locked
Message says "Windows not genuine" but it is and everything else works fine RRS feed

  • Question

  • The windows activation works fine. Windows updates and Security Essentials also. Are critical windows files damaged? Can I restore without loosing everything else in the computer?

    Diagnostic Report (1.9.0027.0):

    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-24DY8-P7WHF-D2YRM
    Windows Product Key Hash: Xr8+EEGI3BHnrWVSXHZUH8yQ8Oo=
    Windows Product ID: 00359-OEM-9804437-97970
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {F58BC3AD-2E1E-4353-AB9A-3370F970CE39}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130801-1533
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 114 Blocked VLK 2
    Microsoft Office Professional Edition 2003 - 114 Blocked VLK 2
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Georgios\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{F58BC3AD-2E1E-4353-AB9A-3370F970CE39}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-D2YRM</PKey><PID>00359-OEM-9804437-97970</PID><PIDType>8</PIDType><SID>S-1-5-21-4241730073-2239099615-3908753796</SID><SYSTEM><Manufacturer>Sony Corporation</Manufacturer><Model>VPCEB1J1E</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>R0300Y8</Version><SMBIOSVersion major="2" minor="6"/><Date>20100720000000.000000+000</Date></BIOS><HWID>EE0A3E07018400FC</HWID><UserLCID>0408</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GTB Standard Time(GMT+02:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>Sony</OEMID><OEMTableID>VAIO</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>114</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>114</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>59D1605114E3500</Val><Hash>vfZmaSmFPIYrLWTcZSZErUQg+Fo=</Hash><Pid>73931-640-0000106-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="114"/><App Id="16" Version="11" Result="114"/><App Id="18" Version="11" Result="114"/><App Id="19" Version="11" Result="114"/><App Id="1A" Version="11" Result="114"/><App Id="1B" Version="11" Result="114"/><App Id="44" Version="11" Result="114"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-044-397970-02-1032-7601.0000-2952013
    Installation ID: 009265336195357203567944384002258182284205258791952894
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: D2YRM
    License Status: Licensed
    Remaining Windows rearm count: 0
    Trusted time: 26/10/2013 7:53:49 μμ

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000004040
    Event Time Stamp: 10:25:2013 19:28
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAABAAAAAgABAAEA6GEalhJp+kVSxx7uerdGKlhLju725Fxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC Sony VAIO
      FACP Sony VAIO
      HPET Sony VAIO
      MCFG Sony VAIO
      SLIC Sony VAIO
      SSDT Sony VAIO
      SSDT Sony VAIO

    Saturday, October 26, 2013 4:59 PM

Answers

  • Thank you very mach for your effort help. I will backup.
    • Marked as answer by George Chris Tuesday, October 29, 2013 5:06 PM
    Monday, October 28, 2013 3:02 PM

All replies

  • HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui

    Please run a full CHKDSK and SFC scan....

     

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     

    At the Command prompt, type

     

    CHKDSK C: /R

     

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.

     

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

     

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -

    then run the SFC.

     

    SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     

    At the Command prompt, type

     

    SFC /SCANNOW

     

    and hit the Enter key

     

    Wait for the scan to finish - make a note of any error messages - and then reboot.

     

     

    Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive Public folder (http://skydrive.live.com ) and post a link to it so that I can take a look.

     

    Post a new MGADiag report with details of any error messages encountered.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Saturday, October 26, 2013 9:51 PM
    Moderator
  • Thank you for your answer.

    Here is a link to the CBS.log : https://www.dropbox.com/s/6q4h8l6xqclmjno/CBS.zip (it is not skydrive but I hope dropbox will work too).

