This computer is not running genuine Windows - Error: 0x8004fe21

Page 1 of 2 12 LastLast

  1. Posts : 9
    Windows 7 Pro 32bit
       #1

    This computer is not running genuine Windows - Error: 0x8004fe21


    I have a computer that's 3-4 years old now and in the last couple of weeks has been giving me a popup alert saying 'This computer is not running genuine Windows' with and error # 0x8004fe21.

    I have called Microsoft telephone activations and was asked to run 'slui.exe 3' from the command prompt and re-enter the Windows product key (from the computer case), which I did and it successfully activated. I restarted and everything initially seemed fine, but now the message has returned.

    The MGADiag report (below) shows a number of 'File Mismatch' errors - but I'm not sure what to do about it. Any assistance would be greatly appreciated!


    Code:
     
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
     
    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-KWCCR-KRXFC-32CJM
    Windows Product Key Hash: lqrr1lQUkZfJlNC528E/53raqu8=
    Windows Product ID: 00371-OEM-9305396-62912
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {7DABE994-67A9-4B8C-8292-4327982D19BE}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
     
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
     
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
     
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft
     
    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Plus 2007 - 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
     
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
     
    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
     
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{7DABE994-67A9-4B8C-8292-4327982D19BE}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-32CJM</PKey><PID>00371-OEM-9305396-62912</PID><PIDType>8</PIDType><SID>S-1-5-21-4131884669-999156524-2995001951</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Veriton M490G </Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>P01-A2 </Version><SMBIOSVersion major="2" minor="6"/><Date>20100226000000.000000+000</Date></BIOS><HWID>F2173507018400FC</HWID><UserLCID>1409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>New Zealand Standard Time(GMT+12:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>78B5301CC8F6D8C</Val><Hash>IdWLkVy2DzxI8kgoWGpLnsFiR4o=</Hash><Pid>89409-710-0023243-65557</Pid><PidType>14</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>B921F3FBC65772A</Val><Hash>l105StMzMRKRVsI/2X9lPuk44Ww=</Hash><Pid>81602-917-3062433-68739</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults> 
     
    Spsys.log Content: 0x80070002
     
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
     
    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: da22eadd-46dc-4056-a287-f5041c852470
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00186-053-962912-02-5129-7601.0000-2842012
    Installation ID: 011714407971340730317465182501637870772115268884247084
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 32CJM
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 11/10/2012 10:14:47 a.m.
     
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 10:10:2012 08:35
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys
     
     
    HWID Data-->
    HWID Hash Current: LgAAAAEAAgABAAEAAQABAAAAAQABAAEAeqhYHCB1YnWQXBp4YjHgK7z+MMZcXQ==
     
    OEM Activation 1.0 Data-->
    N/A
     
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
    ACPI Table Name    OEMID Value    OEMTableID Value
    APIC            ACRSYS        APIC1657
    FACP            ACRSYS        FACP1657
    HPET            ACRSYS        OEMHPET 
    MCFG            ACRSYS        OEMMCFG 
    SLIC            ACRSYS        ACRPRDCT
    OEMB            ACRSYS        OEMB1657
    ASF!            LEGEND        I865PASF
    GSCI            ACRSYS        GMCHSCI 
    AWMI            ACRSYS        OEMB1657
    SSDT            DpgPmm        CpuPm
    Last edited by Brink; 14 Oct 2012 at 09:43. Reason: code box
      My Computer


  2. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #2

    This may simply be caused by a bad set of Intel Rapid Storage Technology drivers -

    Installing the Intel Rapid Storage Drivers
    try downloading and installing them from here - http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&ProdId=2101&DwnldID=21730

    (you want the iata_enu.exe download)

    Once complete, please reboot twice, then post another MGADiag report.
      My Computer


  3. Posts : 9
    Windows 7 Pro 32bit
    Thread Starter
       #3

    Thanks for your quick reply, Noel. I've done as you instructed, but it doesn't seem to have made any difference.

