Another Virus [Archive] - Fly Fishing Forum

: Another Virus


JimW
12-04-2001, 04:44 PM
Looks like a real nasty one.
http://vil.nai.com/vil/virusSummary.asp?virus_k=99272

fredaevans
12-04-2001, 08:27 PM
I've been able to dodge the bullit so far ... should I go click and read the site? Zero on this 'crap' for years and now 5 wacks in a little over a week.

What does this one do? Or do I want to know?
:>)

fredaevans
12-05-2001, 02:10 PM
Many large companies got this little bugger in the past few days so "BE VERY CARFULL OUT THERE." Appears the first thing it does is go after you anti-virus programs and firewalls. Eliminates them and then it really goes to work. Because this 'worm' is/was so new no ones system picked up until it was already installed and doing 'it's thing.'

Would 15 years in the Gray Bar Hotel be enough?


Subject: Fw: EMERGENCY VIRUS ALERT - W32/Goner@MM

I'm passing this forward as either the bank's Lotus scan of incomeing E mails, or my home system, has caught 5, count'um 5! virus shots in my e mails in the past week. "Be careful out there!"
Fred

[This message is brought to you as a subscriber to the
McAfee.com Dispatch. To unsubscribe, please follow the
instructions at the bottom of the page.]

------------------------------------------------------------
** EMERGENCY VIRUS ALERT - W32/Goner@MM **
------------------------------------------------------------


McAfee.com has seen an OUTBREAK of computers infected with
W32/Goner@MM, also known as Pentagone, Goner or Gone. This
is a NEW, HIGH RISK virus that spreads via Microsoft Outlook
email and ICQ instantmessaging programs. This mass-mailing
worm will arrive from someone you know with the following
email message:

Subject: Hi

Body: How are you ?
When I saw this screen saver, I immediately thought about you
I am in a harry, I promise you will love it!

Attachment: GONE.SCR

Goner has a DESTRUCTIVE PAYLOAD. When the attachment is
opened, it will look for a variety of anti-virus, firewall
and other security programs and attempt to delete them,
along with ALL FILES in the same directory. This worm
will also place a trojan, REMOTE32.INI, on the system, which
contains instructions to attempt Denial-of-Service attacks
on other IRC users.

For detection and removal instructions for the
W32/Goner@MM virus, click here.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2639

McAfee.com VirusScan Online and Clinic subscribers:
If you don't have ActiveShield installed and updated, you
are not protected from this virus. Click here to download
ActiveShield.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2372

Retail VirusScan Users:
Version 4.0.70 and above with DAT file 4174 will detect and
remove this worm. To download the latest DAT files, click here.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2645


Find out more about this worm. Click here to go to the
W32/Goner@MM Help Center.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2639

Become a McAfee.com subscriber and check your system online.
Click here.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2377

Buy the latest VirusScan in the McAfee Store! Click here.
===>
http://mcafeestore.beyond.com/AF77887-VS_700/Product/0,1057,3-18-SN107852,00
.html

Is your VirusScan current? Existing VirusScan Users can buy
a one time upgrade to the latest version of VirusScan,
Click here.
===>
http://mcafeestore.beyond.com/AF77887-SMP_400/Product/0,1057,3-18-SN102899,0
0.html

Download the latest DAT files, click here.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2645


_____________________Anti-Virus Tips!_______________________

Find out how to detect and prevent viruses with these handy
tips. Click here.
===> http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=1589