Windows 7 not genuine error message

Answered Windows 7 not genuine error message

  • Monday, July 23, 2012 5:34 PM
     
     

    Hi,

    I keep getting an error message that tells me my version of Windows 7 is not genuine. However, it is genuine.

    Error code it shows is 0x8004fe22

    Things I've tried from different topics:

    - Click on the Start Button and type CMD in Search Bar. Right click on the Command Prompt shortcut and select Run As Administrator.
    - At the administrator command prompt, type in "slmgr.vbs -ipk <insert your product key here>".

    This gave me the message that registration is succesful, however I still get the prompt of a message saying that my version is not genuine.

    When I left click 'Computer' and then scroll down to check if Windows is activated, it says it is. However, when I go to the website to confirm it's genuine it refers me to a page where it offers me to buy a new windows install. Basically I'm really confused as to why I get this message even though when I check it differently, it says it is genuine.

    I've also deleted update kb 971033.

    Any help would be great, thanks.


    • Edited by FrankvH91 Monday, July 23, 2012 5:35 PM
    •  

All Replies

  • Monday, July 23, 2012 5:41 PM
     
     

    To properly analyse and solve problems with Activation and Validation, we need to see a full copy of the report produced by the MGADiag tool
    (download and save to desktop - http://go.microsoft.com/fwlink/?linkid=52012 )
     Once saved, run the tool.
    Click on the Continue button, which will produce the report.
     To copy the report to your response, click on the Copy button in the tool (ignore any error messages at this point), and then paste (using either r-click/Paste, or Ctrl+V ) into your response.
      - **in your own thread**, please

    Please also state the Version and Edition of Windows quoted on your COA sticker (if you have one) on the case of your machine (or inside the battery compartment), but do NOT quote the Key on the sticker!
    http://www.microsoft.com/en-us/howtotell/Hardware.aspx


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Monday, July 23, 2012 5:53 PM
     
     

    Here's the diagnostics report. I will post the info of the sticker in a moment.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE22
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
    Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
    Windows Product ID: 00359-OEM-8992687-00007
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-4062122376-4072100849-687342899</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>N53SV</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>N53SV.214</Version><SMBIOSVersion major="2" minor="6"/><Date>20110810000000.000000+000</Date></BIOS><HWID>32483607018400FE</HWID><UserLCID>0413</UserLCID><SystemLCID>0413</SystemLCID><TimeZone>West-Europa (standaardtijd)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Versie van Software Licensing-service: 6.1.7601.17514

    Naam: Windows(R) 7, HomePremium edition
    Beschrijving: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activerings-id: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Toepassings-id55c92734-d682-4d71-983e-d6ec3f16059f
    Uitgebreide PID: 00359-00178-926-800007-02-1043-7601.0000-2042012
    Installatie-id103581693171297156972282569086101210664472043971214596
    URL van processorcertificaat: http://go.microsoft.com/fwlink/?LinkID=88338
    URL van computercertificaat: http://go.microsoft.com/fwlink/?LinkID=88339
    URL van gebruikte licentie: http://go.microsoft.com/fwlink/?LinkID=88341
    URL van productcodecertificaat: http://go.microsoft.com/fwlink/?LinkID=88340
    Gedeeltelijke productcode: 9YQTR
    Licentiestatus: licentie
    Resterend aantal nieuwe Windows-activeringen: 1
    Vertrouwde tijd: 23-7-2012 19:50:41

    Windows Activation Technologies-->
    HrOffline: 0x8004FE22
    HrOnline: N/A
    HealthStatus: 0x0000000000000800
    Event Time Stamp: 7:23:2012 19:32
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration


    HWID Data-->
    HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAonaMkncW0ikaOKwefPacvwQ/kgnm8gA+LnM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            _ASUS_        Notebook
      FACP            _ASUS_        Notebook
      DBGP            _ASUS_        Notebook
      HPET            _ASUS_        Notebook
      MCFG            _ASUS_        Notebook
      ECDT            _ASUS_        Notebook
      SLIC            _ASUS_        Notebook
      SSDT            PmRef        Cpu0Ist
      SSDT            PmRef        Cpu0Ist
      ASF!            INTEL          HCG

  • Monday, July 23, 2012 6:10 PM
     
      Has Code

    Your problem is due to this...

