This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows key missing, constant freezing on google. [Closed]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

Firstly I just want to thank whoever is reading this, and the website's members for all the help you've given previously!

I have a Toshiba L500-1XJ, purchased in 2009. In 2011, I somehow got a virus or something that started by making my computer think that a genuine copy of Windows 7 was installed, and then wouldn't start up. I was literally JUST in my warranty, so I called Argos, where I bought it from, and they took the laptop back and it appeared that they'd fixed it. However after about a week, I started getting the same error messages telling me that my Windows might not be a geuine copy. My warranty had run out and they wouldn't fix it again for me, and the windows key on the bottom of the laptop has faded to obscurity.

I've tried to live with the problem since then, but it's really annoying and I can't install any service packs or anything and I really really need to get this sorted.

My other, more simple issue, is that I keep getting a script error when using google on Firefox. When I try IE, google freezes for five minutes at a time every time I go to google, and every time after I search etc. Sometimes it just hangs for 2 minutes, then at others I get script error: chrome://bbrs_002.tb/content/witapi.js:529

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:44:24, on 29/01/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
C:\Windows\System32\WinFLTray.exe
C:\Users\Lucy\Program Files\NewSoftware's\Folder Lock\FLComServCtrl.exe
C:\Users\Lucy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Lucy\Program Files\NewSoftware's\Folder Lock\FLComServ.exe
C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lucy\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O2 - BHO: script helper for ie - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (file missing)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110405175648.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Hotspot Shield - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [MessengerPlusForSkypeService] "C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVG PC Tuneup 2011] "C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe" -UseTray
O4 - HKCU\..\Run: [WinFLTray] C:\Windows\system32\WinFLTray.exe
O4 - HKCU\..\Run: [FLBackup] C:\Users\Lucy\Program Files\NewSoftware's\Folder Lock\FLComServCtrl.exe
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Lucy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Lucy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2011\spy.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2011\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2011\spy.htm
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Jigsaw%20Puzzle%20Platinum/Images/stg_drm.ocx
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Jigsaw%20Puzzle%20Platinum/Images/armhelper.ocx
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - http://content.systemrequirementslab.com.s…el_4.4.24.0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BD0973FD-FF61-43C3-AFDD-2BF001627150}: NameServer = 8.8.8.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{BD0973FD-FF61-43C3-AFDD-2BF001627150}: NameServer = 8.8.8.8
O17 - HKLM\System\CS2\Services\Tcpip\..\{BD0973FD-FF61-43C3-AFDD-2BF001627150}: NameServer = 8.8.8.8
O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll
O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\Program Files\McAfee\VirusScan\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: Messenger Plus! Service (MsgPlusService) - Yuna Software - C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

–
End of file - 16326 bytes

Any help would be AMAZING! Thank you!
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



It would appear that you have more than one anti-virus solution on your machine. I can see Microsoft Security Essentials, AVG and traces of some McAfee installed.
Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.
Before continuing on, please completely uninstall two of the programs. The easiest way to do this is by going to your control panel > Programs and Features and choosing to uninstall the unwanted programs. After doing each one please reboot the machine.

The choice of what to remove is up to you, but since you are having other issues with your Microsoft Genunie Advantage at the moment, I'd suggest removing AVG and and anything McAfee and keeping Microsoft Security Essentials. You can always remove it later if you want and replace it with one of the others again once we are done.



After removing two of those programs completely, before we can continue, since you have indicated a problem with Genuine Advantage, I need you to do the following for me:

We Need to Diagnose the Possible Problem with WGA
  • Please download MGADiag and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop.
  • Push [external image: Posted Image]
  • Push [external image: Posted Image]
  • Go to Start -> Run and type in "Notepad"
  • Go to Edit -> Paste in notepad.
  • x out all of the numbers and letters in the line beginning with "Windows Product Key:"
  • Copy and paste that log here.

This will let me see if it is a virus that is blocking your access to the downloads for your updates, or if it is indeed a real problem with the Windows key. Some viruses are "scareware" that make you think you have a problem when you don't. As long as Microsoft sees your key as valid we can continue.

If there is a real problem with the Windows key then we'll need to get that sorted before we can continue. Even if the key comes back as invalid, there may be remedies you still have with Microsoft even if you are out of warranty. We will need to see the results of the scan to know more.

I will do my best to assist you, but please understand that if your key is not valid assisting you prior to working this out could be construed in the eyes of the law to be aiding and abetting a crime. So we do need to be sure of what we are dealing with before we can move on.

