Win7 suddenly reporting not genuine

Page 1 of 3 123 LastLast

  1. Posts : 17
    Windows 7 Ultimate x64
       #1

    Win7 suddenly reporting not genuine


    My lenovo laptop (W510 running 7 Ultimate 4) suddenly started reporting that windows is not genuine.

    MGADiag still shows it as genuine but reports several system files with file mismatch

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
    File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
    File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]

    i already tried to reactivate which worked fine but the not genuine thing keeps coming back. Also ran Vipre, Spybot and Malwarebytes

    Any help would be appreciated in getting this machine happy again. And yes it is a genuine windows that came with the laptop bought directly from lenovo. Had it for a while and it was working fine until recently. Cant think of anything special that would have happened recently. No special installs or anything

    thanks

    Mike
      My Computer


  2. Posts : 119
    window 7 home premium 64 bits
       #2

    same thing happen to me after 3 years activated .
    this is microsoft for you .
    a lot of peoples are getting to same thing .why .god know .
    right now i have installed xp with a real copy and i am activated but then again it say that am not .but i am .
    now i have installed pclinux on one of my drive and i never did this b.........and after a few week i like it better then w7
      My Computer


  3. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #3

    Upload the entire log

    Click on the # sign on the top of the message box . You will see [CODE][/CODE] paste the text log in between the [CODE][/CODE] tags
      My Computer


  4. Posts : 17
    Windows 7 Ultimate x64
    Thread Starter
       #4

    sorry about that

    here is the full report

    Code:
    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Genuine
    Validation Code: 0
    Cached Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-7JVM3-2M9JT-4GQC9
    Windows Product Key Hash: ULy+hte2xK1tgks+bRbEWOf1hsQ=
    Windows Product ID: 00426-OEM-9402033-26291
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.001
    ID: {E9EACD4D-1E30-4FC3-93F4-404BEC54062F}(3)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130318-1533
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A
    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    WGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
    File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
    File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
    File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
    File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
    File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
    File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{E9EACD4D-1E30-4FC3-93F4-404BEC54062F}</UGUID><Version>1.9.0019.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4GQC9</PKey><PID>00426-OEM-9402033-26291</PID><PIDType>8</PIDType><SID>S-1-5-21-2274270284-221895154-2144399453</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4318CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>6NET49WW (1.12 )</Version><SMBIOSVersion major="2" minor="6"/><Date>20100222000000.000000+000</Date></BIOS><HWID>611F3907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-6N   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
    Spsys.log Content: 0x80070002
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
    Name: Windows(R) 7, Ultimate edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 022a1afb-b893-4190-92c3-8f69a49839fb
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00426-00188-020-326291-02-1033-7601.0000-1852013
    Installation ID: 010531209143469672205113585786496690779254852925820272
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 4GQC9
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 7/5/2013 6:17:06 PM
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: 0x00000000
    HealthStatus: 0x000000000001EFF0
    Event Time Stamp: 7:3:2013 14:00
    WAT Activex: Registered
    WAT Admin Service: Registered
    HWID Data-->
    HWID Hash Current: OAAAAAEAAgABAAEAAAACAAAABgABAAEAHKLkZEe2Ht50rkIwkGJIMql5uH72LnY8uPVyir5BdlY=
    OEM Activation 1.0 Data-->
    N/A
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC   LENOVO  TP-6N   
      FACP   LENOVO  TP-6N   
      HPET   LENOVO  TP-6N   
      BOOT   LENOVO  TP-6N   
      MCFG   LENOVO  TP-6N   
      SSDT   LENOVO  TP-6N   
      ECDT   LENOVO  TP-6N   
      ASF!   LENOVO  TP-6N   
      SLIC   LENOVO  TP-6N   
      SSDT   LENOVO  TP-6N   
      TCPA   PTL   CRESTLN
      DMAR   INTEL   CP_FIELD
      SSDT   LENOVO  TP-6N   
      SSDT   LENOVO  TP-6N   
      SSDT   LENOVO  TP-6N
      My Computer


  5. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #5

    Open up an Elevated Command Prompt. Click on in type CMD . Right click on CMD under Programs (1) choose . On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

    Type the highlighted text inside Command Prompt

    SFC /scannow and press <ENTER>
      My Computer


  6. Posts : 17
    Windows 7 Ultimate x64
    Thread Starter
       #6

    Code:
    Beginning verification phase of system scan.
    Verification 100% complete.
    Windows Resource Protection found corrupt files but was unable to fix some of th
    em.
    Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
    C:\Windows\Logs\CBS\CBS.log
    C:\Windows\system32>
    the log is quite big so i am not posting it right away
      My Computer


  7. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #7

    Location of the log : C:\Windows\Logs\CBS\CBS.log
      My Computer


  8. Posts : 17
    Windows 7 Ultimate x64
    Thread Starter
       #8

    Well the log is too long

    i uploaded it here

    http://starzen.com/cbslog.txt
      My Computer


  9. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #9

    Open up an Elevated Command Prompt. Click on in type CMD . Right click on CMD under Programs (1) choose . On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

    Type the command below

    chkdsk /F /R
    press [ENTER]

    When you type chkdsk /F /R you will get this message

    Code:
    The type of the file system is NTFS.
    Cannot lock current drive.
    
