none
An Unauthorized change was made to Windows

    Question

  • Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Status: Genuine
    Validation Code: 0
    Cached Online Validation Code: N/A, hr = 0x80070426
    Windows Product Key: *****-*****-98KXH-GV9M8-JHWP2
    Windows Product Key Hash: 6rUcO240HKgME9no4tXwJG5AhNo=
    Windows Product ID: 89578-OEM-7249042-62494
    Windows Product ID Type: 8
    Windows License Type: COA SLP
    Windows OS version: 6.0.6000.2.00010300.0.0.003
    ID: {EA2BE68D-7529-45B1-B8EB-A672B1931467}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6000.vista_gdr.100218-0019
    TTS Error: M:20130820185156327-
    Validation Diagnostic: 
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: 6.0.6001.18000

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    Default Browser: C:\Users\mondoburley\AppData\Local\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\user32.dll[6.0.6000.16438], Hr = 0x800b0100

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{EA2BE68D-7529-45B1-B8EB-A672B1931467}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6000.2.00010300.0.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-JHWP2</PKey><PID>89578-OEM-7249042-62494</PID><PIDType>8</PIDType><SID>S-1-5-21-2500782374-3172049252-1819504981</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Inspiron 1520                   </Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>A04</Version><SMBIOSVersion major="2" minor="4"/><Date>20071105000000.000000+000</Date></BIOS><HWID>45300500018400FA</HWID><UserLCID>1809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL  </OEMID><OEMTableID>M08    </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: U1BMRwEAAAAAAQAABAAAAI1rVgAAAAAAYWECADAgAACQe/Cgrr/KARhDs/4hWdo7Xkl9D+HKpnhTxh+wxQg/A4i1Ai2KgzvF86i/uXdVV3Gzd1HCxJ+7BhY3hlB6ccWFlfEC2sD/66L09mtkaKAWLORd97F81Jp8sEGnmR0ReJ9KlWCJouxq6PAIwHwHVMfvNauSbFvmaTBYC/G/amipOp+xBjXwWbbP9S/GUDYecePFRKM/leS97bxOVVm9fICZUkfHdDNbo725QzYM7NoLIP6BsYz9FHAia30CP0z0OYRuUWLuf4S5JTOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMvTbpTJVExpKCfqWZhr6UXa78R3/bnGSgb/MQw0f3nPErDD4HrDkZw1L+b/MWSE84xaPotV14Z5INwzRVvWsztBg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJh5BRhkeY9gVsjnGneifskdJzGrd/PyI/Fr8JTdC0e9O+ZRJ0w7jfPDmJzOMRtWkHDfUxUTAlCg1WWZ0veQsn5TOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM0CtKv0wsQJzlHzdy9g94zCZiKPXnYWchxIG28kkOCOTkNwqomAZ2PmfYFBnWmfZOKww+B6w5GcNS/m/zFkhPOFIddwJy545wj6o30H/aZcEYPzXtLwK7UdSUY0dUUEtOXQGlGwPoPC3HoCfHMRTYiYeQUYZHmPYFbI5xp3on7JHScxq3fz8iPxa/CU3QtHvTvmUSdMO43zw5iczjEbVpBw31MVEwJQoNVlmdL3kLJ+UzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDNArSr9MLECc5R83cvYPeMwsVr51d8piFwQ6Muo8P+Ts+0dZ1WqwbqbytRv+ZX2amSsMPgesORnDUv5v8xZITziFMh6ccWMNx4k7rEy+PVndGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2ImHkFGGR5j2BWyOcad6J+yR0nMat38/Ij8WvwlN0LR7075lEnTDuN88OYnM4xG1aQcN9TFRMCUKDVZZnS95CyflM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMKKil+UozyBSE7zVPGXRaeVwYVZiizinfDwDFeFpo+JcrDD4HrDkZw1L+b/MWSE84XNZk7uFlQY85Y/7MrRTaTRg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJh5BRhkeY9gVsjnGneifskdJzGrd/PyI/Fr8JTdC0e9O+ZRJ0w7jfPDmJzOMRtWkHDfUxUTAlCg1WWZ0veQsn5TOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM0CtKv0wsQJzlHzdy9g94zAYMY0I2krpV1tyhhexLXNC+bw3npDuaEHeNJDLXzW/jKww+B6w5GcNS/m/zFkhPOBjt/yFcPXiunc+C2/bQMPwYPzXtLwK7UdSUY0dUUEtOXQGlGwPoPC3HoCfHMRTYiYeQUYZHmPYFbI5xp3on7JHScxq3fz8iPxa/CU3QtHvTvmUSdMO43zw5iczjEbVpBw31MVEwJQoNVlmdL3kLJ+UzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDNArSr9MLECc5R83cvYPeMzP2tQemByxm2be1BKqf1Gq8iWhfHkT2tEP1WWbz4mipCsMPgesORnDUv5v8xZITzhfLgbKOVFItUVgOX8FxZwLGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2ImHkFGGR5j2BWyOcad6J+yR0nMat38/Ij8WvwlN0LR7075lEnTDuN88OYnM4xG1aQcN9TFRMCUKDVZZnS95CyflM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMvv7VtZ0zFGGZ3T5gFY5PkWVduJf6ch73pKWwo7PPmVQrDD4HrDkZw1L+b/MWSE84Oh3s5ZDIi5pDEZcnuNhFvxg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJh5BRhkeY9gVsjnGneifskdJzGrd/PyI/Fr8JTdC0e9O+ZRJ0w7jfPDmJzOMRtWkHDfUxUTAlCg1WWZ0veQsn5TOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM

    Licensing Data-->
    Software Licensing service is not running.

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: OAAAAAAABgABAAIAAQAAAAAAAwABAAEAJJT26ZIvJCtmc14KkHNGg8KDUoO4+/L0fEk6j6xWKoU=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20000
    OEMID and OEMTableID Consistent: yes
    BIOS Information: 
      ACPI Table Name OEMID Value OEMTableID Value
      APIC DELL   M08    
      FACP DELL   M08    
      HPET DELL   M08    
      BOOT DELL   M08    
      MCFG DELL   M08    
      SLIC DELL   M08    
      SSDT PmRef CpuPm

    Tuesday, August 20, 2013 6:47 PM

Answers

  • You have a Mod-Auth Tamper....

    Please run a full CHKDSK and SFC scan....

     

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     

    At the Command prompt, type

     

    CHKDSK C: /R

     

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.

     

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

     

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -

    then run the SFC.

     

    SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

     

    At the Command prompt, type

     

    SFC /SCANNOW

     

    and hit the Enter key

     

    Wait for the scan to finish - make a note of any error messages - and then reboot.

     

     

    Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive Public folder (http://skydrive.live.com ) and post a link to it so that I can take a look.

     

    Post a new MGADiag report with details of any error messages encountered.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
    No - I do not work for Microsoft, or any of its contractors.

    Wednesday, August 21, 2013 9:09 AM
    Moderator