locked
Not Genuine, not true RRS feed

  • Question

  • My Windows 7 install has been working for years, until this week when the "not genuine" pop-up appeared.

    This Win7 instance is a virtual machine running under Parallels on my MacBook Pro. Might be coincidental, but last weekend I defragmented the Mac's hard drive with iDefrag, which would defragment the gigantic VM file. Maybe Windows 7 resources got relocated?

    When I bought the MacBook from macsales.com, they installed Parallels and Windows 7. The partial product key in the MGA diagnostic report (below) matches the key on my Certificate of Authenticity label.

    More information added...

    All updates were current yesterday. I use Microsoft Security Essentials and it too is current with status = green.

    When I click Start > Right-click Computer > click Properties, under "Windows activation" it says "Windows is activated".

    No product key is shown (which might be normal) but if I click "Change Product Key"
    I get a pop-up titled "slui.exe - Bad Image" stating

    C:\Windows\system32\sppcext.dll is either not designed to run on
    Windows or it contains an error. Try installing the program again using
    the original installation media or contact your system administrator or
    the software vendor for support.  [OK]

    This may be unrelated since MGA diagnostic log below appears to show the right key (at least what's shown).

    Thanks for helping, Gary

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-9VKH6-P6HWJ-BYQDH
    Windows Product Key Hash: 7J61wBtqRVrd+hLhTPfnavtZmmM=
    Windows Product ID: 00371-OEM-9044792-06176
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppcext.dll[Hr = 0x800b0100]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BYQDH</PKey><PID>00371-OEM-9044792-06176</PID><PIDType>3</PIDType><SID>S-1-5-21-3506055729-4056116513-913861776</SID><SYSTEM><Manufacturer>Parallels Software International Inc.</Manufacturer><Model>Parallels Virtual Platform</Model></SYSTEM><BIOS><Manufacturer>Parallels Software International Inc.</Manufacturer><Version>8.0.18608.898384</Version><SMBIOSVersion major="2" minor="3"/><Date>20071026000000.000000+000</Date></BIOS><HWID>0C433607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
    Activation ID: e120e868-3df2-464a-95a0-b52fa5ada4bf
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00180-447-906176-02-1033-7600.0000-1292011
    Installation ID: 007744959616411642569352335835422506110302185082430073
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: BYQDH
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/10/2013 7:34:48 AM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000000040
    Event Time Stamp: 11:9:2013 09:16
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui


    HWID Data-->
    HWID Hash Current: MAAAAAEABAABAAEAAAABAAAAAQABAAEA6GGKkiZYYC+OqRKYWP70PQaFOlvMy4x1

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PRLS          PRLS_OEM
      FACP            PRLS          PRLS_OEM
      WAET            PRLS          PRLS_OEM


    Sunday, November 10, 2013 5:01 PM

Answers

  • Hi Noel,

    After performing above steps, SFC now reports, "Windows Resource Protection did not find any integrity violations"

    public link to my third CBS log: https://dl.dropboxusercontent.com/u/34992494/CBS3.log

    Here is my third MGADiag report, below... 

    THANK YOU once again!  Gary

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-9VKH6-P6HWJ-BYQDH
    Windows Product Key Hash: 7J61wBtqRVrd+hLhTPfnavtZmmM=
    Windows Product ID: 00371-OEM-9044792-06176
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BYQDH</PKey><PID>00371-OEM-9044792-06176</PID><PIDType>3</PIDType><SID>S-1-5-21-3506055729-4056116513-913861776</SID><SYSTEM><Manufacturer>Parallels Software International Inc.</Manufacturer><Model>Parallels Virtual Platform</Model></SYSTEM><BIOS><Manufacturer>Parallels Software International Inc.</Manufacturer><Version>8.0.18608.898384</Version><SMBIOSVersion major="2" minor="3"/><Date>20071026000000.000000+000</Date></BIOS><HWID>0C433607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
    Activation ID: e120e868-3df2-464a-95a0-b52fa5ada4bf
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00180-447-906176-02-1033-7600.0000-1292011
    Installation ID: 007744959616411642569352335835422506110302185082430073
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: BYQDH
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/13/2013 7:52:30 AM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 11:9:2013 09:16
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEABAABAAEAAAABAAAAAQABAAEA6GGKkiZYYC+OqRKYWP70PQaFOlvMy4x1

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PRLS          PRLS_OEM
      FACP            PRLS          PRLS_OEM
      WAET            PRLS          PRLS_OEM

    Wednesday, November 13, 2013 4:41 PM

All replies

  • Please run a full CHKDSK and SFC scan....

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    CHKDSK C: /R

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -

    then run the SFC.

    SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    SFC /SCANNOW

    and hit the Enter key

    Wait for the scan to finish - make a note of any error messages - and then reboot.

    Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive Public folder (http://skydrive.live.com ) and post a link to it so that I can take a look.

    Post a new MGADiag report with details of any error messages encountered.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, November 10, 2013 8:41 PM
    Moderator
  • Hi Noel,

    I ran chkdsk /r and SFC scan as described.

    Instead of posting the entire CBS.log to Skydrive, here are the full text blocks extracted from my

    CBS.log for two exception types: "[SR] Cannot repair" and "[SR] Could not reproject"

    =================================

    All "[SR] Cannot repair" exceptions in CBS.log:

    =================================

    2013-11-12 13:10:41, Info                  CSI    0000003c [SR] Cannot repair member file [l:24{12}]"AudioSes.dll" of Microsoft-Windows-Audio-AudioCore, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:10:44, Info                  CSI    0000003f [SR] Cannot repair member file [l:24{12}]"AudioSes.dll" of Microsoft-Windows-Audio-AudioCore, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:12:09, Info                  CSI    00000095 [SR] Cannot repair member file [l:24{12}]"himalaya.ttf" of Microsoft-Windows-Font-TrueType-MicrosoftHimalaya, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:12:28, Info                  CSI    000000c3 [SR] Cannot repair member file [l:24{12}]"msgothic.ttc" of Microsoft-Windows-Font-TrueType-MSGothic, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:15:26, Info                  CSI    00000170 [SR] Cannot repair member file [l:22{11}]"sppcext.dll" of Microsoft-Windows-Security-SPP-ClientExt, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:15:33, Info                  CSI    00000172 [SR] Cannot repair member file [l:22{11}]"sppcext.dll" of Microsoft-Windows-Security-SPP-ClientExt, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:20:56, Info                  CSI    000002e7 [SR] Cannot repair member file [l:24{12}]"powercfg.exe" of Microsoft-Windows-PowerManagement-Configuration-Cmdline, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:20:59, Info                  CSI    000002e9 [SR] Cannot repair member file [l:24{12}]"powercfg.exe" of Microsoft-Windows-PowerManagement-Configuration-Cmdline, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:52, Info                  CSI    0000032b [SR] Cannot repair member file [l:24{12}]"AudioSes.dll" of Microsoft-Windows-Audio-AudioCore, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:52, Info                  CSI    0000032d [SR] Cannot repair member file [l:24{12}]"himalaya.ttf" of Microsoft-Windows-Font-TrueType-MicrosoftHimalaya, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:52, Info                  CSI    0000032f [SR] Cannot repair member file [l:24{12}]"msgothic.ttc" of Microsoft-Windows-Font-TrueType-MSGothic, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:52, Info                  CSI    00000331 [SR] Cannot repair member file [l:22{11}]"sppcext.dll" of Microsoft-Windows-Security-SPP-ClientExt, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:52, Info                  CSI    00000333 [SR] Cannot repair member file [l:24{12}]"powercfg.exe" of Microsoft-Windows-PowerManagement-Configuration-Cmdline, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:53, Info                  CSI    0000033b [SR] Cannot repair member file [l:24{12}]"AudioSes.dll" of Microsoft-Windows-Audio-AudioCore, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:53, Info                  CSI    0000033e [SR] Cannot repair member file [l:22{11}]"sppcext.dll" of Microsoft-Windows-Security-SPP-ClientExt, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    2013-11-12 13:21:53, Info                  CSI    00000344 [SR] Cannot repair member file [l:24{12}]"powercfg.exe" of Microsoft-Windows-PowerManagement-Configuration-Cmdline, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch

    ====================================
    All "[SR] Could not reproject" exceptions in CBS.log:

    ====================================

    2013-11-12 13:15:33, Info                  CSI    00000176 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"sppcext.dll"; source file in store is also corrupted
    2013-11-12 13:20:59, Info                  CSI    000002ed [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"powercfg.exe"; source file in store is also corrupted
    2013-11-12 13:21:53, Info                  CSI    00000342 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"sppcext.dll"; source file in store is also corrupted
    2013-11-12 13:21:53, Info                  CSI    00000348 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"powercfg.exe"; source file in store is also corrupted

    ======================================

    Here is the new MGADiag report after chkdsk and sfc:

