locked
Windows not Genuine Notice RRS feed

  • Question

  • On a Gateway NV 79 purchased at Best Buy, I have started receiving a Windows not genuine pop up.  Not sure what is causing it.  Have read through Windows 7 Genuine Advantage Validation Issues (Windows 7) thread & tried some of suggested solutions but to no avail.

    Any help is appreciated.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800006-02-1033-7601.0000-2222012
    Installation ID: 007332383173317421326466248293047701499831295165286955
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 7QJB7
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 8/10/2012 7:59:09 AM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000008000
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: LgAAAAEAAQABAAEAAAABAAAAAwABAAEA6GESl+ARuoMG+3j/tCd81hCPTs9cXQ==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, August 10, 2012 12:02 PM

Answers

  • Posting that link never works - it just means that I end up validating :)

    OK - it's time for a repair install then.....

    Download the SP1 Refresh for your language and edition from the links on these pages...

    http://www.heidoc.net/joomla/technology-science/microsoft

     

    The links are for downloads from the Digital River servers run for MS, so are about as safe as
    you can get :)

    Once you have it downloaded, you then need to burn the DVD from it - use either the Windows Disk Image Burner, or (better still) your favourite burning application at the slowest speed possible.

    Note that you do NOT 'drag and drop' the file to the disk, you must use the 'burn an image' option from your app - or you'll end up with a useless coaster :)

    Once you have the disk burnt, check that it boots the (or any other) system OK - but do NOT start the repair from there - you must start the repair from within a normal Windows boot.

    Follow the instructions in this tutorial - http://www.sevenforums.com/tutorials/3413-repair-install.html?ltr=R
    - and they should help you get through it (it's not as difficult as it looks!)

    Always ask questions first if you're unsure - either here, or in sevenforums.

    Good luck with it!



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 12, 2012 11:40 AM
    Moderator

All replies

  • You have a unique combination of errors:-

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514], Hr = 0x800b0100

    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui

    I don't recall ever having seen it before.

     

    Please run a full CHKDSK and SFC scan....

     type in the Search box

     

     CMD.EXE

     

     right-click on the only file that is found

     Select Run as Administrator

     - the Elevated Command Prompt window should pop up

     At the Command prompt, type

     

     CHKDSK C: /R

     

     and hit the Enter key.

     

     

     You will be told that the drive is locked,

     and the CHKDSK will run at he next boot - hit the Y key, and then reboot.

     

     

     The chkdsk will take a few hours depending on the size  of the drive, so be patient!

     

     After the CHKDSK has run, Windows should boot normally  (possibly after a second auto-reboot) - then run the SFC

     

     

     SFC -System File Checker - Instructions

     Click on the Start button

     type in the Search box

     

     CMD.EXE

     

     right-click on the only file that is found

      Select Run as Administrator - the Elevated Command Prompt window should pop up

     At the Command prompt, type

     

     SFC /SCANNOW

     

     and hit the Enter key

     

     Wait for the scan to finish - make a note of any error messages - and then reboot.

      Post an MGADiag report with details of any error messages encountered.     


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 10, 2012 1:35 PM
    Moderator
  • Ran all of the diagnostics and utilities. Copied the results:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>SFC /SCANNOW

    Beginning system scan.  This process will take some time.

    Beginning verification phase of system scan.
    Verification 100% complete.

    Windows Resource Protection did not find any integrity violations.

    Posted is the second MGADiag report:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800006-02-1033-7601.0000-2222012
    Installation ID: 007332383173317421326466248293047701499831295165286955
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 7QJB7
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 8/10/2012 3:16:24 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000008000
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: LgAAAAEAAQABAAEAAAABAAAAAwABAAEA6GESl+ARuoMG+3j/tCd81hCPTs9cXQ==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, August 10, 2012 7:22 PM
  • Odd - I'd have expected the File mismatch to have produced an error in the SFC scan.

    Lets take a closer look.....

