w32tm /query /status.....malfunctioning clock time work up and fix

Anonymous
2016-02-19T17:23:14+00:00

This mobile workstation was placed into use on 9/20/15 and has had persistent problems with incorrect time.

asdfasdfasdfasdfafd

Using windows 7 professional change date and time settings each of these settings were used to synchronize time:  time.windows.com, time.nist.gov, time-nw.nist.gov, time-a.nist.gov and time-b.nist.gov.

All of these settings failed with progressive time delays using windows 7 professional.

Time synchronization was turned off and again the mobile workstation had progressive delayed time.

Often at approximately 1 minute and 15 to 20 seconds it would reset on its own to a few seconds delay with or without time synchronization.

The CMOS RTC battery was replaced and there was no change in the time delay problem.

A second operating system was used, Ubuntu.

Ubuntu was tested for 12 hours and it displayed time ahead on the time.is web site.

The computer manufacturer replaced the motherboard and the intel chip.  The bios date and time were reset.

The first three days after the motherboard replacement the time delay was at its worst with over 5 minute delays.

On the third day there was a bios update.

After the bios update the mobile workstation malfunctioned as it did before the motherboard replacement.  With windows 7 professional there was progressive delayed time up to approximately 1 minute and 15 to 20 seconds and then it would somehow reset itself.  The mobile workstation was then rebooted to Ubunt to remoe windows 7 professional form the picture.  This time Ubuntu was ran for approximately 36 hours.  The time was always ahead.  The rate of time ahead with Ubuntu seemed to be slower than the rate of time behind with windows 7 professional.

Using administrative command prompt I posted the results of the w32tm /query /status commands.  The first one was with time synchronization off.  The second one was after multiple configure internet time settings update now clicks.  Multiple sfc /scannow were ran that indicated no integrity violations.

At this moment the time delay is 4 minutes and 39.1 seconds behind.

The latest w32tm /query /status displays:  Leap Indicator:  3(last minute has 61 seconds).

What does this mean:  last minute has 61 seconds?

What is Stratum and how come it changed to unspecified?

What is reference Id and how come it is now unspecified?

When the configure internet and time settings is viewed it displays next synchronization 2/25/2016 and it displays the clock was successfully synchronized with the time-nw.nist.gov on 2/19/2016 at 6:19 AM.

How come the date and time indicates a successful synchronized time on 2/19/2016 6:19 AM and the last few w32tm /query /status indicate the last successful sync time was on 2/18/2016 8:11:35 AM.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

113 answers

Sort by: Newest
  1. Anonymous
    2016-02-24T10:48:51+00:00

    John,

    Over the past few days there were so many changes that I don't remember what I did between clean boot and safe mode.  I can repeat each again.  Currently this computer is used in one location and is not subject to vibration or hard drive damage.  The windows 7 professional operating system is on a 256 GB internal flash drive.  By default all files are saved to the flash drive.  There is an internal 1 TB hard drive.  Extra steps are needed to save things to this drive.  This is protected with HD drive guard.  But the operating system is not on this drive and seems to be in a safer location on the internal flash drive.  I am the only one that uses this computer and log in as a regular user.  The notebook has never been infected with malware.  No registry tools have been used on this computer.  The closest thing to modifications is using Ccleaner.  The HP Client security has its pro and con.  One of the HP representatives commented that he sets the HP client security to block access to the USB ports after 15 minutes and require a password.  He uses it so that if he goes to a rest room he can prevent anyone from going to the computer with an external flash drive and copying files.  I liked what he was doing and he showed me how to do it on this computer with remote access.  That is the only deliberate feature that I am using with the HP Client Security.  Within the past few weeks there was a problem with the HP client security and HP had me uninstall and reinstall it and then update the settings.  The notebook is connected to a modem and router which I have control.  Most if not all of the time it is connected by ethernet wire to the router.  I don't know of any inadvertent step that may have altered access.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-02-24T09:45:52+00:00

    The time service was properly installed and running fine in clean boot, there was no need to reset it again, the question is what caused it to disappear when you booted to safe mode or normal boot?  Did you /unregister it after it was running properly?  I need to know more about the laptop:

    Do you use this computer for work?

    Was the laptop supplied by your employer?

    Does it connect to a domain, to a company network?

    If you are self employed and if you use it for work do you carry it around to different customer locations as part of your work and does it hold sensitive information?

    Or is this just a laptop for home use?

    John

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-02-24T07:25:51+00:00

    I came across this and remember that we had made similar steps:  https://support.microsoft.com/en-us/kb/929276

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=15ba2584-eba8-4112-896f-46e65383cac4)

    These are some other links that I found on google search:

    https://social.technet.microsoft.com/Forums/windows/en-US/5828b5a6-9f70-4129-a086-34c25c1fe948/system-error-1290-after-register-w32time-service?forum=winservergen

    http://answers.microsoft.com/en-us/windows/forum/windows\_7-performance/cwindowssystem32net-start-w32time-system-error/89f3c786-de98-4371-b3df-58fc7cab5a1a

    Neither of the above was done.  Not yet comfortable with any registry steps without guidance.

