.

    HKEY_LOCAL_MACHINE\HKEY_USERS
  • Once selected, click File > Export....
  • Change the Save as type: to Registry Hive Files (.).
  • Name this file USERS (with no file extension) and save it to your Desktop.
  • Right-click on the saved file and choose Send To -> Compressed (zipped) Folder.
  • Attach the .ZIP file to your next post.
  • If the file is too large to upload here, upload to Dropbox or OneDrive or WeTransfer and just provide the link in a private message to myself.
 
  1. Download Handle from the Sysinternals suite and then save it to your Desktop
  2. Unzip handle.zip and then open an administrative/elevated command prompt in the same directory as handle.exe
  3. From command prompt, please enter the following command: handle -a -v HKEY_LOCAL_MACHINE\HKEY_USERS\S-1-5-21-2281769908-589326359-3636360395-32558 >> %userprofile%\Desktop\UserHandles.csv
  4. A .csv file called UserHandles should be saved to your Desktop, please attach this file in your next post.
 
Thanks, could you please get a Process Monitor trace while you're trying to update?

Capture Process Monitor BootLog
1. Download and run Process Monitor. Leave this running while you perform the next steps.
2. Select the Options....Enable Boot Logging option. A Enable Boot Logging dialog will come up. Just click OK.
3. Create a folder on your desktop named BootLog.
4. Attempt to install the update just like you have in the past. Let the machine reboot and revert just like it has in the past.
5. After the machine has rebooted and come back up to the desktop, open Process Monitor again. A message box will come up telling you that a log of boot-time activity was created and ask if you wish to save it. Click Yes and save to the BootLog folder on your desktop.
6. This may take some time as it converts the boot-time data. Allow it to finish.
7. Zip up the entire BootLog folder on your desktop and upload to a file sharing service of your choice for my review. Examples of services to upload to are Dropbox or OneDrive or WeTransfer
 
Ok, I will do IT but tomorrow. I can delete user profiles with specified sids. Do it?
 
Last edited:
I can delete user profiles with specified sids. Do it?
No because I don't believe those are the issue, it seems that another program is accessing part of your registry at the same time as Windows Update which is causing the update to roll back and fail. The Process Monitor boot trace should hopefully reveal what is accessing those keys during the update process.
 
In the meantime, could you please run the following command from command prompt and then post the output in your next post:

Code:
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" /s
 
Yes , of course
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Default REG_EXPAND_SZ %SystemDrive%\Users\Default
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users
ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramData
Public REG_EXPAND_SZ %SystemDrive%\Users\Public

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
State REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
Flags REG_DWORD 0x0
ProfileImagePath REG_EXPAND_SZ %systemroot%\ServiceProfiles\LocalService
State REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
Flags REG_DWORD 0x0
ProfileImagePath REG_EXPAND_SZ %systemroot%\ServiceProfiles\NetworkService
State REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14168
ProfileImagePath REG_EXPAND_SZ C:\Users\admin1
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED858370000
Guid REG_SZ {b236cb40-4a1d-4635-a0bc-6c9e9797ad4c}
LocalProfileLoadTimeLow REG_DWORD 0x4d519e54
LocalProfileLoadTimeHigh REG_DWORD 0x1d8f9c8
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xa4452190
LocalProfileUnloadTimeHigh REG_DWORD 0x1d8fda4

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14169
ProfileImagePath REG_EXPAND_SZ C:\Users\admin2
Flags REG_DWORD 0x1
FullProfile REG_DWORD 0x1
State REG_DWORD 0x100
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED859370000
Guid REG_SZ {54985567-b2da-4dcf-abeb-c6ca97525241}
LocalProfileLoadTimeLow REG_DWORD 0x385d217e
LocalProfileLoadTimeHigh REG_DWORD 0x1d98c8d
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x3be04568
LocalProfileUnloadTimeHigh REG_DWORD 0x1d98c8d

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14170
ProfileImagePath REG_EXPAND_SZ C:\Users\admin3
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED85A370000
Guid REG_SZ {304f0d8c-1478-48f4-a7a8-f78791274722}
LocalProfileLoadTimeLow REG_DWORD 0x41cb94b1
LocalProfileLoadTimeHigh REG_DWORD 0x1d97cc0
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x2764a838
LocalProfileUnloadTimeHigh REG_DWORD 0x1d97f54

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14180
ProfileImagePath REG_EXPAND_SZ C:\Users\admin4
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x204
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED864370000
Guid REG_SZ {446c3b5a-9249-4073-b310-067938f051cd}
LocalProfileLoadTimeLow REG_DWORD 0xa4e6f05e
LocalProfileLoadTimeHigh REG_DWORD 0x1d808ca
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xaeaf09c4
LocalProfileUnloadTimeHigh REG_DWORD 0x1d808cb

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14181
ProfileImagePath REG_EXPAND_SZ C:\Users\admin5
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED865370000
Guid REG_SZ {da312697-4a99-4c49-a1d8-dd141f2fecc2}
LocalProfileLoadTimeLow REG_DWORD 0xb03dd113
LocalProfileLoadTimeHigh REG_DWORD 0x1d96609
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xa16d9aa0
LocalProfileUnloadTimeHigh REG_DWORD 0x1d96621

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-14652
ProfileImagePath REG_EXPAND_SZ C:\Users\admin6
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED83C390000
Guid REG_SZ {8840c098-26f3-4853-aa5e-5e746d0f850b}
LocalProfileLoadTimeLow REG_DWORD 0xfccaf84c
LocalProfileLoadTimeHigh REG_DWORD 0x1d7df74
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xbed9a46b
LocalProfileUnloadTimeHigh REG_DWORD 0x1d7f2c6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-24653
ProfileImagePath REG_EXPAND_SZ C:\Users\admin7
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED84D600000
Guid REG_SZ {091e7341-8b5c-43e9-bea8-6e5a1c40c787}
LocalProfileLoadTimeLow REG_DWORD 0x58aba0e2
LocalProfileLoadTimeHigh REG_DWORD 0x1d99904
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xdd63a580
LocalProfileUnloadTimeHigh REG_DWORD 0x1d9993f

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-32558
ProfileImagePath REG_EXPAND_SZ C:\Users\admin8
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x204
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED82E7F0000
Guid REG_SZ {a6cd7793-8094-4d22-b824-488a0d7f7d55}
LocalProfileLoadTimeLow REG_DWORD 0xd28d2e81
LocalProfileLoadTimeHigh REG_DWORD 0x1d9013a
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x9500cbcf
LocalProfileUnloadTimeHigh REG_DWORD 0x1d910d7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-37241
ProfileImagePath REG_EXPAND_SZ C:\Users\admin9
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED879910000
Guid REG_SZ {6cb4750c-f893-48a4-a562-d99c38943743}
LocalProfileLoadTimeLow REG_DWORD 0xf51b406d
LocalProfileLoadTimeHigh REG_DWORD 0x1d94262
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x9c6c355f
LocalProfileUnloadTimeHigh REG_DWORD 0x1d947d2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-38750
ProfileImagePath REG_EXPAND_SZ C:\Users\admin10
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED85E970000
Guid REG_SZ {f2bfe292-7139-42af-9e9a-f2a9827d8cb3}
LocalProfileLoadTimeLow REG_DWORD 0x2e522b4d
LocalProfileLoadTimeHigh REG_DWORD 0x1d99a8e
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x77538e40
LocalProfileUnloadTimeHigh REG_DWORD 0x1d99a8e

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-39153
ProfileImagePath REG_EXPAND_SZ C:\Users\admin11
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED8F1980000
Guid REG_SZ {432e2f35-719b-42e4-8b5f-ae26b020568f}
LocalProfileLoadTimeLow REG_DWORD 0x68e832dc
LocalProfileLoadTimeHigh REG_DWORD 0x1d99a9a
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xfffcc2f3
LocalProfileUnloadTimeHigh REG_DWORD 0x1d99af2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-39681
ProfileImagePath REG_EXPAND_SZ C:\Users\admin12
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED8019B0000
Guid REG_SZ {a5d42358-3d1a-4a8a-bf07-7819ffdac2f1}
LocalProfileLoadTimeLow REG_DWORD 0x9fa4a7a9
LocalProfileLoadTimeHigh REG_DWORD 0x1d99c5c
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x3664e179
LocalProfileUnloadTimeHigh REG_DWORD 0x1d99c55

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-39763
ProfileImagePath REG_EXPAND_SZ C:\Users\admin14
Flags REG_DWORD 0x1
FullProfile REG_DWORD 0x1
State REG_DWORD 0x100
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED8539B0000
Guid REG_SZ {6c80e40b-c47a-443d-b9a3-62fc0c28ba17}
LocalProfileLoadTimeLow REG_DWORD 0xe520457c
LocalProfileLoadTimeHigh REG_DWORD 0x1d992ec
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xe89786da
LocalProfileUnloadTimeHigh REG_DWORD 0x1d992ec

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2281769908-589326359-3636360395-9626
ProfileImagePath REG_EXPAND_SZ C:\Users\admin15
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x204
Sid REG_BINARY 010500000000000515000000B40B018817682023CB74BED89A250000
Guid REG_SZ {0bb0734d-73c2-42f8-a3c0-1e809e89f6f6}
LocalProfileLoadTimeLow REG_DWORD 0x5d6736ff
LocalProfileLoadTimeHigh REG_DWORD 0x1d931e2
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xb59dfa86
LocalProfileUnloadTimeHigh REG_DWORD 0x1d931e2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2990528403-172780673-2064200256-500
ProfileImagePath REG_EXPAND_SZ C:\Users\Administrator
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x100
Sid REG_BINARY 01050000000000051500000093D73FB2816C4C0A4032097BF4010000
LocalProfileLoadTimeLow REG_DWORD 0x5e418774
LocalProfileLoadTimeHigh REG_DWORD 0x1d7a301
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0x43a61021
LocalProfileUnloadTimeHigh REG_DWORD 0x1d7a308

