locked
Windows 7 build 7601 not genuine, nothing has changed except basic updates, bought new from Amazon.com RRS feed

  • Question

  • Hello, I've seen many other posts, but none seem to help. Here are my results my from the diagnostic tool:

    What can I do to fix this? Thanks!!  

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc0000022
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Dan Hickman\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-173273786-991932481-227531499</SID><SYSTEM><Manufacturer>Gateway</Manufacturer><Model>SX2840</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>P01-B0</Version><SMBIOSVersion major="2" minor="6"/><Date>20100120000000.000000+000</Date></BIOS><HWID>65DC3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.
    Error: 0x80070426 

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0001000000000000
    Event Time Stamp: 5:14:2012 19:10
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered Service: sppsvc


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAACAAAAAQABAAEAonaq0oSxgJYY1l6qZCe2OQaHBNb0JVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ACRSYS APIC0850
      FACP ACRSYS FACP0850
      HPET ACRSYS OEMHPET 
      MCFG ACRSYS OEMMCFG 
      SLIC ACRSYS ACRPRDCT
      OEMB ACRSYS OEMB0850
      GSCI ACRSYS GMCHSCI 
      AWMI ACRSYS OEMB0850
      SSDT DpgPmm CpuPm




    Monday, May 14, 2012 11:17 PM

Answers

  • "danandnikki07" wrote in message news:a59d91b8-778c-4fa1-be5b-b64dde84703a...

    Hi Noel, No, no error message either. I did try to copy/paste only a portion of the link: slmgr.vbs /rilc >%userprofile%\desktop\test1.txt, and Windows Script Host error popped up saying:

    Re-installing license files...

    On a computer running Microsoft Windows non-core deition, run 'slui.exe 0x2a0x80070426' to display error text.

    Error: 0x80070426

    ------

    I tried this, and I received the Windows Activation Error, Code: 0xC0020012

    Thanks again!


    Dan

    OK - that may give us something to work with (cscript is not properly registered, I suspect)
    The 426 error doesn't really surprise me, and the 0xC0020012 error is probably a result of that, rather than a different error.
     
    I think your only option now is a repair install - (you are able to read the COA sticker, aren't you??)
     
    you'll need to download the x64 ISO for Win 7 Home Premium SP1 from the link here - http://www.heidoc.net/joomla/technology-science/microsoft
     
    and burn the DVD from it.
    Then you need to perform the repair install itself - look here for a good set of instructions = Repair Install
     
    remember to back up your data to external media first!
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Thursday, June 7, 2012 11:57 AM
    Moderator

All replies

  • Hello danandnikki07,

      Sorry for the wait.  The first thing I would suggest is to try recreating the licensing store:

    1) Click Start button.
    2) Type: CMD.exe into the 'Search programs and files' field
    3) Right-Click on CMD.exe and select Run as Administrator
    4) Type: net stop sppsvc   (It may ask you if you are sure, select yes)
    Note: the Software Protection servive may not be running, this is ok.
    5) Type: cd %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    6) Type: rename tokens.dat tokens.bar
    7) Type: cd %windir%\system32
    8) Type: net start sppsvc
    9) Type: slui.exe
    10) After a couple of seconds Windows Activation dialog will appear. You may be asked to re-activate and/or re-enter your product key or Activation may occur automatically.

    Thank you,


    Darin MS

    Thursday, May 17, 2012 5:43 PM
  • Thanks! I tried everything and double checked every step twice, and after entering slui.exe, I received the following msg:

    An error has occurred:

    Details:

    Code: 0xC0000022

    Description:

    {Access Denied}

    A process has requested access to an object, but has not been granted those access rights. 


    Dan

    Thursday, May 17, 2012 7:31 PM
  • "danandnikki07" wrote in message news:c3454ddb-4137-40c7-b9fa-382ac238b923...

    Thanks! I tried everything and double checked every step twice, and after entering slui.exe, I received the following msg:

    An error has occurred:

    Details:

    Code: 0xC0000022

    Description:

    {Access Denied}

    A process has requested access to an object, but has not been granted those access rights.


    Dan

    Click on Start
    in the Search box, type
    SERVICES.MSC
    and hit the Enter key - accept the UAC prompt if you get one.
    Look in the console for the Software Protection service, right-click on it and select Properties.
    make sure that the Startup Type is set to Automatic (Delayed Start), and click Apply.

    Try starting the service now - do you get an error message? Does it start? does it almost immediately stop again?
    Post back with your results, and a new MGADiag report.

    If it doesn't start, then please do the following...
    Please open an Elevated (Administrator) Command Prompt window and use the following commands....

    net start sppsvc
    sc qc sppsvc
    sc queryex sppsvc
    sc qprivs sppsvc
    sc qsidtype sppsvc
    sc sdshow sppsvc
    Here are some instructions to maike life easier :)
    1) To open an Elevated Command Prompt Window (the CP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt.
    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Windows, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once.
    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Friday, May 18, 2012 7:36 AM
    Moderator
  • The SPS only ran for a second, here is the msg:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>net start sppsvc
    The Software Protection service is starting.
    The Software Protection service could not be started.

    A system error has occurred.

    System error 2 has occurred.

    The system cannot find the file specified.


    C:\Windows\system32>net start sppsvc
    The Software Protection service is starting.
    The Software Protection service could not be started.

    A system error has occurred.

    System error 2 has occurred.

    The system cannot find the file specified.


    C:\Windows\system32>


    Dan

    Friday, May 18, 2012 4:05 PM
  • "danandnikki07" wrote in message news:4c0f6fe9-b3c6-4a29-b7f2-f457d1243933...

    The SPS only ran for a second, here is the msg:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>net start sppsvc
    The Software Protection service is starting.
    The Software Protection service could not be started.

    A system error has occurred.

    System error 2 has occurred.

    The system cannot find the file specified.


    C:\Windows\system32>net start sppsvc
    The Software Protection service is starting.
    The Software Protection service could not be started.

    A system error has occurred.

    System error 2 has occurred.

    The system cannot find the file specified.


