Answered by:
Win 7 Ultimate "Build 7601 this copy of windows is not genuine"

Question
-
I am getting a "This copy of windows is not genuine" error message for a few days now and am having trouble figuring out what the problem is. I am hopeful someone can help.
Here is the output from mgadiag.exe:
Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 50 Cached Online Validation Code: N/A, hr = 0xc004f012 Windows Product Key: *****-*****-9VDRQ-JVWWB-WDYTW Windows Product Key Hash: aU5vFdBvphKrvupqxpsLHdRvEM8= Windows Product ID: 00426-068-3778683-86639 Windows Product ID Type: 5 Windows License Type: Retail Windows OS version: 6.1.7601.2.00010100.1.0.001 ID: {9862DB61-C3C8-4547-9136-CCFF92FF2C6A}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Ultimate Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.130104-1431 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> File Mismatch: C:\Windows\system32\sppwinob.dll[2.0.50727.4927], Hr = 0x80004005 Other data--> Office Details: <GenuineResults><MachineData><UGUID>{9862DB61-C3C8-4547-9136-CCFF92FF2C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-WDYTW</PKey><PID>00426-068-3778683-86639</PID><PIDType>5</PIDType><SID>S-1-5-21-3163584284-2657221260-1632861152</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F10</Version><SMBIOSVersion major="2" minor="4"/><Date>20100205000000.000000+000</Date></BIOS><HWID>10FF3207018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> Software licensing service version: 6.1.7601.17514 Name: Windows(R) 7, Ultimate edition Description: Windows Operating System - Windows(R) 7, RETAIL channel Activation ID: a0cde89c-3304-4157-b61c-c8ad785d1fad Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f Extended PID: 00426-00172-068-377868-00-1033-7601.0000-1362011 Installation ID: 021144448572929413338966749346148784814996089030460783 Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338 Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339 Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341 Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340 Partial Product Key: WDYTW License Status: Licensed Remaining Windows rearm count: 0 Trusted time: 4/26/2013 2:45:12 PM Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: N/A HealthStatus: 0x0000000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: NgAAAAEAAgABAAIAAgABAAAAAwABAAEA6GE+BdAqCIXCj4ypznDom8KP8Bcqz9j7WiwomEbK OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes, but no SLIC table Windows marker version: N/A OEMID and OEMTableID Consistent: N/A BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC GBT GBTUACPI FACP GBT GBTUACPI HPET GBT GBTUACPI MCFG GBT GBTUACPI EUDS GBT TAMG GBT GBT B0 SSDT PmRef CpuPm
seems to me this is the problem line:
File Mismatch: C:\Windows\system32\sppwinob.dll
I have done sfc /scannow
I have been through the MS Genuine register process where you go online and get a new confirmation code for your software.
looking it up online, this appears to be related to the windows activation process.
Any help would be appreciated.
Friday, April 26, 2013 6:50 PM
Answers
-
It does create the data but it may not be written to file immediately- which is why I ask for the reboot afterwards.
Your report is now showing as genuine :)
Please attempt validation at www.microsoft.com/genuine/validate using Internet Explorer - with luck you'll pass.
Post a final MGADiag report to double-check.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.- Marked as answer by rm17592 Thursday, May 2, 2013 5:03 PM
Thursday, May 2, 2013 6:13 AMModerator
All replies
-
Windows Product ID: 00426-068-3778683-86639
The product ID -068- Indicates a not for resale MSDN account. If you are not the account holder and you purchased this in a retail box, the box and it's contents are counterfeit. Demand an immediate refund from the seller
For more information see this:
http://social.microsoft.com/Forums/en-US/genuinewindows7/thread/a2444f34-0aff-4f29-a8ac-67e28b0c0285
And this:
http://social.microsoft.com/Forums/en-US/genuinewindows7/thread/309bb621-92d5-43d6-98c1-2bb51b35607f
To see how good these counterfeits are becoming, see:
http://www.youtube.com/watch?v=hzqNNiOM0cs
You will have to purchase a legitimate windows from a legitimate retailer.
