KB2732487 is unable to update - Error Code 800700B7

Hmmm.
The common meaning of this error code is 'cannot create a file where this file already exists'
What that means in the context of a Windows Update is anyone's guess :)

It could refer to a number of things - the extraction folders, the extracted files, or the target location (or even registry entries)

Trawling the forums for solutions isn't getting me anywhere that I can see - most threads are totally inconclusive, or end up being solved by reinstalls.

If you're prepared for what could be a very long haul, then we can try and fix it (if I can find the errant references!)
If you'd rather have a quick solution, then a repair install would be your best bet.

Let me know.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Hi Noel,

Let's try option 1 - to fix this.

However, it is time for me to get some rest as it is a bit late and I got something up tomorrow morning.

Thanks for helping! You have been a great help! :)

Let me know what I need to do and I will update here again. See you tomorrow!
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
(You're a braver man than I am! :))

OK - I'll work up some instructions to go on a fact-finding expedition :)
I'll have them for your morning coffee.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Please open an Elevated Command Prompt, and run the following commands
Code:
DIR C:\ >%userprofile%\desktop\nplog.log
DIR C:\ /AH >>%userprofile%\desktop\nplog.log
DIR C:\Windows\Temp >>%userprofile%\desktop\nplog.log
DIR C:\Windows\Servicing\Packages\Package_for_KB2719857* >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\494814537ad..ecadc3cd7f9_31bf3856ad364e35_6.1.7601.22097_ebfea08197c02d91" >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\7204f34e7a2..45b666f42e5_31bf3856ad364e35_6.1.7601.22044_d9c34e4a2b46602e" >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\netrndis.inf_31bf3856ad364e35_6.1.7601.17887_259febb55ca2345a" >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\ApplicabilityEvaluationCache\Package_for_KB2719857~31bf3856ad364e35~amd64~~6.1.1.2" >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2719857_SP1~31bf3856ad364e35~amd64~~6.1.1.2" >>%userprofile%\desktop\nplog.log
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2719857~31bf3856ad364e35~amd64~~6.1.1.2" >>%userprofile%\desktop\nplog.log
 
.
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Here it is:

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>DIR C:\ >%userprofile%\desktop\nplog.log
C:\windows\system32>DIR C:\ /AH >>%userprofile%\desktop\nplog.log
C:\windows\system32>DIR C:\Windows\Temp >>%userprofile%\desktop\nplog.log
C:\windows\system32>DIR C:\Windows\Servicing\Packages\Package_for_KB2719857* >>%
userprofile%\desktop\nplog.log
C:\windows\system32>REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\4948145
37ad..ecadc3cd7f9_31bf3856ad364e35_6.1.7601.22097_ebfea08197c02d91" >>%userprofi
le%\desktop\nplog.log
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\7204f34
e7a2..45b666f42e5_31bf3856ad364e35_6.1.7601.22044_d9c34e4a2b46602e" >>%userprofi
le%\desktop\nplog.log
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>REG QUERY "HKLM\COMPONENTS\CanonicalData\Deployments\netrndi
s.inf_31bf3856ad364e35_6.1.7601.17887_259febb55ca2345a" >>%userprofile%\desktop\
nplog.log
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Co
mponent Based Servicing\ApplicabilityEvaluationCache\Package_for_KB2719857~31bf3
856ad364e35~amd64~~6.1.1.2" >>%userprofile%\desktop\nplog.log
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Co
mponent Based Servicing\Packages\Package_for_KB2719857_SP1~31bf3856ad364e35~amd6
4~~6.1.1.2" >>%userprofile%\desktop\nplog.log
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Co
mponent Based Servicing\Packages\Package_for_KB2719857~31bf3856ad364e35~amd64~~6
.1.1.2" >>%userprofile%\desktop\nplog.log
C:\windows\system32>
C:\windows\system32>.
'.' is not recognized as an internal or external command,
operable program or batch file.
C:\windows\system32>
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
Great - you should now have a file nplog.log on your desktop - please attach it to a reply.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
here it is!
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
The registry entries are interesting - but I'm not certain how to interpret them.
The
LastError REG_DWORD 0x80070426
entry tends to indicate that a service was unable to start - but the question then obviously is 'which service'?


Please downloadthe Farbar Service Scanner from



http://www.bleepingcomputer.com/download/farbar-service-scanner/



Run it, and tickall the options, then click on the Scan button - copy and paste the report toyour response.



