Go to Unsolved Mystery Publications Main Index Go to Free account page
Go to frequently asked mystery questions Go to Unsolved Mystery Publications Main Index
Welcome: to Unsolved Mysteries 1 2 3
 
 New Mystery StoryNew Unsolved Mystery UserLogon to Unsolved MysteriesRead Random Mystery StoryChat on Unsolved MysteriesMystery Coffee houseGeneral Mysterious AdviceSerious Mysterious AdviceReplies Wanted on these mystery stories
 




Show Stories by
Newest
Recently Updated
Wanting Replies
Recently Replied to
Discussions&Questions
Site Suggestions
Highest Rated
Most Rated
General Advice
Ancient Beliefs
Angels, God, Spiritual
Animals&Pets
Comedy
Conspiracy Theories
Debates
Dreams
Dream Interpretation
Embarrassing Moments
Entertainment
ESP
General Interest
Ghosts/Apparitions
Hauntings
History
Horror
Household tips
Human Interest
Humor / Jokes
In Recognition of
Lost Friends/Family
Missing Persons
Music
Mysterious Happenings
Mysterious Sounds
Near Death Experience
Ouija Mysteries
Out of Body Experience
Party Line
Philosophy
Prayers
Predictions
Psychic Advice
Quotes
Religious / Religions
Reviews
Riddles
Science
Sci-fi
Serious Advice
Strictly Fiction
Unsolved Crimes
UFOs
Urban Legends
USM Events and People
USM Games
In Memory of
Search Stories:


Stories By AuthorId:


Google
Web Site   

GONER VIRUS....MORE INFO AND HOW TO REMOVE IT...PAMMIEROSE

  Author:  29928  Category:(Interesting) Created:(12/7/2001 8:22:00 PM)
This post has been Viewed (617 times)

Symantec Security Response - W32.Goner.A@mm Due to the increased rate of submission and level of damage, Symantec Security Response is upgrading W32.Goner.A@mm from Category 3 to Category 4.

W32.Goner.A@mm is a mass-mailing worm that is written in Visual Basic. The worm has been compressed using a known Portable Executable (PE)* file compressor. The worm can spread its infection using the ICQ network as well as by email using Microsoft Outlook. If IRC is installed, this worm can also insert mIRC scripts that will enable the computer to be used in Denial of Service (DOS) attacks.

Removal Tool Symantec Security Response has posted a removal tool to assist in eradicating this worm. Please go here to read the instructions and download the removal tool.

Virus Type: Worm

Infection Length: 38,912 bytes

W32.Goner.A@mm is capable of spreading over the ICQ network. If ICQ is installed on an infected machine, the worm will do the following: 1. Check for the version of the ICQ .dll file that contains the APIs that will be used. If the correct version is found, the worm proceeds. 2. Disable all notification. This means that the user cannot see what the worm is doing in the background. 3. Retrieve a list of all "buddies" who are currently online. 4. Retrieve information about each user individually. This information is required to be able to send files. 5. Send itself to all users on the list. 6. Re-enable all notifications.

If mIRC is installed, this worm can insert scripts into the mIRC folder. This allows the computer to be used in DOS attacks.

W32.Goner.A@mm Discovered on: December 4, 2001 Last Updated on: December 4, 2001 at 09:15:56 PM PST

Printer-friendly version Tell a Friend

W32.Goner.A@mm is a mass-mailing worm that is written in Visual Basic. The worm has been compressed using a known Portable Executable (PE)* file compressor. The worm can spread its infection using the ICQ network as well as by email using Microsoft Outlook. If IRC is installed, this worm can also insert mIRC scripts that will enable the computer to be used in Denial of Service (DOS) attacks.

Removal Tool Symantec Security Response has posted a removal tool to assist in eradicating Damage:

Payload: Upon execution Large scale e-mailing: Send itself to all users in Outlook Address Books Deletes files: Attemps to delete several files, including NAV Distribution:

Subject of email: Hi Name of attachment: Gone.scr Size of attachment: 38,912 bytes

Technical description:

W32.Goner.A@mm starts by displaying the following window.

In the background, the worm starts iterating the Microsoft Outlook address book and sends itself to all addresses in the address book. The email appears as follows.

The worm has been packed using a known Portable Executable (PE) packer. The size of the worm unpacked is approximately 159 KB.

The worm adds the value

C:\%SYSTEM%\gone.scr C:\%SYSTEM%\gone.scr

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

NOTES:

%SYSTEM% is the path to the Windows System folder. In most cases this would be C:\Windows\System; however, the location could be different if the Windows System folder has been installed to a different location. The key has the same value as the name of the file that is being called.

Once the registry key has been added, the worm will terminate the processes of common anti-virus and firewall products found on the computer from the list below:

APLICA32.EXE AVCONSOL.EXE AVP.EXE AVP32.EXE AVPCC.EXE AVPM.EXE CFIADMIN.EXE CFIAUDIT.EXE CFINET32.EXE ESAFE.EXE FRW.EXE ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSUPP95.EXE ICSUPPNT.EXE LOCKDOWN2000.EXE NAVAPW32.EXE NAVW32.EXE PCFWallIcon.EXE SAFEWEB.EXE TDS2-98.EXE TDS2-NT.EXE VSECOMR.EXE VSHWIN32.EXE VSSTAT.EXE WEBSCANX.EXE ZONEALARM.EXE _AVP32.EXE _AVPCC.EXE _AVPM.EXE

If such a process is found, the worm will delete the executable file and all files contained within the same directory and subdirectories where the given file resides. If the files are in use and cannot be deleted, the file %SYSTEM%\Wininit.ini is created, and is used to delete the files when the computer restarts.