Friday, April 26, 2013 6:57 PMAnswerer -
I received this license as a benefit of an MS launch event I attended a few years ago. I am an MSDN partner (or at least was, I have not kept it up to date) but my understanding on the licensing is that I could install it within a year (which I did) and it would not expire...Friday, April 26, 2013 7:20 PM -
also note that this machine has been running fine up until a couple of weeks ago. I did not re-install the OS...Friday, April 26, 2013 7:26 PM
-
ok. then my answer does not apply to you.
File Mismatch: C:\Windows\system32\sppwinob.dll
you are correct.this is the cause of your issue. unfortunately it is beyond my skills.
hopefully Noel will have alook
Friday, April 26, 2013 10:27 PMAnswerer -
Please run a full CHKDSK and SFC scan....
Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.
At the Command prompt, type
CHKDSK C: /R
and hit the Enter key.
You will be told that the drive is locked,
and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.
The CHKDSK will take a few hours depending on the size of the drive, so be patient!
After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -
then run the SFC.
SFC -System File Checker - Instructions
Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.
At the Command prompt, type
SFC /SCANNOW
and hit the Enter key
Wait for the scan to finish - make a note of any error messages - and then reboot.
Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive Public folder (http://skydrive.live.com ) and post a link to it so that I can take a look.
Post a new MGADiag report with details of any error messages encountered.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Saturday, April 27, 2013 7:50 AMModerator -
Thank you for your help.
here are the links, its not letting me post links yet, please add https:// to both of these:
cbs.log
skydrive.live.com/redir?resid=934895F9F0ADA212!113&authkey=!AORxrl0P30dIyhI
a screenshot of the sfc results:
skydrive.live.com/redir?resid=934895F9F0ADA212!112&authkey=!AA4OxVuX1cw_M9c
Tuesday, April 30, 2013 4:54 PM -
and, finally, the MGADiag results:
Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 50 Cached Online Validation Code: N/A, hr = 0xc004f012 Windows Product Key: *****-*****-9VDRQ-JVWWB-WDYTW Windows Product Key Hash: aU5vFdBvphKrvupqxpsLHdRvEM8= Windows Product ID: 00426-068-3778683-86639 Windows Product ID Type: 5 Windows License Type: Retail Windows OS version: 6.1.7601.2.00010100.1.0.001 ID: {9862DB61-C3C8-4547-9136-CCFF92FF2C6A}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Ultimate Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.130104-1431 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> File Mismatch: C:\Windows\system32\sppwinob.dll[2.0.50727.4927], Hr = 0x80004005 Other data--> Office Details: <GenuineResults><MachineData><UGUID>{9862DB61-C3C8-4547-9136-CCFF92FF2C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-WDYTW</PKey><PID>00426-068-3778683-86639</PID><PIDType>5</PIDType><SID>S-1-5-21-3163584284-2657221260-1632861152</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F10</Version><SMBIOSVersion major="2" minor="4"/><Date>20100205000000.000000+000</Date></BIOS><HWID>10FF3207018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> Software licensing service version: 6.1.7601.17514 Name: Windows(R) 7, Ultimate edition Description: Windows Operating System - Windows(R) 7, RETAIL channel Activation ID: a0cde89c-3304-4157-b61c-c8ad785d1fad Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f Extended PID: 00426-00172-068-377868-00-1033-7601.0000-1362011 Installation ID: 021144448572929413338966749346148784814996089030460783 Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338 Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339 Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341 Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340 Partial Product Key: WDYTW License Status: Licensed Remaining Windows rearm count: 0 Trusted time: 4/30/2013 3:01:26 PM Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: N/A HealthStatus: 0x0000000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: NgAAAAEAAgABAAIAAgABAAAAAwABAAEA6GE+BdAqCIXCj4ypznDom8KP8Bcqz9j7WiwomEbK OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes, but no SLIC table Windows marker version: N/A OEMID and OEMTableID Consistent: N/A BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC GBT GBTUACPI FACP GBT GBTUACPI HPET GBT GBTUACPI MCFG GBT GBTUACPI EUDS GBT TAMG GBT GBT B0 SSDT PmRef CpuPm
Tuesday, April 30, 2013 7:02 PM -
You have a fair amount of corruption....
