locked
Vista-unauthorized change to windows RRS feed

  • Question

  • I also have just had the unauthorized change to windows. How is it fixed?

    Diagnostic Report (1.7.0069.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50
    Online Validation Code: 0x80070426
    Cached Validation Code: N/A, hr = 0x80070426
    Windows Product Key: *****-*****-27HYQ-XTKW2-WQD8Q
    Windows Product Key Hash: U8YEZzymoD4DMyaMb32rPrNIS90=
    Windows Product ID: 89578-OEM-7332157-00061
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.0.6000.2.00010300.0.0.003
    CSVLK Server: N/A
    CSVLK PID: N/A
    ID: {5EFA6A5F-F72F-4405-B48A-8DBB8B135B35}(1)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6000.vista_gdr.071023-1545
    TTS Error: M:20080410033201436-
    Validation Diagnostic:
    Resolution Status: N/A

    WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: 6.0.6001.18000

    Notifications Data-->
    Cached Result: N/A
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    OGA Version: Registered, 1.6.21.0
    Signed By: Microsoft
    Office Diagnostics: B4D0AA8B-531-645_B4D0AA8B-531-645_025D1FF3-282-80041010_025D1FF3-170-80041010_025D1FF3-171-1_025D1FF3-434-80040154_025D1FF3-178-80040154_025D1FF3-179-2_025D1FF3-185-80070002_025D1FF3-199-3_672A8F41-307-80004005_672A8F41-349-80004005_672A8F41-244-80004005_672A8F41-307-80004005_672A8F41-349-80004005_672A8F41-244-80004005

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    Default Browser: C:\PROGRA~1\MOZILL~1\FIREFOX.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\dnsapi.dll[6.0.6000.16615]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{5EFA6A5F-F72F-4405-B48A-8DBB8B135B35}</UGUID><Version>1.7.0069.0</Version><OS>6.0.6000.2.00010300.0.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-WQD8Q</PKey><PID>89578-OEM-7332157-00061</PID><PIDType>2</PIDType><SID>S-1-5-21-3110102184-4214464418-289001227</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>HP Pavilion dv6000 (GA456UA#ABA)  </Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.3D    </Version><SMBIOSVersion major="2" minor="4"/><Date>20071122000000.000000+000</Date></BIOS><HWID>DF313507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><BRT/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>6DDB1271381FF71</Val><Hash>qRxCngR0nvMQzOnpfRc+s1lV8Pg=</Hash><Pid>89446-952-9178897-65785</Pid><PidType>1</PidType></Product><Product GUID="{91120000-0014-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional 2007</Name><Ver>12</Ver><Val>41C920CF4F5B27E</Val><Hash>P1l0PyGEQR3ukIylNJbPzYqwjxo=</Hash><Pid>81605-319-4410586-65861</Pid><PidType>10</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>8400250A0269A6A</Val><Hash>G2N4NuWkv61P2j2nXQRblVU3kBQ=</Hash><Pid>81602-309-9985146-68789</Pid><PidType>10</PidType></Product></Products></Office></Software></GenuineResults> 

    Spsys.log Content: U1BMRwEAAAAAAQAABAAAALwTAAAAAAAAYWECADAgAABRt/9Y5ZrIAdArSr9MLECc5R83cvYPeMz6L364NUDV1N9OQFaV5vEck6VfH50wGHAzWh3J+8/OJPmA2FF124VnPMn56Nv0G9EFv9D81lg0OGcZuYaYg4XjGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2IlE7oPk/SPeaYoTWCOSbwhb0nMat38/Ij8WvwlN0LR706J/AdUP4L3wi2m/Gi/9qyM7UcmmKQdXOYNsqcu4BNLbM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAw=

     

     

    Thursday, April 10, 2008 10:59 AM

Answers

  • Hello steven C_il,

     

    Vista is in, what is called a 'Mod-Auth' Tamper state.  There are 2 types of Mod-Auth tampers.

     

    1) A critical system file was modified On Disk - What this means is that the file, located on the hard drive, was modified in some way. This can be caused by random file corruption, a malicious program (spyware, malware, virus) or by manual file modification (by a user of the system). There is also a very small chance that an Update may fail in mid-update and cause this type of issue. As a safety mechanism, Updates are made so that if they fail, they roll back any updating that was done before the failure, but there is an off-chance that the roll back did not occure.

     

    2) A critical system file was modified In Memory - What this means is the file itself (on the hard drive) is un-modified, but the code, from that file, running in the system, was modified in some way. and is usually caused by a running program that is incompatible with Vista.

     

      Because of the Mismatched file listed under the "File Scan Data-->" line of your Diagnostic Report, your issue is an On Disk Mod-Auth. The Mismatched file (dnsapi.dll) is the file that has been Modified or has become corrupted.

     

      Normally, I would just have you re-install a past update that contained the file. This would replace the bad file with an unmodified/corrupted copy. But I am unable to find any update that contains file dnsapi.dll. Therefor I am only able to suggest 2 other options and neither are very good.

     

    1) You can try installing Service Pack 1 for Vista (http://www.microsoft.com/downloads/details.aspx?FamilyID=b0c7136d-5ebb-413b-89c9-cb3d06d12674&DisplayLang=en). I do not know for sure, but it is possible that file dnsapi.dll could be included in SP1. If it is, your issue will be resolved, but if it doesn't, then you will have to go to option 2

     

    2) Reinstall Vista. I don't like suggesting this, but I know of no other way to replace that file and untill that file is replaced or repaired, this issue will continue.

     

    Sorry I couldn't be more help

    Darin Smith

    WGA Forum Manager

     

    Thursday, April 10, 2008 10:42 PM