Build 7601 This copy of Windows is not genuine

Page 2 of 6 FirstFirst 1234 ... LastLast

  1. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #11

    OK _ we'll have to go at it another way....

    Please open an Elevated Command Prompt, and run the following commands.

    TAKEOWN /F C:\Windows\System32\SLUI.EXE
    ICACLS C:\Windows\System32\SLUI.EXE /remove:d Everyone
    ICACLS C:\Windows\System32\SLUI.EXE /grant "NT SERVICE\TrustedInstaller":(F)
    ICACLS C:\Windows\System32\SLUI.EXE
    ICACLS C:\Windows\System32\SLUI.EXE /setowner "NT SERVICE\TrustedInstaller"

    Post the results, then reboot
      My Computer


  2. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #12

    There are two more files which have the same problem - once we have SLUI sorted, we'll work on those.
    There are other problems as well.

    As you suspected, the printer-related items are error indicators, but the problem is that if ICACLS can't gain access is may be very difficult to do anything about them - but we'll worry about that when the time comes :)
      My Computer


  3. Posts : 55
    Windows 7
       #13

    Some success? (Wonder whether you will conquer printing prob. that has been defying everyone). N.b. current puter - MIKE4-PC is networked to other puter MIKE-PC - wh. is rarely on. But both PC printers sometimes show up under Printers on MIKE4 - with 2 versions of same Samsung printer. So I wonder whether there may have been some confusion there. Thx again

    ***************

    C:\Windows\system32>TAKEOWN /F C:\Windows\System32\SLUI.EXE

    SUCCESS: The file (or folder): "C:\Windows\System32\SLUI.EXE" now owned by user
    "Mike4-PC\Mike".

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE /remove:d Everyone
    processed file: C:\Windows\System32\SLUI.EXE
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE /grant "NT SERVICE\Trust
    edInstaller"F)
    processed file: C:\Windows\System32\SLUI.EXE
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE
    C:\Windows\System32\SLUI.EXE NT SERVICE\TrustedInstallerF)
    NT AUTHORITY\SYSTEMI)(F)
    BUILTIN\AdministratorsI)(F)
    BUILTIN\UsersI)(RX)
    Mike4-PC\MikeI)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE /setowner "NT SERVICE\Tr
    ustedInstaller"
      My Computer


  4. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #14

    Looks as if the last command didn't process - but that's not too much of a problem.
    Please open an Elevated Command Prompt, and run the following commands...

    TAKEOWN C:\Windows\System32\Wat\WatAdminSvc.exe
    ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /remove:d Everyone
    ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /grant "NT SERVICE\TrustedInstaller":(F)
    ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /setowner "NT SERVICE\TrustedInstaller"
    TAKEOWN C:\Windows\System32\Wat\WatUX.exe
    ICACLS C:\Windows\System32\Wat\WatUX.exe /remove:d Everyone
    ICACLS C:\Windows\System32\Wat\WatUX.exe /grant "NT SERVICE\TrustedInstaller":(F)
    ICACLS C:\Windows\System32\Wat\WatUX.exe /setowner "NT SERVICE\TrustedInstaller"
    ICACLS C:\Windows\System32\SLUI.EXE /setowner "NT SERVICE\TrustedInstaller"
    ICACLS C:\Windows\System32\Wat\WatUX.exe
    ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe
    ICACLS C:\Windows\System32\SLUI.EXE
      My Computer


  5. Posts : 55
    Windows 7
       #15

    Results:

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>TAKEOWN C:\Windows\System32\Wat\WatAdminSvc.exe
    ERROR: Invalid argument/option - 'C:\Windows\System32\Wat\WatAdminSvc.exe'.
    Type "TAKEOWN /?" for usage.

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /remove:d Eve
    ryone
    processed file: C:\Windows\System32\Wat\WatAdminSvc.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /grant "NT SE
    RVICE\TrustedInstaller"F)
    processed file: C:\Windows\System32\Wat\WatAdminSvc.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe /setowner "NT
    SERVICE\TrustedInstaller"
    processed file: C:\Windows\System32\Wat\WatAdminSvc.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>TAKEOWN C:\Windows\System32\Wat\WatUX.exe
    ERROR: Invalid argument/option - 'C:\Windows\System32\Wat\WatUX.exe'.
    Type "TAKEOWN /?" for usage.

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatUX.exe /remove:d Everyone
    processed file: C:\Windows\System32\Wat\WatUX.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatUX.exe /grant "NT SERVICE\
    TrustedInstaller"F)
    processed file: C:\Windows\System32\Wat\WatUX.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatUX.exe /setowner "NT SERVI
    CE\TrustedInstaller"
    processed file: C:\Windows\System32\Wat\WatUX.exe
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE /setowner "NT SERVICE\Tr
    ustedInstaller"
    processed file: C:\Windows\System32\SLUI.EXE
    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatUX.exe
    C:\Windows\System32\Wat\WatUX.exe NT SERVICE\TrustedInstallerF)
    NT AUTHORITY\SYSTEMI)(F)
    BUILTIN\AdministratorsI)(F)
    BUILTIN\UsersI)(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\Wat\WatAdminSvc.exe
    C:\Windows\System32\Wat\WatAdminSvc.exe NT SERVICE\TrustedInstallerF)
    NT AUTHORITY\SYSTEMI)(F)
    BUILTIN\AdministratorsI)(F)
    BUILTIN\UsersI)(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE
      My Computer


  6. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #16

    OH b&gg%r
    my booboo
    I Forgot the /F switch in the Takeown commands - again

    Luckily, those files don't appear to have been locked in quite the same way, so the remaining commands still worked! :)

    The SPP system should now be working properly.

    Please run another MGADiag report and post the new log.
      My Computer


  7. Posts : 55
    Windows 7
       #17

    Well the printing probs seem still there - Word and Notepad print files to begin with, but then go into endless loops. Printers?Devices wont open. I notice below says: "

    Tampered Service: sppsvc"

    Thx as always

    ********************
    Windows Validation Data-->

    Validation Code: 0x8004FE21
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-CWRF2-TRJKB-PV9HW
    Windows Product Key Hash: Fs455Nky3AorD9YNxMNmvlm1bGw=
    Windows Product ID: 00371-OEM-8992671-00407
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {DF709CC9-27BD-40CE-8BBA-D46F261717D5}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Professional Plus 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{DF709CC9-27BD-40CE-8BBA-D46F261717D5}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-PV9HW</PKey><PID>00371-OEM-8992671-00407</PID><PIDType>2</PIDType><SID>S-1-5-21-637814681-3575538249-3970651240</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>GA-78LMT-USB3</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>FA</Version><SMBIOSVersion major="2" minor="4"/><Date>20130423000000.000000+000</Date></BIOS><HWID>D3323207018400F2</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>83770C147C39586</Val><Hash>HujjXRyTgOYjf4RCWfGtC0B0HlY=</Hash><Pid>89409-707-1230233-65551</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 50e329f7-a5fa-46b2-85fd-f224e5da7764
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00371-00178-926-700407-02-2057-7601.0000-0182014
    Installation ID: 020613869355526472529191926315721705492003989732922060
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: PV9HW
    License Status: Initial grace period
    Time remaining: 43200 minute(s) (30 day(s))
    Remaining Windows rearm count: 1
    Trusted time: 19/01/2014 18:48:06

    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0001000000000000
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered Service: sppsvc


    HWID Data-->
    HWID Hash Current: MgAAAAEABAABAAEAAAACAAAAAQABAAEAln2+QJa94KgYiBAzVPI6jMTZNBZ+t+zLdjI=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC GBT GBTUACPI
    FACP GBT GBTUACPI
    HPET GBT GBTUACPI
    MCFG GBT GBTUACPI
    MSDM GBT GBTUACPI
    SSDT AMD POWERNOW
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #18

    OK - that's at least got us a step further :)


    Please download the Farbar Service Scanner from

    http://www.bleepingcomputer.com/download/farbar-service-scanner/

    Right-click on the saved file and select 'Run as Administrator', and tick all the options, then click on the Scan button - copy and paste the report to your response.

      My Computer


  9. Posts : 55
    Windows 7
       #19

    Farbar Service Scanner Version: 08-01-2014
    Ran by Mike (administrator) on 19-01-2014 at 19:25:21
    Running from "C:\Users\Mike\Downloads"
    Microsoft Windows 7 Professional Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\ipnathlp.dll => MD5 is legit
    C:\Windows\System32\iphlpsvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit


    **** End of log ****
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #20

    Hmm - that's all OK.


    Please open an Elevated (Administrator) Command Prompt window and use the following commands....

    net start sppsvc
    sc qc sppsvc
    sc queryex sppsvc
    sc qprivs sppsvc
    sc qsidtype sppsvc
    sc sdshow sppsvc

    Copy and paste the output to your reply
      My Computer


 
Page 2 of 6 FirstFirst 1234 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:04.
Find Us