Help WGA validation says this windows version has been hacked

Discussion in 'Software' started by topkat690, Apr 11, 2012.

  1. topkat690

    topkat690 Private First Class

    I am helping a friend with her pc her mom bought it from Dell over five years ago and she said it was running very slow so I added more memory, it worked fine then this message kept popping up saying that Wga had to be downloaded so I did and the windows passed validation and then I downloaded the Free Avast and after it scanned and put stuff in the chest the WGA started saying the windows was counterfeit I took Avast off and ran a WGA diagnostics and here is the report

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Status: Invalid Product Key
    Validation Code: 8
    Cached Validation Code: N/A
    Windows Product Key: *****-*****-WV37P-GC7V7-8GCXD
    Windows Product Key Hash: hdoM8R5BMEt2IoswUm6GA1Ma2J0=
    Windows Product ID: 76487-640-5401173-23489
    Windows Product ID Type: 1
    Windows License Type: Volume
    Windows OS version: 5.1.2600.2.00010100.2.0.pro
    ID: {2D1F85A6-DC41-4453-9DF2-10E191FCAA11}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.9.42.0
    Signed By: Microsoft
    Product Name: N/A
    Architecture: N/A
    Build lab: N/A
    TTS Error: N/A
    Validation Diagnostic: 025D1FF3-230-1
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A
    Version: N/A

    Windows XP Notifications Data-->
    Cached Result: 8
    File Exists: Yes
    Version: 1.9.40.0
    WgaTray.exe Signed By: Microsoft
    WgaLogon.dll Signed By: Microsoft

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 100 Genuine
    Microsoft Office Enterprise 2007 - 100 Genuine
    OGA Version: Registered, 2.0.48.0
    Signed By: Microsoft
    Office Diagnostics: 025D1FF3-230-1

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{2D1F85A6-DC41-4453-9DF2-10E191FCAA11}</UGUID><Version>1.9.0027.0</Version><OS>5.1.2600.2.00010100.2.0.pro</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-8GCXD</PKey><PID>76487-640-5401173-23489</PID><PIDType>1</PIDType><SID>S-1-5-21-57989841-2111687655-725345543</SID><SYSTEM><Manufacturer>Dell Computer Corporation</Manufacturer><Model>Dimension 3000 </Model></SYSTEM><BIOS><Manufacturer>Dell Computer Corporation</Manufacturer><Version>A02</Version><SMBIOSVersion major="2" minor="3"/><Date>20041108000000.000000+000</Date></BIOS><HWID>AA1E39E70184606C</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification><File Name="WgaTray.exe" Version="1.9.40.0"/><File Name="WgaLogon.dll" Version="1.9.40.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>64BC76978749586</Val><Hash>GW6PzcEVEDTVKeO5Ym5UUm41dBk=</Hash><Pid>89388-707-0441865-65062</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

    Licensing Data-->
    N/A

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    N/A

    OEM Activation 1.0 Data-->
    BIOS string matches: yes
    Marker string from BIOS: 1B2BE:Dell Inc|1B2BE:Microsoft Corporation
    Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

    OEM Activation 2.0 Data-->

    I posted this in the Microsoft Forums and one of the other posters said it appears that "Windows is using a Key which was never issued by MS - and must therefore have been generated by a hacker's KeyGen utility.

    For which version and edition of Windows is the machine licensed, according to the COA sticker on the case??"

    The COA says that Windows Home Version came installed on the computer but in my computer I looked up the windows and it says Windows Pro. so if I restore it back to the original factory settings do you think that will correct the problem?
     
  2. shnerdly

    shnerdly MajorGeek

    If you are talking about the Factory Dell Restore, that should get it straightened out BUT it is going to format and reinstall the OS and all of the Dell crap and all of the current software, settings and data will be gone forever unless you back it up.
     
  3. topkat690

    topkat690 Private First Class

    I found out that someone else put that version on the computer so is ther a way I can find out if they formatted the hard drive and the sector that has the original factory settings on it?
     
  4. sach2

    sach2 Major Geek Extraordinaire

    Get the model number of the dell off the circle around the power button. Then we can find what the key sequence would be for factory restore.

    You can also go to Disk Management and see what partitions exist. Recovery partitions are usually 6-10gb so if a partition that size exist then it is likely the recovery partition but the XP Pro installation may have overwritten the original MBR which might make it hard to start recovery.
     
  5. topkat690

    topkat690 Private First Class

    The model is a dell dimension 3000
     
  6. sach2

    sach2 Major Geek Extraordinaire

    Here is a link to your manual http://support.dell.com/support/edocs/systems/dim3000/en/OM/j6758A04.pdf

    It says hitting <ctrl> + F11 during the screen with the blue bar and dell.com at startup will take you into the factory restore menu.

    You must realize that will delete everything, all documents, photos, email etc. It all goes back to factory defaults. You should discuss that with your friend and let her do backups of her data.

    Of course the availability of factory restore depends on whether the partition was deleted when XP Pro was put on the computer. The manual does seem to imply that an OS installation disc was included with the computer-it would be wise to see if our friend can find that disc in case there were a problem with the factory restore.

    You can try the ctrl + F11 key sequence to see if you get a restore menu. You will get an option to Reboot or Restore. You can just click Reboot to exit without restoring, so at least you would know that the key sequence works.
     
  7. topkat690

    topkat690 Private First Class

    I went to disc management and saw only two partitions the c drive which was 72 gigs and a backup z drive 2gb so I do believe that the windows that person put on here wipe out the original factory partition.
     
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Did you try F11?
     
  9. shnerdly

    shnerdly MajorGeek

    Like plodr said, try the F11 option. If that doesn't work see if the owner of the computer has the original disks that came with the computer. That set of disks should include the original OS disk, XP Home". It won't look like a regular Windows disk, it will probably be blue and white or green and white. It will install the OS only and give you a much cleaner install then the F11 restore. There should also be a driver disk with the set that should get everything going unless some hardware changes have been made.
     
  10. topkat690

    topkat690 Private First Class

    I just tried F11 at the dell screen and it goes straight to the windows screen. so if my friend can not find her copy of the system restore disc how can we get a copy from dell?
     
  11. topkat690

    topkat690 Private First Class

    Where would that option be because it is taking me to microsoft and given me the option to purchase a kit or windows 7
     
  12. tgell

    tgell Major Geek Extraordinaire


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds