Windows 7 build 7601 This copy of windows is not genuine.

Anonymous
2012-11-27T02:34:43+00:00

Watermark on desktop: "Windows 7 build 7601 This copy of windows is not genuine." I have had Windows 7 running for 15 mo.; bought from HP. It is genuine. Tried to activate and ran slui.exe - no success. Ran MGADIAG with results as follows:

Diagnostic Report (1.9.0027.0):


Windows Validation Data-->

Validation Code: 0x8004FE21

Cached Online Validation Code: N/A, hr = 0xc0000022

Windows Product Key: *****-*****-788W3-H689G-6P6GT

Windows Product Key Hash: yr8OHoeXhbT4dc6MxGYjdAStSPY=

Windows Product ID: 00371-OEM-8992671-00008

Windows Product ID Type: 2

Windows License Type: OEM SLP

Windows OS version: 6.1.7601.2.00010100.1.0.048

ID: {998A7F9F-2A4B-44ED-BA11-EC66B03D29E2}(3)

Is Admin: Yes

TestCab: 0x0

LegitcheckControl ActiveX: N/A, hr = 0x80070002

Signed By: N/A, hr = 0x80070002

Product Name: Windows 7 Professional

Architecture: 0x00000009

Build lab: 7601.win7sp1_gdr.120830-0333

TTS Error:

Validation Diagnostic:

Resolution Status: N/A

Vista WgaER Data-->

ThreatID(s): N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->

Cached Result: N/A, hr = 0x80070002

File Exists: No

Version: N/A, hr = 0x80070002

WgaTray.exe Signed By: N/A, hr = 0x80070002

WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

OGAExec.exe Signed By: N/A, hr = 0x80070002

OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->

Office Status: 109 N/A

OGA Version: N/A, 0x80070002

Signed By: N/A, hr = 0x80070002

Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->

Proxy settings: N/A

User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)

Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Download signed ActiveX controls: Prompt

Download unsigned ActiveX controls: Disabled

Run ActiveX controls and plug-ins: Allowed

Initialize and script ActiveX controls not marked as safe: Disabled

Allow scripting of Internet Explorer Webbrowser control: Disabled

Active scripting: Allowed

Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->

Office Details: <GenuineResults><MachineData><UGUID>{998A7F9F-2A4B-44ED-BA11-EC66B03D29E2}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-6P6GT</PKey><PID>00371-OEM-8992671-00008</PID><PIDType>2</PIDType><SID>S-1-5-21-2978311456-595975254-546380561</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>p7-1080t</Model></SYSTEM><BIOS><Manufacturer>AMI</Manufacturer><Version>7.13</Version><SMBIOSVersion major="2" minor="6"/><Date>20110722000000.000000+000</Date></BIOS><HWID>5D4A3607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-CPC</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> 

Spsys.log Content: 0x80070002

Licensing Data-->

On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.

Error: 0x80070426

Windows Activation Technologies-->

HrOffline: 0x8004FE21

HrOnline: N/A

HealthStatus: 0x0001000000000000

Event Time Stamp: 11:24:2012 08:59

ActiveX: Registered, Version: 7.1.7600.16395

Admin Service: Registered, Version: 7.1.7600.16395

HealthStatus Bitmask Output:

Tampered Service: sppsvc

HWID Data-->

HWID Hash Current: LAAAAAEAAQABAAEAAAACAAAAAQABAAEAonagc8aHJOn6mtb2Yj1YpRQZLnM=

OEM Activation 1.0 Data-->

N/A

OEM Activation 2.0 Data-->

BIOS valid for OA 2.0: yes

Windows marker version: 0x20001

OEMID and OEMTableID Consistent: yes

BIOS Information:

  ACPI Table Name    OEMID Value    OEMTableID Value

  APIC            HPQOEM        SLIC-CPC

  FACP            HPQOEM        SLIC-CPC

  DBGP            HPQOEM        SLIC-CPC

  HPET            HPQOEM        SLIC-CPC

  MCFG            HPQOEM        SLIC-CPC

  SSDT            HPQOEM        SLIC-CPC

  SLIC            HPQOEM        SLIC-CPC

Any suggestions on above? Thanks.

Windows for home | Previous Windows versions | Licensing and activation

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

43 answers

Sort by: Oldest
  1. Anonymous
    2012-12-03T13:07:42+00:00

    OK, I ran the Farber scanner. I think the first time I followed the link, the Reimage ad was at the top of the Farber page and I did not notice that it was an ad separate from the Farber scanner.

     Farbar Service Scanner Version: 01-12-2012 02

    Ran by Millonig Family 2011 (administrator) on 03-12-2012 at 08:01:44

    Running from "C:\Download"

    Windows 7 Professional Service Pack 1 (X64)

    Boot Mode: Normal

    ****************************************************************

    Internet Services:

    ============

    Connection Status:

    ==============

    Localhost is accessible.

    LAN connected.

    Google IP is accessible.

