Two Computers/ Infected! One Wireless


Recommended Posts

Hello!! I have been reading here for a couple months and have successfully removed (or thought that i had) a trojan a few months ago. But now I have a major problem. I have two computers on my home network The comp that is hooked up wireless will not install malawarebytes or let me run any of the removal tools except superantispyware and that says it has a problem updating, I have tried safe mode, I installed combofix and that wont run also, and now its freezing up to the point of being useless. And my comp that is hooked directly to the modem is getting bad also But it still lets me run malawarebytes + spybot s+d and avast the first 2 say not infected but avast comes up with alot of infections but wont let me delete them, also neither one will let me run root repeal. If I clean the MAIN comp will my SECOND (and much worse comp reinfect it?) which one do i try to fix first I have created a Hjack this log of the worst one, comp2 and will be waiting for further assistance. Thank You.....Logfile of Trend Micro

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 6:54:33 PM, on 7/2/2009

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\windows\system\hpsysdrv.exe

C:\WINDOWS\System32\hkcmd.exe

C:\Program Files\Winamp\Winampa.exe

C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Belkin\F5D7050v5\Belkinwcui.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\gearsec.exe

C:\WINDOWS\system32\fxssvc.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\HiJack THIS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eznsearch.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Marquette-Adams Telephone Cooperative

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.102

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe

O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe

O4 - HKLM\..\Run: [QAGENT] C:\QAGENT.EXE

O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe

O4 - HKCU\..\Run: [vmmreg32] C:\WINDOWS\vmmreg32.exe

O4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EASYIN~1\eznorun.exe

O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\196_150_ni.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Belkin Wireless G USB Adapter Client Utility.lnk = ?

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.eznsearch.com

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200112...meInstaller.exe

O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://wdownload.weatherbug.com/minibug/tr...uginstaller.cab

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: kbdsf - Unknown owner - C:\WINDOWS\System32\kbdsf.exe (file missing)

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--

End of file - 7222 bytes

Link to post
Share on other sites

hi

Please run the MGA Diagnostic Tool and post back the report it shall produce:

  1. Download MGADiag to your desktop.
  2. Double-click on MGADiag.exe to launch the program
  3. Click "Continue"
  4. Ensure that the "Windows" tab is selected (it should be by default).
  5. Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  6. Paste the MGA Diagnostic Report back here in your next reply.

Link to post
Share on other sites

Hello!! Thank you for your quick response, Just to ad a few things this comp has been infected bad before and since then I have never been able to install any updates!! I originally had a hard time finding the report (never used clipboard viewer) but after a little search and reading I believe this is what you asked for.....

Diagnostic Report (1.9.0006.1):

-----------------------------------------

WGA Data-->

Validation Status: Validation Control not Installed

Validation Code: 0

Online Validation Code: N/A

Cached Validation Code: N/A

Windows Product Key: *****-*****-BRVBB-38MQ9-3PMFT

Windows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA=

Windows Product ID: 55277-OEM-2111907-00106

Windows Product ID Type: 2

Windows License Type: OEM SLP

Windows OS version: 5.1.2600.2.00010300.0.0.hom

ID: {9877488F-2E78-46A9-B29E-00216777659A}(3)

Is Admin: Yes

TestCab: 0x0

WGA Version: N/A, hr = 0x80070002

Signed By: N/A, hr = 0x80070002

Product Name: N/A

Architecture: N/A

Build lab: N/A

TTS Error: N/A

Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_78155E4D-232-80004005

Resolution Status: N/A

WgaER Data-->

ThreatID(s): N/A

Version: N/A

WGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

File Exists: No

Version: N/A, hr = 0x80070002

WgaTray.exe Signed By: N/A, hr = 0x80070002

WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

WGATray.exe Signed By: N/A, hr = 0x80070002

OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->

Office Status: 100 Genuine

Microsoft Office XP Professional with FrontPage - 100 Genuine

OGA Version: N/A, 0x80070002

Signed By: N/A, hr = 0x80070002

Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005

Browser Data-->

Proxy settings: N/A

User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)

Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe

Download signed ActiveX controls: Prompt

Download unsigned ActiveX controls: Disabled

Run ActiveX controls and plug-ins: Allowed

Initialize and script ActiveX controls not marked as safe: Disabled

Allow scripting of Internet Explorer Webbrowser control:

Active scripting:

Script ActiveX controls marked as safe for scripting:

File Scan Data-->

File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\licdll.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\ntoskrnl.exe[5.1.2600.31]

File Mismatch: C:\WINDOWS\system32\ntdll.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\kernel32.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\crypt32.dll[5.131.2600.0]

File Mismatch: C:\WINDOWS\system32\advapi32.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\setupapi.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\oembios.bin[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\oembios.dat[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\oembios.sig[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.0]

Other data-->

Office Details: <GenuineResults><MachineData><UGUID>{9877488F-2E78-46A9-B29E-00216777659A}</UGUID><Version>1.9.0006.1</Version><OS>5.1.2600.2.00010300.0.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-3PMFT</PKey><PID>55277-OEM-2111907-00106</PID><PIDType>2</PIDType><SID>S-1-5-21-4097411637-2163411867-2876842818</SID><SYSTEM><Manufacturer>HP Pavilion 04</Manufacturer><Model>P6304A-ABA XG922</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies LTD</Manufacturer><Version>3.02</Version><SMBIOSVersion major="2" minor="31"/><Date>20010824******.******+***</Date><SLPBIOS>HP PAVILION</SLPBIOS></BIOS><HWID>8E2731BF01846036</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Hewlett-Packard</name><model>Pavilion</model></SBID><OEM/><GANotification/></MachineData> <Software><Office><Result>100</Result><Products><Product GUID="{40280409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional with FrontPage</Name><Ver>10</Ver><Val>571B916CC4B4000</Val><Hash>k2jOTMTeoNV1RWDOaywky/SOcZM=</Hash><Pid>54185-640-0000007-17004</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="17" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>

Licensing Data-->

N/A

HWID Data-->

N/A

OEM Activation 1.0 Data-->

BIOS string matches: yes

Marker string from BIOS: 13576:Hewlett-Packard Company

Marker string from OEMBIOS.DAT: HP PAVILION

OEM Activation 2.0 Data-->

N/A

Edited by beaners
Link to post
Share on other sites

Hello Again11 I am not very good with comps but i will do my best. Thanks again

Validation Complete!

Thank you for completing the validation process and for using genuine Microsoft software.

By using genuine Microsoft software, you can be confident that you will have access to the latest features, security, and support, which will help to improve your productivity and expand the capabilities of your computer.

You will also have access to new innovations and offerings available only to genuine Microsoft software customers

Link to post
Share on other sites

hi

Please run the MGA Diagnostic Tool and post back the report it shall produce:

  1. Download MGADiag to your desktop.
  2. Double-click on MGADiag.exe to launch the program
  3. Click "Continue"
  4. Ensure that the "Windows" tab is selected (it should be by default).
  5. Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  6. Paste the MGA Diagnostic Report back here in your next reply.

Link to post
Share on other sites

Here you go!!!!

Diagnostic Report (1.9.0006.1):

-----------------------------------------

WGA Data-->

Validation Status: Validation Control not Installed

Validation Code: 0

Online Validation Code: N/A

Cached Validation Code: N/A

Windows Product Key: *****-*****-BRVBB-38MQ9-3PMFT

Windows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA=

Windows Product ID: 55277-OEM-2111907-00106

Windows Product ID Type: 2

Windows License Type: OEM SLP

Windows OS version: 5.1.2600.2.00010300.0.0.hom

ID: {9877488F-2E78-46A9-B29E-00216777659A}(3)

Is Admin: Yes

TestCab: 0x0

WGA Version: N/A, hr = 0x80070002

Signed By: N/A, hr = 0x80070002

Product Name: N/A

Architecture: N/A

Build lab: N/A

TTS Error: N/A

Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_78155E4D-232-80004005

Resolution Status: N/A

WgaER Data-->

ThreatID(s): N/A

Version: N/A

WGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

File Exists: No

Version: N/A, hr = 0x80070002

WgaTray.exe Signed By: N/A, hr = 0x80070002

WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->

Cached Result: N/A, hr = 0x80070002

Version: N/A, hr = 0x80070002

WGATray.exe Signed By: N/A, hr = 0x80070002

OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->

Office Status: 100 Genuine

Microsoft Office XP Professional with FrontPage - 100 Genuine

OGA Version: N/A, 0x80070002

Signed By: N/A, hr = 0x80070002

Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-800b0001_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005

Browser Data-->

Proxy settings: N/A

User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)

Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe

Download signed ActiveX controls: Prompt

Download unsigned ActiveX controls: Disabled

Run ActiveX controls and plug-ins: Allowed

Initialize and script ActiveX controls not marked as safe: Disabled

Allow scripting of Internet Explorer Webbrowser control: Disabled

Active scripting: Allowed

Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

File Mismatch: C:\WINDOWS\system32\winlogon.exe[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\licdll.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\ntoskrnl.exe[5.1.2600.31]

File Mismatch: C:\WINDOWS\system32\ntdll.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\kernel32.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\crypt32.dll[5.131.2600.0]

File Mismatch: C:\WINDOWS\system32\advapi32.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\setupapi.dll[5.1.2600.0]

File Mismatch: C:\WINDOWS\system32\oembios.bin[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\oembios.dat[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\oembios.sig[hr = 0x80070714]

File Mismatch: C:\WINDOWS\system32\syssetup.dll[5.1.2600.0]

Other data-->

Office Details: <GenuineResults><MachineData><UGUID>{9877488F-2E78-46A9-B29E-00216777659A}</UGUID><Version>1.9.0006.1</Version><OS>5.1.2600.2.00010300.0.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-3PMFT</PKey><PID>55277-OEM-2111907-00106</PID><PIDType>2</PIDType><SID>S-1-5-21-4097411637-2163411867-2876842818</SID><SYSTEM><Manufacturer>HP Pavilion 04</Manufacturer><Model>P6304A-ABA XG922</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies LTD</Manufacturer><Version>3.02</Version><SMBIOSVersion major="2" minor="31"/><Date>20010824******.******+***</Date><SLPBIOS>HP PAVILION</SLPBIOS></BIOS><HWID>8E2731BF01846036</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Hewlett-Packard</name><model>Pavilion</model></SBID><OEM/><GANotification/></MachineData> <Software><Office><Result>100</Result><Products><Product GUID="{40280409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office XP Professional with FrontPage</Name><Ver>10</Ver><Val>571B916CC4B4000</Val><Hash>k2jOTMTeoNV1RWDOaywky/SOcZM=</Hash><Pid>54185-640-0000007-17004</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="10" Result="100"/><App Id="16" Version="10" Result="100"/><App Id="17" Version="10" Result="100"/><App Id="18" Version="10" Result="100"/><App Id="1A" Version="10" Result="100"/><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>

Licensing Data-->

N/A

HWID Data-->

N/A

OEM Activation 1.0 Data-->

BIOS string matches: yes

Marker string from BIOS: 13576:Hewlett-Packard Company

Marker string from OEMBIOS.DAT: HP PAVILION

OEM Activation 2.0 Data-->

N/A

Link to post
Share on other sites

You still haven't validated your Windows, and you have lied to me about doing it

Since this is a very clear sign of a pirated Windows, which we do not help fix, I am going to close this.

Microsoft has a program for people who unknowingly receive counterfeit software:

Q:

What are the details of the genuine Windows offer?

A:

To help customers who unknowingly purchased a counterfeit version of Windows XP, Microsoft has created two genuine Windows offers for those who qualify:

* Complimentary offer: Microsoft will make a complimentary copy of Windows XP available to customers who have been sold counterfeit Windows. Customers will be required to submit a proof of purchase, the counterfeit CD, and a counterfeit report with details of their purchase. Only high-quality counterfeit Windows will qualify for the complimentary offer.

* Electronic License Key Offer: Microsoft will offer an alternative for customers who find out via the WGA validation process that they are not running genuine Windows, but do not qualify for, or choose not to take advantage of, the complimentary offer. These customers will be able to license a Windows Genuine Advantage Kit for Windows XP directly from Microsoft for a special on-line purchase price. The Windows Genuine Advantage Kit for Windows XP will include a new 25-character Product Key and a Windows Product Key Update tool that will allow customers to convert their counterfeit copy to genuine Windows XP electronically.

Link to post
Share on other sites
Guest
This topic is now closed to further replies.