Windows Secrets logo

 

 

   
       
   
Windows Secrets Newsletter • Issue 198 • 2009-05-21 • Circulation: over 400,000

   
   
BONUS DOWNLOAD

Land the Tech Job You Love excerpt
Find a great company whether you need it or not
Our free bonus this month is based on Andy Lester's new book, Land the Tech Job You Love. It's packed with helpful how-tos on writing killer résumés, completing job applications, securing those valuable employment interviews, and more. The printed book won't be available until June, but all Windows Secrets subscribers can receive an excerpt of two enlightening chapters simply by visiting their preferences page, after which a download link will appear. Hurry, we can only offer this for free through June 3. Thanks! —Brian Livingston, editorial director

All subscribers: Set your preferences and download your bonus
Info on the printed book: United States / Canada / Elsewhere


   
   
Table of contents
TOP STORY: Get all security patches without WGA nightmares
KNOWN ISSUES: WGA affects legitimate MS customers differently
WACKY WEB WEEK: This food's out to attack more than your heart
LANGALIST PLUS: Fix power-management glitches in XP and Vista
BEST SOFTWARE: Software improves lighting on digital photos
WOODY'S WINDOWS: Microsoft improves AutoRun and AutoPlay features

   
       
   
ADS

Free PC performance & security scan   Free PC performance & security scan
Take a few minutes to find out why your PC is so slow. Run the free PC Pitstop Optimize 2.0 scan and receive a free custom report detailing common issues that might be keeping your PC from running at full speed. Over 100 million scans run. Scan now!
PC Pitstop

Never reinstall your XP again   Never reinstall your XP again
New technology: no set-up, no loss of data or applications. The ultimate professional repair tool. Free PC booster with every scan, get it now!
Reimage

See your ad here

   
   
TOP STORY

Get all security patches without WGA nightmares

Susan Bradley By Susan Bradley

If you're a legitimate Microsoft customer, you can download and install all the Windows updates you need without running Windows Genuine Advantage (WGA) and exposing yourself to the false positives it's become known for.

In today's article, I explain how to install Windows XP and upgrade it with every available security fix and many optional updates as well, without ever installing WGA.

In an April 16 Windows Secrets story, contributing editor Ryan Russell argued that WGA poses a risk to the world because Microsoft prevents machines that fail WGA validation from getting some security patches through Windows' Automatic Updates mechanism. Unpatched machines are vulnerable to remote attacks that enroll them in hackers' bot armies.

In today's Known Issues column, several WS readers report that WGA wrongly disabled software they'd legitimately purchased. (An Ars Technica article back in January 2007 estimated at least 5 million WGA false positives, based on Microsoft's own numbers.) However, other readers defend the technology.

In the Windows Security Blog last month, Microsoft developer Paul Cooke claimed in a post that "all security updates go to all users," whether or not their machines have failed WGA validation.

As Ryan pointed out in his article, it's true that Microsoft posts all security updates to various Web pages, and that an advanced user could find each page in turn and then install each patch manually. Few users are likely to do this, however. The risk to the world arises because:
  • If a machine fails WGA validation, Automatic Updates installs only those security patches Microsoft rates as "Critical," not those rated "Important" or lower (some of which are just as crucial to a user's security, in my opinion);

  • Many users turn off Automatic Updates out of fear that their machines will be disabled, which was Microsoft's policy in the original release of Vista (as explained in a February 2007 article by Adrian Kingsley-Hughes);

  • If WGA has labeled a system as "nongenuine," Microsoft prevents the user from running Windows Update or the more extensive Microsoft Update, which are the official methods to patch a system on demand.
Because unpatched PCs are a threat to everyone, and because some people fail WGA validation due to false positives, I set out to determine how to fully patch a Windows PC without installing the WGA Notifications tool. Microsoft stated in a recent MSDN blog post that the company is focusing its antipiracy measures on XP, the most-widely used version of Windows. Therefore, my tests focused on XP Service Pack 2 and the more recent XP Service Pack 3.

It's important to note that in my tests, I entered a valid Windows product key and activated the operating system. I believe every user should legitimately activate a paid-for copy of Windows.

Bear in mind that Windows activation to date has been a completely separate process from WGA validation. This will change with the release of Windows 7 later this year, however. In Windows 7, WGA is being renamed Windows Activation Technologies (WAT).

Microsoft's Genuine Windows blog indicates that validation will be more streamlined in Windows 7. You'll need only enter a valid product key during activation. Your system will then be tested by WAT for "genuine" status at that time. Look for more information on WAT in an upcoming Windows Secrets column.