    Here is the updated MGADiag report:

    Code:
     
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
     
    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-KWCCR-KRXFC-32CJM
    Windows Product Key Hash: lqrr1lQUkZfJlNC528E/53raqu8=
    Windows Product ID: 00371-OEM-9305396-62912
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {7DABE994-67A9-4B8C-8292-4327982D19BE}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
     
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
     
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
     
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft
     
    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Plus 2007 - 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
     
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
     
    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
     
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{7DABE994-67A9-4B8C-8292-4327982D19BE}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-32CJM</PKey><PID>00371-OEM-9305396-62912</PID><PIDType>8</PIDType><SID>S-1-5-21-4131884669-999156524-2995001951</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Veriton M490G </Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>P01-A2 </Version><SMBIOSVersion major="2" minor="6"/><Date>20100226000000.000000+000</Date></BIOS><HWID>F2173507018400FC</HWID><UserLCID>1409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>New Zealand Standard Time(GMT+12:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>78B5301CC8F6D8C</Val><Hash>IdWLkVy2DzxI8kgoWGpLnsFiR4o=</Hash><Pid>89409-710-0023243-65557</Pid><PidType>14</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>B921F3FBC65772A</Val><Hash>l105StMzMRKRVsI/2X9lPuk44Ww=</Hash><Pid>81602-917-3062433-68739</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults> 
     
    Spsys.log Content: 0x80070002
     
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
     
    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: da22eadd-46dc-4056-a287-f5041c852470
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00186-053-962912-02-5129-7601.0000-2842012
    Installation ID: 011714407971340730317465182501637870772115268884247084
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 32CJM
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 12/10/2012 10:20:30 a.m.
     
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 10:10:2012 08:35
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys
     
     
    HWID Data-->
    HWID Hash Current: LgAAAAEAAgABAAEAAQABAAAAAQABAAEAeqhYHCB1YnWQXBp4YjHgK7z+MMZcXQ==
     
    OEM Activation 1.0 Data-->
    N/A
     
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
    ACPI Table Name    OEMID Value    OEMTableID Value
    APIC            ACRSYS        APIC1657
    FACP            ACRSYS        FACP1657
    HPET            ACRSYS        OEMHPET 
    MCFG            ACRSYS        OEMMCFG 
    SLIC            ACRSYS        ACRPRDCT
    OEMB            ACRSYS        OEMB1657
    ASF!            LEGEND        I865PASF
    GSCI            ACRSYS        GMCHSCI 
    AWMI            ACRSYS        OEMB1657
    SSDT            DpgPmm        CpuPm
    Last edited by Brink; 14 Oct 2012 at 09:44. Reason: code box
      My Computer


  4. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #4

    Hmmm.


    Please run the following commands in an Elevated command prompt window, and copy/paste the results to your reply, together with a new MGADiag report.

    NET START CRYPTSVC
    SC QC CRYPTSVC
    SC QUERYEX CRYPTSVC



    Here are some instructions to make life easier :)
    1) To open an Elevated Command Prompt Window (the CP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt.
    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Window, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once.
    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.
      My Computer


  5. Posts : 9
    Windows 7 Pro 32bit
    Thread Starter
       #5

    Thanks, Noel.

    Here is the output from the commands:

    Code:
    C:\Windows\system32>net start cryptsvc
    The requested service has already been started.
    More help is available by typing NET HELPMSG 2182.
    
    C:\Windows\system32>sc qc cryptsvc
    [SC] QueryServiceConfig SUCCESS
    SERVICE_NAME: cryptsvc
            TYPE               : 20  WIN32_SHARE_PROCESS
            START_TYPE         : 2   AUTO_START
            ERROR_CONTROL      : 1   NORMAL
            BINARY_PATH_NAME   : C:\Windows\system32\svchost.exe -k NetworkService
            LOAD_ORDER_GROUP   :
            TAG                : 0
            DISPLAY_NAME       : Cryptographic Services
            DEPENDENCIES       : RpcSs
            SERVICE_START_NAME : NT Authority\NetworkService
    