    Google.com is accessible.

    Yahoo IP is accessible.

    Yahoo.com is accessible.

    Windows Firewall:

    =============

    Firewall Disabled Policy:

    ==================

    System Restore:

    ============

    System Restore Disabled Policy:

    ========================

    Action Center:

    ============

    Windows Update:

    ============

    Windows Autoupdate Disabled Policy:

    ============================

    Windows Defender:

    ==============

    WinDefend Service is not running. Checking service configuration:

    The start type of WinDefend service is set to Demand. The default start type is Auto.

    The ImagePath of WinDefend service is OK.

    The ServiceDll of WinDefend service is OK.

    Other Services:

    ==============

    File Check:

    ========

    C:\Windows\System32\nsisvc.dll => MD5 is legit

    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit

    C:\Windows\System32\dhcpcore.dll => MD5 is legit

    C:\Windows\System32\drivers\afd.sys => MD5 is legit

    C:\Windows\System32\drivers\tdx.sys => MD5 is legit

    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit

    C:\Windows\System32\dnsrslvr.dll => MD5 is legit

    C:\Windows\System32\mpssvc.dll => MD5 is legit

    C:\Windows\System32\bfe.dll => MD5 is legit

    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit

    C:\Windows\System32\SDRSVC.dll => MD5 is legit

    C:\Windows\System32\vssvc.exe => MD5 is legit

    C:\Windows\System32\wscsvc.dll => MD5 is legit

    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit

    C:\Windows\System32\wuaueng.dll => MD5 is legit

    C:\Windows\System32\qmgr.dll => MD5 is legit

    C:\Windows\System32\es.dll => MD5 is legit

    C:\Windows\System32\cryptsvc.dll => MD5 is legit

    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

    C:\Windows\System32\ipnathlp.dll => MD5 is legit

    C:\Windows\System32\iphlpsvc.dll => MD5 is legit

    C:\Windows\System32\svchost.exe => MD5 is legit

    C:\Windows\System32\rpcss.dll => MD5 is legit

    **** End of log ****

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2012-12-03T14:02:08+00:00

    It didn't find anything significant :(

    OK - let's try a few more relevant services.....

    NET START SPPUINOTIFY

    SC QUERYEX SPPUINOTIFY

    NET START SPLDR

    SC QUERYEX SPLDR

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2012-12-03T22:30:21+00:00

    RESULTS:’

    Microsoft Windows [Version 6.1.7601]

    Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

    C:\Windows\system32>NET START SPPUINOTIFY

    The SPP Notification Service service is starting.

    The SPP Notification Service service was started successfully.

    C:\Windows\system32>SC QUERYEX SPPUINOTIFY

    SERVICE_NAME: SPPUINOTIFY

    TYPE               : 20  WIN32_SHARE_PROCESS

    STATE              : 4  RUNNING

    (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN)

    WIN32_EXIT_CODE    : 0  (0x0)

    SERVICE_EXIT_CODE  : 0  (0x0)

    CHECKPOINT         : 0x0

    WAIT_HINT          : 0x0

    PID                : 1060

    FLAGS              :

    C:\Windows\system32>NET START SPLDR

    The requested service has already been started.

    More help is available by typing NET HELPMSG 2182.

    C:\Windows\system32>SC QUERYEX SPLDR

    SERVICE_NAME: SPLDR

    TYPE               : 1  KERNEL_DRIVER

    STATE              : 4  RUNNING

    (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)

    WIN32_EXIT_CODE    : 0  (0x0)

    SERVICE_EXIT_CODE  : 0  (0x0)

    CHECKPOINT         : 0x0

    WAIT_HINT          : 0x0

    PID                : 0

     FLAGS              :

    C:\Windows\system32>

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2012-12-03T23:05:57+00:00

    Please run a full CHKDSK and SFC scan....

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    CHKDSK C: /R

    and hit the Enter key.

    You will be told that the drive is locked,

    and the CHKDSK will run at he next boot - hit the Y key, and then reboot.

    The CHKDSK will take a few hours depending on the size of the drive, so be patient!

    After the CHKDSK has run, Windows should boot normally (possibly after a second auto-reboot) -

    then run the SFC.

    SFC -System File Checker - Instructions

    Click on Start > All Programs > Accessories

    Right-click on the Command Prompt entry

    Select Run as Administrator and accept the UAC prompt - the Elevated Command Prompt window should pop up.

    At the Command prompt, type

    SFC /SCANNOW

    and hit the Enter key

    Wait for the scan to finish - make a note of any error messages - and then reboot.

    Copy the CBS.log file created (C:\Windows\Logs\CBS\CBS.log) to your desktop (you can't manipulate it directly) and then compress the copy and upload it to your SkyDrive (http://skydrive.live.com ) and post a link to it so that I can take a look.

