Win7 suddenly reporting not genuine

starzen

New member
Local time
6:45 PM
Messages
17
My lenovo laptop (W510 running 7 Ultimate 4) suddenly started reporting that windows is not genuine.

MGADiag still shows it as genuine but reports several system files with file mismatch

File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]

i already tried to reactivate which worked fine but the not genuine thing keeps coming back. Also ran Vipre, Spybot and Malwarebytes

Any help would be appreciated in getting this machine happy again. And yes it is a genuine windows that came with the laptop bought directly from lenovo. Had it for a while and it was working fine until recently. Cant think of anything special that would have happened recently. No special installs or anything

thanks

Mike
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
same thing happen to me after 3 years activated .
this is microsoft for you .
a lot of peoples are getting to same thing .why .god know .
right now i have installed xp with a real copy and i am activated but then again it say that am not .but i am .
now i have installed pclinux on one of my drive and i never did this b.........and after a few week i like it better then w7
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build by me
OS
window 7 home premium 64 bits
CPU
amd a6 5400k
Motherboard
gigabyte fm2+ f2a88x-up4
Memory
gskill 4 gbs 1333 7-7-7-21
Graphics Card(s)
none
Sound Card
none
Monitor(s) Displays
32 inc sony bravia ex340 hdtv
Screen Resolution
1360x768
Hard Drives
ssd corsair gtx 128 gbs
PSU
rosewill 600w performance serie
Case
aerocool strike x very nice case and very big
Cooling
5 120mm red fans plus a 220 mm red fan
Keyboard
logitech mk 320
Mouse
logitech 320
Internet Speed
????????
Antivirus
malwarebytes- security essensial- spywareblaster
Browser
firefox 28
Other Info
new build about 4 months ago restart time is 19 secs
Upload the entire log

Click on the # sign on the top of the message box . You will see [CODE][/CODE] paste the text log in between the [CODE][/CODE] tags
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
sorry about that

here is the full report

Code:
Diagnostic Report (1.9.0019.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-7JVM3-2M9JT-4GQC9
Windows Product Key Hash: ULy+hte2xK1tgks+bRbEWOf1hsQ=
Windows Product ID: 00426-OEM-9402033-26291
Windows Product ID Type: 8
Windows License Type: COA SLP
Windows OS version: 6.1.7601.2.00010100.1.0.001
ID: {E9EACD4D-1E30-4FC3-93F4-404BEC54062F}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.130318-1533
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E9EACD4D-1E30-4FC3-93F4-404BEC54062F}</UGUID><Version>1.9.0019.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4GQC9</PKey><PID>00426-OEM-9402033-26291</PID><PIDType>8</PIDType><SID>S-1-5-21-2274270284-221895154-2144399453</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4318CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>6NET49WW (1.12 )</Version><SMBIOSVersion major="2" minor="6"/><Date>20100222000000.000000+000</Date></BIOS><HWID>611F3907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-6N   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Ultimate edition
Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Activation ID: 022a1afb-b893-4190-92c3-8f69a49839fb
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00188-020-326291-02-1033-7601.0000-1852013
Installation ID: 010531209143469672205113585786496690779254852925820272
Processor Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88338[/URL]
Machine Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88339[/URL]
Use License URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88341[/URL]
Product Key Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88340[/URL]
Partial Product Key: 4GQC9
License Status: Licensed
Remaining Windows rearm count: 2
Trusted time: 7/5/2013 6:17:06 PM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: 0x00000000
HealthStatus: 0x000000000001EFF0
Event Time Stamp: 7:3:2013 14:00
WAT Activex: Registered
WAT Admin Service: Registered
HWID Data-->
HWID Hash Current: OAAAAAEAAgABAAEAAAACAAAABgABAAEAHKLkZEe2Ht50rkIwkGJIMql5uH72LnY8uPVyir5BdlY=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC   LENOVO  TP-6N   
  FACP   LENOVO  TP-6N   
  HPET   LENOVO  TP-6N   
  BOOT   LENOVO  TP-6N   
  MCFG   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  ECDT   LENOVO  TP-6N   
  ASF!   LENOVO  TP-6N   
  SLIC   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  TCPA   PTL   CRESTLN
  DMAR   INTEL   CP_FIELD
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Open up an Elevated Command Prompt. Click on :orb: in
2nqbqes.png
type CMD . Right click on CMD under Programs (1) choose
mawket.jpg
. On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