Line 54114: 2013-04-29 14:37:12, Info CSI 00000374 [SR] Repairing 12 (0x000000000000000c) components Line 54115: 2013-04-29 14:37:12, Info CSI 00000375 [SR] Beginning Verify and Repair transaction Line 54118: 2013-04-29 14:37:12, Info CSI 00000377 [SR] Cannot repair member file [l:32{16}]"intelppm.sys.mui" of cpu.inf.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54121: 2013-04-29 14:37:12, Info CSI 00000379 [SR] Cannot repair member file [l:30{15}]"IPMIDrv.sys.mui" of ipmidrv.inf.Resources, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54124: 2013-04-29 14:37:12, Info CSI 0000037b [SR] Cannot repair member file [l:24{12}]"calc.exe.mui" of Microsoft-Windows-calc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54129: 2013-04-29 14:37:12, Info CSI 0000037e [SR] Cannot verify component files for Microsoft-Windows-IE-WinsockAutodialStub, Version = 9.4.8112.16470, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral, manifest is damaged (TRUE) Line 54132: 2013-04-29 14:37:12, Info CSI 00000380 [SR] Cannot repair member file [l:30{15}]"ndiscap.sys.mui" of Microsoft-Windows-NDIS-PacketCapture.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54135: 2013-04-29 14:37:15, Info CSI 00000382 [SR] Cannot repair member file [l:38{19}]"NlsLexicons001a.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54138: 2013-04-29 14:37:16, Info CSI 00000384 [SR] Cannot repair member file [l:22{11}]"ndisuio.inf" of Microsoft-Windows-NDISUIO, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54141: 2013-04-29 14:37:16, Info CSI 00000386 [SR] Cannot repair member file [l:26{13}]"rdbss.sys.mui" of Microsoft-Windows-RDBSS.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54144: 2013-04-29 14:37:16, Info CSI 00000388 [SR] Cannot repair member file [l:24{12}]"sppwinob.dll" of Microsoft-Windows-Security-SPP-Plugin-Windows, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54147: 2013-04-29 14:37:16, Info CSI 0000038a [SR] Cannot repair member file [l:26{13}]"rdpwd.sys.mui" of Microsoft-Windows-TerminalServices-RDP-WinStationDriver.Resources, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54150: 2013-04-29 14:37:16, Info CSI 0000038c [SR] Cannot repair member file [l:26{13}]"msdsm.sys.mui" of msdsm.inf.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 54153: 2013-04-29 14:37:16, Info CSI 0000038e [SR] Cannot repair member file [l:20{10}]"sqmapi.dll" of Microsoft-Windows-IE-RuntimeUtilities, Version = 9.4.8112.16470, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
There are also registry problems (showing in the above results), which may be cured by running the CheckSUR tool, which need to be fixed first, if we can.
Please download and save the CheckSUR tool from http://support.microsoft.com/kb/947821
(you'll need to look in the details for Windows 7, downloading from the Microsoft Download Center)
Run it - The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.
The result is logged in the C:\Windows\Logs\CBS\CheckSUR.log file - and an archive …\checksur.persist.log file
Then zip the CheckSUR.log and upload it to your SkyDrive Public folder so I can take a look - post a link in your reply.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Tuesday, April 30, 2013 8:55 PMModerator -
Thanks again, Noel.
I have completed this, and here are the results, please append https:// to the link
skydrive.live.com/redir?resid=934895F9F0ADA212!114&authkey=!AE3kn0OP-Bhb1Mk
I am wondering now if my issue is my disk. I have another new drive I can use to replace my current system drive. should I go through the effort of doing a backup/restore to the new drive before correcting these issues?
Wednesday, May 1, 2013 2:10 PM -
Here's the problem listing from the CheckSUR log...
