This is almost brand new work computer. It is about 3 months old.
The PC ran perfectly fine for about 1-2 months. About 3 weeks ago we started receiving the genuine activation screen.
Our IT has attempted to validate it online (several times) and it takes the validation fine and confirms it is validated. Within a day or so it starts to throw up the genuine advantage screen again.
Below is the MGA report. Any assistance would be awesome. I am extremely limited on what I can install on this PC for trying to resolve this.
The original OS on this was Windows 8. IBM or the shipper installs our image (Windows7) onto the PC before shipping to us.
Thanks,
David
I also found this in the CBS log.
The PC ran perfectly fine for about 1-2 months. About 3 weeks ago we started receiving the genuine activation screen.
Our IT has attempted to validate it online (several times) and it takes the validation fine and confirms it is validated. Within a day or so it starts to throw up the genuine advantage screen again.
Below is the MGA report. Any assistance would be awesome. I am extremely limited on what I can install on this PC for trying to resolve this.
The original OS on this was Windows 8. IBM or the shipper installs our image (Windows7) onto the PC before shipping to us.
Thanks,
David
I also found this in the CBS log.
Code:
2013-10-17 12:24:24, Info CSI 00000032 [SR] Verify complete
2013-10-17 12:24:24, Info CSI 00000033 [SR] Repairing 1 components
2013-10-17 12:24:24, Info CSI 00000034 [SR] Beginning Verify and Repair transaction
2013-10-17 12:24:24, Info CSI 00000035 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe do not match actual file [l:16{8}]"slui.exe" :
Found: {l:32 b:KbG6TMN0neM3ruj/BBo1+ZFDV/wkGWknSYBX+12/4vw=} Expected: {l:32 b:y2+q+f+8kaTzBqldRHLuI3FckbBs5ZOU1qXCOk9LlHY=}
2013-10-17 12:24:24, Info CSI 00000036 [SR] Cannot repair member file [l:16{8}]"slui.exe" of Microsoft-Windows-Security-SPP-UX, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-10-17 12:24:24, Info CSI 00000037 Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe do not match actual file [l:16{8}]"slui.exe" :
Found: {l:32 b:KbG6TMN0neM3ruj/BBo1+ZFDV/wkGWknSYBX+12/4vw=} Expected: {l:32 b:y2+q+f+8kaTzBqldRHLuI3FckbBs5ZOU1qXCOk9LlHY=}
2013-10-17 12:24:24, Info CSI 00000038 [SR] Cannot repair member file [l:16{8}]"slui.exe" of Microsoft-Windows-Security-SPP-UX, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2013-10-17 12:24:24, Info CSI 00000039 [SR] This component was referenced by [l:198{99}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.WindowsFoundationDelivery"
2013-10-17 12:24:25, Info CSI 0000003a Hashes for file member \??\C:\Windows\System32\slui.exe do not match actual file [l:16{8}]"slui.exe" :
Found: {l:32 b:KbG6TMN0neM3ruj/BBo1+ZFDV/wkGWknSYBX+12/4vw=} Expected: {l:32 b:y2+q+f+8kaTzBqldRHLuI3FckbBs5ZOU1qXCOk9LlHY=}
2013-10-17 12:24:25, Info CSI 0000003b Hashes for file member \SystemRoot\WinSxS\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe do not match actual file [l:16{8}]"slui.exe" :
Found: {l:32 b:KbG6TMN0neM3ruj/BBo1+ZFDV/wkGWknSYBX+12/4vw=} Expected: {l:32 b:y2+q+f+8kaTzBqldRHLuI3FckbBs5ZOU1qXCOk9LlHY=}
2013-10-17 12:24:25, Info CSI 0000003c [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:16{8}]"slui.exe"; source file in store is also corrupted
2013-10-17 12:24:25, Info CSI 0000003d Repair results created:
POQ 3 starts:
Code:
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0x8004FE22
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-*****-*****-H33D2
Windows Product Key Hash: Tq24kYqwT+RhkWSsC/r/tNLr2+Q=
Windows Product ID: 55041-011-1418304-86946
Windows Product ID Type: 6
Windows License Type: Volume MAK
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {7BE08F9C-6508-4390-8908-9BB98E925787}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.9.42.0
Signed By: Microsoft
Product Name: Windows 7 Professional
Architecture: 0x00000000
Build lab: 7601.win7sp1_gdr.130828-1532
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional Edition 2003 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
File Mismatch: C:\Windows\system32\slui.exe[6.1.7601.17514], Hr = 0x800b0100
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{7BE08F9C-6508-4390-8908-9BB98E925787}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>55041-011-1418304-86946</PID><PIDType>6</PIDType><SID>S-1-5-21-3038940248-1809484214-3910411663</SID><SYSTEM><Manufacturer>LENOVO</Manufacturer><Model>5100C2U</Model></SYSTEM><BIOS><Manufacturer>LENOVO</Manufacturer><Version>9ZKT36AUS</Version><SMBIOSVersion major="2" minor="7"/><Date>20130226000000.000000+000</Date></BIOS><HWID>C9A23F07018400F2</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>LENOVO</OEMID><OEMTableID>TC-9Z </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>8E25C6D3C374502</Val><Hash>rwXx3PUlaihtED/ay+7VFRE5MiA=</Hash><Pid>73931-641-5849754-57631</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Professional edition
Description: Windows Operating System - Windows(R) 7, VOLUME_MAK channel
Activation ID: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 55041-00172-011-141830-03-1033-7601.0000-2772013
Installation ID: 012420877990416064854012095692622432543152539353168482
Processor Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88338[/URL]
Machine Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88339[/URL]
Use License URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88341[/URL]
Product Key Certificate URL: [URL]http://go.microsoft.com/fwlink/?LinkID=88340[/URL]
Partial Product Key: H33D2
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 10/17/2013 12:26:12 PM
Windows Activation Technologies-->
HrOffline: 0x8004FE22
HrOnline: N/A
HealthStatus: 0x0000000000000800
Event Time Stamp: 10:17:2013 12:24
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
HWID Data-->
HWID Hash Current: LgAAAAEAAQABAAIAAAACAAAAAQABAAEAeqh4a3pnCLJE6xxDznCKmzzaejKGWw==
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC LENOVO TC-9Z
FACP LENOVO TC-9Z
HPET LENOVO TC-9Z
MCFG LENOVO TC-9Z
FPDT LENOVO TC-9Z
TCPA LENOVO TC-9Z
SLIC LENOVO TC-9Z
MSDM LENOVO TC-9Z
BGRT LENOVO TC-9Z
SSDT LENOVO TC-9Z
SSDT LENOVO TC-9Z
IVRS LENOVO TC-9Z
CRAT LENOVO TC-9Z
Last edited:
My Computer
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- IBM
- OS
- Windows 7 Professional 32bit
- CPU
- AMD A6
- Motherboard
- LENOVO Annapurna CRB
- Memory
- 4096MB
- Graphics Card(s)
- AMD RADEON 7540D
- Hard Drives
- WD 5000 (500.11GB)
- Antivirus
- TrendMicro
- Browser
- IE 9
since the output from the command I gave you is perfectly normal for a 32-bit machine, which means that we're going to have to dig a bit deeper for a cause/solution.