[SOLVED] [Win7] Can't install SP1 + SURT "CSI C Mark Deployment Missing" errors

FRST log follows:

Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Claudio (25-03-2017 18:08:15) Run:1
Running from C:\SW\FRST
Loaded Profiles: Claudio (Available Profiles: Claudio)
Boot Mode: Normal
==============================================


fixlist content:
*****************
CreateRestorePoint:
S4 moguzyvy; C:\Users\Claudio\AppData\Roaming\00000000-1429258640-0000-0000-002185FC955E\nsr8528.tmp [X]
S4 poxuwyvy; C:\Users\Claudio\AppData\Roaming\00000000-1429258640-0000-0000-002185FC955E\jnsiEE09.tmp [X]
S4 sycoboxy; C:\Users\Claudio\AppData\Local\00000000-1429266052-0000-0000-002185FC955E\snscE6F8.tmp [X]
S3 NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [X]
S3 NTIOLib_1_0_C; \??\C:\MSI\MSI SUITE\NTIOLib_X64.sys [X]
S3 NTIOLib_1_0_D; \??\C:\MSI\MSI SUITE\ControlCenter\NTIOLib_X64.sys [X]
S3 NTIOLib_1_1_S; \??\C:\MSI\MSI SUITE\Super-Charger\NTIOLib_X64.sys [X]
C:\Users\Claudio\AppData\Local\AVAST Software
C:\ProgramData\AVAST Software
2017-03-24 16:58 - 2012-03-10 18:13 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.149037109606209
2017-03-24 16:57 - 2013-03-15 07:40 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149037109309306
2017-03-24 16:57 - 2012-03-10 18:13 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.149037109218704
2017-03-22 10:27 - 2013-03-15 07:40 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149017484359306
2017-03-22 10:27 - 2012-03-10 18:13 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.149017484596809
2017-03-22 10:27 - 2012-03-10 18:13 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.149017484223404
2017-03-02 11:59 - 2013-03-15 07:40 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148845237132812
2017-03-02 11:59 - 2012-03-10 18:13 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.148845237001507
2017-03-02 11:59 - 2012-03-10 18:13 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148845237079610
Task: {397F12E9-E665-4CA7-9179-590AC12D548E} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
C:\SW\avast\
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#ROOT#SW_ASWNDISMP#0000#{cac88484-7515-4c03-82e6-71a87abac361}]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWNDIS2]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWNDISFLT]
EmptyTemp:
*****************


Restore point was successfully created.
HKLM\System\CurrentControlSet\Services\moguzyvy => key removed successfully
moguzyvy => service removed successfully
HKLM\System\CurrentControlSet\Services\poxuwyvy => key removed successfully
poxuwyvy => service removed successfully
HKLM\System\CurrentControlSet\Services\sycoboxy => key removed successfully
sycoboxy => service removed successfully
HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_3 => key removed successfully
NTIOLib_1_0_3 => service removed successfully
HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_C => key removed successfully
NTIOLib_1_0_C => service removed successfully
HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_D => key removed successfully
NTIOLib_1_0_D => service removed successfully
HKLM\System\CurrentControlSet\Services\NTIOLib_1_1_S => key removed successfully
NTIOLib_1_1_S => service removed successfully
C:\Users\Claudio\AppData\Local\AVAST Software => moved successfully
C:\ProgramData\AVAST Software => moved successfully
C:\Windows\system32\Drivers\aswsp.sys.149037109606209 => moved successfully
C:\Windows\system32\Drivers\aswvmm.sys.149037109309306 => moved successfully
C:\Windows\system32\Drivers\aswsp.sys.149037109218704 => moved successfully
C:\Windows\system32\Drivers\aswvmm.sys.149017484359306 => moved successfully
C:\Windows\system32\Drivers\aswsp.sys.149017484596809 => moved successfully
C:\Windows\system32\Drivers\aswsp.sys.149017484223404 => moved successfully
C:\Windows\system32\Drivers\aswvmm.sys.148845237132812 => moved successfully
C:\Windows\system32\Drivers\aswsnx.sys.148845237001507 => moved successfully
C:\Windows\system32\Drivers\aswsp.sys.148845237079610 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{397F12E9-E665-4CA7-9179-590AC12D548E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{397F12E9-E665-4CA7-9179-590AC12D548E} => key removed successfully
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup => key removed successfully
C:\SW\avast => moved successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#ROOT#SW_ASWNDISMP#0000#{cac88484-7515-4c03-82e6-71a87abac361} => key removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWNDIS2 => key removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWNDISFLT => key removed successfully


