Build 7601 This copy of Windows is not genuine

Page 1 of 6 123 ... LastLast

  1. Posts : 1
    Windows 7 Home Premium 64bit
       #1

    Build 7601 This copy of Windows is not genuine


    2 years or more after owning my XPS L502X I received an error saying that I needed to activate my version of windows. Windows 7 Home Premium came installed on my computer and I haven't had any activation issues with it until now. I had done a system restore yesterday to late December 2013 since about half of the websites I frequent wouldn't load. I had tried restarting my router/modem and messing with connections to no avail. It fixed my web issues and I have used the computer almost constantly in the day since without a problem. The error occurred without a restart or anything(though I do get a windows error on restart now). I was mid-episode of a show that I had previously watched using the same software I had previously used(VLC) to watch it. The only changes I have done since the restore were to add torrentprivacy.com's bit torrent anonymizer and download a few torrents. The torrents were positively commented and passed avast virus scan.

    Code:
    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    
    Validation Code: 50
    Cached Online Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-8X62T-GGHFY-2GKJJ
    Windows Product Key Hash: Xd2EH73bu/w8jpuXwBnmthjtGew=
    Windows Product ID: 00359-OEM-9822232-65856
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {9B01FFFB-CF86-4D89-954F-B1C0786A5AB9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: T:20140114174854501-
    Validation Diagnostic: 
    Resolution Status: N/A
    
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    
    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Jay\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    
    File Scan Data-->
    
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{9B01FFFB-CF86-4D89-954F-B1C0786A5AB9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-2GKJJ</PKey><PID>00359-OEM-9822232-65856</PID><PIDType>8</PIDType><SID>S-1-5-21-3435727749-3974888768-120381978</SID><SYSTEM><Manufacturer>Dell Inc.         </Manufacturer><Model>Dell System XPS L502X</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.         </Manufacturer><Version>A12</Version><SMBIOSVersion major="2" minor="6"/><Date>20120907000000.000000+000</Date></BIOS><HWID>0BC43907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL  </OEMID><OEMTableID>QA09   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
    
    Spsys.log Content: U1BMRwEAAAAAAQAACAAAALkrkgAAAAAAYWECAID4//8FH5nykxHPAWbXGpOihAOpMHzDmWxsjuo0ZgVzlPgd/6/Rdl6Lo1N4LE7vLclF1lRfhuMyqJyM4TOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAx4dZsxs/sxaQSZh6DCEuBHhdkHIAOF0lxvOI+ClsQz9yVjoCW/CyZssURg2+DeY0kzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM
    
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
    
    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
    Activation ID: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00196-222-365856-02-1033-7601.0000-0142014
    Installation ID: 001596586076922515437660370601389150421655972191205963
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: 2GKJJ
    License Status: Notification
    Notification Reason: 0xC004F200 (non-genuine).
    Remaining Windows rearm count: 5
    Trusted time: 1/14/2014 7:35:40 PM
    
    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0xC004C4A8
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 1:14:2014 18:14
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    
    
    HWID Data-->
    HWID Hash Current: MgAAAAEAAQABAAIAAAACAAAAAwABAAEAln3q8Go0iOoOA3SIDMaggybUrhQ4sErQLnM=
    
    OEM Activation 1.0 Data-->
    N/A
    
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name	OEMID Value	OEMTableID Value
      APIC			DELL  		QA09   
      FACP			DELL  		QA09   
      HPET			DELL  		QA09   
      MCFG			DELL  		QA09   
      SLIC			DELL  		QA09   
      SSDT			DELL  		PtidDevc
      ASF!			DELL  		QA09   
      SSDT			DELL  		PtidDevc
      SSDT			DELL  		PtidDevc
      SSDT			DELL  		PtidDevc
      UEFI			DELL  		QA09   
      UEFI			DELL  		QA09   
      UEFI			DELL  		QA09
      My Computer


  2. Posts : 3,724
    Windows 10x64 Build 1709
       #2

    Welcome to the forums!