Please post the results of the scan and then we can go from there.
Hi there, Thank you so much, you're already giving me hope… this diagnostic tool is brilliant. But anyway, here is the log… Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Code: 0x8004FE21 Cached Online Validation Code: N/A, hr = 0xc0000022 Windows Product Key: *****-*****-XXXXX-XXXXX-XXXXX Windows Product Key Hash: EkRG02noirn1etiserf2jJnVqlM= Windows Product ID: 00359-OEM-8992687-00017 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 6.1.7601.2.00010300.1.0.003 ID: {CBED65B4-CD83-44EA-9CB4-80C582F107DF}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Home Premium Architecture: 0x00000000 Build lab: 7601.win7sp1_gdr.110408-1631 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Enterprise 2007 - 100 Genuine Microsoft Office Home and Student 2007 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-b063_E2AD56EA-766-0_E2AD56EA-134-80004005_B4D0AA8B-920-80070057 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {CBED65B4-CD83-44EA-9CB4-80C582F107DF}1.9.0027.06.1.7601.2.00010300.1.0.003x32*****-*****-*****-*****-BWX7700359-OEM-8992687-000172S-1-5-21-3182853127-146928663-405207266TOSHIBASatellite L500TOSHIBAV1.9020091217000000.000000+0008B1F3E07018400F808090409GMT Standard Time(GMT+00:00)03TOSCPLTOSCPL00100 Spsys.log Content: 0x80070002 Licensing Data–> On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text. Error: 0x80070426 Windows Activation Technologies–> HrOffline: 0x8004FE21 HrOnline: N/A HealthStatus: 0x0001000000000000 Event Time Stamp: 1:31:2013 08:48 ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: Tampered Service: sppsvc HWID Data–> HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAeqhIRLBsdxbaejqFrlhawszh4iOAQqL3Rso= OEM Activation 1.0 Data–> N/A OEM Activation 2.0 Data–> BIOS valid for OA 2.0: yes Windows marker version: 0x20001 OEMID and OEMTableID Consistent: yes BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC PTLTD APIC FACP TOSCPL CRESTLNE HPET INTEL CRESTLNE BOOT PTLTD $SBFTBL$ MCFG INTEL CRESTLNE SLIC TOSCPL TOSCPL00 OSFR TOSHIB A+2nd ID SSDT BrtRef DD01BRT SSDT BrtRef DD01BRT
Interestingly, the diagnostic isn't showing a pass or fail, but is showing a blocked access for the Windows Key. I do want to check something if you don't mind working with me just a bit longer. I did find after searching a bit, that this error is a bit more common than you might think. It gives the appearance of a counterfeit OS, but could just be a bad registry setting. So lets look a little further before taking to referring you to Microsoft for a remedy.

Please run the following commands, and post the results.

REG QUERY HKLM\SYSTEM\CurrentControlSet\services\spldr /S
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR /S
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SLSVC
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SPPSVC


Here is how to run these commands:
1) To open an Elevated Command Prompt Window by clicking on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt if necessary
2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the command prompt Window, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once.
3) To copy the results… click on the Black/White icon in the top left, and select Edit… 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.
Thank you once again :) (Could I ask - is it ok to still have "PC Tuneup" by AVG? It's not part of the virus scanner, it was separate. Thanks!) The results are here: Microsoft Windows [Version 6.1.7601] Copyright © 2009 Microsoft Corporation. All rights reserved. C:\Users\Lucy>REG QUERY HKLM\SYSTEM\CurrentControlSet\services\spldr /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\spldr DisplayName REG_SZ Security Processor Loader Driver ErrorControl REG_DWORD 0x3 Start REG_DWORD 0x3 Type REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\spldr\Enum 0 REG_SZ Root\LEGACY_SPLDR\0000 Count REG_DWORD 0x1 NextInstance REG_DWORD 0x1 C:\Users\Lucy>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR /S HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR NextInstance REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000 Service REG_SZ spldr Legacy REG_DWORD 0x1 ConfigFlags REG_DWORD 0x400 Class REG_SZ LegacyDriver ClassGUID REG_SZ {8ECC055D-047F-11D1-A537-0000F8753ED1} DeviceDesc REG_SZ Security Processor Loader Driver Capabilities REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR\0000\Control C:\Users\Lucy>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SLSVC ERROR: The system was unable to find the specified registry key or value. C:\Users\Lucy>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SPPSVC ERROR: The system was unable to find the specified registry key or value. C:\Users\Lucy>
I'm not sure this will make a difference but let's give it a try. We're going to merge in a fresh registry entry for that field. I don't see an obvious problem that I was expecting to see, but you never know. Let's just get a fresh Windows 7 registry entry there and we can't go wrong.

Download the following file to your desktop:

http://download.bleepingcomputer.com/win-s…EGACY_SPLDR.reg


Double click the file and allow it to run. When prompted, let it merge.

After running the fix, please reboot the computer into normal mode and then run a new MGADiag for me from here. Go ahead and post the results and let's see what we get.

If this still doesn't show it passed, we can get you in touch with Microsoft. You do still have options with them to get a valid key even if your warranty with the computer manufacturer has expired. There have been many cases of OEM keys that have been corrupted and when you have paid for a valid license Microsoft will work with you. So please don't think all is lost either way. We just need to get you back to a validated status and then we can get your machine all sorted out. Let's see what we get after this and we'll go from there.

