Skip to main content

Goner: ICQ-loving Internet-Worm

December 5, 2001

Kaspersky Labs, an international data-security software-development company, announces the detection of a new mass mailing Internet-worm I-Worm.Goner. Reports of infection by this malicious program already have been reported in many countries throughout the world.

Kaspersky Lab, an international data-security software-development company, announces the detection of a new mass mailing Internet-worm I-Worm.Goner. Reports of infection by this malicious program already have been reported in many countries throughout the world. In order to be activated, "Goner" requires a user to manually launch the worm-carrier file (GONE.SCR) that will initiate the target-computer infection routine. To accomplish this, the worm creates its copy in the default Windows system folder under the same name (GONE.SCR), and registers this file in the start-up section of the Windows system registry. As a result, "Goner" will be activated each time the computer is rebooted.

After this, "Goner" starts its spreading routine. To make it more effective, the worm uses two data-transmission channels simultaneously: e-mail and ICQ, the popular Internet-paging software. When spreading via e-mail, "Goner" gains access to Microsoft Outlook, creates a new message that contains an infected file, GONE.SCR, and unbeknownst to the user, sends it out to all the recipients from the Outlook address book. The distributed e-mail messages appear as follows:

After the e-mail spreading is finished, the worm consequently shows the following two windows:

"Goner" also tries to spread using ICQ. When active, it continuously traces the list of online ICQ users and regularly tries to send them the worm-carrier file. To conceal its unauthorized activity with ICQ, the worm permanently scans names of newly appeared dialogue boxes, and closes down those that are ICQ system messages. In addition to spreading over the Internet, "Goner" also performs an attack on the #pentagonex IRC-channel. To accomplish this, the worm executes an additional script-program on the infected computer that regularly creates new members with random names on this channel. In some cases, this can overload the IRC channel and certainly annoys the IRC community. Protection against "Goner" already has been added to the Kaspersky Anti-Virus daily update. A more detailed description of the worm is available in the Kaspersky Anti-Virus Encyclopedia.

Goner: ICQ-loving Internet-Worm

Kaspersky Labs, an international data-security software-development company, announces the detection of a new mass mailing Internet-worm I-Worm.Goner. Reports of infection by this malicious program already have been reported in many countries throughout the world.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases