Virus Characteristics
This mass mailing worm attempts to send itself using Microsoft Outlook to all entries found in the Outlook Address book. It tries to delete security software, can spread via ICQ, and drops an IRC bot script. It arrives in an email message containing the following information:
Subject: Hi
Body:
How are you ?
When I saw this screen saver, I immediately thought about you
I am in a harry, I promise you will love it!
Attachment: GONE.SCR
Running this attachment infects the local system.
When run, the worm displays a message box entitled, "About"
After a short time, another window entitled "Error" is displayed:
The worm copies itself into the "WINDOWS SYSTEM" folder and adds the following registry key to load itself at startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run\C:\%WINDIR%\%SYSTEM%\gone.scr=C:\%WINDIR%\%SYSTEM%\gone.scr
The exact location is depending on the windows installations options, but on most Windows 9x/ME systems it'll be C:\WINDOWS\SYSTEM\GONE.SCR , whereas on WinNT based systems it would be C:\WINNT\SYSTEM32\GONE.SCR.
Under Windows 9x/ME, the worm looks for the following processes in memory:
_AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
APLICA32.EXE
AVP.EXE
AVP32.EXE
AVPCC.EXE
AVPM.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET32.EXE
ESAFE.EXE
FRW.EXE
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
LOCKDOWN2000.EXE
NAVW32.EXE
PCFWallICON.EXE
SAFEWEB.EXE
TDS2-98.EXE
TDS2-NT.EXE
VSHWIN32.EXE
ZONEALARM.EXE
If present, the process is terminated and all files in the directory containing that executable are deleted, as well as all files within any subdirectories. If this action fails, the worm may create a WININIT.INI file to delete the files upon restart.
The worm attempts to copy ICQMAPI.DLL to the WINDOWS SYSTEM directory to send itself to ICQ users. DLL calls are made which send the worm to ICQ contacts which are on-line. The worm also creates the file REMOTE32.INI and modifies the mIRC MIRC.INI file to use it. This causes the mIRC client to become an IRC bot, accepting instructions to initiate a Denial of Service attack from remote IRC users who are connected to the same channel. The script connects to the server "twisted.ma.us.dal.net" and joins the channel "#pentagonex". The user does not have to be knowingly connected to this server in order for this script to join this channel, they only have to start mIRC and the script will join this channel in the background.
Note that on WinNT based systems, the virus is visible in the task manager as "pentagone". Under the process tab it should be listed as "gone.scr".