    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration

    please run the following commands in an Elevated Command Prompt window which may help isolate the actual cause.

    SFC /SCANFILE=C:\windows\system32\slui.exe
    DIR C:\Windows\slui.* /S
    ICACLS C:\Windows\System32\slui.exe

      Here are some instructions to make life easier :)
    1) To open an Elevated Command Prompt Window (the CP window), click on Start, All Programs, Accessories – then right-click on Command Prompt, and select Run as Administrator. Accept the UAC prompt. 
    2) To run the commands easier, highlight the block of commands, and right-click on the highlight – select Copy. In the CP Windows, click on the black/white icon at top left – select Paste. The commands will run but may not complete the last command, so hit the Enter Key once. 
    3) To copy the results... click on the Black/White icon in the top left, and select Edit... 'Select All', and hit the Enter key - then use Ctrl+V or r-click+Paste to paste it into your response.     


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Monday, July 23, 2012 6:23 PM
     
     

    My laptop downloaded the KB971033 update again, should I just let it install?

    Here's the cmd results, it's in Dutch, any fast way I can change that?The first message states 'No violates of integrity found'.

    Thanks for your help by the way.

    Microsoft Windows [versie 6.1.7601]
    Copyright (c) 2009 Microsoft Corporation. Alle rechten voorbehouden.

    C:\Users\Frank>sfc /scanfile=C:\windows\system32\slui.exe


    Er zijn geen schendingen van de integriteit gevonden.

    C:\Users\Frank>dir C:\windows\slui.* /S
     De volumenaam van station C is OS
     Het volumenummer is 2484-EBDD

     Map van C:\windows\Prefetch

    23-07-2012  19:50            29.658 SLUI.EXE-724E99D9.pf
                   1 bestand(en)           29.658 bytes

     Map van C:\windows\System32

    20-11-2010  15:25           349.696 slui.exe
                   1 bestand(en)          349.696 bytes

     Map van C:\windows\System32\nl-NL

    19-02-2011  06:39            28.672 slui.exe.mui
                   1 bestand(en)           28.672 bytes

     Map van C:\windows\winsxs\amd64_microsoft-windows-s..ty-spp-ux.resources_31bf38
    56ad364e35_6.1.7600.16385_nl-nl_0de6d4439e3b71d5

    19-02-2011  06:39            28.672 slui.exe.mui
                   1 bestand(en)           28.672 bytes

     Map van C:\windows\winsxs\amd64_microsoft-windows-security-spp-ux_31bf3856ad364
    e35_6.1.7600.16385_none_b7b69062b883381f

    14-07-2009  03:39           349.696 slui.exe
                   1 bestand(en)          349.696 bytes

     Map van C:\windows\winsxs\amd64_microsoft-windows-security-spp-ux_31bf3856ad364
    e35_6.1.7601.17514_none_b9e7a42ab571bbb9

    20-11-2010  15:25           349.696 slui.exe
                   1 bestand(en)          349.696 bytes

         Totaal aantal weergegeven bestanden:
                   6 bestand(en)        1.136.090 bytes
                   0 map(pen)  66.224.492.544 bytes beschikbaar

    C:\Users\Frank>ICACLS C:\windows\system32\slui.exe
    C:\windows\system32\slui.exe NT SERVICE\TrustedInstaller:(F)
                                 INGEBOUWD\Administrators:(RX)
                                 NT AUTHORITY\SYSTEM:(RX)
                                 INGEBOUWD\Gebruikers:(RX)

    1 bestanden zijn verwerkt; 0 bestanden zijn niet verwerkt

    C:\Users\Frank>

  • Monday, July 23, 2012 6:41 PM
     
     

    please attempt to delete the Prefetch file

    DEL C:\Windows\Prefetch\SLUI.EXE-724E99D9.pf

    It doesn't exist on my system, and the filesize appears to be wrong anyhow.