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-651377827-682003330-140008
ProfileImagePath REG_EXPAND_SZ C:\Users\non_adminuser
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010500000000000515000000BE043E32A33CD326828BA628E8220200
Guid REG_SZ {6082c9f8-6708-4526-b7e9-238816fc3a46}
LocalProfileLoadTimeLow REG_DWORD 0xf6d1593e
LocalProfileLoadTimeHigh REG_DWORD 0x1d853b6
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xf98a1488
LocalProfileUnloadTimeHigh REG_DWORD 0x1d853b6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\SQLTELEMETRY
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010600000000000550000000447A1A9EE0235381234A54AA9BD0549C4FCC0642
LocalProfileLoadTimeLow REG_DWORD 0x24e2b2f7
LocalProfileLoadTimeHigh REG_DWORD 0x1d99afb
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xd09adb6f
LocalProfileUnloadTimeHigh REG_DWORD 0x1d99a53

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\MSSQLSERVER
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010600000000000550000000E20F4FE7B15874E48E19026478C2DC9AC307B83E
LocalProfileLoadTimeLow REG_DWORD 0x76132a28
LocalProfileLoadTimeHigh REG_DWORD 0x1d7a310
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xb4055268
LocalProfileUnloadTimeHigh REG_DWORD 0x1d7a313

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-80-4050220999-2730734961-1537482082-519850261-379003301
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\SQLServerReportingServices
Flags REG_DWORD 0x0
FullProfile REG_DWORD 0x1
State REG_DWORD 0x0
Sid REG_BINARY 010600000000000550000000C77769F171B5C3A2621DA45B1549FC1EA5219716
LocalProfileLoadTimeLow REG_DWORD 0x612321f6
LocalProfileLoadTimeHigh REG_DWORD 0x1d7a312
ProfileAttemptedProfileDownloadTimeLow REG_DWORD 0x0
ProfileAttemptedProfileDownloadTimeHigh REG_DWORD 0x0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
LocalProfileUnloadTimeLow REG_DWORD 0xcd4e53ae
LocalProfileUnloadTimeHigh REG_DWORD 0x1d7a313
 
Thanks, just wanted to check if those user profiles were related to particular software or were just "ordinary" user profiles. Once you're able to get the Process Monitor boot trace tomorrow or in the next few days, then I'll have a look at it and let you know if I find anything in particular.
 
Thanks for providing the boot log over private message, I've had a quick look and there is certainly a number of services accessing those user profile keys. Could you please open an elevated/administrative command prompt and then the following command:

Code:
wmic service get name,displayname,pathname,startmode,exitcode > "%userprofile%\desktop\services.txt"

Please attach the services.txt file which will be saved to your desktop. I just want to take a look at what those services are for.
 
