|
VIRUS ALERT (General Discussion)
VIRUS ALERT // General Discussion
Dec 5, 2001, 6:36am
McAfee.com has seen an OUTBREAK of computers infected with
W32/Goner at MM, also known as Pentagone, Goner or Gone. This
is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
email and ICQ instantmessaging programs. This mass-mailing
worm will arrive from someone you know with the following
email message:
Subject: Hi
Body: How are you ?
When I saw this screen saver, I immediately thought about you
I am in a harry, I promise you will love it!
Attachment: GONE.SCR
Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
opened, it will look for a variety of anti-virus, firewall
and other security programs and attempt to delete them,
along with ALL FILES in the same directory. This worm
will also place a trojan, REMOTE32.INI, on the system, which
contains instructions to attempt Denial-of-Service attacks
on other IRC users.
For detection and removal instructions for the
W32/Goner at MM virus, click here.
===> http://www.mcafee.com/anti-virus/viruses/Goner/default.asp
Dec 5, 2001, 7:46pm
> This worm
> will also place a trojan, REMOTE32.INI, on the system, which
> contains instructions to attempt Denial-of-Service attacks
> on other IRC users.
>
Just a note: This does require mirc to be installed on the machine.
Dec 6, 2001, 1:07am
Just a note scr files cant do that :)
--
- - - - - - - - - - - - - -
TrekkerX
Commatron & Athnex
http://www.commatron.com
http://www.athnex.com
[View Quote]"evil overlord" <bob at thespire.net> wrote in message
news:3c0e9598$1 at server1.Activeworlds.com...
>
> Just a note: This does require mirc to be installed on the machine.
>
>
|
Dec 6, 2001, 2:18am
do you really think its a .scr file?
[View Quote]"trekkerx" <zac at commatron.com> wrote in message
news:3c0ee0e9$1 at server1.Activeworlds.com...
> Just a note scr files cant do that :)
>
> --
>
>
> - - - - - - - - - - - - - -
> TrekkerX
> Commatron & Athnex
> http://www.commatron.com
> http://www.athnex.com
> "evil overlord" <bob at thespire.net> wrote in message
> news:3c0e9598$1 at server1.Activeworlds.com...
>
>
|
Dec 6, 2001, 2:22am
I've had this e-mail sent to me twice already, meaning someone with me in
their address book was infected.
Anyway, the attachment in both of mine were:
gone.zlq of 39.0kb in size.
--
_________________________________________
Anduin Lothario
ICQ#:17962714
SMS: +278314217962714
More ways to contact me:
http://wwp.icq.com/17962714
http://www.anduin-lothario.com
_________________________________________
[View Quote]"syko" <sykofreak169 at msn.com> wrote in message
news:3c0ef19e at server1.Activeworlds.com...
> do you really think its a .scr file?
> "trekkerx" <zac at commatron.com> wrote in message
> news:3c0ee0e9$1 at server1.Activeworlds.com...
>
>
|
Dec 6, 2001, 2:45am
..scr files are screen savers, they are programs like the others and can do whatever they want.
Fox Mc Cloud
"trekkerx" <zac at commatron.com> a écrit dans le message news: 3c0ee0e9$1 at server1.Activeworlds.com...
> Just a note scr files cant do that :)
Dec 6, 2001, 3:02am
I got this virus sent to me once.. it was gone.scr
[View Quote]"anduin lothario" <anduin at anduin-lothario.com> wrote in message
news:3c0ef281 at server1.Activeworlds.com...
> I've had this e-mail sent to me twice already, meaning someone with me in
> their address book was infected.
> Anyway, the attachment in both of mine were:
> gone.zlq of 39.0kb in size.
>
> --
> _________________________________________
> Anduin Lothario
> ICQ#:17962714
>
> SMS: +278314217962714
> More ways to contact me:
> http://wwp.icq.com/17962714
> http://www.anduin-lothario.com
> _________________________________________
>
> "syko" <sykofreak169 at msn.com> wrote in message
> news:3c0ef19e at server1.Activeworlds.com...