    Below is a new MGADiag report.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-24DY8-P7WHF-D2YRM
    Windows Product Key Hash: Xr8+EEGI3BHnrWVSXHZUH8yQ8Oo=
    Windows Product ID: 00359-OEM-9804437-97970
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {F58BC3AD-2E1E-4353-AB9A-3370F970CE39}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130801-1533
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 114 Blocked VLK 2
    Microsoft Office Professional Edition 2003 - 114 Blocked VLK 2
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Georgios\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{F58BC3AD-2E1E-4353-AB9A-3370F970CE39}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-D2YRM</PKey><PID>00359-OEM-9804437-97970</PID><PIDType>8</PIDType><SID>S-1-5-21-4241730073-2239099615-3908753796</SID><SYSTEM><Manufacturer>Sony Corporation</Manufacturer><Model>VPCEB1J1E</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>R0300Y8</Version><SMBIOSVersion major="2" minor="6"/><Date>20100720000000.000000+000</Date></BIOS><HWID>EE0A3E07018400FC</HWID><UserLCID>0408</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GTB Standard Time(GMT+02:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>Sony</OEMID><OEMTableID>VAIO</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>114</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>114</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>59D1605114E3500</Val><Hash>vfZmaSmFPIYrLWTcZSZErUQg+Fo=</Hash><Pid>73931-640-0000106-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="114"/><App Id="16" Version="11" Result="114"/><App Id="18" Version="11" Result="114"/><App Id="19" Version="11" Result="114"/><App Id="1A" Version="11" Result="114"/><App Id="1B" Version="11" Result="114"/><App Id="44" Version="11" Result="114"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-044-397970-02-1032-7601.0000-2952013
    Installation ID: 009265336195357203567944384002258182284205258791952894
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: D2YRM
    License Status: Licensed
    Remaining Windows rearm count: 0
    Trusted time: 27/10/2013 1:35:01 μμ

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000004040
    Event Time Stamp: 10:25:2013 18:28
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAABAAAAAgABAAEA6GEalhJp+kVSxx7uerdGKlhLju725Fxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC Sony VAIO
      FACP Sony VAIO
      HPET Sony VAIO
      MCFG Sony VAIO
      SLIC Sony VAIO
      SSDT Sony VAIO
      SSDT Sony VAIO

     
    Sunday, October 27, 2013 11:38 AM
  • DropBox is fine :)

    You have a fair number of file corruptions...

