Win 7 Home no longer genuine error 0x8004FE21

darknightwing

New member
Local time
1:42 PM
Messages
9
System properties shows the computer is activated. But I keep receiving a pop up saying its not genuine and click to resolve. Microsoft's website says I need to purchase Windows 7. I verified the product key is the one on the side of the pc.

Here is the diagnostic log.

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-QCPVQ-KHRB8-RMV82
Windows Product Key Hash: +Rj3N34NLM2JqoBO/OzgzTZXgbY=
Windows Product ID: 00359-OEM-8992687-00095
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {0F7885A4-0039-49AF-982D-9BC3452E4804}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120830-0333
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Office XP Professional - 100 Genuine
Microsoft Office Access Runtime (English) 2007 - 121
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\slc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{0F7885A4-0039-49AF-982D-9BC3452E4804}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-RMV82</PKey><PID>00359-OEM-8992687-00095</PID><PIDType>2</PIDType><SID>S-1-5-21-520870393-465678712-3318434586</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Studio XPS 8000</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A01</Version><SMBIOSVersion major="2" minor="5"/><Date>20090811000000.000000+000</Date></BIOS><HWID>0FCC3607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL </OEMID><OEMTableID>FX09 </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91110409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional</Name><Ver>10</Ver><Val>90DFC4EEEA903E</Val><Hash>Nfd7TCeLbVubMW2z4h7sHsaoZhI=</Hash><Pid>54186-OEM-1793044-33055</Pid><PidType>4</PidType></Product><Product GUID="{90120000-001C-0409-0000-0000000FF1CE}"><LegitResult>121</LegitResult><Name>Microsoft Office Access Runtime (English) 2007</Name><Ver>12</Ver><Val>A6DF1BF2503CD6C</Val><Hash>dTTDvXHN4cR0t+IYAOhhFudJX58=</Hash><Pid>00000-694-0010114-62650</Pid><PidType>2</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Software licensing service version: 6.1.7601.17514

Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00178-926-800095-02-1033-7601.0000-2862012
Installation ID: 009852349214400176227433939404314094041495394026576960
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: RMV82
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 12/7/2012 11:54:46 AM

Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000000C370
Event Time Stamp: 12:7:2012 11:57
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\sppobjs.dll
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


HWID Data-->
HWID Hash Current: NgAAAAIABAABAAEAAAACAAAAAgABAAEAln3eESLoAmOUVoCWQsb211T9mnKaiD43ABy8DnZW

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC DELL FX09
FACP DELL FX09
HPET DELL OEMHPET
MCFG DELL OEMMCFG
SLIC DELL FX09
OSFR DELL FX09
OEMB DELL FX09
GSCI DELL GMCHSCI


Any help would be great.
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
Interesting selection of error messages there! - I don't recall seeing that combination before.

Please run a full CHKDSK and SFC scan....

Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

At the Command prompt, type

CHKDSK C: /R

and hit the Enter key.
You will be told that the drive is locked,
and the CHKDSK will run at he next boot - hit the Y key, and then reboot.

The CHKDSK will take a few hours depending on the size of the drive, so be patient!

After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -
then run the SFC.

SFC -System File Checker - Instructions
Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

At the Command prompt, type

SFC /SCANNOW

and hit the Enter key

Wait for the scan to finish - make a note of any error messages - and then reboot.


Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive (http://skydrive.live.com ) and post a link to it so that I can take a look.

