AOL instant messenger worm poses as Microsoft's Windows Genuine Advantage

By
Follow google news

AOL Instant messenger (IM) users were warned this week of a new worm that poses as Microsoft’s controversial Windows Genuine Advantage (WGA) program.

Researchers at Sophos said the WGA worm, known as Cuebot-K, spreads by AOL Instant Messenger and registers itself as a new system driver service named wgavn.


The malware uses Windows Genuine Advantage Validation Notification as a display name and runs during system startup, according to Sophos. The worm then disables the Windows firewall and opens a backdoor to infected PCs, which allows malicious users to gain remote access or launch DDoS attacks.

Graham Cluley, senior technology consultant at Sophos, said the worm deceives users by appearing to be helpful software.

"People may think they have been sent the file from one of their AOL IM buddies, but in fact the program has no friendly intentions. Technical Windows users wouldn’t be surprised to see WGA in their list of services and so may not realize that the worm is using that name as a cloak to hide the fact that it has infected the PC," he said. "Once in place, this malware disables the firewall and opens a backdoor by which hackers can gain control over your computer to steal, spy and launch DDoS attacks."

Microsoft was hit with its second lawsuit in as many weeks over WGA as two companies and three residents from Washington state filed motions claiming the software violated spyware regulations.

Microsoft has issued new versions of WGA and has published directions on how to uninstall the program altogether.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Microsoft releases fix for flawed January security update

Microsoft releases fix for flawed January security update

Starlink faces high-profile security test in Iran crackdown

Starlink faces high-profile security test in Iran crackdown

Single Windows image drove RedVDS disposable cybercrime server business

Single Windows image drove RedVDS disposable cybercrime server business

Microsoft patches single-click Copilot data stealing attack

Microsoft patches single-click Copilot data stealing attack

Log In

  |  Forgot your password?