    C:\Windows\system32>


    Dan

    ,,,,,and the rest of the information I asked for??
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Friday, May 18, 2012 5:34 PM
    Moderator
  • Hi Noel, Sorry about that. When I try to copy the report, it now give the following error msg:

    Failed to create output files, hr = 0x80070002

    I restarted and tried again... same msg. ahhhh

    see attached. Thanks!

    


    Dan

    Friday, May 18, 2012 7:36 PM
  • ignore the error message. it will still copy and paste
    Friday, May 18, 2012 8:03 PM
    Answerer
  • Oh, okay, here's what it goes.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc0000022
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Dan Hickman\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-173273786-991932481-227531499</SID><SYSTEM><Manufacturer>Gateway</Manufacturer><Model>SX2840</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>P01-B0</Version><SMBIOSVersion major="2" minor="6"/><Date>20100120000000.000000+000</Date></BIOS><HWID>65DC3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.
    Error: 0x80070426 

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0001000000000000
    Event Time Stamp: 5:17:2012 07:42
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered Service: sppsvc


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAACAAAAAQABAAEAonaq0oSxgJYY1l6qZCe2OQaHBNb0JVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ACRSYS APIC0850
      FACP ACRSYS FACP0850
      HPET ACRSYS OEMHPET 
      MCFG ACRSYS OEMMCFG 
      SLIC ACRSYS ACRPRDCT
      OEMB ACRSYS OEMB0850
      GSCI ACRSYS GMCHSCI 
      AWMI ACRSYS OEMB0850
      SSDT DpgPmm CpuPm


    Dan

    Friday, May 18, 2012 8:11 PM
  • You have still not provided the asked-for information - the output from

    net start sppsvc
    sc qc sppsvc
    sc queryex sppsvc
    sc qprivs sppsvc
    sc qsidtype sppsvc
    sc sdshow sppsvc


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, May 18, 2012 9:28 PM
    Moderator
  • Hi Noel, Sorry again.  Here ya go. Thanks in advance!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>net start sppsvc
    The Software Protection service is starting.
    The Software Protection service could not be started.

    A system error has occurred.

    System error 2 has occurred.

    The system cannot find the file specified.


    C:\Windows\system32>sc qc sppsvc
    [SC] QueryServiceConfig SUCCESS

    SERVICE_NAME: sppsvc
            TYPE               : 10  WIN32_OWN_PROCESS
            START_TYPE         : 2   AUTO_START  (DELAYED)
            ERROR_CONTROL      : 1   NORMAL
            BINARY_PATH_NAME   : C:\Windows\system32\sppsvc.exe
            LOAD_ORDER_GROUP   :
            TAG                : 0
            DISPLAY_NAME       : Software Protection
            DEPENDENCIES       : RpcSs
            SERVICE_START_NAME : NT AUTHORITY\NetworkService

    C:\Windows\system32>sc queryex sppsvc

    SERVICE_NAME: sppsvc
            TYPE               : 10  WIN32_OWN_PROCESS
            STATE              : 1  STOPPED
            WIN32_EXIT_CODE    : 2  (0x2)
            SERVICE_EXIT_CODE  : 0  (0x0)
            CHECKPOINT         : 0x0
            WAIT_HINT          : 0x0
            PID                : 0
            FLAGS              :

    C:\Windows\system32>sc qprivs sppsvc
    [SC] QueryServiceConfig2 SUCCESS

    SERVICE_NAME: sppsvc
            PRIVILEGES       : SeAuditPrivilege
                             : SeChangeNotifyPrivilege
                             : SeCreateGlobalPrivilege
                             : SeImpersonatePrivilege

    C:\Windows\system32>sc qsidtype sppsvc
    [SC] QueryServiceConfig2 SUCCESS

    SERVICE_NAME: sppsvc
    SERVICE_SID_TYPE:  UNRESTRICTED

    C:\Windows\system32>sc sdshow sppsvc

    D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPLO
    CRRC;;;IU)(A;;CCLCSWRPLOCRRC;;;SU)(A;;LCRP;;;AU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCW
    DWO;;;WD)

    C:\Windows\system32>


    Dan

    Saturday, May 19, 2012 1:49 AM
  • "danandnikki07" wrote in message news:293bb6f1-b078-4b9d-8fc0-43cb062b1b5c...

    Hi Noel, Sorry again.  Here ya go. Thanks in advance!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.


    Dan

    OK That looks normal enough -
    Please run the following commands - post the results
    REG QUERY HKU
    REG QUERY HKU\S-1-5-20
    REG QUERY HKU\S-1-5-20\Environment
    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"
    ICACLS C:\Windows\ServiceProfiles\NetworkService
    ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    DIR C:\Windows\ServiceProfiles\NetworkService
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Saturday, May 19, 2012 9:43 AM
    Moderator
  • Hi Noel, Okay, here ya go. Thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>reg query hku

    HKEY_USERS\.DEFAULT
    HKEY_USERS\S-1-5-19
    HKEY_USERS\S-1-5-20
    HKEY_USERS\S-1-5-21-173273786-991932481-227531499-1001
    HKEY_USERS\S-1-5-21-173273786-991932481-227531499-1001_Classes
    HKEY_USERS\S-1-5-18

    C:\Windows\system32>reg query hku\s-1-5-20

    HKEY_USERS\s-1-5-20\AppEvents
    HKEY_USERS\s-1-5-20\Console
    HKEY_USERS\s-1-5-20\Control Panel
    HKEY_USERS\s-1-5-20\Environment
    HKEY_USERS\s-1-5-20\EUDC
    HKEY_USERS\s-1-5-20\Keyboard Layout
    HKEY_USERS\s-1-5-20\Network
    HKEY_USERS\s-1-5-20\Printers
    HKEY_USERS\s-1-5-20\Software
    HKEY_USERS\s-1-5-20\System

    C:\Windows\system32>reg query hku\s-1-5-20\environment

    HKEY_USERS\s-1-5-20\environment
        TEMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp
        TMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp


    C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentversion
    \profilelist\s-1-5-20"

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\profilelist\s-1-
    5-20
        ProfileImagePath    REG_EXPAND_SZ    C:\Windows\ServiceProfiles\NetworkServi
    ce
        Flags    REG_DWORD    0x0
        State    REG_DWORD    0x0


