KB2732487 is unable to update - Error Code 800700B7

Page 4 of 14 FirstFirst ... 23456 ... LastLast

  1. Posts : 70
    Windows 7 Home Premium 64bit
    Thread Starter
       #31

    Here you go,


    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.
    C:\windows\system32>NET START CRYPTSVC
    The Cryptographic Services service is starting.
    The Cryptographic Services service was started successfully.

    C:\windows\system32> REG QUERY HKLM\SYSTEM\CurrentControlSet\services\CryptSvc /
    S
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc
    DisplayName REG_SZ @%SystemRoot%\system32\cryptsvc.dll,-1001
    ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k NetworkSe
    rvice
    Description REG_SZ @%SystemRoot%\system32\cryptsvc.dll,-1002
    ObjectName REG_SZ NT Authority\NetworkService
    ErrorControl REG_DWORD 0x1
    Start REG_DWORD 0x2
    Type REG_DWORD 0x20
    DependOnService REG_MULTI_SZ RpcSs
    ServiceSidType REG_DWORD 0x1
    RequiredPrivileges REG_MULTI_SZ SeChangeNotifyPrivilege\0SeCreateGloba
    lPrivilege\0SeImpersonatePrivilege
    FailureActions REG_BINARY 80510100000000000000000003000000140000000100
    000060EA000000000000000000000000000000000000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc\Parameters
    ServiceDll REG_EXPAND_SZ %SystemRoot%\system32\cryptsvc.dll
    ServiceMain REG_SZ CryptServiceMain
    ServiceDllUnloadOnStop REG_DWORD 0x1
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\CryptSvc\Security
    Security REG_BINARY 00000E0001

    C:\windows\system32> SFC /SCANFILE C:\Windows\System32\cryptsvc.dll
    Microsoft (R) Windows (R) Resource Checker Version 6.0
    Copyright (c) 2006 Microsoft Corporation. All rights reserved.
    Scans the integrity of all protected system files and replaces incorrect version
    s with
    correct Microsoft versions.
    SFC [/SCANNOW] [/VERIFYONLY] [/SCANFILE=<file>] [/VERIFYFILE=<file>]
    [/OFFWINDIR=<offline windows directory> /OFFBOOTDIR=<offline boot directory>
    ]
    /SCANNOW Scans integrity of all protected system files and repairs files
    with
    problems when possible.
    /VERIFYONLY Scans integrity of all protected system files. No repair operati
    on is
    performed.
    /SCANFILE Scans integrity of the referenced file, repairs file if problems
    are
    identified. Specify full path <file>
    /VERIFYFILE Verifies the integrity of the file with full path <file>. No re
    pair
    operation is performed.
    /OFFBOOTDIR For offline repair specify the location of the offline boot dire
    ctory
    /OFFWINDIR For offline repair specify the location of the offline windows d
    irectory
    e.g.
    sfc /SCANNOW
    sfc /VERIFYFILE=c:\windows\system32\kernel32.dll
    sfc /SCANFILE=d:\windows\system32\kernel32.dll /OFFBOOTDIR=d:\ /OFFWINDI
    R=d:\windows
    sfc /VERIFYONLY
    C:\windows\system32>
    C:\windows\system32>
      My Computer


  2. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #32

    OK - so the service does start, but seems to stop for some reason.
    The registry entry looks normal to me.

    Please run the following commands and post the results.
    Code:
    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost"
    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService"
    REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost"
    REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService"
     
