locked
I think I have a virus version of windows RRS feed

  • Question

  • A weird icon poped up in my task bar and the my background screen became black and this information popped up in the lower right hand corner, Widowns Vista (TM) Build 6001 This copy of Windows is not genuine, than I ran the Validation and it says it is invalid

     

    Diagnostic Report (1.9.0019.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50

    Cached Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-4WD8X-M9WM7-CH4CG
    Windows Product Key Hash: EkdqJZ28Y9zyrh7DU/lHNjTXlQY=
    Windows Product ID: 89572-OEM-7332166-00096
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.0.6001.2.00010300.1.0.002
    ID: {63E3A2E6-A20E-4F2D-89E6-594631453EF0}(1)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Basic
    Architecture: 0x00000000
    Build lab: 6001.vistasp1_gdr.091208-0542
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    WGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 102
    Microsoft Office Professional 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{63E3A2E6-A20E-4F2D-89E6-594631453EF0}</UGUID><Version>1.9.0019.0</Version><OS>6.0.6001.2.00010300.1.0.002</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-CH4CG</PKey><PID>89572-OEM-7332166-00096</PID><PIDType>2</PIDType><SID>S-1-5-21-4045156641-2412093056-2964816466</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>HP Pavilion dv7 Notebook PC</Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.49</Version><SMBIOSVersion major="2" minor="4"/><Date>20090817000000.000000+000</Date></BIOS><HWID>FD303507018400F6</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>102</Result><Products><Product GUID="{91120000-0014-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional 2007</Name><Ver>12</Ver><Val>41E8C78E9760AB6</Val><Hash>VCL0ln2oPqvyft12VTcSEscbIQs=</Hash><Pid>81605-347-4680613-65929</Pid><PidType>10</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/></Applications></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.0.6001.18000
    Name: Windows(TM) Vista, HomeBasic edition
    Description: Windows Operating System - Vista, OEM_SLP channel
    Activation ID: 199086aa-6cb8-4e5b-b698-f2be56f1e8ee
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 89572-00146-321-600096-02-1033-6001.0000-0562010
    Installation ID: 014706480721115884195051161423273593036972908805126613
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
    Partial Product Key: CH4CG
    License Status: Notification
    Notification Reason: 0xC004F032.

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: OAAAAAEABAABAAEAAQACAAAAAwABAAEAeqiWwVAepANGZFT5EDPsLVrG8vTqRVSqSASWMaxWfig=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20000
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name OEMID Value OEMTableID Value
      APIC   HPQOEM  SLIC-MPC
      FACP   HP      TRINITY
      HPET   HPQOEM  SLIC-MPC
      BOOT   HPQOEM  SLIC-MPC
      MCFG   HPQOEM  SLIC-MPC
      SLIC   HPQOEM  SLIC-MPC
      SSDT   AMD     PowerNow

     

    Sunday, March 28, 2010 4:53 PM

Answers

  • Hello Sarah Yuille,

    It appears that Vista's Licensing Store may be corrupt or it's data is "messed up" in some way.  I recommend recreating the Store using the below steps.

    1) Open an Internet Browser window.
    2) Type: %windir%\system32 into the browser address bar.
    3) Find the file CMD.exe
    4) Right-Click on CMD.exe and select 'Run as Administrator'
    5) Type: net stop slsvc  (it may ask you if you are sure, select yes)
    6) Type: cd %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing
    7) Type: rename tokens.dat tokens.bar
    8) Type: cd %windir%\system32
    9) Type: net start slsvc
    10) Type: cscript slmgr.vbs -rilc (It may take a long time for this to complete, please be patient)
    11) Restart your computer twice.
    12) You may be required to enter the Product Key and/or Activate. (use the product key from the sticker on the side or bottom of the PC and Activate by Phone).

     

    Thank you,


    Darin MS
    Monday, March 29, 2010 10:00 PM