    C:\Windows\system32>icacls C:\windows\serviceprofiles\networkservice
    C:\windows\serviceprofiles\networkservice NT AUTHORITY\SYSTEM:(OI)(CI)(F)
                                              BUILTIN\Administrators:(OI)(CI)(F)
                                              NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(
    F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>icacls c:\windows\serviceprofiles\networkservice\ntuser.dat
    c:\windows\serviceprofiles\networkservice\ntuser.dat NT AUTHORITY\SYSTEM:(I)(F)
                                                         BUILTIN\Administrators:(I)(
    F)
                                                         NT AUTHORITY\NETWORK SERVIC
    E:(I)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>dir c:\windows\serviceprofiles\networkservice
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of c:\windows\serviceprofiles\networkservice

    06/21/2011  08:07 PM    <DIR>          .
    06/21/2011  08:07 PM    <DIR>          ..
    07/14/2009  12:45 AM    <DIR>          Desktop
    07/14/2009  12:45 AM    <DIR>          Documents
    07/14/2009  12:45 AM    <DIR>          Downloads
    07/14/2009  12:45 AM    <DIR>          Favorites
    07/14/2009  12:45 AM    <DIR>          Links
    07/14/2009  12:45 AM    <DIR>          Music
    07/14/2009  12:45 AM    <DIR>          Pictures
    07/14/2009  12:45 AM    <DIR>          Saved Games
    07/14/2009  12:45 AM    <DIR>          Videos
                   0 File(s)              0 bytes
                  11 Dir(s)  777,016,561,664 bytes free

    C:\Windows\system32>


    Dan

    Saturday, May 19, 2012 2:56 PM
  • This thread may have fallen off of Noel's radar.

    Bumping the thread to the top of the list for better viability.

    Thank you,


    Darin MS

    Monday, May 21, 2012 10:32 PM
  • "danandnikki07" wrote in message news:f7ebe27e-1836-47fe-a2b2-0ce7522fcccb...

    Hi Noel, Okay, here ya go. Thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>reg query hku

    HKEY_USERS\.DEFAULT
    HKEY_USERS\S-1-5-19
    HKEY_USERS\S-1-5-20
    HKEY_USERS\S-1-5-21-173273786-991932481-227531499-1001
    HKEY_USERS\S-1-5-21-173273786-991932481-227531499-1001_Classes
    HKEY_USERS\S-1-5-18

    C:\Windows\system32>reg query hku\s-1-5-20

    HKEY_USERS\s-1-5-20\AppEvents
    HKEY_USERS\s-1-5-20\Console
    HKEY_USERS\s-1-5-20\Control Panel
    HKEY_USERS\s-1-5-20\Environment
    HKEY_USERS\s-1-5-20\EUDC
    HKEY_USERS\s-1-5-20\Keyboard Layout
    HKEY_USERS\s-1-5-20\Network
    HKEY_USERS\s-1-5-20\Printers
    HKEY_USERS\s-1-5-20\Software
    HKEY_USERS\s-1-5-20\System

    C:\Windows\system32>reg query hku\s-1-5-20\environment

    HKEY_USERS\s-1-5-20\environment
        TEMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp
        TMP    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Temp


    C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentversion
    \profilelist\s-1-5-20"

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\profilelist\s-1-
    5-20
        ProfileImagePath    REG_EXPAND_SZ    C:\Windows\ServiceProfiles\NetworkServi
    ce
        Flags    REG_DWORD    0x0
        State    REG_DWORD    0x0


    C:\Windows\system32>icacls C:\windows\serviceprofiles\networkservice
    C:\windows\serviceprofiles\networkservice NT AUTHORITY\SYSTEM:(OI)(CI)(F)
                                              BUILTIN\Administrators:(OI)(CI)(F)
                                              NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(
    F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>icacls c:\windows\serviceprofiles\networkservice\ntuser.dat
    c:\windows\serviceprofiles\networkservice\ntuser.dat NT AUTHORITY\SYSTEM:(I)(F)
                                                         BUILTIN\Administrators:(I)(
    F)
                                                         NT AUTHORITY\NETWORK SERVIC
    E:(I)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>dir c:\windows\serviceprofiles\networkservice
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987

    Directory of c:\windows\serviceprofiles\networkservice

    06/21/2011  08:07 PM    <DIR>          ..
    06/21/2011  08:07 PM    <DIR>          ...
    07/14/2009  12:45 AM    <DIR>          Desktop
    07/14/2009  12:45 AM    <DIR>          Documents
    07/14/2009  12:45 AM    <DIR>          Downloads
    07/14/2009  12:45 AM    <DIR>          Favorites
    07/14/2009  12:45 AM    <DIR>          Links
    07/14/2009  12:45 AM    <DIR>          Music
    07/14/2009  12:45 AM    <DIR>          Pictures
    07/14/2009  12:45 AM    <DIR>          Saved Games
    07/14/2009  12:45 AM    <DIR>          Videos
                   0 File(s)              0 bytes
                  11 Dir(s)  777,016,561,664 bytes free

    C:\Windows\system32>

    Dan

    (thanks for the nudge, Darin )
     
    That all looks normal -
    In an elevated COmmand Prompt, run the following commands
     
    SFC /scanfile=c:\windows\system32\sppsvc.exe
    SFC /scanfile=c:\windows\system32\slc.dll
    SFC /scanfile=c:\windows\system32\sppobjs.dll
    SFC /scanfile=c:\windows\system32\sppcomapi.dll
    SFC /scanfile=c:\windows\system32\sppc.dll
     
    post the results

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Tuesday, May 22, 2012 9:02 AM
    Moderator
  • Hi Noel, Thanks again! Here are the results:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>sfc/scanfile=c:\windows\system32\sppsvc.exe


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>sfc/scanfile=c:\windows\system32\slc.dll


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>sfc/scanfile=c:\windows\system32\sppobjs.dll


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>sfc/scanfile=c:\windows\system32\sppcomapi.dll


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>sfc/scanfile=c:\windows\system32\sppc.dll


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>


    Dan

    Tuesday, May 22, 2012 12:06 PM
  • "danandnikki07" wrote in message news:2a79e442-0ced-4493-bea7-ee980cbca771...