 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Here is the report, thank you.

Farbar Service Scanner Version: 03-03-2013
Ran by user (administrator) on 17-03-2013 at 20:04:05
Running from "C:\Users\user\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Attempt to access Yahoo.com returned error: Yahoo.com is offline
IE proxy is enabled.
ProxyServer: http=proxy.singnet.com.sg:8080


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============
cryptsvc Service is not running. Checking service configuration:
The start type of cryptsvc service is OK.
The ImagePath of cryptsvc service is OK.
The ServiceDll of cryptsvc: "%SystemRoot%\system32\cryptsvc.dll".


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
The cryptsvc not running would explain a lot!
The question become - why not?

Please open an Elevated Command Prompt, and run the following commands - post the results.

NET START CRYPTSVC
REG QUERY HKLM\SYSTEM\CurrentControlSet\services\CryptSvc /S
SFC /SCANFILE C:\Windows\System32\cryptsvc.dll

(the last one may take a couple of inutes - please wait for it to complete)
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Here you go,


Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>NET START CRYPTSVC
The Cryptographic Services service is starting.
The Cryptographic Services service was started successfully.

C:\windows\system32> REG QUERY HKLM\SYSTEM\CurrentControlSet\services\CryptSvc /
S
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc
DisplayName REG_SZ @%SystemRoot%\system32\cryptsvc.dll,-1001
ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k NetworkSe
rvice
Description REG_SZ @%SystemRoot%\system32\cryptsvc.dll,-1002
ObjectName REG_SZ NT Authority\NetworkService
ErrorControl REG_DWORD 0x1
Start REG_DWORD 0x2
Type REG_DWORD 0x20
DependOnService REG_MULTI_SZ RpcSs
ServiceSidType REG_DWORD 0x1
RequiredPrivileges REG_MULTI_SZ SeChangeNotifyPrivilege\0SeCreateGloba
lPrivilege\0SeImpersonatePrivilege
FailureActions REG_BINARY 80510100000000000000000003000000140000000100
000060EA000000000000000000000000000000000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc\Parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\system32\cryptsvc.dll
ServiceMain REG_SZ CryptServiceMain
ServiceDllUnloadOnStop REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc\Security
Security REG_BINARY 00000E0001

C:\windows\system32> SFC /SCANFILE C:\Windows\System32\cryptsvc.dll
Microsoft (R) Windows (R) Resource Checker Version 6.0
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
Scans the integrity of all protected system files and replaces incorrect version
s with
correct Microsoft versions.
SFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]
[/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory>
]
/SCANNOW Scans integrity of all protected system files and repairs files
with
problems when possible.
/VERIFYONLY Scans integrity of all protected system files. No repair operati
on is
performed.
/SCANFILE Scans integrity of the referenced file, repairs file if problems
are
identified. Specify full path <file>
/VERIFYFILE Verifies the integrity of the file with full path <file>. No re
pair
operation is performed.
/OFFBOOTDIR For offline repair specify the location of the offline boot dire
ctory
/OFFWINDIR For offline repair specify the location of the offline windows d
irectory
e.g.
sfc /SCANNOW
sfc /VERIFYFILE=c:\windows\system32\kernel32.dll
sfc /SCANFILE=d:\windows\system32\kernel32.dll /OFFBOOTDIR=d:\ /OFFWINDI
R=d:\windows
sfc /VERIFYONLY
C:\windows\system32>
C:\windows\system32>
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
OK - so the service does start, but seems to stop for some reason.
The registry entry looks normal to me.

Please run the following commands and post the results.
Code:
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost"
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService"
REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost"
REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService"
 
