Answered by:
Unauthorised Change was made to Windows ......that will result in limited Windows functionality.

Question
-
Dear Sirs
I have Windows Vista. Whenever I start up the lap-top I get the message that an 'Unauthorised Change was made to Windows ......that will result in limited Windows functionality'. I then get the two options to 'Close' or 'Find out more via internet'. I have now done a System Restore several times from Safe Mode and then run the diagnostic report. Last time I re-started I got an 'Invalid License' message in the Validation Status field. However the latest report (below) says 'Genuine'.
The only programs I've installed at all recently are I-tunes and Avira Control Centre. Avira Control is still installed whereas I-tunes was removed following recent System Restores. From recent experience I know that when I next re-start my lap-top I will get the Unauthorised Change message and another enforced closure.
Any ideas how I can stop this happening?
Thanks
R
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-4JJQP-TP64Y-RPFFV
Windows Product Key Hash: W7I5PeTN2iJuvTTU9QmIXc6iQqY=
Windows Product ID: 89578-OEM-7332157-00043
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6000.2.00010300.0.0.003
ID: {313E4E71-4D99-4DB7-A22D-7952921253F1}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Premium
Architecture: 0x00000000
Build lab: 6000.vista_gdr.100218-0019
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
2007 Microsoft Office system - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\rpcrt4.dll[6.0.6000.16850], Hr = 0x800b0100
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{313E4E71-4D99-4DB7-A22D-7952921253F1}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6000.2.00010300.0.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-RPFFV</PKey><PID>89578-OEM-7332157-00043</PID><PIDType>2</PIDType><SID>S-1-5-21-787076782-3102516086-3553492109</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>X51RL </Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>202 </Version><SMBIOSVersion major="2" minor="4"/><Date>20071015000000.000000+000</Date></BIOS><HWID>6B333507018400FA</HWID><UserLCID>0809</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>GMT Standard Time(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0031-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>2007 Microsoft Office system</Name><Ver>12</Ver><Val>8CC7C7D6B1B4A60</Val><Hash>K5gJcLQIjjKb44ENXDUVIeb4kRc=</Hash><Pid>89451-304-6477911-66726</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>
Spsys.log Content: U1BMRwEAAAAAAQAABAAAAIYKAAAAAAAAWmICANOQu5dkT09AdtvNAdArSr9MLECc5R83cvYPeMzGx4MqqP+YalFTOOioLR732hMyVXAONObrS1HTQHuvOl+gwhNu+IeQRxhCs7OCF+MPsg444/Xtree8HCGD62w0GD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2IlIVcU1NmgXOc/3y+M9lv7f0nMat38/Ij8WvwlN0LR700BeYdi5UqK8Ce5F2YRTEM9PN3MXtCtbOqphU++LYllJM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMF7bOQuRstbdvUyZ2P5dhbIKk0oGoA2e1u/4lRDqcNUVfoMITbviHkEcYQrOzghfjcyxyrVFBvYOoi4PTXBxL5hg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJSFXFNTZoFznP98vjPZb+39JzGrd/PyI/Fr8JTdC0e9NAXmHYuVKivAnuRdmEUxDPTzdzF7QrWzqqYVPvi2JZSTOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM0CtKv0wsQJzlHzdy9g94zORp2wXQSZfcuBA6o8XP2F4fWdhYmuh1YIo7kMmm/DEMX6DCE274h5BHGEKzs4IX4zY2t3bBEDAUdOvf4imvxHIYPzXtLwK7UdSUY0dUUEtOXQGlGwPoPC3HoCfHMRTYiUhVxTU2aBc5z/fL4z2W/t/Scxq3fz8iPxa/CU3QtHvTQF5h2LlSorwJ7kXZhFMQz083cxe0K1s6qmFT74tiWUkzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDNArSr9MLECc5R83cvYPeMxwv0zNy7Qfq8aJN4ZTLuHAdsNhTgsubZeqXf3rYNJtgV+gwhNu+IeQRxhCs7OCF+NYA1e140mQyVvaw+Zbzj0iGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2IlIVcU1NmgXOc/3y+M9lv7f0nMat38/Ij8WvwlN0LR700BeYdi5UqK8Ce5F2YRTEM9PN3MXtCtbOqphU++LYllJM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMMSTMU71x0B0ZfHseeel8xfukTZ6ZIa9Yp992UN1WOClfoMITbviHkEcYQrOzghfj3T2gXC8FfZqrJdNyte4nhhg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJSFXFNTZoFznP98vjPZb+39JzGrd/PyI/Fr8JTdC0e9NAXmHYuVKivAnuRdmEUxDPTzdzF7QrWzqqYVPvi2JZSTOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM0CtKv0wsQJzlHzdy9g94zEEoDY3v3465W6jTS+EIgSHXzqFemjr1yWAsC5/3fh7WX6DCE274h5BHGEKzs4IX4098kcv0WGMLA093NtHfD/wYPzXtLwK7UdSUY0dUUEtOXQGlGwPoPC3HoCfHMRTYiUhVxTU2aBc5z/fL4z2W/t/Scxq3fz8iPxa/CU3QtHvTQF5h2LlSorwJ7kXZhFMQz083cxe0K1s6qmFT74tiWUkzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDNArSr9MLECc5R83cvYPeMz0duLDn6cp98OEPf4Fq4pIxIuPNnD4LrjnNrUVMaMb6F+gwhNu+IeQRxhCs7OCF+Ot0aBDf0o11KGSdj7j21akGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2IlIVcU1NmgXOc/3y+M9lv7f0nMat38/Ij8WvwlN0LR700BeYdi5UqK8Ce5F2YRTEM9PN3MXtCtbOqphU++LYllJM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAzQK0q/TCxAnOUfN3L2D3jMl9RN8oJZ4zJQcPImF3Nktw1bXRCf+vaBICrMhAyNhUdfoMITbviHkEcYQrOzghfjDe6S9yaBJ3WIEoq1uv5Bqhg/Ne0vArtR1JRjR1RQS05dAaUbA+g8LcegJ8cxFNiJSFXFNTZoFznP98vjPZb+39JzGrd/PyI/Fr8JTdC0e9NAXmHYuVKivAnuRdmEUxDPTzdzF7QrWzqqYVPvi2JZSTOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM0CtKv0wsQJzlHzdy9g94zAUu3I0hh3uXz0OFOf8hF01EhtKhoG7gFlUg+XKkvINOX6DCE274h5BHGEKzs4IX43RAieeC6WcvBkTprWsqkIgYPzXtLwK7UdSUY0dUUEtOXQGlGwPoPC3HoCfHMRTYiUhVxTU2aBc5z/fL4z2W/t/Scxq3fz8iPxa/CU3QtHvTQF5h2LlSorwJ7kXZhFMQz083cxe0K1s6qmFT74tiWUkzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDA==
Licensing Data-->
Software licensing service version: 6.0.6000.16509
Name: Windows(TM) Vista, HomePremium edition
Description: Windows Operating System - Vista, OEM_SLP channel
Activation ID: bffdc375-bbd5-499d-8ef1-4f37b61c895f
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 89578-00146-321-500043-02-1033-6000.0000-3032012
Installation ID: 104614664920479316123381501386383712872944721410995340
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkId=57201
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkId=57203
Use License URL: http://go.microsoft.com/fwlink/?LinkId=57205
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkId=57204
Partial Product Key: RPFFV
License Status: Licensed
Windows Activation Technologies-->
N/A
HWID Data-->
HWID Hash Current: OAAAAAEABQABAAEAAQABAAAAAwABAAEAJJQodqpYzLSyNJYwkKa4kWb7IM7y9KgCUIl+fKxWKoU=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20000
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC A.M.I OEMAPIC
FACP A.M.I OEMFACP
BOOT A.M.I OEMBOOT
MCFG A.M.I OEMMCFG
SLIC _ASUS_ Notebook
OEMB A.M.I AMI_OEM
- Edited by robert Wheatcroft Wednesday, December 26, 2012 1:14 PM
Wednesday, December 26, 2012 1:12 PM
Answers
-
You have a couple of problems.....
the obvious one is
File Mismatch: C:\Windows\system32\rpcrt4.dll[6.0.6000.16850], Hr = 0x800b0100
The less obvious one is that you haven't installed either of the Service Packs for Vista.
Please run a full CHKDSK and SFC scan....
Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.
At the Command prompt, type
CHKDSK C: /R
and hit the Enter key.
You will be told that the drive is locked,
and the CHKDSK will run at he next boot - hit the Y key, press Enter, and then reboot.
The CHKDSK will take a few hours depending on the size of the drive, so be patient!
After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -
then run the SFC.
SFC -System File Checker - Instructions
Click on Start > All Programs > Accessories
Right-click on the Command Prompt entry
Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.
At the Command prompt, type
SFC /SCANNOW
and hit the Enter key
Wait for the scan to finish - make a note of any error messages - and then reboot.
Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive (http://skydrive.live.com ) and post a link to it so that I can take a look.
Post a new MGADiag report with details of any error messages encountered.
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth
- Proposed as answer by Noel D PatonModerator Saturday, December 29, 2012 11:34 AM
- Marked as answer by Noel D PatonModerator Saturday, January 5, 2013 10:35 AM
Wednesday, December 26, 2012 1:20 PMModerator