Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Win7 suddenly reporting not genuine


05 Jul 2013   #1

Windows 7 Ultimate x64
 
 
Win7 suddenly reporting not genuine

My lenovo laptop (W510 running 7 Ultimate 4) suddenly started reporting that windows is not genuine.

MGADiag still shows it as genuine but reports several system files with file mismatch

File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]

i already tried to reactivate which worked fine but the not genuine thing keeps coming back. Also ran Vipre, Spybot and Malwarebytes

Any help would be appreciated in getting this machine happy again. And yes it is a genuine windows that came with the laptop bought directly from lenovo. Had it for a while and it was working fine until recently. Cant think of anything special that would have happened recently. No special installs or anything

thanks

Mike

My System SpecsSystem Spec
.

05 Jul 2013   #2

window 7 home premium 64 bits
 
 

same thing happen to me after 3 years activated .
this is microsoft for you .
a lot of peoples are getting to same thing .why .god know .
right now i have installed xp with a real copy and i am activated but then again it say that am not .but i am .
now i have installed pclinux on one of my drive and i never did this b.........and after a few week i like it better then Windows 7
My System SpecsSystem Spec
05 Jul 2013   #3

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Upload the entire log

Click on the # sign on the top of the message box . You will see [CODE][/CODE] paste the text log in between the [CODE][/CODE] tags
My System SpecsSystem Spec
.


05 Jul 2013   #4

Windows 7 Ultimate x64
 
 

sorry about that

here is the full report

Code:
Diagnostic Report (1.9.0019.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-7JVM3-2M9JT-4GQC9
Windows Product Key Hash: ULy+hte2xK1tgks+bRbEWOf1hsQ=
Windows Product ID: 00426-OEM-9402033-26291
Windows Product ID Type: 8
Windows License Type: COA SLP
Windows OS version: 6.1.7601.2.00010100.1.0.001
ID: {E9EACD4D-1E30-4FC3-93F4-404BEC54062F}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.130318-1533
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E9EACD4D-1E30-4FC3-93F4-404BEC54062F}</UGUID><Version>1.9.0019.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4GQC9</PKey><PID>00426-OEM-9402033-26291</PID><PIDType>8</PIDType><SID>S-1-5-21-2274270284-221895154-2144399453</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4318CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>6NET49WW (1.12 )</Version><SMBIOSVersion major="2" minor="6"/><Date>20100222000000.000000+000</Date></BIOS><HWID>611F3907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-6N   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Ultimate edition
Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Activation ID: 022a1afb-b893-4190-92c3-8f69a49839fb
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00188-020-326291-02-1033-7601.0000-1852013
Installation ID: 010531209143469672205113585786496690779254852925820272
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: 4GQC9
License Status: Licensed
Remaining Windows rearm count: 2
Trusted time: 7/5/2013 6:17:06 PM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: 0x00000000
HealthStatus: 0x000000000001EFF0
Event Time Stamp: 7:3:2013 14:00
WAT Activex: Registered
WAT Admin Service: Registered
HWID Data-->
HWID Hash Current: OAAAAAEAAgABAAEAAAACAAAABgABAAEAHKLkZEe2Ht50rkIwkGJIMql5uH72LnY8uPVyir5BdlY=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC   LENOVO  TP-6N   
  FACP   LENOVO  TP-6N   
  HPET   LENOVO  TP-6N   
  BOOT   LENOVO  TP-6N   
  MCFG   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  ECDT   LENOVO  TP-6N   
  ASF!   LENOVO  TP-6N   
  SLIC   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  TCPA   PTL   CRESTLN
  DMAR   INTEL   CP_FIELD
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N
My System SpecsSystem Spec
05 Jul 2013   #5

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Open up an Elevated Command Prompt. Click on in type CMD . Right click on CMD under Programs (1) choose . On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

Type the highlighted text inside Command Prompt

SFC /scannow and press <ENTER>
My System SpecsSystem Spec
05 Jul 2013   #6

Windows 7 Ultimate x64
 
 

Code:
Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some of th
em.
Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
C:\Windows\Logs\CBS\CBS.log
C:\Windows\system32>
the log is quite big so i am not posting it right away
My System SpecsSystem Spec
05 Jul 2013   #7

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Location of the log : C:\Windows\Logs\CBS\CBS.log
My System SpecsSystem Spec
05 Jul 2013   #8

Windows 7 Ultimate x64
 
 

Well the log is too long

i uploaded it here

http://starzen.com/cbslog.txt
My System SpecsSystem Spec
05 Jul 2013   #9

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Open up an Elevated Command Prompt. Click on in type CMD . Right click on CMD under Programs (1) choose . On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

Type the command below

chkdsk /F /R
press [ENTER]

When you type chkdsk /F /R you will get this message

Code:
The type of the file system is NTFS.
Cannot lock current drive.

