ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Four held in Israel for Goner virus

Wendy McAuliffe ZDNet.co.uk

Published: 10 Dec 2001 11:24 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Four Israeli teenagers have been remanded in custody on suspicion of writing the malicious Goner email worm, which is thought to have spread more rampantly than last year's infamous Love Letter virus.

The high school students, aged 15 and 16, were arrested on Friday night, and were expected to remain in a Tel Aviv jail until Monday. Evidence that linked the boys to the Goner worm (so called because of its reference to what it calls the "Pentagone") was presented to the Northern Branch of the Anti-Fraud Squad on Wednesday. The investigation remains in progress, but under Israeli law, the minors could face between three and five years in jail for distributing such a destructive virus code.

Antivirus firm MessageLabs has detected 6342 incidents of Goner in the last 24 hrs, and more than 133,000 international cases since the worm was first detected on 4 December.

Goner is a mass-mailing Internet worm, written in Visual Basic Script (VBS), and is compressed into the UPX (Ultimate Packer for eXecutables) format, making it harder for antivirus software to detect. It arrives as an email with the subject line "Hi", and disguises itself as a screensaver.

It contains the text: "How are you? When I saw this screensaver, I immediately thought about you. I am in a harry, I promise you will love it!"

When the file is opened in Microsoft Outlook, Goner will attempt to terminate a number of antivirus products installed on the infected computer, and will then delete all files from any directory containing files of those names. Goner also uses the Inernet Relay Chat application called mIRC to install a backdoor, which can be used to launch a Denial of Service (DoS) attack on IRC channels, and on other uses connected to the same IRC channel as the infected user.

The first incident of Goner was detected in the US last Tuesday, but antivirus companies had been receiving a large number of reports from France. The minor spelling error in the body text had indicated that the virus author was not English.

For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
40 out of 79 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Internet Team Leader

Responsibility for maintaining the integrity of the networks (i.e.providing adequate protection from viruses, spam, hacking, compliance with the Data ...

Project Manager? Love fashion?

My client is the largest online fashion and beauty store in the UK, as well as the fastest growing, and they're looking to expand their business ...

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains