locked
Windows all of sudden is telling me it is not genuine, I had the computer for almost a year, purchased from lenovo RRS feed

  • Question

  • I downloaded the MS genuine advantage diagnostic tool (1.9.0027.0) from link in other replies from this forum. The tool runs and when complete the Window tab if opened and the following information is shown:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-MV8MH-98QJM-24367
    Windows Product Key Hash: wgci5Gdejx4esg7++zTOe3LWF+4=
    Windows Product ID: 00371-OEM-8992671-00437
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {54C942A1-FAEF-4412-8760-FF04AB486C6A}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\sppc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{54C942A1-FAEF-4412-8760-FF04AB486C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-24367</PKey><PID>00371-OEM-8992671-00437</PID><PIDType>2</PIDType><SID>S-1-5-21-1314044117-754041802-2465433324</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>2359CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>G4ET96WW (2.56 )</Version><SMBIOSVersion major="2" minor="7"/><Date>20130912000000.000000+000</Date></BIOS><HWID>BAFB0300018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-G4   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 50e329f7-a5fa-46b2-85fd-f224e5da7764
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00178-926-700437-02-1033-7601.0000-0452013
    Installation ID: 019351008216127902307805808531609392714021024504749036
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 24367
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 11/26/2013 9:03:29 AM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000000E720
    Event Time Stamp: 11:25:2013 16:11
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: MgAAAAAAAQABAAIAAAACAAAABAABAAEAln1aFjxPZPS2o2YvcjpNwETmjH+4c2TSlmM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC LENOVO TP-G4   
      FACP LENOVO TP-G4   
      HPET LENOVO TP-G4   
      MCFG LENOVO TP-G4   
      SLIC LENOVO TP-G4   
      TCPA PTL LENOVO
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      ECDT LENOVO TP-G4   
      FPDT LENOVO TP-G4   
      ASF! LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      POAT LENOVO TP-G4   
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      UEFI LENOVO TP-G4   
      DBG2 LENOVO TP-G4   

    I also have licensed copies of MalwareBytes Anti-Malware and Kaspersky 2013 Anti-virus and full scans run clean.

    Can someone assist with fixing this issue. The laptop was pre-built with windows and at present I can't find the license code that came with it.

    Thank you,

    Mikek


    • Edited by MikeK2525 Tuesday, November 26, 2013 2:21 PM add more info
    Tuesday, November 26, 2013 2:16 PM

Answers

  • Hey Noel,

    I figured something had you tied up, glad you are better.

    The warning became very annoying and kept interfering with work demands, so yesterday I did a system restore to a point prior to when I thought the issue started,

    and all seems good now. Windows validates now on the MS site, so I think the problem is resolved. I had to re-install a couple things, but seem to be ok.

    Thanks for all the time you spent attempting to assist me, I appreciate it.

    Sunday, December 8, 2013 2:00 PM

All replies

  • Please run a full CHKDSK and SFC scan....

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    CHKDSK C: /R

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -

    then run the SFC.

    SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    SFC /SCANNOW

    and hit the Enter key

    Wait for the scan to finish - make a note of any error messages - and then reboot.

    Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive Public folder (http://skydrive.live.com ) and post a link to it so that I can take a look.

    Post a new MGADiag report with details of any error messages encountered.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, November 26, 2013 6:15 PM
    Moderator
  • CHKDSK C: /R all 5 stages were clean.

    SFC /SCANNOW showed this:

    C:\Windows\System32>sfc /SCANNOW

    Beginning system scan.  This process will take some time.

    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection found corrupt files but was unable to fix some of them.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
    C:\Windows\Logs\CBS\CBS.log

    CBS.log file compressed and can bee accessed at https://skydrive.live.com/redir?resid=693F9E14476594DD!107&authkey=!ACvuutKykAeI86o&ithint=folder%2c.zip

    New run MGADiag report is below:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-MV8MH-98QJM-24367
    Windows Product Key Hash: wgci5Gdejx4esg7++zTOe3LWF+4=
    Windows Product ID: 00371-OEM-8992671-00437
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {54C942A1-FAEF-4412-8760-FF04AB486C6A}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\sppc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{54C942A1-FAEF-4412-8760-FF04AB486C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-24367</PKey><PID>00371-OEM-8992671-00437</PID><PIDType>2</PIDType><SID>S-1-5-21-1314044117-754041802-2465433324</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>2359CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>G4ET96WW (2.56 )</Version><SMBIOSVersion major="2" minor="7"/><Date>20130912000000.000000+000</Date></BIOS><HWID>BAFB0300018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-G4   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 50e329f7-a5fa-46b2-85fd-f224e5da7764
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00178-926-700437-02-1033-7601.0000-0452013
    Installation ID: 002564701701581803511413754985005534875882454260483334
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 24367
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 11/26/2013 3:40:56 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000000E720
    Event Time Stamp: 11:25:2013 16:11
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: NAAAAAEAAQABAAIAAAACAAAABAABAAEAln1aFgPGPE9k9LajZi9yOk3AROaMf/KnZNKWYw==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC LENOVO TP-G4   
      FACP LENOVO TP-G4   
      HPET LENOVO TP-G4   
      MCFG LENOVO TP-G4   
      SLIC LENOVO TP-G4   
      TCPA PTL LENOVO
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      ECDT LENOVO TP-G4   
      FPDT LENOVO TP-G4   
      ASF! LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      POAT LENOVO TP-G4   
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      UEFI LENOVO TP-G4   
      DBG2 LENOVO TP-G4   

    Please advise.

