Windows Not Genuine Nag Screen - PC out of storage

Page 2 of 2 FirstFirst 12

  1. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #11

    That's OK - the folders don't change :)
    Thanks for the detail on how you managed to work around it - that was definitely the way to go :)


    Some of the files are now fixed - but there's a couple that didn't seem to 'take' for some reason.

    Please run another SFC /SCANNOW and post the new CBS.log - that will give me a clean version to work from.
    Your MGADiag report is now showing as genuine -so you shouldn't be seeing notifications any more.
      My Computer


  2. Posts : 8
    Windows 7 Ultimate 64 bit
    Thread Starter
       #12

    Thanks Noel

    Here is the cbs log after running sfc again. also, below is the latest MGADiag report.

    Code:
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    
    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-PHG9M-49G3P-DGQGF
    Windows Product Key Hash: dle/BRmDaGEEc376qpK6eaEckBY=
    Windows Product ID: 00426-292-3586346-85167
    Windows Product ID Type: 5
    Windows License Type: Retail
    Windows OS version: 6.1.7601.2.00010100.1.0.001
    ID: {D73BA89A-CAA7-4454-85A9-6BD5CA669464}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130104-1431
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
    
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Ally\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    
    File Scan Data-->
    
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{D73BA89A-CAA7-4454-85A9-6BD5CA669464}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-DGQGF</PKey><PID>00426-292-3586346-85167</PID><PIDType>5</PIDType><SID>S-1-5-21-2991815051-882960362-2897927280</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>P67A-UD4-B3</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F3</Version><SMBIOSVersion major="2" minor="4"/><Date>20110331000000.000000+000</Date></BIOS><HWID>BD363707018400FE</HWID><UserLCID>0C09</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>AUS Eastern Standard Time(GMT+10:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
    
    Spsys.log Content: 0x80070002
    
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
    
    Name: Windows(R) 7, Ultimate edition
    Description: Windows Operating System - Windows(R) 7, RETAIL channel
    Activation ID: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00426-00170-292-358634-00-3081-7600.0000-0662011
    Installation ID: 014273172933039322856175556631986463448065599763897261
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: DGQGF
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 7/03/2013 7:56:33 AM
    
    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 3:7:2013 03:22
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    
    
    HWID Data-->
    HWID Hash Current: NgAAAAIAAgABAAEAAQADAAAAAgABAAEAln2GSBSNdxaUimoDDJpkDNAcYj2Q4aXZ7tJCZy5z
    
    OEM Activation 1.0 Data-->
    N/A
    
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information: 
      ACPI Table Name	OEMID Value	OEMTableID Value
      APIC			GBT   		GBTUACPI
      FACP			GBT   		GBTUACPI
      HPET			GBT   		GBTUACPI
      MCFG			GBT   		GBTUACPI
      ASPT			GBT   		PerfTune
      SSPT			GBT   		SsptHead
      EUDS			GBT   		
      MATS			GBT   		
      TAMG			GBT   		GBT   B0
      SSDT			INTEL		PPM RCM
      My Computer


  3. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #13

    The remaining files requiring attention are
    Code:
     Line 19468: 2013-03-07 07:30:42, Info                  CSI    0000032a [SR] Beginning Verify and Repair transaction
     Line 19469: 2013-03-07 07:30:42, Info                  CSI    0000032b [SR] Cannot repair member file [l:42{21}]"about_scopes.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19470: 2013-03-07 07:30:42, Info                  CSI    0000032c [SR] Cannot repair member file [l:42{21}]"about_arrays.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19471: 2013-03-07 07:30:42, Info                  CSI    0000032d [SR] Cannot repair member file [l:58{29}]"about_Reserved_Words.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19472: 2013-03-07 07:30:42, Info                  CSI    0000032e [SR] Cannot repair member file [l:56{28}]"about_remote_output.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19473: 2013-03-07 07:30:42, Info                  CSI    0000032f [SR] Cannot repair member file [l:70{35}]"about_Comparison_Operators.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19474: 2013-03-07 07:30:42, Info                  CSI    00000330 [SR] Cannot repair member file [l:52{26}]"about_WMI_Cmdlets.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19475: 2013-03-07 07:30:42, Info                  CSI    00000331 [SR] Cannot repair member file [l:108{54}]"Microsoft.PowerShell.Commands.Diagnostics.dll-Help.xml" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19476: 2013-03-07 07:30:42, Info                  CSI    00000332 [SR] Cannot repair member file [l:54{27}]"about_transactions.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
     Line 19477: 2013-03-07 07:30:42, Info                  CSI    00000333 [SR] Cannot repair member file [l:42{21}]"about_scopes.help.txt" of Microsoft-Windows-PowerShell-PreLoc.Resources, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture = [l:10{5}]"en-US", VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
    In case you hadn't noticed, your machine is showing as genuine now - so you shouldn't be getting any notifications.

    I don't know why these files are resisting replacement - I've been seeing a few threads with such problems over the past few days, so I'm beginning to suspect malware affecting either the files, or the registry (but I'll check that I didn't post the wrong files anyhow)

    back soon.
      My Computer


  4. Posts : 8
    Windows 7 Ultimate 64 bit
    Thread Starter
       #14

    Thank You Noel, I certainly haven't seen any messages and that was my query so thank you for your knowledge, clear instructions and patience. Your last comment worries me a bit though..!
      My Computer


  5. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #15

    So far as I can see, the files I posted are the right ones.

