Windows Not Genuine thread Error 0x8004fe21

Page 2 of 2 FirstFirst 12

  1. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #11

    The CBS log is clear
    You appear to have used DISM, on 31/12 - can I ask what for?
    There are actually three SFC logs in the file - all are apparently clear.


    Please download and save the CheckSUR tool from http://support.microsoft.com/kb/947821
    (you'll need to look in the details for Method 2)

    Run it - The tool can take anywhere from 5 mins to a couple of hours to run (or 'Install') depending on how much it has to do, and may exit silently - it may appear to freeze for most of that time, but be patient.
    The result is logged in the C:\Windows\Logs\CBS\CheckSUR.log file - and an archive …\checksur.persist.log file

    Then zip the CheckSUR.log and attach it to your reply..
      My Computer


  2. Posts : 13
    Windows 7 Home Premium 64bit.
    Thread Starter
       #12

    here is the CheckSUR log and the CheckSUR.persist. i just put em in one zip i hope it is okay
      My Computer


  3. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #13

    You appear to have re-started the tool? - the first run was clear anyhow.

    Let's check some of the peripheral services that the SPPSVC uses....

    Open an Elevated Command Prompt, and run the following commands - post the results.

    NET START EVENTLOG
    NET START EVENTSYSTEM
    NET START VSS
    NET START WUAUSERV
    NET START BFE
    NET START BITS
      My Computer


  4. Posts : 13
    Windows 7 Home Premium 64bit.
    Thread Starter
       #14

    there is one that said it got activated else the others said they already are running here is the result of the commands:
    C:\Windows\system32>NET START EVENTLOG
    Den anmodede tjeneste er allerede blevet startet.

    Der er mere hjælp til rådighed, hvis du taster NET HELPMSG 2182.


    C:\Windows\system32>NET START EVENTSYSTEM
    Den anmodede tjeneste er allerede blevet startet.

    Der er mere hjælp til rådighed, hvis du taster NET HELPMSG 2182.


    C:\Windows\system32>NET START VSS
    Tjenesten Øjebliksbillede af diskenhed starter.
    Tjenesten Øjebliksbillede af diskenhed er startet.


    C:\Windows\system32>NET START WUAUSERV
    Den anmodede tjeneste er allerede blevet startet.

    Der er mere hjælp til rådighed, hvis du taster NET HELPMSG 2182.


    C:\Windows\system32>NET START BFE
    Den anmodede tjeneste er allerede blevet startet.

    Der er mere hjælp til rådighed, hvis du taster NET HELPMSG 2182.


    C:\Windows\system32>NET START BITS
    Den anmodede tjeneste er allerede blevet startet.

    Der er mere hjælp til rådighed, hvis du taster NET HELPMSG 2182.


    C:\Windows\system32>
      My Computer


  5. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #15

    Please open an Elevated Command Prompt, and run the following commands - post the results

    REG QUERY HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156} /S
    REG QUERY HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\Performance\Resolvers
    REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Software Protection Platform Service"
    REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\Key Management Service\KmsRequests"
    REG QUERY HKLM\SYSTEM\CurrentControlSet\Control\WMI
    REG QUERY HKLM\SYSTEM\CurrentControlSet\services\sppsvc /S


    That's most of the Registry's direct references to the SPPSVC and its executable :)
      My Computer


  6. Posts : 13
    Windows 7 Home Premium 64bit.
    Thread Starter
       #16

    here is the results:

    C:\Windows\system32>REG QUERY HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WIN
    EVT\Publishers\{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156} /S

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{
    e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}
    (Standard) REG_SZ Microsoft-Windows-Security-SPP
    ResourceFileName REG_EXPAND_SZ %windir%\system32\sppsvc.exe
    MessageFileName REG_EXPAND_SZ %windir%\system32\sppsvc.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{
    e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}\ChannelReferences
    Count REG_DWORD 0x1