    Hi Noel, Thanks again! Here are the results:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    Dan

    Rats! that's all normal, as well.
    Please run the following commands
     
    ICACLS C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    ICACLS C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
     
    post the results.
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Tuesday, May 22, 2012 12:22 PM
    Moderator
  • Thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>ICACLS C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7
    327-5P-0.C7483456-A289-439d-8115-601632D005A0
    C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d
    -8115-601632D005A0 NT AUTHORITY\SYSTEM:(I)(F)

                       BUILTIN\Administrators:(I)(F)

                       BUILTIN\Users:(I)(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7
    327-5P-1.C7483456-A289-439d-8115-601632D005A0
    C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d
    -8115-601632D005A0 NT AUTHORITY\SYSTEM:(I)(F)

                       BUILTIN\Administrators:(I)(F)

                       BUILTIN\Users:(I)(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>


    Dan

    Tuesday, May 22, 2012 12:29 PM
  • "danandnikki07" wrote in message news:bd173550-36c6-4527-be20-bd1bd5d5cb5a...

    Thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    Dan

    So much for that bright idea! :(
    OK - back to basics....
    Please run a full CHKDSK and SFC scan.... 
    type in the Search box
    CMD.EXE
    right-click on the only file that is found
    Select Run as Administrator
    - the Elevated Command Prompt window should pop up
    At the Command prompt, type
    CHKDSK C: /R
    and hit the Enter key.
     
    You will be told that the drive is locked,
    and the CHKDSK will run at he next boot - hit the Y key, and then reboot.
     
     
    The chkdsk will take a few hours depending on the size
    of the drive, so be patient!
     
    After the CHKDSK has run, Windows should boot normally
    (possibly after a second auto-reboot) - then run the SFC
     
    SFC -System File Checker - Instructions
    Click on the Start button
    type in the Search box
    CMD.EXE
    right-click on the only file that is found
     
    Select Run as Administrator
    - the Elevated Command Prompt window should pop up
    At the Command prompt, type
     
    SFC /SCANNOW
     
    and hit the Enter key
     
    Wait for the scan to finish - make a note of any error messages - and then reboot.
    Post an MGADiag report with details of any error messages encountered.     
    Please then upload the CBS.log file to your SkyDrive (you'll have to copy it to the desktop first) and post a link
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Tuesday, May 22, 2012 12:39 PM
    Moderator
  • Hi Noel, The scndsk will not start. After rebooting, it a msg appears saying that "a recently installed software program" is not allowing the scan... Then windows starts normally. 

    Dan

    Tuesday, May 22, 2012 12:52 PM
  • "danandnikki07" wrote in message news:9d476ef7-ef7d-4525-ad83-44e140830418...
    Hi Noel, The scndsk will not start. After rebooting, it a msg appears saying that "a recently installed software program" is not allowing the scan... Then windows starts normally. 

    Dan

    That probably means the   pending.xml file is stuck :(
     
    c:\windows\winsxs\pending.xml
     
    please open the file in Notepad - If it's not too big, paste it here, or otherwise you can upload it to your SkyDrive and post a link.
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Tuesday, May 22, 2012 1:16 PM
    Moderator
  • Hi Noel, I need a little help with this one. When I follow the file path, I end up in a folder with hundreds of other folders. When I open it in notepad, it will not find the file. Ideas? Thanks! 

    Dan

    Tuesday, May 22, 2012 8:08 PM
  • In an Elevated Command Prompt, run the following commands

    DIR C:\Windows\Pending.xml /s

    DIR C:\Windows\pending.xml /s /ah

    DIR C:\windows\pending.xml /s /as

    If the File exists, it should show it in one of them, make a note of the location and post back with details of file size and date.

    Note that the file should only exist when there installs pending - so not having it isn't drastic.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Tuesday, May 22, 2012 8:31 PM
    Moderator
  • Hi Noel, here you go. Thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>dir c:\windows\pending.exm /s
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>dir c:\windows\pending.xml /s /ah
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>dir c:\windows\pending.xml /s /as
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>


    Dan

    Wednesday, May 23, 2012 6:11 PM
  • "danandnikki07" wrote in message news:8d313a96-12b6-4be4-8c25-ffebb54368aa...

    Hi Noel, here you go. Thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>dir c:\windows\pending.exm /s
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>dir c:\windows\pending.xml /s /ah
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>dir c:\windows\pending.xml /s /as
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>

    Dan

    OK - the pending .xml is obviously not the problem then.
    Your best option in that case is to run the CHKDSK and SFC in offline mode from a Recovery Environment boot.
     
    reboot the computer, and tap the F8 key until you get the advanced boot menu up - one option should be 'Repair your computer'. Pick that one.
    Log into your normal account
    you'll get a set of options - pick the Command Prompt one
    At the command prompt, type
    DIR D:\
    - if we're lucky this will bring up a listing of your normal C: drive contents, including the Program Files folder(s) and the Windows folder.
    If not, try E:\ (etc. until you get the right letter)
    then type the following command
     
    CHKDSK <drive>: /R
     
    and wait for it to complete - it could take a few hours, depending on the size of the drive
     
    Once complete, type
     
    sfc /scannow /OFFBOOTDIR=<drive:\> /OFFWINDIR=<drive>:\Windows
     
    where <drive> is the letter you found above.
    Wait for the command to complete.
    (make a note of the response!)
    once it has, type
    EXIT
    and the pick the option to reboot.
     
    post another MGADiag report
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Wednesday, May 23, 2012 7:32 PM
    Moderator
  • Hi Noel, Everything worked fine, and once I entered the last command, sfc /scannow... etc.  It repeaded several message about not finding any issues. 

    Here is the MGAdiag report. Thanks again! 