    .
      My Computer


  3. Posts : 70
    Windows 7 Home Premium 64bit
    Thread Starter
       #33

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.
    C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
    \Svchost"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
    RPCSS REG_MULTI_SZ RpcEptMapper\0RpcSs
    defragsvc REG_MULTI_SZ defragsvc
    LocalSystemNetworkRestricted REG_MULTI_SZ UxSms\0WdiSystemHost\0Netman
    \0trkwks\0AudioEndpointBuilder\0WUDFSvc\0IPBusEnum\0hidserv\0dot3svc\0irmon\0sys
    main\0PcaSvc\0homegrouplistener\0WPDBusEnum\0wlansvc\0TabletInputService
    LocalService REG_MULTI_SZ nsi\0WdiServiceHost\0w32time\0EventSystem\0R
    emoteRegistry\0WinHttpAutoProxySvc\0sppuinotify\0THREADORDER\0netprofm\0lltdsvc\
    0fdphost\0SstpSvc\0WebClient
    netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserv
    er\0gpsvc\0IKEEXT\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Nt
    mssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedac
    cess\0SRService\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDet
    ection\0LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0seclogon\0AppInfo\0ms
    iscsi\0MMCSS\0winmgmt\0SessionEnv\0browser\0EapHost\0schedule\0hkmsvc\0wercplsup
    port\0ProfSvc\0Themes\0BDESVC
    WerSvcGroup REG_MULTI_SZ wersvc
    LocalServiceNoNetwork REG_MULTI_SZ DPS\0PLA\0BFE\0mpssvc\0WwanSvc
    termsvcs REG_MULTI_SZ TermService
    swprv REG_MULTI_SZ swprv
    LocalServiceNetworkRestricted REG_MULTI_SZ DHCP\0eventlog\0AudioSrv\0B
    thHFSrv\0LmHosts\0wscsvc\0homegroupprovider\0WPCSvc
    LocalServicePeerNet REG_MULTI_SZ PNRPSvc\0p2pimsvc\0p2psvc\0PnrpAutoRe
    g
    NetworkServiceAndNoImpersonation REG_MULTI_SZ KtmRm
    regsvc REG_MULTI_SZ RemoteRegistry
    LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSv
    r\0TBS\0fdrespub\0FontCache\0AppIDSvc\0QWAVE\0wcncsvc\0Mcx2Svc\0SensrSvc
    DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
    NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
    NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0lan
    manworkstation\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
    sdrsvc REG_MULTI_SZ sdrsvc
    WbioSvcGroup REG_MULTI_SZ WbioSrvc
    imgsvc REG_MULTI_SZ StiSvc
    wcssvc REG_MULTI_SZ WcsPlugInService
    AxInstSVGroup REG_MULTI_SZ AxInstSV
    secsvcs REG_MULTI_SZ WinDefend
    bthsvcs REG_MULTI_SZ bthserv
    GPSvcGroup REG_MULTI_SZ GPSvc
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\AxInstSV
    Group
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\defragsv
    c
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\GPSvcGro
    up
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
    vice
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
    viceAndNoImpersonation
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
    viceNetworkRestricted
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSer
    viceNoNetwork
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSys
    temNetworkRestricted
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
    ervice
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
    erviceRemoteDesktopHyperVAgent
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
    erviceRemoteDesktopPublishing
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\SDRSVC
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\swprv
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\wercplsu
    pport
    C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
    \Svchost\NetworkService"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkS
    ervice
    CoInitializeSecurityParam REG_DWORD 0x1
    DefaultRpcStackSize REG_DWORD 0x1c

    C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\Cu
    rrentVersion\Svchost"
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost
    netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserv
    er\0gpsvc\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Ntmssvc\0N
    WCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedaccess\0SR
    Service\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDetection\0
    LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0msiscsi\0schedule\0SessionEnv
    \0winmgmt
    LocalService REG_MULTI_SZ RemoteRegistry\0WinHttpAutoProxySvc\0sppuino
    tify\0netprofm\0WebClient
    LocalSystemNetworkRestricted REG_MULTI_SZ Netman\0AudioEndpointBuilder
    \0dot3svc\0WPDBusEnum\0wlansvc
    LocalServiceNoNetwork REG_MULTI_SZ PLA
    rpcss REG_MULTI_SZ RpcSs
    LocalServiceNetworkRestricted REG_MULTI_SZ AudioSrv\0BthHFSrv\0LmHosts
    \0wscsvc\0WPCSvc
    LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSv
    r\0TBS\0QWAVE\0wcncsvc
    DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
    NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0Nap
    Agent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
    imgsvc REG_MULTI_SZ StiSvc
    wcssvc REG_MULTI_SZ WcsPlugInService
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\LocalService
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\LocalServiceAndNoImpersonation
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\LocalServiceNetworkRestricted
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\LocalServiceNoNetwork
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\LocalSystemNetworkRestricted
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\netsvcs
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\NetworkService
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\NetworkServiceRemoteDesktopHyperVAgent
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\NetworkServiceRemoteDesktopPublishing
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\termsvcs
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\wcssvc
    C:\windows\system32>REG QUERY "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\Cu
    rrentVersion\Svchost\NetworkService"
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svch
    ost\NetworkService
    CoInitializeSecurityParam REG_DWORD 0x1
    DefaultRpcStackSize REG_DWORD 0x1c

