Technology Computer & Networking security

Gokar worm targets antivirus

Discovered on December 12, 2001, the Gokar worm spreads via email, IRC, and infected web servers. It also targets antivirus processes and attempts to shut them down. Gokar sends itself via email with random subject lines, random message bodies, and random attachment names, ending in BAT, COM, EXE, SCR, or PIF. When an infected attachment is opened, Gokar creates the file KAREN.EXE in the Windows folder and modifies the Registry to run the file when Windows is started.

Gokar then access the Outlook Address Book, sending itself to addresses found therein.
The worm searches for IRC software on the system and if found, replaces the mIRC chat client's SCRIPT.INI file with its own. Thereafter, infected users will unwittingly send the infected file, KAREN.EXE, to anyone who joins an IRC channel they are present on. The file is sent with the message "If this doesn't make you smile, nothing will. "

If the infected computer is a web server running either PWS (Personal Web Server) or IIS (Microsoft Internet Information Server), the worm will copy itself as WEB.EXE to the C:\inetpub\wwwroot directory. It also renames the file DEFAULT.HTM (the default homepage of the website) to REDESI.HTM and creates a new DEFAULT.HTM which offers the infected WEB.EXE to site visitors.

The Gokar worm searches for and aborts the realtime components of certain anti-virus software.
SHARE
RELATED POSTS on "Technology"
Use Online Backup to Keep Your Valuable Data Safe
Use Online Backup to Keep Your Valuable Data Safe
'Problem occurred while doing OST sync operation' Error and Recovery
'Problem occurred while doing OST sync operation' Error and Recovery
Data Recovery - Important Factors to Consider
Data Recovery - Important Factors to Consider
Email Spam Protection Quite Essential To Help Cut The Time And Money Due To Manpower Use
Email Spam Protection Quite Essential To Help Cut The Time And Money Due To Manpower Use
Remove Feed Helperbar Redirect Virus From Windows and Mac OS X
Remove Feed Helperbar Redirect Virus From Windows and Mac OS X
Check System And Get Ensure: How To Make Your Windows PC Spyware Free
Check System And Get Ensure: How To Make Your Windows PC Spyware Free
Speed Up XP Software - Download Right Now!
Speed Up XP Software - Download Right Now!
The Right Time To Use A Registry Cleaner Windows XP Optimizer
The Right Time To Use A Registry Cleaner Windows XP Optimizer
Stop Piracy and Use CD Duplication Service for Creating Largest Number of Discs
Stop Piracy and Use CD Duplication Service for Creating Largest Number of Discs
Migrate Contacts From Lotus Notes to Outlook Exchange Server 5.5 or Exchange 2000
Migrate Contacts From Lotus Notes to Outlook Exchange Server 5.5 or Exchange 2000
Guide On How To Make Low Priced But Required Components In Creating Basement Insulation For Any Time
Guide On How To Make Low Priced But Required Components In Creating Basement Insulation For Any Time
Remove Ddos Clean: To Get Rid of Fake Anti Spyware Program
Remove Ddos Clean: To Get Rid of Fake Anti Spyware Program
How to Get Rid of Spyware on My Computer
How to Get Rid of Spyware on My Computer
How to Avoid a Malware Infection?
How to Avoid a Malware Infection?
Outstanding Registry Cleaner
Outstanding Registry Cleaner
Why You Should Be Using Vipre Internet Security?
Why You Should Be Using Vipre Internet Security?
Run Data Recovery Software to Restore Data from RAW USB Hard Drive?
Run Data Recovery Software to Restore Data from RAW USB Hard Drive?
How to Remove Virus Protector Spyware Automatically-Manually
How to Remove Virus Protector Spyware Automatically-Manually
Data Recovery of IBM Drive
Data Recovery of IBM Drive
What Are the Best Registry Cleaners For Windows?
What Are the Best Registry Cleaners For Windows?
Protect Your Laptop and the Data It Holds
Protect Your Laptop and the Data It Holds

Leave Your Reply

*