Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Windows XP
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Windows XP >
Legitimage Copy of Windows

Reply  
Thread Tools
draya's Avatar
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Beginner
20-Nov-2009, 06:28 PM #1
Exclamation Legitimage Copy of Windows
Recently I put a question up about lag and was told this by Phantom010: "Well, perhaps if you had a legitimate copy of Windows XP, you wouldn't be having this problem..." and This log entry says it all. O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll Antiwpa.dll is a prohibited software crack which is used to avoid the Windows’ copy protection. This file to start automatically makes use of the Winlogon Notify key. I DO own a legitimate copy of windows. I bought and still have everything and have even had my copy validated like everyone else in order to get updates from Microsoft. I have owned it for years! Had it validated multiple times, never ever had a problem. I am beyond freaked out by this! Is this a virus? It's old and only came with Service pack 1, which means I have had to download 2, and now 3, from Microsoft every time I have reformatted my comp over the years. I don't have a clue how to crack anything or where I would even get it from. Help??

I just ran, for my own piece of mind, the MGAdiag tool and I do have a genuine copy. I can and will post the transcript if I needed.

Last edited by draya; 20-Nov-2009 at 06:47 PM.. Reason: proof for self
techkid's Avatar
Computer Specs
Senior Member with 2,288 posts.
 
Join Date: Sep 2004
Location: Sydney, Australia
Experience: Fix it until it's broken
20-Nov-2009, 07:31 PM #2
You would probably be best to provide the proof at this point.

Doing a search shows that the file, while being a Windows crack, is also classified as part of a rootkit. If you can provide that transcript, it might cast a different light on your situation.
draya's Avatar
Computer Specs
Junior Member with 4 posts.
 
Join Date: Nov 2009
Experience: Beginner
20-Nov-2009, 07:44 PM #3
Diagnostic Report (1.9.0011.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0

Cached Validation Code: N/A
Windows Product Key: *****-*****-MJVXG-2YR27-MKG9J
Windows Product Key Hash: MtxulD+GwD5ePqPzpNixPWLZ5xE=
Windows Product ID: 76487-OEM-2242693-51319
Windows Product ID Type: 3
Windows License Type: OEM System Builder
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {E66EF059-0689-493C-8D14-8FDA03067D0E}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.9.40.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A
Version: N/A

WGA Notifications Data-->
Cached Result: 0
File Exists: Yes
Version: 1.9.40.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional Edition 2003 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E66EF059-0689-493C-8D14-8FDA03067D0E}</UGUID><Version>1.9.0011.0</Version><OS>5.1.2600.2.00010100.3.0.pro</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-MKG9J</PKey><PID>76487-OEM-2242693-51319</PID><PIDType>3</PIDType><SID>S-1-5-21-1957994488-1004336348-839522115</SID><SYSTEM><Manufacturer>System manufacturer</Manufacturer><Model>System Product Name</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>0212 </Version><SMBIOSVersion major="2" minor="5"/><Date>20090116000000.000000+000</Date></BIOS><HWID>3C9E33FF01848078</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification><File Name="WgaTray.exe" Version="1.9.40.0"/><File Name="WgaLogon.dll" Version="1.9.40.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>B4731799DF39D00</Val><Hash>TE2IkmLeZINNu18+rAJgSV4jzMk=</Hash><Pid>73931-640-1790864-57900</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>

Licensing Data-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 13D60:ASUSTeK Computer Inc
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

OEM Activation 2.0 Data-->
N/A
Lance1's Avatar
Computer Specs
Senior Member with 3,975 posts.
 
Join Date: Aug 2003
Location: Vernon BC, Canada
Experience: Computers & I get along.
20-Nov-2009, 11:31 PM #4
Of course, the crack fools the WGA test just as it does when accessing the Windows update validation. That diagnostic means nothing.
flavallee's Avatar
Computer Specs
Trusted Advisor with 40,857 posts.
 
Join Date: May 2002
Location: Brandon/Valrico, Florida
Experience: Advanced
21-Nov-2009, 12:02 AM #5
techkid/Lance1:

This is the previous thread that draya is referring to:

http://forums.techguy.org/windows-xp...g-startup.html

----------------------------------------------------------------
JSntgRvr's Avatar
Moderator & Malware Removal Specialist with 16,281 posts.
 
Join Date: Jul 2003
Location: Puerto Rico
Experience: Advanced
21-Nov-2009, 12:03 AM #6
Hi, draya

I am very sorry but all indicates your copy of Windows is not legitimate.

While I understand that you may not have been aware of it, I am unable to help you any further on this site. We have a strict policy and adhere to in only helping people who have legitmate copies of Windows. If you feel your copy is legitimate, you will need to contact Microsoft for assistance. Until your system appears legitimate, there is nothing I can do for you at this time.

Thank you for understanding.
__________________
Unanswered threads for 5 days will no longer be part of my subscriptions.
Reply

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:02 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.