    	Line 46762: 2013-10-27 13:21:41, Info                  CSI    000003fe [SR] Repairing 27 (0x000000000000001b) components
    	Line 46763: 2013-10-27 13:21:41, Info                  CSI    000003ff [SR] Beginning Verify and Repair transaction
    	Line 46766: 2013-10-27 13:21:43, Info                  CSI    00000401 [SR] Cannot repair member file [l:30{15}]"NlsData0024.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46769: 2013-10-27 13:21:43, Info                  CSI    00000403 [SR] Cannot repair member file [l:30{15}]"NlsData0022.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46772: 2013-10-27 13:21:47, Info                  CSI    00000405 [SR] Cannot repair member file [l:36{18}]"Title_Page_PAL.wmv" of Microsoft-Windows-OpticalMediaDisc-Style-Performance, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46775: 2013-10-27 13:21:47, Info                  CSI    00000407 [SR] Cannot repair member file [l:36{18}]"Title_Page_Ref.wmv" of Microsoft-Windows-OpticalMediaDisc-Style-Pets, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46778: 2013-10-27 13:21:47, Info                  CSI    00000409 [SR] Cannot repair member file [l:70{35}]"SportsMainToNotesBackground_PAL.wmv" of Microsoft-Windows-OpticalMediaDisc-Style-Sports, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46781: 2013-10-27 13:21:48, Info                  CSI    0000040b [SR] Cannot repair member file [l:62{31}]"SportsMainToNotesBackground.wmv" of Microsoft-Windows-OpticalMediaDisc-Style-Sports, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46784: 2013-10-27 13:21:50, Info                  CSI    0000040d [SR] Cannot repair member file [l:18{9}]"mraut.dll" of Microsoft-Windows-TabletPC-MathRecognizer, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46787: 2013-10-27 13:21:50, Info                  CSI    0000040f [SR] Cannot repair member file [l:50{25}]"Microsoft.MediaCenter.dll" of Microsoft.MediaCenter, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_MSIL (8), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46790: 2013-10-27 13:21:50, Info                  CSI    00000411 [SR] Cannot repair member file [l:24{12}]"polstore.dll" of Microsoft-Windows-Network-Security-Domain-Clients-Svc, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46793: 2013-10-27 13:21:50, Info                  CSI    00000413 [SR] Cannot repair member file [l:14{7}]"P2P.dll" of Microsoft-Windows-PeerToPeerBase, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46796: 2013-10-27 13:21:50, Info                  CSI    00000415 [SR] Cannot repair member file [l:28{14}]"sppcommdlg.dll" of Microsoft-Windows-Security-SPP-UX, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46799: 2013-10-27 13:21:50, Info                  CSI    00000417 [SR] Cannot repair member file [l:44{22}]"SyncInfrastructure.dll" of Microsoft-Windows-SyncInfrastructure, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46802: 2013-10-27 13:21:50, Info                  CSI    00000419 [SR] Cannot repair member file [l:16{8}]"ole2.dll" of Microsoft-Windows-COM-LegacyOLE, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46805: 2013-10-27 13:21:50, Info                  CSI    0000041b [SR] Cannot repair member file [l:28{14}]"shellstyle.dll" of Microsoft-Windows-class_ss, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46808: 2013-10-27 13:21:50, Info                  CSI    0000041d [SR] Cannot repair member file [l:20{10}]"ogldrv.dll" of Microsoft-Windows-OpenGL-MSOGL, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46811: 2013-10-27 13:21:50, Info                  CSI    0000041f [SR] Cannot repair member file [l:20{10}]"objsel.dll" of Microsoft-Windows-Object-Picker, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46814: 2013-10-27 13:21:52, Info                  CSI    00000421 [SR] Cannot repair member file [l:38{19}]"NlsLexicons0816.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46817: 2013-10-27 13:21:54, Info                  CSI    00000423 [SR] Cannot repair member file [l:38{19}]"NlsLexicons0026.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46820: 2013-10-27 13:21:54, Info                  CSI    00000425 [SR] Cannot repair member file [l:24{12}]"p2pnetsh.dll" of Microsoft-Windows-PeerToPeerAdmin, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46823: 2013-10-27 13:21:54, Info                  CSI    00000427 [SR] Cannot repair member file [l:64{32}]"SystemPropertiesComputerName.exe" of Microsoft-Windows-SystemPropertiesComputerName, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46826: 2013-10-27 13:21:54, Info                  CSI    00000429 [SR] Cannot repair member file [l:24{12}]"spwizimg.dll" of Microsoft-Windows-Setup-Navigation-Wizard-Framework, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46829: 2013-10-27 13:21:54, Info                  CSI    0000042b [SR] Cannot repair member file [l:22{11}]"pidgenx.dll" of Microsoft-Windows-Security-SPP-PIDGenX, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46832: 2013-10-27 13:21:54, Info                  CSI    0000042d [SR] Cannot repair member file [l:22{11}]"sppcext.dll" of Microsoft-Windows-Security-SPP-ClientExt, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46835: 2013-10-27 13:21:54, Info                  CSI    0000042f [SR] Cannot repair member file [l:18{9}]"sppcc.dll" of Microsoft-Windows-Security-SPP-UX-SPPCC, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46838: 2013-10-27 13:21:54, Info                  CSI    00000431 [SR] Cannot repair member file [l:24{12}]"sxsstore.dll" of Microsoft-Windows-SxS-Store, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46841: 2013-10-27 13:21:54, Info                  CSI    00000433 [SR] Cannot repair member file [l:26{13}]"sqlceqp30.dll" of Microsoft-Windows-SQLLiteQP, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46844: 2013-10-27 13:21:54, Info                  CSI    00000435 [SR] Cannot repair member file [l:16{8}]"sort.exe" of Microsoft-Windows-Sort, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46847: 2013-10-27 13:21:54, Info                  CSI    00000437 [SR] Cannot repair member file [l:14{7}]"tdh.dll" of Microsoft-Windows-TraceDataHelper, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    	Line 46850: 2013-10-27 13:21:54, Info                  CSI    00000439 [SR] Cannot repair member file [l:24{12}]"thawbrkr.dll" of Microsoft-Windows-WordbreakerStemmer-Thai, Version = 7.0.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
    

    I'll post a fix protocol for them a bit later.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, October 27, 2013 12:42 PM
    Moderator
  • I've uploaded a file - gcsaa.zip - to my SkyDrive at Noel's SkyDrive

    Please download and save it.