>
>
|
Dec 6, 2001, 3:17am
They can do a lot... I know ive made a few myself.. But scr files are
limited to what they can do by windows... they cant edit vitial infomation
or shutdown computers
--
- - - - - - - - - - - - - -
TrekkerX
Commatron & Athnex
http://www.commatron.com
http://www.athnex.com
[View Quote]"foxmccloud" <FoxMcCloud at cyberbrain.com> wrote in message
news:3c0ef7ed$1 at server1.Activeworlds.com...
> .scr files are screen savers, they are programs like the others and can do
whatever they want.
>
> Fox Mc Cloud
>
> "trekkerx" <zac at commatron.com> a écrit dans le message news:
3c0ee0e9$1 at server1.Activeworlds.com...
>
>
|
Dec 6, 2001, 6:48am
An scr is just a renamed exe designed to operate in the windows root
directory. The program can be made to do anything, including anything
available in the windows api.
Play music, change file, examine your hard drive, close down windows
anything.
Thats why most virus checkers and zone alarm will auto rename and
quarantine and .scr file before it gets into your system because they
can also autorun.
Moria
[View Quote]On 6 Dec 2001 00:17:54 -0500, "trekkerx" <zac at commatron.com> wrote:
|
>They can do a lot... I know ive made a few myself.. But scr files are
>limited to what they can do by windows... they cant edit vitial infomation
>or shutdown computers
>
Dec 6, 2001, 12:05pm
*comment* why do people waste talent on making things that will hurt other:(
[View Quote]"data21" <dbmiller at kiski.net> wrote in message
news:3c0ddc90 at server1.Activeworlds.com...
> McAfee.com has seen an OUTBREAK of computers infected with
> W32/Goner at MM, also known as Pentagone, Goner or Gone. This
> is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
> email and ICQ instantmessaging programs. This mass-mailing
> worm will arrive from someone you know with the following
> email message:
>
> Subject: Hi
>
> Body: How are you ?
> When I saw this screen saver, I immediately thought about you
> I am in a harry, I promise you will love it!
>
> Attachment: GONE.SCR
>
> Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
> opened, it will look for a variety of anti-virus, firewall
> and other security programs and attempt to delete them,
> along with ALL FILES in the same directory. This worm
> will also place a trojan, REMOTE32.INI, on the system, which
> contains instructions to attempt Denial-of-Service attacks
> on other IRC users.
>
> For detection and removal instructions for the
> W32/Goner at MM virus, click here.
> ===> http://www.mcafee.com/anti-virus/viruses/Goner/default.asp
>
>
|
Dec 6, 2001, 10:22pm
Yeah, I get these viruses all the time. You have to stay on your toes.
[View Quote]"xelnaga" <eric at disaxiom.net> wrote in message
news:3c0efbcc$1 at server1.Activeworlds.com...
> I got this virus sent to me once.. it was gone.scr
>
>
> "anduin lothario" <anduin at anduin-lothario.com> wrote in message
> news:3c0ef281 at server1.Activeworlds.com...
in
machine.
>
>
|
Dec 6, 2001, 11:39pm
I know that ive made them... But windows wont allow deletion of certain
files... also most virus/trojan scanners will detect anything thats massivly
deleting files that wasnt done using a certain program and stuff
--
- - - - - - - - - - - - - -
TrekkerX
Commatron & Athnex
http://www.commatron.com
http://www.athnex.com
[View Quote]"donna" <awedonna at hotmail.com> wrote in message
news:3c0f7b27 at server1.Activeworlds.com...
> *comment* why do people waste talent on making things that will hurt
other:(
> "data21" <dbmiller at kiski.net> wrote in message
> news:3c0ddc90 at server1.Activeworlds.com...
>
>
|
Dec 7, 2001, 1:42pm
Instead of arguing that this thing can't do what was said it DOES do...
check out www.sarc.com. Yes, it does delete program files.
Casay
[View Quote]"trekkerx" <zac at commatron.com> wrote in message
news:3c101ddb$1 at server1.Activeworlds.com...
> I know that ive made them... But windows wont allow deletion of certain
> files... also most virus/trojan scanners will detect anything thats
massivly
> deleting files that wasnt done using a certain program and stuff
>
> --
>
>
> - - - - - - - - - - - - - -
> TrekkerX
> Commatron & Athnex
> http://www.commatron.com
> http://www.athnex.com
> "donna" <awedonna at hotmail.com> wrote in message
> news:3c0f7b27 at server1.Activeworlds.com...