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Svchost"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
RPCSS REG_MULTI_SZ RpcEptMapper\0RpcSs
defragsvc REG_MULTI_SZ defragsvc
LocalSystemNetworkRestricted REG_MULTI_SZ UxSms\0WdiSystemHost\0Netman
\0trkwks\0AudioEndpointBuilder\0WUDFSvc\0IPBusEnum\0hidserv\0dot3svc\0irmon\0sys
main\0PcaSvc\0homegrouplistener\0WPDBusEnum\0wlansvc\0TabletInputService
LocalService REG_MULTI_SZ nsi\0WdiServiceHost\0w32time\0EventSystem\0R
emoteRegistry\0WinHttpAutoProxySvc\0sppuinotify\0THREADORDER\0netprofm\0lltdsvc\
0fdphost\0SstpSvc\0WebClient
netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserv
er\0gpsvc\0IKEEXT\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Nt
mssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedac
cess\0SRService\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDet
ection\0LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0seclogon\0AppInfo\0ms
iscsi\0MMCSS\0winmgmt\0SessionEnv\0browser\0EapHost\0schedule\0hkmsvc\0wercplsup
port\0ProfSvc\0Themes\0BDESVC
WerSvcGroup REG_MULTI_SZ wersvc
LocalServiceNoNetwork REG_MULTI_SZ DPS\0PLA\0BFE\0mpssvc\0WwanSvc
termsvcs REG_MULTI_SZ TermService
swprv REG_MULTI_SZ swprv
LocalServiceNetworkRestricted REG_MULTI_SZ DHCP\0eventlog\0AudioSrv\0B
thHFSrv\0LmHosts\0wscsvc\0homegroupprovider\0WPCSvc
LocalServicePeerNet REG_MULTI_SZ PNRPSvc\0p2pimsvc\0p2psvc\0PnrpAutoRe
g
NetworkServiceAndNoImpersonation REG_MULTI_SZ KtmRm
regsvc REG_MULTI_SZ RemoteRegistry
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSv
r\0TBS\0fdrespub\0FontCache\0AppIDSvc\0QWAVE\0wcncsvc\0Mcx2Svc\0SensrSvc
DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0lan
manworkstation\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
sdrsvc REG_MULTI_SZ sdrsvc
WbioSvcGroup REG_MULTI_SZ WbioSrvc
imgsvc REG_MULTI_SZ StiSvc
wcssvc REG_MULTI_SZ WcsPlugInService
AxInstSVGroup REG_MULTI_SZ AxInstSV
secsvcs REG_MULTI_SZ WinDefend
bthsvcs REG_MULTI_SZ bthserv
GPSvcGroup REG_MULTI_SZ GPSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\AxInstSV
Group
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\defragsv
c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\GPSvcGro
up
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
vice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
viceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
viceNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
viceNoNetwork
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSys
temNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
ervice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
erviceRemoteDesktopHyperVAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
erviceRemoteDesktopPublishing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\SDRSVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\swprv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\wercplsu
pport
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Svchost\NetworkService"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
ervice
CoInitializeSecurityParam REG_DWORD 0x1
DefaultRpcStackSize REG_DWORD 0x1c

C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\Cu
rrentVersion\Svchost"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost
netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserv
er\0gpsvc\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Ntmssvc\0N
WCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedaccess\0SR
Service\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDetection\0
LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0msiscsi\0schedule\0SessionEnv
\0winmgmt
LocalService REG_MULTI_SZ RemoteRegistry\0WinHttpAutoProxySvc\0sppuino
tify\0netprofm\0WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ Netman\0AudioEndpointBuilder
\0dot3svc\0WPDBusEnum\0wlansvc
LocalServiceNoNetwork REG_MULTI_SZ PLA
rpcss REG_MULTI_SZ RpcSs
LocalServiceNetworkRestricted REG_MULTI_SZ AudioSrv\0BthHFSrv\0LmHosts
\0wscsvc\0WPCSvc
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSv
r\0TBS\0QWAVE\0wcncsvc
DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0Nap
Agent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
imgsvc REG_MULTI_SZ StiSvc
wcssvc REG_MULTI_SZ WcsPlugInService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\LocalServiceNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\LocalServiceNoNetwork
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\LocalSystemNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\NetworkService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\NetworkServiceRemoteDesktopHyperVAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\NetworkServiceRemoteDesktopPublishing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\termsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\wcssvc
C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\Cu
rrentVersion\Svchost\NetworkService"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
ost\NetworkService
CoInitializeSecurityParam REG_DWORD 0x1
DefaultRpcStackSize REG_DWORD 0x1c

C:\windows\system32>
C:\windows\system32>.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
That looks normal

Please run the following commands and post the results

SC QUERYEX CRYPTSVC
SC QUERYEX EVENTLOG

reboot and run the commands again, then post an MGADiag report - it may show something...




http://www.sevenforums.com/windows-updates-activation/234159-windows-genuine-activation-issue-posting-instructions.html



Ignore errors produced when clicking on theCopy button - they simply mean that the tool could not create the backup filesfor some reason. The data is still copied to the clipboard for pasting to yourresponse.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
The reports before and after seems to be the same. I have attached it in the notepads.




