locked
Unauthorized Change to Windows - Windows Not Genuine RRS feed

  • Question

  • I woke up this morning and my computer told me an unauthorized change had been made to my Vista Basic. It also told me I had to determine if my software was valid. The computer program said it was invalid, even though it came pre-installed on my computer from Wal Mart. Now it's asking me for the product key, which I don't have because the computer didn't come with any manuals. I ran the diagnostic, and here's what I came up with:

    Diagnostic Report (1.7.0066.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Invalid License
    Validation Code: 50
    Online Validation Code: 0xc004c2fa
    Cached Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-GD2PK-BD3R2-44MV3
    Windows Product Key Hash: f7FPE6g/CLFmnJ4E6GbEU9Xn1sA=
    Windows Product ID: 89572-OEM-7332166-00021
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.0.6000.2.00010300.0.0.002
    CSVLK Server: N/A
    CSVLK PID: N/A
    ID: {18C3B9FA-801D-441B-8F81-0319089A10D9}(1)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows Vista (TM) Home Basic
    Architecture: 0x00000000
    Build lab: 6000.vista_ldr.071009-1543
    TTS Error: T:20080122194117182-
    Validation Diagnostic:
    Resolution Status: N/A

    Notifications Data-->
    Cached Result: N/A
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: FCEE394C-2989-80070002

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{18C3B9FA-801D-441B-8F81-0319089A10D9}</UGUID><Version>1.7.0066.0</Version><OS>6.0.6000.2.00010300.0.0.002</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-44MV3</PKey><PID>89572-OEM-7332166-00021</PID><PIDType>2</PIDType><SID>S-1-5-21-3872871182-1035829241-2458305014</SID><SYSTEM><Manufacturer>Compaq-Presario</Manufacturer><Model>GN573AA-ABA SR5223WM</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies, LTD</Manufacturer><Version> 5.10</Version><SMBIOSVersion major="2" minor="4"/><Date>20070716000000.000000+000</Date></BIOS><HWID>CB313507018400F6</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-CPC</OEMTableID></OEM><BRT/></MachineData><Software><Office><Result>109</Result><Products/></Office></Software></GenuineResults> 

    Spsys.log Content: U1BMRwEAAAAAAQAABAAAALIFAAAAAAAAYWECANOQLJWPGNgLYV3IAdKUkVDxCoM358lePs/mGn16applgn7p9gNdwjp57985L6qqUWB3Xw8iGcufHyELXzOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAyuPJYEjuzrM7pi8z8IgTuMGcCdHwAFbEfbsOJHuhJK5izwfOFvqpUZOPmStp57YQIzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM


    Wednesday, January 23, 2008 4:39 PM

Answers

  •  

    It appears that the command that you typed was:

     Branden1977 wrote:

    cscript %windir%\System32\slmgr.vbs /ilc %\System32\licensing\ppdlic\Security-Licensing-SLC-ppdic.xrm-ms

    The correct command is:

     

    cscript %windir%\System32\slmgr.vbs /ilc %windir%\System32\licensing\ppdlic\Security-Licensing-SLC-ppdlic.xrm-ms

     

     (the part highlighted in red is missing from the command you typed)

     

    Darin

     

     

    Thursday, January 24, 2008 8:19 PM

All replies

  • Hello Branden1977,

     

      If you look at the Diagnostic Report, you should see the line that starts "TTS Error:" This stands for Tamper Time Stamp error. When Vista is suffering from a Tamper State, the TTS Error line will be followed by a letter and then a large number (such as T:20080122194117182-).

     

      The letter can be either M, K or T.   M = Mod-Auth Tamper, K = Kernel Tamper and T = Trusted Store Tamper

     

      In your case you have a Trusted Store Tamper, which is the rarest, but should be the easiest to fix. There are currently no "known" Vista hacks that target the trusted store (for obvious reasons), so we believe the Trusted Store files were just a victim of random corruption.

     

      To fix this issue, please try the below steps:

     

     

    (If you access to the start button)

    1) Click the Start button

    2) Type: cmd in the Start Search field

    3) At the top the Start window, you will see cmd.exe

    4) Right Click cmd.exe and select Run as Administrator

    5) Type: cscript %windir%\System32\slmgr.vbs /ilc %windir%\System32\licensing\ppdlic\Security-Licensing-SLC-ppdlic.xrm-ms

    6) Hit the Enter key

    7) Reboot 2 times

     

    (If you Do Not access to the start button)

    1) Click the option Access computer with reduced functionality

    2) A Browser will open, type: %windir%\system32 into the address field

    3) Find the file cmd.exe

    4) Right Click on the cmd.exe and select Run as Administrator

    5) Type: cscript %windir%\System32\slmgr.vbs /ilc %windir%\System32\licensing\ppdlic\Security-Licensing-SLC-ppdlic.xrm-ms

    6) Hit the Enter key

    7) Reboot 2 times

     

    Please tell me if this resolves your issue.

