Common Tasks

Recent Posts


Email Notifications

Personal Links


Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Cuebot-K IM Worm - Hides as a Windows Genuine Advantage Service

Users should always be careful to avoid processing files or URLs in the Instant Messaging environment.  This new IM threat disguises itself like the new WGA process Microsoft is using to ensure the Windows OS has the proper license control keys.

Cuebot-K IM Worm - Hides as a Windows Genuine Advantage (WGA) Service

W32/Cuebot-K is a instant messaging worm and backdoor for the Windows platform. W32/Cuebot-K spreads via AOL Instant Messenger. The file wgavn.exe is registered as a new system driver service named "wgavn", with a display name of "Windows Genuine Advantage Validation Notification" and a startup type of automatic, so that it is started automatically during system startup.


Donna's SecurityFlash said:

The fake Windows Genuine Advantage Tool (wgavn.exe) has been named as W32.Cuebot-K worm by Sophos. ...
# July 1, 2006 2:12 AM