Hello, no problem
Code:
DisplayName                                                                         ExitCode  Name                                      PathName                                                                                                                                                                       StartMode 
Microsoft Monitoring Agent Audit Forwarding                                         1077      AdtAgent                                  C:\Windows\system32\AdtAgent.exe                                                                                                                                               Disabled   
AllJoyn Router Service                                                              1077      AJRouter                                  C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Application Layer Gateway Service                                                   1077      ALG                                       C:\Windows\System32\alg.exe                                                                                                                                                    Manual     
Application Identity                                                                1077      AppIDSvc                                  C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Application Information                                                             0         Appinfo                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Application Management                                                              1077      AppMgmt                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
App Readiness                                                                       1077      AppReadiness                              C:\Windows\System32\svchost.exe -k AppReadiness -p                                                                                                                             Manual     
Microsoft App-V Client                                                              1077      AppVClient                                C:\Windows\system32\AppVClient.exe                                                                                                                                             Disabled   
AppX Deployment Service (AppXSVC)                                                   0         AppXSvc                                   C:\Windows\system32\svchost.exe -k wsappx -p                                                                                                                                   Manual     
Windows Audio Endpoint Builder                                                      1077      AudioEndpointBuilder                      C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Windows Audio                                                                       1077      Audiosrv                                  C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
ActiveX Installer (AxInstSV)                                                        1077      AxInstSV                                  C:\Windows\system32\svchost.exe -k AxInstSVGroup                                                                                                                               Disabled   
AzureAttestService                                                                  0         AzureAttestService                        C:\Windows\system32\svchost.exe -k AzureAttestService                                                                                                                          Auto       
Base Filtering Engine                                                               0         BFE                                       C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                                                                                                            Auto       
Background Intelligent Transfer Service                                             0         BITS                                      C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Background Tasks Infrastructure Service                                             0         BrokerInfrastructure                      C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Auto       
Bluetooth Audio Gateway Service                                                     1077      BTAGService                               C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted                                                                                                               Manual     
AVCTP service                                                                       0         BthAvctpSvc                               C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Bluetooth Support Service                                                           1077      bthserv                                   C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Capability Access Manager Service                                                   0         camsvc                                    C:\Windows\system32\svchost.exe -k appmodel -p                                                                                                                                 Manual     
Connected Devices Platform Service                                                  0         CDPSvc                                    C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Auto       
Certificate Propagation                                                             0         CertPropSvc                               C:\Windows\system32\svchost.exe -k netsvcs                                                                                                                                     Manual     
Client License Service (ClipSVC)                                                    0         ClipSVC                                   C:\Windows\System32\svchost.exe -k wsappx -p                                                                                                                                   Manual     
COM+ System Application                                                             0         COMSysApp                                 C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}                                                                                              Manual     
CoreMessaging                                                                       0         CoreMessagingRegistrar                    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p                                                                                                                    Auto       
Cryptographic Services                                                              0         CryptSvc                                  C:\Windows\system32\svchost.exe -k NetworkService -p                                                                                                                           Auto       
Offline Files                                                                       1077      CscService                                C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Disabled   
DCOM Server Process Launcher                                                        0         DcomLaunch                                C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Auto       
Data Deduplication Service                                                          0         ddpsvc                                    C:\Windows\system32\svchost -k ddpsvc                                                                                                                                          Manual     
Data Deduplication Volume Shadow Copy Service                                       0         ddpvssvc                                  C:\Windows\system32\svchost -k ddpvssvc                                                                                                                                        Auto       
Optimize drives                                                                     0         defragsvc                                 C:\Windows\system32\svchost.exe -k defragsvc                                                                                                                                   Manual     
Device Association Service                                                          1077      DeviceAssociationService                  C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Device Install Service                                                              1077      DeviceInstall                             C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Manual     
DevQuery Background Discovery Broker                                                1077      DevQueryBroker                            C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
DHCP Client                                                                         0         Dhcp                                      C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Auto       
Microsoft (R) Diagnostics Hub Standard Collector Service                            1077      diagnosticshub.standardcollector.service  C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe                                                                                                      Manual     
Connected User Experiences and Telemetry                                            0         DiagTrack                                 C:\Windows\System32\svchost.exe -k utcsvc -p                                                                                                                                   Auto       
Device Management Enrollment Service                                                0         DmEnrollmentSvc                           C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Device Management Wireless Application Protocol (WAP) Push message Routing Service  1077      dmwappushservice                          C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
DNS Client                                                                          0         Dnscache                                  C:\Windows\system32\svchost.exe -k NetworkService -p                                                                                                                           Auto       
Delivery Optimization                                                               1077      DoSvc                                     C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Disabled   
Wired AutoConfig                                                                    1077      dot3svc                                   C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
DPM Agent Coordinator                                                               1077      DPMAC                                     "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\dpmac.exe" -DPMAC                                                                                                   Manual     
DPM AccessManager Service                                                           0         DPMAMService                              "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\DPMAMService.exe"                                                                                                   Auto       
DPM CPWrapper Service                                                               1077      DpmCPWrapperService                       "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\CPWrapperServiceHost.exe"                                                                                           Disabled   
DPMLA                                                                               1077      DPMLA                                     "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\DPMLA.exe" -LAAgent                                                                                                 Manual     