    Chkdsk cannot run because the volume is in use by another
    process.  Would you like to schedule this volume to be
    checked the next time the system restarts? (Y/N)

    When you type " Y " and press [Enter] you get this message below

    Code:
    This volume will be checked the next time the system restarts.
    
    C:\Windows\system32>
    Close the command prompt window by typing exit and press [enter] Restart the PC manually .

    When you're back inside Windows. Open up Powershell by clicking on type Powershell inside and press [ENTER] . Inside the Powershell paste the command below

    Code:
    get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, message | out-file Desktop\CHKDSKResults.txt
    and Press [Enter] upload the CHKDSKResults.txt file

       Note
    To paste inside the Powershell window press on the right click button on the mouse
      My Computer


  10. Posts : 17
    Windows 7 Ultimate x64
    Thread Starter
       #10

    ok, ran chkdsk. didnt take long

    Code:
     
    TimeCreated : 6/7/2013 1:26:19 PM
    Message     : 
                  
                  Checking file system on C:
                  The type of the file system is NTFS.
                  Volume label is Windows7_OS.
                  
                  
                  One of your disks needs to be checked for consistency. You
                  may cancel the disk check, but it is strongly recommended
                  that you continue.
                  Windows will now check the disk.                         
                  
                  CHKDSK is verifying files (stage 1 of 3)...
                  Cleaning up instance tags for file 0xe8da.
                  Cleaning up instance tags for file 0x12006.
                  Cleaning up instance tags for file 0x3c202.
                  Attribute record of type 0x80 and instance tag 0x4 is cross linked
                  starting at 0x114a4b for possibly 0x1 clusters.
                  Some clusters occupied by attribute of type 0x80 and instance tag 0x4
                  in file 0xe9baa is already in use.
                  Deleting corrupt attribute record (128, "")
                  from file record segment 957354.
                    1610240 file records processed.                                         
                  File verification completed.
                    1759 large file records processed.                                   
                    0 bad file records processed.                                     
                    4 EA records processed.                                           
                    77 reparse records processed.                                      
                  CHKDSK is verifying indexes (stage 2 of 3)...
                  The file reference 0x90000000e396c of index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e4820636
                  88f8df5b9_1e0daff3 of index $I30
                  with parent 0xe568 is not the same as 0xa0000000e396c.
                  Deleting index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e482063688f8df5b9_1e0daff3 in index $
                  I30 of file 58728.
                    1980706 index entries processed.                                        
                  Index verification completed.
                  CHKDSK is scanning unindexed files for reconnect to their original directory.
                  Recovering orphaned file AP3F6A~1.EXE (64889) into directory file 58728.
                  Recovering orphaned file AppHang_sbamui.exe_80a338b884835c701c90fb26d77fb335babeb0_1a814aa6 (64889) into 
                  directory file 58728.
                  Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_226b9b7a (98931) 
                  into directory file 58728.
                    3 unindexed files scanned.                                        
                  Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_6bab9b5b (243833)
                   into directory file 58728.
                    0 unindexed files recovered.                                      
                  CHKDSK is verifying security descriptors (stage 3 of 3)...
                    1610240 file SDs/SIDs processed.                                        
                  CHKDSK is compacting the security descriptor stream
                  Cleaning up 2671 unused security descriptors.
                  Inserting data attribute into file 957354.
                    185235 data files processed.                                           
                  CHKDSK is verifying Usn Journal...
                    36659048 USN bytes processed.                                            
                  Usn Journal verification completed.
                  CHKDSK discovered free space marked as allocated in the
                  master file table (MFT) bitmap.
                  Correcting errors in the Volume Bitmap.
                  Windows has made corrections to the file system.
                  
                   916779004 KB total disk space.
                   426360688 KB in 1373527 files.
                      684036 KB in 185237 indexes.
                           0 KB in bad sectors.
                     1743420 KB in use by the system.
                       65536 KB occupied by the log file.
                   487990860 KB available on disk.
                  
                        4096 bytes in each allocation unit.
                   229194751 total allocation units on disk.
                   121997715 allocation units available on disk.
                  
                  Internal Info:
                  00 92 18 00 f1 c8 17 00 e5 1b 28 00 00 00 00 00  ..........(.....
                  0a 2f 00 00 4d 00 00 00 00 00 00 00 00 00 00 00  ./..M...........
                  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
                  
                  Windows has finished checking your disk.
                  Please wait while your computer restarts.
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:02.
Find Us