    (you may need to boot to Safe Mode to delete it properly)

    Reboot

    Then run another MGADiag report, and post the results.

    This is strange - I'm now dealing with two identical (almost) problems in two different languages - hopefully it'll lead to a quick isolation of the cause!. (but if I get confused or confusing, please shout!) - see here.... http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_install/win-7-validation/58213e5a-a001-4343-a635-3e05388253c4


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


  • Monday, July 23, 2012 6:57 PM
     
     

    Didn't get the pop up this reboot, but that's happened before and then it came back. At least the tempered file is gone now.

    Should I try to re-install the KB971033 update and validate it online? Or keep it like this and reply if it comes back?

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
    Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
    Windows Product ID: 00359-OEM-8992687-00007
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\npwatweb.dll[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watweb.dll[Hr = 0x80070003]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-4062122376-4072100849-687342899</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>N53SV</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>N53SV.214</Version><SMBIOSVersion major="2" minor="6"/><Date>20110810000000.000000+000</Date></BIOS><HWID>32483607018400FE</HWID><UserLCID>0413</UserLCID><SystemLCID>0413</SystemLCID><TimeZone>West-Europa (standaardtijd)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Versie van Software Licensing-service: 6.1.7601.17514

    Naam: Windows(R) 7, HomePremium edition
    Beschrijving: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activerings-id: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Toepassings-id55c92734-d682-4d71-983e-d6ec3f16059f
    Uitgebreide PID: 00359-00178-926-800007-02-1043-7601.0000-2042012
    Installatie-id103581693171297156972282569086101210664472043971214596
    URL van processorcertificaat: http://go.microsoft.com/fwlink/?LinkID=88338
    URL van computercertificaat: http://go.microsoft.com/fwlink/?LinkID=88339
    URL van gebruikte licentie: http://go.microsoft.com/fwlink/?LinkID=88341
    URL van productcodecertificaat: http://go.microsoft.com/fwlink/?LinkID=88340
    Gedeeltelijke productcode: 9YQTR
    Licentiestatus: licentie
    Resterend aantal nieuwe Windows-activeringen: 1
    Vertrouwde tijd: 23-7-2012 20:54:28

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 7:23:2012 19:32
    ActiveX: Not Registered - 0x80040154
    Admin Service: Not Registered - 0x80040154
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAonaMkncW0ikaOKwefPacvwQ/kgnm8gA+LnM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            _ASUS_        Notebook
      FACP            _ASUS_        Notebook
      DBGP            _ASUS_        Notebook
      HPET            _ASUS_        Notebook
      MCFG            _ASUS_        Notebook
      ECDT            _ASUS_        Notebook
      SLIC            _ASUS_        Notebook
      SSDT            PmRef        Cpu0Ist
      SSDT            PmRef        Cpu0Ist
      ASF!            INTEL          HCG

  • Monday, July 23, 2012 7:09 PM
     
     

    WOW _ that surprised me!

    I really was NOT expecting that to work.

    Yes, please reinstall teh KB971033 update - it does help diagnosis of any other problems.

    Once installed, please reboot, and  attempt validation at www.microsoft.com/genuine/validate, and post another MGADiag report

    In view of the surprise result, please do some thorough malware tests on the machine - this may be the result of an infection of some kind.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Monday, July 23, 2012 8:43 PM
     
     

    Installed the update, didn't get a popup screen but when validarting it puts me back at the screen where it tells me to buy Windows.I had to install some update from Microsoft when trying to validate through the browser, could it have something to do with that or is it just the KB971033 update?

    The tampered file is back now as well..

    I'll run a full system scan, should take an hour or two probably.