Type the highlighted text inside Command Prompt

SFC /scannow and press <ENTER>
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Code:
Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some of th
em.
Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
C:\Windows\Logs\CBS\CBS.log
C:\Windows\system32>

the log is quite big so i am not posting it right away
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Location of the log : C:\Windows\Logs\CBS\CBS.log
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Open up an Elevated Command Prompt. Click on :orb: in
2nqbqes.png
type CMD . Right click on CMD under Programs (1) choose
mawket.jpg
. On the User Access Control window click on the Yes button . Command Prompt opens up to C:\Windows\System32>_

Type the command below

chkdsk /F /R
press [ENTER]

When you type chkdsk /F /R you will get this message

Code:
The type of the file system is NTFS.
Cannot lock current drive.

Chkdsk cannot run because the volume is in use by another
process.  Would you like to schedule this volume to be
checked the next time the system restarts? (Y/N)


When you type " Y " and press [Enter] you get this message below

Code:
This volume will be checked the next time the system restarts.

C:\Windows\system32>

Close the command prompt window by typing exit and press [enter] Restart the PC manually .

When you're back inside Windows. Open up Powershell by clicking on :orb: type Powershell inside
2nqbqes.png
and press [ENTER] . Inside the Powershell paste the command below

Code:
get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, message | out-file Desktop\CHKDSKResults.txt

and Press [Enter] upload the CHKDSKResults.txt file

   Note
To paste inside the Powershell window press on the right click button on the mouse
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
ok, ran chkdsk. didnt take long

Code:
TimeCreated : 6/7/2013 1:26:19 PM
Message     : 
              
              Checking file system on C:
              The type of the file system is NTFS.
              Volume label is Windows7_OS.
              
              
              One of your disks needs to be checked for consistency. You
              may cancel the disk check, but it is strongly recommended
              that you continue.
              Windows will now check the disk.                         
              
              CHKDSK is verifying files (stage 1 of 3)...
              Cleaning up instance tags for file 0xe8da.
              Cleaning up instance tags for file 0x12006.
              Cleaning up instance tags for file 0x3c202.
              Attribute record of type 0x80 and instance tag 0x4 is cross linked
              starting at 0x114a4b for possibly 0x1 clusters.
              Some clusters occupied by attribute of type 0x80 and instance tag 0x4
              in file 0xe9baa is already in use.
              Deleting corrupt attribute record (128, "")
              from file record segment 957354.
                1610240 file records processed.                                         
              File verification completed.
                1759 large file records processed.                                   
                0 bad file records processed.                                     
                4 EA records processed.                                           
                77 reparse records processed.                                      
              CHKDSK is verifying indexes (stage 2 of 3)...
              The file reference 0x90000000e396c of index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e4820636
              88f8df5b9_1e0daff3 of index $I30
              with parent 0xe568 is not the same as 0xa0000000e396c.
              Deleting index entry AppCrash_CIMSHR5util.exe_a9af562c66d2f0ff4a7285e482063688f8df5b9_1e0daff3 in index $
              I30 of file 58728.
                1980706 index entries processed.                                        
              Index verification completed.
              CHKDSK is scanning unindexed files for reconnect to their original directory.
              Recovering orphaned file AP3F6A~1.EXE (64889) into directory file 58728.
              Recovering orphaned file AppHang_sbamui.exe_80a338b884835c701c90fb26d77fb335babeb0_1a814aa6 (64889) into 
              directory file 58728.
              Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_226b9b7a (98931) 
              into directory file 58728.
                3 unindexed files scanned.                                        
              Recovering orphaned file AppCrash_explorer.exe_b01b936a1e34be38a4ed4393dae4b65a6e9161e7_6bab9b5b (243833)
               into directory file 58728.
                0 unindexed files recovered.                                      
              CHKDSK is verifying security descriptors (stage 3 of 3)...
                1610240 file SDs/SIDs processed.                                        
              CHKDSK is compacting the security descriptor stream
              Cleaning up 2671 unused security descriptors.
              Inserting data attribute into file 957354.
                185235 data files processed.                                           
              CHKDSK is verifying Usn Journal...
                36659048 USN bytes processed.                                            
              Usn Journal verification completed.
              CHKDSK discovered free space marked as allocated in the
              master file table (MFT) bitmap.
              Correcting errors in the Volume Bitmap.
              Windows has made corrections to the file system.
              