    Right-click on the saved file and select Extract all...

    Change the target to C:\ and click on Extract

    Close all windows (it would be a good idea to print these
    instructions!)

    Now reboot to the Repair Environment - as soon as the machine restarts, start
    tapping F8 - this should bring up the Advanced Boot Menu, at the top of which
    should be the option 'Repair my Computer'

    Pick that

    You'll have to log in with your username and password.

    Pick the option to use a Command Prompt

    At the prompt type

    DIR C:\gcsaa

    hit the enter key - if you get a 'Not Found' error try

    DIR D:\gcsaa

    or

    DIR E:\gcsaa

     

    The drive letter in use when you find the folder will need to be substituted (for<drive>) into the following
    command...

     

    XCOPY <drive>:\gcsaa   <drive>:\windows\winsxs /y /i /s /v /h

     

    (e.g. XCOPY P:\wfire P:\windows\winsxs /y /i /s /v /h )

     

    run the command (it should take almost no time)and when the prompt returns, type

    EXIT

    and hit the Enter key to exit Command Prompt - reboot to Normal Mode Windows.

    Now run SFC /SCANNOW in an Elevated Command Prompt

    then reboot and upload the new CBS.log file to your SkyDrive Public folder, and
    post a new link

    Also run a new MGADiag report, and post the result.

     



    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, October 27, 2013 1:10 PM
    Moderator
  • Here are the new CBS log and MGADiag report:

    https://www.dropbox.com/s/9wovntjzaxkhj27/CBS_new.zip

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-24DY8-P7WHF-D2YRM
    Windows Product Key Hash: Xr8+EEGI3BHnrWVSXHZUH8yQ8Oo=
    Windows Product ID: 00359-OEM-9804437-97970
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {F58BC3AD-2E1E-4353-AB9A-3370F970CE39}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130801-1533
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 114 Blocked VLK 2
    Microsoft Office Professional Edition 2003 - 114 Blocked VLK 2
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Georgios\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{F58BC3AD-2E1E-4353-AB9A-3370F970CE39}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-D2YRM</PKey><PID>00359-OEM-9804437-97970</PID><PIDType>8</PIDType><SID>S-1-5-21-4241730073-2239099615-3908753796</SID><SYSTEM><Manufacturer>Sony Corporation</Manufacturer><Model>VPCEB1J1E</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>R0300Y8</Version><SMBIOSVersion major="2" minor="6"/><Date>20100720000000.000000+000</Date></BIOS><HWID>EE0A3E07018400FC</HWID><UserLCID>0408</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GTB Standard Time(GMT+02:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>Sony</OEMID><OEMTableID>VAIO</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>114</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>114</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>59D1605114E3500</Val><Hash>vfZmaSmFPIYrLWTcZSZErUQg+Fo=</Hash><Pid>73931-640-0000106-57766</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="114"/><App Id="16" Version="11" Result="114"/><App Id="18" Version="11" Result="114"/><App Id="19" Version="11" Result="114"/><App Id="1A" Version="11" Result="114"/><App Id="1B" Version="11" Result="114"/><App Id="44" Version="11" Result="114"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-044-397970-02-1032-7601.0000-2952013
    Installation ID: 009265336195357203567944384002258182284205258791952894
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: D2YRM
    License Status: Licensed
    Remaining Windows rearm count: 0
    Trusted time: 27/10/2013 4:10:12 μμ

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 10:25:2013 18:28
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAEAAwABAAEAAAABAAAAAgABAAEA6GEalhJp+kVSxx7uerdGKlhLju725Fxd

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC Sony VAIO
      FACP Sony VAIO
      HPET Sony VAIO
      MCFG Sony VAIO
      SLIC Sony VAIO
      SSDT Sony VAIO
      SSDT Sony VAIO

    Sunday, October 27, 2013 2:10 PM
  • The MGADiag report looks a lot better :)

    However, the SFC scan terminated prematurely...

