PDA

View Full Version : Windows Genuine Disadvantage malware sighted



ZaZu
07-04-2006, 05:50 PM
Perfidious virus pushers have created a worm that poses as Microsoft's anti-piracy program, Windows Genuine Advantage (WGA).

The Cuebot-K worm spreads via AOL instant messenger in the guise of WGA. The timing of the release of the malware coincides with controversy over a feature in WGA that meant that the anti-piracy program "phoned home" with hardware and software data from PCs every time Windows started up.

Cuebot-K attempts to register itself as a new system driver service called 'wgavn', with the display name 'Windows Genuine Advantage Validation Notification'. Thereafter it runs every time a computer starts up. Users who attempt to remove the malware are falsely informed that getting rid of the program will result in system instability.

Once installed on infected machines, Cuebot-K disables Windows firewall and opens a backdoor on compromised machines, surrendering their control to hackers.

More information on the malware can be found in an analysis by anti-virus firm Sophos here. (http://www.sophos.com/virusinfo/analyses/w32cuebotk.html)

:source: Source: TheRegister.co.uk (http://www.theregister.co.uk/2006/07/03/wga_worm/)

I ain't got WGA and don't plan on installing any new Microsloth stuff ... gonna switch permanently to Linux ...

Tempestv
07-04-2006, 06:42 PM
I run windows and office, but that is all the microsoft stuff I run. do you really think I would trust the security of my machine to microsoft?

Imperfection
07-04-2006, 08:25 PM
Microsoft keeps invading privacy, all to fight piracy... no need to keep the call back feature when it has been prooved to be authentic... Imo

mavers
07-05-2006, 02:55 PM
had one of those today on a customers pc nasty little bugger

vip
07-06-2006, 03:57 AM
The length these idiots go to in order to create a virus.Don't they have anything better to do?

sear
07-06-2006, 04:08 AM
I thought WGA was malware :unsure: I mean it tried to sneak on to my system then send it's data back to it's paymaster.

tesco
07-06-2006, 10:19 PM
I thought WGA was malware :unsure: I mean it tried to sneak on to my system then send it's data back to it's paymaster.It's microsoft malwares. :P