    C:\windows\system32>
    C:\windows\system32>.
      My Computer


  4. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #34

    That looks normal

    Please run the following commands and post the results

    SC QUERYEX CRYPTSVC
    SC QUERYEX EVENTLOG

    reboot and run the commands again, then post an MGADiag report - it may show something...




    https://www.sevenforums.com/windows-updates-activation/234159-windows-genuine-activation-issue-posting-instructions.html



    Ignore errors produced when clicking on theCopy button - they simply mean that the tool could not create the backup filesfor some reason. The data is still copied to the clipboard for pasting to yourresponse.
      My Computer


  5. Posts : 70
    Windows 7 Home Premium 64bit
    Thread Starter
       #35

    The reports before and after seems to be the same. I have attached it in the notepads.




    Code:
    Diagnostic Report 
    (1.9.0027.0):
    -----------------------------------------
    Windows Validation 
    Data-->
    
     
    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows 
    Product Key: *****-*****-4F8HK-M4P73-W8DQG
    Windows Product Key Hash: 
    Xs1iQgVeo0C+sObJxS7eu+FuBPQ=
    Windows Product ID: 
    00359-OEM-8992687-00057
    Windows Product ID Type: 2
    Windows License Type: 
    OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: 
    {F20E3B27-F478-4816-8F07-14C7B2FFE745}(1)
    Is Admin: Yes
    TestCab: 
    0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: 
    Microsoft
    Product Name: Windows 7 Home Premium
    Architecture: 
    0x00000009
    Build lab: 7601.win7sp1_gdr.130104-1431
    TTS Error: 
    
    Validation Diagnostic: 
    Resolution Status: N/A
    
     
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, 
    hr = 0x80070002
    
     
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 
    0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe 
    Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 
    0x80070002
    
     
    OGA Notifications Data-->
    Cached Result: N/A, hr = 
    0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 
    0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    
     
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 
    0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 
    025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    
     
    Browser Data-->
    Proxy settings: http=proxy.singnet.com.sg:8080
    User 
    Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program 
    Files (x86)\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: 
    Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls 
    and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as 
    safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: 
    Allowed
    Active scripting: Allowed
    Script ActiveX controls marked as safe 
    for scripting: Allowed
    
     
    File Scan Data-->
    File Mismatch: 
    C:\windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
    File 
    Mismatch: C:\windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 
    0x80092003
    File Mismatch: C:\windows\system32\sppobjs.dll[6.1.7601.17514], Hr 
    = 0x80092003
    File Mismatch: C:\windows\system32\sppc.dll[6.1.7601.17514], Hr 
    = 0x800b0100
    File Mismatch: C:\windows\system32\sppcext.dll[6.1.7600.16385], 
    Hr = 0x800b0100
    File Mismatch: 
    C:\windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
    File 
    Mismatch: C:\windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File 
    Mismatch: C:\windows\system32\slcext.dll[6.1.7600.16385], Hr = 
    0x800b0100
    File Mismatch: 
    C:\windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
    File 
    Mismatch: C:\windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
    File 
    Mismatch: C:\windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 
    0x800b0100
    File Mismatch: C:\windows\system32\sppcommdlg.dll[6.1.7600.16385], 
    Hr = 0x800b0100
    File Mismatch: 
    C:\windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
    File 
    Mismatch: C:\windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 
    0x80092003
    File Mismatch: C:\windows\system32\drivers\spldr.sys[6.1.7127.0], 
    Hr = 0x80092003
    File Mismatch: 
    C:\windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File 
    Mismatch: C:\windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
    
