windows 7 non genuine issue

Page 4 of 9 FirstFirst ... 23456 ... LastLast

  1. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #31

    Hmmm - it seems that the System attribute isn't critical (I just checked a couple more systems and more have it active than don't)

    Please run the following commands - it may confirm that the problem is with the file...

    DIR C:\Windows\ServiceProfiles\NetworkService\ntuser.* /AH
      My Computer


  2. Posts : 46
    Windows 7 Home Basic 64bit
    Thread Starter
       #32

    Code:
    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.
    
    C:\Users\WINSTON>DIR C:\Windows\ServiceProfiles\NetworkService\ntuser.* /AH
     Volume in drive C has no label.
     Volume Serial Number is D47A-AFE8
    
     Directory of C:\Windows\ServiceProfiles\NetworkService
    
    13-Mar-13  05:38 AM           524,288 ntuser.dat
    21-Nov-10  12:07 AM             1,024 NTUSER.DAT.LOG
    13-Mar-13  05:38 AM           226,304 NTUSER.DAT.LOG1
    13-Jul-09  09:45 PM                 0 NTUSER.DAT.LOG2
    13-Jul-09  10:01 PM            65,536 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bc
    de3ec}.TM.blf
    13-Jul-09  10:01 PM           524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bc
    de3ec}.TMContainer00000000000000000001.regtrans-ms
    13-Jul-09  10:01 PM           524,288 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bc
    de3ec}.TMContainer00000000000000000002.regtrans-ms
    24-May-12  02:36 AM            65,536 NTUSER.DAT{6e5a0662-a4f2-11e1-9e13-806e6f6
    e6963}.TM.blf
    24-May-12  02:36 AM           524,288 NTUSER.DAT{6e5a0662-a4f2-11e1-9e13-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    24-May-12  02:36 AM           524,288 NTUSER.DAT{6e5a0662-a4f2-11e1-9e13-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    11-Apr-12  10:11 AM            65,536 NTUSER.DAT{706893db-83d5-11e1-a965-806e6f6
    e6963}.TM.blf
    11-Apr-12  10:11 AM           524,288 NTUSER.DAT{706893db-83d5-11e1-a965-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    11-Apr-12  10:11 AM           524,288 NTUSER.DAT{706893db-83d5-11e1-a965-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    31-Jan-12  06:32 PM            65,536 NTUSER.DAT{7218a0bf-4c51-11e1-85eb-806e6f6
    e6963}.TM.blf
    31-Jan-12  06:32 PM           524,288 NTUSER.DAT{7218a0bf-4c51-11e1-85eb-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    31-Jan-12  06:32 PM           524,288 NTUSER.DAT{7218a0bf-4c51-11e1-85eb-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    28-Feb-12  11:36 PM            65,536 NTUSER.DAT{96d131d0-6299-11e1-a198-806e6f6
    e6963}.TM.blf
    28-Feb-12  11:36 PM           524,288 NTUSER.DAT{96d131d0-6299-11e1-a198-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    28-Feb-12  11:36 PM           524,288 NTUSER.DAT{96d131d0-6299-11e1-a198-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    22-Sep-12  07:53 AM            65,536 ntuser.dat{a6d1dc23-04bf-11e2-8f1e-806e6f6
    e6963}.TM.blf
    22-Sep-12  07:53 AM           524,288 ntuser.dat{a6d1dc23-04bf-11e2-8f1e-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    22-Sep-12  07:53 AM           524,288 ntuser.dat{a6d1dc23-04bf-11e2-8f1e-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    22-Sep-12  05:48 AM            65,536 ntuser.dat{bd664f2f-04b3-11e2-88db-806e6f6
    e6963}.TM.blf
    22-Sep-12  05:48 AM           524,288 ntuser.dat{bd664f2f-04b3-11e2-88db-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    22-Sep-12  05:48 AM           524,288 ntuser.dat{bd664f2f-04b3-11e2-88db-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
    10-Mar-12  10:07 PM            65,536 NTUSER.DAT{e655b353-6b2a-11e1-9fd0-806e6f6
    e6963}.TM.blf
    10-Mar-12  10:07 PM           524,288 NTUSER.DAT{e655b353-6b2a-11e1-9fd0-806e6f6
    e6963}.TMContainer00000000000000000001.regtrans-ms
    10-Mar-12  10:07 PM           524,288 NTUSER.DAT{e655b353-6b2a-11e1-9fd0-806e6f6
    e6963}.TMContainer00000000000000000002.regtrans-ms
                  28 File(s)      9,664,512 bytes
                   0 Dir(s)  109,062,057,984 bytes free
    
    C:\Users\WINSTON>
      My Computer


  3. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #33

    That's a bust The file has been updated today, so we can assume that it's functioning properly.

