beaners Posted July 3, 2009 Report Share Posted July 3, 2009 Hello!! I have been reading here for a couple months and have successfully removed (or thought that i had) a trojan a few months ago. But now I have a major problem. I have two computers on my home network The comp that is hooked up wireless will not install malawarebytes or let me run any of the removal tools except superantispyware and that says it has a problem updating, I have tried safe mode, I installed combofix and that wont run also, and now its freezing up to the point of being useless. And my comp that is hooked directly to the modem is getting bad also But it still lets me run malawarebytes + spybot s+d and avast the first 2 say not infected but avast comes up with alot of infections but wont let me delete them, also neither one will let me run root repeal. If I clean the MAIN comp will my SECOND (and much worse comp reinfect it?) which one do i try to fix first I have created a Hjack this log of the worst one, comp2 and will be waiting for further assistance. Thank You.....Logfile of Trend MicroLogfile of Trend Micro HijackThis v2.0.2Scan saved at 6:54:33 PM, on 7/2/2009Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\Explorer.EXEC:\windows\system\hpsysdrv.exeC:\WINDOWS\System32\hkcmd.exeC:\Program Files\Winamp\Winampa.exeC:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeC:\Program Files\Belkin\F5D7050v5\Belkinwcui.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\gearsec.exeC:\WINDOWS\system32\fxssvc.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\HiJack THIS\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eznsearch.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Marquette-Adams Telephone CooperativeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.102R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exeO4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exeO4 - HKLM\..\Run: [QAGENT] C:\QAGENT.EXEO4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exeO4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exeO4 - HKCU\..\Run: [vmmreg32] C:\WINDOWS\vmmreg32.exeO4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EASYIN~1\eznorun.exeO4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\196_150_ni.exeO4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeO4 - Global Startup: Belkin Wireless G USB Adapter Client Utility.lnk = ?O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dllO14 - IERESET.INF: START_PAGE_URL=http://www.eznsearch.comO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exeO16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://wdownload.weatherbug.com/minibug/tr...uginstaller.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dllO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exeO23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: kbdsf - Unknown owner - C:\WINDOWS\System32\kbdsf.exe (file missing)O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE--End of file - 7222 bytes Link to post Share on other sites
Rorschach112 Posted July 4, 2009 Report Share Posted July 4, 2009 hiPlease run the MGA Diagnostic Tool and post back the report it shall produce:Download MGADiag to your desktop.Double-click on MGADiag.exe to launch the programClick "Continue"Ensure that the "Windows" tab is selected (it should be by default).Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.Paste the MGA Diagnostic Report back here in your next reply. Link to post Share on other sites
beaners Posted July 4, 2009 Author Report Share Posted July 4, 2009 (edited) Hello!! Thank you for your quick response, Just to ad a few things this comp has been infected bad before and since then I have never been able to install any updates!! I originally had a hard time finding the report (never used clipboard viewer) but after a little search and reading I believe this is what you asked for.....Diagnostic Report (1.9.0006.1):-----------------------------------------WGA Data-->Validation Status: Validation Control not InstalledValidation Code: 0Online Validation Code: N/ACached Validation Code: N/AWindows Product Key: *****-*****-BRVBB-38MQ9-3PMFTWindows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA=Windows Product ID: 55277-OEM-2111907-00106Windows Product ID Type: 2Windows License Type: OEM SLPWindows OS version: 5.1.2600.2.00010300.0.0.homID: {9877488F-2E78-46A9-B29E-00216777659A}(3)Is Admin: YesTestCab: 0x0WGA Version: N/A, hr = 0x80070002Signed By: N/A, hr = 0x80070002Product Name: N/AArchitecture: N/ABuild lab: N/ATTS Error: N/AValidation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_78155E4D-232-80004005Resolution Status: N/AWgaER Data-->ThreatID(s): N/AVersion: N/AWGA Notifications Data-->Cached Result: N/A, hr = 0x80070002File Exists: NoVersion: N/A, hr = 0x80070002WgaTray.exe Signed By: N/A, hr = 0x80070002WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->Cached Result: N/A, hr = 0x80070002Version: N/A, hr = 0x80070002WGATray.exe Signed By: N/A, hr = 0x80070002OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->Office Status: 100 GenuineMicrosoft Office XP Professional with FrontPage - 100 GenuineOGA Version: N/A, 0x80070002Signed By: N/A, hr = 0x80070002Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005Browser Data-->Proxy settings: N/AUser Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)Default Browser: C:\Program Files\Mozilla Firefox\firefox.exeDownload signed ActiveX controls: PromptDownload unsigned ActiveX controls: DisabledRun ActiveX controls and plug-ins: AllowedInitialize and script ActiveX controls not marked as safe: DisabledAllow scripting of Internet Explorer Webbrowser control: Active scripting: Script ActiveX controls marked as safe for scripting: File Scan Data-->File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\licdll.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\ntoskrnl.exe[5.1.2600.31]File Mismatch: C:\WINDOWS\system32\ntdll.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\kernel32.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\crypt32.dll[5.131.2600.0]File Mismatch: C:\WINDOWS\system32\advapi32.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\setupapi.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\oembios.bin[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\oembios.dat[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\oembios.sig[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.0]Other data-->Office Details: <GenuineResults><MachineData><UGUID>{9877488F-2E78-46A9-B29E-00216777659A}</UGUID><Version>1.9.0006.1</Version><OS>5.1.2600.2.00010300.0.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-3PMFT</PKey><PID>55277-OEM-2111907-00106</PID><PIDType>2</PIDType><SID>S-1-5-21-4097411637-2163411867-2876842818</SID><SYSTEM><Manufacturer>HP Pavilion 04</Manufacturer><Model>P6304A-ABA XG922</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies LTD</Manufacturer><Version>3.02</Version><SMBIOSVersion major="2" minor="31"/><Date>20010824******.******+***</Date><SLPBIOS>HP PAVILION</SLPBIOS></BIOS><HWID>8E2731BF01846036</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Hewlett-Packard</name><model>Pavilion</model></SBID><OEM/><GANotification/></MachineData> <Software><Office><Result>100</Result><Products><Product GUID="{40280409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional with FrontPage</Name><Ver>10</Ver><Val>571B916CC4B4000</Val><Hash>k2jOTMTeoNV1RWDOaywky/SOcZM=</Hash><Pid>54185-640-0000007-17004</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="17" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults> Licensing Data-->N/AHWID Data-->N/AOEM Activation 1.0 Data-->BIOS string matches: yesMarker string from BIOS: 13576:Hewlett-Packard CompanyMarker string from OEMBIOS.DAT: HP PAVILIONOEM Activation 2.0 Data-->N/A Edited July 4, 2009 by beaners Link to post Share on other sites
Rorschach112 Posted July 4, 2009 Report Share Posted July 4, 2009 You need to validate windows before we can help Link to post Share on other sites
beaners Posted July 5, 2009 Author Report Share Posted July 5, 2009 Hello Again11 I am not very good with comps but i will do my best. Thanks againValidation Complete!Thank you for completing the validation process and for using genuine Microsoft software.By using genuine Microsoft software, you can be confident that you will have access to the latest features, security, and support, which will help to improve your productivity and expand the capabilities of your computer.You will also have access to new innovations and offerings available only to genuine Microsoft software customers Link to post Share on other sites
Rorschach112 Posted July 5, 2009 Report Share Posted July 5, 2009 hiPlease run the MGA Diagnostic Tool and post back the report it shall produce:Download MGADiag to your desktop.Double-click on MGADiag.exe to launch the programClick "Continue"Ensure that the "Windows" tab is selected (it should be by default).Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.Paste the MGA Diagnostic Report back here in your next reply. Link to post Share on other sites
beaners Posted July 5, 2009 Author Report Share Posted July 5, 2009 Here you go!!!!Diagnostic Report (1.9.0006.1):-----------------------------------------WGA Data-->Validation Status: Validation Control not InstalledValidation Code: 0Online Validation Code: N/ACached Validation Code: N/AWindows Product Key: *****-*****-BRVBB-38MQ9-3PMFTWindows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA=Windows Product ID: 55277-OEM-2111907-00106Windows Product ID Type: 2Windows License Type: OEM SLPWindows OS version: 5.1.2600.2.00010300.0.0.homID: {9877488F-2E78-46A9-B29E-00216777659A}(3)Is Admin: YesTestCab: 0x0WGA Version: N/A, hr = 0x80070002Signed By: N/A, hr = 0x80070002Product Name: N/AArchitecture: N/ABuild lab: N/ATTS Error: N/AValidation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_78155E4D-232-80004005Resolution Status: N/AWgaER Data-->ThreatID(s): N/AVersion: N/AWGA Notifications Data-->Cached Result: N/A, hr = 0x80070002File Exists: NoVersion: N/A, hr = 0x80070002WgaTray.exe Signed By: N/A, hr = 0x80070002WgaLogon.dll Signed By: N/A, hr = 0x80070002OGA Notifications Data-->Cached Result: N/A, hr = 0x80070002Version: N/A, hr = 0x80070002WGATray.exe Signed By: N/A, hr = 0x80070002OGAAddin.dll Signed By: N/A, hr = 0x80070002OGA Data-->Office Status: 100 GenuineMicrosoft Office XP Professional with FrontPage - 100 GenuineOGA Version: N/A, 0x80070002Signed By: N/A, hr = 0x80070002Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005Browser Data-->Proxy settings: N/AUser Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exeDownload signed ActiveX controls: PromptDownload unsigned ActiveX controls: DisabledRun ActiveX controls and plug-ins: AllowedInitialize and script ActiveX controls not marked as safe: DisabledAllow scripting of Internet Explorer Webbrowser control: DisabledActive scripting: AllowedScript ActiveX controls marked as safe for scripting: AllowedFile Scan Data-->File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\licdll.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\ntoskrnl.exe[5.1.2600.31]File Mismatch: C:\WINDOWS\system32\ntdll.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\kernel32.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\crypt32.dll[5.131.2600.0]File Mismatch: C:\WINDOWS\system32\advapi32.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\setupapi.dll[5.1.2600.0]File Mismatch: C:\WINDOWS\system32\oembios.bin[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\oembios.dat[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\oembios.sig[hr = 0x80070714]File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.0]Other data-->Office Details: <GenuineResults><MachineData><UGUID>{9877488F-2E78-46A9-B29E-00216777659A}</UGUID><Version>1.9.0006.1</Version><OS>5.1.2600.2.00010300.0.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-3PMFT</PKey><PID>55277-OEM-2111907-00106</PID><PIDType>2</PIDType><SID>S-1-5-21-4097411637-2163411867-2876842818</SID><SYSTEM><Manufacturer>HP Pavilion 04</Manufacturer><Model>P6304A-ABA XG922</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies LTD</Manufacturer><Version>3.02</Version><SMBIOSVersion major="2" minor="31"/><Date>20010824******.******+***</Date><SLPBIOS>HP PAVILION</SLPBIOS></BIOS><HWID>8E2731BF01846036</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Hewlett-Packard</name><model>Pavilion</model></SBID><OEM/><GANotification/></MachineData> <Software><Office><Result>100</Result><Products><Product GUID="{40280409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional with FrontPage</Name><Ver>10</Ver><Val>571B916CC4B4000</Val><Hash>k2jOTMTeoNV1RWDOaywky/SOcZM=</Hash><Pid>54185-640-0000007-17004</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="17" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults> Licensing Data-->N/AHWID Data-->N/AOEM Activation 1.0 Data-->BIOS string matches: yesMarker string from BIOS: 13576:Hewlett-Packard CompanyMarker string from OEMBIOS.DAT: HP PAVILIONOEM Activation 2.0 Data-->N/A Link to post Share on other sites
Rorschach112 Posted July 5, 2009 Report Share Posted July 5, 2009 You still haven't validated your Windows, and you have lied to me about doing itSince this is a very clear sign of a pirated Windows, which we do not help fix, I am going to close this.Microsoft has a program for people who unknowingly receive counterfeit software:Q:What are the details of the genuine Windows offer?A:To help customers who unknowingly purchased a counterfeit version of Windows XP, Microsoft has created two genuine Windows offers for those who qualify: * Complimentary offer: Microsoft will make a complimentary copy of Windows XP available to customers who have been sold counterfeit Windows. Customers will be required to submit a proof of purchase, the counterfeit CD, and a counterfeit report with details of their purchase. Only high-quality counterfeit Windows will qualify for the complimentary offer. * Electronic License Key Offer: Microsoft will offer an alternative for customers who find out via the WGA validation process that they are not running genuine Windows, but do not qualify for, or choose not to take advantage of, the complimentary offer. These customers will be able to license a Windows Genuine Advantage Kit for Windows XP directly from Microsoft for a special on-line purchase price. The Windows Genuine Advantage Kit for Windows XP will include a new 25-character Product Key and a Windows Product Key Update tool that will allow customers to convert their counterfeit copy to genuine Windows XP electronically. Link to post Share on other sites
Recommended Posts