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0x8004FE22
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
    Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
    Windows Product ID: 00359-OEM-8992687-00007
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-4062122376-4072100849-687342899</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>N53SV</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>N53SV.214</Version><SMBIOSVersion major="2" minor="6"/><Date>20110810000000.000000+000</Date></BIOS><HWID>32483607018400FE</HWID><UserLCID>0413</UserLCID><SystemLCID>0413</SystemLCID><TimeZone>West-Europa (standaardtijd)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Versie van Software Licensing-service: 6.1.7601.17514

    Naam: Windows(R) 7, HomePremium edition
    Beschrijving: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activerings-id: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Toepassings-id55c92734-d682-4d71-983e-d6ec3f16059f
    Uitgebreide PID: 00359-00178-926-800007-02-1043-7601.0000-2042012
    Installatie-id103581693171297156972282569086101210664472043971214596
    URL van processorcertificaat: http://go.microsoft.com/fwlink/?LinkID=88338
    URL van computercertificaat: http://go.microsoft.com/fwlink/?LinkID=88339
    URL van gebruikte licentie: http://go.microsoft.com/fwlink/?LinkID=88341
    URL van productcodecertificaat: http://go.microsoft.com/fwlink/?LinkID=88340
    Gedeeltelijke productcode: 9YQTR
    Licentiestatus: licentie
    Resterend aantal nieuwe Windows-activeringen: 1
    Vertrouwde tijd: 23-7-2012 22:39:47

    Windows Activation Technologies-->
    HrOffline: 0x8004FE22
    HrOnline: N/A
    HealthStatus: 0x0000000000000800
    Event Time Stamp: 7:23:2012 22:39
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:
    Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration


    HWID Data-->
    HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAonaMkncW0ikaOKwefPacvwQ/kgnm8gA+LnM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            _ASUS_        Notebook
      FACP            _ASUS_        Notebook
      DBGP            _ASUS_        Notebook
      HPET            _ASUS_        Notebook
      MCFG            _ASUS_        Notebook
      ECDT            _ASUS_        Notebook
      SLIC            _ASUS_        Notebook
      SSDT            PmRef        Cpu0Ist
      SSDT            PmRef        Cpu0Ist
      ASF!            INTEL          HCG

  • Tuesday, July 24, 2012 1:00 AM
     
     

    Well it did not find any malware (well, it said Steam was malware...weird Avast scanner!). But I haven't gotten the popup either now. So should I leave it like this or should I again delete that file you mentioned?

    Edit: It just gave me a pop up again... kind of depressing. Any ideas? Delete update & file?

    • Edited by FrankvH91 Tuesday, July 24, 2012 2:59 AM
    •  
  • Tuesday, July 24, 2012 6:58 AM
     
     

    Some Steam 'games' most definitely ARE malware!

    They regularly cause problems, and I would recommend uninstalling any flagged as such - at least for the duration.

    I would also suggest a scan with MalwareBytes Anti-Malware...

    Please download and install Malwarebytes Anti-malware (free version) www.malwarebytes.org and update it, and run a full scan (DO NOT enable the Real-Time protection option!) in your main account, and Quick scans in any other user accounts.

    Delete everything it finds   


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Tuesday, July 24, 2012 5:43 PM
     
     
    The Malwarebytes scan didn't find anything malicious after a full scan
  • Thursday, July 26, 2012 9:56 AM
    Moderator
     
      Has Code

    Hi,


    Based on my research, please try the following:


    1. Test the issue again in Clean Boot Mode.


    2. Re-Activate Windows 7 (Rename tokens.dat)

    =================================

    1) Close all the open windows.

    2) Click "Start", click "All programs", and click "Accessories".

    3) Right-click "Command Prompt", and click "Run as administrator".

    4) In "Administrator: Command Prompt" window, type the following command lines and press Enter after each of them.

     

    net stop sppsvc 
    
    cd %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform
    
    ren tokens.dat tokens.bar
    
    cd %windir%\system32
    
    net start sppsvc
    
    cscript slmgr.vbs -rilc (It may take a long time for this to complete, please be patient)

    5) Reboot twice.

    6) You may be required to reactivate the system. Please use the following steps to activate the system by phone.

     

    a. Click "Start" , type "slui 4" in the search bar and press "Enter".

    b. You will receive a dialogue box and a number to call once you have selected your country.

    c. After that, please restart the computer and test the issue again.


    If issue persists, it is recommended to contact Windows Genuine Advantage technical support to check your product key and for further troubleshooting.


    Hope this helps.