    Please run the following commands, and post the results

    Code:
     
    DIR C:\Windows\about_arrays.help.txt /S
    DIR C:\Windows\about_arrays.help.txt /AR /S
    ICACLS C:\Windows\winsxs\about_arrays.help.txt /T
    ICACLS C:\Windows\winsxs\wow64_microsoft-windows-p..ll-preloc.resources_31bf3856ad364e35_6.1.7600.16385_en-us_27fbee50ef7f6588
    They will each take a minute or two to run - please wait until the prompt and cursor reappear before posting the output
      My Computer


  6. Posts : 8
    Windows 7 Ultimate 64 bit
    Thread Starter
       #16

    Here are the results

    Code:
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.
    
    C:\Users\Ally>DIR C:\Windows\about_arrays.help.txt /S
     Volume in drive C has no label.
     Volume Serial Number is 2C8E-02F3
    
     Directory of C:\Windows\System32\WindowsPowerShell\v1.0\en-US
    
    11/06/2009  08:40 AM             8,667 about_arrays.help.txt
                   1 File(s)          8,667 bytes
    
     Directory of C:\Windows\SysWOW64\WindowsPowerShell\v1.0\en-US
    
    10/06/2009  10:22 PM             8,667 about_arrays.help.txt
                   1 File(s)          8,667 bytes
    
     Directory of C:\Windows\winsxs\amd64_microsoft-windows-p..ll-preloc.resources_3
    1bf3856ad364e35_6.1.7600.16385_en-us_1da743febb1ea38d
    
    11/06/2009  08:40 AM             8,667 about_arrays.help.txt
                   1 File(s)          8,667 bytes
    
     Directory of C:\Windows\winsxs\wow64_microsoft-windows-p..ll-preloc.resources_3
    1bf3856ad364e35_6.1.7600.16385_en-us_27fbee50ef7f6588
    
    10/06/2009  10:22 PM             8,667 about_arrays.help.txt
                   1 File(s)          8,667 bytes
    
     Directory of C:\Windows\winxs\wow64_microsoft-windows-p..ll-preloc.resources_31
    bf3856ad364e35_6.1.7600.16385_en-us_27fbee50ef7f6588
    
    10/06/2009  10:22 PM             8,667 about_arrays.help.txt
                   1 File(s)          8,667 bytes
    
         Total Files Listed:
                   5 File(s)         43,335 bytes
                   0 Dir(s)  935,973,679,104 bytes free
    
    C:\Users\Ally>DIR C:\Windows\about_arrays.help.txt /AR /S
     Volume in drive C has no label.
     Volume Serial Number is 2C8E-02F3
    File Not Found
    
    C:\Users\Ally>ICACLS C:\Windows\winsxs\about_arrays.help.txt /T
    C:\Windows\winsxs\amd64_microsoft-windows-p..ll-preloc.resources_31bf3856ad364e3
    5_6.1.7600.16385_en-us_1da743febb1ea38d\about_arrays.help.txt NT SERVICE\Trusted
    Installer:(F)
    
                                                                  BUILTIN\Administra
    tors:(RX)
    
                                                                  NT AUTHORITY\SYSTE
    M:(RX)
    
                                                                  BUILTIN\Users:(RX)
    
    
    C:\Windows\winsxs\wow64_microsoft-windows-p..ll-preloc.resources_31bf3856ad364e3
    5_6.1.7600.16385_en-us_27fbee50ef7f6588\about_arrays.help.txt NT SERVICE\Trusted
    Installer:(F)
    
                                                                  BUILTIN\Administra
    tors:(RX)
    
                                                                  NT AUTHORITY\SYSTE
    M:(RX)
    
                                                                  BUILTIN\Users:(RX)
    
    
    Successfully processed 2 files; Failed processing 0 files
    
    C:\Users\Ally>ICACLS C:\Windows\winsxs\wow64_microsoft-windows-p..ll-preloc.reso
    urces_31bf3856ad364e35_6.1.7600.16385_en-us_27fbee50ef7f6588
    C:\Windows\winsxs\wow64_microsoft-windows-p..ll-preloc.resources_31bf3856ad364e3
    5_6.1.7600.16385_en-us_27fbee50ef7f6588 NT SERVICE\TrustedInstaller:(I)(OI)(CI)(
    F)
    
                                            BUILTIN\Administrators:(I)(OI)(CI)(RX)
    
                                            NT AUTHORITY\SYSTEM:(I)(OI)(CI)(RX)
    
                                            BUILTIN\Users:(I)(OI)(CI)(RX)
    
    Successfully processed 1 files; Failed processing 0 files
    
    C:\Users\Ally>
      My Computer


  7. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #17

    As far as I can see, all those results are normal.
    I'll have to sleep on it - back tomorrow :)
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #18

    Please check your Device manager - enable viewing of Hidden devices.
    Are any devices shown with Yellow or red flags? if so, which ones? double-click on each, and note the error code - post back with details
    Are any network-related items duplicated?

    Please attach your Event Viewer logs to your reply....

    Please open Event Viewer
    In the left pane, navigate to the Windows Logs
    right-click on Applications and select 'Save all events as...' save as Apps.evtx
    repeat for the System logs - save as Sys.evtx
    Compress both files, and attach to your reply.
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:40.
Find Us