w32tm /query /status.....malfunctioning clock time work up and fix

Anonymous
2016-02-19T17:23:14+00:00

This mobile workstation was placed into use on 9/20/15 and has had persistent problems with incorrect time.

asdfasdfasdfasdfafd

Using windows 7 professional change date and time settings each of these settings were used to synchronize time:  time.windows.com, time.nist.gov, time-nw.nist.gov, time-a.nist.gov and time-b.nist.gov.

All of these settings failed with progressive time delays using windows 7 professional.

Time synchronization was turned off and again the mobile workstation had progressive delayed time.

Often at approximately 1 minute and 15 to 20 seconds it would reset on its own to a few seconds delay with or without time synchronization.

The CMOS RTC battery was replaced and there was no change in the time delay problem.

A second operating system was used, Ubuntu.

Ubuntu was tested for 12 hours and it displayed time ahead on the time.is web site.

The computer manufacturer replaced the motherboard and the intel chip.  The bios date and time were reset.

The first three days after the motherboard replacement the time delay was at its worst with over 5 minute delays.

On the third day there was a bios update.

After the bios update the mobile workstation malfunctioned as it did before the motherboard replacement.  With windows 7 professional there was progressive delayed time up to approximately 1 minute and 15 to 20 seconds and then it would somehow reset itself.  The mobile workstation was then rebooted to Ubunt to remoe windows 7 professional form the picture.  This time Ubuntu was ran for approximately 36 hours.  The time was always ahead.  The rate of time ahead with Ubuntu seemed to be slower than the rate of time behind with windows 7 professional.

Using administrative command prompt I posted the results of the w32tm /query /status commands.  The first one was with time synchronization off.  The second one was after multiple configure internet time settings update now clicks.  Multiple sfc /scannow were ran that indicated no integrity violations.

At this moment the time delay is 4 minutes and 39.1 seconds behind.

The latest w32tm /query /status displays:  Leap Indicator:  3(last minute has 61 seconds).

What does this mean:  last minute has 61 seconds?

What is Stratum and how come it changed to unspecified?

What is reference Id and how come it is now unspecified?

When the configure internet and time settings is viewed it displays next synchronization 2/25/2016 and it displays the clock was successfully synchronized with the time-nw.nist.gov on 2/19/2016 at 6:19 AM.

How come the date and time indicates a successful synchronized time on 2/19/2016 6:19 AM and the last few w32tm /query /status indicate the last successful sync time was on 2/18/2016 8:11:35 AM.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

113 answers

Sort by: Most helpful
  1. Anonymous
    2016-02-24T06:33:50+00:00

    John,

    This notebook is a mobile workstation and comes with a fingerprint reader.  For the clean boot under services hide all Microsoft services was checked then disable all was clicked.  On the startup tab the disable all was also clicked.  Then the notebook was rebooted. 

    On regular boot there are two icons, one for password and one for finger print.  Typically I just swipe my finger multiple times until it detects my finger an launches windows 7 professional.  In the clean boot there was only one icon.  The finger print was not available.  I clicked on the icon.  The HP Client Security responded please wait.  The biometric authentication is not functioning properly.  There were two choices, one to wait for it to respond or to login in without it.  I then entered the password and windows then opened in the clean boot state.

    The HP Client Security has been a source of problems as it can block communication with flash drives, external hard drives.  For example when it comes configured it may come from the factory with pre set settings to b on a network and block these communications.  All attempts to use typical administrative rights are always trumped by any settings within the HP Client Security.  For the new user this experience was painful as it was not expected that the default setting was for networks and to block USB port access.  For the clean boot I did not know how it would perform until I made the typical steps for the clean boot. 

    In control panel then add remove programs there are 84 programs.  Most of these were pre-installed followed by updates.  Sometimes if there were issues with any pre-installed software I would delet it and then reinstall it using the serial number or product code from the HP web site.  Under control panel add remoe programs there are 84 programs and in this view they are listed by installed on date:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=7611ed24-f702-4cde-8bd5-8c0fc1c15e61)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=f75afefc-eaa5-43b8-8086-be5248634bf4)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=54743fd4-ec64-424f-b8f8-2ef822837b1b)

    The computer was brand new and placed into use on 9/20/2015.  There are 49 items with an installation date on or after 9/20/2015.  Eliminating HP, Nvidia, Intel items and drivers these are items that could easily be tested by un-installation and re-installation: 

    go to meeting

    adobe acobat reader

    adobe flash player

    mozilla maintenance service

    mozilla firefox

    java 8 udate 73

    adobe flash player 20 activex

    ccleaner

    speedfan

    google chrome

    whocrashed

    spybot search and destroy

    malwarebytes anti malware

    cisco webex meetings

    skype

    samsung kies

    everything

    adobe shockwave player

    adobe air

    citrix online launcher

    Of the listings spypot and speedfan would be the first suspects.  However the performance during safe boot did not seem much difference from clean boot.