Post a new MGADiag report with details of any error messages encountered.
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Interesting result!
Please run SFC again - it's stating that it needs it....
Code:
2012-12-07 16:44:56, Info                  CSI    000002ef [SR] Repairing 2 components
2012-12-07 16:44:56, Info                  CSI    000002f0 [SR] Beginning Verify and Repair transaction
2012-12-07 16:44:56, Info                  CSI    000002f1 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:56, Info                  CSI    000002f2 [SR] Cannot repair member file [l:20{10}]"tcpmon.ini" of Microsoft-Windows-Printing-StandardPortMonitor-TCPMonINI, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:56, Info                  CSI    000002f3 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:56, Info                  CSI    000002f4 [SR] Cannot repair member file [l:24{12}]"ntoskrnl.exe" of Microsoft-Windows-OS-Kernel, Version = 6.1.7601.17944, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:56, Info                  CSI    000002f5 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:56, Info                  CSI    000002f6 [SR] Cannot repair member file [l:20{10}]"tcpmon.ini" of Microsoft-Windows-Printing-StandardPortMonitor-TCPMonINI, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:56, Info                  CSI    000002f7 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2012-12-07 16:44:56, Info                  CSI    000002f8 Hashes for file member \??\C:\Windows\System32\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:56, Info                  CSI    000002f9 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:56, Info                  CSI    000002fa [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"tcpmon.ini"; source file in store is also corrupted
2012-12-07 16:44:56, Info                  CSI    000002fb Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:56, Info                  CSI    000002fc [SR] Cannot repair member file [l:24{12}]"ntoskrnl.exe" of Microsoft-Windows-OS-Kernel, Version = 6.1.7601.17944, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:56, Info                  CSI    000002fd [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2724197~31bf3856ad364e35~amd64~~6.1.1.3.2724197-5_neutral_GDR"
2012-12-07 16:44:56, Info                  CSI    000002fe Hashes for file member \??\C:\Windows\SysWOW64\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:56, Info                  CSI    000002ff Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:56, Info                  CSI    00000300 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"ntoskrnl.exe"; source file in store is also corrupted
2012-12-07 16:44:56, Info                  CSI    00000301 Repair results created:
POQ 121 starts:
 
POQ 121 ends.
2012-12-07 16:44:56, Info                  CSI    00000302 [SR] Repair complete
2012-12-07 16:44:56, Info                  CSI    00000303 [SR] Committing transaction
2012-12-07 16:44:56, Info                  CSI    00000304 [SR] Cannot commit interactively, there are boot critical components being repaired
2012-12-07 16:44:56, Info                  CSI    00000305 [SR] Repairing 2 components
2012-12-07 16:44:56, Info                  CSI    00000306 [SR] Beginning Verify and Repair transaction
2012-12-07 16:44:56, Info                  CSI    00000307 Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:56, Info                  CSI    00000308 [SR] Cannot repair member file [l:20{10}]"tcpmon.ini" of Microsoft-Windows-Printing-StandardPortMonitor-TCPMonINI, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:56, Info                  CSI    00000309 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:56, Info                  CSI    0000030a [SR] Cannot repair member file [l:24{12}]"ntoskrnl.exe" of Microsoft-Windows-OS-Kernel, Version = 6.1.7601.17944, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:57, Info                  CSI    0000030b Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:57, Info                  CSI    0000030c [SR] Cannot repair member file [l:20{10}]"tcpmon.ini" of Microsoft-Windows-Printing-StandardPortMonitor-TCPMonINI, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:57, Info                  CSI    0000030d [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
2012-12-07 16:44:57, Info                  CSI    0000030e Hashes for file member \??\C:\Windows\System32\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:57, Info                  CSI    0000030f Hashes for file member \SystemRoot\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini do not match actual file [l:20{10}]"tcpmon.ini" :
  Found: {l:32 b:as3OOcx5px0XiJa7f7s9BVvlW/FFlKR4NMU/T+UP/Kg=} Expected: {l:32 b:ENtKeUct91LKlHclgfWTvnCdCOHHwDe+SYrPzZTTezU=}
2012-12-07 16:44:57, Info                  CSI    00000310 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"tcpmon.ini"; source file in store is also corrupted
2012-12-07 16:44:57, Info                  CSI    00000311 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:57, Info                  CSI    00000312 [SR] Cannot repair member file [l:24{12}]"ntoskrnl.exe" of Microsoft-Windows-OS-Kernel, Version = 6.1.7601.17944, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-12-07 16:44:57, Info                  CSI    00000313 [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2724197~31bf3856ad364e35~amd64~~6.1.1.3.2724197-5_neutral_GDR"
2012-12-07 16:44:57, Info                  CSI    00000314 Hashes for file member \??\C:\Windows\SysWOW64\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:57, Info                  CSI    00000315 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe do not match actual file [l:24{12}]"ntoskrnl.exe" :
  Found: {l:32 b:5qFvOwhYt+ynk38d7eD+0kzNSppmBRnzVY4Y6LY7LIw=} Expected: {l:32 b:ok9ADE/Gt9QIX54mT20/cME9Z4wONLPjH5FjzxDkI+w=}
2012-12-07 16:44:57, Info                  CSI    00000316 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"ntoskrnl.exe"; source file in store is also corrupted
2012-12-07 16:44:57, Info                  CSI    00000317 Repair results created:
POQ 122 starts:
 