    Just clicked on change date and time settings:

    This computer is not set to automatically synchronize with an Internet time server.

    The box for Synchronize with an Internet time server was checked.

    Each of the five choices was selected followed by update now.  All displayed Unable to start Internet time service.  Please try again later.

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=b82a0358-bb46-4805-add9-85441876ae2c)

    Now I will run the Microsoft fix it and reboot and see what happens.

    The Microsoft Fixit was processed:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=d5a259d7-8632-4cc3-b691-c4c7b4fbad5c)

    After running Microsoft Fixit I rebooted and opened change date and time.  There it indicated that it is set to automatically update.  However it did not let me alter the settings as it somehow changed to an administrative privilege.  I am both.  This had happened once before and I forgot what I had done to get past this obstacle. 

    Then I attempted to see what was happening in administrative command prompt with the query and other commands:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=ab9f4058-15dd-4f38-bdbf-ae0eb41f11f8)

    So no progress yet with the Microsoft Fixit

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-02-24T06:33:50+00:00

    John,

    This notebook is a mobile workstation and comes with a fingerprint reader.  For the clean boot under services hide all Microsoft services was checked then disable all was clicked.  On the startup tab the disable all was also clicked.  Then the notebook was rebooted. 

    On regular boot there are two icons, one for password and one for finger print.  Typically I just swipe my finger multiple times until it detects my finger an launches windows 7 professional.  In the clean boot there was only one icon.  The finger print was not available.  I clicked on the icon.  The HP Client Security responded please wait.  The biometric authentication is not functioning properly.  There were two choices, one to wait for it to respond or to login in without it.  I then entered the password and windows then opened in the clean boot state.

    The HP Client Security has been a source of problems as it can block communication with flash drives, external hard drives.  For example when it comes configured it may come from the factory with pre set settings to b on a network and block these communications.  All attempts to use typical administrative rights are always trumped by any settings within the HP Client Security.  For the new user this experience was painful as it was not expected that the default setting was for networks and to block USB port access.  For the clean boot I did not know how it would perform until I made the typical steps for the clean boot. 

    In control panel then add remove programs there are 84 programs.  Most of these were pre-installed followed by updates.  Sometimes if there were issues with any pre-installed software I would delet it and then reinstall it using the serial number or product code from the HP web site.  Under control panel add remoe programs there are 84 programs and in this view they are listed by installed on date:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=7611ed24-f702-4cde-8bd5-8c0fc1c15e61)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=f75afefc-eaa5-43b8-8086-be5248634bf4)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=54743fd4-ec64-424f-b8f8-2ef822837b1b)

    The computer was brand new and placed into use on 9/20/2015.  There are 49 items with an installation date on or after 9/20/2015.  Eliminating HP, Nvidia, Intel items and drivers these are items that could easily be tested by un-installation and re-installation: 

    go to meeting

    adobe acobat reader

    adobe flash player

    mozilla maintenance service

    mozilla firefox

    java 8 udate 73

    adobe flash player 20 activex

    ccleaner

    speedfan

    google chrome

    whocrashed

    spybot search and destroy

    malwarebytes anti malware

    cisco webex meetings

    skype

    samsung kies

    everything

    adobe shockwave player

    adobe air

    citrix online launcher

    Of the listings spypot and speedfan would be the first suspects.  However the performance during safe boot did not seem much difference from clean boot.

    Somewhere in the process of Clean boot  to safe boot I attempted to fine tune to reply to w32tm.  I didn't know enough about the w32tm as to why it sometimes displayed the isp address and more often displayed unavailable.  In safe boot I had attempted to use the microsoft fixit and in the process it indicated that it would not complete the process in safe mode.  Then I went back to regular boot and used it.  I don't remember now what the result was.  I do remeber seeing windows time under services.  I may have checked query source in addition to query status.  Also I may have attempted manual net stop w32time fthe w32tm /unregister then w32tm /register then net start w3time.  I may have tried w32tm /resync.  Somewher in the process I don't think I was able to get it to to display the ISP address.  I seemed to me that if the time settings were not set optimally before running clean boot or safe mode it could make the testing inaccurate or incomplete.  So I was attempting to get it in the optimal state before either clean boot or safe mode   For this I didn't know what it should display for w32tm /query /status to make it a valid test before running the clean boot or safe mode.  I can repeat these again.

    For malware I've never had any known malware on this notebook.  I refresh spybot immunize and scan at least one or more times per day.  MSE I refresh daily and run quick scans in addition to the automated scan once per week.  Also I run the full scan once per week.  Malwarebytes I run once per week.  I used you link to Kaspersky root kit and downloaded their software from http://support.kaspersky.com/viruses/disinfection/5350.  When I attempted ti use it it was going to automatically uninstall MSE.  I didn't know whether I should allow it to uninstall MSE.  Also I didn't check to see how to reinstall MSE if spybot and malwarebytes were already installed.  Would they need to be removed before reinstallation?

