locked
False tampering message by SLUI RRS feed

  • Question

  • I just got a message stating my windows installation has been tampered with by SLUI, and I'm not sure what's going on... This just started today.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 50
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
    Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
    Windows Product ID: 00359-OEM-8992687-00007
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {75FC63B7-A542-4C22-BD4B-360065FBCE41}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Users\Stephen\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{75FC63B7-A542-4C22-BD4B-360065FBCE41}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-2358918262-3504525436-692860453</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>G74Sx</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>G74Sx.203</Version><SMBIOSVersion major="2" minor="6"/><Date>20110923000000.000000+000</Date></BIOS><HWID>652F3D07018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0xC004F012' to display the error text.
    Error: 0xC004F012 

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 6:9:2012 11:34
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: NgAAAAIAAQABAAEAAQABAAAABQABAAEAln2m9dIpTjTuI6AGIo3eiAIYtpyO9JoqmWxUUi5z

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC _ASUS_ Notebook
      FACP _ASUS_ Notebook
      DBGP _ASUS_ Notebook
      HPET _ASUS_ Notebook
      MCFG _ASUS_ Notebook
      ECDT _ASUS_ Notebook
      SLIC _ASUS_ Notebook
      SSDT PmRef Cpu0Ist
      SSDT PmRef Cpu0Ist
      ASF! INTEL HCG

    Sunday, August 5, 2012 10:16 PM

Answers

  • SLUI.EXE is part of your operating system - it's supposed to 'tamper' :)

    What did you get this warning from?

    please do the following.


    Please run a full CHKDSK and SFC scan....
     type in the Search box

     CMD.EXE

     right-click on the only file that is found
     Select Run as Administrator
     - the Elevated Command Prompt window should pop up
     At the Command prompt, type

     CHKDSK C: /R

     and hit the Enter key.

     You will be told that the drive is locked,
     and the CHKDSK will run at he next boot - hit the Y key, and then reboot.

     The chkdsk will take a few hours depending on the size
     of the drive, so be patient!
     
     After the CHKDSK has run, Windows should boot normally
     (possibly after a second auto-reboot) - then run the SFC

     SFC -System File Checker - Instructions
     Click on the Start button
     type in the Search box

     CMD.EXE

     right-click on the only file that is found
      Select Run as Administrator - the Elevated Command Prompt window should pop up
     At the Command prompt, type
     
     SFC /SCANNOW
     
     and hit the Enter key
     
     Wait for the scan to finish - make a note of any error messages - and then reboot.
      Post an MGADiag report with details of any error messages encountered.     


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Sunday, August 5, 2012 10:25 PM
    Moderator