    Jeremy Wu

    TechNet Community Support

  • Thursday, July 26, 2012 10:30 AM
     
      Has Code

    I may have found an answer....

    please run the following commands in an elevated Command Prompt window, and paste the results

    REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}/S
    REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}/S


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Thursday, July 26, 2012 10:31 AM
     
     

    Jeremy

    That cannot work, due to the Tamper/COM Registration problem.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Thursday, July 26, 2012 5:01 PM
     
      Has Code

    I may have found an answer....

    please run the following commands in an elevated Command Prompt window, and paste the results

    REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}/S
    REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}/S


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth


    It tells me it cannot find the registry keys. I deleted the .pf file, but still have the KB971033 update.
  • Thursday, July 26, 2012 5:45 PM
     
     Answered

    'Good' :)

    let's try this....

    Copy the text enclosed in +++++ to Notepad, and save as regwowfix.reg

    ++++++++++++++++++++++++++++++++++++++++++++++++++++
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}\1.0]
    @="SPPUI 1.0 Type Library"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}\1.0\0]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}\1.0\0\win32]
    @=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\

    00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,6c,00,\
      75,00,69,00,2e,00,65,00,78,00,65,00,00,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EE574957-4077-4AD6-8658-327C2C86C5AA}\1.0\FLAGS]
    @="0"

    +++++++++++++++++++++++++++++++++++++++++++++++++++++++++

    Once saved close all applications, tehn right-click on the file and select Merge

    You'll get at leasst one warning - accept it/them.

    You should then get a 'Success' message.

    accept that, and reboot.

    run another MGADiag report.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

    • Marked As Answer by FrankvH91 Friday, July 27, 2012 5:55 PM
    •  
  • Thursday, July 26, 2012 5:55 PM
     
     

    I'm double-checking but this sounds awfully familiar to the problem when installing OEM software on an upgraded system.

    Did you receive Win 7 from a Dell or other prebuilt system and then upgrade it?

    Or (just in case) have you installed any cracked/pirated software?  Won't ask you to go into details but this can sometimes cause problems as well.
    • Edited by garwynn Thursday, July 26, 2012 6:13 PM
    •  
  • Thursday, July 26, 2012 5:58 PM
     
     
    I get an error message after trying to merge, where it tells me it cannot import the file because it's not a registerscript.
  • Thursday, July 26, 2012 6:01 PM
     
     

    I'm double-checking but this sounds awfully familiar to the problem when installing OEM software on an upgraded system.

    Did you receive Win 7 from a Dell or other prebuilt system and then upgrade it?


    It's a pre-installed Win7 Home Premium that already was on my laptop when I bought it, and I haven't upgraded it.
  • Thursday, July 26, 2012 6:15 PM
     
     
    That sounds as if you may have also copied teh ++++++ lines - remove them, and try again.

    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Thursday, July 26, 2012 6:18 PM
     
     

    Sorry about that, thought you meant including the +++ lines.

    Got a success message now. Going to reboot and will post the report after.

  • Thursday, July 26, 2012 6:28 PM
     
     

    No tampered file! So I guess this fixed it?The pop-up doesn't appear every single time I boot my pc, but http://www.microsoft.com/genuine/validate/ didn't redirect me to the screen where it tells me to buy windows, so it seems valid now!

    It seems a bit like black magic to me, could you tell me what the problem was?

    Thank you so much!

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
    Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
    Windows Product ID: 00359-OEM-8992687-00007
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.120503-2030
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{14A28CF0-4668-4E5A-B6C9-8A6E042B78A9}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-4062122376-4072100849-687342899</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>N53SV</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>N53SV.214</Version><SMBIOSVersion major="2" minor="6"/><Date>20110810000000.000000+000</Date></BIOS><HWID>32483607018400FE</HWID><UserLCID>0413</UserLCID><SystemLCID>0413</SystemLCID><TimeZone>West-Europa (standaardtijd)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>  

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Versie van Software Licensing-service: 6.1.7601.17514

