WGA worm shows up
p2p news / p2pnet: It was inevitable: someone’s apparently crafted a worm to take advantage of Windows Genuine (dis)Advantage, the Microsoft application Bill and the Boyz say isn’t spyware.
The program was designed to poke around inside your PC to make sure you’re not running Microsoft counterfeits and to rat you out if you are, calling Redmond every day with updates.
Then, following an attack of Bad PRitis, the company decided once every two weeks was enough, but too late because in Seattle, close to where Microsoft lives, Brian Johnson had already asked for class-action status, claiming the company failed to adequately disclose details when WG(dis)A was downloaded through Automatic Update.
Now, “IT security experts have warned of a worm that purports to be Microsoft’s Windows Genuine Advantage (WGA) anti-piracy tool,” says venunet.com, going on:
“The Cuebot-K worm spreads via AOL Instant Messenger, registering itself as a new system driver service called ‘wgavn’. It carries the display name ‘Windows Genuine Advantage Validation Notification’, and runs automatically during system startup.
“Users who view the list of services are told that removing or stopping the service will result in ’system instability’.”
Once in place, Cuebot-K disables the Windows firewall and opens a backdoor, “which allows hackers to gain remote access, spy on users, and potentially launch distributed denial-of-service attacks,” ads venunet.com.
Meanwhile, firewallleaktester.com has a diminutive application dubbed, appropriately, RemoveWGA which nullifies the notification part without touching Validation.
Get RemoveWGA here, and we’ve also filed a copy here.
Also See:
class-action status - Microsoft sued over WGA, June 29, 2006
Bad PRitis - Disable Microsoft WGA, June 24, 2006
venunet.com - Worm poses as Windows Genuine Advantage, July 4, 2006
Digg this.
p2pnet newsfeeds for your site.
rss feed: http://p2pnet.net/p2p.rss
Mobile - http://p2pnet.net/index-wml.php





p2pnet - rss feed: 
July 4th, 2006 at 2:26 pm
Well BBC is reporting that WGA is putting Microsoft customers off Windows.
http://news.bbc—————————–17161233595329
Content-Disposition: form-data; name=”page”
reply
July 4th, 2006 at 2:27 pm
Well BBC is reporting that WGA is putting Microsoft customers off Windows.
http://news.bbc.co.uk/1/hi/technology/5144698.stm