     
    Other data-->
    Office Details: 
    <GenuineResults><MachineData><UGUID>{F20E3B27-F478-4816-8F07-14C7B2FFE745}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-W8DQG</PKey><PID>00359-OEM-8992687-00057</PID><PIDType>2</PIDType><SID>S-1-5-21-4064131365-3982532405-1399218412</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Qosmio 
    F60</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 
    2.70  </Version><SMBIOSVersion major="2" 
    minor="5"/><Date>20101207000000.000000+000</Date></BIOS><HWID>EC1B3107018400FE</HWID><UserLCID>4809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Malay 
    Peninsula Standard 
    Time(GMT+08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSHIB</OEMID><OEMTableID>A007A   
    </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  
    
    
     
    Spsys.log Content: 0x80070002
    
     
    Licensing Data-->
    Software licensing service version: 
    6.1.7601.17514
    
     
    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating 
    System - Windows(R) 7, OEM_SLP channel
    Activation ID: 
    d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 
    55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 
    00359-00178-926-800057-02-1033-7600.0000-2492010
    Installation ID: 
    013902150052123840938622931670999034916864230355573526
    Processor Certificate 
    URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine 
    Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use 
    License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product 
    Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial 
    Product Key: W8DQG
    License Status: Licensed
    Remaining Windows rearm count: 
    4
    Trusted time: 17/3/2013 10:35:34 PM
    
     
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: 
    N/A
    HealthStatus: 0x0000000000000010
    Event Time Stamp: N/A
    ActiveX: 
    Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 
    7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: 
    %systemroot%\system32\sppobjs.dll
    
     
    
    HWID Data-->
    HWID Hash Current: 
    MgAAAAEABAABAAEAAAABAAAAAgABAAEAln2EjUNoJBOYexClQJLMawDyDrXafFRgdlY=
    
     
    OEM Activation 1.0 Data-->
    N/A
    
     
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker 
    version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
    
      ACPI Table Name OEMID Value OEMTableID Value
      
    APIC   TOSHIB  A007A   
      
    FACP   TOSHIB  A007A   
      
    DBGP   TOSHIB  A007A   
      
    HPET   TOSHIB  A007A   
      
    BOOT   TOSHIB  A007A   
      
    MCFG   TOSHIB  A007A   
      
    SLIC   TOSHIB  A007A   
      
    SSDT   TOSHIB  SataAhci
      
    SSDT   TOSHIB  SataAhci
      
    ASF!   TOSHIB  A007A   
      
    SSDT   TOSHIB  SataAhci
      My Computer


  6. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #36

    Ah....

    This may simplybe caused by a bad set of Intel Rapid Storage Technology drivers -



    Installing theIntel Rapid Storage Drivers

    try downloadingand installing them from here - http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&ProdId=2101&DwnldID=21730



    (you want theiata_enu.exe download)



    Once complete,please reboot twice, then post another MGADiag report.

      My Computer


  7. Posts : 70
    Windows 7 Home Premium 64bit
    Thread Starter
       #37

    Here's the report:


    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Code: 0x8004FE21
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-4F8HK-M4P73-W8DQG
    Windows Product Key Hash: Xs1iQgVeo0C+sObJxS7eu+FuBPQ=
    Windows Product ID: 00359-OEM-8992687-00057
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {F20E3B27-F478-4816-8F07-14C7B2FFE745}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130104-1431
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A
    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002
    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002
    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
    Browser Data-->
    Proxy settings: http=proxy.singnet.com.sg:8080
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Allowed
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed
    File Scan Data-->
    File Mismatch: C:\windows\system32\wat\watadminsvc.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\windows\system32\wat\watux.exe[7.1.7600.16395], Hr = 0x80092003
    File Mismatch: C:\windows\system32\sppobjs.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\windows\system32\sppc.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\sppwinob.dll[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\windows\system32\slc.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\sppuinotify.dll[6.1.7600.16385], Hr = 0x80092003
    File Mismatch: C:\windows\system32\slui.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\windows\system32\sppcomapi.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\sppcommdlg.dll[6.1.7600.16385], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\sppsvc.exe[6.1.7601.17514], Hr = 0x80092003
    File Mismatch: C:\windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
    File Mismatch: C:\windows\system32\systemcpl.dll[6.1.7601.17514], Hr = 0x800b0100
    File Mismatch: C:\windows\system32\user32.dll[6.1.7601.17514], Hr = 0x800b0100
    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{F20E3B27-F478-4816-8F07-14C7B2FFE745}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-W8DQG</PKey><PID>00359-OEM-8992687-00057</PID><PIDType>2</PIDType><SID>S-1-5-21-4064131365-3982532405-1399218412</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Qosmio F60</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 2.70 </Version><SMBIOSVersion major="2" minor="5"/><Date>20101207000000.000000+000</Date></BIOS><HWID>EC1B3107018400FE</HWID><UserLCID>4809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Malay Peninsula Standard Time(GMT+08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSHIB</OEMID><OEMTableID>A007A </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>
    Spsys.log Content: 0x80070002
    Licensing Data-->
    Software licensing service version: 6.1.7601.17514
    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800057-02-1033-7600.0000-2492010
    Installation ID: 013902150052123840938622931670999034916864230355573526
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: W8DQG
    License Status: Licensed
    Remaining Windows rearm count: 4
    Trusted time: 18/3/2013 12:08:47 AM
    Windows Activation Technologies-->
    HrOffline: 0x8004FE21
    HrOnline: N/A
    HealthStatus: 0x0000000000000010
    Event Time Stamp: N/A
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\sppobjs.dll

    HWID Data-->
    HWID Hash Current: MgAAAAEABAABAAEAAAABAAAAAgABAAEAln2EjUNoJBOYexClQJLMawDyDrXafFRgdlY=
    OEM Activation 1.0 Data-->
    N/A
    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC TOSHIB A007A
    FACP TOSHIB A007A
    DBGP TOSHIB A007A
    HPET TOSHIB A007A
    BOOT TOSHIB A007A
    MCFG TOSHIB A007A
    SLIC TOSHIB A007A
    SSDT TOSHIB SataAhci
    SSDT TOSHIB SataAhci
    ASF! TOSHIB A007A
    SSDT TOSHIB SataAhci
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #38

    Serves me right for not fully reading the report
    buried near the bottom is the cause of your problems.

    Tampered File: %systemroot%\system32\sppobjs.dll


    What I don't understand is why that error isn't showing in the SFC results in your initial post.

    Please run another SFC /SCANNOW, and post the new CBS.log
    Please also run the following commands and post the results.

    DIR C:\Windows\sppobjs.dll /S
    DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    REG LOAD HKLM\COMPONENTS C:\Windows\System32\config\COMPONENTS
    REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    REG UNLOAD HKLM\COMPONENTS
      My Computer


  9. Posts : 70
    Windows 7 Home Premium 64bit
    Thread Starter
       #39

    CBS log is attached and the report is here: :)

