locked
Windows 7 has become non-genuine RRS feed

  • Question

  • Hi,

    I'm trying to fix a problem with my parents acer laptop, this is a store bought laptop which has windows 7 pre-installed, they have been using it for many months, but all of a sudden it's running very slowly and they are receiving the windows not genuine message.  Attached below is the diagnostic report from the MGAdiag tool, please can you advise what the issue is and how I can fix it you get them back up and running?

    Also worth noting when I go to the http://www.microsoft.com/genuine/validate site it doesn't work, giving an error message 'Windows validation was interrupted. Windows Activation Technologies is not able to validate Windows on your PC. Not to worry, we can help you with that.' but following the troubleshooting instructions does not work to resolve this

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {039E3C67-575D-4798-AD99-8112655C5E59}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Edition 2003 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: N/A, hr=0x80070002
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{039E3C67-575D-4798-AD99-8112655C5E59}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-1882192398-2439343769-1556924648</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Aspire 5733</Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>V1.02</Version><SMBIOSVersion major="2" minor="6"/><Date>20110420000000.000000+000</Date></BIOS><HWID>2C7B3907018400FC</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>3DD6CA2476A3D04</Val><Hash>al7oz29B02uFGUHmJZp/0fN6meA=</Hash><Pid>73931-642-6447707-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800006-02-1033-7601.0000-0972011
    Installation ID: 017516353312009681073441050474729502604853902015473690
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 7QJB7
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 24/01/2013 08:25:39

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 11:20:2012 09:39
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys


    HWID Data-->
    HWID Hash Current: KgAAAAEAAQABAAEAAAABAAAAAQABAAEA6GFOkMIxcrOGaGhoPq1cgVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Thursday, January 24, 2013 11:44 AM

Answers

  • No real need for that - but there is bad news :(

    Your Hard Drive is showing early signs of failure - you should back up all data to external storage, and then test the drive with the manufacturer's test utility.

    I would recommend being gentle with the drive until you have corrected the problem.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.


    Saturday, January 26, 2013 2:15 PM
    Moderator

All replies

  • Download and install the Intel Rapid Storage Technology Drivers.   Let us know if this resolved your issue.

    Carey Frisch

    Thursday, January 24, 2013 3:26 PM
    Moderator
  • Hi, Intel drivers installed and rebooted but this appears to have made no difference at all, it's still running very slowly and reporting the product key as being invalid.


    • Edited by Matty5858 Thursday, January 24, 2013 9:14 PM
    Thursday, January 24, 2013 9:13 PM
  • Please post another MGADiag report, so we can see if there's any change in the results.

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Friday, January 25, 2013 12:24 AM
    Moderator
  • Updated diagnostic below, it's still running crazily slowly:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-DHRTY-G3HRH-93TQR
    Windows Product Key Hash: OtoQVGIEsXgBQqyPCfKkTbK2yFI=
    Windows Product ID: 00359-OEM-9816981-84739
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {039E3C67-575D-4798-AD99-8112655C5E59}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Edition 2003 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: N/A, hr=0x80070002
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{039E3C67-575D-4798-AD99-8112655C5E59}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-93TQR</PKey><PID>00359-OEM-9816981-84739</PID><PIDType>8</PIDType><SID>S-1-5-21-1882192398-2439343769-1556924648</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Aspire 5733</Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>V1.02</Version><SMBIOSVersion major="2" minor="6"/><Date>20110420000000.000000+000</Date></BIOS><HWID>2C7B3907018400FC</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>3DD6CA2476A3D04</Val><Hash>al7oz29B02uFGUHmJZp/0fN6meA=</Hash><Pid>73931-642-6447707-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-169-884739-02-2057-7601.0000-0242013
    Installation ID: 000846992632804716047563539615679045138402102510877574
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 93TQR
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 25/01/2013 13:00:11

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 1:25:2013 07:31
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys


    HWID Data-->
    HWID Hash Current: KgAAAAEAAQABAAEAAAABAAAAAQABAAEA6GFOkMIxcrOGaGhoPq1cgVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, January 25, 2013 1:13 PM
  • Please run the following commands in an Elevated Command Prompt

     

    NET STOP CRYPTSVC
    REN C:\WINDOWS\SYSTEM32\CATROOT2 CATROOT2OLD
    NET START CRYPTSVC

     

    once complete, leave the system alone for at least an hour to rebuild the database, then reboot, and run another MGADiag report.
    Note that this will delete your Update History - but all updates will remain installed, and can be viewed in the Installed Updates listing.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Friday, January 25, 2013 1:36 PM
    Moderator
  • Hi Noel, thanks very much for your help, really appreciate your time.  I have followed your instructions and rebooted and updated diagnostic file report below, I can see the catroot2 folder has been recreated in windows/system32.  It still seems to be running terribly slowly however :( Pretty much everything I try and run (windows explorer windows, notepad, internet explorer, the MGA tool, all take ages to load and hang as not responding for several minutes at a time)

    I also ran sfc /scannow and the results said corrupted files had been found, but the CBS.log is over 12mb and mostly unintelligible,  I can't work out anything useful from it, not sure if this is relevant or worth posting too?

    I'm really keen to try and understand if this is something that my parents have somehow done to the laptop or if it's some other issue.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-DHRTY-G3HRH-93TQR
    Windows Product Key Hash: OtoQVGIEsXgBQqyPCfKkTbK2yFI=
    Windows Product ID: 00359-OEM-9816981-84739
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {039E3C67-575D-4798-AD99-8112655C5E59}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120830-0333
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Edition 2003 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: N/A, hr=0x80070002
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{039E3C67-575D-4798-AD99-8112655C5E59}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-93TQR</PKey><PID>00359-OEM-9816981-84739</PID><PIDType>8</PIDType><SID>S-1-5-21-1882192398-2439343769-1556924648</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Aspire 5733</Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>V1.02</Version><SMBIOSVersion major="2" minor="6"/><Date>20110420000000.000000+000</Date></BIOS><HWID>2C7B3907018400FC</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>3DD6CA2476A3D04</Val><Hash>al7oz29B02uFGUHmJZp/0fN6meA=</Hash><Pid>73931-642-6447707-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-169-884739-02-2057-7601.0000-0242013
    Installation ID: 000846992632804716047563539615679045138402102510877574
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 93TQR
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 25/01/2013 22:07:53

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 1:25:2013 19:11
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys


    HWID Data-->
    HWID Hash Current: KgAAAAEAAQABAAEAAAABAAAAAQABAAEA6GFOkMIxcrOGaGhoPq1cgVxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, January 25, 2013 10:13 PM
  • CBS logs are fun reading - please upload it to your SkyDrive or other favoured fileshare site, and post the link, and I'll take a look.

    It may be worth running a deep CHKDSK as well (I usually suggest running it prior to the SFC, just in case, but...)

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated
    Command Prompt window should pop up.

     

    At the Command prompt, type

     

    CHKDSK C: /R

     

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.

     

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

     

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Friday, January 25, 2013 10:19 PM
    Moderator
  • Hi, OK thanks, I will do that in a few hours and report back - worth mentioning that I am doing this all remotely as my parents are at home and I'm away with work, so once I run the deep chkdsk will it automatically restart into windows? Also I obviously won't be able to see the screen while it's happening and my parents aren't great at recording what messages actually say, will there be a log file accessible after reboot?

    CBS file is uploaded to my dropbox, this link should be publically downloadable:

    http://dl.dropbox.com/u/77749485/CBS.log

    I can always run sfc again after the chkdsk.


    Friday, January 25, 2013 10:51 PM
  • Something nasty appears to have happened after the end of the SFC scan you ran that finished at 13:45 on 25 Jan

    The one you started at 18:52 appears to have crashed about 1/5th of the way through.

    Having said that - there are a number of failures throughout the log.....