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{
    e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}\ChannelReferences\0
    (Standard) REG_SZ Microsoft-Windows-Security-SPP/Perf
    Id REG_DWORD 0x10
    Flags REG_DWORD 0x0


    C:\Windows\system32>REG QUERY HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Dia
    gnostics\Performance\Resolvers

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\Perform
    ance\Resolvers
    SystemBinariesList REG_EXPAND_SZ win32k.sys:winlogon.exe:EXPLORER.EXE:
    CSRSS.Exe:dwm.exe:logon.scr:logonui.exe:lsass.exe:lsm.exe:ntkrpamp.exe:ntoskrnl.
    exe:RUNDLL32.EXE:services.exe:sppsvc.exe:smss.exe:spoolsv.exe:svchost.exe:tasken
    g.exe:WinInit.exe:WISPTIS.EXE:dllhost.exe:dllhst3g.exe:cscript.exe:mmc.exe:msiex
    ec.exe:upnpcont.exe:wscript.exe:WUDFHost.exe:dfsvc.exe:dfsvc.exe:fdbs.exe:ntfsbs
    .exe:memdiag.exe:NETFXSBS10.exe:applaunch.exe:aspnet_compiler.exe:aspnet_regbrow
    sers.exe:aspnet_regiis.exe:aspnet_regsql.exe:aspnet_state.exe:aspnet_wp.exe:casp
    ol.exe:csc.exe:CVTRES.EXE:dfsvc.exe:dw20.exe:IEExec.exe:ilasm.exe:InstallUtil.ex
    e:jsc.exe:MSBuild.exe:mscorsvw.exe:ngen.exe:RegAsm.exe::RegSvcs.exe:vbc.exe:Trus
    tedInstaller.exe:Aurora.scr:AutoChk.Exe:AUTOFMT.EXE:CHKDSK.EXE:CHKNTFS.EXE:conse
    nt.exe:PnPUnattend.exe:PnPutil.exe:RacAgent.exe:fsquirt.exe:Uninst.exe:updateWmc
    .exe:wmdc.exe:wmdsync.exe:mofcomp.exe:ScrCons.exe:smi2smir.exe:unsecapp.exe:wbem
    test.exe:winmgmt.exe:wmic.exe:bfsvc.exe:Twunk_16.exe:Twunk_32.exe:wuauclt.exe:ws
    qmcons.exe:sapisvr.exe:WinSAT.exe2phost.exe:SearchProtocolHost.exe:WerFault.ex
    e:drvinst.exe:ehshell.exe:UI0Detect.exe:ehtray.exe:HelpPane.exe:mrt.exe:SearchFi
    lterHost.exe:mobsync.exe:Narrator.exe:SLUI.exe:taskmgr.exe:PresentationSettings.
    exe:vds.exe:sdclt.exe:irftp.exeFDWiz.exe:SndVol.exe:makecab.exe:msfeedssync.ex
    e:unregmp2.exeeviceProperties.exe:rstrui.exe:MdRes.exe:netsh.exerintui.exe:m
    cupdate.exe:4mmdat.sys:61883.sys:ACPI.sys:amdk7.sys:amdk8.sys:ASYNCMAC.SYS:atapi
    .sys:AVC.SYS:cdfs.sys:cdrom.sys:circlass.sys:cmbatt.sys:crusoe.sys:CSC.Sys:dc21x
    4vm.sys:disk.sys:dot4.sys:dot4usb.sys:drmkaud.sys:ecache.sys:fdc.sys:floppy.sys:
    hdaudbus.sys:HDAudio.sys:HIDBTH.SYS:HIDIR.SYS:i8042prt.sys:intelppm.sys:irenum.S
    YS:IRSIR.SYS:kbdclass.sys:kbdhid.sys:LOOP.SYS:mf.sys:monitor.sys:mouclass.sys:mo
    uhid.sys:msisadrv.sys:msiscsi.sys:NDISWAN.SYS:nsiproxy.syshci1394.sysci.sys:
    pciide.sysowerfil.sysrocessr.sys:rasl2tp.sys:raspppoe.sys:RASPPTP.SYS:RDPCDD
    .SYS:rfcomm.sys:sbp2port.sys:sdbus.sys:serenum.sys:serial.sys:sermouse.sys:sffdi
    sk.sys:sffp_mmc.sys:smbios.sys:swenum.sys:tdx.sys:termdd.sys:tpm.sys:tunmp.sys:t
    unnel.sys:umbus.sys:update.sys:usb8023.sys:USBAudio.sys:USBCCGP.SYS:usbcir.sys:U
    SBEHCI.sys:usbhub.sys:USBOHCI.sys:usbprint.sys:USBUHCI.sys:viac7.sys:wacompen.sy
    s:wceusbsh.sys:winusb.sys:ws2ifsl.sys:xnacc.sys
    ExpirationDays REG_DWORD 0x5a


