Hi peeps,
I'm following this thread since Nov, 22, as I have one new Win10 home machine in the house which has the problem. I'm in the IT business and know what to do (usually), but this one, hmm. Did many of the solutions, that are also here, but not the one, what is the solution for most of you.
Here it does NOT work. The machine simply doesn't have this registry key: HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\NL$KM\
Yes, I opened regedit with psexec -i -s, but the machine only has the DPAPI_SYSTEM key, which has the same entries like NL$KM...
So I deleted the CurVal and OldVal Default values there, but without success. All I got, was that all passwords from any apps and even the PIN for login went away.
OK, gave the user a new password with the utilman.exe solution and being logged on again, but all other apps (Adobe/Nextcloud/Outlook etc.) telling me there might be a MITM attack, asking for logins again.
This is true, as the CurVal key holds all LSA secrets of the machine, nicely explained here: https://www.passcape.com/index.php?section=docsys&cmd=details&id=23
So I'm wondering why deleting the encrypted values of the secrets will solve the problem of this installing/repairing/uninstalling loop.
I created the NL$KM values manually by exporting the DPAPI_SYSTEM key, renaming DPAPI_SYSTEM with NL$KM in an editor and imported it with empty CurVal and OldVal while opened regedit with psexec. But the machine isn't using it.
So I went for hiding the latest cumulative update with the solution here (2 files reset win upd & wuhide). Strange, now no download starts, even when I click "Download" below the offered updates. Services are running.
Anyway, it's a 1 year old OEM install, so I will reinstall from scratch Win11.
CU
DigitalTrance