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc0000022
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Dan Hickman\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-173273786-991932481-227531499</SID><SYSTEM><Manufacturer>Gateway</Manufacturer><Model>SX2840</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>P01-B0</Version><SMBIOSVersion major="2" minor="6"/><Date>20100120000000.000000+000</Date></BIOS><HWID>65DC3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.
    Error: 0x80070426 

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0001000000000000
    Event Time Stamp: 5:20:2012 22:22
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered Service: sppsvc


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAACAAAAAQABAAEAonaq0oSxgJYY1l6qZCe2OQaHBNb0JVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ACRSYS APIC0850
      FACP ACRSYS FACP0850
      HPET ACRSYS OEMHPET 
      MCFG ACRSYS OEMMCFG 
      SLIC ACRSYS ACRPRDCT
      OEMB ACRSYS OEMB0850
      GSCI ACRSYS GMCHSCI 
      AWMI ACRSYS OEMB0850
      SSDT DpgPmm CpuPm


    Dan

    Thursday, May 24, 2012 12:58 AM
  • "danandnikki07" wrote in message news:a4af9cfa-735d-445b-958a-a640055a96a7...

    Hi Noel, Everything worked fine, and once I entered the last command, sfc /scannow... etc.  It repeaded several message about not finding any issues.

    Here is the MGAdiag report. Thanks again!

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc0000022
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Dan Hickman\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{04ACF188-085E-4DF4-A0F1-9CCAF0013FE6}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-173273786-991932481-227531499</SID><SYSTEM><Manufacturer>Gateway</Manufacturer><Model>SX2840</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>P01-B0</Version><SMBIOSVersion major="2" minor="6"/><Date>20100120000000.000000+000</Date></BIOS><HWID>65DC3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.
    Error: 0x80070426


    Dan

    OK let's look in a slightly different place...
     
    REG QUERY HKLM\CurrentControlSet\Services\sppsvc
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Thursday, May 24, 2012 7:00 AM
    Moderator
  • No luck here:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>REG QUERY HKLM\CurrentControlSet\Services\sppsvc
    ERROR: The system was unable to find the specified registry key or value.

    C:\Windows\system32>


    Dan

    Thursday, May 24, 2012 2:21 PM
  • Sorry - my fault

    Try this one...

    REG QUERY HKLM\SYSTEM\CurrentControlSet\services\sppsvc


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Thursday, May 24, 2012 3:02 PM
    Moderator
  • Yes, this one worked. Thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\sppsvc

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppsvc
        DisplayName    REG_SZ    @%SystemRoot%\system32\sppsvc.exe,-101
        ImagePath    REG_EXPAND_SZ    %SystemRoot%\system32\sppsvc.exe
        Description    REG_SZ    @%SystemRoot%\system32\sppsvc.exe,-100
        ObjectName    REG_SZ    NT AUTHORITY\NetworkService
        ErrorControl    REG_DWORD    0x1
        Start    REG_DWORD    0x2
        DelayedAutoStart    REG_DWORD    0x1
        Type    REG_DWORD    0x10
        DependOnService    REG_MULTI_SZ    RpcSs
        ServiceSidType    REG_DWORD    0x1
        RequiredPrivileges    REG_MULTI_SZ    SeAuditPrivilege\0SeChangeNotifyPrivil
    ege\0SeCreateGlobalPrivilege\0SeImpersonatePrivilege
        FailureActions    REG_BINARY    80510100000000000000000003000000140000000100
    0000C0D4010001000000E09304000000000000000000

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppsvc\Security

    C:\Windows\system32>


    Dan

    Thursday, May 24, 2012 3:12 PM
  • "danandnikki07" wrote in message news:b66bba0d-4761-4ac0-8049-c0b5da314203...

    Yes, this one worked. Thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\sppsvc


    Dan

    That all looks fine to me.
    (not too surprising - it's a restatement of the first commands I asked you to run)
     
    one thing we haven't checked yet....
     
    ICACLS C:\Windows\SLUI.* /T
     
    (Dunno why I keep on forgetting that? - too simple, I suppose!)
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Friday, May 25, 2012 9:58 AM
    Moderator
  • Here it is. Thanks again!!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>ICACLS C:\Windows\SLUI.* /T
    C:\Windows\Prefetch\SLUI.EXE-A65918C4.pf BUILTIN\Administrators:(I)(F)

    C:\Windows\System32\slui.exe NT SERVICE\TrustedInstaller:(F)
                                 BUILTIN\Administrators:(RX)
                                 NT AUTHORITY\SYSTEM:(RX)
                                 BUILTIN\Users:(RX)

    C:\Windows\System32\en-US\slui.exe.mui NT SERVICE\TrustedInstaller:(F)
                                           BUILTIN\Administrators:(RX)
                                           NT AUTHORITY\SYSTEM:(RX)
                                           BUILTIN\Users:(RX)

    C:\Windows\System32\LogFiles\WMI\RtBackup\SLUI.*: Access is denied.
    Successfully processed 3 files; Failed processing 1 files

    C:\Windows\system32>


    Dan

    Friday, May 25, 2012 4:49 PM
  • C:\Windows\System32\LogFiles\WMI\RtBackup\SLUI.*: Access is denied.
    Successfully processed 3 files; Failed processing 1 files

    ..... this shows a problem - but it's one I've not met before, so I'll have to do some research.

    back tomorrow!


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, May 25, 2012 5:45 PM
    Moderator
  • "Noel D Paton" wrote in message news:f88bb1e6-8757-41e9-8fe9-1e9b2f196580...

    C:\Windows\System32\LogFiles\WMI\RtBackup\SLUI.*: Access is denied.
    Successfully processed 3 files; Failed processing 1 files

    ..... this shows a problem - but it's one I've not met before, so I'll have to do some research.

    back tomorrow!


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    I still have no idea where this file cam from - it shouldn't exist in this position as far as I'm aware.
     
    Please run the following commands in an Elevated Command Prompt.
     
    dir c:\windows /al /s
    PATH
    dir C:\Windows\System32\LogFiles\WMI\RtBackup
    dir C:\Windows\System32\LogFiles\WMI\RtBackup /ah
    dir C:\Windows\System32\LogFiles\WMI\RtBackup /as
    dir C:\Windows\System32\LogFiles\WMI\RtBackup /ar
     
    post the results.

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Saturday, May 26, 2012 11:41 AM
    Moderator
  • Hi Noel, Here are the results. thanks! 

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>dir c:\windows /al /s
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987
    File Not Found

    C:\Windows\system32>PATH
    PATH=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32
    \WindowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Intuit\QBPOSSDKRunt
    ime;C:\Program Files (x86)\QuickTime\QTSystem\

    C:\Windows\system32>dir C:\Windows\System32\LogFiles\WMI\RtBackup
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32\LogFiles\WMI\RtBackup

    File Not Found

    C:\Windows\system32>dir C:\Windows\System32\LogFiles\WMI\RtBackup /ah
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32\LogFiles\WMI\RtBackup

    File Not Found

    C:\Windows\system32>dir C:\Windows\System32\LogFiles\WMI\RtBackup /as
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32\LogFiles\WMI\RtBackup

    File Not Found

    C:\Windows\system32>dir C:\Windows\System32\LogFiles\WMI\RtBackup /ar
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32\LogFiles\WMI\RtBackup

    File Not Found

    C:\Windows\system32>


    Dan

    Sunday, May 27, 2012 7:10 PM
  • "danandnikki07" wrote in message news:a61732e7-bb05-4775-b059-9e88545393cd...

    Hi Noel, Here are the results. thanks!


    C:\Windows\system32>dir C:\Windows\System32\LogFiles\WMI\RtBackup
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987

    Directory of C:\Windows\System32\LogFiles\WMI\RtBackup

    File Not Found


    Dan

    Now I'm totally confused - unless the SLUI file is an artefact produced somewhere at runtime, or the permissions are very odd. There should be files in the folder - and your results indicate there are none at all.
    Hmmmm - checking the default settings, the permissions are a little strange
     
    It appears that the permissions are such (by default) that those commands will actually give that error! (why it can't fail more gracefully, I have no idea).
     
    So that means we have to look elsewhere for the root cause.
     
    please run the following commands and post the results.
    dir C:\Windows\System32\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms
    dir C:\Windows\SysWOW64\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms
    icacls C:\Windows\System32\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms
    icacls C:\Windows\SysWOW64\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Sunday, May 27, 2012 8:23 PM
    Moderator
  • Hi Noel, Here you go. Thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>dir C:\Windows\System32\spp\tokens\pkeyconfig\pkeyconfig.xrm
    -ms
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32\spp\tokens\pkeyconfig

    11/20/2010  09:39 AM         1,018,920 pkeyconfig.xrm-ms
                   1 File(s)      1,018,920 bytes
                   0 Dir(s)  775,895,199,744 bytes free

    C:\Windows\system32>dir C:\Windows\SysWOW64\spp\tokens\pkeyconfig\pkeyconfig.xrm
    -ms
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\SysWOW64\spp\tokens\pkeyconfig

    11/20/2010  08:33 AM         1,018,920 pkeyconfig.xrm-ms
                   1 File(s)      1,018,920 bytes
                   0 Dir(s)  775,895,199,744 bytes free

    C:\Windows\system32>icacls C:\Windows\System32\spp\tokens\pkeyconfig\pkeyconfig.
    xrm-ms
    C:\Windows\System32\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms NT SERVICE\TrustedIn
    staller:(F)
                                                                BUILTIN\Administrato
    rs:(RX)
                                                                NT AUTHORITY\SYSTEM:
    (RX)
                                                                BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>icacls C:\Windows\SysWOW64\spp\tokens\pkeyconfig\pkeyconfig.
    xrm-ms
    C:\Windows\SysWOW64\spp\tokens\pkeyconfig\pkeyconfig.xrm-ms NT SERVICE\TrustedIn
    staller:(F)
                                                                BUILTIN\Administrato
    rs:(RX)
                                                                NT AUTHORITY\SYSTEM:
    (RX)
                                                                BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>


    Dan

    Monday, May 28, 2012 2:53 AM
  • Please run the following commands

    DIR C:\Windows\csrss.exe /s

    ICACLS C:\windows\system32\csrss.exe

    ICACLS C:\windows\system32\en-US\csrss.exe.mui

    ICACLS C:\windows\system32\sspicli.dll

    ICACLS c:\windows\system32\schedsvc.dll

    ICACLS c:\windows\system32\taskschd.dll

    post the results


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, May 28, 2012 12:41 PM
    Moderator
  • Here ya go. thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\csrss.exe /s
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\System32

    07/13/2009  09:39 PM             7,680 csrss.exe
                   1 File(s)          7,680 bytes

     Directory of C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6
    .1.7600.16385_none_b4d8d57efdc6b4f3

    07/13/2009  09:39 PM             7,680 csrss.exe
                   1 File(s)          7,680 bytes

         Total Files Listed:
                   2 File(s)         15,360 bytes
                   0 Dir(s)  775,880,404,992 bytes free

    C:\Windows\system32>ICACLS C:\windows\system32\csrss.exe
    C:\windows\system32\csrss.exe NT SERVICE\TrustedInstaller:(F)
                                  BUILTIN\Administrators:(RX)
                                  NT AUTHORITY\SYSTEM:(RX)
                                  BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\windows\system32\en-US\csrss.exe.mui
    C:\windows\system32\en-US\csrss.exe.mui NT SERVICE\TrustedInstaller:(F)
                                            BUILTIN\Administrators:(RX)
                                            NT AUTHORITY\SYSTEM:(RX)
                                            BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\windows\system32\sspicli.dll
    C:\windows\system32\sspicli.dll NT SERVICE\TrustedInstaller:(F)
                                    BUILTIN\Administrators:(RX)
                                    NT AUTHORITY\SYSTEM:(RX)
                                    BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS c:\windows\system32\schedsvc.dll
    c:\windows\system32\schedsvc.dll NT SERVICE\TrustedInstaller:(F)
                                     BUILTIN\Administrators:(RX)
                                     NT AUTHORITY\SYSTEM:(RX)
                                     BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS c:\windows\system32\taskschd.dll
    c:\windows\system32\taskschd.dll NT SERVICE\TrustedInstaller:(F)
                                     BUILTIN\Administrators:(RX)
                                     NT AUTHORITY\SYSTEM:(RX)
                                     BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>


    Dan

    Monday, May 28, 2012 1:24 PM
  • Ever  get the feeling you're running around in circles? :(

    I need to think for a while -  back tomorrow!


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, May 28, 2012 2:05 PM
    Moderator
  • Hi Noel, any updates? Thanks!! 

    Dan

    Friday, June 1, 2012 3:04 PM
  • "danandnikki07" wrote in message news:6aa36e42-88d0-450c-8e33-6e0604175b92...