    Please open an Elevated COmmand Prompt, and run the following commands

    DIR C:\Windows\System32\user32.* /S

    DIR C:\Windows\System32\sppsvc.* /S

    ICACLS C:\Windows\System32\user32.* /T

    ICACLS C:\Windows\System32\sppsvc.* /T

    DIR C:\Windows\SysWOW64\user32.* /S

    ICACLS C:\Windows\SysWOW64\user32.* /T

    Post the results


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


    Friday, August 10, 2012 7:50 PM
    Moderator
  • Results of the most recent diagnostics

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\System32\user32.* /S
     Volume in drive C is Hal
     Volume Serial Number is 2440-87FB

     Directory of C:\Windows\System32

    04/19/2011  03:11 PM         1,008,128 user32.dll
                   1 File(s)      1,008,128 bytes

     Directory of C:\Windows\System32\en-US

    04/19/2011  03:12 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\System32\manifeststore

    04/19/2011  03:12 PM           342,524 user32.amx
                   1 File(s)        342,524 bytes

         Total Files Listed:
                   3 File(s)      1,368,572 bytes
                   0 Dir(s)  269,847,162,880 bytes free

    C:\Windows\system32>DIR C:\Windows\System32\sppsvc.* /S
     Volume in drive C is Hal
     Volume Serial Number is 2440-87FB

     Directory of C:\Windows\System32

    04/19/2011  03:13 PM         3,524,608 sppsvc.exe
                   1 File(s)      3,524,608 bytes

     Directory of C:\Windows\System32\en-US

    07/13/2009  10:26 PM            18,944 sppsvc.exe.mui
                   1 File(s)         18,944 bytes

         Total Files Listed:
                   2 File(s)      3,543,552 bytes
                   0 Dir(s)  269,847,134,208 bytes free

    C:\Windows\system32>ICACLS C:\Windows\System32\user32.* /T
    C:\Windows\System32\user32.dll NT SERVICE\TrustedInstaller:(F)
                                   BUILTIN\Administrators:(RX)
                                   NT AUTHORITY\SYSTEM:(RX)
                                   BUILTIN\Users:(RX)

    C:\Windows\System32\en-US\user32.dll.mui NT SERVICE\TrustedInstaller:(F)
                                             BUILTIN\Administrators:(RX)
                                             NT AUTHORITY\SYSTEM:(RX)
                                             BUILTIN\Users:(RX)

    C:\Windows\System32\manifeststore\user32.amx NT SERVICE\TrustedInstaller:(F)
                                                 BUILTIN\Administrators:(RX)
                                                 NT AUTHORITY\SYSTEM:(RX)
                                                 BUILTIN\Users:(RX)

    Successfully processed 3 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\sppsvc.* /T
    C:\Windows\System32\sppsvc.exe NT SERVICE\TrustedInstaller:(F)
                                   BUILTIN\Administrators:(RX)
                                   NT AUTHORITY\SYSTEM:(RX)
                                   BUILTIN\Users:(RX)

    C:\Windows\System32\en-US\sppsvc.exe.mui NT SERVICE\TrustedInstaller:(F)
                                             BUILTIN\Administrators:(RX)
                                             NT AUTHORITY\SYSTEM:(RX)
                                             BUILTIN\Users:(RX)

    Successfully processed 2 files; Failed processing 0 files

    C:\Windows\system32>DIR C:\Windows\SysWOW64\user32.* /S
     Volume in drive C is Hal
     Volume Serial Number is 2440-87FB

     Directory of C:\Windows\SysWOW64

    04/19/2011  03:12 PM           833,024 user32.dll
                   1 File(s)        833,024 bytes

     Directory of C:\Windows\SysWOW64\en-US

    04/19/2011  03:13 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\SysWOW64\manifeststore

    04/19/2011  03:13 PM           367,164 user32.amx
                   1 File(s)        367,164 bytes

         Total Files Listed:
                   3 File(s)      1,218,108 bytes
                   0 Dir(s)  269,846,863,872 bytes free

    C:\Windows\system32>ICACLS C:\Windows\SysWOW64\user32.* /T
    C:\Windows\SysWOW64\user32.dll NT SERVICE\TrustedInstaller:(F)
                                   BUILTIN\Administrators:(RX)
                                   NT AUTHORITY\SYSTEM:(RX)
                                   BUILTIN\Users:(RX)

    C:\Windows\SysWOW64\en-US\user32.dll.mui NT SERVICE\TrustedInstaller:(F)
                                             BUILTIN\Administrators:(RX)
                                             NT AUTHORITY\SYSTEM:(RX)
                                             BUILTIN\Users:(RX)