Chkdsk cannot run because the volume is in use by another
process.  Would you like to schedule this volume to be
checked the next time the system restarts? (Y/N)

When you type " Y " and press [Enter] you get this message below

Code:
This volume will be checked the next time the system restarts.

C:\Windows\system32>
Close the command prompt window by typing exit and press [enter] Restart the PC manually .

When you're back inside Windows. Open up Powershell by clicking on type Powershell inside and press [ENTER] . Inside the Powershell paste the command below

Code:
get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, message | out-file Desktop\CHKDSKResults.txt
and Press [Enter] upload the CHKDSKResults.txt file

Note   Note
To paste inside the Powershell window press on the right click button on the mouse
My System SpecsSystem Spec
06 Jul 2013   #10

Windows 7 Ultimate x64
 
 

ok, ran chkdsk. didnt take long

Code:
 
TimeCreated : 6/7/2013 1:26:19 PM
Message     : 
              
              Checking file system on C:
              The type of the file system is NTFS.
              Volume label is Windows7_OS.
              
              
              One of your disks needs to be checked for consistency. You
              may cancel the disk check, but it is strongly recommended
              that you continue.
              Windows will now check the disk.                         
              
              CHKDSK is verifying files (stage 1 of 3)...
              Cleaning up instance tags for file 0xe8da.
              Cleaning up instance tags for file 0x12006.
              Cleaning up instance tags for file 0x3c202.
              Attribute record of type 0x80 and instance tag 0x4 is cross linked
              starting at 0x114a4b for possibly 0x1 clusters.
              Some clusters occupied by attribute of type 0x80 and instance tag 0x4
              in file 0xe9baa is already in use.
              Deleting corrupt attribute record (128, "")
              from file record segment 957354.
                1610240 file records processed.                                         
              File verification completed.
                1759 large file records processed.                                   
                0 bad file records processed.                                     
                4 EA records processed.                                           
                77 reparse records processed.                                      
              CHKDSK is verifying indexes (stage 2 of 3)...
              The file reference 0x90000000e396c of index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e4820636
              88f8df5b9_1e0daff3 of index $I30
              with parent 0xe568 is not the same as 0xa0000000e396c.
              Deleting index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e482063688f8df5b9_1e0daff3 in index $
              I30 of file 58728.
                1980706 index entries processed.                                        
              Index verification completed.
              CHKDSK is scanning unindexed files for reconnect to their original directory.
              Recovering orphaned file AP3F6A~1.EXE (64889) into directory file 58728.
              Recovering orphaned file AppHang_sbamui.exe_80a338b884835c701c90fb26d77fb335babeb0_1a814aa6 (64889) into 
              directory file 58728.
              Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_226b9b7a (98931) 
              into directory file 58728.
                3 unindexed files scanned.                                        
              Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_6bab9b5b (243833)
               into directory file 58728.
                0 unindexed files recovered.                                      
              CHKDSK is verifying security descriptors (stage 3 of 3)...
                1610240 file SDs/SIDs processed.                                        
              CHKDSK is compacting the security descriptor stream
              Cleaning up 2671 unused security descriptors.
              Inserting data attribute into file 957354.
                185235 data files processed.                                           
              CHKDSK is verifying Usn Journal...
                36659048 USN bytes processed.                                            
              Usn Journal verification completed.
              CHKDSK discovered free space marked as allocated in the
              master file table (MFT) bitmap.
              Correcting errors in the Volume Bitmap.
              Windows has made corrections to the file system.
              
               916779004 KB total disk space.
               426360688 KB in 1373527 files.
                  684036 KB in 185237 indexes.
                       0 KB in bad sectors.
                 1743420 KB in use by the system.
                   65536 KB occupied by the log file.
               487990860 KB available on disk.
              
                    4096 bytes in each allocation unit.
               229194751 total allocation units on disk.
               121997715 allocation units available on disk.
              
              Internal Info:
              00 92 18 00 f1 c8 17 00 e5 1b 28 00 00 00 00 00  ..........(.....
              0a 2f 00 00 4d 00 00 00 00 00 00 00 00 00 00 00  ./..M...........
              00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
              
              Windows has finished checking your disk.
              Please wait while your computer restarts.
My System SpecsSystem Spec
Reply

 Win7 suddenly reporting not genuine




Thread Tools



Similar help and support threads for2: Win7 suddenly reporting not genuine
Thread Forum
Windows is reporting it isn't genuine Windows Updates & Activation
Suddenly Windows 7 is not genuine Windows Updates & Activation
Solved Windows is reporting it isn't genuine, Validation code 0x8004FE21 Windows Updates & Activation
my windows suddenly says not genuine. Windows Updates & Activation
Suddenly getting pop-up box saying W7 not genuine Windows Updates & Activation
Genuine Windows suddenly not genuine. A solution? Windows Updates & Activation
Win7 64bit Suddenly not genuine? Installation & Setup

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 11:57 PM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33