               916779004 KB total disk space.
               426360688 KB in 1373527 files.
                  684036 KB in 185237 indexes.
                       0 KB in bad sectors.
                 1743420 KB in use by the system.
                   65536 KB occupied by the log file.
               487990860 KB available on disk.
              
                    4096 bytes in each allocation unit.
               229194751 total allocation units on disk.
               121997715 allocation units available on disk.
              
              Internal Info:
              00 92 18 00 f1 c8 17 00 e5 1b 28 00 00 00 00 00  ..........(.....
              0a 2f 00 00 4d 00 00 00 00 00 00 00 00 00 00 00  ./..M...........
              00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
              
              Windows has finished checking your disk.
              Please wait while your computer restarts.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Upload a new MGADiag report .
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Code:
Diagnostic Report (1.9.0019.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-7JVM3-2M9JT-4GQC9
Windows Product Key Hash: ULy+hte2xK1tgks+bRbEWOf1hsQ=
Windows Product ID: 00426-OEM-9402033-26291
Windows Product ID Type: 8
Windows License Type: COA SLP
Windows OS version: 6.1.7601.2.00010100.1.0.001
ID: {E9EACD4D-1E30-4FC3-93F4-404BEC54062F}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.130318-1533
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E9EACD4D-1E30-4FC3-93F4-404BEC54062F}</UGUID><Version>1.9.0019.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4GQC9</PKey><PID>00426-OEM-9402033-26291</PID><PIDType>8</PIDType><SID>S-1-5-21-2274270284-221895154-2144399453</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4318CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>6NET49WW (1.12 )</Version><SMBIOSVersion major="2" minor="6"/><Date>20100222000000.000000+000</Date></BIOS><HWID>611F3907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-6N   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Ultimate edition
Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Activation ID: 022a1afb-b893-4190-92c3-8f69a49839fb
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00188-020-326291-02-1033-7601.0000-1852013
Installation ID: 010531209143469672205113585786496690779254852925820272
Processor Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88338[/URL]
Machine Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88339[/URL]
Use License URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88341[/URL]
Product Key Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88340[/URL]
Partial Product Key: 4GQC9
License Status: Licensed
Remaining Windows rearm count: 2
Trusted time: 7/6/2013 10:52:30 AM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: 0x00000000
HealthStatus: 0x000000000001EFF0
Event Time Stamp: 7:3:2013 14:00
WAT Activex: Registered
WAT Admin Service: Registered
HWID Data-->
HWID Hash Current: OAAAAAEAAgABAAEAAAACAAAABgABAAEAHKLkZEe2Ht50rkIwkGJIMql5uH72LnY8uPVyir5BdlY=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC   LENOVO  TP-6N   
  FACP   LENOVO  TP-6N   
  HPET   LENOVO  TP-6N   
  BOOT   LENOVO  TP-6N   
  MCFG   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  ECDT   LENOVO  TP-6N   
  ASF!   LENOVO  TP-6N   
  SLIC   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  TCPA   PTL   CRESTLN
  DMAR   INTEL   CP_FIELD
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
starzen

I have asked NoelDP to take a look at your report . He is out of the country so he will have a look at it as soon as he reads my message .
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
thanks for all the help so far

Mike
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Interesting that SF said that it found errors but couldn't repair them - there are no signs of it in the log.

Your File Mismatches are consistent with at least one dll file being unregistered - have you been using any form of Registry Cleaner?

Please run another SFC /SCANNOW and post the new CBS.log file.

Please also run a scan with the CheckSUR tool - it may give us some clues.

Please download and save the CheckSUR tool from http://support.microsoft.com/kb/947821
(you'll need to look in the details for Windows 7, downloading from the Microsoft Download Center)

Run it - The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.
The result is logged in the C:\Windows\Logs\CBS\CheckSUR.log file - and an archive …\checksur.persist.log file

Then zip the CheckSUR.log and upload it to your SkyDrive Public folder (or other fileshare site) so I can take a look - post a link in your reply.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Code:
Beginning system scan.  This process will take some time.
Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection found corrupt files but was unable to fix some of th
em.
Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example
C:\Windows\Logs\CBS\CBS.log
C:\Windows\system32>

Log file

will work on the checksur next

thanks
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
tried to install checksur but am getting the following error

checksurinst.png
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Again, the SFC results are clear, and no background in the rest of the CBS log to indicate a problem.