Code:
Diagnostic Report 
(1.9.0027.0):
-----------------------------------------
Windows Validation 
Data-->

 
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows 
Product Key: *****-*****-4F8HK-M4P73-W8DQG
Windows Product Key Hash: 
Xs1iQgVeo0C+sObJxS7eu+FuBPQ=
Windows Product ID: 
00359-OEM-8992687-00057
Windows Product ID Type: 2
Windows License Type: 
OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: 
{F20E3B27-F478-4816-8F07-14C7B2FFE745}(1)
Is Admin: Yes
TestCab: 
0x0
LegitcheckControl ActiveX: Registered, 1.9.42.0
Signed By: 
Microsoft
Product Name: Windows 7 Home Premium
Architecture: 
0x00000009
Build lab: 7601.win7sp1_gdr.130104-1431
TTS Error: 

Validation Diagnostic: 
Resolution Status: N/A

 
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, 
hr = 0x80070002

 
Windows XP Notifications Data-->
Cached Result: N/A, hr = 
0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe 
Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 
0x80070002

 
OGA Notifications Data-->
Cached Result: N/A, hr = 
0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 
0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

 
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 
0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 
025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

 
Browser Data-->
Proxy settings: http=proxy.singnet.com.sg:8080
User 
Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program 
Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: 
Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls 
and plug-ins: Allowed
Initialize and script ActiveX controls not marked as 
safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: 
Allowed
Active scripting: Allowed
Script ActiveX controls marked as safe 
for scripting: Allowed

 
File Scan Data-->
File Mismatch: 
C:\windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
File 
Mismatch: C:\windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 
0x80092003
File Mismatch: C:\windows\system32\sppobjs.dll[6.1.7601.17514], Hr 
= 0x80092003
File Mismatch: C:\windows\system32\sppc.dll[6.1.7601.17514], Hr 
= 0x800b0100
File Mismatch: C:\windows\system32\sppcext.dll[6.1.7600.16385], 
Hr = 0x800b0100
File Mismatch: 
C:\windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
File 
Mismatch: C:\windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
File 
Mismatch: C:\windows\system32\slcext.dll[6.1.7600.16385], Hr = 
0x800b0100
File Mismatch: 
C:\windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
File 
Mismatch: C:\windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
File 
Mismatch: C:\windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 
0x800b0100
File Mismatch: C:\windows\system32\sppcommdlg.dll[6.1.7600.16385], 
Hr = 0x800b0100
File Mismatch: 
C:\windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
File 
Mismatch: C:\windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 
0x80092003
File Mismatch: C:\windows\system32\drivers\spldr.sys[6.1.7127.0], 
Hr = 0x80092003
File Mismatch: 
C:\windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
File 
Mismatch: C:\windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100

 
Other data-->
Office Details: 
<GenuineResults><MachineData><UGUID>{F20E3B27-F478-4816-8F07-14C7B2FFE745}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-W8DQG</PKey><PID>00359-OEM-8992687-00057</PID><PIDType>2</PIDType><SID>S-1-5-21-4064131365-3982532405-1399218412</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Qosmio 
F60</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 
2.70  </Version><SMBIOSVersion major="2" 
minor="5"/><Date>20101207000000.000000+000</Date></BIOS><HWID>EC1B3107018400FE</HWID><UserLCID>4809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Malay 
Peninsula Standard 
Time(GMT+08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSHIB</OEMID><OEMTableID>A007A   
</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  


 
Spsys.log Content: 0x80070002

 
Licensing Data-->
Software licensing service version: 
6.1.7601.17514

 
Name: Windows(R) 7, HomePremium edition
Description: Windows Operating 
System - Windows(R) 7, OEM_SLP channel
Activation ID: 
d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 
55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 
00359-00178-926-800057-02-1033-7600.0000-2492010
Installation ID: 
013902150052123840938622931670999034916864230355573526
Processor Certificate 
URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88338[/URL]
Machine 
Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88339[/URL]
Use 
License URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88341[/URL]
Product 
Key Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88340[/URL]
Partial 
Product Key: W8DQG
License Status: Licensed
Remaining Windows rearm count: 
4
Trusted time: 17/3/2013 10:35:34 PM