When a legitimate, paid-for XP system is flagged as counterfeit, the PC may require reactivation because significant hardware changes were made. An excellent summary of reactivation can be found in Alex Nichol's article, "Windows Product Activation (WPA) on Windows XP," which is posted on the Windows Support Center (AumHa) site.

Let me go on the record: using a counterfeit copy of Windows is asking for trouble. Paying for Microsoft software makes you less likely to end up with malware, according to an IDC whitepaper being distributed by Microsoft's Download Center. (On this page, you'll be prompted to register with Microsoft, but you can download the files without registering.) For example, it's been reported that some BitTorrent versions of the Windows 7 beta have been found to contain Trojan horses.

Regardless of how you obtained Windows, I recommend that you set Automatic Updates to Download but do not install, as I describe below in Step 2. This setting allows you to wait two or three days before installing patches that cause more problems than they prevent.

Two days after Microsoft Patch Tuesday each month, Windows Secrets publishes my Patch Watch column with information about which patches cause incompatibilities. You can then choose which updates to install and which to postpone. That includes the WGA Notifications tool, which Automatic Updates ordinarily installs as though it were a "critical" security patch.

In my tests, I started from scratch by installing XP SP2 and XP SP3 on clean machines. If you've already installed WGA on XP but no longer want it, you must remove the so-called patch KB905474. In KB article 921914, Microsoft provides manual removal instructions only for the "pilot" versions of WGA Notifications: 1.5.0527.0 through 1.5.0532.2. The article says higher-numbered "release" versions cannot be uninstalled.

UPDATE 2009-05-28: You can disable WGA Notifications by removing its entry in Scheduled Tasks using Autoruns, a free program that's downloadable from Microsoft.com. For details, see the 2009-05-28 Known Issues column.

Note that without WGA, you can't download Windows Defender, Windows Media Player 11, Network Diagnostics tools, and other Windows extras. Microsoft describes the products that are affected by WGA on its Genuine Microsoft Software page.

How to patch without running WGA validation

The following steps will allow you to install all Windows security patches on a new build of XP, without installing or running WGA on the machine:

  • Step 1: Install and activate XP. For XP SP2 only (not XP SP3), you must also download and install the patch described in KB article 898461, which updates the installer program and ensures that your system will receive future updates.

  • Step 2: In either version of XP, click Start, Control Panel, Security Center, Automatic Updates. Choose Download updates for me, but let me choose when to install them.

  • Step 3: Whenever you see a yellow-shield icon in the notification area (previously known as the system tray), click the icon and then choose Custom install.

  • Step 4: Scroll to the bottom of the patch window and uncheck Windows Genuine Advantage Notification (KB905474), as shown in Figure 1. (For more info, see Microsoft KB article 905474 to read the company's description of WGA Notification.)

    Uncheck KB 90474
    Figure 1. Uncheck KB905474 to prevent WGA from being installed on the system.

  • Step 5: After you click Install, check Don't notify me about these updates again in the resulting dialog to prevent WGA from being included in future Windows updates (see Figure 2). Click OK.

    Don't be offered WGA in the future
    Figure 2. Check this option to avoid being offered WGA Notifications as part of future updates.
From this point forward, every time you update your system, review the patches being offered to you and deselect those you don't want before proceeding with the installation.

Microsoft occasionally updates the WGA Notifications tool, so you can count on its being offered to you again, despite your choice in Step 5 above. The explanation Microsoft officials gave me for this decision is that the company feels it's wise to reinstall WGA periodically to ensure that customers haven't been the victim of unscrupulous consultants who use illegal media when reinstalling your operating system.

There's a flaw in this thinking: the reason many of these consultants use the wrong media is that Microsoft doesn't make it easy to get replacements for your Windows installation discs. It's also difficult to get up-to-date installation media unless you're one of Microsoft's enterprise-level customers.

Microsoft's recommendation that you set your machine to update automatically as the best way to protect it is also flawed. These days, our PCs aren't just simple e-mail and Web terminals. They're crucial to all our work, and if they're disabled we can't make a living. For example, if a Windows update causes our Internet connection to break because of a conflict with a third-party security program — as has happened many times in the recent past — we might be unproductive for hours or days.

Also, if you enable Automatic Updates, you may be as dismayed as I was to learn that Microsoft treats legitimate customers like thieves. The WGA Notifications patch described in KB article 905474 automatically installs if Automatic Updates is empowered to act without permission. In that case, you either have to run the WGA tool the next time you reboot or press Cancel every time you start your system. (See Figure 3.) Is that any way to treat a customer?

WGA Notifications nag note
Figure 3. If you install WGA Notifications on XP, this dialog box will reappear each time you reboot until you click Next and run the process.

Use a third-party patch testing tool

The WS Security Baseline page is periodically updated to describe a bare-minimum set of defensive tools that home users of Windows should install. The page currently recommends, among other things, that you regularly test for OS and application patches that vendors have released but you haven't yet installed. Secunia.com's Online Software Inspector is listed as a third-party service that tests for app patches in addition to Windows updates.

However, I personally prefer the free Shavlik Patch Google Gadget. I'm not thrilled with Shavlik's use of Google Desktop as the platform for its update checker. But Shavlik's tool recently informed me about an update to Adobe Flash Player on a test PC, whereas Secunia's tool had missed this fact.

I'll bring you a detailed report on the two services in a future article soon. In the meantime, to get Shavlik's program, visit the company's download page. For more information on Secunia's online and downloadable software inspectors, visit the company's vulnerability scanning page.

To recap: the best way to keep your system up-to-date is to set Windows' updater to download patches but not to install them automatically, deselect WGA Notifications updates, and run a tool such as the Shavlik Patch Google Gadget at least once a month to verify that your software is fully patched.

Susan Bradley recently received an MVP (Most Valuable Professional) award from Microsoft for her knowledge in the areas of Small Business Server and network security. She's also a partner in a California CPA firm.

Table of contents

   
   
ADS

Save up to 76% on quality inkjet ink   Save up to 76% on quality inkjet ink
We offer the sharpest prices on the Web for quality ink and laser toner. Bonus: save an extra 10% by using coupon code DAS926M. Free shipping to contiguous U.S. locations for all orders over $50. Offer expires 5/31/2009 and excludes OEM items.
4InkJets

Are your computer's drivers up-to-date?   Are your computer's drivers up-to-date?
Driver Detective provides the most up-to-date drivers specific to your computer! With more than 1 million drivers, Driver Detective saves you endless hours of work and aggravation normally associated with updating drivers.
Driver Detective

Get your message seen by 400,000 readers   Get your message seen by 400,000 readers
Does your company offer a product or service? Now you can place an ad in the Windows Secrets Newsletter and be seen by more than 400,000 active buyers of PC hardware and software. Bid as much or as little as you like to get the ideal ad placement.
Windows Secrets Newsletter

See your ad here

   
   
KNOWN ISSUES

WGA affects legitimate MS customers differently

Dennis O'Reilly By Dennis O'Reilly

Following an April 16 Top Story on the Windows Genuine Advantage (WGA) copy-protection scheme, Windows Secrets heard from several readers who have — to put it mildly — a range of opinions.

Several readers couldn't pass Microsoft's WGA validation, despite having purchased Windows legitimately, while other readers have had no bad experiences and defend the testing system.

One subscriber with first-hand experience of Microsoft's anti-copying technology is Aaron Fox:
  • "I am in WGA hell. I have a completely valid copy of Windows XP Pro. Our company (to remain unidentified) buys a site license from Microsoft. I can install Windows on as many machines at work as I please.

    "I replaced the motherboard on an old working computer. I wanted to keep the hard drive intact, so I deleted the drivers. My intention was to install the motherboard and then reinstall the drivers. Because the hard drive had not been altered, all my programs and data files would be intact.

    "Except for WGA. After I replaced the motherboard, Windows asked me for my password and then informed me that 'this copy of Windows must be activated with Microsoft. Do you want to activate Windows now?' If I answer no, my computer is kindly rebooted by Microsoft and I'm back at the Windows log-on screen.

    "If I answer yes, I get an 'activate software' screen. I tried to activate the software over the phone by calling Microsoft, but the Microsoft technical people (it's pretty funny that they are called 'technical people') told me that my computer was generating an 'installation ID' that tells the activation people that I have an illegal version of Windows. So I read to them my Windows XP Pro installation-disc product key, and they agreed that it's valid. But there's nothing they could do.

    "In effect, WGA software has hijacked my computer. I can't log on. I can't run programs. I can't do anything. I need my computer, and I don't want to reformat and reinstall everything. I have now been e-mailing and calling Microsoft for two weeks. I'm no closer to having a functional computer. I'll probably break down soon and reformat the hard drive and reinstall Windows."
Charles Cunis experienced a different form of Microsoft-activation responsiveness:
  • "I installed MS Office 2003 Student Version — purchased from Office Depot — and activated it in 2006. Fast forward to January 2009, when I installed a new motherboard and a hard drive. Last week, I needed to do some work that required Office 2003, and I tried to activate it using the same key code of the original install. No go.

    "Tried to activate again via the Internet. No go.

    "Got on the telephone, keyed in the eight or so groups of numbers. No go.

    "Got back on the phone and went through the whole eight-groups-of-numbers routine with an MS rep. No go.

    "He switched me to the next level. Line disconnects. Tried the whole routine again — including reciting the numbers to the rep while he ate lunch. Line cuts off.

    "Tried to find someone to call at MS Web site. No go.

    "Gave up.

    "My tale of woe is only one of thousands. Something has to be done with MS. This is wrong. The only way they're going to move is if you folks keep the pressure on. Great article."
One reader who perceives WGA as a boon to legitimate software users (not just to Microsoft) is Rio Zuni:
  • "I've been in IT since 1980 in a wide range of corporate and private positions, ranging from early adopter to executive IT administrator. There has never been an instance in which I thought WGA was a mistake or thwarted users.

    "At one point in my career, I was a software manager for the California State University system. At CSU, student piracy of everything — software included — was rampant. The networks and data storage were so clogged with unlicensed software being downloaded, stored, and traded among students, friends, and faculty that an endless supply of money was thrown into expanding them so as not to upset the 'freedom' accorded tuition-paying students. In other words, the university looked the other way and piracy was allowed to flourish.

    "During this time, WGA was introduced. It never impacted campus systems, since our licenses were institutional. Student-owned systems were impacted, but only where students were trying to install pirated OS or applications on them or where their systems were infected or misconfigured....

    "Most systems I have pulled out of the ditch had one or more of these issues:

    "Pirated software, viruses, spyware, adware, no WGA, OS and application software updates missing, fragmented hard drives, unnecessary OS and application tweaks, antivirus software, antispyware software, anti-adware software, mismatched system resources (such as not enough memory to do the expected job), etc.

    "The list of horrors in personal systems goes on and on. People abuse their personal systems more than I could imagine. But the 'helping' anti-whatever software is often the cause of the problem.

    "WGA is not the problem, nor is it a problem. It is certainly a symptom when it fails. WGA is Microsoft's way of protecting their revenue stream so they can bring us more marginal software in the future. I can't justify a lot of product decisions that Microsoft makes, but I can appreciate some of their business decisions."
No one who writes for Windows Secrets is in favor of counterfeiters, who profit by making unlicensed copies of Windows. But, as WS contributing editor Ryan Russell pointed out in his April 16 article, WGA doesn't prevent counterfeiters from producing and selling thousands of systems.

Machines that fail WGA receive via Automatic Updates only those security patches rated "Critical," not those rated "Important" or lower — and the affected users are prohibited by Microsoft from running Windows Update at all. The unpatched machines are easily infected and become part of bot armies that attack legitimate users.

Readers Aaron, Charles, and Rio will each receive a gift certificate for a book, CD, or DVD of their choice for sending comments we printed. Send us your tips via the Windows Secrets contact page.

The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com.

Table of contents

   
   
WACKY WEB WEEK

This food's out to attack more than your heart

Food Fight By Katy Abby

We're taught from a tender age not to play with our food. Still, many of my formative years were spent slyly sculpting fortresses out of mashed potatoes and creating formidable moats of gravy — those green beans never stood a chance!

Watch what happens when some valiant victuals get their own ideas about who's at the top of the food chain in this incredible stop-motion short. The video shows that war isn't healthy for any of the major food groups. John Belushi's got nothing on these morsels. Warning: gastronomically explicit! Play the video

Table of contents

   
   
PERMALINKS

Use these permalinks to share info with friends

We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.)

The following link includes all articles this week: http://WindowsSecrets.com/comp/090521

Free content posted on May 21, 2009:

 
You get all of the following in our paid content:

Get our paid content by making any contribution

12 months of paid content

There's no fixed fee! Contribute whatever it's worth to you
Readers who make a financial contribution of any amount by May 27, 2009, will immediately receive the latest issue of our full, paid newsletter and 12 months of new paid content. Pay as much or as little as you like — we want as many people as possible to have this information.
 
John Lester E. in the Philippines

A portion of your support helps children in developing countries
Each month, we send a full year of sponsorship to a different child. Your contributions in May are helping us to sponsor John Lester E., an 8-year-old boy from the Philippines who has three siblings and likes playing basketball. Children International channels development aid from donors to John Lester and his community. We also sponsor kids through Plan USA, Save the Children, and other respected agencies. More info

Use the link below to learn more about the benefits of becoming a paid subscriber!

More info on how to upgrade

Thanks in advance for your support!

   
   

Table of contents

   
   
YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets resulted from the merger of several publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Program Manager: Ryan Biesemeyer. Web Developer: Damian Wadley. Research Director: Katy Abby. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Mark Joseph Edwards, Michael Lasky, Woody Leonhard, Ryan Russell, Becky Waring.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
Copyright © 2009 by WindowsSecrets.com LLC. All rights reserved.

Table of contents