none
OEM Windows Vista Build 6002 Not Genuine Message RRS feed

  • Question

  • Tried slui 4 : it does not give a "By Phone" option. When I click "Go online and resolve now" Explorer opens a new window and it loads www.microsoft.com/genuine/validate/?OSV=6.0.6002.2.00010300.2.0.003.00.1033&LS=3&LegitCheckError=C004C4A8

    Before it runs through the validation process the browser is immediately redirected to search.microsoft.com/?mkt=en-us with no resolution.

    Thanks for the assistance.

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-G694Q-C3DD4-MCJWJ
    Windows Product Key Hash: GeUZb6s47Ofvh2lv6MQU4Ioj/oc=
    Windows Product ID: 89578-OEM-7352202-41119
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.0.6002.2.00010300.2.0.003
    ID: {4F017B6B-0F90-478B-A3AD-86BC5BED1745}(3)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6002.vistasp2_gdr.100608-0458
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    WGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office XP Standard for Students and Teachers - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F017B6B-0F90-478B-A3AD-86BC5BED1745}</UGUID><Version>1.9.0019.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-MCJWJ</PKey><PID>89578-OEM-7352202-41119</PID><PIDType>3</PIDType><SID>S-1-5-21-3646491923-1764803297-3543362824</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>MCP67</Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.32    </Version><SMBIOSVersion major="2" minor="4"/><Date>20090303000000.000000+000</Date></BIOS><HWID>7C303507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{913D0409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Standard for Students and Teachers</Name><Ver>10</Ver><Val>979FB3055A5E050</Val><Hash>vRcosDjncwIiT1NKIagbeAbncIY=</Hash><Pid>55866-718-4671127-17938</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.0.6002.18005
    Name: Windows(TM) Vista, HomePremium edition
    Description: Windows Operating System - Vista, OEM_COA_NSLP channel
    Activation ID: f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 89578-00146-522-041119-02-1033-6002.0000-0182011
    Installation ID: 017035179725533102183251860626547225040483849351596402
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
    Partial Product Key: MCJWJ
    License Status: Notification
    Notification Reason: 0xC004F200 (non-genuine).

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: PAAAAAEABwABAAEAAQABAAAAAwABAAEAeqjMBL5ddhu84yC+gASIzAaYmGBW4UQs8vSm1bD2AIusVniq

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: no, invalid SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PTLTD              APIC  
      FACP            NVIDIA        MCP67-M
      SRAT            AMD           HAMMER  
      HPET            PTLTD         HPETTBL
      BOOT            PTLTD         $SBFTBL$
      MCFG            PTLTD           MCFG  
      TCPA            Phoeni        x      
      SSDT            PTLTD         POWERNOW
      SLIC            HPQOEM        SLIC-MPC


    Friday, January 21, 2011 12:06 AM

Answers

  • None of the possible solutions worked.

    Result: Complete reinstall. Not the end of the world.

    Thank you for all the assistance.


    ~Chris
    • Marked as answer by Darin Smith MS Wednesday, January 26, 2011 9:43 PM
    Tuesday, January 25, 2011 11:12 PM

All replies

  • Hello nomadatoll,

     

    It's possibel that Vista's Licensing Store may be corrupt of it's data may be messed up in some way. Please try the below steps to reset the Licensing Store and it's data.

    1) Open an Internet Browser window.
    2) Type: %windir%\system32 into the browser address bar.
    3) Find the file CMD.exe
    4) Right-Click on CMD.exe and select 'Run as Administrator'
    5) Type: net stop slsvc   (it may ask you if you are sure, select yes)
    6) Type: cd %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing
    7) Type: rename tokens.dat tokens.bar
    8) Type: cd %windir%\system32
    9) Type: net start slsvc
    10) Type: cscript slmgr.vbs -rilc (It may take a long time for this to complete, please be patient)
    11) Restart your computer twice.
    12) You may be required to enter the Product Key and/or Activate.

    Thank you,


    Darin MS
    • Proposed as answer by Darin Smith MS Friday, January 21, 2011 12:18 AM
    Friday, January 21, 2011 12:17 AM
  • Nope, that did not work. It definitely reset and reinstalled the licensing as intended, but on the second restart, I type in the code from the bottom of the computer and I keep getting the same response. It say that it's not genuine. So, I click the "Go online and resolve now", which is the only option, and it opens an Explorer window. I can read the the page just before it gets redirected and it says that I need to install the ActiveX Control, but before I can do anything I'm at a Bing search page. I re-ran the diagnostics.

     

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-G694Q-C3DD4-MCJWJ
    Windows Product Key Hash: GeUZb6s47Ofvh2lv6MQU4Ioj/oc=
    Windows Product ID: 89578-OEM-7352202-41119
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.0.6002.2.00010300.2.0.003
    ID: {4F017B6B-0F90-478B-A3AD-86BC5BED1745}(3)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6002.vistasp2_gdr.100608-0458
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    WGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office XP Standard for Students and Teachers - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F017B6B-0F90-478B-A3AD-86BC5BED1745}</UGUID><Version>1.9.0019.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-MCJWJ</PKey><PID>89578-OEM-7352202-41119</PID><PIDType>3</PIDType><SID>S-1-5-21-3646491923-1764803297-3543362824</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>MCP67</Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.32    </Version><SMBIOSVersion major="2" minor="4"/><Date>20090303000000.000000+000</Date></BIOS><HWID>7C303507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{913D0409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Standard for Students and Teachers</Name><Ver>10</Ver><Val>979FB3055A5E050</Val><Hash>vRcosDjncwIiT1NKIagbeAbncIY=</Hash><Pid>55866-718-4671127-17938</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.0.6002.18005
    Name: Windows(TM) Vista, HomePremium edition
    Description: Windows Operating System - Vista, OEM_COA_NSLP channel
    Activation ID: f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 89578-00146-522-041119-02-1033-6002.0000-0212011
    Installation ID: 017035179725533102183251860626547225040483849351596402
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
    Partial Product Key: MCJWJ
    License Status: Notification
    Notification Reason: 0xC004F200 (non-genuine).

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: PAAAAAEABwABAAEAAQABAAAAAwABAAEAeqjMBL5ddhu84yC+gASIzAaYmGBW4UQs8vSm1bD2AIusVniq

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: no, invalid SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PTLTD              APIC  
      FACP            NVIDIA        MCP67-M
      SRAT            AMD           HAMMER  
      HPET            PTLTD         HPETTBL
      BOOT            PTLTD         $SBFTBL$
      MCFG            PTLTD           MCFG  
      TCPA            Phoeni        x      
      SSDT            PTLTD         POWERNOW
      SLIC            HPQOEM        SLIC-MPC

    Friday, January 21, 2011 5:44 AM
  • "nomadatoll" wrote in message news:aa848752-40d0-4376-be12-f7106698d815...

    Nope, that did not work. It definitely reset and reinstalled the licensing as intended, but on the second restart, I type in the code from the bottom of the computer and I keep getting the same response. It say that it's not genuine. So, I click the "Go online and resolve now", which is the only option, and it opens an Explorer window. I can read the the page just before it gets redirected and it says that I need to install the ActiveX Control, but before I can do anything I'm at a Bing search page. I re-ran the diagnostics.

     

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-G694Q-C3DD4-MCJWJ
    Windows Product Key Hash: GeUZb6s47Ofvh2lv6MQU4Ioj/oc=
    Windows Product ID: 89578-OEM-7352202-41119
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.0.6002.2.00010300.2.0.003


    Please post back with the details of exactly what the COA sticker says - but NOT the key on it

    --


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Friday, January 21, 2011 9:17 AM
    Moderator
  • The sticker is a bit worn, but here's what is there:

    Windows Vista Home Premium

    (bar code)

    #s to worn to read

    00146-522-041-119

    (bar code)

    Key Code

    To the right of the two vertical security strips are these #s x13-04657

    Here is the computer info:

    HP DV6700

    p/n KN831UA#ABA

    Service Tag # DV6815nr

    two extra pieces of information:

    replaced heat sink & fan on Jan 3rd

    Ethertnet driver not working properly - uninstalled and reinstalled - now working properly


    ~Chris
    Friday, January 21, 2011 11:06 PM
  • "nomadatoll" wrote in message news:06dcc686-467f-47bf-9c01-8ec2ca8b5a24...

    The sticker is a bit worn, but here's what is there:

    Windows Vista Home Premium

    (bar code)

    #s to worn to read

    00146-522-041-119

    (bar code)

    Key Code

    To the right of the two vertical security strips are these #s x13-04657

    Here is the computer info:

    HP DV6700

    p/n KN831UA#ABA

    Service Tag # DV6815nr

    two extra pieces of information:

    replaced heat sink & fan on Jan 3rd

    Ethertnet driver not working properly - uninstalled and reinstalled - now working properly


    ~Chris

    Odd - I was expecting the Windows version/Edition to be different, because your current Key is a System Builder one, which is used by small builders, and for the free Upgrades provided by larger manufacturers at a new Windows launch.
    Do the visible Key numbers in the report match the ones on the sticker?
     