    Somewhere in the process of Clean boot  to safe boot I attempted to fine tune to reply to w32tm.  I didn't know enough about the w32tm as to why it sometimes displayed the isp address and more often displayed unavailable.  In safe boot I had attempted to use the microsoft fixit and in the process it indicated that it would not complete the process in safe mode.  Then I went back to regular boot and used it.  I don't remember now what the result was.  I do remeber seeing windows time under services.  I may have checked query source in addition to query status.  Also I may have attempted manual net stop w32time fthe w32tm /unregister then w32tm /register then net start w3time.  I may have tried w32tm /resync.  Somewher in the process I don't think I was able to get it to to display the ISP address.  I seemed to me that if the time settings were not set optimally before running clean boot or safe mode it could make the testing inaccurate or incomplete.  So I was attempting to get it in the optimal state before either clean boot or safe mode   For this I didn't know what it should display for w32tm /query /status to make it a valid test before running the clean boot or safe mode.  I can repeat these again.

    For malware I've never had any known malware on this notebook.  I refresh spybot immunize and scan at least one or more times per day.  MSE I refresh daily and run quick scans in addition to the automated scan once per week.  Also I run the full scan once per week.  Malwarebytes I run once per week.  I used you link to Kaspersky root kit and downloaded their software from http://support.kaspersky.com/viruses/disinfection/5350.  When I attempted ti use it it was going to automatically uninstall MSE.  I didn't know whether I should allow it to uninstall MSE.  Also I didn't check to see how to reinstall MSE if spybot and malwarebytes were already installed.  Would they need to be removed before reinstallation?

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=a3d3f86a-4d94-4aac-bf44-e03238cc5087)

    Hp suggested running the time test in the bios.  The enI were to ship it to him that that is what he would do.  Unfortunately in the bios the detection is by minutes and not by seconds.  Testing the bios prevents use of the computer and when using the computer the time delay typically starts at approximately 5 seconds delay and progresses to 1 minute and 15 seconds to 1 minute and 20 seconds delay before resetting.  It had kept resetting on its own at this level of delay.  There were two periods of time where the delay was greater than 1 minute and 20 seconds.  That was the first 3 days after the motherboard replacement where time delays rose to over 5 minutes.  On the third day after the motherboard replacement the computer was rebooted and the bios was updated. The progressive time delay changed from over 5 minutes to back to the typical progression of up to  1 minute and 15 to 20 second delay. 

    The other progressive longer term time period was recent where the time delay rose to over 4 minutes.  There has been no recent bios update.  This has somehow returned to the typical progressive delay of up to 1 minute 15 to 20 second delay before it automatically resets.  I don;t know how or why it automatically resets back to approximately 5 seconds delay on its own when the windows time is only done once per week and this over one minute time delay and reset happens each day or probably more than once per day.  If I view the bios time which is only in minutes I am wondering whether I would likely miss it.  I am wondering if it does delay in the bios whether I would be able to capture the time period that is over one minute delay before it resets itself.  With the bios only moving in minutes if this is not watched constantly the 1 minute minimum delay could be missed before it resets itself.  So this may be a useful test but it appears at first to be a challenge to not see the seconds delay and wait hours to see more than one minute delay before it resets itself.

    When rerunning either clean boot or safe mode are the test invalid if the w32tm displays the specified service does not exist as an installed service?

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=2530d884-b777-4ee2-adc7-87b06cfb0ad7)

    What steps should be done and what should be displayed for administrative command prompt w32tm /query /status and or w32tm /query /source to  the testing useful before starting mode?  Are the timings for reboot after making changes important/unimportant knowing that each clean boot and safe mode will require a reboot?

    The Microsoft fixit https://technet.microsoft.com/en-us/library/cc738995(v=ws.10).aspx was just ran and the w32tm is /query /status is now displaying the service has not been started:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=372d34e0-d1e8-4e15-9538-072a0419cbab)

    The administrative command prompt net start w32time was then entered and displayed:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=dd47239b-1103-4206-83ee-0cf80728cd02)

    It is unclear how to get the service started without errors.  Using administrative command promw32tm /resync was entered and it displayed:  the service has not been started

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=64b5817f-e6a2-444b-b694-c83d8dbfec64)

    The administrative command prompt displays More help is available by typing NET HELPMSG 3521.

    When I typed either NET HELPMSG 3521 or NET HELPMSG 3521. they did not work.

    the unregister command w32tmplayed access is denied

    the w32tm /register command was successful.

    How come the registration was needed after the Microsoft fixit as it was already registered with the fixit?

    the net start w32time did not work after the register  and displayed:  The service start failed since one or more services in the same process have an incompatible service SID type setting.  A service with restricted service SID type can only coexist in the same process with other services with a restricted SID type.  If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=f96186e5-bd59-4ed7-9358-fef90676c4a8)

    It's unclear to me how to be ready with the w32tm before testing with either clean boot or safe mode.  If it doesn't get to where it displays an ISP address does it make the test useful?  In this case I could never get to to display anything beyond errors or not started.