POQ 122 ends.
2012-12-07 16:44:57, Info                  CSI    00000318 [SR] Repair complete

Post the new CBS.log file afterwards.
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Actually - I may be mis-interpreting that log, and it may require that you run teh SFC in Offline mode.



Your best option in that case is to run the CHKDSK and SFC in offline mode from a Recovery Environment boot.

Reboot the computer, and tap the F8 key until you get the advanced boot menu up - one option should be 'Repair your computer'. Pick that one.

Log into your normal account.
You'll get a set of options - pick the Command Prompt one.
At the command prompt, type DIR C:\
- if we're lucky this will bring up a listing of your normal C: drive contents, including the Program Files folder(s) and the Windows folder.
If not, try D:\ or E:\ (etc. until you get the right letter)
then type the following command


sfc /scannow /OFFBOOTDIR=<drive>:\ /OFFWINDIR=<drive>:\Windows

where <drive> is the letter you found above.

Wait for the command to complete. (make a note of the response!).

Once it has, type EXIT and the pick the option to reboot.

Post another MGADiag report
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
OK, I will do that. It will be Monday before I have a chance though. This is my office computer its happening to and we are closed for the weekend. I will run sfc and chckdsk from recovery and post back Monday.

Thanks.
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
You shouldn't need to run the CHDSK again - only the SFC - which will reduce the time taken by hours :)
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
Never mind I have it running in recovery console now.
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
Here is an sfc scan from the recovery console. Sfc completed said it found errors but could not fix.

here is the CBS log. https://skydrive.live.com/redir?resid=BFCD71AB2234B8F2!157&authkey=!AETQyPpygedF2UA

here is the MGAdaig log.

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-QCPVQ-KHRB8-RMV82
Windows Product Key Hash: +Rj3N34NLM2JqoBO/OzgzTZXgbY=
Windows Product ID: 00359-OEM-8992687-00095
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {0F7885A4-0039-49AF-982D-9BC3452E4804}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120830-0333
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Office XP Professional - 100 Genuine
Microsoft Office Access Runtime (English) 2007 - 121
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\slc.dll.mui[6.1.7600.16385], Hr = 0x800b0100

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{0F7885A4-0039-49AF-982D-9BC3452E4804}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-RMV82</PKey><PID>00359-OEM-8992687-00095</PID><PIDType>2</PIDType><SID>S-1-5-21-520870393-465678712-3318434586</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Studio XPS 8000</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A01</Version><SMBIOSVersion major="2" minor="5"/><Date>20090811000000.000000+000</Date></BIOS><HWID>0FCC3607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL </OEMID><OEMTableID>FX09 </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91110409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional</Name><Ver>10</Ver><Val>90DFC4EEEA903E</Val><Hash>Nfd7TCeLbVubMW2z4h7sHsaoZhI=</Hash><Pid>54186-OEM-1793044-33055</Pid><PidType>4</PidType></Product><Product GUID="{90120000-001C-0409-0000-0000000FF1CE}"><LegitResult>121</LegitResult><Name>Microsoft Office Access Runtime (English) 2007</Name><Ver>12</Ver><Val>A6DF1BF2503CD6C</Val><Hash>dTTDvXHN4cR0t+IYAOhhFudJX58=</Hash><Pid>00000-694-0010114-62650</Pid><PidType>2</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Software licensing service version: 6.1.7601.17514

Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00178-926-800095-02-1033-7601.0000-2862012
Installation ID: 008253772586224864032990782143496930332810058351482286
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: RMV82
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 12/13/2012 9:54:09 AM

Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000000C370
Event Time Stamp: 12:13:2012 09:00
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\sppobjs.dll
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui


HWID Data-->
HWID Hash Current: NgAAAAIABAABAAEAAAACAAAAAgABAAEAln3eESLoAmP215RWgJZCxlT9mnKaiD43ABy8DnZW

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC DELL FX09
FACP DELL FX09
HPET DELL OEMHPET
MCFG DELL OEMMCFG
SLIC DELL FX09
OSFR DELL FX09
OEMB DELL FX09
GSCI DELL GMCHSCI
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
You seems to have some major problems with the MGADiag report, and surprisingly few problems according to SFC.

Here's the list of unsolved problems there (all 2 of them)
Code:
 Line 67183: 2012-12-13 08:42:47, Info                  CSI    00000308 [SR] Cannot repair member file [l:20{10}]"tcpmon.ini" of Microsoft-Windows-Printing-StandardPortMonitor-TCPMonINI, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
 Line 67186: 2012-12-13 08:42:47, Info                  CSI    0000030a [SR] Cannot repair member file [l:24{12}]"ntoskrnl.exe" of Microsoft-Windows-OS-Kernel, Version = 6.1.7601.17944, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch

I'll work on a fix for these two - but I suspect that there will be more to come.


Please download and save the CheckSUR tool from http://support.microsoft.com/kb/947821
(you'll need to look in the details for Method 2)

Run it - The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.
The result is logged in the C:\Windows\Logs\CBS\CheckSUR.log file - and an archive …\checksur.persist.log file

Then zip the CheckSUR.log and attach it to your reply
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Here's teh critical points .....
Code:
 winsxs\manifests\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.21306_none_f093daaf88d88568.manifest
 winsxs\manifests\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.17107_none_f00b3c486fba01ce.manifest

I'll post a fix tomorrow (large quantities of whisky prohibit a sensible attempt currently!)

we can then see what the situation is.
 

My Computer My Computer

At a glance

Win 7 x64 Home Premium (and x86 VirtualBox VM...i3 370M/i7 6500U8GB - finally :)/8GBit's an i3, dude!/dual Intel&nVidia
Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Hello darknightwing and welcome to the forums :party:

Noel has kindly let me repair the corruptions in your log :)

SFCFix Script

Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.


  1. Download SFCFix.exe (by niemiro) and save this to your Desktop
  2. Download the attached file, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it
  3. Save any open documents and close all open windows
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it

    SFCFix.gif
  6. SFCFix will now process the script
  7. Upon completion, two files should be created on your Desktop: SFC.txt and Trace.txt.
  8. Copy (Ctrl + C) and Paste (Ctrl + V} the contents of these files into your next post for me to analyse please - put [CODE][/CODE] tags around each log to break up the text
Tom
 
Last edited:

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
When dragging the .zip file over the sfcfix.exe file I receive an error. "the program can't start because MSVCP100.dll is missing from your computer. Try reinstalling the program to fix the problem."
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Please use this attached file instead. If you have already downloaded the previous one, delete it.
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
SFCfix.txt
Code:
SFCFix version 1.0.1.0 by niemiro.
Start time: 2012-12-14 14:22:59.640
Using .zip script file at C:\Users\AmersonWhite\Downloads\SFCFix.zip




Debug:: directive completed successfully.




TakePermissions::
Successfully took permissions for file C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
Successfully took permissions for file C:\Windows\Sysnative\tcpmon.ini
Successfully took permissions for file C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
Successfully took permissions for file C:\Windows\SysWOW64\ntoskrnl.exe
TakePermissions:: directive completed successfully.




