|
Goner Virus : W32/Goner@MM - Mass Mailing Internet Worm Disguised as Screen Saver; Attempts to Delete Anti-Virus Programs | ||||
|
McAfee AVERT (Anti-Virus Emergency Response Team), a division of Network Associates today assigned a HIGH-OUTBREAK risk assessment to the recently discovered Goner worm. Since its discovery earlier today, McAfee AVERT labs has received more than 500 reports from end-users and corporate enterprises worldwide, including Fortune 500 businesses. Symptoms APLICA32.EXE Subject: Hi Cure Tripwire Integrity Alert: IA120401A new virus dubbed Gone, Goner or Pentagone, is a Visual Basic Script program that spreads via e-mail and the messaging system ICQ. On infected computers, it stops most antivirus and security programs. The virus only affects computers running Microsoft Windows and spreads through Outlook e-mail clients. Macs and computers running Linux or other Unix-like operating systems are unaffected. The virus arrives in a message with the subject "Hi" and the following text in the body of the e-mail: "How are you? When I saw this screensaver, I immediately thought about you I am in a harry, I promise you will love it!" Attached to the message is what appears to be a screensaver file, Gone.scr, a compressed copy of the virus. When the file is opened, the Goner virus will infect the victim's PC, stopping a variety of antivirus and security applications and deleting all the files in the folders containing those applications. Kaspersky Lab's AVP, Zone Labs' ZoneAlarm, and Internet Security Systems' Black Ice are among the programs affected. After eliminating the security on the computer, the virus opens up a dialog box containing its name, Goner, and the handles of its creators. The dialog box also includes acknowledgements to other people on the Net, in a style similar to that of online vandals who deface Web sites. The virus then installs a backdoor program linked to mIRC, a popular Internet Relay Chat program. The backdoor can be used to execute denial-of-service attacks against IRC servers. In addition, the virus attempts to spread using e-mail and ICQ. To spread by e-mail, Goner uses script commands to send a copy of itself to every entry in the victim's Outlook address book. In ICQ, the virus uses specific commands to send a copy of itself to other people using the messaging application. Tripwire Will Detect & Facilitate Recovery from Goner Virus If you are using a standard installation of Tripwire based on our default policy file, you would expect to see the following new/modified entries: Added Files:
Possible Added/Modified Files (depending on currently installed software):
Possible Deleted Files:
Modified Registry Key:
Tripwire for Servers utilizes a "baseline" of information about the systems it protects, and reports on deviations from that known good baseline. These reports provide a comprehensive list of the files and registry keys that have been affected by the virus. By outlining the exact changes made by this virus, you can focus your recovery effort on only the specific files and registry keys that were changed by the virus, not on reinstalling the complete operating system and other applications. Tripwire for Servers will assist you in specific recovery efforts that provide an easy recovery path. | ||||
| December 4, 2001 | © Yenra | |||