    Microsoft Windows [Version 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. All rights reserved.
    C:\windows\system32>DIR C:\Windows\sppobjs.dll /S
    Volume in drive C is S3A5912D001
    Volume Serial Number is 5461-260C
    Directory of C:\Windows\System32
    20/11/2010 09:27 PM 1,082,880 sppobjs.dll
    1 File(s) 1,082,880 bytes
    Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
    1bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    14/07/2009 09:41 AM 1,082,880 sppobjs.dll
    1 File(s) 1,082,880 bytes
    Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
    1bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    20/11/2010 09:27 PM 1,082,880 sppobjs.dll
    1 File(s) 1,082,880 bytes
    Total Files Listed:
    3 File(s) 3,248,640 bytes
    0 Dir(s) 260,699,267,072 bytes free
    C:\windows\system32> DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plug
    in-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    Volume in drive C is S3A5912D001
    Volume Serial Number is 5461-260C
    Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
    1bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    14/07/2009 11:20 AM <DIR> .
    14/07/2009 11:20 AM <DIR> ..
    14/07/2009 09:55 AM 11,758 sppobjs-spp-plugin-manifest-signed.xrm-ms
    14/07/2009 09:41 AM 1,082,880 sppobjs.dll
    2 File(s) 1,094,638 bytes
    2 Dir(s) 260,699,267,072 bytes free
    C:\windows\system32> DIR C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plug
    in-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    Volume in drive C is S3A5912D001
    Volume Serial Number is 5461-260C
    Directory of C:\Windows\winsxs\amd64_microsoft-windows-s..y-spp-plugin-common_3
    1bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    09/08/2011 11:42 AM <DIR> .
    09/08/2011 11:42 AM <DIR> ..
    20/11/2010 09:43 PM 11,758 sppobjs-spp-plugin-manifest-signed.xrm-ms
    20/11/2010 09:27 PM 1,082,880 sppobjs.dll
    2 File(s) 1,094,638 bytes
    2 Dir(s) 260,699,267,072 bytes free
    C:\windows\system32> REG LOAD HKLM\COMPONENTS C:\Windows\System32\config\COMPONE
    NTS
    The operation completed successfully.
    C:\windows\system32> REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_micr
    osoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4
    e4a00e66f1
    HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..
    y-spp-plugin-common_31bf3856ad364e35_6.1.7600.16385_none_1f05c4e4a00e66f1
    identity REG_BINARY 4D6963726F736F66742D57696E646F77732D53656375726974
    792D5350502D506C7567696E2D436F6D6D6F6E2C2043756C747572653D6E65757472616C2C205665
    7273696F6E3D362E312E373630302E31363338352C205075626C69634B6579546F6B656E3D333162
    663338353661643336346533352C2050726F636573736F724172636869746563747572653D616D64
    36342C2076657273696F6E53636F70653D4E6F6E537853
    S256H REG_BINARY 1137570264EB23861382BBEC6332088399E57D4E4250BD12731DD
    58F4E6036B0
    f!sppobjs-spp-plugin-manife_cc9ad20225dac2f2 REG_BINARY 7300700070006F
    0062006A0073002D007300700070002D0070006C007500670069006E002D006D0061006E00690066
    006500730074002D007300690067006E00650064002E00780072006D002D006D007300
    f!sppobjs.dll REG_BINARY 7300700070006F0062006A0073002E0064006C006C00
    c!windowsfoundation_31bf3856ad364e35_6.1.7600.16385_5f2ecc1aaa4ac3b2 REG_
    BINARY

    C:\windows\system32> REG QUERY HKLM\COMPONENTS\DerivedData\Components\amd64_micr
    osoft-windows-s..y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8
    ac9cfcea8b
    HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-s..
    y-spp-plugin-common_31bf3856ad364e35_6.1.7601.17514_none_2136d8ac9cfcea8b
    identity REG_BINARY 4D6963726F736F66742D57696E646F77732D53656375726974
    792D5350502D506C7567696E2D436F6D6D6F6E2C2043756C747572653D6E65757472616C2C205665
    7273696F6E3D362E312E373630312E31373531342C205075626C69634B6579546F6B656E3D333162
    663338353661643336346533352C2050726F636573736F724172636869746563747572653D616D64
    36342C2076657273696F6E53636F70653D4E6F6E537853
    S256H REG_BINARY 91A4040F9874EF8DD585885002D2133708D179F424BA04059E08C
    490F0B20822
    c!windowsfoundation_31bf3856ad364e35_6.1.7601.17514_615fdfe2a739474c REG_
    BINARY
    f!sppobjs-spp-plugin-manife_cc9ad20225dac2f2 REG_BINARY 7300700070006F
    0062006A0073002D007300700070002D0070006C007500670069006E002D006D0061006E00690066
    006500730074002D007300690067006E00650064002E00780072006D002D006D007300
    f!sppobjs.dll REG_BINARY 7300700070006F0062006A0073002E0064006C006C00

    C:\windows\system32> REG UNLOAD HKLM\COMPONENTS
    ERROR: Access is denied.
    C:\windows\system32>
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #40

    Strange that you weren't allowed to unload the hive at the end, there - but I don't think it's a problem.
    Please try running that command again (Elevated CP again)...

    REG UNLOAD HKLM\COMPONENTS

    I can't see anything wrong there at all, and SFC still says that there's nothing wrong.

    Please run the following commands and post the results.

    REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules" /S
    ICACLS %systemroot%\system32\sppobjs.dll
      My Computer


 
Page 4 of 14 FirstFirst ... 23456 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 23:15.
Find Us