[Am-info] Symantec Security Response - W32.Goner.A@mm

Fred A. Miller fm@cupserv.org
Tue, 4 Dec 2001 17:17:13 -0500


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Symantec Security Response - W32.Goner.A@mm

Due to the increased rate of submission and level of damage, Symantec 
Security Response is upgrading W32.Goner.A@mm from Category 3 to 
Category 4. 

W32.Goner.A@mm is a mass-mailing worm that is written in Visual Basic. 
The worm has been compressed using a known Portable Executable (PE)* 
file compressor. The worm can spread its infection using the ICQ 
network as well as by email using Microsoft Outlook. If IRC is 
installed, this worm can also insert mIRC scripts that will enable the 
computer to be used in Denial of Service (DOS) attacks.

Type: Worm 

Infection Length: 38,912 bytes 

Virus Definitions: December 4, 2001  
http://www.symantec.com/avcenter/venc/data/w32.goner.a@mm.html

- -- 
Fred A. Miller
Systems Administrator
Cornell Univ. Press Services
fm@cupserv.org

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8DUtpIhTtc6nTZIIRAv53AJ0U3A+x8i5QgeDHZhJV7iSaBQW2hACglG2E
1nzLAN8JZeHlxu5DMfRoIX0=
=6U4p
-----END PGP SIGNATURE-----