    C:\Windows\SysWOW64\manifeststore\user32.amx NT SERVICE\TrustedInstaller:(F)
                                                 BUILTIN\Administrators:(RX)
                                                 NT AUTHORITY\SYSTEM:(RX)
                                                 BUILTIN\Users:(RX)

    Successfully processed 3 files; Failed processing 0 files

    C:\Windows\system32>

    Friday, August 10, 2012 10:18 PM
  • There's definitely something odd about the user32.dll files - but one is the same as on my 'vanilla' updated VM from an SP1 install (but not the 'live' one from an RTM install) - this is confusing me!!

    There must be an update (or part of a later patch) that's come down for that which isn't on my main install.

    Please run the following commands - it may tell us something.

    DIR C:\Windows\WinSxS\user32.* /S

    SFC /SCANFILE=C:\windows\system32\user32.dll

    post the results.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 10, 2012 10:41 PM
    Moderator
  • Thanks for all the help.

    Results follow:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>DIR C:\Windows\WinSxS\user32.* /S
     Volume in drive C is Hal
     Volume Serial Number is 2440-87FB

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-a..structure-manifests_3
    1bf3856ad364e35_6.1.7600.16385_none_f9c056b9cd0366f5

    07/13/2009  07:38 PM           342,512 user32.amx
                   1 File(s)        342,512 bytes

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-a..structure-manifests_3
    1bf3856ad364e35_6.1.7601.17514_none_fbf16a81c9f1ea8f

    04/19/2011  03:12 PM           342,524 user32.amx
                   1 File(s)        342,524 bytes

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-user32.resources_31bf385
    6ad364e35_6.1.7600.16385_en-us_99f2e97144ce40b4

    07/13/2009  10:26 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-user32.resources_31bf385
    6ad364e35_6.1.7601.17514_en-us_9c23fd3941bcc44e

    04/19/2011  03:12 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_
    6.1.7600.16385_none_292d5de8870d85d9

    07/13/2009  09:41 PM         1,008,640 user32.dll
                   1 File(s)      1,008,640 bytes

     Directory of C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_
    6.1.7601.17514_none_2b5e71b083fc0973

    04/19/2011  03:11 PM         1,008,128 user32.dll
                   1 File(s)      1,008,128 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-a..structure-manifests_3
    1bf3856ad364e35_6.1.7600.16385_none_0415010c016428f0

    07/13/2009  07:25 PM           367,152 user32.amx
                   1 File(s)        367,152 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-a..structure-manifests_3
    1bf3856ad364e35_6.1.7601.17514_none_064614d3fe52ac8a

    04/19/2011  03:13 PM           367,164 user32.amx
                   1 File(s)        367,164 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-user32.resources_31bf385
    6ad364e35_6.1.7600.16385_en-us_a44793c3792f02af

    07/13/2009  10:03 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-user32.resources_31bf385
    6ad364e35_6.1.7601.17514_en-us_a678a78b761d8649

    04/19/2011  03:13 PM            17,920 user32.dll.mui
                   1 File(s)         17,920 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_
    6.1.7600.16385_none_3382083abb6e47d4

    07/13/2009  09:11 PM           833,024 user32.dll
                   1 File(s)        833,024 bytes

     Directory of C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_
    6.1.7601.17514_none_35b31c02b85ccb6e

    04/19/2011  03:12 PM           833,024 user32.dll
                   1 File(s)        833,024 bytes

         Total Files Listed:
                  12 File(s)      5,173,848 bytes
                   0 Dir(s)  269,570,883,584 bytes free

    C:\Windows\system32>SFC /SCANFILE=C:\windows\system32\user32.dll


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>

    Friday, August 10, 2012 11:12 PM
  • I think I know what may be going on here - and it's nothing to worry about (I hope!!)

    It's simply a difference in the source of the updated files when installing SP1.