     

    Thank you,

    Darin Smith

    WGA Forum Manager

    Wednesday, January 23, 2008 7:18 PM

  • I don't seem to be able to put the computer in 'reduced functionality' mode, and I don't have access to the start button. When the computer boots it up, it prompts me to enter the product key (I don't have one, as the software just came on the computer with no manuals or anything.) Or, I can try to verify online, which I do, and the online verifier tells me it can't determine whether my copy is genuine or not (I've tried this about 15 times.)

    As a sidenote, this is incredibly frustrating. Whatever is causing this, please stop it or just give XP back, because this sucks. I would rather not be spending my free time fixing this ***.
    Wednesday, January 23, 2008 9:17 PM
  • Hello Branden1977,

     

      Please try the above steps again, but for step 1) just click whatever option that brings up an internet browser.  In your case, I believe the option is 'Verify Online'. Then go on to step 2.

     

    "it prompts me to enter the product key (I don't have one, as the software just came on the computer with no manuals or anything.) " The product key can be found on the sticker (called the COA Sticker) found on the bottom or side of the computer.

     

       All computers that come pre-installed with a "Windows License Type: OEM SLP" version of Vista must have a COA sticker either on the bottom or side of the computer. If your computer does not have this sticker, please contact the company that built the computer (in your case, Compaq) for further assistance in obtaining the proper COA sticker.

     

    Thank you,

    Darin Smith

    WGA Forum Manager

    Wednesday, January 23, 2008 9:39 PM
  • Every time I type the %windir%\system32 into the address, it just brings up a google search for the phrase.
    Wednesday, January 23, 2008 9:50 PM
  • Please make sure that

     

    a) you are entering the command %windir%\system32 in the Address bar of the browser, not the Search area. The address bar is the place that you normally type in a website's URL

     

    b) there is no http before the command

     

    c) there are no spaces before or after the command

     

    you can also try typing C:/Windows/System32 or file:///C:/Windows/System32 in the browser address bar, instead.

     

     

    Darin

    Wednesday, January 23, 2008 11:02 PM
  • Here is what I get when I try to run the script:

    Microsoft Windows [Version 6.0.6000]
    Copyright (c) 2006 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>cscript %windir%\System32\slmgr.vbs /ilc %\System32\licensin
    g\ppdlic\Security-Licensing-SLC-ppdic.xrm-ms
    Microsoft (R) Windows Script Host Version 5.7
    Copyright (C) Microsoft Corporation. All rights reserved.

    Run 'slui.exe 0x2a 0x4C' to display the error text.
    Error: 0x4C

    Help?

    Thursday, January 24, 2008 3:06 AM
  •  

    It appears that the command that you typed was:

     Branden1977 wrote:

    cscript %windir%\System32\slmgr.vbs /ilc %\System32\licensing\ppdlic\Security-Licensing-SLC-ppdic.xrm-ms

    The correct command is:

     

    cscript %windir%\System32\slmgr.vbs /ilc %windir%\System32\licensing\ppdlic\Security-Licensing-SLC-ppdlic.xrm-ms

     

     (the part highlighted in red is missing from the command you typed)

     

    Darin

     

     

    Thursday, January 24, 2008 8:19 PM
  • Hi Mr. Darin Smith,

    Please  help me solved my problem "Unauthorized changed to Windows". I'm using Windows server 2008 Standard.

    Below is my WGA Diagnostic Report:

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Status: Genuine
    Validation Code: 0
    Cached Online Validation Code: N/A, hr = 0x80070426
    Windows Product Key: N/A, hr=0x80070005
    Windows Product Key Hash: N/A, hr=0x80070005
    Windows Product ID: 55041-098-6382977-76331
    Windows Product ID Type: 6
    Windows License Type: Volume MAK
    Windows OS version: 6.0.6001.2.00030110.1.0.007
    ID: {CADF2437-5005-4C6A-AA3B-7D87A1A9CB61}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: Windows Server (R) 2008 Standard
    Architecture: 0x00000009
    Build lab: 6001.vistasp1_gdr.101014-0432
    TTS Error: K:20120911182212696-M:20120830054106758-
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: B4D0AA8B-543-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Disabled
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Disabled
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Disabled
    Script ActiveX controls marked as safe for scripting: Disabled

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{CADF2437-5005-4C6A-AA3B-7D87A1A9CB61}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6001.2.00030110.1.0.007</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>55041-098-6382977-76331</PID><PIDType>6</PIDType><SID>S-1-5-21-1729199846-460099133-885371487</SID><SYSTEM><Manufacturer>IBM </Manufacturer><Model>BladeCenter HS22 -[7870G4A]-</Model></SYSTEM><BIOS><Manufacturer>IBM</Manufacturer><Version>-[P9E151BUS-1.12]-</Version><SMBIOSVersion major="2" minor="5"/><Date>20110207000000.000000+000</Date></BIOS><HWID>14300500018400F4</HWID><UserLCID>3409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Malay Peninsula Standard Time(GMT+08:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>IBM   </OEMID><OEMTableID>BLADE   </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: U1BMRwEAAAAAAQAACAAAAAmFAQgAAAAAYWECAAAAAADEx+q1uQLNARhy9171jCizkdIEkQaJZ642ZA5TsBWdNQErgJ/weBWkfsKLYJCiOOaxwp6Iq2ZamSd7IPmIgITKmLNv1wD2WLa8a4hZHk5kc4H7EmfFQHlh4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsOaDbvMnTA1onDIC8xbfNWgsGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuEqJYzaSHRtgndXm2B3WObjVke86lsyOM2BtfSSZCGGgneyD5iICEypizb9cA9li2uXAg3SKfHdYgKFQzx8ExxamjnBHePB2LDp7apxATyFCKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDmg27zJ0wNaJwyAvMW3zVoLBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrkrGpzEYydYtlIY31aPS1gs0egnvTe659BGf1R9t6VFnJ3sg+YiAhMqYs2/XAPZYtr7lGu9VFp80Ksi1PY9+sW6po5wR3jwdiw6e2qcQE8hQipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw5oNu8ydMDWicMgLzFt81aCwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ67Kuc+CO3U32wprsYMLIkjcRR918r7ih0DPpkE/kU6qaid7IPmIgITKmLNv1wD2WLbKVrligNyf20JzfDkN7DtCqaOcEd48HYsOntqnEBPIUIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsOaDbvMnTA1onDIC8xbfNWgsGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuYH70ocfXdQBiCnRTSHGztWvei3YBE53+3Q4tmtS0vMwneyD5iICEypizb9cA9li2QzqqkaPX1/fetnG5eQQframjnBHePB2LDp7apxATyFCKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDmg27zJ0wNaJwyAvMW3zVoLBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrhyiK7kTQZkaehLfDB7ELGlN0fDGbmnEDcZFmEniBZW2J3sg+YiAhMqYs2/XAPZYtn02Cy1Qprak6Qf+FQTya/6po5wR3jwdiw6e2qcQE8hQipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw5oNu8ydMDWicMgLzFt81aCwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ65h61Heeyc/UGuPiVg1WAaZBsgbuLfdDe+Gteb7NjLl/yd7IPmIgITKmLNv1wD2WLb0WJLGX1MEwaaxHfvNAFZxqaOcEd48HYsOntqnEBPIUIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsOaDbvMnTA1onDIC8xbfNWgsGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeubV+gpYJUNOW797uT3fMZXGN+oIGyA6u/9MlIs4SDFZAneyD5iICEypizb9cA9li2Ik58aKuavDyM9jhJEQSJEamjnBHePB2LDp7apxATyFCKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDmg27zJ0wNaJwyAvMW3zVoLBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM

    Licensing Data-->
    Software Licensing service is not running.

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    HWID Hash Current: LAAAAAAAAAABAAEAAgAAAAAAAwABAAEACrYc9VBPCq+0f/L0nBU2VnEAgig=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20000
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            IBM           BLADE   
      FACP            IBM           BLADE   
      HPET            IBM           BLADE   
      MCFG            IBM           BLADE   
      TCPA                    
      SLIC            IBM           BLADE   
      SSDT            IBM           CPUSCOPE
      SSDT            IBM           CPUSCOPE
      SSDT            IBM           CPUSCOPE
      ERST            IBM           BLADE  

    Thanks,

    Xandra

    Wednesday, September 12, 2012 3:09 AM
  • Please repost your report in a NEW thread of your own to avoid confusion - you have a problem with the Software Licensing Service.

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    Wednesday, September 12, 2012 6:09 AM
    Moderator
  • Ok I will...
    Wednesday, September 12, 2012 10:30 AM