Answered by:
WGA now thinks my copy of windows is not genuine

Question
-
Hi - recently started receiving 'your copy is not geniune' notices in win7, after no problems for about a year or so. I have 29 days to solve this, apparently!
People recommended using sfc /scannow to work out whats going on with dodgy files - this said there were no errors. Anything else I can try?
output from MGADiag follows. Thanks!
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-WV7XR-DPT4X-QYDYG
Windows Product Key Hash: D/tJp1/tLFsGlvJhZsYEisVKqgc=
Windows Product ID: 00371-153-9694626-85282
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {5A4F194C-2C02-4D69-B939-222F0A4B6EB9}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Professional
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120503-2030
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Enterprise 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_ 025D1FF3-230-1_025D1FF3-517- 80040154_025D1FF3-237- 80040154_025D1FF3-238-2_ 025D1FF3-244-80070002_ 025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Users\Pippa\AppData\Local\Google\Chrome\Application\ chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\en-US\sppc.dll.mui[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\sppcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\slc.dll.mui[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\slcext.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\sppuinotify.dll.mui[6.1.7600. 16385], Hr = 0x80092003
File Mismatch: C:\Windows\system32\en-US\slui.exe.mui[6.1.7600.16385], Hr = 0x80092003
File Mismatch: C:\Windows\system32\en-US\sppcomapi.dll.mui[6.1.7600. 16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\sppcommdlg.dll.mui[6.1.7600. 16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\sppsvc.exe.mui[6.1.7600.16385] , Hr = 0x80092003
File Mismatch: C:\Windows\system32\drivers\spsys.sys[6.1.7127.0], Hr = 0x80092003
File Mismatch: C:\Windows\system32\drivers\spldr.sys[6.1.7127.0], Hr = 0x80092003
File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7601.17514] , Hr = 0x800b0100
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{5A4F194C-2C02-4D69- B939-222F0A4B6EB9}</UGUID>< Version>1.9.0027.0</Version>< OS>6.1.7601.2.00010100.1.0. 048</OS><Architecture>x64</ Architecture><PKey>*****-***** -*****-*****-QYDYG</PKey><PID> 00371-153-9694626-85282</PID>< PIDType>5</PIDType><SID>S-1-5- 21-3420906285-400059534- 282165741</SID><SYSTEM>< Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>GA- MA785GT-UD3H</Model></SYSTEM>< BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version> F4</Version><SMBIOSVersion major="2" minor="4"/><Date> 20091203000000.000000+000</ Date></BIOS><HWID> 16B93607018400F4</HWID>< UserLCID>0809</UserLCID>< SystemLCID>0409</SystemLCID>< TimeZone>GMT Standard Time(GMT+00:00)</TimeZone>< iJoin>0</iJoin><SBID><stat>3</ stat><msppid></msppid><name></ name><model></model></SBID>< OEM/><GANotification/></ MachineData><Software><Office> <Result>100</Result><Products> <Product GUID="{91120000-0030-0000- 0000-0000000FF1CE}">< LegitResult>100</LegitResult>< Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val> BD2221991067773</Val><Hash> 5IlVzYcpWcP1Epd/JQnVKWatqc4=</ Hash><Pid>81599-953-8892107- 65497</Pid><PidType>1</ PidType></Product></Products>< Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications>< /Office></Software></ GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Professional edition
Description: Windows Operating System - Windows(R) 7, RETAIL channel
Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00371-00170-153-969462-01-2057-7601.0000-1762012
Installation ID: 003773669364608861350156758566346430826121169435904021
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: QYDYG
License Status: Notification
Notification Reason: 0xC004F009 (grace time expired).
Remaining Windows rearm count: 4
Trusted time: 26/06/2012 11:59:26
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000001EF60
Event Time Stamp: 6:26:2012 11:21
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify. dll.mui
Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll. mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll. mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
Tampered File: %systemroot%\system32\drivers\spsys.sys
HWID Data-->
HWID Hash Current: NAAAAAEABAABAAEAAAADAAAAAQABAAEAJJSyp1L+VPIQM+ CoGIiMYcS46kUqz4vIzMoYeQ==
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC GBT GBTUACPI
FACP GBT GBTUACPI
HPET GBT GBTUACPI
MCFG GBT GBTUACPI
SSDT PTLTD POWERNOW
TAMG GBT GBT B0Tuesday, June 26, 2012 11:31 AM
Answers
-
looks like you have vistalizator installed. see this:
http://social.microsoft.com/Forums/en-US/genuinewindows7/thread/6f6b1cb8-e84e-4c1f-a2ac-181a77d2f772
- Proposed as answer by Darin Smith MS Tuesday, June 26, 2012 4:57 PM
- Marked as answer by Darin Smith MS Friday, June 29, 2012 6:20 PM
Tuesday, June 26, 2012 11:56 AMAnswerer
All replies
-
looks like you have vistalizator installed. see this:
http://social.microsoft.com/Forums/en-US/genuinewindows7/thread/6f6b1cb8-e84e-4c1f-a2ac-181a77d2f772
- Proposed as answer by Darin Smith MS Tuesday, June 26, 2012 4:57 PM
- Marked as answer by Darin Smith MS Friday, June 29, 2012 6:20 PM
Tuesday, June 26, 2012 11:56 AMAnswerer -
"george1009" wrote in message news:4228b6e3-db4d-423d-ae07-bac16f2234c5...
looks like you have vistalizator installed. see this:
http://social.microsoft.com/Forums/en-US/genuinewindows7/thread/6f6b1cb8-e84e-4c1f-a2ac-181a77d2f772
I can't even blame the caffeine this time!
:(
Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed SlothTuesday, June 26, 2012 12:11 PMModerator