Unavailable repair files: winsxs\manifests\x86_netfx-mscorjit_dll_b03f5f7f11d50a3a_6.1.7601.21693_none_7cf378100772d8a0.manifest winsxs\manifests\x86_netfx-mscorjit_dll_b03f5f7f11d50a3a_6.1.7601.17587_none_93bfc365edccc5c7.manifest winsxs\manifests\amd64_microsoft-windows-ie-winsockautodialstub_31bf3856ad364e35_9.4.8112.16470_none_6491ffa230979599.manifest servicing\packages\Package_1_for_KB2809289~31bf3856ad364e35~amd64~~9.4.1.0.mum servicing\packages\Package_1_for_KB2809289~31bf3856ad364e35~amd64~~9.4.1.0.cat
I doubt this is due to disk problems - but you can check that by looking in the Event Viewer Windows Logs - System log, with sources Ntfs, Wininit, and Disk, and Application log Wininiit events
(or upload the C:\Windows\System32\winevt\logs\Applicarion.evtx and ...\System.evtx and post a link)
I'll post a fix protocol for the CheckSUR results in a few minutes, and once we have that clear, we can work on the SFC results.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 2:24 PMModerator -
I've uploaded a file - r92aa.zip - to my SkyDrive at Noel's SkyDrive
Please download and save it.
Right-click on the downloaded file, and select Extract all…
Extract to the default location - which will create a new folder r92aa in the same place.
Open this folder - there should be two folders inside it (Manifests, and Packages)
Copy the content of the Packages folder to the folder
C:\Windows\Temp\CheckSur\Servicing\Packages
And the content of the manifests folder (.manifest files) into this folder:
C:\Windows\Temp\CheckSur\Winsxs\Manifests
Now run the CheckSUR tool again (it may take a while)
Post the new CheckSUR.log file, and the CheckSUR.persist.log file.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 2:43 PMModerator -
OK, done.
skydrive.live.com/redir?resid=934895F9F0ADA212!115&authkey=!AFuFe2a0b2qqsRU
Wednesday, May 1, 2013 4:10 PM -
Great - the CheckSUR results are now clear.
Please run another SFC /SCANNOW and post the new CBS.log file, just in case anything there has changed, and we'll get to work on that.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 4:27 PMModerator -
OK, should i be rebooting between these? I have not been.Wednesday, May 1, 2013 5:24 PM
-
It would probably be a good idea, just to make sure that any changes are properly bedded in.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 5:30 PMModerator -
OK, rebooted and ran again.
I included a screenshot and the cbs.log file in the zip:
skydrive.live.com/redir?resid=934895F9F0ADA212!116&authkey=!ACgVFYYvu6u6Ldo
Wednesday, May 1, 2013 6:08 PM -
OK - that shows the same results as the earlier one (apart from the error fixed by CheckSUR)
Line 37223: 2013-05-01 13:57:04, Info CSI 0000036d [SR] Repairing 11 (0x000000000000000b) components Line 37224: 2013-05-01 13:57:04, Info CSI 0000036e [SR] Beginning Verify and Repair transaction Line 37227: 2013-05-01 13:57:04, Info CSI 00000370 [SR] Cannot repair member file [l:32{16}]"intelppm.sys.mui" of cpu.inf.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37230: 2013-05-01 13:57:05, Info CSI 00000372 [SR] Cannot repair member file [l:30{15}]"IPMIDrv.sys.mui" of ipmidrv.inf.Resources, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37233: 2013-05-01 13:57:05, Info CSI 00000374 [SR] Cannot repair member file [l:24{12}]"calc.exe.mui" of Microsoft-Windows-calc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37236: 2013-05-01 13:57:05, Info CSI 00000376 [SR] Cannot repair member file [l:30{15}]"ndiscap.sys.mui" of Microsoft-Windows-NDIS-PacketCapture.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37239: 2013-05-01 13:57:11, Info CSI 00000378 [SR] Cannot repair member file [l:38{19}]"NlsLexicons001a.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37242: 2013-05-01 13:57:15, Info CSI 0000037a [SR] Cannot repair member file [l:22{11}]"ndisuio.inf" of Microsoft-Windows-NDISUIO, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37245: 2013-05-01 13:57:15, Info CSI 0000037c [SR] Cannot repair member file [l:26{13}]"rdbss.sys.mui" of Microsoft-Windows-RDBSS.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37248: 2013-05-01 13:57:15, Info CSI 0000037e [SR] Cannot repair member file [l:24{12}]"sppwinob.dll" of Microsoft-Windows-Security-SPP-Plugin-Windows, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37251: 2013-05-01 13:57:15, Info CSI 00000380 [SR] Cannot repair member file [l:26{13}]"rdpwd.sys.mui" of Microsoft-Windows-TerminalServices-RDP-WinStationDriver.Resources, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37254: 2013-05-01 13:57:15, Info CSI 00000382 [SR] Cannot repair member file [l:26{13}]"msdsm.sys.mui" of msdsm.inf.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch Line 37257: 2013-05-01 13:57:15, Info CSI 00000384 [SR] Cannot repair member file [l:20{10}]"sqmapi.dll" of Microsoft-Windows-IE-RuntimeUtilities, Version = 9.4.8112.16470, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
I've uploaded a file - rm2aa.zip - to my SkyDrive at Noel's SkyDrive
Please download and save it.Right-click on the saved file and select Extract all...