    You could try a repair install, it will save your programs/settings and restore Windows to its original state. We have many excellent tutorials here at the forums, heres how to do that if you haven't before. Just click on the link.

    Repair Install

    I'm assuming you've ran all your Antivirus and malware scans, correct?
      My Computer


  3. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #3

    You have a Trysted Store Tamper - and an error code I don't ever remember seeing before... 0xc004c4a8 - but which in fact just means that the license is invalid.

    I would suggest recreating the Licensing Store..


    Please first try recreating Licensing Store.

    Recreate the Licensing Store
    Go to Start > All Programs > Accessories
    Right-Click on Command Prompt and select Run as Administrator - accept the UAC prompt
    Run the following commands in the Command Prompt window, using the Enter key at the end of each

    net stop sppsvc
    (wait until the service has stopped before entering the following lines)

    CD %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    REN tokens.dat tokens.bar
    net start sppsvc
    slui.exe

    After a couple of seconds the Windows Activation dialog will appear.
    You may be asked to re-activate and/or re-enter your product key, or Activation may occur automatically.
    If you are asked for your Key, use the one on the COA sticker on the machine's case

    Reboot and Post back with a new MGADiag report.

    (Note: the Line 'CD %win......\SoftwareProtectionPlatform' is all on one line - it may be broken in the Forum listing)
      My Computer


  4. Posts : 55
    Windows 7
       #4

    Hi

    I'm trying your recreating the Licensing Store

    slui.exe

    gives me: Access denied [in Run as Administrator]

    and
    REN tokens.dat tokens.bak [ you mis-spelled I think]

    cant find the file specified

    Any ideas?

    Thx
      My Computer


  5. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #5

    In that case you have some severe permissions problems.


    Open an Elevated Command Prompt, and run the following commands

    sc sdshow plugplay
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18" /S
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19" /S
    REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20" /S


    Copy and paste the results to your reply


    Here are some instructions to make life easier :)
    1) To open an Elevated Command Prompt Window (the ECP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt.
    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Window, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once.
    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.
      My Computer


  6. Posts : 55
    Windows 7
       #6

    Thx for suggestions. I ran your text - here are results

    *******
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>sc sdshow plugplay

    DA;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCR
    RC;;;IU)(A;;CCLCSWLOCRRC;;;SU)SAU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5-18" /S

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-18
    Flags REG_DWORD 0xc
    State REG_DWORD 0x0
    RefCount REG_DWORD 0x1
    Sid REG_BINARY 010100000000000512000000
    ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprof
    ile


    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5-19" /S

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-
    5-19
    ProfileImagePath REG_EXPAND_SZ C:\Windows\ServiceProfiles\LocalService

    Flags REG_DWORD 0x0
    State REG_DWORD 0x0


    C:\Windows\system32>REG QUERY "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
    CurrentVersion\ProfileList\S-1-5-20" /S

    ****

    Thx again
      My Computer


  7. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #7

    That looks normal enough - although the last command didn't run.
    let's look at it another way...

    Open an Elevated Command Prompt, and run the following commands...

    ICACLS C:\Windows\System32\SLUI.EXE
    ICACLS C:\Windows\System32
    ICACLS C:\Windows

    Post the results.
      My Computer


  8. Posts : 55
    Windows 7
       #8

    Hi NoelDP,

    Seems ok:

    ****

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE
    C:\Windows\System32\SLUI.EXE EveryoneDENY)(S,X)
    NT AUTHORITY\SYSTEMI)(F)
    BUILTIN\AdministratorsI)(F)
    BUILTIN\UsersI)(RX)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows\System32
    C:\Windows\System32 NT SERVICE\TrustedInstallerF)
    NT SERVICE\TrustedInstallerCI)(IO)(F)
    NT AUTHORITY\SYSTEMM)
    NT AUTHORITY\SYSTEMOI)(CI)(IO)(F)
    BUILTIN\AdministratorsM)
    BUILTIN\AdministratorsOI)(CI)(IO)(F)
    BUILTIN\UsersRX)
    BUILTIN\UsersOI)(CI)(IO)(GR,GE)
    CREATOR OWNEROI)(CI)(IO)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>ICACLS C:\Windows
    C:\Windows NT SERVICE\TrustedInstallerF)
    NT SERVICE\TrustedInstallerCI)(IO)(F)
    NT AUTHORITY\SYSTEMM)
    NT AUTHORITY\SYSTEMOI)(CI)(IO)(F)
    BUILTIN\AdministratorsM)
    BUILTIN\AdministratorsOI)(CI)(IO)(F)
    BUILTIN\UsersRX)
    BUILTIN\UsersOI)(CI)(IO)(GR,GE)
    CREATOR OWNEROI)(CI)(IO)(F)

    Successfully processed 1 files; Failed processing 0 files

    C:\Windows\system32>^V
    *****
      My Computer


  9. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #9

    There's one I've never seen before...
    Code:
    C:\Windows\system32>ICACLS C:\Windows\System32\SLUI.EXE
    C:\Windows\System32\SLUI.EXE Everyone:(DENY)(S,X)
    NT AUTHORITY\SYSTEM:(I)(F)
    BUILTIN\Administrators:(I)(F)
    BUILTIN\Users:(I)(RX)
    I'm not sure how best to go about this - but let's try the obvious one first...


    Open an Elevated Command Prompt, and run the following commands...

    ICACLS C:\Windows\System32 /findsid Everyone /T /C
    ICACLS C:\Windows\System32\SLUI.EXE /remove:d Everyone
    ICACLS C:\Windows\System32\SLUI.EXE /grant "NT SERVICE\TrustedInstaller"F)
    ICACLS C:\Windows\System32\SLUI.EXE

    Don't bother posting all the output - just the last 25 or so lines will do.
    It will tell me if any significant number of other files have been tampered in the same way.
      My Computer


  10. Posts : 55
    Windows 7
       #10

    Hi,

    Hope you'll forgive - bit more than 25 lines - because it shows "Access is denied" to Printer files - and I at mo. am having major probs with Printing ops - after failed new Epson installation. When I open Print in several progs, they go into endless loops, Devices and Printers won't open,and Word won't open, despite Windows auto-reconfiguring it twice. So this stuff may provide clue. Many thx again

    C:\Windows\System32\spool\PRINTERS\*: Access is denied.
    C:\Windows\System32\spool\SERVERS\MIKE-PC: Access is denied.
    C:\Windows\System32\spool\SERVERS\MIKE-PC\*: Access is denied.
    C:\Windows\System32\sysprep\Panther\IE\diagerr.xml: Access is denied.
    C:\Windows\System32\sysprep\Panther\IE\diagwrn.xml: Access is denied.
    C:\Windows\System32\sysprep\Panther\IE\setupact.log: Access is denied.
    C:\Windows\System32\sysprep\Panther\IE\setuperr.log: Access is denied.
    C:\Windows\System32\Tasks\*: Access is denied.
    SID Found: C:\Windows\System32\Wat\WatAdminSvc.exe.
    SID Found: C:\Windows\System32\Wat\WatUX.exe.
    C:\Windows\System32\wbem\MOF: Access is denied.
    C:\Windows\System32\wbem\AutoRecover\1BA88ACB624E02A260404A9D8F7BD8E5.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\26A5A04A346330E389400293E01228AC.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\32C943873CC624333BD0BF2A77384240.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\3FA3650B664BC96A8672EC85A7AE4225.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\451233ED13E097000776690B79D8D753.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\542DC56D520FDDEDA279A0D2F398203D.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\6792FDA793556851BD20EA3DD8BD4F6B.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\6F8564A71977AE6B940705DCC4847A8D.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\7073EBB8E2F3C70E0FA1F650B7DEA970.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\716FDC254E211F547A560E1A71D0E6CA.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\779E080B33F322115205BB50F1E0B8D1.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\7C45C8B7490D3AD44A961494C7FBFAFD.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\807DD20ADF6F5D5EEA0C4E4CF016E69E.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\BBF206490BAA431B592F9A13534F43F6.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\CF881EBD6F50B8BAA9BD57DC3DAC5CB2.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\D361F8B496FD6DAF7BEEF497E09C0DC1.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\E6195BA9E153534E5472835E2F29A5B0.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\AutoRecover\F10B24E451DC4F5B5B66AEE71603E35B.mof: Acces
    s is denied.
    C:\Windows\System32\wbem\MOF\*: Access is denied.
    C:\Windows\System32\wdi\*: Access is denied.
    C:\Windows\System32\wfp\*: Access is denied.
    C:\Windows\System32\winevt\Logs\Application.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\HardwareEvents.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Internet Explorer.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Key Management Service.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Media Center.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Proble
    m-Steps-Recorder.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Progra
    m-Compatibility-Assistant.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Progra
    m-Compatibility-Troubleshooter.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Progra
    m-Inventory.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Progra
    m-Telemetry.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4CaptureMonitor.evtx: Ac
    cess is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4Operational.evtx: Acces
    s is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Backup.evtx: Access is denied.

