Internet Security Systems suggest the following cleanup for the Goner worm W32.goner.a@mm:
Delete the following registry key created by Goner:
HKEY_LOCAL_MACHINE\SoftwareMicrosoft\Windows\CurrentVersion\Run\%System%\gone.scr = %System%\gone.scr
Delete the Gone.SCR file. Depending on system configuration, it will be in:
C:\WINDOWS\system\ or C:\WINNT\system32\
Requires Free Membership to View
SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!
Michael S. Mimoso, Editorial Director