    2013-10-27 16:01:53, Error                 CSI    000002d2 (F) c0000185 [Error,Facility=(system),Code=389 (0x0185)] #6274435# from Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile(h = 1ce4 ("\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.1.7601.17514_none_9fe23e2588fdee38\NlsLexicons0026.dll"), evt = 0, apcr = NULL, apcc = NULL, iosb = @0xd4ce30, data = {l:0 b:}, byteoffset = 4980736 (0x00000000004c0000), key = (null))
    [gle=0xd0000185]
    2013-10-27 16:01:53, Error                 CSI    000002d3@2013/10/27:14:01:53.151 (F) d:\win7sp1_gdr\base\wcp\sil\merged\ntu\ntsystem.cpp(2155): Error c0000185 [Error,Facility=(system),Code=389 (0x0185)] originated in function Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile expression: (null)
    [gle=0x80004005]
    

    The file indicated is actually one of the ones we replaced - and I'm not sure why it should be complained about.

    Please try running the SFC scan again - post the new CBS log, and we'll see if the same thing occurs.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Sunday, October 27, 2013 8:13 PM
    Moderator
  • I tried the SFC scan again. It stopped at 88% with the message: "Windows Protection could not perform the requested operation". The new CBS log is at  https://www.dropbox.com/s/aojdygwzow2294i/CBS_3.zip

    Monday, October 28, 2013 6:34 AM
  • Obviously the problem recurred...

    2013-10-28 08:12:09, Info                  CSI    000002d1 [SR] Beginning Verify and Repair transaction
    2013-10-28 08:13:42, Error                 CSI    000002d2 (F) c0000185 [Error,Facility=(system),Code=389 (0x0185)] #6274925# from Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile(h = 1ce4 ("\Device\HarddiskVolume3\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.1.7601.17514_none_9fe23e2588fdee38\NlsLexicons0026.dll"), evt = 0, apcr = NULL, apcc = NULL, iosb = @0x187cfd0, data = {l:0 b:}, byteoffset = 4980736 (0x00000000004c0000), key = (null))
    [gle=0xd0000185]
    2013-10-28 08:13:42, Error                 CSI    000002d3@2013/10/28:06:13:42.564 (F) d:\win7sp1_gdr\base\wcp\sil\merged\ntu\ntsystem.cpp(2155): Error c0000185 [Error,Facility=(system),Code=389 (0x0185)] originated in function Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile expression: (null)
    [gle=0x80004005]
    2013-10-28 08:13:47, Error                 CSI    000002d4 (F) c0000185 [Error,Facility=(system),Code=389 (0x0185)] #6274924# from Windows::Rtl::SystemImplementation::CFile_IRtlFileTearoff::ReadFile(Flags = 3, Buffer = {l:0 ml:65536 b:}, Offset = 4980736 (0x00000000004c0000), Disposition = 0)[gle=0xd0000185]
    2013-10-28 08:18:26, Info                  CBS    Session: 30331813_2196828593 initialized by client WindowsUpdateAgent.
    2013-10-28 08:18:33, Info                  CBS    Trusted Installer signaled for shutdown, going to exit.
    

    As to what to do about it, I'm currently inclined to think that the error is an I/O error - which would point to a failing hard drive.

    What was the result of the CHKDSK? - if you didn't catch it before the auto-reboot, check in the Applications Eventlog - it'll be logged as a Wininit Event


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Monday, October 28, 2013 7:27 AM
    Moderator
  • Indeed, some weeks ago I had a hard disk problem and I was asked to run a chkdsk. Now, I opened the Event Viewer. Where can I locate wininit events?  In any case, after the xcopy we did yesterday the message about genuine windows has not appeared (up to now). 
    Monday, October 28, 2013 8:27 AM
  • If you open Event Viewer, in the left pane, find the Windows logs and expand that, then find the Application log.

    in the right pane, Click on Filter Current Log - in the 'Event Sources' dropdown, put a tick against Wininit, and click OK

    That should show the results of recent CHKDSK scans.