    Please run the following commands

    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\APITracing"

    REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\APITracing"

    REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\System\USER32"

    REG QUERY "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs"

    post the results - hopfully that will show some kind of error.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 10, 2012 11:47 PM
    Moderator
  • Next set of results:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Users\Liu>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\APITra
    cing"

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\APITracing
        LogFileDirectory    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\A
    PITracing
        InstalledManifests    REG_MULTI_SZ    %windir%\system32\manifeststore\advapi
    32.amx\0%windir%\system32\manifeststore\gdi32.amx\0%windir%\system32\manifeststo
    re\kernel32.amx\0%windir%\system32\manifeststore\kernelbase.amx\0%windir%\system
    32\manifeststore\user32.amx
        LogApiNamesOnly    REG_DWORD    0x0
        LogApisRecursively    REG_DWORD    0x0
        EnableSequentialLog    REG_DWORD    0x0
        MaximumLogFileSize    REG_DWORD    0x0
        LogFileName    REG_SZ
        IncludeModules    REG_MULTI_SZ    advapi32.dll\0gdi32.dll\0kernel32.dll\0ker
    nelbase.dll\0user32.dll
        IncludeApis    REG_MULTI_SZ
        ExcludeApis    REG_MULTI_SZ


    C:\Users\Liu>REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVe
    rsion\APITracing"

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\APIT
    racing
        LogFileDirectory    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\A
    PITracing
        InstalledManifests    REG_MULTI_SZ    %windir%\syswow64\manifeststore\advapi
    32.amx\0%windir%\syswow64\manifeststore\gdi32.amx\0%windir%\syswow64\manifeststo
    re\kernel32.amx\0%windir%\syswow64\manifeststore\kernelbase.amx\0%windir%\syswow
    64\manifeststore\user32.amx
        LogApiNamesOnly    REG_DWORD    0x0
        LogApisRecursively    REG_DWORD    0x0
        EnableSequentialLog    REG_DWORD    0x0
        MaximumLogFileSize    REG_DWORD    0x0
        LogFileName    REG_SZ
        IncludeModules    REG_MULTI_SZ    advapi32.dll\0gdi32.dll\0kernel32.dll\0ker
    nelbase.dll\0user32.dll
        IncludeApis    REG_MULTI_SZ
        ExcludeApis    REG_MULTI_SZ


    C:\Users\Liu>REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\System\U
    SER32"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\USER32
        EventMessageFile    REG_EXPAND_SZ    %SystemRoot%\System32\user32.dll
        TypesSupported    REG_DWORD    0x7


    C:\Users\Liu>REG QUERY "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kn
    ownDLLs"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs
        clbcatq    REG_SZ    clbcatq.dll
        ole32    REG_SZ    ole32.dll
        advapi32    REG_SZ    advapi32.dll
        COMDLG32    REG_SZ    COMDLG32.dll
        DllDirectory    REG_EXPAND_SZ    %SystemRoot%\system32
        DllDirectory32    REG_EXPAND_SZ    %SystemRoot%\syswow64
        gdi32    REG_SZ    gdi32.dll
        IERTUTIL    REG_SZ    IERTUTIL.dll
        IMAGEHLP    REG_SZ    IMAGEHLP.dll
        IMM32    REG_SZ    IMM32.dll
        kernel32    REG_SZ    kernel32.dll
        LPK    REG_SZ    LPK.dll
        MSCTF    REG_SZ    MSCTF.dll
        MSVCRT    REG_SZ    MSVCRT.dll
        NORMALIZ    REG_SZ    NORMALIZ.dll
        NSI    REG_SZ    NSI.dll
        OLEAUT32    REG_SZ    OLEAUT32.dll
        PSAPI    REG_SZ    PSAPI.DLL
        rpcrt4    REG_SZ    rpcrt4.dll
        sechost    REG_SZ    sechost.dll
        Setupapi    REG_SZ    Setupapi.dll
        SHELL32    REG_SZ    SHELL32.dll
        SHLWAPI    REG_SZ    SHLWAPI.dll
        URLMON    REG_SZ    URLMON.dll
        user32    REG_SZ    user32.dll
        USP10    REG_SZ    USP10.dll
        WININET    REG_SZ    WININET.dll
        WLDAP32    REG_SZ    WLDAP32.dll
        WS2_32    REG_SZ    WS2_32.dll
        DifxApi    REG_SZ    difxapi.dll


    C:\Users\Liu>

    Friday, August 10, 2012 11:55 PM
  • I can't see anything amiss there.