    Please reset all your Internet Explorer security settings to Default, then attempt validation again at http://www.microsoft.com/genuine/validate
    If it fails, go to the diagnostics page
    and see what it has to say  - follow any advice it gives, and then post back with a new MGADiag report.

    --


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Saturday, January 22, 2011 8:48 AM
    Moderator
  • Noel~

    At one point they were different. I ran a MGADiag report and the keys did not match, as expected. Then, after reinstalling the Licensing Store data and inputting the key from the COA sticker the new report has them matching.

    I've reset the defaults in Internet Explorer with no change in outcome. When I go to the Validate page it immediately redirects to search.microsoft.com. When I go to the Diagnostic page and click on the "Start Diagnostics" button, again it immediately redirects to search.microsoft.com.

    Interestingly, under "Browser Data" Firefox is listed as default browser, but I have made IE my default browser.

    Here's the new MGGADiag report:

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-G694Q-C3DD4-MCJWJ
    Windows Product Key Hash: GeUZb6s47Ofvh2lv6MQU4Ioj/oc=
    Windows Product ID: 89578-OEM-7352202-41119
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.0.6002.2.00010300.2.0.003
    ID: {4F017B6B-0F90-478B-A3AD-86BC5BED1745}(3)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6002.vistasp2_gdr.100608-0458
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    WGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: 2.0.48.0
    OGAExec.exe Signed By: Microsoft
    OGAAddin.dll Signed By: Microsoft

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office XP Standard for Students and Teachers - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{4F017B6B-0F90-478B-A3AD-86BC5BED1745}</UGUID><Version>1.9.0019.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-MCJWJ</PKey><PID>89578-OEM-7352202-41119</PID><PIDType>3</PIDType><SID>S-1-5-21-3646491923-1764803297-3543362824</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>MCP67</Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.32    </Version><SMBIOSVersion major="2" minor="4"/><Date>20090303000000.000000+000</Date></BIOS><HWID>7C303507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{913D0409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Standard for Students and Teachers</Name><Ver>10</Ver><Val>979FB3055A5E050</Val><Hash>vRcosDjncwIiT1NKIagbeAbncIY=</Hash><Pid>55866-718-4671127-17938</Pid><PidType>1</PidType></Product></Products><Applications><App Id="16" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.0.6002.18005
    Name: Windows(TM) Vista, HomePremium edition
    Description: Windows Operating System - Vista, OEM_COA_NSLP channel
    Activation ID: f3acdd3c-119a-4932-a3d7-0b6f33a1dca9
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 89578-00146-522-041119-02-1033-6002.0000-0212011
    Installation ID: 017035179725533102183251860626547225040483849351596402
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
    Partial Product Key: MCJWJ
    License Status: Notification
    Notification Reason: 0xC004F200 (non-genuine).

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: PAAAAAEABwABAAEAAQABAAAAAwABAAEAeqjMBL5ddhu84yC+gASIzAaYmGBW4UQs8vSm1bD2AIusVniq

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: no, invalid SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            PTLTD              APIC 
      FACP            NVIDIA        MCP67-M
      SRAT            AMD           HAMMER 
      HPET            PTLTD         HPETTBL
      BOOT            PTLTD         $SBFTBL$
      MCFG            PTLTD           MCFG 
      TCPA            Phoeni        x     
      SSDT            PTLTD         POWERNOW
      SLIC            HPQOEM        SLIC-MPC



    ~Chris
    Saturday, January 22, 2011 4:23 PM
  • "nomadatoll" wrote in message news:c075ab8a-9456-4527-9a7f-4f20d1e03c24...

    Noel~

    At one point they were different. I ran a MGADiag report and the keys did not match, as expected. Then, after reinstalling the Licensing Store data and inputting the key from the COA sticker the new report has them matching.

    I've reset the defaults in Internet Explorer with no change in outcome. When I go to the Validate page it immediately redirects to search.microsoft.com. When I go to the Diagnostic page and click on the "Start Diagnostics" button, again it immediately redirects to search.microsoft.com.

    Interestingly, under "Browser Data" Firefox is listed as default browser, but I have made IE my default browser.

    Here's the new MGGADiag report:

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: 0xc004c4a8
    Windows Product Key: *****-*****-G694Q-C3DD4-MCJWJ
    Windows Product Key Hash: GeUZb6s47Ofvh2lv6MQU4Ioj/oc=
    Windows Product ID: 89578-OEM-7352202-41119
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.0.6002.2.00010300.2.0.003



    ~Chris

     
    The only thing I can think of is that there's some form of hijack in progress.
    Open Internet Properties and reset all Security settings to Default.
    Look in the 'Connections' tab - make sure that all proxies are disabled in the Settings and LAN settings options (make a note of any found first, just in case!).
    Download and install MalwareBytes Anti-Malware (free version - www.malwarebytes.org) and update it - run a Quick scan in all user profiles on the machine.
     