DPMRA                                                                               0         DPMRA                                     "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\DPMRA.exe" -DPMRA                                                                                                   Manual     
DPM-VMM Helper Service                                                              1077      DpmVmmHelperService                       "C:\Program Files\Microsoft System Center 2022\DPM\DPM\VmmHelperService\VmmHelperServiceHost.exe"                                                                              Disabled   
DPM Writer                                                                          0         DpmWriter                                 "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\DpmWriter.exe"                                                                                                      Auto       
Diagnostic Policy Service                                                           0         DPS                                       C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p                                                                                                                    Auto       
Device Setup Manager                                                                0         DsmSvc                                    C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Data Sharing Service                                                                0         DsSvc                                     C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Extensible Authentication Protocol                                                  1077      Eaphost                                   C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Encrypting File System (EFS)                                                        1077      EFS                                       C:\Windows\System32\lsass.exe                                                                                                                                                  Manual     
Embedded Mode                                                                       1077      embeddedmode                              C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Enterprise App Management Service                                                   1077      EntAppSvc                                 C:\Windows\system32\svchost.exe -k appmodel -p                                                                                                                                 Manual     
Windows Event Log                                                                   0         EventLog                                  C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Auto       
COM+ Event System                                                                   0         EventSystem                               C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Auto       
Function Discovery Provider Host                                                    0         fdPHost                                   C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Function Discovery Resource Publication                                             0         FDResPub                                  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p                                                                                                           Manual     
Windows Font Cache Service                                                          0         FontCache                                 C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Auto       
Windows Camera Frame Server                                                         1077      FrameServer                               C:\Windows\System32\svchost.exe -k Camera                                                                                                                                      Manual     
FusionInventory Agent                                                               0         FusionInventory-Agent                     "C:\Program Files\FusionInventory-Agent\perl\bin\fusioninventory-agent.exe" "C:\Program Files\FusionInventory-Agent\perl\bin\fusioninventory-win32-service"                    Auto       
Group Policy Client                                                                 0         gpsvc                                     C:\Windows\system32\svchost.exe -k GPSvcGroup                                                                                                                                  Auto       
GraphicsPerfSvc                                                                     1077      GraphicsPerfSvc                           C:\Windows\System32\svchost.exe -k GraphicsPerfSvcGroup                                                                                                                        Disabled   
Microsoft Monitoring Agent                                                          0         HealthService                             "C:\Program Files\Microsoft Monitoring Agent\Agent\HealthService.exe"                                                                                                          Auto       
Host Guardian Client Service                                                        1077      HgClientService                           C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Human Interface Device Service                                                      1077      hidserv                                   C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
HV Host Service                                                                     0         HvHost                                    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Windows Mobile Hotspot Service                                                      1077      icssvc                                    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Disabled   
IKE and AuthIP IPsec Keying Modules                                                 1077      IKEEXT                                    C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Microsoft Store Install Service                                                     1077      InstallService                            C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
IP Helper                                                                           0         iphlpsvc                                  C:\Windows\System32\svchost.exe -k NetSvcs -p                                                                                                                                  Auto       
CNG Key Isolation                                                                   0         KeyIso                                    C:\Windows\system32\lsass.exe                                                                                                                                                  Manual     
KDC Proxy Server service (KPS)                                                      1077      KPSSVC                                    C:\Windows\system32\svchost.exe -k KpsSvcGroup                                                                                                                                 Manual     
KtmRm for Distributed Transaction Coordinator                                       1077      KtmRm                                     C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation -p                                                                                                         Manual     
Server                                                                              0         LanmanServer                              C:\Windows\System32\svchost.exe -k smbsvcs                                                                                                                                     Auto       
Workstation                                                                         0         LanmanWorkstation                         C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Auto       
Geolocation Service                                                                 1077      lfsvc                                     C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
Windows License Manager Service                                                     0         LicenseManager                            C:\Windows\System32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Link-Layer Topology Discovery Mapper                                                1077      lltdsvc                                   C:\Windows\System32\svchost.exe -k LocalService -p                                                                                                                             Disabled   
TCP/IP NetBIOS Helper                                                               0         lmhosts                                   C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Local Session Manager                                                               0         LSM                                       C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Auto       
Downloaded Maps Manager                                                             1077      MapsBroker                                C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Disabled   
Windows Defender Firewall                                                           0         mpssvc                                    C:\Windows\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p                                                                                                            Auto       
DPM                                                                                 0         MSDPM                                     "C:\Program Files\Microsoft System Center 2022\DPM\DPM\bin\msdpm.exe"                                                                                                          Manual     
Distributed Transaction Coordinator                                                 0         MSDTC                                     C:\Windows\System32\msdtc.exe                                                                                                                                                  Auto       
Microsoft iSCSI Initiator Service                                                   1077      MSiSCSI                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Windows Installer                                                                   1077      msiserver                                 C:\Windows\system32\msiexec.exe /V                                                                                                                                             Manual     
SQL Server (MSSQLSERVER)                                                            0         MSSQLSERVER                               "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER                                                                              Auto       
Network Connectivity Assistant                                                      0         NcaSvc                                    C:\Windows\System32\svchost.exe -k NetSvcs -p                                                                                                                                  Manual     
Network Connection Broker                                                           0         NcbService                                C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Netlogon                                                                            0         Netlogon                                  C:\Windows\system32\lsass.exe                                                                                                                                                  Auto       
