« Spybot S&D definitions update 2006-07-01 | Blog Home | MailWasher Pro Screens Incoming Email and Filters Out Spam and Viruses »


Sign-up for Bluehost Web Hosting, from $6.95/month

We use Bluehost to host all of our associated websites and many of our clients are hosted here as well. If you are seeking reliable web hosting, with all types of scripting options included, at a reasonable price, with US based phone and chat support, please give Bluehost a try.

Bookmark and Share

Worm Masquerades as Microsoft Antipiracy Program

Source: http://www.pcworld.com/resource/article/0,aid,126307,pg,1,RSS,RSS,00.asp

W32.Cuebot-K spreads via through AIM and disguises itself as Windows
Genuine Advantage on infected PCs.

Security analysts have detected a new piece of malware that appears to run
as a Microsoft program used to detect unlicensed versions of its operating
system.

The malware has been classified as a worm and spreads through AOL's
Instant Messenger program, said Graham Cluley, senior technology
consultant for Sophos PLC, a security vendor.

Sophos is calling it W32.Cuebot-K, a new variation in the Cuebot family of
malware. The worm has a range of malicious functions. After it's
installed, the worm immediately tries to connect to two Web sites, a sign
it may try to download other bad programs on the machine.

A Nasty Payload

Cuebot-K can disable other software, shut off the Windows firewall,
download new malicious programs, perform basic DDOS (distributed denial of
service) attacks, scan local files and spawn a command prompt, Sophos
said.

Worms that spread through instant messaging programs often appear as
messages or links sent from friends, which trick a user into executing the
program. Cuebot-K propagates by sending itself as a file named "wgavn.exe"
to more people in the user's "Buddy List" but without a message, Cluley
said.

Worm With an Ironic Twist

If installed on a computer, Cuebot-K is registered as a new system device
driver service named "wgavn." When a list of services running on the
computer is summoned, the worm appears as "Windows Genuine Advantage
Validation Notification" Sophos said.

Cuebot-K's registry entry appears as
HKLM\SYSTEM\CurrentControlSet\Services\wgavn\.

The worm's ironic ruse comes as Microsoft's Windows Genuine Advantage
program is being criticized for functioning like spyware. WGA collects
hardware and software data on a user's computer and compares it to a
database of licensed operating systems.

If an improper copy is detected, Microsoft warns the user and cuts off
some free downloads.

Bookmark and Share  

Trend Micro Internet Security products, for home and office users, use in-the-cloud malware definitions that are updated every day, all day, as soon as new or altered strains of viruses and other malware are detected in the wild and analyzed. By offloading the bulk of these ever changing virus definitions to cloud servers, the load on your computers is greatly reduced. All users of Trend security programs are instantly protected from hostile web pages laden with malware exploits and hostile email, by the Trend Micro Smart Protection Network.

Creative Commons License This weblog is licensed under a Creative Commons License.
The content on this blog may be reprinted provided you do not modify the content and that you give credit to Wizcrafts and provide a link back to the blog home page, or individual blog articles you wish to reprint. Commercial use, or derivative work requires written permission from the author.

About the author
Wiz FeinbergWiz's Blog is written by Bob "Wiz" Feinberg, an experienced freelance computer consultant, troubleshooter and webmaster. Wiz's specialty is in computer and website security and combating spam. Wizcrafts Computer Services was established in 1996.

I produce this blog and website at my own expense. If you find this information valuable please consider making a donation via PayPal.

We are hosted on Bluehost and couldn't be happier!

Fight website spammers