 
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: 
N/A
HealthStatus: 0x0000000000000010
Event Time Stamp: N/A
ActiveX: 
Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 
7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: 
%systemroot%\system32\sppobjs.dll

 

HWID Data-->
HWID Hash Current: 
MgAAAAEABAABAAEAAAABAAAAAgABAAEAln2EjUNoJBOYexClQJLMawDyDrXafFRgdlY=

 
OEM Activation 1.0 Data-->
N/A

 
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker 
version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 

  ACPI Table Name OEMID Value OEMTableID Value
  
APIC   TOSHIB  A007A   
  
FACP   TOSHIB  A007A   
  
DBGP   TOSHIB  A007A   
  
HPET   TOSHIB  A007A   
  
BOOT   TOSHIB  A007A   
  
MCFG   TOSHIB  A007A   
  
SLIC   TOSHIB  A007A   
  
SSDT   TOSHIB  SataAhci
  
SSDT   TOSHIB  SataAhci
  
ASF!   TOSHIB  A007A   
  
SSDT   TOSHIB  SataAhci
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Here's the report:


Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-4F8HK-M4P73-W8DQG
Windows Product Key Hash: Xs1iQgVeo0C+sObJxS7eu+FuBPQ=
Windows Product ID: 00359-OEM-8992687-00057
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {F20E3B27-F478-4816-8F07-14C7B2FFE745}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.130104-1431
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: http=proxy.singnet.com.sg:8080
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Allowed
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
File Mismatch: C:\windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 0x80092003
File Mismatch: C:\windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
File Mismatch: C:\windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
File Mismatch: C:\windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
File Mismatch: C:\windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
File Mismatch: C:\windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
File Mismatch: C:\windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
File Mismatch: C:\windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{F20E3B27-F478-4816-8F07-14C7B2FFE745}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-W8DQG</PKey><PID>00359-OEM-8992687-00057</PID><PIDType>2</PIDType><SID>S-1-5-21-4064131365-3982532405-1399218412</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Qosmio F60</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 2.70 </Version><SMBIOSVersion major="2" minor="5"/><Date>20101207000000.000000+000</Date></BIOS><HWID>EC1B3107018400FE</HWID><UserLCID>4809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Malay Peninsula Standard Time(GMT+08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSHIB</OEMID><OEMTableID>A007A </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00178-926-800057-02-1033-7600.0000-2492010
Installation ID: 013902150052123840938622931670999034916864230355573526
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: W8DQG
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 18/3/2013 12:08:47 AM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x0000000000000010
Event Time Stamp: N/A
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\sppobjs.dll

HWID Data-->
HWID Hash Current: MgAAAAEABAABAAEAAAABAAAAAgABAAEAln2EjUNoJBOYexClQJLMawDyDrXafFRgdlY=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC TOSHIB A007A
FACP TOSHIB A007A
DBGP TOSHIB A007A
HPET TOSHIB A007A
BOOT TOSHIB A007A
MCFG TOSHIB A007A
SLIC TOSHIB A007A
SSDT TOSHIB SataAhci
SSDT TOSHIB SataAhci
ASF! TOSHIB A007A
SSDT TOSHIB SataAhci
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
Serves me right for not fully reading the report :(
buried near the bottom is the cause of your problems.

Tampered File: %systemroot%\system32\sppobjs.dll


What I don't understand is why that error isn't showing in the SFC results in your initial post.

Please run another SFC /SCANNOW, and post the new CBS.log
Please also run the following commands and post the results.

DIR C:\Windows\sppobjs.dll /S
DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
REG LOAD HKLM\COMPONENTS C:\Windows\System32\config\COMPONENTS
REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
REG UNLOAD HKLM\COMPONENTS
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
CBS log is attached and the report is here: :)

