Answered by:
Windows 7 OEM 64Bit Ultimate - Keep getting Windows is not genuine pop-up

Question
-
Hi All,
Had this copy of Win 7 for almost a year but now I keep getting "Windows Activation Technologies" pop-up telling me my copy is not genuine.
I have call Microsoft and re-validated my copy with no success. Microsoft have confirmed it's a valid copy but not sure what to do next. Below is a post of my Microsoft Genuine Advantage Diagnostic Tool resalts.
All I can think of when this started happing was when Windows Update stop working after I installed 3 hot fixes, KB979538, KB2362165 and KB2158563. All hot fixes where successfully installed.
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-93C22-XGWPR-DB3F4
Windows Product Key Hash: LfSoif2yIRk7rvAgDoU0xE91o6c=
Windows Product ID: 00426-OEM-9154234-38642
Windows Product ID Type: 3
Windows License Type: OEM System Builder
Windows OS version: 6.1.7600.2.00010100.0.0.001
ID: {5D354F1E-0392-4A95-AD3B-92172D019646}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7600.win7_gdr.100618-1621
TTS Error:
Validation Diagnostic:
Resolution Status: N/AVista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional Plus 2007 - 100 Genuine
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{5D354F1E-0392-4A95-AD3B-92172D019646}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-DB3F4</PKey><PID>00426-OEM-9154234-38642</PID><PIDType>3</PIDType><SID>S-1-5-21-3930289557-1644914298-3946816306</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-DS4P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F5</Version><SMBIOSVersion major="2" minor="4"/><Date>20080709000000.000000+000</Date></BIOS><HWID>97BA3607018400F8</HWID><UserLCID>0C09</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>AUS Eastern Standard Time(GMT+10:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0011-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Plus 2007</Name><Ver>12</Ver><Val>B357D90FB836D86</Val><Hash>pZdUqPVWsDt+FhdrLvGoWOal9Po=</Hash><Pid>89409-707-0273711-65088</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7600.16385Name: Windows(R) 7, Ultimate edition
Description: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
Activation ID: cfb3e52c-d707-4861-af51-11b27ee6169c
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00426-00182-542-338642-02-3081-7600.0000-0122010
Installation ID: 000252071905390113340420649356676144321803955900526793
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: DB3F4
License Status: Licensed
Remaining Windows rearm count: 3
Trusted time: 6/10/2010 6:03:15 PMWindows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000003EFFF
Event Time Stamp: 10:4:2010 10:02
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\wat\watadminsvc.exe
Tampered File: %systemroot%\system32\wat\watweb.dll
Tampered File: %systemroot%\system32\wat\npwatweb.dll
Tampered File: %systemroot%\system32\wat\watux.exe
Tampered File: %systemroot%\system32\sppobjs.dll
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\sppwinob.dll
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
Tampered File: %systemroot%\system32\drivers\spsys.sys
Tampered File: %systemroot%\system32\drivers\spldr.sys
HWID Data-->
HWID Hash Current: OgAAAAIABgABAAEAAAACAAAAAgABAAEA6GFC3GwjVCZGvAw1hDTkv5I8KAsShfTW8q6peX7zLIFGyg==OEM Activation 1.0 Data-->
N/AOEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC GBT GBTUACPI
FACP GBT GBTUACPI
HPET GBT GBTUACPI
MCFG GBT GBTUACPI
SSDT PmRef CpuPm
RegardsAlvi
Wednesday, October 6, 2010 8:33 AM
Answers
-
You have several tampered files, validation is dependant upon these files. The steps below MAY help, if not use the link at the bottom of the post to start a no cost tech support incident.
type cmd in the search box of the start menu, right click on the icon that appears and type sfc /scannow without the qoutes and press enter, allow SFC to run, reboot when directed. If you get any error messages write them down exactly as they appear. After rebooting go to www.microsoft.com/genuine and attempt to validate.
If that does not work then type system restore in the search box, click on the resulting program and follow the wizards prompts to restore to a previous point prior to the non-genuine status.
If that does not work then start a no cost wga tech support incident at the following link http://support.microsoft.com/gp/contactwga
- Proposed as answer by David. FModerator Wednesday, October 6, 2010 8:47 PM
- Marked as answer by David. FModerator Monday, October 11, 2010 6:59 PM
Wednesday, October 6, 2010 12:38 PM