Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.



Windows 7: Virus

06 Jun 2012   #1

Microsoft Windows 7 Professional 32-bit 7601 Multiprocessor Free Service Pack 1
 
 
Virus

Hello, i have had my computer in 2 years and yesterday i saw a messege from my OS that told me that it had occured an not allowed change in my OS and told me to reintsall windows. So the reason i write here is that i don't have an cd or any key, my parents bought the computer from a store and all was in it we didn't get any key or cd and im worried that i may have to buy a new copy of windows to be able to reinstall it. Your soonest asnwer is welcome!

Sinceraly: Rixxor

My System SpecsSystem Spec
.

06 Jun 2012   #2

Microsoft Community Contributor Award Recipient

Windows 7 SP1, Home Premium, 64-bit
 
 

Please fill out your system specifications. We have no idea what type of PC you have.

Do you hava a recovery partition?

Have you made recovery disks?
My System SpecsSystem Spec
06 Jun 2012   #3

Microsoft Windows 7 Professional 32-bit 7601 Multiprocessor Free Service Pack 1
 
 

I don't have any recovery disks and i don't know what recovery partition is. the thing i do atm is donig some deepscans with several antivirus programs like telia säker surf and avast free
My System SpecsSystem Spec
.


06 Jun 2012   #4

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64 Ubuntu 12.04 LTS Tri-Boot
 
 

Hi Rixxor,

Lets see whether its a system issue that can be fixed by gathering some information about your system.

1. Please follow this tutorial to update your system specifications fully:
System Info - See Your System Specs

2. Download and Save to desktop from this link:
http://go.microsoft.com/fwlink/?linkid=52012

3. Once saved, run the tool. Click on the Continue button, which will produce the report.

4. Click on the Copy button in the tool (ignore any error messages), and then paste into your next reply.

Regards,
Golden
My System SpecsSystem Spec
06 Jun 2012   #5

Microsoft Windows 7 Professional 32-bit 7601 Multiprocessor Free Service Pack 1
 
 

Code:
 
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
 
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-GK4PY-FDWYH-7TP9F
Windows Product Key Hash: u3xU6PnmumgYLgUpnmbqEw9Q2OA=
Windows Product ID: 00371-OEM-8992671-00004
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {020AAE58-566F-490B-9BBC-96A4C34CBCD4}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Professional
Architecture: 0x00000000
Build lab: 7601.win7sp1_gdr.120330-1504
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
 
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
 
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
 
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
 
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
 
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Users\Ägaren\AppData\Local\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
 
File Scan Data-->
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
 
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{020AAE58-566F-490B-9BBC-96A4C34CBCD4}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-7TP9F</PKey><PID>00371-OEM-8992671-00004</PID><PIDType>2</PIDType><SID>S-1-5-21-3066797389-1948560292-4112811822</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Veriton M670G</Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>P01-A1</Version><SMBIOSVersion major="2" minor="5"/><Date>20091124000000.000000+000</Date></BIOS><HWID>2E6C3F07018400F8</HWID><UserLCID>041D</UserLCID><SystemLCID>041D</SystemLCID><TimeZone>Västeuropa, normaltid(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> 
 
Spsys.log Content: 0x80070002
 
Licensing Data-->
Kör slui.exe 0x2a 0xC004F012 på en dator som kör Microsoft Windows utan processorkärna om du vill visa felmeddelandet.
Fel: 0xC004F012 
 
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x0000000000000010
Event Time Stamp: 3:23:2012 20:29
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\sppobjs.dll
 
 
HWID Data-->
HWID Hash Current: NAAAAAIAAgABAAEAAgACAAAAAQABAAEAeqj8BiB1K7bI6xLK0F+IOGR8je+aiJbeAENMWA==
 
OEM Activation 1.0 Data-->
N/A
 
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
ACPI Table Name    OEMID Value    OEMTableID Value
APIC            112409        APIC1736
FACP            112409        FACP1736
HPET            112409        OEMHPET 
MCFG            112409        OEMMCFG 
SLIC            ACRSYS        ACRPRDCT
OEMB            112409        OEMB1736
ASF!            LEGEND        I865PASF
GSCI            112409        GMCHSCI 
TCPA            112409        TBLOEMID
AWMI            112409        OEMB1736
SSDT            DpgPmm        CpuPm
i filled in that i could on my components.
My System SpecsSystem Spec
06 Jun 2012   #6

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64 Ubuntu 12.04 LTS Tri-Boot
 
 

Hi,

The problem is a tampered file:

Quote:
File Scan Data-->
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
Quote:
Tampered File: %systemroot%\system32\sppobjs.dll
This could be a corruption of some system files, or possibly bad Intel Rapid Storage drivers.

Try this first:

SFC /SCANNOW Command - System File Checker

Please post back the output, reboot the PC, then run a new updated MGADIAG report and post it here.

Regards,
Golden
My System SpecsSystem Spec
06 Jun 2012   #7

Microsoft Windows 7 Professional 32-bit 7601 Multiprocessor Free Service Pack 1
 
 

MGADIAG what is that?
My System SpecsSystem Spec
06 Jun 2012   #8

Microsoft Windows 7 Professional 32-bit 7601 Multiprocessor Free Service Pack 1
 
 

damaged files were found but some could not be reparied
the information can be found in cbs.log windir/logs/cbs/cbs. for example
C:/windows/system32/sfc/scannow

That is what showed up when i had done the scan.

Ps i don't have a cd or any key is it safe to reboot it then?
My System SpecsSystem Spec
06 Jun 2012   #9

Windows 7 Professional SP1 64-bit
 
 

Reboot the computer and run SFC /Scannow again. Sometimes it has to be run as much as three times to fix everything it can.
My System SpecsSystem Spec
06 Jun 2012   #10
Microsoft MVP

 

Do you have a COA sticker on the computer case with a geniune Windows 7 seal and Product Key used to reinstall Windows 7?

Name:  1270558000_86224332_1-Pictures-of--Buying-Windows-7-Prof-COA-Sticker-Only-100pcs-up-Needed.jpg
Views: 4
Size:  22.5 KB

If so you can Clean Reinstall - Factory OEM Windows 7. Everything you need is in the blue link including how to rescue any files first.


My System SpecsSystem Spec
Reply

 Virus





Thread Tools




Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 06:23 PM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33