The New “Your Copy of Windows is Not Genuine” Popup From Microsoft
Is Bill Gates harassing you? Is he stalking you, inside your computer, telling you that “This copy of Windows is not genuine” with annoying little popup messages? Then you are not alone. This latest Microsoft stunt basically installs a virus, created by Microsoft, through Windows Auto Update. The WGA Virus will present users of unregistered or unofficial Windows installations with an alarming warning message. What Microsoft calls a “Genuine” copy of Windows is one that has a unique key, identified by their database, and registered to a specific user or company. Whether you have a pirated copy of Windows or have simply not registered for reasons of privacy, you will be harassed by WGA Notifications (Windows Genuine Advantage), unless you take precautions. If it is already too late, then there are some things you can do to undo the damage caused by the new Microsoft WGA Virus.
A Washington Post blog by Brian Krebs has details on the new Microsoft WGA Virus. Some highlights of that article are included here. The article explains how the WGA Virus, although it does not describe it as such, is installed via the Windows Automatic Update feature. Windows XP users in the United States who have set up automatic security updates will receive the WGA Virus, as of April 27, 2006. After installation and reboot, users may find their computers popping up an alert that reads: “This copy of Windows is not genuine; you may be a victim of software counterfeiting.”
You Can Avoid Getting the Microsoft WGA Virus!
*. update: Since this story was written we have ran a second story with specific instructions. We recommend you follow this link for information on avoiding WGA. Also, click here “WGA” for all stories on this subject.
Microsoft is calling this a “pilot program” and users will be presented with an option to decline participation. Windows Auto Update will not install the Windows Genuine Advantage software if you “decline” acceptance of the License Terms dialog that you will be presented with.
Key Point: Click “decline” on the License Agreement presented as part of the WGA Software.
Oops! Accidentally accepted the license agreement already?
If you do not decline the license agreement, the WGA Virus software will be installed. Then you will see WGA notifications telling you “This copy of Windows is not genuine” at boot time, login time, and periodically to via a system tray bubble notification. Although you will have an option to suppress the messages, they will only be temporarily suppressed. Basically, annoying messages, similar to those shareware nag screens, will harass you, urging you to pay the money to Microsoft, reformat and install what Microsoft considers a Genuine Copy of their Windows operating system.
When you see the popup message, you will be presented with two options with the following verbiage:
- You can click Resolve now to start the Get genuine Windows process.
- You can click Remind me later.
If you use the “Remind me later” option, an icon will be available in the notification area that you can double-click to start the Get genuine Windows process, which you will not actually ever want to do. Neither of these two options will be satisfactory to users of private, non-licensed copies of Windows XP. If you have the WGA Virus already installed, there are still some ways to possibly remove it and get rid of the popup harassment. Those workarounds will be covered later in this article.
Will the WGA Virus Report My Illegal Copy of Windows to Microsoft?
From a Microsoft spokesperson, “WGA Notifications is for Windows XP users. Our client software does not collect any information that can be used to identify or contact a user. We use the same process used by many popular search engines and Web sites to determine where their users are from — a form of IP lookup. This IP lookup process does not include any information that is used to identify you or contact you, and only gives a rough geographic representation of where users are located.”
So basically, the answer to the question, “will they come for you” is “no, not at this time.” However, Microsoft is becoming more aggressive in attempting to halt the propagation of pirate copies of their Windows operating system. Microsoft will go as far as the public, and the government, will allow. To protect yourself, it may be wise to disable Windows Auto Update altogether.
Microsoft is calling their WGA Virus by the name “Windows Genuine Advantage Notifications software,” and it is also being referred to as the “WGA Notifications Patch.” The WGA Notifications patch is installed if the user has opted to automatically update Windows via the Windows Update Website or if XP users manually download the latest Windows updates.
Stop The Harassment and Kill the WGA Virus
Several ways to stop the WGA Virus popup have been posted on various Internet forums including one titled, “WGA install workaround (KB905474).” Here we have provided the various workarounds currently available.
Removal Workaround Method (A)
- End the process wgatray.exe in Windows TaskManager and restart Windows XP in safe mode.
- Delete the following files:
WgaTray.exe in c:\windows\system32
WgaTray.exe in c:\windows\system32\dllcache - Use the Registry Editor to delete the folder key “WGALOGON” in the following branch:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonNotify
Removal Workaround Method (B)
-
Locate WgaLogon.dll in the Windows system folder and alter the executable bit. According to this suggestion, winlogin will not be able to call it as a notification package at boot, and since
- Disable simple file sharing in Windows
- Right-click on the WgaLogon.dll file and choose Advanced
- uncheck the Inherit box
- Remote the execute permission and leave the read permission active
- Apply the changes and reboot
WgaLogon is responsible for running and maintaining WgaTray.exe, the icon tray balloons will also be eliminated.
