locked
Windows says not genuine. RRS feed

  • Question

  • This computer has been running Windows 7 Professional for months. Randomly it shows that it is not genuine. Windows validation and slui show that its valid yet i'm still getting non-genuine messages.

    Diag:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-*****-*****-WP7JM
    Windows Product Key Hash: tcg6kWHPg0eRwwssPvDXAl8/rjM=
    Windows Product ID: 55041-033-2325952-86917
    Windows Product ID Type: 6
    Windows License Type: Volume MAK
    Windows OS version: 6.1.7601.2.00010100.1.0.048
    ID: {B6EAA3B9-66B4-4566-BBEF-AE2CA6BFE06D}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Professional
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.130828-1532
    TTS Error: 
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-604-645_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\npwatweb.dll[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watweb.dll[Hr = 0x80070003]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{B6EAA3B9-66B4-4566-BBEF-AE2CA6BFE06D}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>55041-033-2325952-86917</PID><PIDType>6</PIDType><SID>S-1-5-21-610681652-479775348-3327451856</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>4105R9U</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>60KT46AUS</Version><SMBIOSVersion major="2" minor="6"/><Date>20130403000000.000000+000</Date></BIOS><HWID>B9333507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TC-60   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Professional edition
    Description: Windows Operating System - Windows(R) 7, VOLUME_MAK channel
    Activation ID: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 55041-00172-033-232595-03-1033-7601.0000-1812014
    Installation ID: 014674039990010243586032950235109383724286807125983930
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: WP7JM
    License Status: Licensed
    Remaining Windows rearm count: 0
    Trusted time: 7/7/2014 4:43:03 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 4:14:2014 15:47
    ActiveX: Not Registered - 0x80040154
    Admin Service: Not Registered - 0x80040154
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: KgAAAAEAAQABAAEAAAABAAAAAQABAAEAln2sHdRxNi48trKLJHX8hOqC

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC PTLTD APIC  
      FACP INTEL TYLERBRG
      HPET PTLTD HPETTBL 
      BOOT PTLTD $SBFTBL$
      MCFG PTLTD  MCFG  
      SSDT INTEL PPM RCM 
      TCPA LENOVO TC-2W   
      SLIC LENOVO TC-60   
      DMAR Intel OEMDMAR 
      ASF! LENOVO TC-60   

    Any help?

    Monday, July 7, 2014 10:00 PM

Answers

  • RemoveWAT will cause other problems! - and won't do what you want it to do anyhow, in all probability, since the WAT update isn't installed.

    What is the current AV? What other security products are running at boot? What other AV's have EVER been installed?

    What non-MS products are loading at boot? (look in MSCONFIG's Startup tab)

    Maybe you should install the WAT update (KB971033) and see if it gives us more data? It does enable MGADiag to see stuff that's not visible otherwise.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, July 8, 2014 2:08 PM
    Moderator

All replies

  • This kind of behaviour is caused by a race condition, and is notoriously difficult to pin down. Often it's the result of an AV (or malware) interfering in the bootup license checks but any process that uses a lot of CPU time can cause it.

    There doesn't appear to be any problem with the report.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, July 8, 2014 6:54 AM
    Moderator
  • Have any idea's of what would solve it? Malware bytes scan comes back negative, and chkdsk too. I'm close to just trying RemoveWAT and having the error go away.
    Tuesday, July 8, 2014 1:31 PM
  • What about just eliminating ALL programs from startup and killing off any non-microsoft services?
    Tuesday, July 8, 2014 1:32 PM
  • RemoveWAT will cause other problems! - and won't do what you want it to do anyhow, in all probability, since the WAT update isn't installed.

    What is the current AV? What other security products are running at boot? What other AV's have EVER been installed?

    What non-MS products are loading at boot? (look in MSCONFIG's Startup tab)

    Maybe you should install the WAT update (KB971033) and see if it gives us more data? It does enable MGADiag to see stuff that's not visible otherwise.


    Noel Paton | Nil Carborundum Illegitemi
    CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Tuesday, July 8, 2014 2:08 PM
    Moderator
  • I disabled all non-ms programs in msconfig and all services relevant to AV. We are running Trend Micro as an AV. Only other ever installed was malware bytes. Will try the update and report back if it has helpded.
    Tuesday, July 8, 2014 2:46 PM