    C:\Windows\system32>REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\A
    pplication\Software Protection Platform Service"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Softwa
    re Protection Platform Service
    EventMessageFile REG_EXPAND_SZ %windir%\system32\sppsvc.exe
    TypesSupported REG_DWORD 0x7
    ProviderGuid REG_SZ {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}


    C:\Windows\system32>REG QUERY "HKLM\SYSTEM\CurrentControlSet\services\eventlog\K
    ey Management Service\KmsRequests"

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Key Management Ser
    vice\KmsRequests
    EventMessageFile REG_EXPAND_SZ %windir%\system32\sppsvc.exe
    TypesSupported REG_DWORD 0x7
    ProviderGuid REG_SZ {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}


    C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Control\WMI

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security

    C:\Windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\sppsvc /S

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppsvc
    DisplayName REG_SZ @%SystemRoot%\system32\sppsvc.exe,-101
    ImagePath REG_EXPAND_SZ %SystemRoot%\system32\sppsvc.exe
    Description REG_SZ @%SystemRoot%\system32\sppsvc.exe,-100
    ObjectName REG_SZ NT AUTHORITY\NetworkService
    ErrorControl REG_DWORD 0x1
    Start REG_DWORD 0x2
    DelayedAutoStart REG_DWORD 0x1
    Type REG_DWORD 0x10
    DependOnService REG_MULTI_SZ RpcSs
    ServiceSidType REG_DWORD 0x1
    RequiredPrivileges REG_MULTI_SZ SeAuditPrivilege\0SeChangeNotifyPrivil
    ege\0SeCreateGlobalPrivilege\0SeImpersonatePrivilege
    FailureActions REG_BINARY 80510100000000000000000003000000140000000100
    0000C0D4010001000000E09304000000000000000000

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sppsvc\Security
    Security REG_BINARY 01001480A0000000AC000000140000003000000002001C0001
    00000002801400FF010F00010100000000000100000000020070000500000000001400FD01020001
    010000000000051200000000001800FF010F0001020000000000052000000020020000000014009D
    010200010100000000000504000000000014009D0102000101000000000005060000000000140014
    00000001010000000000050B000000010100000000000512000000010100000000000512000000


    C:\Windows\system32>
      My Computer


  7. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #17

    Those all look perfectly normal to me.
    I suspect that it may be a permissions thing in the registry - and it's beyond my current skills/knowledge to fix that.
    I suspect that the only cure is going to be either a repair install or a clean install.
      My Computer


  8. Posts : 13
    Windows 7 Home Premium 64bit.
    Thread Starter
       #18

    ok ty for trying to help hope i havent wasted your time :) well kan you keep an eye on here for a day or two so i can tell you if the problem is solved i will let you know :) but in general your are the best i have tried so many forums where they didnt even care about me there could go like a week before they answered a question but you answer almost emidietly and i just wanted to let you know
      My Computer


  9. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #19

    I see all new posts to the forum, so if you come back, I'll know :)
    Good luck!
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 23:18.
Find Us