    I'll have to sleep on it (it's 1 a.m. here) -- I'll have a new set of instructtions for you tomorrow (we'll try looking for the other error)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 12:08 AM
    Moderator
  • OK - lets see what we can find....

    Please open an Elevated Command prompt and run the following commands...

    SFC /SCANFILE=C:\Windows\System32\en-US\user32.dll.mui
    DIR C:\Windows\System32\sppsvc.* /S
    ICACLS C:\Windows\System32\sppsvc.* /T
    REG QUERY HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules /v SPPSVC-In-TCP-NoScope
    REG QUERY HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules /v SPPSVC-In-TCP
    REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Software Protection Platform Service" 
    
    Copy and paste the results to your reply, and we'll see what we can see.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 9:19 AM
    Moderator
  • New results for latest diagnostics:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Users\Liu>SFC /SCANFILE=C:\Windows\System32\en-US\user32.dll.mui

    You must be an administrator running a console session in order to
    use the sfc utility.

    C:\Users\Liu>DIR C:\Windows\System32\sppsvc.* /S
     Volume in drive C is Hal
     Volume Serial Number is 2440-87FB

     Directory of C:\Windows\System32

    04/19/2011  03:13 PM         3,524,608 sppsvc.exe
                   1 File(s)      3,524,608 bytes

     Directory of C:\Windows\System32\en-US

    07/13/2009  10:26 PM            18,944 sppsvc.exe.mui
                   1 File(s)         18,944 bytes

         Total Files Listed:
                   2 File(s)      3,543,552 bytes
                   0 Dir(s)  269,277,032,448 bytes free

    C:\Users\Liu>ICACLS C:\Windows\System32\sppsvc.* /T
    C:\Windows\System32\sppsvc.exe NT SERVICE\TrustedInstaller:(F)
                                   BUILTIN\Administrators:(RX)
                                   NT AUTHORITY\SYSTEM:(RX)
                                   BUILTIN\Users:(RX)

    C:\Windows\System32\com\dmp\sppsvc.*: Access is denied.
    Successfully processed 1 files; Failed processing 1 files

    C:\Users\Liu>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Param
    eters\FirewallPolicy\FirewallRules /v SPPSVC-In-TCP-NoScope


    ERROR: The system was unable to find the specified registry key or value.

    C:\Users\Liu>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Param
    eters\FirewallPolicy\FirewallRules /v SPPSVC-In-TCP


    ERROR: The system was unable to find the specified registry key or value.

    C:\Users\Liu>REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\Applicat
    ion\Software Protection Platform Service"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Softwa
    re Protection Platform Service
        EventMessageFile    REG_EXPAND_SZ    %windir%\system32\sppsvc.exe
        TypesSupported    REG_DWORD    0x7
        ProviderGuid    REG_SZ    {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}


    C:\Users\Liu>

    Saturday, August 11, 2012 1:06 PM
  • You have a couple of potential problems there - but they may be because of third-party software, rather than anything else.

    What firewall are you using? - the Windows one, or a third-party offering of some kind?

    Also, I this error  -

    C:\Windows\System32\com\dmp\sppsvc.*: Access is denied.

    Which is probably caused by the fact that you aren't running the queries in Elevated mode as requested.

    Please run the following commands in an Elevated Command Prompt window.....

    SFC /SCANFILE=C:\Windows\System32\en-US\user32.dll.mui

    ICACLS C:\Windows\System32\sppsvc.* /T

    SFC /SCANFILE=C:\Windows\System32\en-US\sppsvc.exe.mui

     

    (I would still expect an error in the second reponse - but in a different place)

    Here are some instructions to make life easier, and ensure that we're singing from the same page.  :)

    1) To open an Elevated Command Prompt Window (the CP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt. 

    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Windows, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once. 

    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.     



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 1:54 PM
    Moderator
  • Sorry, didn't realize there was a difference.  I'm using McAfee for my virus & firewall. 