    Also - if you go to the System log, and Filter on disk/Disk and Ntfs, you may see more recent problems highlighted, associated with disk access.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Monday, October 28, 2013 12:14 PM
    Moderator
  • Noel thanks again for your guidance and help. I followed your proposal and here are the logs from yesterday's chkdsk scan and also from the System:

    Log Name:      Application
    Source:        Microsoft-Windows-Wininit
    Date:          27/10/2013 11:05:28 πμ
    Event ID:      1001
    Task Category: None
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Computer:      Georgios-VAIO
    Description:


    Checking file system on C:
    The type of the file system is NTFS.

    A disk check has been scheduled.
    Windows will now check the disk.                         

    CHKDSK is verifying files (stage 1 of 5)...
      236288 file records processed.                                         

    File verification completed.
      671 large file records processed.                                   

      0 bad file records processed.                                     

      0 EA records processed.                                           

      67 reparse records processed.                                      

    CHKDSK is verifying indexes (stage 2 of 5)...
      298038 index entries processed.                                        

    Index verification completed.
      0 unindexed files scanned.                                        

      0 unindexed files recovered.                                      

    CHKDSK is verifying security descriptors (stage 3 of 5)...
      236288 file SDs/SIDs processed.                                        

    Cleaning up 135 unused index entries from index $SII of file 0x9.
    Cleaning up 135 unused index entries from index $SDH of file 0x9.
    Cleaning up 135 unused security descriptors.
    Security descriptor verification completed.
      30876 data files processed.                                           

    CHKDSK is verifying Usn Journal...
      36176976 USN bytes processed.                                            

    Usn Journal verification completed.
    CHKDSK is verifying file data (stage 4 of 5)...
    Read failure with status 0xc0000185 at offset 0x266df1000 for 0x10000 bytes.
    Read failure with status 0xc0000185 at offset 0x266df3000 for 0x1000 bytes.
    Windows replaced bad clusters in file 116676
    of name \Windows\winsxs\X8D01B~1.163\SYNCCE~1.DLL.
      236272 files processed.                                                

    File data verification completed.
    CHKDSK is verifying free space (stage 5 of 5)...
      58769112 free clusters processed.                                        

    Free space verification is complete.
    Adding 6 bad clusters to the Bad Clusters File.
    Correcting errors in the Volume Bitmap.
    Windows has made corrections to the file system.

     297824255 KB total disk space.
      62257920 KB in 133544 files.
        140996 KB in 30877 indexes.
           396 KB in bad sectors.
        348515 KB in use by the system.
         65536 KB occupied by the log file.
     235076428 KB available on disk.

          4096 bytes in each allocation unit.
      74456063 total allocation units on disk.
      58769107 allocation units available on disk.

    Internal Info:
    00 9b 03 00 51 82 02 00 01 a9 04 00 00 00 00 00  ....Q...........
    d0 13 00 00 43 00 00 00 00 00 00 00 00 00 00 00  ....C...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

    Windows has finished checking your disk.
    Please wait while your computer restarts.

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" EventSourceName="Wininit" />
        <EventID Qualifiers="16384">1001</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-10-27T09:05:28.000000000Z" />
        <EventRecordID>44679</EventRecordID>
        <Correlation />
        <Execution ProcessID="0" ThreadID="0" />
        <Channel>Application</Channel>
        <Computer>Georgios-VAIO</Computer>
        <Security />
      </System>
      <EventData>
        <Data>

    Checking file system on C:
    The type of the file system is NTFS.

    A disk check has been scheduled.
    Windows will now check the disk.                         

    CHKDSK is verifying files (stage 1 of 5)...
      236288 file records processed.                                         

    File verification completed.
      671 large file records processed.                                   

      0 bad file records processed.                                     