CopyFiles::
Failed to copy file \\?\C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini to \\?\C:\Windows\Sysnative\tcpmon.ini with error code 0x20.
Successfully copied file \\?\C:\Users\AmersonWhite\AppData\Local\niemiro\Archive\ntoskrnl.exe to \\?\C:\Windows\SysWOW64\ntoskrnl.exe.
Successfully copied file \\?\C:\Users\AmersonWhite\AppData\Local\niemiro\Archive\ntoskrnl.exe to \\?\C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe.
CopyFiles:: directive completed successfully.




RestorePermissions::
Successfully restored permissions on C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
Failure code returned from icacls process in RestoreFromDataBlock function for file C:\Windows\Sysnative\tcpmon.ini. Error code 0x6.
Successfully restored permissions on C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
Failure code returned from icacls process in RestoreFromDataBlock function for file C:\Windows\SysWOW64\ntoskrnl.exe. Error code 0x6.
RestorePermissions:: directive failed to complete successfully.




TrustedInstaller::
Successfully set file ownership to TrustedInstaller for C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
Successfully set file ownership to TrustedInstaller for C:\Windows\Sysnative\tcpmon.ini
Successfully set file ownership to TrustedInstaller for C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
Successfully set file ownership to TrustedInstaller for C:\Windows\SysWOW64\ntoskrnl.exe
TrustedInstaller:: directive completed successfully.




Failed to process all directives successfully.
SFCFix version 1.0.1.0 by niemiro has completed.
Currently storing 4 datablocks.
Finish time: 2012-12-14 14:23:01.200
----------------------EOF-----------------------