Network Connections                                                                 1077      Netman                                    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Network List Service                                                                0         netprofm                                  C:\Windows\System32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Network Setup Service                                                               0         NetSetupSvc                               C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Net.Tcp Port Sharing Service                                                        1077      NetTcpPortSharing                         C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe                                                                                                                  Disabled   
Microsoft Passport Container                                                        1077      NgcCtnrSvc                                C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Microsoft Passport                                                                  1077      NgcSvc                                    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Network Location Awareness                                                          0         NlaSvc                                    C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Auto       
Network Store Interface Service                                                     0         nsi                                       C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Auto       
Program Compatibility Assistant Service                                             0         PcaSvc                                    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Performance Counter DLL Host                                                        1077      PerfHost                                  C:\Windows\SysWow64\perfhost.exe                                                                                                                                               Manual     
Phone Service                                                                       1077      PhoneSvc                                  C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Disabled   
Performance Logs & Alerts                                                           1077      pla                                       C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork -p                                                                                                                    Manual     
Plug and Play                                                                       0         PlugPlay                                  C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Manual     
IPsec Policy Agent                                                                  0         PolicyAgent                               C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted -p                                                                                                          Manual     
Power                                                                               0         Power                                     C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Auto       
Printer Extensions and Notifications                                                1077      PrintNotify                               C:\Windows\system32\svchost.exe -k print                                                                                                                                       Manual     
User Profile Service                                                                0         ProfSvc                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
ProLiant Monitor Service                                                            0         ProLiantMonitor                           "C:\Program Files\Hewlett-Packard\iLO 3\service\ProLiantMonitor.exe"                                                                                                           Auto       
Windows PushToInstall Service                                                       1077      PushToInstall                             C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
Quality Windows Audio Video Experience                                              1077      QWAVE                                     C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p                                                                                                           Manual     
Remote Access Auto Connection Manager                                               1077      RasAuto                                   C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Remote Access Connection Manager                                                    0         RasMan                                    C:\Windows\System32\svchost.exe -k netsvcs                                                                                                                                     Auto       
Routing and Remote Access                                                           1077      RemoteAccess                              C:\Windows\System32\svchost.exe -k netsvcs                                                                                                                                     Disabled   
Remote Registry                                                                     0         RemoteRegistry                            C:\Windows\system32\svchost.exe -k localService -p                                                                                                                             Auto       
Radio Management Service                                                            1077      RmSvc                                     C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted                                                                                                               Disabled   
RPC Endpoint Mapper                                                                 0         RpcEptMapper                              C:\Windows\system32\svchost.exe -k RPCSS -p                                                                                                                                    Auto       
Remote Procedure Call (RPC) Locator                                                 1077      RpcLocator                                C:\Windows\system32\locator.exe                                                                                                                                                Manual     
Remote Procedure Call (RPC)                                                         0         RpcSs                                     C:\Windows\system32\svchost.exe -k rpcss -p                                                                                                                                    Auto       
Resultant Set of Policy Provider                                                    1077      RSoPProv                                  C:\Windows\system32\RSoPProv.exe                                                                                                                                               Manual     
Special Administration Console Helper                                               0         sacsvr                                    C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Security Accounts Manager                                                           0         SamSs                                     C:\Windows\system32\lsass.exe                                                                                                                                                  Auto       
Smart Card                                                                          1077      SCardSvr                                  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation                                                                                                              Manual     
Smart Card Device Enumeration Service                                               1077      ScDeviceEnum                              C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted                                                                                                                Disabled   
Task Scheduler                                                                      0         Schedule                                  C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Smart Card Removal Policy                                                           0         SCPolicySvc                               C:\Windows\system32\svchost.exe -k netsvcs                                                                                                                                     Auto       
Secondary Logon                                                                     1077      seclogon                                  C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Windows Security Service                                                            1077      SecurityHealthService                     C:\Windows\system32\SecurityHealthService.exe                                                                                                                                  Manual     
Payments and NFC/SE Manager                                                         1077      SEMgrSvc                                  C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Disabled   
System Event Notification Service                                                   0         SENS                                      C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Windows Defender Advanced Threat Protection Service                                 1077      Sense                                     "C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe"                                                                                                     Manual     
Sensor Data Service                                                                 1077      SensorDataService                         C:\Windows\System32\SensorDataService.exe                                                                                                                                      Disabled   
Sensor Service                                                                      1077      SensorService                             C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Sensor Monitoring Service                                                           1077      SensrSvc                                  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p                                                                                                           Manual     
Remote Desktop Configuration                                                        0         SessionEnv                                C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
System Guard Runtime Monitor Broker                                                 1077      SgrmBroker                                C:\Windows\system32\SgrmBroker.exe                                                                                                                                             Manual     
Internet Connection Sharing (ICS)                                                   1077      SharedAccess                              C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
Shell Hardware Detection                                                            0         ShellHWDetection                          C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Shared PC Account Manager                                                           1077      shpamsvc                                  C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
Microsoft Storage Spaces SMP                                                        0         smphost                                   C:\Windows\System32\svchost.exe -k smphost                                                                                                                                     Manual     
SNMP Trap                                                                           1077      SNMPTRAP                                  C:\Windows\System32\snmptrap.exe                                                                                                                                               Manual     