    Post a new MGADiag report with details of any error messages encountered.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2012-12-05T02:49:25+00:00

    Can you give me some idea of what we are doing with this troubleshooting? We keep running test after test but I do not understand what they mean and we are not getting any closer to resolution.

    I ran the tests below. Presently, the watermark is gone but it will probably reappear. Seems like this could be a virus or malware but I have run Symantec several times. I did try to Check for Windows Updates. Result was “Windows could not search for new updates. Error Code C0000022. Windows encountered an unknown error.” I clicked help for this error but there were no results for it. I have done this before. It seems odd and significant that the problem goes away and then comes back.

    Ran CHKDSK; did not see any errors but I was not there at the end upon reboot.

    Ran SFCScan. “Windows Resource Protection did not find any integrity violations.”

    I do not have a Skydrive account. Can’t I just email the file to your or do something else?

    Diagnostic Report (1.9.0027.0):


    Windows Validation Data-->

    Validation Code: 0x8004FE21

    Cached Online Validation Code: N/A, hr = 0xc0000022

    Windows Product Key: *****-*****-788W3-H689G-6P6GT

    Windows Product Key Hash: yr8OHoeXhbT4dc6MxGYjdAStSPY=

    Windows Product ID: 00371-OEM-8992671-00008

    Windows Product ID Type: 2

    Windows License Type: OEM SLP

    Windows OS version: 6.1.7601.2.00010100.1.0.048

    ID: {998A7F9F-2A4B-44ED-BA11-EC66B03D29E2}(3)

    Is Admin: Yes

    TestCab: 0x0

    LegitcheckControl ActiveX: N/A, hr = 0x80070002

    Signed By: N/A, hr = 0x80070002

    Product Name: Windows 7 Professional

    Architecture: 0x00000009

    Build lab: 7601.win7sp1_gdr.120503-2030

    TTS Error:

    Validation Diagnostic:

    Resolution Status: N/A

    Vista WgaER Data-->

    ThreatID(s): N/A, hr = 0x80070002

    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->

    Cached Result: N/A, hr = 0x80070002

    File Exists: No

    Version: N/A, hr = 0x80070002

    WgaTray.exe Signed By: N/A, hr = 0x80070002

    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->

    Cached Result: N/A, hr = 0x80070002

    Version: N/A, hr = 0x80070002

    OGAExec.exe Signed By: N/A, hr = 0x80070002

    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->

    Office Status: 109 N/A

    OGA Version: N/A, 0x80070002

    Signed By: N/A, hr = 0x80070002

    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->

    Proxy settings: N/A

    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)

    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    Download signed ActiveX controls: Prompt

    Download unsigned ActiveX controls: Disabled

    Run ActiveX controls and plug-ins: Allowed

    Initialize and script ActiveX controls not marked as safe: Disabled

    Allow scripting of Internet Explorer Webbrowser control: Disabled

    Active scripting: Allowed

    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->

    Office Details: <GenuineResults><MachineData><UGUID>{998A7F9F-2A4B-44ED-BA11-EC66B03D29E2}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-6P6GT</PKey><PID>00371-OEM-8992671-00008</PID><PIDType>2</PIDType><SID>S-1-5-21-2978311456-595975254-546380561</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>p7-1080t</Model></SYSTEM><BIOS><Manufacturer>AMI</Manufacturer><Version>7.13</Version><SMBIOSVersion major="2" minor="6"/><Date>20110722000000.000000+000</Date></BIOS><HWID>5D4A3607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-CPC</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> 

    Spsys.log Content: 0x80070002

    Licensing Data-->

    On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x80070426' to display the error text.

    Error: 0x80070426

    Windows Activation Technologies-->

    HrOffline: 0x8004FE21

    HrOnline: N/A

    HealthStatus: 0x0001000000000000

    Event Time Stamp: 11:28:2012 03:48

    ActiveX: Registered, Version: 7.1.7600.16395

    Admin Service: Registered, Version: 7.1.7600.16395

    HealthStatus Bitmask Output:

    Tampered Service: sppsvc

    HWID Data-->

    HWID Hash Current: LAAAAAEAAQABAAEAAAACAAAAAQABAAEAonagc8aHJOn6mtb2Yj1YpRQZLnM=

    OEM Activation 1.0 Data-->

    N/A

    OEM Activation 2.0 Data-->

    BIOS valid for OA 2.0: yes

    Windows marker version: 0x20001

    OEMID and OEMTableID Consistent: yes

    BIOS Information:

    ACPI Table Name             OEMID Value       OEMTableID Value

    APIC                                     HPQOEM                              SLIC-CPC

    FACP                                   HPQOEM                              SLIC-CPC

    DBGP                                   HPQOEM                              SLIC-CPC

    HPET                                   HPQOEM                              SLIC-CPC

    MCFG                                  HPQOEM                              SLIC-CPC

    SSDT                                   HPQOEM                              SLIC-CPC

    SLIC                                     HPQOEM                              SLIC-CPC

    Was this answer helpful?

    0 comments No comments