I suspect I know what the problem is - from the error you got when attempting CheckSUR, it looks like our friend the IRST drivers.

to check this...

Please follow this tutorial and post an MGADiag report - then we can (hopefully) see what the problem is.

http://www.sevenforums.com/windows-updates-activation/234159-windows-genuine-activation-issue-posting-instructions.html

Ignore errors produced when clicking on the Copy button - they simply mean that the tool could not create the backup files for some reason. The data is still copied to the clipboard for pasting to your response.


 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Woops! - I forgot you'd already post that - never mind.

This is almost certainly NOT the IRST drivers - but it could be a corrupted CATROOT2 folder....

Please run the following commands in an Elevated Command Prompt

NET STOP CRYPTSVC
REN C:\WINDOWS\SYSTEM32\CATROOT2 CATROOT2OLD
NET START CRYPTSVC


once complete, leave the system alone for at least an hour to rebuild the database, then reboot, and run another MGADiag report.
Note that this may delete your Update History - but all updates will remain installed, and can be viewed in the Installed Updates listing.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
ok did the catroot rebuild and here is the report. looks like it hasnt changed

Code:
Diagnostic Report (1.9.0019.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-7JVM3-2M9JT-4GQC9
Windows Product Key Hash: ULy+hte2xK1tgks+bRbEWOf1hsQ=
Windows Product ID: 00426-OEM-9402033-26291
Windows Product ID Type: 8
Windows License Type: COA SLP
Windows OS version: 6.1.7601.2.00010100.1.0.001
ID: {E9EACD4D-1E30-4FC3-93F4-404BEC54062F}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.130318-1533
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_B4D0AA8B-604-645_B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\wat\watux.exe[7.1.7600.16395]
File Mismatch: C:\Windows\system32\sppobjs.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppc.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppwinob.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\slc.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppuinotify.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcomapi.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\sppcommdlg.dll[6.1.7600.16385]
File Mismatch: C:\Windows\system32\sppsvc.exe[6.1.7601.17514]
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7601.17514]
File Mismatch: C:\Windows\system32\en-us\user32.dll.mui[6.1.7601.17514]
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E9EACD4D-1E30-4FC3-93F4-404BEC54062F}</UGUID><Version>1.9.0019.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-4GQC9</PKey><PID>00426-OEM-9402033-26291</PID><PIDType>8</PIDType><SID>S-1-5-21-2274270284-221895154-2144399453</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4318CTO</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>6NET49WW (1.12 )</Version><SMBIOSVersion major="2" minor="6"/><Date>20100222000000.000000+000</Date></BIOS><HWID>611F3907018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TP-6N   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Ultimate edition
Description: Windows Operating System - Windows(R) 7, OEM_COA_SLP channel
Activation ID: 022a1afb-b893-4190-92c3-8f69a49839fb
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00188-020-326291-02-1033-7601.0000-1852013
Installation ID: 010531209143469672205113585786496690779254852925820272
Processor Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88338[/URL]
Machine Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88339[/URL]
Use License URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88341[/URL]
Product Key Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88340[/URL]
Partial Product Key: 4GQC9
License Status: Licensed
Remaining Windows rearm count: 2
Trusted time: 7/7/2013 9:01:43 AM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: 0x00000000
HealthStatus: 0x000000000001EFF0
Event Time Stamp: 7:3:2013 14:00
WAT Activex: Registered
WAT Admin Service: Registered
HWID Data-->
HWID Hash Current: OAAAAAEAAgABAAEAAAACAAAABgABAAEAHKLkZEe2Ht50rkIwkGJIMql5uH72LnY8uPVyir5BdlY=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC   LENOVO  TP-6N   
  FACP   LENOVO  TP-6N   
  HPET   LENOVO  TP-6N   
  BOOT   LENOVO  TP-6N   
  MCFG   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  ECDT   LENOVO  TP-6N   
  ASF!   LENOVO  TP-6N   
  SLIC   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  TCPA   PTL   CRESTLN
  DMAR   INTEL   CP_FIELD
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N   
  SSDT   LENOVO  TP-6N
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo W510
OS
Windows 7 Ultimate x64
CPU
I7
Antivirus
Vipre
Back
Top