Change the target to C:\ and click on Extract
Close all windows (it would be a good idea to print these
instructions!)
Now reboot to the Repair Environment - as soon as the machine restarts, start
tapping F8 - this should bring up the Advanced Boot Menu, at the top of which
should be the option 'Repair my Computer'
Pick that
You'll have to log in with your username and password.Pick the option to use a Command Prompt
At the prompt type
DIR C:\rm2aa
hit the enter key - if you get a 'Not Found' error try
DIR D:\rm2aa
or
DIR E:\rm2aaThe drive letter in use when you find the folder will need to be substituted (for<drive>) into the following
command...XCOPY <drive>:\rm2aa <drive>:\windows\winsxs /y /i /s /v /h
(e.g. XCOPY P:\wfire P:\windows\winsxs /y /i /s /v /h )
run the command (it should take almost no time) and when the prompt returns, type
EXIT
and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.Now run SFC /SCANNOW in an Elevated Command Prompt
then reboot and upload the new CBS.log file to your SkyDrive Public folder, and post a new linkAlso run a new MGADiag report, and post the result.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 6:42 PMModerator -
I'm having connection problems at my end - if the file isn't there, try again later.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Wednesday, May 1, 2013 7:14 PMModerator -
OK, thanks, I am going to have to wait until I am in front of the machine tonight to do this step. The rest I have been doing remotely...
Thanks again for your help! there is no way I could have fixed this on my own without a complete reinstall.
Wednesday, May 1, 2013 8:22 PM -
OK, I think we are getting somewhere.
the sfc reported no issues. i included the screenshot in the zip.
skydrive.live.com/redir?resid=934895F9F0ADA212!117&authkey=!ACuUBfsluhJVS7I
here are the MGADiag results
Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 0 Cached Online Validation Code: N/A, hr = 0xc004f012 Windows Product Key: *****-*****-9VDRQ-JVWWB-WDYTW Windows Product Key Hash: aU5vFdBvphKrvupqxpsLHdRvEM8= Windows Product ID: 00426-068-3778683-86639 Windows Product ID Type: 5 Windows License Type: Retail Windows OS version: 6.1.7601.2.00010100.1.0.001 ID: {9862DB61-C3C8-4547-9136-CCFF92FF2C6A}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Ultimate Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.130104-1431 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: <GenuineResults><MachineData><UGUID>{9862DB61-C3C8-4547-9136-CCFF92FF2C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-WDYTW</PKey><PID>00426-068-3778683-86639</PID><PIDType>5</PIDType><SID>S-1-5-21-3163584284-2657221260-1632861152</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F10</Version><SMBIOSVersion major="2" minor="4"/><Date>20100205000000.000000+000</Date></BIOS><HWID>10FF3207018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> Software licensing service version: 6.1.7601.17514 Name: Windows(R) 7, Ultimate edition Description: Windows Operating System - Windows(R) 7, RETAIL channel Activation ID: a0cde89c-3304-4157-b61c-c8ad785d1fad Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f Extended PID: 00426-00172-068-377868-00-1033-7601.0000-1362011 Installation ID: 006010737801467516469395225901796886806595684261918042 Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338 Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339 Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341 Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340 Partial Product Key: WDYTW License Status: Licensed Remaining Windows rearm count: 0 Trusted time: 5/1/2013 6:45:21 PM Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: N/A HealthStatus: 0x0000000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: NgAAAAEAAgABAAIAAgABAAAAAwABAAEA6GE+BdAqCIXCj4yp6JvOcPAXwo8qz9j7WiwomEbK OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes, but no SLIC table Windows marker version: N/A OEMID and OEMTableID Consistent: N/A BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC GBT GBTUACPI FACP GBT GBTUACPI HPET GBT GBTUACPI MCFG GBT GBTUACPI EUDS GBT TAMG GBT GBT B0 SSDT PmRef CpuPm
Wednesday, May 1, 2013 11:59 PM -
on the cbs.log file, the timestamp was older, I am not sure it creates one when it did not find issues?Thursday, May 2, 2013 2:55 AM
-
It does create the data but it may not be written to file immediately- which is why I ask for the reboot afterwards.
