Mike Michalak
12-05-2001, 07:12 AM
Here's the latest on a virus that literally attacks your anti-virus software! We had Norton wiped off a machine here in the office with this thing...pretty nasty.
** Latest Worm Attacks Antivirus Apps
A new Visual Basic Script virus is rapidly spreading via E-
mail and the ICQ instant-messaging system, shutting down most
antivirus and desktop security apps. The worm, dubbed the
Goner virus, greets targets with the subject "Hi" and the text
reads: "How are you? When I saw this screensaver, I
immediately thought about you. I am in a hurry, I promise you
will love it!"
What users really download is Gone.scr, a copy of the
compressed worm. If the file is opened, the worm tries to
destroy all security apps. A back door is installed, linked to
an Internet Relay Chat program, and the app can be used to
launch denial-of-service attacks against Internet Relay Chat
servers.
"This thing is spreading far faster than Badtrans," says Russ
Cooper, surgeon general with security firm TruSecure Corp.,
referring to another mass-mailer virus that struck users hard
over Thanksgiving weekend. Secure E-mail company MessageLabs
says it has stopped more than 30,000 copies of Goner with its
antivirus software, and the company is seeing Goner arrive
with one out of every 30 E-mails. According to MessageLabs,
the Love Bug virus arrived with one out of every 28 E-mails.
Most antivirus vendors placed Goner as a medium risk earlier
in the day, but by late Tuesday afternoon it became apparent
that Goner was spreading faster than many expected. "We don't
know why it's spreading so fast," Cooper says. "Anyone who
experienced Badtrans would have protected against .scr
attachments. "He says Goner has hit many large companies hard.
"Very few people block attachments at the gateway. And desktop
users did not have their antivirus updated, so it reached
critical mass." Given the risks, many experts are surprised
that companies let potentially dangerous attachments enter
their E-mail systems. -
** Latest Worm Attacks Antivirus Apps
A new Visual Basic Script virus is rapidly spreading via E-
mail and the ICQ instant-messaging system, shutting down most
antivirus and desktop security apps. The worm, dubbed the
Goner virus, greets targets with the subject "Hi" and the text
reads: "How are you? When I saw this screensaver, I
immediately thought about you. I am in a hurry, I promise you
will love it!"
What users really download is Gone.scr, a copy of the
compressed worm. If the file is opened, the worm tries to
destroy all security apps. A back door is installed, linked to
an Internet Relay Chat program, and the app can be used to
launch denial-of-service attacks against Internet Relay Chat
servers.
"This thing is spreading far faster than Badtrans," says Russ
Cooper, surgeon general with security firm TruSecure Corp.,
referring to another mass-mailer virus that struck users hard
over Thanksgiving weekend. Secure E-mail company MessageLabs
says it has stopped more than 30,000 copies of Goner with its
antivirus software, and the company is seeing Goner arrive
with one out of every 30 E-mails. According to MessageLabs,
the Love Bug virus arrived with one out of every 28 E-mails.
Most antivirus vendors placed Goner as a medium risk earlier
in the day, but by late Tuesday afternoon it became apparent
that Goner was spreading faster than many expected. "We don't
know why it's spreading so fast," Cooper says. "Anyone who
experienced Badtrans would have protected against .scr
attachments. "He says Goner has hit many large companies hard.
"Very few people block attachments at the gateway. And desktop
users did not have their antivirus updated, so it reached
critical mass." Given the risks, many experts are surprised
that companies let potentially dangerous attachments enter
their E-mail systems. -