    Next results follow:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>SFC /SCANFILE=C:\Windows\System32\en-US\user32.dll.mui


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>ICACLS C:\Windows\System32\sppsvc.* /T
    C:\Windows\System32\sppsvc.exe NT SERVICE\TrustedInstaller:(F)
                                   BUILTIN\Administrators:(RX)
                                   NT AUTHORITY\SYSTEM:(RX)
                                   BUILTIN\Users:(RX)

    C:\Windows\System32\en-US\sppsvc.exe.mui NT SERVICE\TrustedInstaller:(F)
                                             BUILTIN\Administrators:(RX)
                                             NT AUTHORITY\SYSTEM:(RX)
                                             BUILTIN\Users:(RX)

    Successfully processed 2 files; Failed processing 0 files

    C:\Windows\system32>SFC /SCANFILE=C:\Windows\System32\en-US\sppsvc.exe.mui


    Windows Resource Protection did not find any integrity violations.

    C:\Windows\system32>

    Saturday, August 11, 2012 2:31 PM
  • As far as I can tell, even with the Windows Firewall switched off, the expected registry values should still be there.

    Have you been using any form of Registry Cleaner? (DON'T!)

    REG QUERY HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules /t REG_SZ

    Having said that, simply removing those two entries from the registry doesn't cause a problem in my machine

    Have you recently updated McAfee, or changed to McAfee from a different AV supplier? - What other AV's have ever been installed?

    There's no need to post the result on this one - I simply need to know how many occurences there are (which should be the last line of the report)


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 3:06 PM
    Moderator
  • Answers to your queries:

    Don't run stand alone registry cleaners. (Can't speak to my virus scans etc.)

    I've used McAfee since I got my computer 3-4 yrs ago and it updates automatically.

    My sister just used CCleaner recently on my system (last 2-3 days)

    Finally, there were 437 match(es) found

    Saturday, August 11, 2012 3:29 PM
  • CCLeaner contains a Registry Cleaner :(

    When the system arrived, did it already have McAfee installed?

    This type of error is sometimes caused by conflicts between an AV and residuals of previous AV's (in the case of Norton and McAfee, even earlier versions of the same AV!).

    Let's eliminate that by uninstalling McAfee temporarily, and running the  MCPR.

    Download the MCPR tool from here, first ...

    http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe

    Also download a new installer for your version of McAfee and make sure that you have your registration/activation details backed up and accessible.

    Disconnect from the internet

    Uninstall McAfee uisng the Programs & Features entry

    Reboot.

    Now run the MCPR tool - it may reboot the system itself during the run.

    Once complete, reboot the system again.

    Now reinstall McAfee, and tehn re-connect to the inernet and update it.

    Run a new MGADiag report and post the results.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 3:51 PM
    Moderator
  • I pretty sure my pc came with a different AV.

    Since I already had an account with McAfee, I used that instead of activating the one on the pc.

    The MGADiag report follows:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800006-02-1033-7601.0000-2222012
    Installation ID: 007332383173317421326466248293047701499831295165286955
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 7QJB7
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 8/11/2012 1:07:04 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000008000
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: LgAAAAEAAQABAAEAAAABAAAAAwABAAEA6GESl+ARuoMG+3j/tCd81hCPTs9cXQ==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Saturday, August 11, 2012 5:09 PM
  • Hmm - Gateway/Acer have a habot of changing their bundled AV - so it could be Norton or something very different. Are there any clues in the Program Files or Program Files (86) folders as to what it may have been?)

    No change in the report, by the way :(


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 6:09 PM
    Moderator
  • I'm pretty sure it was Norton that came on the pc.

    Saturday, August 11, 2012 6:12 PM
  • The worst possible combination!

    Download the Norton Removal Tool from here https://www-secure.symantec.com/norton-support/jsp/help-solutions.jsp?lg=english&ct=united+states&docid=20080710133834EN&product=home&version=1&pvid=f-home

     

    Close all other programs, then run the tool. When it's complete, reboot the machine  whether it asks for it or not.

    post another MGADiag report

     

     

     

     

     

     

     


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Saturday, August 11, 2012 7:05 PM
    Moderator
  • MGADiags after running Norton Removal Tool