And PC Tuneup is fine at this point. You probably don't need it in the long run, but if you are having issues with the machine, now isn't the time to make changes. We should get it all sorted out and then remove any unwanted programs.
Please first create a new System Restore point. We are going to make a manual edit to the registry. You need to be extremely careful when doing this as improper editing can render your computer useless. If you are not comfortable in doing this please stop and let me know. I'd suggest you print out these instructions so you have them right there and can refer to them as you do the steps carefully.

Then click on start and in the search box type REGEDIT
Navigate to the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPLDR Key

Now go to the 0000 subkey and right-click on it.
Select Permissions,
Click on Advanced button, then the Owner tab
Make sure that Administrators is the owner, and put a tick in the 'Replace owner…' box at the bottom
Click OK once
add Administrators to the Groups or Usernames list, and give them Full permissions
CLICK OK

Then close out the box.

Reboot the machine.

Then please try the MGADiag again for me.
Thanks again :) I followed your instructions and the MGADiag and the results are pasted below. x Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Code: 0x8004FE21 Cached Online Validation Code: N/A, hr = 0xc0000022 Windows Product Key: *****-*****-XXXXX-XXXXX-XXXXX Windows Product Key Hash: EkRG02noirn1etiserf2jJnVqlM= Windows Product ID: 00359-OEM-8992687-00017 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 6.1.7601.2.00010300.1.0.003 ID: {CBED65B4-CD83-44EA-9CB4-80C582F107DF}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: Windows 7 Home Premium Architecture: 0x00000000 Build lab: 7601.win7sp1_gdr.110408-1631 TTS Error: Validation Diagnostic: Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 Windows XP Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Enterprise 2007 - 100 Genuine Microsoft Office Home and Student 2007 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_B4D0AA8B-920-80070057 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {CBED65B4-CD83-44EA-9CB4-80C582F107DF}1.9.0027.06.1.7601.2.00010300.1.0.003x32*****-*****-*****-*****-BWX7700359-OEM-8992687-000172S-1-5-21-3182853127-146928663-405207266TOSHIBASatellite L500TOSHIBAV1.9020091217000000.000000+0008B1F3E07018400F808090409GMT Standard Time(GMT+00:00)03TOSCPLTOSCPL00100 Spsys.log Content: 0x80070002 Licensing Data–> On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text. Error: 0x80070426 Windows Activation Technologies–> HrOffline: 0x8004FE21 HrOnline: N/A HealthStatus: 0x0001000000000000 Event Time Stamp: N/A ActiveX: Registered, Version: 7.1.7600.16395 Admin Service: Registered, Version: 7.1.7600.16395 HealthStatus Bitmask Output: Tampered Service: sppsvc HWID Data–> HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAeqhIRLBsdxbaejqFrlhawszh4iOAQqL3Rso= OEM Activation 1.0 Data–> N/A OEM Activation 2.0 Data–> BIOS valid for OA 2.0: yes Windows marker version: 0x20001 OEMID and OEMTableID Consistent: yes BIOS Information: ACPI Table Name OEMID Value OEMTableID Value APIC PTLTD APIC FACP TOSCPL CRESTLNE HPET INTEL CRESTLNE BOOT PTLTD $SBFTBL$ MCFG INTEL CRESTLNE SLIC TOSCPL TOSCPL00 OSFR TOSHIB A+2nd ID SSDT BrtRef DD01BRT SSDT BrtRef DD01BRT
We're still not getting a validation either way pass or fail. Try merging that registry fix one more time. If that doesn't work this time (after allowing the administrator as owner) we'll go ahead and get you over to Microsoft for some assistance.
I tried to merge the reg file again, but nothing unfortunately! Thanks so much for your help anyway! Is this Microsoft involvement going to be painful? lol :)
OK. You can find the full Windows Key in use on your machine by going to Start > Computer and right-clicking on it. Select Properties. Under Windows Activation you'll find the Windows product key and want to note it down.

Then you can go to these instructions and try and re-register the existing key online and if that fails, you can follow the instructions to try and obtain a new key via phone. If the automated system fails, you have the option to talk to a real person to explain the situation.

There is an option in the Windows activation section of the properties screen to change the product key. If Microsoft gives you a new one you just fill it in there and it will activate using the new key they give you. Once you have that activated, you can provide me with the new MGADiag log (sorry, but I will need that to show an activated copy) and then we can move forward with cleaning up the computer.

It shouldn't be a painful process. Something as simple as your computer manufacturer changed a hardware component on the machine could cause this. It shouldn't be too painful for you since you have had work done under warranty recently. If you really had an illegal copy of Windows you wouldn't be working this hard to get your computer cleaned up and working, you'd have found another copy and re-installed by now :) I think you'll be fixed up on the Windows key in no time.

I will keep this thread open until I hear back from you.
Thanks so much for all your information! Before I set off on my Microsoft adventure… I just thought I should mention, when I go to the properties of My Computer, there isn't a mention of my Windows product key. It just says that my windows key is not available. (Attachment below!) Does this make a difference to what Microsoft can do?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI