locked
Windows Activation/Validation Errors RRS feed

  • Question

  • The last week or so I have gotten  the Activation Technologies "Not Running Genuine Windows" pop-up message.  However, I can then go to START->Activate Windows and it says that Windows Activation was successful.  I purchased this version of Windows as a student from IT so it should be genuine.  I researched this problem here and have already deleted/cleared the Key whatever via DOS prompt and Re-validated on the phone.  The NEXT DAY Windows is telling me I'm not Genuine.   Please Help!

    Thanks in Advance;

    John

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE22
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-XBKQ2-KVTXV-4RT8W
    Windows Product Key Hash: 9KF+9g9VlcsO3/ih+WbCJIYBoCE=
    Windows Product ID: 00371-169-3423504-85757
    Windows Product ID Type: 5
    Windows License Type: Retail
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {5B96184D-FF52-441B-A03F-3D04F7F280E9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Enterprise 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Chef-Rewdi\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{5B96184D-FF52-441B-A03F-3D04F7F280E9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4RT8W</PKey><PID>00371-169-3423504-85757</PID><PIDType>5</PIDType><SID>S-1-5-21-749968623-584497727-1144849823</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7696</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V1.5</Version><SMBIOSVersion major="2" minor="7"/><Date>20111222000000.000000+000</Date></BIOS><HWID>2C223607018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>AF30636FF969F12</Val><Hash>eQ6Fi8Wt041ER/GAC7edCPIHhFo=</Hash><Pid>81599-905-7384767-65881</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, RETAIL channel
    Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00170-169-342350-01-1033-7601.0000-3072012
    Installation ID: 010141638236583426032920371763450835832965851330911924
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 4RT8W
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/5/2012 7:13:52 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE22
    HrOnline: N/A
    HealthStatus: 0x0000000000004000
    Event Time Stamp: 11:4:2012 12:56
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui


    HWID Data-->
    HWID Hash Current: OAAAAAEABAABAAQAAAACAAAAAQABAAEAHKKYlQx1XiS0+O77btZ6XtrXznAGfJBQYj1q/p5YAGo=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ALASKA A M I
      FACP ALASKA A M I
      HPET ALASKA A M I
      MCFG A M I GMCH945.
      SSDT AMD   POWERNOW
      SSDT AMD   POWERNOW
      BGRT ALASKA A M I

    Tuesday, November 6, 2012 12:22 AM

Answers

  • I've uploaded a file - rewdi.zip - to my SkyDrive at https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21526

    Please download and save it.

    right-click on the saved file and select Extract all...

    Change the target to C:\  and click on Extract

    This should create a folder C:\rewdi

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start tapping F8 - this should bring up the Advanced Boot Menu, at the top of which should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

     

    At the prompt type 

    DIR C:\rewdi

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\rewdi

    or

    DIR E:\rewdi

     

    The drive letter in use when you find the folder will need to be substituted (for <drive>)  into the following command...

     

    XCOPY <drive>:\rewdi <drive>:\windows\winsxs /y /i /s /v /h

     

    run the command (it should take almost no time)and when the prompt return, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

     

    Now run SFC /SCANNOW in an Elevated Command Prompt

     

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

     

    Also run a new MGADiag report, and post the result.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, November 10, 2012 7:57 PM
    Moderator
  • I've uploaded a file - rewdi2.zip - to my SkyDrive at https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21526

    Please download and save it.

    right-click on the saved file and select Extract all...

    Change the target to C:\rewdi2  and click on Extract

    This should create a folder C:\rewdi2

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start tapping F8 - this should bring up the Advanced Boot Menu, at the top of which should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

    At the prompt type

    DIR C:\rewdi2

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\rewdi2

    or

    DIR E:\rewdi2

    The drive letter in use when you find the folder will need to be substituted (for<drive>)  into the following command...

    XCOPY <drive>:\rewdi2 <drive>:\windows\winsxs /y /i /s /v /h

    run the command (it should take almost no time)and when the prompt return, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

    Now run SFC /SCANNOW in an Elevated Command Prompt

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

    Also run a new MGADiag report, and post the result (just in case!)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, November 11, 2012 1:00 PM
    Moderator

All replies

  • Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui

     

    Please run a full CHKDSK and SFC scan....

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     

     At the Command prompt, type

     CHKDSK C: /R

     and hit the Enter key.

     

     You will be told that the drive is locked,

     and the CHKDSK will run at he next boot - hit the Y key, and then reboot.

     The CHKDSK will take a few hours depending on the size  of the drive, so be patient!

     After the CHKDSK has run, Windows should boot normally  (possibly after a second auto-reboot) -

     

    then run the SFC.

     

     SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     At the Command prompt, type

     SFC /SCANNOW

     and hit the Enter key

     

     Wait for the scan to finish - make a note of any error messages - and then reboot.

     Copy the CBS.log file created to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive (http://skydrive.live.com ) and post a link to it so that I can take a look.

     

    Post a new MGADiag report with details of any error messages encountered.     


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Tuesday, November 6, 2012 8:28 AM
    Moderator
  • Thanks for your help and the speedyou answered too!

    Ok, ran CHKDSK and it re-indexed (I think) a bunch of files - otherwise ok.

    SFC completed w/ error: "Windows Resource Protection found corrupt files but was unable to fix some of them."

    CBS log file as follows:  ... um, after 3 tries I finally was able to paste it to this post.  Then I got a website error saying that a post has to be between 4-60000 characters.  How big is this report?  OH!  I just pasted it into Word and it's 1,044 pages with 194,757 words.  That could be a problem.

    Is there a specific part you need (either by report line number or some searchable text from the beginning of the line so I can pull it)?

    Thursday, November 8, 2012 12:31 AM
  • I asked you to upload the file to your SkyDrive Public folder (you can use any other fileshare service you like as well) - you cannot post large files to the forums.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Thursday, November 8, 2012 12:04 PM
    Moderator
  • Hmm - the CBS log only started at 18:18 on the 8th - which means that the data we need has been archived into the most recent CBSPersist cab file (in the same folder).

    Please upload that and I'll take a look.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, November 9, 2012 9:42 AM
    Moderator
  • Ok, Done.   Thanks again!
    Friday, November 9, 2012 12:46 PM
  • I can't access either that or the original file now? You may simply need to move it to your Public folder.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, November 9, 2012 1:04 PM
    Moderator
  • I deleted what was there (said it was in the share folder) and re-uploaded both original file and CBSPersist file.
    Friday, November 9, 2012 1:19 PM
  • Nope - still getting an error. Please post a new link.

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, November 9, 2012 1:22 PM
    Moderator
  • New link: https://skydrive.live.com/redir?resid=6984AFA47B750571!139
    Saturday, November 10, 2012 1:53 AM
  • Line 14379: 2012-11-08 07:16:58, Info                  CSI    0000000c [SR] Cannot repair member file [l:36{18}]"sppcommdlg.dll.mui" of Microsoft-Windows-Security-SPP-UX.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch 
    Line 14382: 2012-11-08 07:16:58, Info                  CSI    0000000e [SR] Cannot repair member file [l:36{18}]"sppcommdlg.dll.mui" of Microsoft-Windows-Security-SPP-UX.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch 
    Line 14383: 2012-11-08 07:16:58, Info                  CSI    0000000f [SR] This component was referenced by [l:266{133}]"Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.Windows Foundation Language Pack" 
    Line 14388: 2012-11-08 07:16:58, Info                  CSI    00000012 [SR] Could not reproject corrupted file [ml:60{30},l:58{29}]"\??\C:\Windows\SysWOW64\en-US"\[l:36{18}]"sppcommdlg.dll.mui"; source file in store is also corrupted

    That's better :)

    we now know that the winsxs store copy of the file is also corrupted, from the error messages above.

    There may be more corruption that the system hasn't sportted yet, so let's run the CheckSUR tool as a doublecheck before attemtpting to fix the known problem....

    Please run the CheckSUR tool from http://support.microsoft.com/kb/947821

    (you'll need to look in the details for Method 2)

     

    Then zip the CheckSUR.log and upload it to your public SkyDrive so I can take a look - post a link in your reply.

     

    The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on
    how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, November 10, 2012 8:59 AM
    Moderator
  • Here's the link:  https://skydrive.live.com/redir?resid=6984AFA47B750571!149
    Saturday, November 10, 2012 1:32 PM
  • Checking Component Store
    (f)	CSI Payload File Missing	0x00000000	msado20.tlb	amd64_microsoft-windows-m..do-backcompat-tlb20_31bf3856ad364e35_6.1.7601.17857_none_4914f84208d3047d	
    (f)	CSI Payload File Missing	0x00000000	sspicli.dll	amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.17035_none_02756f8b7653d554	
    (f)	CSI Payload File Missing	0x00000000	sspicli.dll	amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16915_none_028b374176436a30	
    

    are the critical points....

    It'll take me a while to craft a repair on these - please shout if you haven't heard anything by this time tomorrow.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, November 10, 2012 4:13 PM
    Moderator
  • Awesome, thanks!
    Saturday, November 10, 2012 6:11 PM
  • I've uploaded a file - rewdi.zip - to my SkyDrive at https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21526

    Please download and save it.

    right-click on the saved file and select Extract all...

    Change the target to C:\  and click on Extract

    This should create a folder C:\rewdi

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start tapping F8 - this should bring up the Advanced Boot Menu, at the top of which should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

     

    At the prompt type 

    DIR C:\rewdi

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\rewdi

    or

    DIR E:\rewdi

     

    The drive letter in use when you find the folder will need to be substituted (for <drive>)  into the following command...

     

    XCOPY <drive>:\rewdi <drive>:\windows\winsxs /y /i /s /v /h

     

    run the command (it should take almost no time)and when the prompt return, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

     

    Now run SFC /SCANNOW in an Elevated Command Prompt

     

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

     

    Also run a new MGADiag report, and post the result.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, November 10, 2012 7:57 PM
    Moderator
  • Ok, Done.  New MGA is below and link for new Skydrive reports is here: https://skydrive.live.com/redir?resid=6984AFA47B750571!154

    The SFC did end by saying there were still unrepairable files like last time.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-XBKQ2-KVTXV-4RT8W
    Windows Product Key Hash: 9KF+9g9VlcsO3/ih+WbCJIYBoCE=
    Windows Product ID: 00371-169-3423504-85757
    Windows Product ID Type: 5
    Windows License Type: Retail
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {5B96184D-FF52-441B-A03F-3D04F7F280E9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Enterprise 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Chef-Rewdi\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{5B96184D-FF52-441B-A03F-3D04F7F280E9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4RT8W</PKey><PID>00371-169-3423504-85757</PID><PIDType>5</PIDType><SID>S-1-5-21-749968623-584497727-1144849823</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7696</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V1.5</Version><SMBIOSVersion major="2" minor="7"/><Date>20111222000000.000000+000</Date></BIOS><HWID>2C223607018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>AF30636FF969F12</Val><Hash>eQ6Fi8Wt041ER/GAC7edCPIHhFo=</Hash><Pid>81599-905-7384767-65881</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, RETAIL channel
    Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00170-169-342350-01-1033-7601.0000-3072012
    Installation ID: 010141638236583426032920371763450835832965851330911924
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 4RT8W
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/10/2012 10:26:08 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 11:10:2012 22:18
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: OAAAAAEABAABAAQAAAACAAAAAQABAAEAHKKYlQx1XiS0+O77btZ6XtrXznAGfJBQYj1q/p5YAGo=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ALASKA A M I
      FACP ALASKA A M I
      HPET ALASKA A M I
      MCFG A M I GMCH945.
      SSDT AMD   POWERNOW
      SSDT AMD   POWERNOW
      BGRT ALASKA A M I

    Sunday, November 11, 2012 3:27 AM
  • The report looks a lot healthier anyhow - are you still seeing non-genuine notices?

    2012-11-10 22:18:21, Info                  CSI    000002fa [SR] Repairing 2 components
    2012-11-10 22:18:21, Info                  CSI    000002fb [SR] Beginning Verify and Repair transaction
    2012-11-10 22:18:21, Info                  CSI    000002fc Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-utilman_31bf3856ad364e35_6.1.7600.16385_none_5e9ea1964aee5579\Utilman.exe do not match actual file [l:22{11}]"Utilman.exe" :
      Found: {l:32 b:uIQByfDPmWEBNdy7mn/NVEo7+V5qsbDP6DSZnYvDenk=} Expected: {l:32 b:fKkGFuaLyFHxRlijZtgPId23p92KhmBJ5UZRFYeEqeo=}
    2012-11-10 22:18:21, Info                  CSI    000002fd [SR] Cannot repair member file [l:22{11}]"Utilman.exe" of Microsoft-Windows-UtilMan, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2012-11-10 22:18:21, Info                  CSI    000002fe Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-utilman_31bf3856ad364e35_6.1.7600.16385_none_5e9ea1964aee5579\Utilman.exe do not match actual file [l:22{11}]"Utilman.exe" :
      Found: {l:32 b:uIQByfDPmWEBNdy7mn/NVEo7+V5qsbDP6DSZnYvDenk=} Expected: {l:32 b:fKkGFuaLyFHxRlijZtgPId23p92KhmBJ5UZRFYeEqeo=}
    2012-11-10 22:18:21, Info                  CSI    000002ff [SR] Cannot repair member file [l:22{11}]"Utilman.exe" of Microsoft-Windows-UtilMan, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2012-11-10 22:18:21, Info                  CSI    00000300 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
    2012-11-10 22:18:21, Info                  CSI    00000301 Hashes for file member \??\C:\Windows\System32\Utilman.exe do not match actual file [l:22{11}]"Utilman.exe" :
      Found: {l:32 b:uIQByfDPmWEBNdy7mn/NVEo7+V5qsbDP6DSZnYvDenk=} Expected: {l:32 b:fKkGFuaLyFHxRlijZtgPId23p92KhmBJ5UZRFYeEqeo=}
    2012-11-10 22:18:21, Info                  CSI    00000302 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-utilman_31bf3856ad364e35_6.1.7600.16385_none_5e9ea1964aee5579\Utilman.exe do not match actual file [l:22{11}]"Utilman.exe" :
      Found: {l:32 b:uIQByfDPmWEBNdy7mn/NVEo7+V5qsbDP6DSZnYvDenk=} Expected: {l:32 b:fKkGFuaLyFHxRlijZtgPId23p92KhmBJ5UZRFYeEqeo=}
    2012-11-10 22:18:21, Info                  CSI    00000303 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"Utilman.exe"; source file in store is also corrupted
    2012-11-10 22:18:21, Info                  CSI    00000304 [SR] Repairing corrupted file [ml:520{260},l:88{44}]"\??\C:\Program Files\Common Files\System\ado"\[l:22{11}]"msado20.tlb" from store
    2012-11-10 22:18:21, Info                  CSI    00000305 Repair results created:
    POQ 125 ends.
    2012-11-10 22:18:21, Info                  CSI    00000306 [SR] Repair complete
    

    ...is not as bad as it looks - there's only one more file that needs repair.

    I'll work on that during the day :)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, November 11, 2012 11:16 AM
    Moderator
  • Actually, no... or not yet.  I did the fixes, posted back and shut down for the night.  I don't see one popping up now though.  Yay!

    Thanks again for your help.

    Sunday, November 11, 2012 12:15 PM
  • I've uploaded a file - rewdi2.zip - to my SkyDrive at https://skydrive.live.com/#cid=936736BB8FCEB92F&id=936736BB8FCEB92F%21526

    Please download and save it.

    right-click on the saved file and select Extract all...

    Change the target to C:\rewdi2  and click on Extract

    This should create a folder C:\rewdi2

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start tapping F8 - this should bring up the Advanced Boot Menu, at the top of which should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

    At the prompt type

    DIR C:\rewdi2

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\rewdi2

    or

    DIR E:\rewdi2

    The drive letter in use when you find the folder will need to be substituted (for<drive>)  into the following command...

    XCOPY <drive>:\rewdi2 <drive>:\windows\winsxs /y /i /s /v /h

    run the command (it should take almost no time)and when the prompt return, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

    Now run SFC /SCANNOW in an Elevated Command Prompt

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

    Also run a new MGADiag report, and post the result (just in case!)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, November 11, 2012 1:00 PM
    Moderator
  • OK.  So the SFC reported No Integrity Violations.  The new Skydrive link and MGADiag report are below: 

    https://skydrive.live.com/redir?resid=6984AFA47B750571!155

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-XBKQ2-KVTXV-4RT8W
    Windows Product Key Hash: 9KF+9g9VlcsO3/ih+WbCJIYBoCE=
    Windows Product ID: 00371-169-3423504-85757
    Windows Product ID Type: 5
    Windows License Type: Retail
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {5B96184D-FF52-441B-A03F-3D04F7F280E9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Enterprise 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Chef-Rewdi\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{5B96184D-FF52-441B-A03F-3D04F7F280E9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4RT8W</PKey><PID>00371-169-3423504-85757</PID><PIDType>5</PIDType><SID>S-1-5-21-749968623-584497727-1144849823</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7696</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V1.5</Version><SMBIOSVersion major="2" minor="7"/><Date>20111222000000.000000+000</Date></BIOS><HWID>2C223607018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>AF30636FF969F12</Val><Hash>eQ6Fi8Wt041ER/GAC7edCPIHhFo=</Hash><Pid>81599-905-7384767-65881</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, RETAIL channel
    Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00170-169-342350-01-1033-7601.0000-3072012
    Installation ID: 010141638236583426032920371763450835832965851330911924
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 4RT8W
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/12/2012 7:48:51 AM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 11:11:2012 07:13
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: OAAAAAEABAABAAQAAAACAAAAAQABAAEAHKKYlQx1XiS0+O77btZ6XtrXznAGfJBQYj1q/p5YAGo=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC ALASKA A M I
      FACP ALASKA A M I
      HPET ALASKA A M I
      MCFG A M I GMCH945.
      SSDT AMD   POWERNOW
      SSDT AMD   POWERNOW
      BGRT ALASKA A M I

    Monday, November 12, 2012 12:52 PM
  • Everything looks OK now - I think we can say you're cured :)

    If you have any other problems, you should probably post in the Answers forums - http://answers.microsoft.com/

    Good luck!


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Monday, November 12, 2012 5:04 PM
    Moderator