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-WJ2H8-R6B6D-7QJB7
    Windows Product Key Hash: ckKNc+BBPDWmo1LUlOkraNjlQ34=
    Windows Product ID: 00359-OEM-8992687-00006
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-7QJB7</PKey><PID>00359-OEM-8992687-00006</PID><PIDType>2</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800006-02-1033-7601.0000-2222012
    Installation ID: 007332383173317421326466248293047701499831295165286955
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 7QJB7
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 8/11/2012 10:05:39 PM

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000008000
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


    HWID Data-->
    HWID Hash Current: LgAAAAEAAQABAAEAAAABAAAAAwABAAEA6GESl+ARuoMG+3j/tCd81hCPTs9cXQ==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Sunday, August 12, 2012 2:06 AM
  • OK - what happens if you now visit validation - www.microsoft.com/genuine/validate - using Internet Explorer, or Chrome.

    (there's no change in the report)

    I'm beginning to think in terms of a repair install here - which means that you'd have to download the proper ISO file and create a disk from it.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 12, 2012 9:42 AM
    Moderator
  • After running the program, I am taken to the following screen where I am asked to either buy Windows or troubleshoot it.
    Sunday, August 12, 2012 11:22 AM
  • Posting that link never works - it just means that I end up validating :)

    OK - it's time for a repair install then.....

    Download the SP1 Refresh for your language and edition from the links on these pages...

    http://www.heidoc.net/joomla/technology-science/microsoft

     

    The links are for downloads from the Digital River servers run for MS, so are about as safe as
    you can get :)

    Once you have it downloaded, you then need to burn the DVD from it - use either the Windows Disk Image Burner, or (better still) your favourite burning application at the slowest speed possible.

    Note that you do NOT 'drag and drop' the file to the disk, you must use the 'burn an image' option from your app - or you'll end up with a useless coaster :)

    Once you have the disk burnt, check that it boots the (or any other) system OK - but do NOT start the repair from there - you must start the repair from within a normal Windows boot.

    Follow the instructions in this tutorial - http://www.sevenforums.com/tutorials/3413-repair-install.html?ltr=R
    - and they should help you get through it (it's not as difficult as it looks!)

    Always ask questions first if you're unsure - either here, or in sevenforums.

    Good luck with it!



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 12, 2012 11:40 AM
    Moderator
  • Thanks, I'll finish the repair when I get back home next week.  Appreciate the help.
    Sunday, August 12, 2012 11:59 AM
  • You're welcome - I'm just sorry we couldn't pinpoint the problem and solve it that way.

    Let us know how you get on?


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 12, 2012 12:29 PM
    Moderator
  • Finally able to finish repair install & everything is good to go.

    Unfortunately, when Windows updated, all updates were completed except for Microsoft Silverlight.

    When I tried to uninstall ver. 4.1.10111.0 and upgrade to ver. 5.1.10411.0 a pop up tells me to: "Insert the 'Microsoft Silverlight' disc and click OK.'  I cannot continue because I know that I did not install from a disc.

    I'm hoping this is a minor problem but I would like to correct all of the errors on my system.

    Friday, August 24, 2012 2:41 PM
  • That error usually means that the uninstaller is missing, or the registry is pointing to the wrong place - unfortunately that's off-topic for this forum (and I have no clear idea how to fix it anyhow!), so your best bet is to post that query in the Answers forum here....

    http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_programs 

    Someone there should be able to help with that.

    Can you please post a new MGADiag report, so we can sign off on a high note?

    Good luck, either way.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 24, 2012 2:57 PM
    Moderator
  • Thanks for all your help!  MGADiag report follows:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-7QDF9-B648Q-QWK73
    Windows Product Key Hash: OL94JWGRvJBX/L3+iDV8Wp6YgLI=
    Windows Product ID: 00359-OEM-9804167-30394
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-QWK73</PKey><PID>00359-OEM-9804167-30394</PID><PIDType>8</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-041-630394-02-1033-7601.0000-2362012
    Installation ID: 012500251812610275064141758362021315714604896650212630
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: QWK73
    License Status: Initial grace period
    Time remaining: 42180 minute(s) (29 day(s))
    Remaining Windows rearm count: 3
    Trusted time: 8/24/2012 11:58:55 AM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 8:24:2012 10:33
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEAAQABAAEAAAACAAAAAwABAAEA6GESl+ARuoMG+3j/tCc5enzWEI9Oz1xd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, August 24, 2012 3:59 PM
  • Just as well I asked - it's still not been activated (although I don't see any good reson why it shouldn't)

    which may be why you're getting a problem with Silverlight!