Print Spooler                                                                       0         Spooler                                   C:\Windows\System32\spoolsv.exe                                                                                                                                                Auto       
Software Protection                                                                 0         sppsvc                                    C:\Windows\system32\sppsvc.exe                                                                                                                                                 Auto       
SQL Server Browser                                                                  0         SQLBrowser                                "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"                                                                                                         Auto       
SQL Server Agent (MSSQLSERVER)                                                      0         SQLSERVERAGENT                            "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER                                                                             Auto       
SQL Server Reporting Services                                                       0         SQLServerReportingServices                "C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\RSHostingService\RSHostingService.exe"                                                                          Auto       
SQL Server CEIP service (MSSQLSERVER)                                               0         SQLTELEMETRY                              "C:\Program Files\Microsoft SQL Server\MSSQL15.MSSQLSERVER\MSSQL\Binn\sqlceip.exe" -Service                                                                                    Auto       
SQL Server VSS Writer                                                               0         SQLWriter                                 "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"                                                                                                                Auto       
SSDP Discovery                                                                      1077      SSDPSRV                                   C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p                                                                                                           Disabled   
OpenSSH Authentication Agent                                                        1077      ssh-agent                                 C:\Windows\System32\OpenSSH\ssh-agent.exe                                                                                                                                      Disabled   
Secure Socket Tunneling Protocol Service                                            0         SstpSvc                                   C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Manual     
State Repository Service                                                            0         StateRepository                           C:\Windows\system32\svchost.exe -k appmodel -p                                                                                                                                 Manual     
Windows Image Acquisition (WIA)                                                     1077      stisvc                                    C:\Windows\system32\svchost.exe -k imgsvc                                                                                                                                      Manual     
Storage Service                                                                     0         StorSvc                                   C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Spot Verifier                                                                       1077      svsvc                                     C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Microsoft Software Shadow Copy Provider                                             0         swprv                                     C:\Windows\System32\svchost.exe -k swprv                                                                                                                                       Manual     
SysMain                                                                             0         SysMain                                   C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Auto       
HP System Management Homepage                                                       0         SysMgmtHp                                 C:\hp\hpsmh\bin\smhstart.exe                                                                                                                                                   Auto       
Sysmon                                                                              0         Sysmon                                    C:\Windows\Sysmon.exe                                                                                                                                                          Auto       
System Events Broker                                                                0         SystemEventsBroker                        C:\Windows\system32\svchost.exe -k DcomLaunch -p                                                                                                                               Auto       
Touch Keyboard and Handwriting Panel Service                                        0         TabletInputService                        C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Telephony                                                                           1077      tapisrv                                   C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Manual     
Telegraf Data Collector Service                                                     0         telegraf                                  "C:\Program Files\Telegraf\telegraf.exe" --config "C:\Program Files\Telegraf\telegraf.conf" --config-directory "C:\Program Files\Telegraf\telegraf.d" --service-name telegraf  Auto       
Remote Desktop Services                                                             0         TermService                               C:\Windows\System32\svchost.exe -k termsvcs                                                                                                                                    Manual     
Themes                                                                              0         Themes                                    C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Storage Tiers Management                                                            1077      TieringEngineService                      C:\Windows\system32\TieringEngineService.exe                                                                                                                                   Manual     
Time Broker                                                                         0         TimeBrokerSvc                             C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Web Account Manager                                                                 0         TokenBroker                               C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Distributed Link Tracking Client                                                    0         TrkWks                                    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Auto       
Windows Modules Installer                                                           0         TrustedInstaller                          C:\Windows\servicing\TrustedInstaller.exe                                                                                                                                      Manual     
Auto Time Zone Updater                                                              1077      tzautoupdate                              C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Disabled   
User Access Logging Service                                                         0         UALSVC                                    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Auto       
User Experience Virtualization Service                                              1077      UevAgentService                           C:\Windows\system32\AgentService.exe                                                                                                                                           Disabled   
Remote Desktop Services UserMode Port Redirector                                    0         UmRdpService                              C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
UPnP Device Host                                                                    1077      upnphost                                  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation -p                                                                                                           Disabled   
User Manager                                                                        0         UserManager                               C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Update Orchestrator Service                                                         0         UsoSvc                                    C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Credential Manager                                                                  1077      VaultSvc                                  C:\Windows\system32\lsass.exe                                                                                                                                                  Manual     
Virtual Disk                                                                        1077      vds                                       C:\Windows\System32\vds.exe                                                                                                                                                    Manual     
Hyper-V Host Compute Service                                                        0         vmcompute                                 C:\Windows\system32\vmcompute.exe                                                                                                                                              Manual     
Hyper-V Guest Service Interface                                                     1077      vmicguestinterface                        C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Hyper-V Heartbeat Service                                                           1077      vmicheartbeat                             C:\Windows\system32\svchost.exe -k ICService -p                                                                                                                                Manual     
Hyper-V Data Exchange Service                                                       1077      vmickvpexchange                           C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Hyper-V Remote Desktop Virtualization Service                                       1077      vmicrdv                                   C:\Windows\system32\svchost.exe -k ICService -p                                                                                                                                Manual     
Hyper-V Guest Shutdown Service                                                      1077      vmicshutdown                              C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Hyper-V Time Synchronization Service                                                1077      vmictimesync                              C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Hyper-V PowerShell Direct Service                                                   1077      vmicvmsession                             C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Hyper-V Volume Shadow Copy Requestor                                                1077      vmicvss                                   C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Hyper-V Virtual Machine Management                                                  0         vmms                                      C:\Windows\system32\vmms.exe                                                                                                                                                   Auto       