    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx:
    Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-BranchCacheSMB%4Operational.ev
    tx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evt
    x: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-DateTimeControlPanel%4Operatio
    nal.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx: Acces
    s is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx: Acc
    ess is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evt
    x: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operation
    al.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx
    : Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Operationa
    l.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-ScriptedDiagnosticsP
    rovider%4Operational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operat
    ional.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Opera
    tional.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4O
    perational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Ope
    rational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operation
    al.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx:
    Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Control Panel%4Opera
    tional.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Provider Service%4Op
    erational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evt
    x: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evt
    x: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operatio
    nal.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.e
    vtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx: Acce
    ss is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx:
    Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx
    : Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational
    .evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Admin.evtx: Access is den
    ied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx: Access
    is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtx: Access
    is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Opera
    tional.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.e
    vtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkLocationWizard%4Operati
    onal.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkProfile%4Operational.ev
    tx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-NlaSvc%4Operational.evtx: Acce
    ss is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-OfflineFiles%4Operational.evtx
    : Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-PrintService%4Admin.evtx: Acce
    ss is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx:
    Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4
    Operational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4
    Operational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4
    Operational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.ev
    tx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionM
    anager%4Admin.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionM
    anager%4Operational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operat
    ional.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-User Profile Service%4Operatio
    nal.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-WER-Diag%4Operational.evtx: Ac
    cess is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.
    evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx: Ac
    cess is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced
    Security%4ConnectionSecurity.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced
    Security%4Firewall.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.ev
    tx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsSystemAssessmentTool%4O
    perational.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operation
    al.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx: Ac
    cess is denied.
    C:\Windows\System32\winevt\Logs\Microsoft-Windows-WPD-MTPClassDriver%4Operationa
    l.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\ODiag.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\OSession.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Security.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Setup.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\System.evtx: Access is denied.
    C:\Windows\System32\winevt\Logs\Windows PowerShell.evtx: Access is denied.
    Successfully processed 14790 files; Failed processing 130 files

    C:\Users\Mike>ICACLS C:\Windows\System32\SLUI.EXE /remove:d Everyone
    C:\Windows\System32\SLUI.EXE: Access is denied.
    Successfully processed 0 files; Failed processing 1 files

    C:\Users\Mike>ICACLS C:\Windows\System32\SLUI.EXE /grant "NT SERVICE\TrustedInst
    aller"F)
    Invalid parameter "NT SERVICE\TrustedInstallerF)"

    C:\Users\Mike>ICACLS C:\Windows\System32\SLUI.EXE
    C:\Windows\System32\SLUI.EXE EveryoneDENY)(S,X)
    NT AUTHORITY\SYSTEMI)(F)
    BUILTIN\AdministratorsI)(F)
    BUILTIN\UsersI)(RX)

    Successfully processed 1 files; Failed processing 0 files
      My Computer


 
Page 1 of 6 123 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:14.
Find Us