    Activate by Internet first.

    If that fails, try telephone activate using the automated service

    if that fails, speak to an operator...

     

    telephone activation (operator calls)

     Click on the Start button

    in the Search box, type

    SLUI 4

     and hit the Enter key

    follow the instructions, but when asked which service you require by the telephone ansafone, do NOT reply - this should force an operator to respond, who can deal with you 


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 24, 2012 4:29 PM
    Moderator
  • Activating via internet took me to a 'Genuine Microsoft Software' website welcome screen.
    Friday, August 24, 2012 5:08 PM
  • Duh? Which one?

    Did you get any 'you are activated' screen?

    Please post a new  MGADIag report, after validating a www.microsoft.com/genuine/validate


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 24, 2012 5:17 PM
    Moderator
  • Just clicked on one of the previous links you gave me (Sunday, August 12, 2012 9:42 AM)

    MGADiags follows:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-7QDF9-B648Q-QWK73
    Windows Product Key Hash: OL94JWGRvJBX/L3+iDV8Wp6YgLI=
    Windows Product ID: 00359-OEM-9804167-30394
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-QWK73</PKey><PID>00359-OEM-9804167-30394</PID><PIDType>8</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-041-630394-02-1033-7601.0000-2362012
    Installation ID: 012500251812610275064141758362021315714604896650212630
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: QWK73
    License Status: Initial grace period
    Time remaining: 42060 minute(s) (29 day(s))
    Remaining Windows rearm count: 3
    Trusted time: 8/24/2012 1:55:48 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 8:24:2012 13:53
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEAAQABAAEAAAACAAAAAwABAAEA6GESl+ARuoMG+3j/tCc5enzWEI9Oz1xd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, August 24, 2012 5:56 PM
  • Still not activated -

    use telephone activation


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 24, 2012 6:03 PM
    Moderator
  • Completed telephone activation, no errors messages.  Reran MGADiags:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-7QDF9-B648Q-QWK73
    Windows Product Key Hash: OL94JWGRvJBX/L3+iDV8Wp6YgLI=
    Windows Product ID: 00359-OEM-9804167-30394
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {4F7C0F1A-C342-4893-A7A6-E627E49D08DA}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F7C0F1A-C342-4893-A7A6-E627E49D08DA}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-QWK73</PKey><PID>00359-OEM-9804167-30394</PID><PIDType>8</PIDType><SID>S-1-5-21-1664600048-2465571457-1835019024</SID><SYSTEM><Manufacturer>Gateway         </Manufacturer><Model>NV79            </Model></SYSTEM><BIOS><Manufacturer>Gateway         </Manufacturer><Version>V1.00</Version><SMBIOSVersion major="2" minor="6"/><Date>20091113000000.000000+000</Date></BIOS><HWID>639F3107018400FC</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>6F1221DD023DF18</Val><Hash>srWoGs2aWTEhShufCiMUSrbqPSo=</Hash><Pid>81602-908-0789515-68092</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-041-630394-02-1033-7601.0000-2362012
    Installation ID: 012500251812610275064141758362021315714604896650212630
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: QWK73
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 8/24/2012 3:57:56 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 8:24:2012 13:53
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEAAQABAAEAAAACAAAAAwABAAEA6GESl+ARuoMG+3j/tCc5enzWEI9Oz1xd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            ACRSYS        ACRPRDCT
      FACP            ACRSYS        ACRPRDCT
      HPET            ACRSYS        ACRPRDCT
      BOOT            ACRSYS        ACRPRDCT
      MCFG            ACRSYS        ACRPRDCT
      WDRT            ACRSYS        ACRPRDCT
      ASF!            ACRSYS        ACRPRDCT
      SLIC            ACRSYS        ACRPRDCT
      ASPT            ACRSYS        ACRPRDCT
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm
      SSDT            PmRef        CpuPm

    Friday, August 24, 2012 7:59 PM
  • Bingo!

    We have a winner :)

    You're good to go.

    Have fun.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Friday, August 24, 2012 8:20 PM
    Moderator