Trace.txt
Code:
 2012-12-14 14:23:00.951      Info      Everyone SID was initialized successfully.
2012-12-14 14:23:00.951      Info      EXPLICIT_ACCESS initialized successfully.
2012-12-14 14:23:00.951      Info      Successfully set entries in ACL.
2012-12-14 14:23:00.951      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be enabled: SeRestorePrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be enabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.951      Info      Current User SID was initialized successfully.
2012-12-14 14:23:00.951      Info      Successfully set owner for C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
2012-12-14 14:23:00.951      Info      Successfully set owner for C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
2012-12-14 14:23:00.951      Info      Successfully set DACL.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be disabled: SeRestorePrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully un-set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be disabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully un-set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.951      Info      Everyone SID was initialized successfully.
2012-12-14 14:23:00.951      Info      EXPLICIT_ACCESS initialized successfully.
2012-12-14 14:23:00.951      Info      Successfully set entries in ACL.
2012-12-14 14:23:00.951      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be enabled: SeRestorePrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.951      Info      Successfully found the privilege.
2012-12-14 14:23:00.951      Info      Privilege is going to be enabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.951      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.951      Info      Successfully set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.951      Info      Current User SID was initialized successfully.
2012-12-14 14:23:00.951      Info      Successfully set owner for C:\Windows\Sysnative\tcpmon.ini
2012-12-14 14:23:00.951      Info      Successfully set owner for C:\Windows\Sysnative\tcpmon.ini
2012-12-14 14:23:00.982      Info      Successfully set DACL.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeRestorePrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.982      Info      Everyone SID was initialized successfully.
2012-12-14 14:23:00.982      Info      EXPLICIT_ACCESS initialized successfully.
2012-12-14 14:23:00.982      Info      Successfully set entries in ACL.
2012-12-14 14:23:00.982      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be enabled: SeRestorePrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be enabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.982      Info      Current User SID was initialized successfully.
2012-12-14 14:23:00.982      Info      Successfully set owner for C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
2012-12-14 14:23:00.982      Info      Successfully set owner for C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
2012-12-14 14:23:00.982      Info      Successfully set DACL.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeRestorePrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.982      Info      Everyone SID was initialized successfully.
2012-12-14 14:23:00.982      Info      EXPLICIT_ACCESS initialized successfully.
2012-12-14 14:23:00.982      Info      Successfully set entries in ACL.
2012-12-14 14:23:00.982      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be enabled: SeRestorePrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be enabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:00.982      Info      Current User SID was initialized successfully.
2012-12-14 14:23:00.982      Info      Successfully set owner for C:\Windows\SysWOW64\ntoskrnl.exe
2012-12-14 14:23:00.982      Info      Successfully set owner for C:\Windows\SysWOW64\ntoskrnl.exe
2012-12-14 14:23:00.982      Info      Successfully set DACL.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeRestorePrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_RESTORE_NAME privilege.
2012-12-14 14:23:00.982      Info      Successfully found the privilege.
2012-12-14 14:23:00.982      Info      Privilege is going to be disabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:00.982      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:00.982      Info      Successfully un-set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:01.154      Error     Failure code returned from icacls process in RestoreFromDataBlock function. Error code 0x6
2012-12-14 14:23:01.200      Error     Failure code returned from icacls process in RestoreFromDataBlock function. Error code 0x6
2012-12-14 14:23:01.200      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:01.200      Info      Successfully found the privilege.
2012-12-14 14:23:01.200      Info      Privilege is going to be enabled: SeRestorePrivilege
2012-12-14 14:23:01.200      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:01.200      Info      Successfully set SE_RESTORE_NAME privilege.
2012-12-14 14:23:01.200      Info      Successfully initialized CurrentProcessToken.
2012-12-14 14:23:01.200      Info      Successfully found the privilege.
2012-12-14 14:23:01.200      Info      Privilege is going to be enabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:01.200      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:01.200      Info      Successfully set SE_TAKE_OWNERSHIP_NAME privilege.
2012-12-14 14:23:01.200      Info      Current User SID was initialized successfully.
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
2012-12-14 14:23:01.200      Info      Successfully created TrustedInstaller SID.
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\WinSxS\amd64_microsoft-windows-p..rtmonitor-tcpmonini_31bf3856ad364e35_6.1.7600.16385_none_2e6dc451c0fa9db5\tcpmon.ini
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\Sysnative\tcpmon.ini
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\Sysnative\tcpmon.ini
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\WinSxS\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17944_none_6e176360127d73e2\ntoskrnl.exe
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\SysWOW64\ntoskrnl.exe
2012-12-14 14:23:01.200      Info      Successfully set owner for C:\Windows\SysWOW64\ntoskrnl.exe
2012-12-14 14:23:01.200      Info      Successfully found the privilege.
2012-12-14 14:23:01.200      Info      Privilege is going to be disabled: SeRestorePrivilege
2012-12-14 14:23:01.200      Info      Privilege application of privilege SeRestorePrivilege succeeded. 
2012-12-14 14:23:01.200      Info      Successfully un-set SE_RESTORE_NAME privilege.
2012-12-14 14:23:01.200      Info      Successfully found the privilege.
2012-12-14 14:23:01.200      Info      Privilege is going to be disabled: SeTakeOwnershipPrivilege
2012-12-14 14:23:01.200      Info      Privilege application of privilege SeTakeOwnershipPrivilege succeeded. 
2012-12-14 14:23:01.200      Info      Successfully un-set SE_TAKE_OWNERSHIP_NAME privilege.
 

My Computer My Computer

At a glance

Win 7 Home Premuim 64bit
OS
Win 7 Home Premuim 64bit
Hello darknightwing,

Thanks for the logs. SFCFix was unable to replace one of the files as it's in use, so we will have to replace this manually. I would like to see another CBS log before we go ahead with a manual fix, so could you run another sfc /scannow command then attach your CBS log as before please?

In order to perform a replacement, we will have to use another tool to do so over a reboot:

http://technet.microsoft.com/en-gb/sysinternals/bb897556.aspx

Please download and extract this to your Desktop. Copy movefile.exe to C:\Windows\system32\

We won't be doing anything with this file just yet, I just want it set up to speed things up for when we perform the fix.

Tom
 

My Computer My Computer

At a glance

Windows 8.1 Pro x64Intel i7 3770K @4.5GHzCorsair Vengeance 2x4GB DDR3 1600MHz Low Prof...Gigabyte Radeon HD 7850 (2GB GDDR5)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Back
Top