    Naam: Windows(R) 7, HomePremium edition
    Beschrijving: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activerings-id: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Toepassings-id55c92734-d682-4d71-983e-d6ec3f16059f
    Uitgebreide PID: 00359-00178-926-800007-02-1043-7601.0000-2042012
    Installatie-id103581693171297156972282569086101210664472043971214596
    URL van processorcertificaat: http://go.microsoft.com/fwlink/?LinkID=88338
    URL van computercertificaat: http://go.microsoft.com/fwlink/?LinkID=88339
    URL van gebruikte licentie: http://go.microsoft.com/fwlink/?LinkID=88341
    URL van productcodecertificaat: http://go.microsoft.com/fwlink/?LinkID=88340
    Gedeeltelijke productcode: 9YQTR
    Licentiestatus: licentie
    Resterend aantal nieuwe Windows-activeringen: 1
    Vertrouwde tijd: 26-7-2012 20:24:04

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 7:25:2012 05:13
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: MgAAAAIAAQABAAIAAAABAAAAAwABAAEAonaMkncW0ikaOKwefPacvwQ/kgnm8gA+LnM=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
      ACPI Table Name    OEMID Value    OEMTableID Value
      APIC            _ASUS_        Notebook
      FACP            _ASUS_        Notebook
      DBGP            _ASUS_        Notebook
      HPET            _ASUS_        Notebook
      MCFG            _ASUS_        Notebook
      ECDT            _ASUS_        Notebook
      SLIC            _ASUS_        Notebook
      SSDT            PmRef        Cpu0Ist
      SSDT            PmRef        Cpu0Ist
      ASF!            INTEL          HCG

  • Thursday, July 26, 2012 6:34 PM
     
     

    So far, so good - that looks OK!

    Please play with it for a while, and let us know teh results.#


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Thursday, July 26, 2012 6:47 PM
     
     

    ...sorry, I'm having browser problems at the moment, and can't see some of the stuff that comes up, so I missed your 'what caused it' question.

    The classic answer would be' You've been using a registry cleaner'!

    have you??


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Thursday, July 26, 2012 8:19 PM
     
     

    Yeah, I've had to mess in my registry to get the installer for Visual Studio 2010 Ultimate to work, so I guess that might've caused it then.

    Thank you!

  • Thursday, July 26, 2012 8:40 PM
     
     

    If you've used a 'commercial' registry cleaner, rather than the MkI eyeball, expect other problems as well!

    There is no such thing as a 'good' registry cleaner - except a lot of knowledge of the system being 'cleaned', and a decent knowledge of the registry.

    Some entries may be redundant - but that is so by design, so that later additions can work properly (particularly the case in Office installs) - NOTHING ever 'needs to be deleted' fro teh registry except known bad entries.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Friday, July 27, 2012 5:55 PM
     
     
    Well haven't gotten the popup in the past day, and Iused to get it 2-3 a day, so it seems like it's solved. Thanks!
  • Friday, July 27, 2012 6:11 PM
     
     

    Good to know!

    Any relapses, let us know - but with luck you should be OK.


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth

  • Tuesday, November 27, 2012 8:31 PM
     
     Proposed Answer

    If you've used a 'commercial' registry cleaner, rather than the MkI eyeball, expect other problems as well!

    There is no such thing as a 'good' registry cleaner - except a lot of knowledge of the system being 'cleaned', and a decent knowledge of the registry.

    Some entries may be redundant - but that is so by design, so that later additions can work properly (particularly the case in Office installs) - NOTHING ever 'needs to be deleted' fro teh registry except known bad entries.


     I had the same problem as Frank, and it was also due to my use of a commercial registry cleaner.

    Found a fast and easy way to fix the problem by, reapplying the saved registery backups that was made every time i cleaned the registry.

    So now my window is working fine and no longer says that it is not a genuine windows. But I would not have found out what was wrong if I had not read this thread, so thanks very much :)

    • Proposed As Answer by KKroghp Tuesday, November 27, 2012 8:34 PM
    •  
  • Tuesday, November 27, 2012 10:36 PM
     
     

    You're welcome - glad it did someone some good :)

    Good luck


    Noel Paton | Nil Carborundum Illegitemi | CrashFixPC | The Three-toed Sloth