|
Detection files published:
04 Dec 2001 |
Description created:
2001-12-04 |
Description updated:
2002-03-13 |
|
Alias:
|
Spreading mechanism
Email, Other | |
|
Payload:
Deletes antivirus files | ||
When executed, it will first display a small animated picture, which will be immediately followed by an error message.



The worm copies itself to the Windows system directory under the name GONE.SCR and sets the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run to point to this.
If ICQ is installed on the infected computer, the worm will attempt to send itself to other ICQ users online.
Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.
| Utilisation | Titre | Commentaire |
|---|---|---|
| Stopper la propagation des virus sur les partages réseau | ||
| Cleaning of back-up folders on Windows Me and XP |