      0 EA records processed.                                           

      67 reparse records processed.                                      

    CHKDSK is verifying indexes (stage 2 of 5)...
      298038 index entries processed.                                        

    Index verification completed.
      0 unindexed files scanned.                                        

      0 unindexed files recovered.                                      

    CHKDSK is verifying security descriptors (stage 3 of 5)...
      236288 file SDs/SIDs processed.                                        

    Cleaning up 135 unused index entries from index $SII of file 0x9.
    Cleaning up 135 unused index entries from index $SDH of file 0x9.
    Cleaning up 135 unused security descriptors.
    Security descriptor verification completed.
      30876 data files processed.                                           

    CHKDSK is verifying Usn Journal...
      36176976 USN bytes processed.                                            

    Usn Journal verification completed.
    CHKDSK is verifying file data (stage 4 of 5)...
    Read failure with status 0xc0000185 at offset 0x266df1000 for 0x10000 bytes.
    Read failure with status 0xc0000185 at offset 0x266df3000 for 0x1000 bytes.
    Windows replaced bad clusters in file 116676
    of name \Windows\winsxs\X8D01B~1.163\SYNCCE~1.DLL.
      236272 files processed.                                                

    File data verification completed.
    CHKDSK is verifying free space (stage 5 of 5)...
      58769112 free clusters processed.                                        

    Free space verification is complete.
    Adding 6 bad clusters to the Bad Clusters File.
    Correcting errors in the Volume Bitmap.
    Windows has made corrections to the file system.

     297824255 KB total disk space.
      62257920 KB in 133544 files.
        140996 KB in 30877 indexes.
           396 KB in bad sectors.
        348515 KB in use by the system.
         65536 KB occupied by the log file.
     235076428 KB available on disk.

          4096 bytes in each allocation unit.
      74456063 total allocation units on disk.
      58769107 allocation units available on disk.

    Internal Info:
    00 9b 03 00 51 82 02 00 01 a9 04 00 00 00 00 00  ....Q...........
    d0 13 00 00 43 00 00 00 00 00 00 00 00 00 00 00  ....C...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

    Windows has finished checking your disk.
    Please wait while your computer restarts.
    </Data>
      </EventData>
    </Event>

    Log Name:      System

    Source:        Disk

    Date:          14/10/2013 6:28:28 μμ

    Event ID:      11

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      Georgios-VAIO

    Description:

    The driver detected a controller error on \Device\Harddisk3\DR3.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Disk" />

        <EventID Qualifiers="49156">11</EventID>

        <Level>2</Level>

        <Task>0</Task>

        <Keywords>0x80000000000000</Keywords>

        <TimeCreated SystemTime="2013-10-14T15:28:28.002209400Z" />

        <EventRecordID>169567</EventRecordID>

        <Channel>System</Channel>

        <Computer>Georgios-VAIO</Computer>

        <Security />

      </System>

      <EventData>

        <Data>\Device\Harddisk3\DR3</Data>

        <Binary>0E03800001000000000000000B0004C003010000000000000000000000082D000000000000000000298E020000000000FFFFFFFF0600000058000000000000000000061208000010000000003C00000000000000000000004075180880FAFFFF000000000000000010BC220780FAFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>

      </EventData>

    </Event>


    Monday, October 28, 2013 12:56 PM
  • Your hard drive is failing - you should back up all data to external media as soon as possible, and prepare to replace the drive.

    If you look at the summary report...

     297824255 KB total disk space.
       62257920 KB in 133544 files.
         140996 KB in 30877 indexes.
            396 KB in bad sectors.
         348515 KB in use by the system.
          65536 KB occupied by the log file.
      235076428 KB available on disk.

    it shows 99 bad sectors (at 4KB/sector) - of which 6 were found in the latest scan

    Since most drives have another 100 or so spare sectors which the OS never actually sees, and takes care of shuffling things around until those sectors run out, this means that your disk is now showing considerable problems, and could well be on the way to failing at any time.

    Generally, the Controller error you found can be ignored - but taken in conjunction with the known disk errors, it is a further warning of imminent failure.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Monday, October 28, 2013 1:37 PM
    Moderator
  • Thank you very mach for your effort help. I will backup.
    • Marked as answer by George Chris Tuesday, October 29, 2013 5:06 PM
    Monday, October 28, 2013 3:02 PM