It seems it spreads through AIM as an invitation to go to a buddies MySpace webpage. It will install itself as a
Windows service and mimic the new
Windows update for Windows Genuine Advantage. It actually installs the service as
Windows Genuine Advantage Checker in
services.msc, but doesn't allow you to stop the service. It runs as
wgav.exe in the task manager as with System rights. It is a variation of a
backdoor trojan. Just like the actual new service (which doesn't get listed) it will send out its data everytime you reboot or logon, plus once a day.
In order to get rid of this you must boot into
Safe Mode and disable the service. You can then delete the actual
wgav.exe found in the
system32 folder and
prefetch folder.