    C:\Windows\system32>sc queryex cryptsvc
    SERVICE_NAME: cryptsvc
            TYPE               : 20  WIN32_SHARE_PROCESS
            STATE              : 4  RUNNING
                                    (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)
            WIN32_EXIT_CODE    : 0  (0x0)
            SERVICE_EXIT_CODE  : 0  (0x0)
            CHECKPOINT         : 0x0
            WAIT_HINT          : 0x0
            PID                : 1504
            FLAGS              :
    Here is the fresh MGADiag report:

    Code:
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-KWCCR-KRXFC-32CJM
    Windows Product Key Hash: lqrr1lQUkZfJlNC528E/53raqu8=
    Windows Product ID: 00371-OEM-9305396-62912
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {7DABE994-67A9-4B8C-8292-4327982D19BE}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft
    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Plus 2007 - 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{7DABE994-67A9-4B8C-8292-4327982D19BE}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-32CJM</PKey><PID>00371-OEM-9305396-62912</PID><PIDType>8</PIDType><SID>S-1-5-21-4131884669-999156524-2995001951</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Veriton M490G      </Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>P01-A2        </Version><SMBIOSVersion major="2" minor="6"/><Date>20100226000000.000000+000</Date></BIOS><HWID>F2173507018400FC</HWID><UserLCID>1409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>New Zealand Standard Time(GMT+12:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>78B5301CC8F6D8C</Val><Hash>IdWLkVy2DzxI8kgoWGpLnsFiR4o=</Hash><Pid>89409-710-0023243-65557</Pid><PidType>14</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>B921F3FBC65772A</Val><Hash>l105StMzMRKRVsI/2X9lPuk44Ww=</Hash><Pid>81602-917-3062433-68739</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  
    Spsys.log Content: 0x80070002
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: da22eadd-46dc-4056-a287-f5041c852470
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00186-053-962912-02-5129-7601.0000-2842012
    Installation ID: 011714407971340730317465182501637870772115268884247084
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 32CJM
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 15/10/2012 2:29:38 p.m.
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 10:10:2012 08:35
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys
    
    HWID Data-->
    HWID Hash Current: LgAAAAEAAgABAAEAAQABAAAAAQABAAEAeqhYHCB1YnWQXBp4YjHgK7z+MMZcXQ==
    OEM Activation 1.0 Data-->
    N/A
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC   ACRSYS  APIC1657
      FACP   ACRSYS  FACP1657
      HPET   ACRSYS  OEMHPET 
      MCFG   ACRSYS  OEMMCFG 
      SLIC   ACRSYS  ACRPRDCT
      OEMB   ACRSYS  OEMB1657
      ASF!   LEGEND  I865PASF
      GSCI   ACRSYS  GMCHSCI 
      AWMI   ACRSYS  OEMB1657
      SSDT   DpgPmm  CpuPm
      My Computer


  6. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #6

    Recreate the Licensing Store
    Go to Start > All Programs > Accessories
    Right-Click on Command Prompt and select Run as Administrator - accept the UAC prompt
    Run the following commands in the Command Prompt window, using the Enter key at the end of each

    net stop sppsvc
    (wait until the service has stopped before entering the following lines)

    Code:
     
    CD %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    REN tokens.dat tokens.bar
    net start sppsvc
    slui.exe
    After a couple of seconds Windows Activation dialog will appear.
    You may be asked to re-activate and/or re-enter your product key or Activation may occur automatically.
    If you are asked for your Key, use the one on the COA sticker on the machine's case

    Reboot and Post back with a new MGADiag report
      My Computer


  7. Posts : 9
    Windows 7 Pro 32bit
    Thread Starter
       #7

    Hi Noel.

    Unfortunately this doesn't seem to have made any difference. Windows activated ok again but the 'not running genuine Windows' message has come back. Do you think my now we may be looking at a Windows reinstall?

