Jump to content
  • Who's Online   0 Members, 0 Anonymous, 9 Guests (See full list)

    • There are no registered users currently online

Cancelling the new WGA Installation sends a report to Microsoft

The Highlander

Recommended Posts

The German computer magazine CT (English translation using Google translate) analyzed the new WGA Notification that is installed during Windows Update. They decided to cancel the installation and immediately after doing so the firewall reported that update.exe tried to connect to the internet. This caught their attention of course and they decided to analyze the data that was send after the connection was established.



They used Wireshark to analyze the traffic and found out that update.exe sends data to genuine.microsoft.com. Some of the data seems to be encrypted while some could be identified. It sends registry information, namely the SusClientID as well as information about the version of the WGA tool, the windows version and the language of the operating system. It also sets a cookie which contains a GUID which could possibly be used to identify the computer.


Microsoft confirmed to the magazine that data is send but it would only be used to optimize the service. The GUID in the cookie would only be used to count all attempts in the most thorough way possible, it would not be used to identify the host.


It is however questionable why Microsoft is not informing the user that data is send using his internet connection.


One way to prevent this would be to either configure your firewall to block access to genuine.microsoft.com or add the following entry to your hosts file “ genuine.microsoft.com”


read it here:


Link to comment
Share on other sites


This topic is now archived and is closed to further replies.

  • Create New...