    Thanks,

    MikeK

    Tuesday, November 26, 2013 8:43 PM
  • Here's the error set from the SFC scan...

    	Line 56312: 2013-11-26 15:24:27, Info                  CSI    00000320 [SR] Verify complete
    	Line 56313: 2013-11-26 15:24:27, Info                  CSI    00000321 [SR] Repairing 1 components
    	Line 56314: 2013-11-26 15:24:27, Info                  CSI    00000322 [SR] Beginning Verify and Repair transaction
    	Line 56317: 2013-11-26 15:24:27, Info                  CSI    00000324 [SR] Cannot repair member file [l:24{12}]"cryptext.dll" of Microsoft-Windows-cryptext-dll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 56320: 2013-11-26 15:24:27, Info                  CSI    00000326 [SR] Cannot repair member file [l:24{12}]"cryptext.dll" of Microsoft-Windows-cryptext-dll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 56321: 2013-11-26 15:24:27, Info                  CSI    00000327 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
    	Line 56326: 2013-11-26 15:24:27, Info                  CSI    0000032a [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:24{12}]"cryptext.dll"; source file in store is also corrupted
    	Line 56331: 2013-11-26 15:24:27, Info                  CSI    0000032c [SR] Repair complete
    

    Just the one file out of whack  - however, there are a lot of entries in the background which make me think that there are other problems as well.

    While I get the fix protocol for this file sorted out,

    Please download and save  the CheckSUR tool from http://support.microsoft.com/kb/947821

    (you'll need to look in the details for Windows 7, downloading from the Microsoft Download Center)

    Run it - The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.

    The result is logged in the C:\Windows\Logs\CBS\CheckSUR.log file  - and an archive …\checksur.persist.log file

    Then zip the CheckSUR.log and upload it to your SkyDrive Public folder so I can take a look - post a link in your reply.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, November 26, 2013 9:02 PM
    Moderator
  • I've uploaded a file - mk2aa.zip - to my SkyDrive at Noel's SkyDrive

    Please download and save it.

    Right-click on the saved file and select Extract all...

    Change the target to C:\ and click on Extract

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start
    tapping F8 - this should bring up the Advanced Boot Menu, at the top of which
    should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

    At the prompt type

    DIR C:\mk2aa

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\mk2aa

    or

    DIR E:\mk2aa

    The drive letter in use when you find the folder will need to be substituted (for<drive>) into the following
    command...

    XCOPY <drive>:\mk2aa  <drive>:\windows\winsxs /y /i /s /v /h

    (e.g. XCOPY P:\wfire P:\windows\winsxs /y /i /s /v /h )

    run the command (it should take almost no time)and when the prompt returns, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

    Now run SFC /SCANNOW in an Elevated Command Prompt

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

    Also run a new MGADiag report, and post the result.



    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, November 26, 2013 9:06 PM
    Moderator
  • I downloaded and ran the KB which ran 5 minutes or so,  and produced a 1KB CheckSUR.log file that contains this:


    =================================
    Checking System Update Readiness.
    Binary Version 6.1.7601.22471
    Package Version 22.0
    2013-11-26 18:27

    Checking Windows Servicing Packages

    Checking Package Manifests and Catalogs

    Checking Package Watchlist

    Checking Component Watchlist

    Checking Packages

    Checking Component Store

    Summary:
    Seconds executed: 250
     No errors detected

    Tuesday, November 26, 2013 11:37 PM
  • I am a little new, or very new to the SkyDrive usage and not sure how to get to your SkyDrive for the file.

    Is this file a fix for the issue?

    Thanks,

    MikeK

    Tuesday, November 26, 2013 11:42 PM
  • At least that's clear :)

    Just click on the link in my last post - or this one.... Noel's SkyDrive  - to access my SkyDrive


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, November 27, 2013 7:39 AM
    Moderator
  • Hi,

    I did the xcopy under the repair environment and rebooted. Then ran the scannow:

    C:\Windows\System32>SFC /SCANNOW

    Beginning system scan.  This process will take some time.

    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection found corrupt files but was unable to fix some of th
    em.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
    C:\Windows\Logs\CBS\CBS.log

    rebooted and zipped the CBS log to CBS1.zip located at this link:

    https://skydrive.live.com/redir?resid=693F9E14476594DD!109&authkey=!ABmyMPScP2-bSHI&ithint=file%2c.zip

    below is the new MGADiag report:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-MV8MH-98QJM-24367
    Windows Product Key Hash: wgci5Gdejx4esg7++zTOe3LWF+4=
    Windows Product ID: 00371-OEM-8992671-00437
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {54C942A1-FAEF-4412-8760-FF04AB486C6A}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\sppc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{54C942A1-FAEF-4412-8760-FF04AB486C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-24367</PKey><PID>00371-OEM-8992671-00437</PID><PIDType>2</PIDType><SID>S-1-5-21-1314044117-754041802-2465433324</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>2359CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>G4ET96WW (2.56 )</Version><SMBIOSVersion major="2" minor="7"/><Date>20130912000000.000000+000</Date></BIOS><HWID>BAFB0300018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-G4   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 50e329f7-a5fa-46b2-85fd-f224e5da7764
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00178-926-700437-02-1033-7601.0000-0452013
    Installation ID: 002564701701581803511413754985005534875882454260483334
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 24367
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 11/27/2013 9:18:03 AM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000000E720
    Event Time Stamp: 11:25:2013 16:11
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: NAAAAAEAAQABAAIAAAACAAAABAABAAEAln1aFgPGPE9k9LajZi9yOk3AROaMf/ImZNKWYw==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC LENOVO TP-G4   
      FACP LENOVO TP-G4   
      HPET LENOVO TP-G4   
      MCFG LENOVO TP-G4   
      SLIC LENOVO TP-G4   
      TCPA PTL LENOVO
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      ECDT LENOVO TP-G4   
      FPDT LENOVO TP-G4   
      ASF! LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      POAT LENOVO TP-G4   
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      UEFI LENOVO TP-G4   
      DBG2 LENOVO TP-G4   

    Thanks,

    MikeK

    Wednesday, November 27, 2013 2:23 PM
  • I must be losing my touch - you're the second person today who's had problems with this procedure.

    Please run the following commands, and we'll see if we can work out what went wrong.

    DIR C:\Windows\winsxs\mk2aa

    DIR C:\mk2aa

    What drive letter did you use for the xcopy command?


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, November 27, 2013 3:17 PM
    Moderator
  • While in repair mode, It was on D: and that is the drive I used and the xcopy said it copied 2 files, I think.

    When I run DIR C:\mk2aa from normal windows, it shows:

    C:\Windows\System32>dir C:\mk2aa
     Volume in drive C is Windows7_OS
     Volume Serial Number is C0C8-C11D

     Directory of C:\mk2aa

    11/27/2013  08:44 AM    <DIR>          .
    11/27/2013  08:44 AM    <DIR>          ..
    11/27/2013  08:43 AM    <DIR>          mk2aa
    11/27/2013  08:42 AM            28,689 mk2aa.zip
                   1 File(s)         28,689 bytes
                   3 Dir(s)  225,121,492,992 bytes free

    it finds nothing in c:\Windows\winsxs\mk2aa

    i'll bet I shouldn't have created the mk2aa folder off the root of C:, right?

    Should I remove the top mk2aa folder and extract the zip again and then try your procedure again?

    Wednesday, November 27, 2013 4:15 PM
  • I did what I said in my last reply, removed the mk2aa folder and extracted the zip again, this time only the amd64 folder and one file .dll under it.

    I rebooted into repair mode and again it found the mk2aa folder on D:

    I did the xcopy with all the specified switches:

    xcopy d:\mk2aa D:\windows\winsxs /y /i /s /v /h

    it said 1 file copied. It appears to have copied the dll into the AMD64... folder

    I rebooted into normal windows and ran the SFC /SCANNOW

    C:\Windows\System32>SFC /SCANNOW

    Beginning system scan.  This process will take some time.

    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection found corrupt files but was unable to fix some of th
    em.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
    C:\Windows\Logs\CBS\CBS.log

    rebooted and zipped the cbs.log in cbs2.zip which is at this link:

    https://skydrive.live.com/redir?resid=693F9E14476594DD!110&authkey=!AIR-SCBuGwm7ATU&ithint=file%2c.zip

    reran the MGADiag tool, results below:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-MV8MH-98QJM-24367
    Windows Product Key Hash: wgci5Gdejx4esg7++zTOe3LWF+4=
    Windows Product ID: 00371-OEM-8992671-00437
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {54C942A1-FAEF-4412-8760-FF04AB486C6A}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\sppc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{54C942A1-FAEF-4412-8760-FF04AB486C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-24367</PKey><PID>00371-OEM-8992671-00437</PID><PIDType>2</PIDType><SID>S-1-5-21-1314044117-754041802-2465433324</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>2359CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>G4ET96WW (2.56 )</Version><SMBIOSVersion major="2" minor="7"/><Date>20130912000000.000000+000</Date></BIOS><HWID>BAFB0300018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-G4   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 50e329f7-a5fa-46b2-85fd-f224e5da7764
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00178-926-700437-02-1033-7601.0000-0452013
    Installation ID: 002564701701581803511413754985005534875882454260483334
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 24367
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 11/27/2013 11:57:42 AM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000000E720
    Event Time Stamp: 11:25:2013 16:11
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: NAAAAAEAAQABAAIAAAACAAAABAABAAEAln1aFgPGPE9k9LajZi9yOk3AROaMf5w+ZNKWYw==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC LENOVO TP-G4   
      FACP LENOVO TP-G4   
      HPET LENOVO TP-G4   
      MCFG LENOVO TP-G4   
      SLIC LENOVO TP-G4   
      TCPA PTL LENOVO
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      ECDT LENOVO TP-G4   
      FPDT LENOVO TP-G4   
      ASF! LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      UEFI LENOVO TP-G4   
      POAT LENOVO TP-G4   
      SSDT LENOVO TP-SSDT2
      SSDT LENOVO TP-SSDT2
      UEFI LENOVO TP-G4   
      DBG2 LENOVO TP-G4   

    Wednesday, November 27, 2013 4:58 PM
  • Please run the following commands again and post the results - wait for my response before doing anything else with them, please

    DIR C:\Windows\winsxs\mk2aa

    DIR C:\mk2aa


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, November 27, 2013 5:01 PM
    Moderator
  • Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\System32>dir C:\Windows\winsxs\mk2aa
     Volume in drive C is Windows7_OS
     Volume Serial Number is C0C8-C11D

     Directory of C:\Windows\winsxs

    File Not Found

    C:\Windows\System32>dir c:\mk2aa
     Volume in drive C is Windows7_OS
     Volume Serial Number is C0C8-C11D

     Directory of c:\mk2aa

    11/27/2013  11:16 AM    <DIR>          .
    11/27/2013  11:16 AM    <DIR>          ..
    11/27/2013  11:16 AM    <DIR>          amd64_microsoft-windows-cryptext-dll_31bf
    3856ad364e35_6.1.7600.16385_none_5b87b4622f6a278f
                   0 File(s)              0 bytes
                   3 Dir(s)  224,618,283,008 bytes free

    C:\Windows\System32>
    Wednesday, November 27, 2013 5:31 PM
  • That's correct, at least p which means that it may be a registry problem.

    I'll post back with a test for it later.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Thursday, November 28, 2013 7:55 AM
    Moderator
  • Any thoughts Noel?

    I continue to get the warning that Windows is not genuine, which is not true. I know I should have a license provided by Lenovo, but I have been unable to locate the 

    sticker for some reason and I certainly do not want to buy another copy...

    Thanks,

    MikeK

    Monday, December 2, 2013 7:05 PM
  • Ooops - sorry, Mike, this slipped off my radar.

    I have to go to work now, but I'll post later.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, December 3, 2013 8:04 AM
    Moderator
  • Ok, I am patiently waiting :)

    I did find my MS Win 7 product key sticker... Had to remove the battery to see it.. If you need the information on it just let me know, but I feel a tad better now that I found it.

    I was starting to wonder about Lenovo, but now they are back in my good graces. 

    Tuesday, December 3, 2013 3:41 PM
  • Sorry about that -came down with a lergy :(

    OK - where were we?

    You have a mismatched file which is resistant to being substituted back by normal means... and I'm a little confused as to why, since everything else seems to be right..

    Checking the SFC log again, it doesn't appear to be a registry problem, simply a file problem.

    Please run the following command in an Elevated Command Prompt, then zip the resulting folder from your desktop and post the zipped file to your SkyDrive.

    XCOPY C:\Windows\winsxs\amd64_microsoft-windows-cryptext-dll_31bf3856ad364e35_6.1.7600.16385_none_5b87b4622f6a278f %userprofile%\desktop\NPFOLDER /E /I
    
    .

    (use copy and paste! - it should all be one line, but will wrap in the prompt window)

    I'll take a look and see what it can tell me.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, December 8, 2013 10:36 AM
    Moderator
  • Hey Noel,

    I figured something had you tied up, glad you are better.

    The warning became very annoying and kept interfering with work demands, so yesterday I did a system restore to a point prior to when I thought the issue started,

    and all seems good now. Windows validates now on the MS site, so I think the problem is resolved. I had to re-install a couple things, but seem to be ok.

    Thanks for all the time you spent attempting to assist me, I appreciate it.

    Sunday, December 8, 2013 2:00 PM
  • You're welcome - thanks for the update!


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, December 8, 2013 2:08 PM
    Moderator