    ======================================

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-9VKH6-P6HWJ-BYQDH
    Windows Product Key Hash: 7J61wBtqRVrd+hLhTPfnavtZmmM=
    Windows Product ID: 00371-OEM-9044792-06176
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppcext.dll[Hr = 0x800b0100]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BYQDH</PKey><PID>00371-OEM-9044792-06176</PID><PIDType>3</PIDType><SID>S-1-5-21-3506055729-4056116513-913861776</SID><SYSTEM><Manufacturer>Parallels Software International Inc.</Manufacturer><Model>Parallels Virtual Platform</Model></SYSTEM><BIOS><Manufacturer>Parallels Software International Inc.</Manufacturer><Version>8.0.18608.898384</Version><SMBIOSVersion major="2" minor="3"/><Date>20071026000000.000000+000</Date></BIOS><HWID>0C433607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
    Activation ID: e120e868-3df2-464a-95a0-b52fa5ada4bf
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00180-447-906176-02-1033-7600.0000-1292011
    Installation ID: 007744959616411642569352335835422506110302185082430073
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: BYQDH
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/12/2013 2:10:51 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000000040
    Event Time Stamp: 11:9:2013 09:16
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui


    HWID Data-->
    HWID Hash Current: MAAAAAEABAABAAEAAAABAAAAAQABAAEA6GGKkiZYYC+OqRKYWP70PQaFOlvMy4x1

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PRLS          PRLS_OEM
      FACP            PRLS          PRLS_OEM
      WAET            PRLS          PRLS_OEM

    END of MGADiag report

    Thank you for helping, Gary

    Tuesday, November 12, 2013 11:16 PM
  • Please post the entire log as requested - there may well be other errors which it's important to know about.

    In the meantime...

    I've uploaded a file - rlpaa.zip - to my SkyDrive at Noel's SkyDrive

    Please download and save it.

    Right-click on the saved file and select Extract all...

    Change the target to C:\ and click on Extract

    Close all windows (it would be a good idea to print these instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start tapping F8 - this should bring up the Advanced Boot Menu, at the top of which
    should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

    At the prompt type

    DIR C:\rlpaa

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\rlpaa

    or

    DIR E:\rlpaa

    The drive letter in use when you find the folder will need to be substituted (for<drive>) into the following
    command...

    XCOPY <drive>:\rlpaa  <drive>:\windows\winsxs /y /i /s /v /h

    (e.g. XCOPY P:\wfire P:\windows\winsxs /y /i /s /v /h )

    run the command (it should take almost no time) and when the prompt returns, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

    Now run SFC /SCANNOW in an Elevated Command Prompt

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new link

    Also run a new MGADiag report, and post the result.



    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, November 13, 2013 2:05 PM
    Moderator
  • Hi Noel,

    After performing above steps, SFC now reports, "Windows Resource Protection did not find any integrity violations"

    public link to my third CBS log: https://dl.dropboxusercontent.com/u/34992494/CBS3.log

    Here is my third MGADiag report, below... 

    THANK YOU once again!  Gary

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-9VKH6-P6HWJ-BYQDH
    Windows Product Key Hash: 7J61wBtqRVrd+hLhTPfnavtZmmM=
    Windows Product ID: 00371-OEM-9044792-06176
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{C1F1A1EC-B04F-4BA3-A29A-E540A02D4823}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BYQDH</PKey><PID>00371-OEM-9044792-06176</PID><PIDType>3</PIDType><SID>S-1-5-21-3506055729-4056116513-913861776</SID><SYSTEM><Manufacturer>Parallels Software International Inc.</Manufacturer><Model>Parallels Virtual Platform</Model></SYSTEM><BIOS><Manufacturer>Parallels Software International Inc.</Manufacturer><Version>8.0.18608.898384</Version><SMBIOSVersion major="2" minor="3"/><Date>20071026000000.000000+000</Date></BIOS><HWID>0C433607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
    Activation ID: e120e868-3df2-464a-95a0-b52fa5ada4bf
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00180-447-906176-02-1033-7600.0000-1292011
    Installation ID: 007744959616411642569352335835422506110302185082430073
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: BYQDH
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 11/13/2013 7:52:30 AM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 11:9:2013 09:16
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEABAABAAEAAAABAAAAAQABAAEA6GGKkiZYYC+OqRKYWP70PQaFOlvMy4x1

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PRLS          PRLS_OEM
      FACP            PRLS          PRLS_OEM
      WAET            PRLS          PRLS_OEM

    Wednesday, November 13, 2013 4:41 PM
  • That seems to have cured the immediate 'genuine' problem....

    The background CBS data looks to be OKK as well.

    You should no longer be seeing any notifications :)

    Reboot a couple of times, and install this month's updates, to check that everything is working - if so, you're good to go!


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, November 13, 2013 9:14 PM
    Moderator
  • Thanks Noel,

    You saved me a lot of grief (reinstalling W7 and all apps).

    Everything seemed to work fine, even though this was a Parallels virtual machine running on my MacBook. I was briefly concerned that F8 during reboot might not launch the Windows repair menu, but it did.

    Thanks again,

    Gary

    Thursday, November 14, 2013 1:12 AM
  • Great! good luck.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Thursday, November 14, 2013 7:13 AM
    Moderator