    Using administrative command prompt and typing w32tm /config /update displayed the service has not been started.

    entering:  reg query HKLM\SYSTEM\CurrentControlSet\services\W32Time\Parameters /v ntpserver

    displayed ntpserver     REG_SZ     time .windows.com,0x9

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=d5c776a9-837b-45c1-9051-85074ec3aab5)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=e44e9320-ce85-4c25-b91d-f35ec9d675f4)

    The time drifted in safe mode like it did with regular boot and clean boot.  The difference that I noted was that in safe mode each browser opened with time ahead then there was progressive delay to time exact then time behind the progressive time behind.  In regular boot the time started with time behind and then progressed to approximately 1 minute 15 to 20 seconds and then reset.

    This is information about the HP Client Security:  http://h10032.www1.hp.com/ctg/Manual/c04597082

    What's happening with the w32tm commands that don't start or display the status with isp?

    How come the resync does not allow it to restart?

    How come the fixit does an incomplete fix?

    How did you want me to proceed with the Kaspersky test and un-installation of MSE

    Which of the items in control panel did you want me to uninstall before retesting the time delay?

    What should be the w32tm displayed result in administrative command prompt before rebooting to clean boot to make the clean boot a useful test?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-02-23T16:57:22+00:00

    The time service is not available in safe mode but you should not have received that output from the command, this is what you should have seen:

    I need to know the chain of events leading to your safe mode error, did you:

    1. Do a clean boot.
    2. While in clean boot reset the time service with the /unregister /register commands.
    3. Test the time service and see that it was working correctly.
    4. After being satisfied that the time service appeared to run properly reboot to safe mode immediately?  Or did you do a normal boot first  then boot to safe mode?

    Confirm if the chronology of events and whether or not the service was reset in clean boot.

    John

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-02-23T14:45:07+00:00

    There is something going on with the machine, you have a virus or rootkit or one of you applications is causing problems with this.  Have you ever used "tweaking" or similar kind of utility on the machine?  Have you ever used registry cleaners?  Look in the registry and see if the W32Time key is still present.

    John

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-02-23T14:38:06+00:00

    The time service is not available in safe mode...but I don't think it should have returned that message, I will have to check later to see if my machine reports the same in safe mode.

    John

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-02-23T14:30:25+00:00

    It's still not a completely clean boot, in a clean boot state nothing other than Microsoft services should be running, I see you have HP items running.  How can you know that HP software is not causing this?  Have you encrypted your drive or secured hardware with HP security products?  You should properly disable all your HP software otherwise you can't be sure that they aren't at the root of the problem, disabling all non Microsoft products means ALL, not just some of them.

    We now know that your time service works properly, the commands are returning the expected results.  About the 61 second thing, don't bother with that, it's normal and may reoccur twice a year, it's a leap second, basically it was discovered a while back that the Earth's rotation is irregular so a leap second was introduced to compensate with solar time, sort of like a leap year, the time service will at times indicate the 61 second minute, although it's never happened it could just as well report a 59 second minute.  Since 1972 and up to June 30, 2015 a total of 36 seconds have been added, so now you find out that in the last 44 years or so we have all aged by an additional 36 seconds!

    For further testing you can boot to Safe Mode with Networking and still connect to the internet, then you will have a more definitive answer as to whether or not software is affecting the hardware clock.  Just keep in mind that the time service does not work in safe mode but that doesn't matter, you only want to know if the clock is still drifting in safe mode.  After that the final test would be to run the computer only booted to the BIOS and check with an accurate clock to see if the clock still drifts with no operating systems booted, you can be darn sure that if it does it can only be a hardware or BIOS problem.

    The Windows time service doesn't cause clocks to go faster or slower, all it does is synchronize the clock with a time server, it can only be as accurate as the time server but you can bet your bottom dollar that if it is syncing with a stratum-1 server it isn't setting the clock back or forward by seconds throughout the day, let alone minutes.  By default the Windows time service only syncs every 7 days and most computers don't lose/gain more than a few seconds in that many days, but there are still a lot of computers that gain or lose minutes in that many days, computers being off by up to 5 seconds per day are quite common.  If you must change the synchronizing frequency I advise that you use Atomic Clock Sync to do it for you, this is a small self-executable program that can make the changes for you, it won't replace the Windows Time service it will only help you configure it, I don't advise that you manually try to change these settings.

    You now know that the time service is working properly in clean boot but not in normal boot so now you have to find the culprit(s) that is breaking the time service, I would suggest that you do some clean-up in your startup programs, you know how to do that.  Start by uninstalling programs that you never use and then decide what is really important and what must really start when Windows is booted, I'm 99.99% sure that you don't need 40+ non Microsoft services starting up when Windows boots and you probably don't need as many Microsoft ones as what you have now.  That is only on the "services" side of things, you probably don't need more than a few of the items in the "Startup" tab.  You have already noticed that your Windows installation works much better in clean boot, that is the all the proof you need, a leaner start means a more efficient Windows installation and an easier one to troubleshoot when problems arise, less clutter to weed through.

    Finally, if you have not done so I strongly suggest that you run a TDSSKiller scan on your machine to eliminate a rootkit as the source of the clock problem, you should run a scan before you do anything else.  Rootkits can cause all kinds of strange, illusive and seemingly impossible to fix problems.

    John

    Was this answer helpful?

    0 comments No comments