    I wonder if it's permissions on the Registry Key itself?
    The problem is that there's no easy way to find out except to check the registry manually.

    Please open Regedit (CAREFULLY! - there is no Undo option available) and navigate to the
    HKEY_USERS\S-1-5-20 key and right-click on it - select Permissions
    Click on the Advanced button -
    What entities are listed and what permissions do they have?
    Click on the Owner tab - who is listed as Owner.
    Cancel out (do NOT click OK!) and close Regedit

    post the results.
      My Computer


  4. Posts : 46
    Windows 7 Home Basic 64bit
    Thread Starter
       #34

    Is my copy of windows genuine one...i didnt have any problem with it before but was it genuine before or it was not genuine one which was installed when i bought this laptop...
      My Computer


  5. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #35

    As far as I can tell it's perfectly genuine- just suffering from a software problem of some kind which the system is interpreting as being an attack on the licensing protection software.

    The COA sticker on the case should be for Windows 7 Home Basic (and probably adds either OA or OEMAct at the end)
      My Computer


  6. Posts : 46
    Windows 7 Home Basic 64bit
    Thread Starter
       #36

    yes windows 7 sticker says Windows 7 Home Basic OA MEA
    Permission Entries:
    type name permission inherited from apply to
    allow NETWORK SERVICE Full Control <not inherited> this key and subkeys
    allow SYSTEM Full Control <not inherited> this key and subkeys
    allow administrators
    (winston-pc\administartors) Full Control <not inherited> this key and subkeys
    allow RESTRICTED Read <not inherited> this key and subkeys

    current owner:
    Administrators (WINSTON-PC\Administrators)
      My Computer


  7. Posts : 46
    Windows 7 Home Basic 64bit
    Thread Starter
       #37

    Also there is some error in system properties option:
    There was an unexpected error in the property page

    The Volume Shadow Copy Service used by system restore is not working..for more info visit view log.(0x81000202)
    Please close property page and try again.
    also sometimes desktop had turned red for sometime then was back to normal during start up
    may be these two factors help the cause..
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #38

    That's possible - the ShadowCopy service is considered fairly important, and does impact on the SPPSVC.


    Pleaseopen Event Viewer

    In theleft pane, navigate to the Windows Logs

    right-clickon Applications and select 'Save all events as...' save as Apps.evtx

    repeatfor the System logs - save as Sys.evtx

    Compressboth files, and attach to your reply.
      My Computer


  9. Posts : 46
    Windows 7 Home Basic 64bit
    Thread Starter
       #39
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #40

    Some interesting errors in the Apps log!
    Also some very interesting errors in the System log.

    I'm really a bit at a loss as where to start!
    The list of broken services includes....
    The AMD External Events Utility service failed to start
    CNG Key Isolation service failed to start
    Extensible Authentication Protocol service depends on the CNG Key Isolation service
    WLAN AutoConfig service depends on the Extensible Authentication Protocol service
    Print Spooler service failed to start
    Connectify service depends on the WLAN AutoConfig service which failed to start
    Photon Plus. OUC service failed to start
    The Protected Storage service failed to start
    speedfan
    TfFsMon
    TFSysMon
    Application Layer Gateway Service service failed to start
    .... etc., etc.,

    All due to either the file or path not being found - despite the fact that the SFC results say that they are present and correct
    This smacks of 'enemy action' in the form of registry corruption induced by malware.
    Let's check a couple of the affected services and see what the registry has for them..

    Please run the following commands, and post the results.

    REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler
    SC QUERYEX SPOOLER
    DIR C:\Windows\system32\drivers\speedfan.sys
    REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ALG
    DIR C:\Windows\system32\alg.exe
      My Computer


 
Page 4 of 9 FirstFirst ... 23456 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:53.
Find Us