Ask the Expert

Manual removal of Goner from infected machine

A user on our network received an e-mail infected with Goner and opened it. His virus scan doesn't work now. Is there a way to remove Goner other then formating and re-installing the OS?

    Requires Free Membership to View

You can do a manual removal of Goner by following these steps:

1. Search the hard drives and delete all instances of the file gone.scr. On Windows 95/98/ME it is best to delete it from DOS by booting the PC while pressing F8 and selecting "Command Prompt Only" mode.

After finding the file, go to its directory and use the command
ATTRIB -s -h -r gone.scr
to be able to delete it.

On Windows NT/2000 systems, boot using the Windows NT/2000 CD and select "Repair Install Console" to get to a command prompt, and follow the same steps as above to find and delete the file.

2. Using regedit.exe, find the key
HKLMSoftwareMicrosoftWindowsCurrentVersion
deleting the key entry where the name "'gone.scr" appears.


For more information on this topic, visit these other searchSecurity resources:
News: Goner worm could have been prevented
Best Web Links: Malware


This was first published in January 2002

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: