Answered by:
Windows Build 7601 - showing a non Genuine software message when I have a genuine Windows 7 Installed

Question
-
HiI have been using Genuine Windows 7 Home Premium. This is full pack which I had purchased at a retail store and have the original purchase invoice as well as the original media with the product key.
This was working fine for more than a year now. Today I tried creating multiple users instead of using only one user. Multiple users were not visible on startup - I went into the forums and read about a regedit step of deleting all other entries in User profiules other than what I had created. This solved the problem i.e. all the users are visible. But now I have a different problem. It is giving an error that the Windows build 7601 is not genuine.
As mentioned in your forum - I have run the MGA tool and pasted the copy here.
Please help as I have Genuine software. I also have Genuine retail p[urchased MS office also installed on the PC and have also recently purchased Outlook online on the microsoft site which is also installed on the same PC.
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 50
Cached Online Validation Code: N/A, hr = 0x80070005
Windows Product Key: *****-*****-GXJV7-J3WK3-2PTTR
Windows Product Key Hash: YImG6RHyK34nxtkD8vVw6zvInqA=
Windows Product ID: 00359-001-0115034-85179
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {451139EA-9FE2-43CD-A42D-362CF76B4802}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{451139EA-9FE2-43CD-A42D-362CF76B4802}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-2PTTR</PKey><PID>00359-001-0115034-85179</PID><PIDType>5</PIDType><SID>S-1-5-21-2261197669-1845000155-2889548959</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DH61WW__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>BEH6110H.86A.0016.2011.0118.1128</Version><SMBIOSVersion major="2" minor="6"/><Date>20110118000000.000000+000</Date></BIOS><HWID>0A5A3E07018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>India Standard Time(GMT+05:30)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>229CFB503293F6E</Val><Hash>y2u4KPJDYMCt6/uK8a0V7Bk8llc=</Hash><Pid>81602-951-2894714-68595</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
Error: 0x46
Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 3:4:2012 15:40
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
HWID Data-->
HWID Hash Current: MAAAAAEAAgABAAEAAAACAAAAAgABAAEAln0U/6gYbFV86aIBwFxqx4NKeKamaC5z
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC INTEL DH61WW
FACP INTEL DH61WW
HPET INTEL DH61WW
MCFG INTEL DH61WW
SSDT INTEL DH61WW
Tuesday, May 1, 2012 3:38 PM
Answers
-
"npuranik" wrote in message news:2c71b98e-cbfa-45a2-b579-60de68c41f20...
As mentioned in the beginning of the thread this problem started when using regedit i deleted the entries other than the ones which had the usernames created by me.
C:\Windows\system32>That was a rather inept thing to do - there are at least three accounts present on ALL computers which are required by the system for it to work anything like normally - the System account, the Local Service account, and the Network Service account.If they are not properly referenced in the registry, the results will be unpredictable at best, and unbootable at worst.If you've deleted the same data elsewhere in the registry, then we may as well give up now, and do a reinstall.If it's only in this registry area then the damage may be limited.I've posted a zip file - Profilelist.zip - here https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21115Please download the file and extract the ProfileListservices.reg file it contains to your desktop.right-click n the extracted file, and select Merge - you should get a UAC prompt, which you accept, and then a 'Succeeded' message.Once complete, reboot, and run a new MGADiag report.Please in future refrain from making registry edits unless you know EXACTLY what you are doing, and why - and do NOT be tempted into using 'Registry Cleaners' or 'Optimisers' - they are all prone to the same sort of error as you just made.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth- Marked as answer by npuranik Wednesday, May 2, 2012 1:53 PM
Wednesday, May 2, 2012 8:17 AMModerator
All replies
-
"npuranik" wrote in message news:23c0d642-87f9-48dd-85b3-85c4b96d47fa...
HiI have been using Genuine Windows 7 Home Premium. This is full pack which I had purchased at a retail store and have the original purchase invoice as well as the original media with the product key.
This was working fine for more than a year now. Today I tried creating multiple users instead of using only one user. Multiple users were not visible on startup - I went into the forums and read about a regedit step of deleting all other entries in User profiules other than what I had created. This solved the problem i.e. all the users are visible. But now I have a different problem. It is giving an error that the Windows build 7601 is not genuine.
As mentioned in your forum - I have run the MGA tool and pasted the copy here.
Please help as I have Genuine software. I also have Genuine retail p[urchased MS office also installed on the PC and have also recently purchased Outlook online on the microsoft site which is also installed on the same PC.
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 50
Cached Online Validation Code: N/A, hr = 0x80070005
Windows Product Key: *****-*****-GXJV7-J3WK3-2PTTR
Windows Product Key Hash: YImG6RHyK34nxtkD8vVw6zvInqA=
Windows Product ID: 00359-001-0115034-85179
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010300.1.0.003
Other data-->
SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DH61WW__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>BEH6110H.86A.0016.2011.0118.1128</Version><SMBIOSVersion major="2" minor="6"/><Date>20110118000000.000000+000</Date></BIOS
Licensing Data-->
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
Error: 0x46
The cause of your problems is the (very unspecific) error highlighted above.First please run the standard file checking tools....Please run CHKDSK and SFC scans -type in the Search box
CMD.EXE
right-click on the only file that is found
Select Run as Administrator
- the Elevated Command Prompt window should pop up
At the Command prompt, type
CHKDSK C: /R
and hit the Enter key.You will be told that the drive is locked,
and the CHKDSK will run at he next boot - hit the Y key, and then reboot.
The chkdsk will take a few hours depending on the size
of the drive, so be patient!
After the CHKDSK has run, Windows should boot normally
(possibly after a second auto-reboot) - then run the SFC
SFC -System File Checker - Instructions
Click on the Start button
type in the Search box
CMD.EXE
right-click on the only file that is found
Select Run as Administrator
- the Elevated Command Prompt window should pop up
At the Command prompt, type
SFC /SCANNOW
and hit the Enter keyWait for the scan to finish - make a note of any error messages - and then reboot.
Post an MGADiag report with details of any error messages encountered.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, May 1, 2012 3:50 PMModerator -
Hi,
Ran both CHKDSK and SFC scan and both did not report any errors. Ran MGADiag again and pasted report below
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->Validation Code: 50
Cached Online Validation Code: N/A, hr = 0x80070005
Windows Product Key: *****-*****-GXJV7-J3WK3-2PTTR
Windows Product Key Hash: YImG6RHyK34nxtkD8vVw6zvInqA=
Windows Product ID: 00359-001-0115034-85179
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010300.1.0.003ID: {451139EA-9FE2-43CD-A42D-362CF76B4802}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/AVista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{451139EA-9FE2-43CD-A42D-362CF76B4802}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-2PTTR</PKey><PID>00359-001-0115034-85179</PID><PIDType>5</PIDType><SID>S-1-5-21-2261197669-1845000155-2889548959</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DH61WW__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>BEH6110H.86A.0016.2011.0118.1128</Version><SMBIOSVersion major="2" minor="6"/><Date>20110118000000.000000+000</Date></BIOS><HWID>0A5A3E07018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>India Standard Time(GMT+05:30)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>229CFB503293F6E</Val><Hash>y2u4KPJDYMCt6/uK8a0V7Bk8llc=</Hash><Pid>81602-951-2894714-68595</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>Spsys.log Content: 0x80070002
Licensing Data-->
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
Error: 0x46
Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 3:4:2012 15:40
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
HWID Data-->
HWID Hash Current: MAAAAAEAAgABAAEAAAACAAAAAgABAAEAln0U/6gYbFV86aIBwFxqx4NKeKamaC5zOEM Activation 1.0 Data-->
N/AOEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC INTEL DH61WW
FACP INTEL DH61WW
HPET INTEL DH61WW
MCFG INTEL DH61WW
SSDT INTEL DH61WWTuesday, May 1, 2012 5:12 PM -
"npuranik" wrote in message news:cd5277e9-0bc0-4e42-9bf5-346c08009a2f...
Hi,
Ran both CHKDSK and SFC scan and both did not report any errors. Ran MGADiag again and pasted report below
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->Validation Code: 50
Cached Online Validation Code: N/A, hr = 0x80070005
Windows Product Key: *****-*****-GXJV7-J3WK3-2PTTR
Windows Product Key Hash: YImG6RHyK34nxtkD8vVw6zvInqA=
Windows Product ID: 00359-001-0115034-85179
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010300.1.0.003ID: {451139EA-9FE2-43CD-A42D-362CF76B4802}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/AVista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{451139EA-9FE2-43CD-A42D-362CF76B4802}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-2PTTR</PKey><PID>00359-001-0115034-85179</PID><PIDType>5</PIDType><SID>S-1-5-21-2261197669-1845000155-2889548959</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DH61WW__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>BEH6110H.86A.0016.2011.0118.1128</Version><SMBIOSVersion major="2" minor="6"/><Date>20110118000000.000000+000</Date></BIOS><HWID>0A5A3E07018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>India Standard Time(GMT+05:30)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>229CFB503293F6E</Val><Hash>y2u4KPJDYMCt6/uK8a0V7Bk8llc=</Hash><Pid>81602-951-2894714-68595</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>Spsys.log Content: 0x80070002
Licensing Data-->
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x46' to display the error text.
Error: 0x46
Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 3:4:2012 15:40
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
HWID Data-->
HWID Hash Current: MAAAAAEAAgABAAEAAAACAAAAAgABAAEAln0U/6gYbFV86aIBwFxqx4NKeKamaC5zOEM Activation 1.0 Data-->
N/AOEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC INTEL DH61WW
FACP INTEL DH61WW
HPET INTEL DH61WW
MCFG INTEL DH61WW
SSDT INTEL DH61WWPlease open an elevated command prompt window, and run the following commands...ICACLS C:\Windows\System32\sppwmi.dllICACLS C:\Windows\System32\sppc.dllICACLS C:\Windows\System32\slwga.dllICACLS C:\Windows\System32\slcext.dllpost the results.Here are some instructions to maike life easier
:)1) To open an Elevated Command Prompt Window
(the CP window), click on Start, All Programs, Accessories – then right-click on
Command Prompt, and select Run as Administrator. Accept the UAC
prompt.2) To run the commands easier, highlight the
block of commands, and right-click on the highlight – select Copy. In the CP
Windows, click on the black/white icon at top left – select Paste. The commands
will run but may not complete the last command, so hit the Enter Key
once.3) To copy the results... click on the
Black/White icon in the top left, and select Edit... 'Select All', and hit the
Enter key - then use Ctrl+V or r-click+Paste to paste it into your
response.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, May 1, 2012 5:21 PMModerator -
Hi
The first command was successful
C:\Windows\System32\sppwmi.dll
Successfully processed 1 file, 0 files failed
for the other three there was a common error message
C:\Windows\System32\sppwmi.dll
C:\Windows\System32\sppc.dll
C:\Windows\System32\slwga.dll
C:\Windows\System32\slcext.dllThis file does not have a program associated with it for performing this action. Please install a program or if one is already installed create an association in the default programs control panel
The system cannot execute the specified programTuesday, May 1, 2012 5:40 PM -
"npuranik" wrote in message news:84d30bdd-a13f-419e-bdc4-deb579f02b02...
Hi
The first command was successful
C:\Windows\System32\sppwmi.dll
Please follow the instructions at the bottom of my post - and try again.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, May 1, 2012 5:47 PMModerator -
Hi
Followed instrction exactly and output below
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.C:\Windows\system32>ICACLS C:\Windows\System32\sppwmi.dll
C:\Windows\System32\sppwmi.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\sppc.dll
C:\Windows\System32\sppc.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\slwga.dll
C:\Windows\System32\slwga.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\slcext.dll
C:\Windows\System32\slcext.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>
Tuesday, May 1, 2012 5:54 PM -
"npuranik" wrote in message news:5fb3f6d2-92f9-4057-9d8f-69cca2de419e...
Hi
Followed instrction exactly and output below
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.C:\Windows\system32>ICACLS C:\Windows\System32\sppwmi.dll
C:\Windows\System32\sppwmi.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\sppc.dll
C:\Windows\System32\sppc.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\slwga.dll
C:\Windows\System32\slwga.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\System32\slcext.dll
C:\Windows\System32\slcext.dll NT SERVICE\TrustedInstaller:(F)
BUILTIN\Administrators:(RX)
NT AUTHORITY\SYSTEM:(RX)
BUILTIN\Users:(RX)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>
That's better :)Unfortunately, all the results are as they should be - which means that the problem lies elsewhere.please run the following commandsREG QUERY HKUREG QUERY HKU\S-1-5-20REG QUERY HKU\S-1-5-20\EnvironmentREG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"ICACLS C:\Windows\ServiceProfiles\NetworkServiceICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DATDIR C:\Windows\ServiceProfiles\NetworkService /asDIR C:\Windows\ServiceProfiles\NetworkService /ahpost the results as before.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, May 1, 2012 7:01 PMModerator -
Hi,
Here is the output.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.C:\Windows\system32>REG QUERY HKU
HKEY_USERS\.DEFAULT
HKEY_USERS\S-1-5-19
HKEY_USERS\S-1-5-20
HKEY_USERS\S-1-5-21-2261197669-1845000155-2889548959-1000
HKEY_USERS\S-1-5-21-2261197669-1845000155-2889548959-1000_Classes
HKEY_USERS\S-1-5-18C:\Windows\system32>REG QUERY HKU\S-1-5-20
HKEY_USERS\S-1-5-20\AppEvents
HKEY_USERS\S-1-5-20\Console
HKEY_USERS\S-1-5-20\Control Panel
HKEY_USERS\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\EUDC
HKEY_USERS\S-1-5-20\Keyboard Layout
HKEY_USERS\S-1-5-20\Network
HKEY_USERS\S-1-5-20\Printers
HKEY_USERS\S-1-5-20\Software
HKEY_USERS\S-1-5-20\SystemC:\Windows\system32>REG QUERY HKU\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\Environment
TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp
C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\ProfileList\S-1-5-20"
ERROR: The system was unable to find the specified registry key or value.C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService
C:\Windows\ServiceProfiles\NetworkService NT AUTHORITY\SYSTEM:(OI)(CI)(F)
BUILTIN\Administrators:(OI)(CI)(F)
NT AUTHORITY\NETWORK SERVICE:(OI)(CI)(
F)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>ICACLS C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT NT AUTHORITY\SYSTEM:(I)(F)
BUILTIN\Administrators:(I)(
F)
NT AUTHORITY\NETWORK SERVIC
E:(I)(F)Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService /as
Volume in drive C has no label.
Volume Serial Number is BC4C-8964Directory of C:\Windows\ServiceProfiles\NetworkService
05/02/2012 12:02 AM 524,288 NTUSER.DAT
07/14/2009 10:31 AM 65,536 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TM.blf
07/14/2009 10:31 AM 524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TMContainer00000000000000000001.regtrans-ms
07/14/2009 10:31 AM 524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TMContainer00000000000000000002.regtrans-ms
04/12/2012 12:04 PM 65,536 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TM.blf
04/12/2012 12:04 PM 524,288 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
04/12/2012 12:04 PM 524,288 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
06/30/2011 10:30 PM 65,536 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TM.blf
06/30/2011 10:30 PM 524,288 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
06/30/2011 10:30 PM 524,288 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
10 File(s) 3,866,624 bytes
0 Dir(s) 6,857,846,784 bytes freeC:\Windows\system32>DIR C:\Windows\ServiceProfiles\NetworkService /ah
Volume in drive C has no label.
Volume Serial Number is BC4C-8964Directory of C:\Windows\ServiceProfiles\NetworkService
07/14/2009 10:15 AM <DIR> AppData
05/02/2012 12:02 AM 524,288 NTUSER.DAT
07/14/2009 12:42 PM 1,024 NTUSER.DAT.LOG
05/02/2012 12:02 AM 226,304 NTUSER.DAT.LOG1
07/14/2009 10:15 AM 0 NTUSER.DAT.LOG2
07/14/2009 10:31 AM 65,536 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TM.blf
07/14/2009 10:31 AM 524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TMContainer00000000000000000001.regtrans-ms
07/14/2009 10:31 AM 524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0b
cde3ec}.TMContainer00000000000000000002.regtrans-ms
04/12/2012 12:04 PM 65,536 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TM.blf
04/12/2012 12:04 PM 524,288 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
04/12/2012 12:04 PM 524,288 NTUSER.DAT{896d5574-8466-11e1-80a2-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
06/30/2011 10:30 PM 65,536 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TM.blf
06/30/2011 10:30 PM 524,288 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TMContainer00000000000000000001.regtrans-ms
06/30/2011 10:30 PM 524,288 NTUSER.DAT{9eb63065-a2e7-11e0-b930-806e6f
6e6963}.TMContainer00000000000000000002.regtrans-ms
13 File(s) 4,093,952 bytes
1 Dir(s) 6,857,846,784 bytes freeC:\Windows\system32>
Tuesday, May 1, 2012 7:44 PM -
"npuranik" wrote in message news:4782c2af-8937-4442-9e76-6c3ffeba0831...
C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20"
ERROR: The system was unable to find the specified registry key or value.C:\Windows\system32>
Seems to be my lucky day! - I wasn't expecting to find anything that quick :)let's see how widespread the problem is....please run the following command, and post the results.REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" /S
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, May 1, 2012 7:59 PMModerator -
As mentioned in the beginning of the thread this problem started when using regedit i deleted the entries other than the ones which had the usernames created by me.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.C:\Windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\ProfileList" /SHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users
Default REG_EXPAND_SZ %SystemDrive%\Users\Default
Public REG_EXPAND_SZ %SystemDrive%\Users\Public
ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramDataHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-2261197669-1845000155-2889548959-1000
ProfileImagePath REG_EXPAND_SZ C:\Users\Nirmal Puranik
Flags REG_DWORD 0x0
State REG_DWORD 0x0
Sid REG_BINARY 0105000000000005150000006523C786DB77F86D9F043BACE803000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x4
RunLogonScriptSync REG_DWORD 0x0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-2261197669-1845000155-2889548959-1002
ProfileImagePath REG_EXPAND_SZ C:\Users\Abhinav Puranik
Flags REG_DWORD 0x0
State REG_DWORD 0x0
Sid REG_BINARY 0105000000000005150000006523C786DB77F86D9F043BACEA03000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-2261197669-1845000155-2889548959-1003
ProfileImagePath REG_EXPAND_SZ C:\Users\Ragini Puranik
Flags REG_DWORD 0x0
State REG_DWORD 0x0
Sid REG_BINARY 0105000000000005150000006523C786DB77F86D9F043BACEB03000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
5-21-2261197669-1845000155-2889548959-1004
ProfileImagePath REG_EXPAND_SZ C:\Users\Mohan Puranik
Flags REG_DWORD 0x0
State REG_DWORD 0x0
Sid REG_BINARY 0105000000000005150000006523C786DB77F86D9F043BACEC03000
0
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
C:\Windows\system32>Wednesday, May 2, 2012 2:12 AM -
"npuranik" wrote in message news:2c71b98e-cbfa-45a2-b579-60de68c41f20...