Your report is now showing as genuine :)
Please attempt validation at www.microsoft.com/genuine/validate using Internet Explorer - with luck you'll pass.
Post a final MGADiag report to double-check.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.- Marked as answer by rm17592 Thursday, May 2, 2013 5:03 PM
Thursday, May 2, 2013 6:13 AMModerator -
OK, here is the diag report. it looks good to me.
Again, thank you so much for all of your help with this!
Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Code: 0 Cached Online Validation Code: 0x0 Windows Product Key: *****-*****-9VDRQ-JVWWB-WDYTW Windows Product Key Hash: aU5vFdBvphKrvupqxpsLHdRvEM8= Windows Product ID: 00426-068-3778683-86639 Windows Product ID Type: 5 Windows License Type: Retail Windows OS version: 6.1.7601.2.00010100.1.0.001 ID: {9862DB61-C3C8-4547-9136-CCFF92FF2C6A}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Ultimate Architecture: 0x00000009 Build lab: 7601.win7sp1_gdr.130104-1431 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: <GenuineResults><MachineData><UGUID>{9862DB61-C3C8-4547-9136-CCFF92FF2C6A}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-WDYTW</PKey><PID>00426-068-3778683-86639</PID><PIDType>5</PIDType><SID>S-1-5-21-3163584284-2657221260-1632861152</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F10</Version><SMBIOSVersion major="2" minor="4"/><Date>20100205000000.000000+000</Date></BIOS><HWID>10FF3207018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> Spsys.log Content: 0x80070002 Licensing Data--> Software licensing service version: 6.1.7601.17514 Name: Windows(R) 7, Ultimate edition Description: Windows Operating System - Windows(R) 7, RETAIL channel Activation ID: a0cde89c-3304-4157-b61c-c8ad785d1fad Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f Extended PID: 00426-00172-068-377868-00-1033-7601.0000-1362011 Installation ID: 021144448572929413338966749346148784814996089030460783 Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338 Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339 Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341 Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340 Partial Product Key: WDYTW License Status: Licensed Remaining Windows rearm count: 0 Trusted time: 5/2/2013 10:43:42 AM Windows Activation Technologies--> HrOffline: 0x00000000 HrOnline: N/A HealthStatus: 0x0000000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: HWID Data--> HWID Hash Current: NgAAAAEAAgABAAIAAgABAAAAAwABAAEA6GE+BdAqCIXCj4ypznDom8KP8Bcqz9j7WiwomEbK OEM Activation 1.0 Data--> N/A OEM Activation 2.0 Data--> BIOS valid for OA 2.0: yes, but no SLIC table Windows marker version: N/A OEMID and OEMTableID Consistent: N/A BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC GBT GBTUACPI FACP GBT GBTUACPI HPET GBT GBTUACPI MCFG GBT GBTUACPI EUDS GBT TAMG GBT GBT B0 SSDT PmRef CpuPm
Thursday, May 2, 2013 2:44 PM -
It looks fine to me too :)
Have fun!
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
No - I do not work for Microsoft, or any of its contractors.Thursday, May 2, 2013 9:31 PMModerator