    --


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Saturday, January 22, 2011 4:44 PM
    Moderator
  • Noel~

    Also ran this diagnostic.

    ComboFix 11-01-21.03 - PSB 01/22/2011  11:28:06.3.2 - x86
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3006.2048 [GMT -5:00]
    Running from: c:\users\Public\Downloads\ComboFix.exe
    AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
    FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
    SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .

    (((((((((((((((((((((((((   Files Created from 2010-12-22 to 2011-01-22  )))))))))))))))))))))))))))))))
    .

    2011-01-22 16:35 . 2011-01-22 16:35    --------    d-----w-    c:\users\Public\AppData\Local\temp
    2011-01-22 16:35 . 2011-01-22 16:35    --------    d-----w-    c:\users\Default\AppData\Local\temp
    2011-01-20 23:51 . 2011-01-22 16:17    --------    d-----w-    C:\MGADiagToolOutput
    2011-01-19 02:44 . 2011-01-19 02:44    --------    d-----w-    c:\users\PSB\AppData\Local\Seven Zip
    2011-01-19 02:41 . 2011-01-19 02:42    --------    d-----w-    c:\users\PSB\AppData\Roaming\muvee Technologies
    2011-01-18 04:54 . 2011-01-18 23:22    --------    d-----w-    c:\users\PSB\AppData\Roaming\FileZilla
    2011-01-18 04:54 . 2011-01-19 02:31    --------    d-----w-    c:\program files\FileZilla FTP Client
    2011-01-12 22:40 . 2010-12-28 15:55    413696    ----a-w-    c:\windows\system32\odbc32.dll
    2011-01-12 22:40 . 2010-12-28 15:53    253952    ----a-w-    c:\program files\Common Files\System\ado\msadox.dll
    2011-01-12 22:40 . 2010-12-28 15:53    241664    ----a-w-    c:\program files\Common Files\System\ado\msadomd.dll
    2011-01-12 22:40 . 2010-12-28 15:53    708608    ----a-w-    c:\program files\Common Files\System\ado\msado15.dll
    2011-01-12 22:40 . 2010-12-28 15:53    57344    ----a-w-    c:\program files\Common Files\System\msadc\msadcs.dll
    2011-01-12 22:40 . 2010-12-28 15:53    180224    ----a-w-    c:\program files\Common Files\System\msadc\msadco.dll
    2011-01-12 22:40 . 2010-12-14 14:49    1169408    ----a-w-    c:\windows\system32\sdclt.exe

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-11-04 18:56 . 2010-12-16 16:55    345600    ----a-w-    c:\windows\system32\wmicmiplugin.dll
    2010-11-04 18:55 . 2010-12-16 16:55    352768    ----a-w-    c:\windows\system32\taskschd.dll
    2010-11-04 18:55 . 2010-12-16 16:55    270336    ----a-w-    c:\windows\system32\taskcomp.dll
    2010-11-04 18:55 . 2010-12-16 16:55    601600    ----a-w-    c:\windows\system32\schedsvc.dll
    2010-11-04 16:34 . 2010-12-16 16:55    171520    ----a-w-    c:\windows\system32\taskeng.exe
    2010-11-02 06:01 . 2010-12-16 16:55    916480    ----a-w-    c:\windows\system32\wininet.dll
    2010-11-02 05:57 . 2010-12-16 16:55    43520    ----a-w-    c:\windows\system32\licmgr10.dll
    2010-11-02 05:57 . 2010-12-16 16:55    1469440    ----a-w-    c:\windows\system32\inetcpl.cpl
    2010-11-02 05:57 . 2010-12-16 16:55    71680    ----a-w-    c:\windows\system32\iesetup.dll
    2010-11-02 05:57 . 2010-12-16 16:55    109056    ----a-w-    c:\windows\system32\iesysprep.dll
    2010-11-02 05:01 . 2010-12-16 16:55    385024    ----a-w-    c:\windows\system32\html.iec
    2010-11-02 04:26 . 2010-12-16 16:55    133632    ----a-w-    c:\windows\system32\ieUnatt.exe
    2010-11-02 04:24 . 2010-12-16 16:55    1638912    ----a-w-    c:\windows\system32\mshtml.tlb
    2010-10-28 15:44 . 2010-12-16 16:55    34304    ----a-w-    c:\windows\system32\atmlib.dll
    2010-10-28 13:27 . 2010-12-16 16:55    292352    ----a-w-    c:\windows\system32\atmfd.dll
    2010-10-28 13:20 . 2010-12-16 16:55    2048    ----a-w-    c:\windows\system32\tzres.dll
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
    "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
    "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-24 13601312]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-24 92704]
    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
    "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2010-08-18 340520]
    "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2009-03-11 468264]
    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-09-24 159472]
    "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
    @="FSFilter System Recovery"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3646491923-1764803297-3543362824-1000]
    "EnableNotificationsRef"=dword:00000001

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
    R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2010-09-24 268528]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
    S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-15 36880]
    S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
    S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-03-18 172328]
    S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-03 19472]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs    REG_MULTI_SZ       BthServ
    WindowsMobile    REG_MULTI_SZ       wcescomm rapimgr
    LocalServiceRestricted    REG_MULTI_SZ       WcesComm RapiMgr
    LocalServiceAndNoImpersonation    REG_MULTI_SZ       FontCache

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2007-08-24 00:34    451872    ----a-w-    c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2011-01-21 c:\windows\Tasks\HPCeeScheduleForPSB.job
    - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-03-10 18:58]

    2011-01-22 c:\windows\Tasks\User_Feed_Synchronization-{4F7BAB36-438F-4656-94D1-617462CB1BF3}.job
    - c:\windows\system32\msfeedssync.exe [2010-12-16 04:25]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    FF - ProfilePath - c:\users\PSB\AppData\Roaming\Mozilla\Firefox\Profiles\040btbhx.default\
    FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
    FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-Locked - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-01-22 11:35
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2011-01-22  11:37:58
    ComboFix-quarantined-files.txt  2011-01-22 16:37
    ComboFix2.txt  2011-01-19 00:35
    ComboFix3.txt  2010-07-19 05:05

    Pre-Run: 42,938,531,840 bytes free
    Post-Run: 42,911,043,584 bytes free

    Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,33
    - - End Of File - - 0172C1DE58A280E0CF4399AF0ABC90B4


    ~Chris
    Saturday, January 22, 2011 4:51 PM
  • "nomadatoll" wrote in message news:e9654d27-f6dd-41d9-bfcc-02c38dae9fcc...

    Noel~

    Also ran this diagnostic.

    ComboFix 11-01-21.03 - PSB 01/22/2011  11:28:06.3.2 - x86
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3006.2048 [GMT -5:00]
    Running from: c:\users\Public\Downloads\ComboFix.exe
    AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
    FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
    SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
    @="FSFilter System Recovery"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3646491923-1764803297-3543362824-1000]
    "EnableNotificationsRef"=dword:00000001


    **************************************************************************

    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000

     


    ~Chris


    It's a very long time since I read a ComboFix report! I no longer feel qualified to read them so if you want a proper reading, and full advice on disinfection (especially if it does turn out to be malware) then I suggest that you go to www.aumha.net or www.bleepingcomputer.net and ask for assistance there (note that they will insist on certain actions before they even look at a report, so read the stickies on their malware removal forums carefully!)
    I've highlighted entries that look a little odd to me - but they may be innocent, and I wouldn't change them without better advice than I can give.
    Did you have Norton Installed at some point? - If so, then I suggest that you run the Norton Removal tool to get rid of the rubbish it leaves behind (even if it was the pre-installed software on the computer, and was never used, it still leaves stuff behind) - http://us.norton.com/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN&ln=en_US
     
    Any results from MBAM yet? (although I'd expect little, if Kaspersky is up to its usual standards)
     

    --


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    • Proposed as answer by Darin Smith MS Monday, January 24, 2011 10:15 PM
    Saturday, January 22, 2011 5:27 PM
    Moderator
  • None of the possible solutions worked.

    Result: Complete reinstall. Not the end of the world.

    Thank you for all the assistance.


    ~Chris
    • Marked as answer by Darin Smith MS Wednesday, January 26, 2011 9:43 PM
    Tuesday, January 25, 2011 11:12 PM
  • "nomadatoll" wrote in message news:9f00226a-e5ab-48aa-a026-5981560b763a...

    None of the possible solutions worked.

    Result: Complete reinstall. Not the end of the world.

    Thank you for all the assistance.


    ~Chris

    Ah well, can't win 'em all!
    Glad you seem to be back to normal operations again - Good Luck.
     

    --


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    Wednesday, January 26, 2011 4:42 AM
    Moderator