PDA

View Full Version : W32/Goner@MM Virus


Strathclyde Eagle
04-12-2001, 10:09 PM
Our office just got hit with this. McAfee are currently listing it as a high risk virus. It came in and spread very quickly indeed.

Full details here (http://vil.nai.com/vil/virusSummary.asp?virus_k=99272)

Basically look out for e-mails with the subject line "Hi" and the attachment GONE*****

Be aware, apparently if you run it as well as mailing out to everyone in your address book it will also attempt to delete the following files.

APLICA32.EXE
ZONEALARM.EXE
ESAFE.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET32.EXE
PCFWallICON.EXE
FRW.EXE
VSHWIN32.EXE
NAVW32.EXE
_AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
AVP32.EXE
AVPCC.EXE
AVPM.EXE
AVP.EXE
LOCKDOWN2000.EXE
ICLOAD95.EXE
ICMON.EXE
ICSUPP95.EXE
ICLOADNT.EXE
ICSUPPNT.EXE
TDS2-98.EXE
TDS2-NT.EXE
SAFEWEB.EXE

Just wanted to warn you all. It caught us unawares and I wouldn't like it to happen to anyone else.

Sunny Fan
04-12-2001, 10:16 PM
Happened to us as well, easy to sort and luckily I never use my outlook:)

britabroad
04-12-2001, 10:18 PM
Yep, got this in Canada too.

Steve in Phoenix
04-12-2001, 10:22 PM
Watch out for the W32@BADTRANS too.. normally comes in with a double suffix attachment like doc.pif or doc***** - never open those! Ive been sent about 20 of them in the last couple days.

Dead Cell
04-12-2001, 11:20 PM
Why do people bother to make virus's? It just p!$$e$ people off.

NO1FAN
05-12-2001, 12:16 AM
Surely that's the point Dead!

Dead Cell
05-12-2001, 01:04 AM
Well they do a damn fine job of it :grrr:

Steve in Phoenix
05-12-2001, 01:05 AM
There's this virus I hadnt heard of.. its apparently harmless but it plays a Korean lovesong. Kinda strange but Im sure there's weirder ones out there..

The Omen
05-12-2001, 03:57 PM
Virus' are created because it gives people a sense of power. Being able to bring down major companies from the safety of your own home is quite a major thing.

I don't think people realise how big some of the virus' they create will become though. Some of the coding is so simple, I remember the Anna Kournikova one - I could have produced that in a matter of hours.

The problem is computer illiterate people opening attachments. It's not their fault but they should be explained the obvious ones not to open, like a file ending in *.vbs.

Microsoft software has so many loopholes and it doesn't take an amazing programmer much effort to exploit them.

Dead Cell
06-12-2001, 02:16 AM
Originally posted by The Omen
Virus' are created because it gives people a sense of power. Being able to bring down major companies from the safety of your own home is quite a major thing.



Yeah! Down with Establishment and Globalisational Company's thats what i say!

biggus mickus
06-12-2001, 02:53 AM
Sitting in Miramar internet cafe, in Benalmadena,Spain.
They have been hit today.
If clever bods can write these things,why not do a real job.Or are they.
Most of the crap that is chucked out over the web,is from anti-virus companys.
WE KNOW WHO YOU ARE.

Random*
06-12-2001, 04:19 AM
Originally posted by The Omen
Microsoft software has so many loopholes and it doesn't take an amazing programmer much effort to exploit them.

I think that's a bit harsh. 99.9% of hacking is opportunism, as you said yourself, the problem is people that aren't IT illiterate. I did an excercise in hacking once, with 20 pc's on a closed network, where you had to run some webpages and other services on your pc, and stop other people's services from running by whatever means (although you're not allowed to physically touch the pc). There were some expert hackers in the group.

Between a decent virus checker and a personal firewall, pretty much every attack was stopped. The people that were running Linux had the same problems as the people running MS software, and we found that most of the insecurities were down to people doing dumb things, and the insecurities in the internet protocols themselves.

redandblue
06-12-2001, 05:15 PM
We use message labs external screening and its the nutz we did not get any virus's through, as mail admin I received notification of each infected mail that was received and it numbered over 1000. Since we have had this service no virus has penetrated our mail systems this stuff is better than annadin.