IT security experts have warned of a
worm that purports to be Microsoft's Windows Genuine Advantage (WGA) anti-piracy tool.
WGA has recently been branded as 'spyware' in that it collects unnecessary
hardware and software
data from users' PCs.
The Cuebot-K worm spreads via
AOL Instant Messenger, registering itself as a new system driver service called 'wgavn'. It carries the display name 'Windows Genuine Advantage Validation Notification', and runs automatically during system startup.
Users who view the list of services are told that removing or stopping the service will result in 'system instability'.
Once in place the worm disables the Windows firewall, and opens a backdoor to infected computers which allows hackers to gain
remote access, spy on users, and potentially launch distributed denial-of-service attacks.
"People may think they have been sent the file from one of their AOL IM buddies, but in fact the program has no friendly intentions," said Graham Cluley, senior technology consultant at Sophos.

View:
Full Article @ VNU.net
(news gathered from neowin.net)