NOTE: On Windows NT/2000/XP machines, the files are deleted by usage of the following registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager

where the files to be deleted are present in the value

PendingFileRenameOperations

Removal instructions:

Symantec Security Response has posted a removal tool to assist in eradicating this worm. Please go here to read the instructions and download the removal tool:

http://securityresponse.symantec.com/avcenter/venc/data/w32.goner.a@mm.removal.tool.html

BE CAREFUL IN WHAT YOU OPEN!!!!!!!!

Huggs, Pammierose

How it changed my life:

I hope it doesnt!

You can join Unsolved Mysteries and post your own mysteries or
interesting stories for the world to read and respond to Click here

Scroll all the way down to read replies.

Show all stories by   Author:  29928 ( Click here )

Spring is coming

Replies:      
Date: 12/5/2001 7:41:00 AM  From Authorid: 10245    Thanks so much! I got it yesterday... from my cousin... I thought that the message that came on it was kind of odd, but tried to open it anyway... it wouldn't fully open, so I hope I'm safe... but I'll check this out and make sure ! :O)  
Date: 12/5/2001 7:45:00 AM  From Authorid: 4255    I have heard alot about this worm and just a few days ago I recieved this virus from a friend but deleted it without opening it Thanx  
Date: 12/5/2001 7:54:00 AM  From Authorid: 4548    thanks so much, i had 8 infected files!  
Date: 12/5/2001 8:17:00 AM  From Authorid: 27121    Thanx for the info. I haven't checked my email yet but when I'm going to, I'll watch out for those emails.  
Date: 12/5/2001 1:07:00 PM  From Authorid: 21132    Thanks for sharing this, Rony :)  
Date: 12/5/2001 2:29:00 PM  From Authorid: 10245    yep! I was infected... 4 files. Thanx again!  
Date: 12/5/2001 9:13:00 PM  ( From Author ) From Authorid: 29928    Well guys as you can see, this one is rampant...I am glad you wer able to find and zap it, before it could really do it's damage..Huggs,  
Date: 12/7/2001 5:25:00 AM  From Authorid: 600    Hiya Pammie! I bookmarked this just in case I should need it. Thank you so much for sharing this info. *hugs*  
Date: 12/7/2001 8:21:00 AM  From Authorid: 943    I updated my updated virus protection, and now it includes the Goner virus. I would HATE to lose all my info and have to start over...just to be safe I think it's time to do a backup disk!!!  
Date: 12/7/2001 9:27:00 AM  From Authorid: 28193    Thanks for sharing this with us.~Golden Taxi.  
Date: 12/7/2001 9:43:00 AM  From Authorid: 46704    Thanks for sharing this! Cloudfire  
Date: 12/7/2001 1:45:00 PM  From Authorid: 38849    Good info to have, too bad it makes it like rocket science to clean these things sometimes. LOL But, yes definately good to have info like this handy at all times. --  
Date: 12/7/2001 1:59:00 PM  From Authorid: 46068    thank you for keeping us up to date... Eagleeye  
Date: 12/7/2001 2:34:00 PM  From Authorid: 8184    Thanx for this important info Pammie Rose!  

Find great Easter stories on Angels Feather
Information Privacy policy and Copyrights

Renasoft is the proud sponsor of the Unsolved Mystery Publications website.
See: www.rensoft.com Personal Site server, Power to build Personal Web Sites and Personal Web Pages
All stories are copyright protected and may not be reproduced in any form, except by specific written authorization
Other Cool Sites:
demo.mysterypalace.com 
demo.thefireman.biz 
demo.myspaceonline.org 
demo.god-jesus-and-angels.com 
demo.towerwebserver.com 
demo.poetryandlove.com 
demo.ezrlty.com 
demo.businessmoneybusiness.com 
demo.bestsportsplace.com 
demo.thetimehascom.com 
Awesome Free Web Graphics 
Favorite Grapic Quotes 
Greetings in Glittery Text 
Your name in Glittery Text 
www.thehomebusinessindex.com 
www.diet-food-weightloss-health.com 
www.investingandinvestments.com 
www.cancerinformationworld.com 
www.datinglovematchmaking.com 
www.creditinformationworld.com 
www.insurancelinksdirect.com 
www.ilovemysteries.com 
www.casinopokergambleing.com 
www.make-money-while-sleeping.com 
www.vacation-travel-cruse-deals-information.com 


.

Pages:287 222 898 532 146 55 374 778 586 398 1152 1424 1309 251 729 877 789 687 1593 179 806 870 743 828 163 889 419 1405 16 174 24 1000 1598 1130 1252 1434 1143 353 809 287 1212 1061 1141 322 17 318 757 109 346 658 957 1052 1290 1309 154 411 1565 1021 1399 731 41 1289 1109 462 1463 377 589 991 176 546 358 1257 1054 1276 1274 788 822 893 1260 1515 181 194 428 405 333 69 202 81 1509 1131