    Here ya go. thanks!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\csrss.exe /s
    Volume in drive C is Gateway
    Volume Serial Number is 7862-4987

    Directory of C:\Windows\System32

    07/13/2009  09:39 PM             7,680 csrss.exe
                   1 File(s)          7,680 bytes

    Directory of C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6
    1.7600.16385_none_b4d8d57efdc6b4f3

    07/13/2009  09:39 PM             7,680 csrss.exe
                   1 File(s)          7,680 bytes

         Total Files Listed:
                   2 File(s)         15,360 bytes
                   0 Dir(s)  775,880,404,992 bytes free

    C:\Windows\system32>ICACLS C:\windows\system32\csrss.exe
    C:\windows\system32\csrss.exe NT SERVICE\TrustedInstaller:(F)
                                  BUILTIN\Administrators:(RX)
                                  NT AUTHORITY\SYSTEM:(RX)
                                  BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\windows\system32\en-US\csrss.exe.mui
    C:\windows\system32\en-US\csrss.exe.mui NT SERVICE\TrustedInstaller:(F)
                                            BUILTIN\Administrators:(RX)
                                            NT AUTHORITY\SYSTEM:(RX)
                                            BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\windows\system32\sspicli.dll
    C:\windows\system32\sspicli.dll NT SERVICE\TrustedInstaller:(F)
                                    BUILTIN\Administrators:(RX)
                                    NT AUTHORITY\SYSTEM:(RX)
                                    BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS c:\windows\system32\schedsvc.dll
    c:\windows\system32\schedsvc.dll NT SERVICE\TrustedInstaller:(F)
                                     BUILTIN\Administrators:(RX)
                                     NT AUTHORITY\SYSTEM:(RX)
                                     BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS c:\windows\system32\taskschd.dll
    c:\windows\system32\taskschd.dll NT SERVICE\TrustedInstaller:(F)
                                     BUILTIN\Administrators:(RX)
                                     NT AUTHORITY\SYSTEM:(RX)
                                     BUILTIN\Users:(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>

    Dan

    Oooops - sorry, I got side-tracked, slightly (don't be afraid to nudge me if it happens again!)
     
    I've just been reminded that I have seen a similar problem before, where the NetworkService account was locked somehow.
    Please run the following commands - hopefully that'll show if the same problem exists here, and check another few things at the same time.
     
    DIR C:\Windows\ServiceProfiles\NetworkService
    ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
     
    post the results, and I'll try not to get sidetracked again :)
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Friday, June 1, 2012 3:25 PM
    Moderator
  • Sorry - need to add another line as well to allow for settings differences.....

    DIR C:\Windows\ServiceProfiles\NetworkService /ah


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, June 1, 2012 3:31 PM
    Moderator
  • Hi Noel, here goes. thanks again!

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\ServiceProfiles\NetworkService

    06/21/2011  08:07 PM    <DIR>          .
    06/21/2011  08:07 PM    <DIR>          ..
    07/14/2009  12:45 AM    <DIR>          Desktop
    07/14/2009  12:45 AM    <DIR>          Documents
    07/14/2009  12:45 AM    <DIR>          Downloads
    07/14/2009  12:45 AM    <DIR>          Favorites
    07/14/2009  12:45 AM    <DIR>          Links
    07/14/2009  12:45 AM    <DIR>          Music
    07/14/2009  12:45 AM    <DIR>          Pictures
    07/14/2009  12:45 AM    <DIR>          Saved Games
    07/14/2009  12:45 AM    <DIR>          Videos
                   0 File(s)              0 bytes
                  11 Dir(s)  770,716,266,496 bytes free

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\AppData\Roa
    ming\Microsoft\SoftwareProtectionPlatform
    C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProt
    ectionPlatform NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)

                   BUILTIN\Administrators:(I)(OI)(CI)(F)

                   NT AUTHORITY\NETWORK SERVICE:(I)(OI)(CI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT NT AUTHORITY\SYSTEM:(I)(F)
                                                         BUILTIN\Administrators:(I)(
    F)
                                                         NT AUTHORITY\NETWORK SERVIC
    E:(I)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService /ah
     Volume in drive C is Gateway
     Volume Serial Number is 7862-4987

