Latest WinWorm Spreads Via ICQ And Outlook
mgooderum was among the many to write in about yet another snippet of malice making the Windows desktop rounds: "The latest email virus -- 'Goner' -- is apparently running around this morning (AP news story on Iwon here - no login needed). The virus is a typical worm that spreads via attachments and user's address books. It appears as a message with an attachment that starts: 'How are you ? When I saw this screen saver I immediately thought about you...' Goner is apparently non-destructive other than the normal DoS issues with the load from it forwarding itself everywhere. What's moderately unique are two features. One is its ability to replicate via ICQ as well as the usual Outlook and Outlook Express. Two is its small size -- it has a packed form that is only 159 bytes. Symantec has details here; McAfee has details here." Update: 12/04 21:57 GMT by T : That should read 159 kilobytes. And as many posters have pointed out, "destructive" is in the eye of the beholder.
It is not non-destructive - it tries to delete anti-virus and firewall software.
Eric Aitala
www.f1m.com
has already sent every one of my fellow employees all over the globe 27 copies of this thing.
.scr.
It's been going on for over two hours now. I can't help but wonder if he's still over there trying to run that damn
Thanks, boss.
Personal me, collaborative you
The story had a few errors:
it has a packed form that is only 159 bytes.
Actually the attachment is 38KB, and the virus itself is 159 KILObytes, not 159 bytes, UNPACKED.
The unique thing about it is it disables some anti-virus software, and things like ZoneAlarm.
As soon as virus writers learn how to spell correctly and learn proper grammar, I think we're going to be in some serious trouble.
"And like that
Didn't everyone get the memo that opening attachments is a really dumb idea? I'm attaching the original message:
<Attachment: Don't_Open_Attachments.eml.vbs>
I just got the warning message from my school's network goons. In a move of administrative widsom at its finest, it mentioned:
"The Bearcat Online email system is now blocking all messages with "Hi" as the subject."
Our office blocks .scr attachments at the server, because we're not completely incompetent. There's no reason to send a .scr or a .vbs or anything like unto it - whatever you have to say could be said in a text file.
It strikes me as extremely sad that a virus like this can still work. How many times does it take?
What can we do to save the unknowing?
Let's not stir that bag of worms...
It says you have to remove the registry entry then reboot. Actually, if you remove the registry entry, the app reinstalls itself, then reboot doesn't do shit.
Shutdown to DOS, then del windows\system\gone.scr
(It's hidden attrib -s-r-h first), then reboot.
You can't delete it before you shutdown, it's 'in-use'.
If you're running NTFS, AND you've been hit, *sigh*..
"I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
Well, since McAfee and Symantec are reporting it, I guess this is not a first draft of magic lantern... unless they issue another press release in 45 minutes saying "um... nevermind, there is no 'Goner' worm."
The problem is there's *nothing* Microsoft can do to stop this sort of virus, as long as they allow execution of files direct from their email client, and honestly I can't see that stopping (and neither can the people where I work, which they're quite happy about :-)
I do worry for apps like this on Linux though, as email clients become able to execute attachments. But the benefit is that Linux doesn't assume things based on file suffix, but on their actual mime type. However, that still leaves a possible vulnerability to mime type spoofing, perhaps.
Matt. Want XML + Apache + Stylesheets? Get AxKit.
I am ashamed that anyone would intentionally use my Slashdot account name to bolster the popularity and reputation of their sick virus. I'm sure the hackers who created this monstrosity were well versed in such hacker tools as Bonzi Buddy and Lunix. If they think I would come out and support such a destructive screen saver they are very, very wrong. If God wanted toasters to fly, he would have given them wings.
So, you hackers, where ever you are, Goner (of Slashdot lore) does not approve!
You'd use MoveFileEx to get rid of the file, like so--
// buffer for system directory
// size of directory buffer
// string with environment variables
// string with expanded strings
// maximum characters in expanded string
MoveFileEx("C:\\WINNT\\System32\\Gone.scr", NULL, MOVEFILE_DELAY_UNTIL_REBOOT);
The combination of MOVEFILE_DELAY_UNTIL_REBOOT and a NULL lpNewFileName creates a special condition where Windows deletes the file at startup. This is commonly used by installers, for example, when a file is in use and DeleteFile fails. For anyone going through the trouble of putting this into an executable, you might want to grab the Windows system directory from Windows itself.. this can be done using GetSystemDirectory (prototyped as--
UINT GetSystemDirectory(
LPTSTR lpBuffer,
UINT uSize
);
) or you could be clever and use ExpandEnvironmentStrings, prototyped as--
DWORD ExpandEnvironmentStrings(
LPCTSTR lpSrc,
LPTSTR lpDst,
DWORD nSize
);
Shrug. =) Just thought this might help, for those unable to figure out how to delete a file in NTFS (but that do have a C/C++ or other compatible compiler).
All I know about Bush is I had a good job when Clinton was president.