As mentioned in the beginning of the thread this problem started when using regedit i deleted the entries other than the ones which had the usernames created by me.
C:\Windows\system32>That was a rather inept thing to do - there are at least three accounts present on ALL computers which are required by the system for it to work anything like normally - the System account, the Local Service account, and the Network Service account.If they are not properly referenced in the registry, the results will be unpredictable at best, and unbootable at worst.If you've deleted the same data elsewhere in the registry, then we may as well give up now, and do a reinstall.If it's only in this registry area then the damage may be limited.I've posted a zip file - Profilelist.zip - here https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21115Please download the file and extract the ProfileListservices.reg file it contains to your desktop.right-click n the extracted file, and select Merge - you should get a UAC prompt, which you accept, and then a 'Succeeded' message.Once complete, reboot, and run a new MGADiag report.Please in future refrain from making registry edits unless you know EXACTLY what you are doing, and why - and do NOT be tempted into using 'Registry Cleaners' or 'Optimisers' - they are all prone to the same sort of error as you just made.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth- Marked as answer by npuranik Wednesday, May 2, 2012 1:53 PM
Wednesday, May 2, 2012 8:17 AMModerator -
Hi Noel,
Thanks a lot for your help this seems to have solved the problem, the message saying that the windows is not genuine has gone away and also the internet explorer is back in use :-)
I have run the MGADiag again after rebooting as advised by you - attached below is the output.
Thanks once again
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-GXJV7-J3WK3-2PTTR
Windows Product Key Hash: YImG6RHyK34nxtkD8vVw6zvInqA=
Windows Product ID: 00359-001-0115034-85179
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {451139EA-9FE2-43CD-A42D-362CF76B4802}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/AVista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{451139EA-9FE2-43CD-A42D-362CF76B4802}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-2PTTR</PKey><PID>00359-001-0115034-85179</PID><PIDType>5</PIDType><SID>S-1-5-21-2261197669-1845000155-2889548959</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DH61WW__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>BEH6110H.86A.0016.2011.0118.1128</Version><SMBIOSVersion major="2" minor="6"/><Date>20110118000000.000000+000</Date></BIOS><HWID>0A5A3E07018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>India Standard Time(GMT+05:30)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>229CFB503293F6E</Val><Hash>y2u4KPJDYMCt6/uK8a0V7Bk8llc=</Hash><Pid>81602-951-2894714-68595</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, RETAIL channel
Activation ID: 2e7d060d-4714-40f2-9896-1e4f15b612ad
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00170-001-011503-00-1033-7600.0000-1552011
Installation ID: 009130996294056334721523171863588873267274566896118821
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: 2PTTR
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 5/2/2012 7:19:29 PMWindows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 3:4:2012 15:40
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
HWID Data-->
HWID Hash Current: MAAAAAEAAgABAAEAAAACAAAAAgABAAEAln0U/6gYbFV86aIBwFxqx4NKeKamaC5zOEM Activation 1.0 Data-->
N/AOEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC INTEL DH61WW
FACP INTEL DH61WW
HPET INTEL DH61WW
MCFG INTEL DH61WW
SSDT INTEL DH61WWWednesday, May 2, 2012 1:53 PM -
That looks OK now - you should check it by going to the validation site at www.microsoft.com/genuine/validate
It should pass - in which case, you'll be offered MSE and IE9 (you don't have to take them)
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
Wednesday, May 2, 2012 2:04 PMModerator -
It Passed :-)
I am already on IE 9 - Thanks for all the help.
Wednesday, May 2, 2012 2:41 PM -
"npuranik" wrote in message news:98373c3f-60d1-455c-ba77-6db3c9395f33...
It Passed :-)
I am already on IE 9 - Thanks for all the help.
Glad to hear it - now steer clear of the registry :)Good luck!
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothWednesday, May 2, 2012 2:45 PMModerator