locked
Help with genuine advantage issue RRS feed

  • Question

  • Hi,
    I'm helping family with a computer issue where it claims that windows cannot be activated.  There's no reason to think it would be originally illegitimate so I wanted to post my mga here so that I could get some insight with which to investigate the issue further.

    Thanks.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 50
    Cached Online Validation Code: 0xc004c4ab
    Windows Product Key: *****-*****-X92GV-V7DCV-P4K27
    Windows Product Key Hash: aU2z1/fnhnLHmhBm699qYZT2E6s=
    Windows Product ID: 00426-OEM-8992662-00400
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010100.1.0.001
    ID: {EACAF12E-02B9-4279-8323-24DEBCD9E2BB}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Enterprise 2007 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{EACAF12E-02B9-4279-8323-24DEBCD9E2BB}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-P4K27</PKey><PID>00426-OEM-8992662-00400</PID><PIDType>2</PIDType><SID>S-1-5-21-4045617612-4058785448-342869276</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>GA-73PVM-S2H</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F4</Version><SMBIOSVersion major="2" minor="4"/><Date>20071220000000.000000+000</Date></BIOS><HWID>4EDA3F07018400FA</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>64BC76978749586</Val><Hash>GW6PzcEVEDTVKeO5Ym5UUm41dBk=</Hash><Pid>89388-707-0441865-65550</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, Ultimate edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00426-00178-926-600400-02-1033-7600.0000-0162012
    Installation ID: 001825145460902293662182976975197315477533029043781200
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: P4K27
    License Status: Notification
    Notification Reason: 0xC004F200 (non-genuine).
    Remaining Windows rearm count: 4
    Trusted time: 9/2/2012 10:14:16 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0xC004C4AB
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 9:2:2012 18:18
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MAAAAAAABAABAAEAAAACAAAAAQABAAEAJJRWPOzFZJ3MBrRzmpz69bZqQnFSciqF

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            GBT           GBTUACPI
      FACP            GBT           GBTUACPI
      HPET            GBT           GBTUACPI
      MCFG            GBT           GBTUACPI
      SSDT            PmRef        CpuPm

    Monday, September 3, 2012 5:19 AM

Answers

  • YOur system has a retail motherboard - the installation of WIndows has been done using a Dell OEM_SLP Key, together with a hacker's Avctivation Exploit to circumvent activation and validation requirements.

    The Windows Software Protection system has discovered the hack - which is why you are being notified.

    You need to either take the issue up with your supplier, or purchase a new Full Retail License for Windows 7 - you should do a full reformat and reinstall, as the integrity of this system cannot be guaranteed until you do.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    • Marked as answer by melink14 Monday, September 3, 2012 7:06 PM
    Monday, September 3, 2012 10:39 AM
    Moderator
  • Unfortunately, the installed OEM copy of Windows 7 Ultimate is non-genuine.  You need to purchase a genuine "full version" edition of Windows 7 and perform a "clean install".  Genuine Windows 7 editions are available from the The Microsoft Store.

    Carey Frisch

    Monday, September 3, 2012 6:07 AM
    Moderator

All replies

  • Unfortunately, the installed OEM copy of Windows 7 Ultimate is non-genuine.  You need to purchase a genuine "full version" edition of Windows 7 and perform a "clean install".  Genuine Windows 7 editions are available from the The Microsoft Store.

    Carey Frisch

    Monday, September 3, 2012 6:07 AM
    Moderator
  • YOur system has a retail motherboard - the installation of WIndows has been done using a Dell OEM_SLP Key, together with a hacker's Avctivation Exploit to circumvent activation and validation requirements.

    The Windows Software Protection system has discovered the hack - which is why you are being notified.

    You need to either take the issue up with your supplier, or purchase a new Full Retail License for Windows 7 - you should do a full reformat and reinstall, as the integrity of this system cannot be guaranteed until you do.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    • Marked as answer by melink14 Monday, September 3, 2012 7:06 PM
    Monday, September 3, 2012 10:39 AM
    Moderator
  • Thanks Carey for the answer and Noel for the extra details.  Especially on labor day.

    I wasn't there when it was installed but supposedly it was done via a disk with holographic microsoft sticker so I guess I'll have them take it to their friend for a reinstall since my labor day 'vacation'/tech support visit ends soon.

    Monday, September 3, 2012 7:19 PM