Windows update couldn't install

Status
Not open for further replies.
Can you please run a new scan with FRST and attach your new FRST.txt and Addition.txt logfiles to your next post.

In the meantime I'll be looking over your latest CBS logs to see whether they tell us anything new.
 
  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
S3 rpmcdriver; \??\D:\ASUS_WTP_MAIN\ThirdPartyTool\Amd\RPMC\rpmcdriver.sys [X]
D:\ASUS_WTP_MAIN\ThirdPartyTool\Amd\RPMC\rpmcdriver.sys
IE trusted site: HKU\S-1-5-21-118308293-610972259-2242679070-1001\...\sharepoint.com -> hxxps://ptwaskita-files.sharepoint.com
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
Hosts:
EmptyTemp:
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

Next ...

  • Double click Frst64.exe to launch it.
  • FRSTwill start to run.
    • When the tool opens click Yes to the disclaimer.
    • Copy/Paste or Type the following line into the Search: box.
    • SearchAll:glasswire;mcafee
    • Press the Search Files button.
    • When finished searching a log will open on your Desktop ... Search.txt
    • Please post or attach it in your next reply.
Next ...

Can you please do the following for me as well

Before you do it, first please re-name the fixlog.txt created earlier to fixlog1.txt otherwise it will get overwritten by the fixlog created when you run this "fix" (which is not really a fix, it's just an export of a few registry keys I want to look at).

  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
ExportKey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService
ExportKey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc
ExportKey:HKEY_LOCAL_MACHINE\Software\Policies\microsoft\windows defender\real-time protection
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log
 
Last edited:
Fix result of Farbar Recovery Scan Tool (x64) Version: 21-07-2022
Ran by asus (27-07-2022 20:01:45) Run:6
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
S3 rpmcdriver; \??\D:\ASUS_WTP_MAIN\ThirdPartyTool\Amd\RPMC\rpmcdriver.sys [X]
D:\ASUS_WTP_MAIN\ThirdPartyTool\Amd\RPMC\rpmcdriver.sys
IE trusted site: HKU\S-1-5-21-118308293-610972259-2242679070-1001\...\sharepoint.com -> hxxps://ptwaskita-files.sharepoint.com
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
Hosts:
EmptyTemp:
*****************

C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\System\CurrentControlSet\Services\rpmcdriver => removed successfully
rpmcdriver => service removed successfully
"D:\ASUS_WTP_MAIN\ThirdPartyTool\Amd\RPMC\rpmcdriver.sys" => not found
HKU\S-1-5-21-118308293-610972259-2242679070-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sharepoint.com => removed successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\McAfee Security Scan Plus.lnk" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 1572864 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 257953270 B
Java, Discord, Steam htmlcache => 576872479 B
Windows/system/drivers => 264825293 B
Edge => 0 B
Chrome => 476876752 B
Firefox => 2083295157 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 492290638 B
systemprofile32 => 492291954 B
LocalService => 492291954 B
NetworkService => 517435572 B
asus => 791298256 B

RecycleBin => 7534357472 B
EmptyTemp: => 13 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:27:52 ====

The search log is attached.

By the way, I should let you know that i followed registry instruction from here: How to permanently disable Windows Defender Antivirus on Windows 10
to try to deactivate Windows Defender just to see if it gives a notification that it's being turned off and let me open the setting but nothing happened.

Here's the fixlog number 2

Fix result of Farbar Recovery Scan Tool (x64) Version: 21-07-2022
Ran by asus (27-07-2022 22:40:46) Run:7
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
ExportKey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService
ExportKey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc
ExportKey:HKEY_LOCAL_MACHINE\Software\Policies\microsoft\windows defender\real-time protection
*****************

================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecurityHealthService]
"DependOnService"="RpcSs"
"Description"="@%systemroot%\system32\SecurityHealthAgent.dll,-1001"
"DisplayName"="@%systemroot%\system32\SecurityHealthAgent.dll,-1002"
"ErrorControl"="1"
"FailureActions"="80510100000000000000000003000000140000000100000060ea00000100000060ea00000000000000000000"
"ImagePath"="%SystemRoot%\system32\SecurityHealthService.exe"
"LaunchProtected"="2"
"ObjectName"="LocalSystem"
"RequiredPrivileges"="SeImpersonatePrivilege*SeBackupPrivilege*SeRestorePrivilege*SeDebugPrivilege*SeChangeNotifyPrivilege*SeSecurityPrivilege*SeAssignPrimaryTokenPrivilege*SeTcbPrivilege*SeSystemEnvironmentPrivilege*SeShu (the data entry has 14 more characters)."
"ServiceSidType"="1"
"Start"="3"
"Type"="16"
[HKLM\SYSTEM\CurrentControlSet\Services\SecurityHealthService\Security]
"Security"="010014801c01000028010000140000003000000002001c000100000002801400ff010f000101000000000001000000000200ec0008000000000018009d00020001020000000000052000000021020000000014009d010200010100000000000512000000 (the data entry has 416 more characters)."

=== End of ExportKey ===
================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]
"DelayedAutoStart"="1"
"DependOnService"="RpcSs"
"Description"="@%SystemRoot%\System32\wscsvc.dll,-201"
"DisplayName"="@%SystemRoot%\System32\wscsvc.dll,-200"
"ErrorControl"="1"
"FailureActions"="805101000000000000000000030000001400000001000000c0d4010001000000e09304000000000000000000"
"ImagePath"="%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted -p"
"LaunchProtected"="2"
"ObjectName"="NT AUTHORITY\LocalService"
"RequiredPrivileges"="SeChangeNotifyPrivilege*SeImpersonatePrivilege"
"ServiceSidType"="1"
"Start"="2"
"Type"="32"
[HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Parameters]
"ServiceDll"="%SystemRoot%\System32\wscsvc.dll"
"ServiceDllUnloadOnStop"="1"
[HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Security]
"Security"="010014801c01000028010000140000003000000002001c000100000002801400ff010f000101000000000001000000000200ec0008000000000018009d00020001020000000000052000000021020000000014009d010200010100000000000512000000 (the data entry has 416 more characters)."

=== End of ExportKey ===
================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\Software\Policies\microsoft\windows defender\real-time protection]

=== End of ExportKey ===

==== End of Fixlog 22:40:46 ====
 

Attachments

  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
C:\Users\asus\Downloads\Programs\GlassWireSetup.exe
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Windows\ASUS\Config\McAfee.ini
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\StoreAPP\Online\McAFee
C:\ProgramData\McAfee
C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.5.0_x64__qmba6cd70vzyy\ModuleDll\McAfee
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\Win32App\McAFee
C:\eSupport\Factory\ProcTool\FacProc\OOBEPage\APRP_Mcafee_oobexml
C:\eSupport\Factory\ProcTool\FacProc\HDI\OOBEPage\APRP_Mcafee_oobexml

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\GlassWire.exe]
[-HKEY_LOCAL_MACHINE\SYSTEM\GlassWire]
[-HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
[-HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mcafeeupdater]
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LocalFileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LocalPath
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LogFileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Host
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | FileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Referer
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | owWPage
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Url0
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | C:\Users\asus\Downloads\Programs\GlassWireSetup.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\ASUS\ASUS System Control Interface\AsusSoftwareManager\ASUS Hello | isFinishedMcAfee

Reboot:
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe (please rename it to Fixlog 2.txt)
  • Please post me the log

Next ...

I need you to export the Registry Key you've been messing around with .... please don't do anything like that again. It's difficult enough to analyse things without you changing things without consulting me first. The Registry can be extremely sensitive to change, and if you don't know what you're doing, and change the wrong thing it's really easy to end up with a very expensive door stop.

  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log
 
Sorry for adding more trouble.

Here's the Fixlog 2:
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2022
Ran by asus (28-07-2022 21:31:52) Run:8
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
C:\Users\asus\Downloads\Programs\GlassWireSetup.exe
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Windows\ASUS\Config\McAfee.ini
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\StoreAPP\Online\McAFee
C:\ProgramData\McAfee
C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.5.0_x64__qmba6cd70vzyy\ModuleDll\McAfee
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\Win32App\McAFee
C:\eSupport\Factory\ProcTool\FacProc\OOBEPage\APRP_Mcafee_oobexml
C:\eSupport\Factory\ProcTool\FacProc\HDI\OOBEPage\APRP_Mcafee_oobexml

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\GlassWire.exe]
[-HKEY_LOCAL_MACHINE\SYSTEM\GlassWire]
[-HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
[-HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mcafeeupdater]
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LocalFileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LocalPath
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | LogFileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Host
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | FileName
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Referer
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | owWPage
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342 | Url0
DeleteValue: HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | C:\Users\asus\Downloads\Programs\GlassWireSetup.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\ASUS\ASUS System Control Interface\AsusSoftwareManager\ASUS Hello | isFinishedMcAfee

Reboot:
*****************

C:\Users\asus\Downloads\Programs\GlassWireSetup.exe => moved successfully
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Windows\ASUS\Config\McAfee.ini => moved successfully
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\StoreAPP\Online\McAFee => moved successfully
C:\ProgramData\McAfee => moved successfully
C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_3.1.5.0_x64__qmba6cd70vzyy\ModuleDll\McAfee => moved successfully
C:\eSupport\FX505DD_2009_X64_V0.02\Driver64\Software\Win32App\McAFee => moved successfully
C:\eSupport\Factory\ProcTool\FacProc\OOBEPage\APRP_Mcafee_oobexml => moved successfully
C:\eSupport\Factory\ProcTool\FacProc\HDI\OOBEPage\APRP_Mcafee_oobexml => moved successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\GlassWire.exe => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\GlassWire => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\McAfee => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee.com => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mcafeeupdater => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\LocalFileName" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\LocalPath" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\LogFileName" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\Host" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\FileName" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\Referer" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\owWPage" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\DownloadManager\342\\Url0" => removed successfully
"HKEY_USERS\S-1-5-21-118308293-610972259-2242679070-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\asus\Downloads\Programs\GlassWireSetup.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\ASUS\ASUS System Control Interface\AsusSoftwareManager\ASUS Hello\\isFinishedMcAfee" => removed successfully


The system needed a reboot.

==== End of Fixlog 21:31:53 ====


This is The Export Key Fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2022
Ran by asus (28-07-2022 21:44:30) Run:9
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
*****************

================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
[HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager]
[HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]

=== End of ExportKey ===

==== End of Fixlog 21:44:30 ====
 
Sorry to mess you around, but I can't see the info I need.

I was under the impression that when FRST exported the contents of a Key that it also exported the contents of all its sub-keys as well, but it's not clear that that's what happened, so I need you to run a further couple of exports for me so I can be sure that both these sub-keys have no entries.

So ...

  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log
 
Here it is

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2022
Ran by asus (29-07-2022 09:16:54) Run:10
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager
ExportKey: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
*****************

================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager]

=== End of ExportKey ===
================== ExportKey: ===================

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]

=== End of ExportKey ===

==== End of Fixlog 09:16:54 ====
 
OK, so no Key values, which would have to be there if they were the cause of your disabled Windows Security.

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection] .... is not present by default on W10 Home machines, so we'll remove it, but as things stand, in all honesty I do not believe it will resolve your problem.

But anyway let's see, so please do the following ...






  • Start FRST.
  • Hit your Windows Key + R to open a Run window
  • Type Notepad then click OK
  • This will open an empty Notepad document
  • Copy/Paste the following into it (Don't include Code: ) .....
Code:
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
Reboot:
  • Save it as fixlist.txt to the same location as FRST (must be in this location)
  • NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

Now please let me know if you can now access Windows Security.
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2022
Ran by asus (29-07-2022 13:01:56) Run:11
Running from C:\Users\asus\Desktop
Loaded Profiles: asus
Boot Mode: Normal
==============================================

fixlist content:
*****************
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
Reboot:
*****************

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection => removed successfully


The system needed a reboot.

==== End of Fixlog 13:01:56 ====

You're right, Windows Security still doesn't open
 
Have you run Windows Troubleshooter ????

If not, please do the following ...

  • In your Search box type ... Perform recommended maintenance tasks automatically
  • Click on the relevant link to open a System Maintenance window
  • Click Next
  • Windows will analyse your machine looking for problems, and will attempt to fix any it finds.
  • If prompted to Try troubleshooting as an administrator allow the prompt
  • Again Windows will analyse your machine for problems and will attempt to fix them.

Please let me know if anything was found, and if so did it resolve your problem.
 
Last edited:
It did not find anything and i still can't open Windows Security. So maybe it's all got to do with my Updates problem too?
 
Very likely it is, but it's also likely to be some 3rd party program that you have installed that could be causing the problem, in which case I'd like you to perform a Clean Boot with Windows to see if it is.

Instructions for how to perform one, and how to check to find which program may be causing your problem can be found at ....

How to perform a clean boot in Windows
 
Okay, i will try, but how can i know which program it is that's interfering with Windows Security?
And do i need to create another local account other than this one i'm using?
 
In the article I linked to, scroll down to the section ...How to determine what is causing the problem after you do a clean boot ... which will explain how to find what program might be causing the problem. Sadly it's quite a time consuming process.

You will almost certainly not need to create another local account to perform a clean boot, just use your normal account.

When you're troubleshooting in Clean Boot, please make careful note of any and all the programs you disable, as you will need to re-eanble them (except for the problematic one if you find it) when you have finished.
 
Well okay, then in case it's gonna be long, is there anything that i need to do also regarding my latest CBS log?
 
I'm still looking that over, to see whether it tells us anything new.

It got put on the back burner while we dealt with your Windows Security problem, since resolving that may help with your update issues.

So far I'm not seeing anything conclusive, so I'm going to have to consult with more experienced colleagues to see if they can see something I'm missing.
 
By the way, I just tried clean boot. Windows Security still didn't open. I don't know if this screenshot will mean anything because i noticed that the App part and else showed 0 byte. Does this mean like a missing/corrupted app situation?
 

Attachments

  • Screenshot (209).png
    Screenshot (209).png
    62.5 KB · Views: 9
I'd like you to send me the following logfiles please ....

  • C:\Windows\Servicing\Sessions\sessions.xml
  • C:\Windows\inf\setupapi.dev.log

Next ....

Please try updating Windows, but do not allow your computer to reboot

Now please send me the following logfile as well ...

  • C:\Windows\WinSxS\pending.xml

Once you've done that you can reboot, at which point your update will probably fail, but that's OK, the only purpose in attempting an update was to get the pending.xml log
 
Status
Not open for further replies.

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top