Answered by:
Vista-unauthorized change to windows

Question
-
I also have just had the unauthorized change to windows. How is it fixed?
Diagnostic Report (1.7.0069.0):
-----------------------------------------
WGA Data-->
Validation Status: Invalid License
Validation Code: 50
Online Validation Code: 0x80070426
Cached Validation Code: N/A, hr = 0x80070426
Windows Product Key: *****-*****-27HYQ-XTKW2-WQD8Q
Windows Product Key Hash: U8YEZzymoD4DMyaMb32rPrNIS90=
Windows Product ID: 89578-OEM-7332157-00061
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6000.2.00010300.0.0.003
CSVLK Server: N/A
CSVLK PID: N/A
ID: {5EFA6A5F-F72F-4405-B48A-8DBB8B135B35}(1)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Premium
Architecture: 0x00000000
Build lab: 6000.vista_gdr.071023-1545
TTS Error: M:20080410033201436-
Validation Diagnostic:
Resolution Status: N/AWgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: 6.0.6001.18000Notifications Data-->
Cached Result: N/A
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Data-->
Office Status: 100 Genuine
OGA Version: Registered, 1.6.21.0
Signed By: Microsoft
Office Diagnostics: B4D0AA8B-531-645_B4D0AA8B-531-645_025D1FF3-282-80041010_025D1FF3-170-80041010_025D1FF3-171-1_025D1FF3-434-80040154_025D1FF3-178-80040154_025D1FF3-179-2_025D1FF3-185-80070002_025D1FF3-199-3_672A8F41-307-80004005_672A8F41-349-80004005_672A8F41-244-80004005_672A8F41-307-80004005_672A8F41-349-80004005_672A8F41-244-80004005Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\PROGRA~1\MOZILL~1\FIREFOX.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->
File Mismatch: C:\Windows\system32\dnsapi.dll[6.0.6000.16615]Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{5EFA6A5F-F72F-4405-B48A-8DBB8B135B35}</UGUID><Version>1.7.0069.0</Version><OS>6.0.6000.2.00010300.0.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-WQD8Q</PKey><PID>89578-OEM-7332157-00061</PID><PIDType>2</PIDType><SID>S-1-5-21-3110102184-4214464418-289001227</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>HP Pavilion dv6000 (GA456UA#ABA) </Model></SYSTEM><BIOS><Manufacturer>Hewlett-Packard</Manufacturer><Version>F.3D </Version><SMBIOSVersion major="2" minor="4"/><Date>20071122000000.000000+000</Date></BIOS><HWID>DF313507018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><BRT/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>6DDB1271381FF71</Val><Hash>qRxCngR0nvMQzOnpfRc+s1lV8Pg=</Hash><Pid>89446-952-9178897-65785</Pid><PidType>1</PidType></Product><Product GUID="{91120000-0014-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional 2007</Name><Ver>12</Ver><Val>41C920CF4F5B27E</Val><Hash>P1l0PyGEQR3ukIylNJbPzYqwjxo=</Hash><Pid>81605-319-4410586-65861</Pid><PidType>10</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><Val>8400250A0269A6A</Val><Hash>G2N4NuWkv61P2j2nXQRblVU3kBQ=</Hash><Pid>81602-309-9985146-68789</Pid><PidType>10</PidType></Product></Products></Office></Software></GenuineResults>Spsys.log Content: U1BMRwEAAAAAAQAABAAAALwTAAAAAAAAYWECADAgAABRt/9Y5ZrIAdArSr9MLECc5R83cvYPeMz6L364NUDV1N9OQFaV5vEck6VfH50wGHAzWh3J+8/OJPmA2FF124VnPMn56Nv0G9EFv9D81lg0OGcZuYaYg4XjGD817S8Cu1HUlGNHVFBLTl0BpRsD6Dwtx6AnxzEU2IlE7oPk/SPeaYoTWCOSbwhb0nMat38/Ij8WvwlN0LR706J/AdUP4L3wi2m/Gi/9qyM7UcmmKQdXOYNsqcu4BNLbM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAw=
Thursday, April 10, 2008 10:59 AM
Answers
-
Hello steven C_il,
Vista is in, what is called a 'Mod-Auth' Tamper state. There are 2 types of Mod-Auth tampers.
1) A critical system file was modified On Disk - What this means is that the file, located on the hard drive, was modified in some way. This can be caused by random file corruption, a malicious program (spyware, malware, virus) or by manual file modification (by a user of the system). There is also a very small chance that an Update may fail in mid-update and cause this type of issue. As a safety mechanism, Updates are made so that if they fail, they roll back any updating that was done before the failure, but there is an off-chance that the roll back did not occure.
2) A critical system file was modified In Memory - What this means is the file itself (on the hard drive) is un-modified, but the code, from that file, running in the system, was modified in some way. and is usually caused by a running program that is incompatible with Vista.
Because of the Mismatched file listed under the "File Scan Data-->" line of your Diagnostic Report, your issue is an On Disk Mod-Auth. The Mismatched file (dnsapi.dll) is the file that has been Modified or has become corrupted.
Normally, I would just have you re-install a past update that contained the file. This would replace the bad file with an unmodified/corrupted copy. But I am unable to find any update that contains file dnsapi.dll. Therefor I am only able to suggest 2 other options and neither are very good.
1) You can try installing Service Pack 1 for Vista (http://www.microsoft.com/downloads/details.aspx?FamilyID=b0c7136d-5ebb-413b-89c9-cb3d06d12674&DisplayLang=en). I do not know for sure, but it is possible that file dnsapi.dll could be included in SP1. If it is, your issue will be resolved, but if it doesn't, then you will have to go to option 2
2) Reinstall Vista. I don't like suggesting this, but I know of no other way to replace that file and untill that file is replaced or repaired, this issue will continue.
Sorry I couldn't be more help
Darin Smith
WGA Forum Manager
Thursday, April 10, 2008 10:42 PM