     Directory of C:\Windows\ServiceProfiles\NetworkService

    02/11/2011  07:16 AM    <DIR>          AppData
    05/30/2012  07:00 AM           524,288 ntuser.dat
    07/14/2009  03:12 AM             1,024 NTUSER.DAT.LOG
    05/30/2012  07:00 AM           226,304 NTUSER.DAT.LOG1
    07/14/2009  12:45 AM                 0 NTUSER.DAT.LOG2
    07/14/2009  01:01 AM            65,536 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
    cde3ec}.TM.blf
    07/14/2009  01:01 AM           524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
    cde3ec}.TMContainer00000000000000000001.regtrans-ms
    07/14/2009  01:01 AM           524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
    cde3ec}.TMContainer00000000000000000002.regtrans-ms
    11/11/2010  04:27 AM            65,536 ntuser.dat{1c316be9-e757-11df-a394-806e6f
    6e6963}.TM.blf
    11/11/2010  04:27 AM           524,288 ntuser.dat{1c316be9-e757-11df-a394-806e6f
    6e6963}.TMContainer00000000000000000001.regtrans-ms
    11/11/2010  04:27 AM           524,288 ntuser.dat{1c316be9-e757-11df-a394-806e6f
    6e6963}.TMContainer00000000000000000002.regtrans-ms
    12/25/2010  02:27 PM            65,536 ntuser.dat{26018843-0ea8-11e0-92e5-806e6f
    6e6963}.TM.blf
    12/25/2010  02:27 PM           524,288 ntuser.dat{26018843-0ea8-11e0-92e5-806e6f
    6e6963}.TMContainer00000000000000000001.regtrans-ms
    12/25/2010  02:27 PM           524,288 ntuser.dat{26018843-0ea8-11e0-92e5-806e6f
    6e6963}.TMContainer00000000000000000002.regtrans-ms
    02/05/2011  04:17 AM            65,536 ntuser.dat{3d32fbbe-28d4-11e0-9280-806e6f
    6e6963}.TM.blf
    02/05/2011  04:17 AM           524,288 ntuser.dat{3d32fbbe-28d4-11e0-9280-806e6f
    6e6963}.TMContainer00000000000000000001.regtrans-ms
    02/05/2011  04:17 AM           524,288 ntuser.dat{3d32fbbe-28d4-11e0-9280-806e6f
    6e6963}.TMContainer00000000000000000002.regtrans-ms
    09/23/2010  10:21 PM            65,536 ntuser.dat{5d18ae26-c780-11df-92e5-806e6f
    6e6963}.TM.blf
    09/23/2010  10:21 PM           524,288 ntuser.dat{5d18ae26-c780-11df-92e5-806e6f
    6e6963}.TMContainer00000000000000000001.regtrans-ms
    09/23/2010  10:21 PM           524,288 ntuser.dat{5d18ae26-c780-11df-92e5-806e6f
    6e6963}.TMContainer00000000000000000002.regtrans-ms
    06/21/2011  08:09 PM            65,536 ntuser.dat{9406de76-9c63-11e0-b533-806e6f
    6e6963}.TM.blf
    06/21/2011  08:09 PM           524,288 ntuser.dat{9406de76-9c63-11e0-b533-806e6f
    6e6963}.TMContainer00000000000000000001.regtrans-ms
    06/21/2011  08:09 PM           524,288 ntuser.dat{9406de76-9c63-11e0-b533-806e6f
    6e6963}.TMContainer00000000000000000002.regtrans-ms
    09/28/2010  05:44 PM            65,536 ntuser.dat{eb2d9dc2-cafd-11df-a3a5-90fba6
    84dcea}.TM.blf
    09/28/2010  05:44 PM           524,288 ntuser.dat{eb2d9dc2-cafd-11df-a3a5-90fba6
    84dcea}.TMContainer00000000000000000001.regtrans-ms
    09/28/2010  05:44 PM           524,288 ntuser.dat{eb2d9dc2-cafd-11df-a3a5-90fba6
    84dcea}.TMContainer00000000000000000002.regtrans-ms
                  25 File(s)      8,550,400 bytes
                   1 Dir(s)  770,715,774,976 bytes free

    C:\Windows\system32>


    Dan

    Saturday, June 2, 2012 7:28 PM
  • Hi Noel, It's me again. Any updates? Thanks! 

    Dan

    Wednesday, June 6, 2012 3:14 PM
  • "danandnikki07" wrote in message news:5417017f-6230-4b98-8656-9d14c9e43e30...
    Hi Noel, It's me again. Any updates? Thanks! 

    Dan

    (Thinks - can I get away with blaming the bank holiday weekend?)
     
    Must admit I thought I'd replied to this one already but it seems not - mea culpa.
     
    The only thing odd about the report is that the NTUSER.DAT file and its derivatives are named in lower case - which would tend to mean that at some stage it's been tampered with manually. Since that goes back to 2010, it's very unlikely to be the cause of your current problems.
     
    (gotta admire your persistence, BTW!)
     
    Let's go off on a tangent - it may give us a pointer....
    run the following command in an Elevated Command Prompt.
     
    Cscript C:\windows\system32\slmgr.vbs /rilc >%userprofile%\desktop\test1.txt
     
    This will place a notepad file on your desktop, called test1.txt
     
    Open it in Notepad and see if there are any error messages there (if you got none during the run) - the last line should say 'License files reinstalled successfully'
    If there are, or the last line doesn't read that way, please upload the file to your public SkyDrive.
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Wednesday, June 6, 2012 4:05 PM
    Moderator
  • Hi Noel, it didn't work..., well, it didn't generate the file. Do I copy/paste the entire file path in the elevated command prompt? That's what I did. Any advice will be appreciated. Thanks again!

    Dan

    Thursday, June 7, 2012 12:14 AM
  • "danandnikki07" wrote in message news:824b1a0a-d5c3-43e6-9240-000f70303ddd...
    Hi Noel, it didn't work..., well, it didn't generate the file. Do I copy/paste the entire file path in the elevated command prompt? That's what I did. Any advice will be appreciated. Thanks again!

    Dan

     
    Yep - it should work (it did in my tests), but your problem may be blocking it.
    No error messages either?
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Thursday, June 7, 2012 7:34 AM
    Moderator
  • Hi Noel, No, no error message either. I did try to copy/paste only a portion of the link: slmgr.vbs /rilc >%userprofile%\desktop\test1.txt, and Windows Script Host error popped up saying:

     Re-installing license files...

    On a computer running Microsoft Windows non-core deition, run 'slui.exe 0x2a0x80070426' to display error text.

    Error: 0x80070426

    ------

    I tried this, and I received the Windows Activation Error, Code: 0xC0020012

    Thanks again! 


    Dan

    Thursday, June 7, 2012 11:34 AM
  • "danandnikki07" wrote in message news:a59d91b8-778c-4fa1-be5b-b64dde84703a...

    Hi Noel, No, no error message either. I did try to copy/paste only a portion of the link: slmgr.vbs /rilc >%userprofile%\desktop\test1.txt, and Windows Script Host error popped up saying:

    Re-installing license files...

    On a computer running Microsoft Windows non-core deition, run 'slui.exe 0x2a0x80070426' to display error text.

    Error: 0x80070426

    ------

    I tried this, and I received the Windows Activation Error, Code: 0xC0020012

    Thanks again!


    Dan

    OK - that may give us something to work with (cscript is not properly registered, I suspect)
    The 426 error doesn't really surprise me, and the 0xC0020012 error is probably a result of that, rather than a different error.
     
    I think your only option now is a repair install - (you are able to read the COA sticker, aren't you??)
     
    you'll need to download the x64 ISO for Win 7 Home Premium SP1 from the link here - http://www.heidoc.net/joomla/technology-science/microsoft
     
    and burn the DVD from it.
    Then you need to perform the repair install itself - look here for a good set of instructions = Repair Install
     
    remember to back up your data to external media first!
     
     

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Thursday, June 7, 2012 11:57 AM
    Moderator
  • No further reply from the Original Poster.

    Issue is assumed to be resolved.


    Darin MS

    Tuesday, June 12, 2012 9:42 PM