Removal Workaround Method (C)
-
In this post it was suggested that clearing the contents of the data.dat file will eliminate the popup messages. The data.dat file is located at the following path:
- Open data.dat in notepad, clear the contents, and save
- Change the permissions on data.dat to Read-Only
- Remove the following files from the Windows System32 folder:
wgalogon.dll spmgs.dll
wgatray.exe The WGA setup file is in C:\WINDOWS\SoftwareDistribution\
Download\6c4788c9549d437e76e1773a7639582a
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage\data
Removal Workaround Method (D)
-
This is considered a manual fix. These permissions can be repaired using Registry Editor as follows:
- Click Start, and then click Run
- In the Open box, type regedit, and then click OK
- Expand HKEY_CLASSES_ROOT
- Locate the subkey HKEY_CLASSES_ROOT\LegitCheckControl.LegitCheck
- Right-click the subkey and select Permissions…
- Ensure that Administrators allowed Full Control permission
- Repeat steps 3-6 for the subkey
HKEY_CLASSES_ROOT\LegitCheckControl.LegitCheck.1
The annoying popup WGA Virus hit United States users only just today, April 27th. Engineers are currently developing better workarounds than what has been presented here. Rest assured, there will be a very nice and tidy solution provided to users very soon. Until then, it is recommended that you disable Windows Automatic Update and simply avoid becoming infected with the WGA Virus from Microsoft.
Update: Make Sure You Do What is Necessary to Avoid WGA
When you manually run Windows Update, be sure to select “Custom” and not “Automatic.” After you enter the JavaScript to disable the WGA check (see our previous article for details) and have advanced to the list of available updates, be sure to locate “Windows Genuine Advantage Notification (KB905474)” and deselect it.
There are now two clear levels of WGA that you must avoid when manually running Windows Update. The first can be bypassed with the JavaScript disable code, and the second must be manually deselected. It is critical you have unchecked this in your list of updates or you will end up the victim of the Microsoft WGA virus.
trc author: Trent Keller
May 6th, 2006 at 8:26 am
I used system restore to get rid of the update and the “declined” later when reasked. Worked just fine on 3 computers infected. Good luck
May 17th, 2006 at 10:34 am
what’s the problem with buying a copy of Windows?? I don’t get it.
May 23rd, 2006 at 10:24 pm
What’s the problem with buying a copy of Windows? You don’t get it?
Well Ricky first off, Microsoft doesn’t call it a “copy” when you buy one of their “Genuine” Windows distributions. So if you are paying for a copy, perhaps you are spending money on a bootleg CD that you could have downloaded an ISO for yourself.
Oh, but that wasn’t your point was it? Of course not.
Bill Gates, the man whole stole MS DOS from a poor overworked genius, a programmer that died falling of a ladder while working on his modest California home. Bill Gates, the man who made a huge corporation founded on another mans work.
Bill Gates, the thief; the thief that got away with a criminal act.
Ok, getting back to your question, why not pay Bill Gates, the thief, for a Genuine copy of Windows, a crippled operating system that has resulted in the deaths of people, and the financial loss of many more, due to errors at inopportune moments, the result of corporate greed, and anti competitive business practices?
I digress again.
Well, frankly Ricky boy, I say SCREW YOU and your Bill Gates Microsoft loving ass, and I have never, nor will I ever, pay Microsoft a single penny for anything they stamp their mark of evil on.
June 2nd, 2006 at 10:42 pm
More info on avoiding the Windows Genuine Advantage Notification update.
http://spacebag.googlepages.com/wga-notify
July 15th, 2006 at 4:31 pm
I just noticed that spacebag link in post #4 talks about having a pirated copy of Windows XP. I am using a legal copy I bought from Best Buy but I am getting the WGA nag balloons too! This fix isn’t just for pirate copies. People who are having the trouble too want to read this, and people who just might want to keep their privacy instead of registering with microsuck. and #2 screw you Rick Timmon because I did pay and I am getting the nag balloons too.
July 19th, 2006 at 7:57 am
All you “privacy lovers” can kiss my ass. Business practices SHOULD be unfair. I hope you all stay deluded for a good long time, it makes my job way easier.
July 20th, 2006 at 9:49 pm
So, hold on a minute, because I don’t want huge corporations knowing my personal information, as in I value my right to privacy, this fact allows me the honor of kissing your back side? That doesn’t even make any sense! Chris, since I doubt you are over 12 years old, or I sure in the hell hope you aren’t, I think that kissing your ass would be criminal. And since you are obviously a juvenile “delinquent,” either by actual age or by mental capacity, I doubt your “job” of sitting around playing Grand Theft Auto, will be threatened by my desire to remain anonymous to corporate America. Now go wipe your nose and tell momma Mr. Woo was mean to you on the big bad Internet!
July 27th, 2006 at 10:25 pm
If you’re still having problems with this, I’ve created a (still) working fix to uninstall this annoying nag and privacy concern. I am also hosting two other fixes to ensure they are available to all who need them! You can also read my fan mail from “James Young, Internet Investigator”. =)
http://www.guidoz.com/WGATray/
–
Peace. ~G
July 22nd, 2007 at 5:10 pm
Ridiculously easy to trick Microsoft into thinking you have a “legit copy”
1. Get a key from somewhere on the internet.
2. Try to activate it
3. Activate by Phone
4. Doesn’t matter what you say for the automated phone thing…shit never works.
5. At the customer rep, tell them you system became corrupted and that you had to reinstall Windows. Tell them when they ask that this is the only computer Windows is installed on and that you bought it at Circuit City.
March 5th, 2008 at 2:21 pm
the insurance companies don’t want you to know…
Information on the life insurance industry…
September 2nd, 2008 at 4:42 pm
to remove notifacation do as follows
1 Safe mode
2 when in safe mode
3 My computer
4 C drive
5 Windows folder
6 system 32 folder 7 wgatray then delete
8 dillcache folder delete wgatray
9 start then run
10 regedit then enter
11 left hand pane, hkey_local_macine\software\microsoft\windowsnt\current version\win logon\notify
12once in location11 delete folder wgalogon and all its contents now reboot
13 now disable updates and do it manually do not validate