By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
According to a Sophos Anti-virus alert, the Gokar worm copies itself as KAREN.EXE into the infected machine's Windows directory and creates the following registry key:
HKLM\Software\MicrosoftWindows\CurrentVersion\Run\Karen = C: