Windows update Error 0x80070005 - Need a fix? Click here.

Anonymous
2009-07-02T19:01:34+00:00

The error code 0x80070005 is also described as ACCESS DENIED. 

Please follow these instructions if you are encountering this error code when checking or installing updates via Windows Udpate. 

To correct the problem, you can try the steps below. Keep in mind that these steps are still experimental. I look forward to your feedback and results. For the long term, we hope that we can create an automated solution for all.

  1. Download and install SubInACL from the Microsoft Download Center http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=23510
  2. Open Notepad (Click Start, type Notepad, and then press Enter)
  3. Copy and paste the following text into Notepad

Set OSBIT=32

IF exist "%ProgramFiles(x86)%" set OSBIT=64

set RUNNINGDIR=%ProgramFiles%

IF %OSBIT% == 64 set RUNNINGDIR=%ProgramFiles(x86)%

subinacl /subkeyreg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing" /grant="nt service\trustedinstaller"=f

  1. Close Notepad, and make sure you save it. When you save the text, make sure that you set

Save as Type to “All Files (*.*)”. Very important! The file name needs end with .CMD. For example: fix.cmd. Lastly, when you save the file, make sure you save it at a location where it will be easy for you to find.

  1. Right click on the file that you just saved in step #4, and select “Run as Adminstrator”

To confirm that you have the symptoms and to validate the problem, please see the below:

The following is applicable to Windows 7 and Windows Vista .

  1. Download AccessChk (Sysinternals).  This tool allows you to evaluate the access level of specific users or groups of resources including files, directories, Registry keys, global objects and Windows services.  Here's the link to download the tool: http://technet.microsoft.com/en-us/sysinternals/bb664922.aspx

2. Save the zip file on your desktop, and extract the file:

  • Right click on the file, and select Extract All...
  • Click Next when prompted for the Destination.

As a result, you should see a folder called AccessChk  on your desktop.

  1. Open the folder AccessChk 
  2. Hold the shift-key and right click in the window.  Select "Open Command Prompt Here"
  3. A command prompt window should open with a similar prompt:

C:\Users<USERNAME>\Desktop\accesschk>

6.  Type the following command, and press Enter:

accesschk.exe -s -n "nt service\trustedinstaller" -k "hklm\software\Microsoft\Windows\CurrentVersion\Component Based Servicing" >accesskchk.txt

Tip: You should be able to copy and paste the command into the command prompt.

  1. Close the Command Prompt Window.  Open the Accesschk folder on yoru desktop (if it has been closed).
  2. Double click on Accesschk.txt (the text file), this should open Notepad.

9.  Copy and Paste your results with a new question on the Windows Update forum.  (Make sure you write 0x80070005 in the subject line).

Cheers!

Kim N. L.

Microsoft Partner Technical Technical Lead

Windows for home | Windows 11 | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2011-10-13T21:55:56+00:00

Hello all,

I would like to apologize for the delayed response on this thread.  All the results (logs) that you have all posted in the thread are helpful.    Based on the various results, it’s evident that the problem has a common cause.  

Here’s a little background on the problem that you are experiencing:

When you use Windows Update to install updates for Windows Vista and Windows 7, the process relies on the Windows Module Installer (trustedinstaller.exe).  The TrustedInstaller is the online interface to the servicing stack.  To keep things simple, it’s one of the most important components when you install updates.   This method also allows Windows to be serviced (to install updates) without the need of an administrator.  In fact, when the components of Windows are being updated, it’s the TrustedInstaller that is used to update the operating system files. 

Furthermore, when you look at the security settings of certain servicing components of Windows, you would notice that the TrustedInstaller is the only item listed under the User Name and Groups with full permissions.   This is only true if the respective folder or registry key is kept at its default state.  In other words, changes to these security settings would cause the ACCESS DENIED (0x80070005).  It’s difficult to associate a culprit to the unwanted changes.   A possible cause that was previously mentioned is malware.

Awhile ago, I asked the community to run a Sysinternal Tool known as Access Check to capture the details of the problem.  The output of the tool would list all of the servicing components where the security permissions restricted the TrustedInstaller.  As a result, when you try to install updates for Windows, you would obtain the error 0x80070005 – also known as ACCESS DENIED.  In summary, it is the TrustedInstaller that has been denied of access to a component that it should have access to.

Here’s an example of the output:

HKLM\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\Retry Agent

HKLM\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\Sqm

HKLM\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\Sqm\VistaSP1-KB936330~31bf3856ad364e35~x86~~6.0.1.18000

HKLM\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\Sqm\VistaSP1-KB936330~31bf3856ad364e35~x86~~6.0.1.18000\InstallCounter

As you can see from the above, there are four registry keys with unexpected security settings.

...The Solution...

To correct the problem, you can try the steps below.  Keep in mind that these steps are still experimental.   I look forward to your feedback and results.  For the long term, we hope that we can create an automated solution for all.

1.       Download and install  SubInACL from the Microsoft Download Center http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=23510

2.       Open Notepad (Click Start, type Notepad, and then press Enter)

3.       Copy and paste the following text into Notepad

Set OSBIT=32

IF exist "%ProgramFiles(x86)%" set OSBIT=64

set RUNNINGDIR=%ProgramFiles%

IF %OSBIT% == 64 set RUNNINGDIR=%ProgramFiles(x86)%

subinacl /subkeyreg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing" /grant="nt service\trustedinstaller"=f

4.       Close Notepad, and make sure you save it.  When you save the text, make sure that you set

Save as Type to “All Files (*.*)”.  Very important!  The file name needs end with .CMD.  For example:  fix.cmd.  Lastly, when you save the file, make sure you save it at a location where it will be easy for you to find.

5.       Right click on the file that you just saved in step #4, and select “Run as Adminstrator”

Thanks and I look forward to your feedback.

Kim

Was this answer helpful?

700+ people found this answer helpful.
0 comments No comments

128 additional answers

Sort by: Most helpful
  1. Anonymous
    2011-10-30T16:13:42+00:00

    This is what I got when I replied to your fix. Still can't updatewindows

     usage: accesschk [-s][-e][-u][-r][-w][-n][-v][[-a]|[-k]|[-p [-f] [-t]][-o [-t <object type>]][-c]|[-d]] [[-l [-i]]|[username]] <file, directory, registry key, process, service, object>

       -a     Name is a Windows account right. Specify '*' as the name to show all

              rights assigned to a user. Note that when you specify a specific

              right, only groups and accounts directly assigned the right are

              displayed.

       -c     Name is a Windows Service e.g. ssdpsrv. Specify '*' as the

              name to show all services and 'scmanager' to check the security

              of the Service Control Manager

       -d     Only process directories or top level key

       -e     Only show explicitly set Integrity Levels (Windows Vista and

              higher only)

       -f     Show full process token information including groups and privileges

       -k     Name is a Registry key e.g. hklm\software

       -i     Ignore objects with only inherited ACEs when dumping full access

              control lists.

       -l     Show full access control list. Add -i to ignore inherited ACEs.

       -n     Show only objects that have no access

       -o     Name is an object in the Object Manager namespace (default is root).

              To view the contents of a directory, specify the name with a trailing

              backslash or add -s. Add -t and an object type (e.g. section) to

              see only objects of a specific type

       -p     Name is a process name or PID e.g. cmd.exe (specify '*' as the

              name to show all processes). Add -f to show full process

              token information including groups and privileges. Add -t to show

              threads

       -q     Omit banner

       -r     Show only objects that have read access

       -s     Recurse

       -t     Object type filter e.g. "section"

       -u     Suppress errors

       -v     Verbose (includes Windows Vista Integrity Level)

       -w     Show only objects that have write access

    If you specify a user or group name and path AccessChk will report the

    effective permissions for that account; otherwise it will show the effective

    access for accounts referenced in the security descriptor.

    By default the path name is interpreted as a file system path (use the

    "\pipe" prefix to specify a named pipe path). For each object AccessChk

    prints R if the account has read access, W for write access and nothing if

    it has neither. The -v switch has AccessChk dump the specific

    accesses granted to an account.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2011-10-30T12:53:59+00:00

    Hello I tried this but it did not work..

    Here is what I tried to date without any results

    Microsoft Fix It

    Accesschk

    Subinacl

    Downloaded:

    Superantispyware and

    Malwaebytes antimalware

    I am all out of ideas....anything else out there that might work?

    Matt

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2011-10-26T21:24:59+00:00

    KIM

    i tried it step by step and the command prompt window flashed for s sec and then there was nothing.im not sure what else to do other than save file and reset cpu to factory settings.....

    im not highly computor savvy and im easily tweeked........help

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2011-10-26T19:35:57+00:00

    Oops!  Kim, I read your advice too late. I've already run the above on my Vista machine to resolve the dreaded 80070005 udate error code (it didn't work). Have I done any damage? Do I need to do anything to recover? I've not noticed any ill effects so far.

    Hi Pedro,

    It's difficult to predict what the potential outcome would be in the future.  By applying those steps, you are not necessarily breaking anything but you just simply opened a few "doors" that shouldn't be.  Like I mentioned in my other post, there are certain part of the Windows Vista/7 that should be serviced (modified) by the TrustedInstaller.  Hence, an administrator shouldn't even have full control access to these components. 

    It's also difficult to undo the steps you did.  I don't think a System Restore would undo the changes.  It's worth a try if the change was recent.  You should consider at some point restoring Windows back to its default state (reinstall OS).  In the meantime, just make sure you have an updated anti-malware solution installed, especially when you are in a venerable state.

    Kim

    Was this answer helpful?

    0 comments No comments