=========== EmptyTemp: ==========


BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 35617577 B
Java, Flash, Steam htmlcache => 62577924 B
Windows/system/drivers => 1014304134 B
Edge => 0 B
Chrome => 310386793 B
Firefox => 458120621 B
Opera => 789983557 B


Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 40213545 B
systemprofile32 => 10825878 B
LocalService => 132311 B
NetworkService => 1391382 B
Claudio => 925387983 B


RecycleBin => 3244396977 B
EmptyTemp: => 6.4 GB temporary data Removed.


================================




The system needed a reboot.


==== End of Fixlog 18:08:54 ====
 
Tried manually, and fails with ERROR_FILE_NOT_FOUND (0X80070002).
With WU, it's Unknown Error
000000B7.
 
OK, please do the following.

Step#1 - Capture Process Monitor Trace
1. Download and run Process Monitor. Leave this running while you perform the next steps.
2. Attempt to install manually like you have in the past.
3. Stop Process Monitor as soon as you receive the ERROR_FILE_NOT_FOUND error. You can simply do this by clicking the magnifying glass on the toolbar as shown below.
11908d1430506241-windows-updates-fail-repeatedly-stop-jpg


4. Select the File menu...Save... and save the file to your desktop. This is likely the default location. The name (unless changed) will be LogFile.PML. This is fine.
5. Zip up and attach the LogFile.PML file as well as your CBS.log.
 
Downloaded Process Monitor from the provided link, run it, pop-up complains about some missing device driver & procmon windows says "No events (capture disabled)".
Going to download from sysinternals and try again ASAP.
 
Got the same again:
"Unable to load Process Monitor device driver" pop-up, clicking OK allows to read "No events (capture disabled)" on main window bottom bar.
The magnifying glass on the toolbar has a super-imposed red X.
If I save the file nonetheless and then try to open it, it says Logfile.PML is corrupted and cannot be opened.
 

Thanks Brian, much appreciated.
This works, and I was able to follow your instructions. However, even if I stopped procmon as soon as the error was produced, the zipped LogFile.PML file is 700+ MB (uncompressed was 7+ GB).
I'm uploading it to uploadfiles.io but it's taking a while, I'll post you when it's done.

CBS.log just wrapped up, so I'll add the last CBSPersist cab. Hope you'll find the info you need there.
 
OK then, here are CBS.log and CBSPersist cab:
View attachment CBS.log
View attachment 25259
Please note:
CbsPersist_20170326110222.cab.zip is not really the zip of a cab. I just manually added a "fake" .zip extension to the cab file, to circumvent allowed filetypes restriction in the forum's Upload Manager. Hope that's not a problem? Please just delete .zip from the filename.

Logfile.zip from procmon here:
Uploadfiles.io - logfile.zip

Thanks.
 
OK, that was very useful information. Please do the following.

Step#1 - SFCFix Script
Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.

  1. Download SFCFix.exe (by niemiro) and save this to your Desktop. If you still have this on your desktop from downloading previously, you don't need to re-download.
  2. Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
  3. Save any open documents and close all open windows.
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
  6. SFCFix will now process the script.
  7. Upon completion, a file should be created on your Desktop: SFCFix.txt.
  8. Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please
 

Attachments

Brian,

inside CbsPersist_20170326110222.log the first occurrence of 0x80070002 - ERROR_FILE_NOT_FOUND is in this line:

2017-03-26 12:28:44, Info CBS Failed to find file: amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winload.efi [HRESULT = 0x80070002 - ERROR_FILE_NOT_FOUND]

which comes right after:

2017-03-26 12:28:44, Info CBS Exec: Staging Package: Package_2_for_KB2506014~31bf3856ad364e35~amd64~~6.1.1.0, Update: 2506014-20_neutral_GDR, PinDeployment: amd64_90492e637c60228836cfc36418093b44_31bf3856ad364e35_6.1.7601.17556_none_63130be6cfd2808b

and a series of similar ones, each with a different PinDeployment field but all related to KB2506014.

Now I checked https://support.microsoft.com/en-us...pdate-for-the-windows-operating-system-loader and indeed the file from the error line, that is
amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5
is included in the KB2506014 package.

Since KB2506014 is not present on my system, I was wondering if installing it before re-trying SP1 setup could help? Just my two cents...

Please let me know what you think of this.

Thanks
 
Whoops, didn't see this post of yours until after posting my last one, sorry about that.

OK, that was very useful information. Please do the following.

Step#1 - SFCFix Script
Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.

  1. Download SFCFix.exe (by niemiro) and save this to your Desktop. If you still have this on your desktop from downloading previously, you don't need to re-download.
  2. Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
  3. Save any open documents and close all open windows.
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
  6. SFCFix will now process the script.
  7. Upon completion, a file should be created on your Desktop: SFCFix.txt.
  8. Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please

Here you go:

SFCFix version 3.0.0.0 by niemiro.
Start time: 2017-03-26 20:07:02.138
Microsoft Windows 7 - amd64
Using .zip script file at C:\SW\sysnative\SFCFix.zip [0]








PowerCopy::
Successfully took permissions for file or folder C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\setbcdlocale.dll
Successfully took permissions for file or folder C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5


Successfully copied file C:\Users\Claudio\AppData\Local\niemiro\Archive\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\setbcdlocale.dll to C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\setbcdlocale.dll.
Successfully copied file C:\Users\Claudio\AppData\Local\niemiro\Archive\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winload.efi to C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winload.efi.
Successfully copied file C:\Users\Claudio\AppData\Local\niemiro\Archive\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winload.exe to C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winload.exe.
Successfully copied file C:\Users\Claudio\AppData\Local\niemiro\Archive\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winresume.efi to C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winresume.efi.
Successfully copied file C:\Users\Claudio\AppData\Local\niemiro\Archive\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winresume.exe to C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\winresume.exe.


Successfully restored ownership for C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\setbcdlocale.dll
Successfully restored permissions on C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5\setbcdlocale.dll
Successfully restored ownership for C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5
Successfully restored permissions on C:\Windows\Winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.20897_none_c5ae5ddcbf9f87c5
PowerCopy:: directive completed successfully.








Successfully processed all directives.
SFCFix version 3.0.0.0 by niemiro has completed.
Currently storing 2 datablocks.
Finish time: 2017-03-26 20:07:02.494
Script hash: dSeEvXyGGH+TR7OC0yNCwvhERW3O/pfmI/h8ZPA01VM=
----------------------EOF-----------------------
 
It's done:
Immagine.jpg
I guess you can mark this as SOLVED, and I go back to re-install my antivirus? Not to mention probably many post-SP1 fixes :lol:

Brian, I can't begin to tell you how happy and grateful I am for this. I had tried to install that SP for ages.
I want to commend you for the high degree of professionalism shown in this endeavour. You demonstrated not only technical knowledge but also commitment, providing fast answers and guidance at almost any hour, even on a weekend!
I want to extend my thanks also to niemiro, as author of the tool we used, and to the sysnative team at large, for running this great forum.

Donation underway...
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top