Volume Shadow Copy                                                                  0         VSS                                       C:\Windows\system32\vssvc.exe                                                                                                                                                  Manual     
VssNullProvider                                                                     0         VssNullProvider                           C:\Windows\system32\dllhost.exe /Processid:{C0DD64EF-4CD7-4CAF-BCF0-37E6AE6FB2B2}                                                                                              Manual     
Windows Time                                                                        0         W32Time                                   C:\Windows\system32\svchost.exe -k LocalService                                                                                                                                Auto       
Windows Update Medic Service                                                        0         WaaSMedicSvc                              C:\Windows\system32\svchost.exe -k wusvcs -p                                                                                                                                   Manual     
WalletService                                                                       1077      WalletService                             C:\Windows\System32\svchost.exe -k appmodel -p                                                                                                                                 Disabled   
WarpJITSvc                                                                          1077      WarpJITSvc                                C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted                                                                                                               Manual     
Windows Biometric Service                                                           1077      WbioSrvc                                  C:\Windows\system32\svchost.exe -k WbioSvcGroup                                                                                                                                Manual     
Windows Connection Manager                                                          0         Wcmsvc                                    C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Auto       
Diagnostic Service Host                                                             1077      WdiServiceHost                            C:\Windows\System32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Diagnostic System Host                                                              0         WdiSystemHost                             C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Windows Defender Antivirus Network Inspection Service                               0         WdNisSvc                                  "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.3-0\NisSrv.exe"                                                                                                 Manual     
Windows Event Collector                                                             1077      Wecsvc                                    C:\Windows\system32\svchost.exe -k NetworkService -p                                                                                                                           Manual     
Windows Encryption Provider Host Service                                            1077      WEPHOSTSVC                                C:\Windows\system32\svchost.exe -k WepHostSvcGroup                                                                                                                             Manual     
Problem Reports and Solutions Control Panel Support                                 1077      wercplsupport                             C:\Windows\System32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
Windows Error Reporting Service                                                     0         WerSvc                                    C:\Windows\System32\svchost.exe -k WerSvcGroup                                                                                                                                 Manual     
Still Image Acquisition Events                                                      1077      WiaRpc                                    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p                                                                                                             Manual     
Windows Defender Antivirus Service                                                  0         WinDefend                                 "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.3-0\MsMpEng.exe"                                                                                                Auto       
WinHTTP Web Proxy Auto-Discovery Service                                            0         WinHttpAutoProxySvc                       C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p                                                                                                            Manual     
Windows Management Instrumentation                                                  0         Winmgmt                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Windows Remote Management (WS-Management)                                           0         WinRM                                     C:\Windows\System32\svchost.exe -k NetworkService -p                                                                                                                           Auto       
Windows Insider Service                                                             1077      wisvc                                     C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Disabled   
Microsoft Account Sign-in Assistant                                                 0         wlidsvc                                   C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
WMI Performance Adapter                                                             0         wmiApSrv                                  C:\Windows\system32\wbem\WmiApSrv.exe                                                                                                                                          Manual     
Windows Media Player Network Sharing Service                                        1077      WMPNetworkSvc                             "C:\Program Files\Windows Media Player\wmpnetwk.exe"                                                                                                                           Manual     
Portable Device Enumerator Service                                                  0         WPDBusEnum                                C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted                                                                                                                Manual     
Windows Push Notifications System Service                                           0         WpnService                                C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Auto       
Windows Search                                                                      1077      WSearch                                   C:\Windows\system32\SearchIndexer.exe /Embedding                                                                                                                               Disabled   
Windows Update                                                                      0         wuauserv                                  C:\Windows\system32\svchost.exe -k netsvcs -p                                                                                                                                  Manual     
CaptureService_74b421                                                               1077      CaptureService_74b421                     C:\Windows\system32\svchost.exe -k LocalService -p                                                                                                                             Manual     
Clipboard User Service_74b421                                                       1077      cbdhsvc_74b421                            C:\Windows\system32\svchost.exe -k ClipboardSvcGroup -p                                                                                                                        Manual     
Connected Devices Platform User Service_74b421                                      0         CDPUserSvc_74b421                         C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                                                                                                            Auto       
ConsentUX_74b421                                                                    1077      ConsentUxUserSvc_74b421                   C:\Windows\system32\svchost.exe -k DevicesFlow                                                                                                                                 Manual     
DevicePicker_74b421                                                                 1077      DevicePickerUserSvc_74b421                C:\Windows\system32\svchost.exe -k DevicesFlow                                                                                                                                 Disabled   
DevicesFlow_74b421                                                                  1077      DevicesFlowUserSvc_74b421                 C:\Windows\system32\svchost.exe -k DevicesFlow                                                                                                                                 Manual     
Contact Data_74b421                                                                 1077      PimIndexMaintenanceSvc_74b421             C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                                                                                                            Manual     
PrintWorkflow_74b421                                                                1077      PrintWorkflowUserSvc_74b421               C:\Windows\system32\svchost.exe -k PrintWorkflow                                                                                                                               Manual     
User Data Storage_74b421                                                            1077      UnistoreSvc_74b421                        C:\Windows\System32\svchost.exe -k UnistackSvcGroup                                                                                                                            Manual     
User Data Access_74b421                                                             1077      UserDataSvc_74b421                        C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                                                                                                            Manual     
Windows Push Notifications User Service_74b421                                      0         WpnUserService_74b421                     C:\Windows\system32\svchost.exe -k UnistackSvcGroup                                                                                                                            Auto
 
It looks like the problematic key is:

Code:
HKEY_LOCAL_MACHINE\HKEY_USERS\S-1-5-21-2281769908-589326359-3636360395-14180

It seems that a process called DSREG commandline tool opens that key just before TiWorker.exe attempts to access it as well. Do you know what that process is related to?

Edit: It seems to an Azure AD troubleshooting tool. I would find out who is using it and why, and if you're able to, close the process from Task Manager and then attempt to install the update again.

Source: Troubleshoot devices by using the dsregcmd command - Microsoft Entra
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top