> other:(
>
>
|
Dec 8, 2001, 10:58pm
Yeah....and theres enough proof that it is destructive. I heard about it
from my dad (he's subscribed to McAffee's thing) and then later from one of
my TechTV newsletters....I must be scared tho (I have mIRC, ICQ, and Outlook
Express here...perfect target me >_<) because I had this dream that I was on
ICQ and I got this message from someone and then I left the message open too
long and it unleashed the virus on my comp. Of course I know its spread thru
e-mail but I've heard it goes thru ICQ too.
--
Captain MAD Mike
-Governor, PC Addict, Odd Man
[View Quote]"casay" <casay2 at attbi.com> wrote in message
news:3c10e34a$1 at server1.Activeworlds.com...
| Instead of arguing that this thing can't do what was said it DOES do...
| check out www.sarc.com. Yes, it does delete program files.
| Casay
| "trekkerx" <zac at commatron.com> wrote in message
| news:3c101ddb$1 at server1.Activeworlds.com...
| > I know that ive made them... But windows wont allow deletion of certain
| > files... also most virus/trojan scanners will detect anything thats
| massivly
| > deleting files that wasnt done using a certain program and stuff
| >
| > --
| >
| >
| > - - - - - - - - - - - - - -
| > TrekkerX
| > Commatron & Athnex
| > http://www.commatron.com
| > http://www.athnex.com
| > "donna" <awedonna at hotmail.com> wrote in message
| > news:3c0f7b27 at server1.Activeworlds.com...
| > > *comment* why do people waste talent on making things that will hurt
| > other:(
| > > "data21" <dbmiller at kiski.net> wrote in message
| > > news:3c0ddc90 at server1.Activeworlds.com...
| > > > McAfee.com has seen an OUTBREAK of computers infected with
| > > > W32/Goner at MM, also known as Pentagone, Goner or Gone. This
| > > > is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
| > > > email and ICQ instantmessaging programs. This mass-mailing
| > > > worm will arrive from someone you know with the following
| > > > email message:
| > > >
| > > > Subject: Hi
| > > >
| > > > Body: How are you ?
| > > > When I saw this screen saver, I immediately thought about you
| > > > I am in a harry, I promise you will love it!
| > > >
| > > > Attachment: GONE.SCR
| > > >
| > > > Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
| > > > opened, it will look for a variety of anti-virus, firewall
| > > > and other security programs and attempt to delete them,
| > > > along with ALL FILES in the same directory. This worm
| > > > will also place a trojan, REMOTE32.INI, on the system, which
| > > > contains instructions to attempt Denial-of-Service attacks
| > > > on other IRC users.
| > > >
| > > > For detection and removal instructions for the
| > > > W32/Goner at MM virus, click here.
| > > > ===> http://www.mcafee.com/anti-virus/viruses/Goner/default.asp
| > > >
| > > >
| > >
| > >
| >
| >
|
|
Dec 8, 2001, 11:48pm
Umm, the virus can be sent through anything, if I were to save the virus
file to disk (which I have), and I sent you the file through ActiveWorlds,
it would do much the same thing.
[View Quote]"captain mad mike" <cmm at swcity.net> wrote in message
news:3c12b722 at server1.Activeworlds.com...
> Yeah....and theres enough proof that it is destructive. I heard about it
> from my dad (he's subscribed to McAffee's thing) and then later from one
of
> my TechTV newsletters....I must be scared tho (I have mIRC, ICQ, and
Outlook
> Express here...perfect target me >_<) because I had this dream that I was
on
> ICQ and I got this message from someone and then I left the message open
too
> long and it unleashed the virus on my comp. Of course I know its spread
thru
> e-mail but I've heard it goes thru ICQ too.
>
> --
> Captain MAD Mike
> -Governor, PC Addict, Odd Man
> "casay" <casay2 at attbi.com> wrote in message
> news:3c10e34a$1 at server1.Activeworlds.com...
> | Instead of arguing that this thing can't do what was said it DOES do...
> | check out www.sarc.com. Yes, it does delete program files.
> | Casay
> | "trekkerx" <zac at commatron.com> wrote in message
> | news:3c101ddb$1 at server1.Activeworlds.com...
> | > I know that ive made them... But windows wont allow deletion of
certain
> | > files... also most virus/trojan scanners will detect anything thats
> | massivly
> | > deleting files that wasnt done using a certain program and stuff
> | >
> | > --
> | >
> | >
> | > - - - - - - - - - - - - - -
> | > TrekkerX
> | > Commatron & Athnex
> | > http://www.commatron.com
> | > http://www.athnex.com
> | > "donna" <awedonna at hotmail.com> wrote in message
> | > news:3c0f7b27 at server1.Activeworlds.com...
> | > > *comment* why do people waste talent on making things that will hurt
> | > other:(
> | > > "data21" <dbmiller at kiski.net> wrote in message
> | > > news:3c0ddc90 at server1.Activeworlds.com...
> | > > > McAfee.com has seen an OUTBREAK of computers infected with
> | > > > W32/Goner at MM, also known as Pentagone, Goner or Gone. This
> | > > > is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
> | > > > email and ICQ instantmessaging programs. This mass-mailing
> | > > > worm will arrive from someone you know with the following
> | > > > email message:
> | > > >
> | > > > Subject: Hi
> | > > >
> | > > > Body: How are you ?
> | > > > When I saw this screen saver, I immediately thought about you
> | > > > I am in a harry, I promise you will love it!
> | > > >
> | > > > Attachment: GONE.SCR
> | > > >
> | > > > Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
> | > > > opened, it will look for a variety of anti-virus, firewall
> | > > > and other security programs and attempt to delete them,
> | > > > along with ALL FILES in the same directory. This worm
> | > > > will also place a trojan, REMOTE32.INI, on the system, which
> | > > > contains instructions to attempt Denial-of-Service attacks
> | > > > on other IRC users.
> | > > >
> | > > > For detection and removal instructions for the
> | > > > W32/Goner at MM virus, click here.
> | > > > ===> http://www.mcafee.com/anti-virus/viruses/Goner/default.asp
> | > > >
> | > > >
> | > >
> | > >
> | >
> | >
> |
>
>
|
Dec 9, 2001, 1:54am
thyre just a renamed exe i dont think there are any limits on them
[View Quote]"trekkerx" <zac at commatron.com> wrote in message
news:3c0eff82 at server1.Activeworlds.com...
> They can do a lot... I know ive made a few myself.. But scr files are
> limited to what they can do by windows... they cant edit vitial infomation
> or shutdown computers
>
> --
>
>
> - - - - - - - - - - - - - -
> TrekkerX
> Commatron & Athnex
> http://www.commatron.com
> http://www.athnex.com
> "foxmccloud" <FoxMcCloud at cyberbrain.com> wrote in message
> news:3c0ef7ed$1 at server1.Activeworlds.com...
do
> whatever they want.
> 3c0ee0e9$1 at server1.Activeworlds.com...
>
>
|
Dec 9, 2001, 6:02pm
yes had that one luckerly Norton stopped it ariving and i promtly deleted it
and cleaned system.
Just shows folks, keep your virus checker unpdated.
[View Quote]"data21" <dbmiller at kiski.net> wrote in message
news:3c0ddc90 at server1.Activeworlds.com...
> McAfee.com has seen an OUTBREAK of computers infected with
> W32/Goner at MM, also known as Pentagone, Goner or Gone. This
> is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
> email and ICQ instantmessaging programs. This mass-mailing
> worm will arrive from someone you know with the following
> email message:
>
> Subject: Hi
>
> Body: How are you ?
> When I saw this screen saver, I immediately thought about you
> I am in a harry, I promise you will love it!
>
> Attachment: GONE.SCR
>
> Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
> opened, it will look for a variety of anti-virus, firewall
> and other security programs and attempt to delete them,
> along with ALL FILES in the same directory. This worm
> will also place a trojan, REMOTE32.INI, on the system, which
> contains instructions to attempt Denial-of-Service attacks
> on other IRC users.
>
> For detection and removal instructions for the
> W32/Goner at MM virus, click here.
> ===> http://www.mcafee.com/anti-virus/viruses/Goner/default.asp
>
>
|
|