White Papers
Goner Worm / W32/Goner@MM, Win32.Goner.A@mm, I-Worm.Goner / Win32.Gone.A@mm / Pentagone / W32/Goner-A / W32/Goner.ini (Finjan)
Overview
Date: Wed, 05 Dec 2001 00:25:08
Name: Goner Worm
Aliases: Aliases: W32/Goner@MM,
Win32.Goner.A@mm, I-Worm.Goner,
Win32.Gone.A@mm, Pentagone,
W32/Goner-A, W32/Goner.ini
There is a new worm circulating worldwide in the wild called “Goner”, which is a screen saver that arrives as an e-mail attachment. This is the biggest outbreak since Love Letter worm. Screen saver (SCR) files are actually executable files, and they can do anything on your system once launched. (The last successful worm, BadTrans.B, arrived also as .SCR attachment).
The subject line of Goner worm is: "Hi."
The content of the e-mail states: “How are you? When I saw this screen saver, I immediately thought about you. I am in a hurry, promise you will love it!".
The attached file is: gone.scr. Goner spreads using Microsoft Outlook, but also using ICQ instant messenger. It isn't the first ICQ worm, but it's quite successful. If IRC chat application is installed, the computer can be used in Denial of Service (DOS) attacks. Numerous companies have reported being hit by this worm, mainly in the US and the UK.
Goner worm disables some anti-virus and personal firewalls applications, but doesn't disable Finjan's security applications. The worm searches for certain security applications, and removes them. Finjan views this as a demonstration of the risk of Instant Messenger applications. It's not always possible to block such applications at the firewall level. Most of these applications can be launched also inside web pages as Java or ActiveX components. Corporations should be protected from the risk of Instant Messengers. Finjan's desktop applications monitor the behavior of active content received by Instant Messengers.
Goner copies itself to the SYSTEM folder folder.
Goner loads itself automatically - C:\%SYSTEM%\gone.scr is added to registry key:
HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run
Publisher Finjan Software, Inc.
File Format HTML
Date Published December 2001
Downloads 4
Format White Papers
Topics N/A