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>DIR C:\Windows\sppobjs.dll /S
Volume in drive C is S3A5912D001
Volume Serial Number is 5461-260C
Directory of C:\Windows\System32
20/11/2010 09:27 PM 1,082,880 sppobjs.dll
1 File(s) 1,082,880 bytes
Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
1bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
14/07/2009 09:41 AM 1,082,880 sppobjs.dll
1 File(s) 1,082,880 bytes
Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
1bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
20/11/2010 09:27 PM 1,082,880 sppobjs.dll
1 File(s) 1,082,880 bytes
Total Files Listed:
3 File(s) 3,248,640 bytes
0 Dir(s) 260,699,267,072 bytes free
C:\windows\system32> DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plug
in-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
Volume in drive C is S3A5912D001
Volume Serial Number is 5461-260C
Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
1bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
14/07/2009 11:20 AM <DIR> .
14/07/2009 11:20 AM <DIR> ..
14/07/2009 09:55 AM 11,758 sppobjs-spp-plugin-manifest-signed.xrm-ms
14/07/2009 09:41 AM 1,082,880 sppobjs.dll
2 File(s) 1,094,638 bytes
2 Dir(s) 260,699,267,072 bytes free
C:\windows\system32> DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plug
in-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
Volume in drive C is S3A5912D001
Volume Serial Number is 5461-260C
Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
1bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
09/08/2011 11:42 AM <DIR> .
09/08/2011 11:42 AM <DIR> ..
20/11/2010 09:43 PM 11,758 sppobjs-spp-plugin-manifest-signed.xrm-ms
20/11/2010 09:27 PM 1,082,880 sppobjs.dll
2 File(s) 1,094,638 bytes
2 Dir(s) 260,699,267,072 bytes free
C:\windows\system32> REG LOAD HKLM\COMPONENTS C:\Windows\System32\config\COMPONE
NTS
The operation completed successfully.
C:\windows\system32> REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_micr
osoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4
e4a00e66f1
HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..
y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
identity REG_BINARY 4D6963726F736F66742D57696E646F77732D53656375726974
792D5350502D506C7567696E2D436F6D6D6F6E2C2043756C747572653D6E65757472616C2C205665
7273696F6E3D362E312E373630302E31363338352C205075626C69634B6579546F6B656E3D333162
663338353661643336346533352C2050726F636573736F724172636869746563747572653D616D64
36342C2076657273696F6E53636F70653D4E6F6E537853
S256H REG_BINARY 1137570264EB23861382BBEC6332088399E57D4E4250BD12731DD
58F4E6036B0
f!sppobjs-spp-plugin-manife_cc9ad20225dac2f2 REG_BINARY 7300700070006F
0062006A0073002D007300700070002D0070006C007500670069006E002D006D0061006E00690066
006500730074002D007300690067006E00650064002E00780072006D002D006D007300
f!sppobjs.dll REG_BINARY 7300700070006F0062006A0073002E0064006C006C00
c!windowsfoundation_31bf3856ad364e35_6.1.7600.16385_5f2ecc1aaa4ac3b2 REG_
BINARY

C:\windows\system32> REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_micr
osoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8
ac9cfcea8b
HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..
y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
identity REG_BINARY 4D6963726F736F66742D57696E646F77732D53656375726974
792D5350502D506C7567696E2D436F6D6D6F6E2C2043756C747572653D6E65757472616C2C205665
7273696F6E3D362E312E373630312E31373531342C205075626C69634B6579546F6B656E3D333162
663338353661643336346533352C2050726F636573736F724172636869746563747572653D616D64
36342C2076657273696F6E53636F70653D4E6F6E537853
S256H REG_BINARY 91A4040F9874EF8DD585885002D2133708D179F424BA04059E08C
490F0B20822
c!windowsfoundation_31bf3856ad364e35_6.1.7601.17514_615fdfe2a739474c REG_
BINARY
f!sppobjs-spp-plugin-manife_cc9ad20225dac2f2 REG_BINARY 7300700070006F
0062006A0073002D007300700070002D0070006C007500670069006E002D006D0061006E00690066
006500730074002D007300690067006E00650064002E00780072006D002D006D007300
f!sppobjs.dll REG_BINARY 7300700070006F0062006A0073002E0064006C006C00

C:\windows\system32> REG UNLOAD HKLM\COMPONENTS
ERROR: Access is denied.
C:\windows\system32>
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Toshiba
OS
Windows 7 Home Premium 64bit
Memory
8.00GB
Antivirus
AVG
Browser
Internet Explorer
Strange that you weren't allowed to unload the hive at the end, there - but I don't think it's a problem.
Please try running that command again (Elevated CP again)...

REG UNLOAD HKLM\COMPONENTS

I can't see anything wrong there at all, and SFC still says that there's nothing wrong.

Please run the following commands and post the results.

REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules" /S
ICACLS %systemroot%\system32\sppobjs.dll
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Back
Top