    MGA Report as follows:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-KWCCR-KRXFC-32CJM
    Windows Product Key Hash: lqrr1lQUkZfJlNC528E/53raqu8=
    Windows Product ID: 00371-OEM-9305396-62912
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {7DABE994-67A9-4B8C-8292-4327982D19BE}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000000
    Build lab: 7601.win7sp1_gdr.120330-1504
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Plus 2007 - 100 Genuine
    Microsoft Office Home and Student 2007 - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\Windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{7DABE994-67A9-4B8C-8292-4327982D19BE}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-32CJM</PKey><PID>00371-OEM-9305396-62912</PID><PIDType>8</PIDType><SID>S-1-5-21-4131884669-999156524-2995001951</SID><SYSTEM><Manufacturer>Acer</Manufacturer><Model>Veriton M490G </Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>P01-A2 </Version><SMBIOSVersion major="2" minor="6"/><Date>20100226000000.000000+000</Date></BIOS><HWID>F2173507018400FC</HWID><UserLCID>1409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>New Zealand Standard Time(GMT+12:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>78B5301CC8F6D8C</Val><Hash>IdWLkVy2DzxI8kgoWGpLnsFiR4o=</Hash><Pid>89409-710-0023243-65557</Pid><PidType>14</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>B921F3FBC65772A</Val><Hash>l105StMzMRKRVsI/2X9lPuk44Ww=</Hash><Pid>81602-917-3062433-68739</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: da22eadd-46dc-4056-a287-f5041c852470
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00186-053-962912-02-5129-7601.0000-2902012
    Installation ID: 011714407971340730317465182501637870772115268884247084
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 32CJM
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 16/10/2012 11:14:17 a.m.

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 10:16:2012 02:29
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll
    Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
    Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
    Tampered File: %systemroot%\system32\sppwinob.dll
    Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
    Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
    Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
    Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
    Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
    Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
    Tampered File: %systemroot%\system32\drivers\spsys.sys


    HWID Data-->
    HWID Hash Current: LgAAAAEAAgABAAEAAQABAAAAAQABAAEAeqhYHCB1YnWQXBp4YjHgK7z+MMZcXQ==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC ACRSYS APIC1657
    FACP ACRSYS FACP1657
    HPET ACRSYS OEMHPET
    MCFG ACRSYS OEMMCFG
    SLIC ACRSYS ACRPRDCT
    OEMB ACRSYS OEMB1657
    ASF! LEGEND I865PASF
    GSCI ACRSYS GMCHSCI
    AWMI ACRSYS OEMB1657
    SSDT DpgPmm CpuPm
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #8

    I hate it when these reports don't follow the rules!

    It's about 1 in 20 cases where the problem you have isn't fixed by installing the IRST drivers, and every time, the final solution has been different.

    Please check in Device Manager
    Once you have it open, click on View in the menu bar, and select Show hidden devices.
    Do any devices show with either Yellow triangles, or Red crosses?
    Are there any 'Unknown devices'

    Please run the following commands, and post the results

    DIR C:\Windows\System32 /AR /S
    DIR C:\Windows\NTUSER.DAT /AH /S
    REG QUERY HKU
      My Computer


  9. Posts : 9
    Windows 7 Pro 32bit
    Thread Starter
       #9

    NoelDP said:
    It's about 1 in 20 cases where the problem you have isn't fixed by installing the IRST drivers, and every time, the final solution has been different.
    Nice to know I'm so special :).

    Device Manager just showed a yellow triangle for 'Microsoft PS/2 Port Mouse (Intelliport)'.

    The commands you asked me to run:

    DIR C:\Windows\System32 /AR /S
    Code:
    C:\Users\Administrator>DIR C:\Windows\System32 /AR /S
     Volume in drive C is Acer
     Volume Serial Number is A4D3-AB7C
    
     Directory of C:\Windows\System32\config\systemprofile
    
    22/04/2010  07:31 p.m.    <DIR>          Contacts
    22/04/2010  07:31 p.m.    <DIR>          Desktop
    22/04/2010  07:31 p.m.    <DIR>          Documents
    22/04/2010  07:31 p.m.    <DIR>          Downloads
    22/04/2010  07:31 p.m.    <DIR>          Favorites
    22/04/2010  07:31 p.m.    <DIR>          Links
    22/04/2010  07:31 p.m.    <DIR>          Music
    22/04/2010  07:31 p.m.    <DIR>          Pictures
    22/04/2010  07:31 p.m.    <DIR>          Saved Games
    22/04/2010  07:31 p.m.    <DIR>          Searches
    22/04/2010  07:31 p.m.    <DIR>          Videos
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\W
    indows\Burn
    
    22/04/2010  07:31 p.m.    <DIR>          Burn
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\W
    indows\Burn\Burn
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\W
    indows Sidebar
    
    22/04/2010  07:31 p.m.    <DIR>          Gadgets
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\W
    indows Sidebar\Gadgets
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows
    
    22/04/2010  07:31 p.m.    <DIR>          Libraries
    22/04/2010  07:31 p.m.    <DIR>          Recent
    22/04/2010  07:31 p.m.    <DIR>          Start Menu
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Libraries
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Recent
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Start Menu
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
    22/04/2010  07:31 p.m.    <DIR>          Programs
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Start Menu\Programs
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
    22/04/2010  07:31 p.m.    <DIR>          Administrative Tools
    22/04/2010  07:31 p.m.    <DIR>          Startup
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Start Menu\Programs\Administrative Tools
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft
    \Windows\Start Menu\Programs\Startup
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Contacts
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Desktop
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Documents
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Downloads
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Favorites
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Links
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Music
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
    22/04/2010  07:31 p.m.    <DIR>          Playlists
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Music\Playlists
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Pictures
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
    22/04/2010  07:31 p.m.    <DIR>          Slide Shows
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Pictures\Slide Shows
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Saved Games
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Searches
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\config\systemprofile\Videos
    
    22/04/2010  07:31 p.m.    <DIR>          .
    22/04/2010  07:31 p.m.    <DIR>          ..
                   0 File(s)              0 bytes
    
     Directory of C:\Windows\System32\Macromed\Flash
    
    09/10/2012  01:36 p.m.         9,641,400 Flash32_11_4_402_287.ocx
                   1 File(s)      9,641,400 bytes
    
     Directory of C:\Windows\System32\OEM
    
    20/02/2009  01:03 p.m.           593,642 install_Windows 7 PROFESSIONAL.clg
                   1 File(s)        593,642 bytes
    
     Directory of C:\Windows\System32\OEM\INT15
    
    31/12/2008  12:25 a.m.               933 ReleaseHistory.txt
                   1 File(s)            933 bytes
    
     Directory of C:\Windows\System32\restore
    
    12/07/2010  02:17 p.m.                76 MachineGuid.txt
                   1 File(s)             76 bytes
    
         Total Files Listed:
                   4 File(s)     10,236,051 bytes
                  63 Dir(s)  21,933,764,608 bytes free
    DIR C:\Windows\NTUSER.DAT /AH /S
    Code:
    C:\Users\Administrator>DIR C:\Windows\NTUSER.DAT /AH /S
     Volume in drive C is Acer
     Volume Serial Number is A4D3-AB7C
    File Not Found
    REG QUERY HKU
    Code:
    C:\Users\Administrator>REG QUERY HKU
    
    HKEY_USERS\.DEFAULT
    HKEY_USERS\S-1-5-19
    HKEY_USERS\S-1-5-20
    HKEY_USERS\S-1-5-21-4131884669-999156524-2995001951-1004
    HKEY_USERS\S-1-5-21-4131884669-999156524-2995001951-1004_Classes
    HKEY_USERS\S-1-5-21-4131884669-999156524-2995001951-500
    HKEY_USERS\S-1-5-21-4131884669-999156524-2995001951-500_Classes
    HKEY_USERS\S-1-5-18
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #10

    PLEASE DO NOT WORK IN THE BUILT-IN ADMINISTRATOR ACCOUNT!!

    Things behave very differently when you do that!
    Do you actually have an ordinary Admin user account, or have you crippled the system?
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:12.
Find Us