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=a3d3f86a-4d94-4aac-bf44-e03238cc5087)

    Hp suggested running the time test in the bios.  The enI were to ship it to him that that is what he would do.  Unfortunately in the bios the detection is by minutes and not by seconds.  Testing the bios prevents use of the computer and when using the computer the time delay typically starts at approximately 5 seconds delay and progresses to 1 minute and 15 seconds to 1 minute and 20 seconds delay before resetting.  It had kept resetting on its own at this level of delay.  There were two periods of time where the delay was greater than 1 minute and 20 seconds.  That was the first 3 days after the motherboard replacement where time delays rose to over 5 minutes.  On the third day after the motherboard replacement the computer was rebooted and the bios was updated. The progressive time delay changed from over 5 minutes to back to the typical progression of up to  1 minute and 15 to 20 second delay. 

    The other progressive longer term time period was recent where the time delay rose to over 4 minutes.  There has been no recent bios update.  This has somehow returned to the typical progressive delay of up to 1 minute 15 to 20 second delay before it automatically resets.  I don;t know how or why it automatically resets back to approximately 5 seconds delay on its own when the windows time is only done once per week and this over one minute time delay and reset happens each day or probably more than once per day.  If I view the bios time which is only in minutes I am wondering whether I would likely miss it.  I am wondering if it does delay in the bios whether I would be able to capture the time period that is over one minute delay before it resets itself.  With the bios only moving in minutes if this is not watched constantly the 1 minute minimum delay could be missed before it resets itself.  So this may be a useful test but it appears at first to be a challenge to not see the seconds delay and wait hours to see more than one minute delay before it resets itself.

    When rerunning either clean boot or safe mode are the test invalid if the w32tm displays the specified service does not exist as an installed service?

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=2530d884-b777-4ee2-adc7-87b06cfb0ad7)

    What steps should be done and what should be displayed for administrative command prompt w32tm /query /status and or w32tm /query /source to  the testing useful before starting mode?  Are the timings for reboot after making changes important/unimportant knowing that each clean boot and safe mode will require a reboot?

    The Microsoft fixit https://technet.microsoft.com/en-us/library/cc738995(v=ws.10).aspx was just ran and the w32tm is /query /status is now displaying the service has not been started:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=372d34e0-d1e8-4e15-9538-072a0419cbab)

    The administrative command prompt net start w32time was then entered and displayed:

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=dd47239b-1103-4206-83ee-0cf80728cd02)

    It is unclear how to get the service started without errors.  Using administrative command promw32tm /resync was entered and it displayed:  the service has not been started

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=64b5817f-e6a2-444b-b694-c83d8dbfec64)

    The administrative command prompt displays More help is available by typing NET HELPMSG 3521.

    When I typed either NET HELPMSG 3521 or NET HELPMSG 3521. they did not work.

    the unregister command w32tmplayed access is denied

    the w32tm /register command was successful.

    How come the registration was needed after the Microsoft fixit as it was already registered with the fixit?

    the net start w32time did not work after the register  and displayed:  The service start failed since one or more services in the same process have an incompatible service SID type setting.  A service with restricted service SID type can only coexist in the same process with other services with a restricted SID type.  If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=f96186e5-bd59-4ed7-9358-fef90676c4a8)

    It's unclear to me how to be ready with the w32tm before testing with either clean boot or safe mode.  If it doesn't get to where it displays an ISP address does it make the test useful?  In this case I could never get to to display anything beyond errors or not started.

    Using administrative command prompt and typing w32tm /config /update displayed the service has not been started.

    entering:  reg query HKLM\SYSTEM\CurrentControlSet\services\W32Time\Parameters /v ntpserver

    displayed ntpserver     REG_SZ     time .windows.com,0x9

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=d5c776a9-837b-45c1-9051-85074ec3aab5)

    ![](http://fud.community.services.support.microsoft.com/Fud/FileDownloadHandler.ashx?fid=e44e9320-ce85-4c25-b91d-f35ec9d675f4)

    The time drifted in safe mode like it did with regular boot and clean boot.  The difference that I noted was that in safe mode each browser opened with time ahead then there was progressive delay to time exact then time behind the progressive time behind.  In regular boot the time started with time behind and then progressed to approximately 1 minute 15 to 20 seconds and then reset.

    This is information about the HP Client Security:  http://h10032.www1.hp.com/ctg/Manual/c04597082

    What's happening with the w32tm commands that don't start or display the status with isp?

    How come the resync does not allow it to restart?

    How come the fixit does an incomplete fix?

    How did you want me to proceed with the Kaspersky test and un-installation of MSE

    Which of the items in control panel did you want me to uninstall before retesting the time delay?

    What should be the w32tm displayed result in administrative command prompt before rebooting to clean boot to make the clean boot a useful test?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-02-23T16:57:22+00:00

    The time service is not available in safe mode but you should not have received that output from the command, this is what you should have seen:

    I need to know the chain of events leading to your safe mode error, did you:

    1. Do a clean boot.
    2. While in clean boot reset the time service with the /unregister /register commands.
    3. Test the time service and see that it was working correctly.
    4. After being satisfied that the time service appeared to run properly reboot to safe mode immediately?  Or did you do a normal boot first  then boot to safe mode?

    Confirm if the chronology of events and whether or not the service was reset in clean boot.

    John

    Was this answer helpful?

    0 comments No comments