    2013-01-24 11:57:09, Error                 CSI    00000031 (F) [SR] Component not found: Microsoft-Windows-Security-SPP-Client, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral[gle=0x80004005]
    2013-01-24 11:57:09, Error                 CSI    00000032@2013/1/24:11:57:09.088 (F) d:\win7sp1_gdr\base\wcp\servicingapi\cmirepair.cpp(312): Error HRESULT_FROM_WIN32(ERROR_SXS_ASSEMBLY_MISSING) originated in function Windows::ServicingAPI::CCSIRepairTransaction::LockComponent expression: HRESULT_FROM_WIN32(14081L)
    
    

    I'm not certain exactly what this error implies - it could well be the result of registry problems, in which case a repair install is probably indicated.

    There's also other errors, which indicate that perhaps another file is corrupted....

    Please open an Elevated Command Prompt, and run the following commands

    MD %userprofile%\desktop\npfiles
    COPY C:\Windows\winsxs\Filemaps\$$_system32_spp_plugin-manifests-signed*.* %userprofile%\desktop\npfiles
     
     
    

    These will create a new folder on your desktop and populate it with at least one file (hopefully!)

    please zip the entire folder, and upload it - I'd like to see what it looks like (we very rarely see errors with these files in the CBS logs) so I can try to work out what's necessary.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Friday, January 25, 2013 11:32 PM
    Moderator
  • Hi,

    I only ran one sfc scan, so if one crashed part way through it must have automatically restarted/continued.  I saw those errors but couldn't work out anything meaningful from them to help with a fix.

    As you say if it's some signficant registry issue I'll have to attempt a full backup and windows re-install remotely, could be fun!

    I have run the commands you gave and file is uploaded to dropbox here (only one file populated):

    http://dl.dropbox.com/u/77749485/npfiles.zip

    Would it make sense to run the chkdsk then run the sfc scan again?

    Saturday, January 26, 2013 3:53 AM
  • Running CHKDSK and SFC again has a low chance of success - but it may be worth it.

    If it doesn't work, then I suggest doing a repair install.

     

    Follow the
    instructions in this tutorial - http://www.sevenforums.com/tutorials/3413-repair-install.html

    - and they should
    help you get through it (it's not as difficult as it looks!)

     

    Always ask
    questions first if you're unsure - either here, or in sevenforums.

     

    Good luck with
    it!



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Saturday, January 26, 2013 8:23 AM
    Moderator
  • Hi,

    OK well I'll try the chkdsk and sfc first as doing a repair install remotely is going to be almost impossible, they only have the Acer factory restore CD's locally not an ISO or retail disc :-(

    I'll doo chkdsk, re run sfc and diag and see if that presents any solution!

    Thanks for your help so far!

    Saturday, January 26, 2013 9:12 AM
  • Hi,

    Well it looks like the deep chkdsk has given some success! It ran for quite a while and it looks to me like it found various issues which it seems to have dealt with.  Windows is now running at normal speed and reports as genuine at http://www.microsoft.com/genuine/validate/

    Now the sfc /scannow also completes with message 'Windows Resource Protection did not find any integrity violations.'

    I've attached the chkdsk log from even viewer, CBS log and genuine advantage diagnostic in the following dropbox link, would really appreciate you taking a quick look and seeing what you think:

    http://dl.dropbox.com/u/77749485/LogFiles.zip

    Would it be advisable to run the deep check disk a further time to double check all is ok?

    Saturday, January 26, 2013 12:27 PM
  • No real need for that - but there is bad news :(

    Your Hard Drive is showing early signs of failure - you should back up all data to external storage, and then test the drive with the manufacturer's test utility.

    I would recommend being gentle with the drive until you have corrected the problem.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.


    Saturday, January 26, 2013 2:15 PM
    Moderator
  • Hi,

    OK cool, yeah I realised that meant the hard drive isn't great, thats OK though, I only need it to make it through another few months and then I can put a new hard drive in and clean windows install. I'll do an external backup now though just in case and run the drive check.

    Thanks for your help and advice in getting to the bottom of the issue - many thanks.

    Matt

    Saturday, January 26, 2013 9:24 PM