Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:I-Worm.Gokar [Kaspersky], W32/Gokar-A [Sophos], W32/Gokar@MM [McAfee], WORM_GOKAR.A [Trend], Win32.Gokar [Computer Associates]
Type:Worm 
Size:14,336 Bytes 
Origin: 
Date:00-00-0000 
Damage:Sent by email. 
VDF Version:  
Danger:Low 
Distribution:Low 

DistributionThe worm adds the email user name at the end of the email text and sends it to all addresses in Outlook. The email has the following structure:

Subject:
If I were God and didn't belive in myself would it be blasphemy
The A-Team VS KnightRider ... who would win ?
Just one kiss, will make it better. just one kiss, and we will be alright.
I can't help this longing, comfort me.
And I miss you most of all, my darling ...
... When autumn leaves start to fall
It's dark in here, you can feel it all around. The underground.
I will always be with you sometimes black sometimes white ...
.. and there's no need to be scared, you re always on my mind.
You just take a giant step, one step higher.
The air will hold you if you try, trust my wings of desire. Glory, Glorified.......


Body:
Happy Birthday
Yeah ok, so it's not yours it's mine :)
The horizons lean forward, offering us space to place new steps of change.
I like this calm, moments before the storm
Darling, when did you fall..when was it over ?
Will you meet me .... and we'll fly away ?!
You should like this, it could have been made for you
speak to you later
They say love is blind ... well, the attachment probably proves it.
Pretty good either way though, isn't it ?
still cause for a celebration though, check out the details I attached
This made me laugh
Got some more stuff to tell you later but I can't stop right now
so I'll email you later or give you a ring if thats ok ?!
Speak to you later

Attachment: random lines and parts of the following strings:
tgfdfg
jhfxvc
cgfd2
trevc
t6tr
ffdasf
glkfh
fhjdv
qesac
kujzv
weafs
twat
rewfd
gfdsf
gbv
fdsc
p0olik
3tgf
rf43dr
t54refd
ut545a
r4354gkjw
vgrewu
xw54re
y343rv
z3vdf

and the extension: .pif scr .exe .com .bat

Technical DetailsThe worm is copied in \Windows directory as Karen.exe. It makes the following autostart entry in the registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Karen c:\%WinDIR%\karen.exe

Then it looks for C:\Mirc directory. If it can find it, it creates the file Script.ini within.

It also looks for C:\inetpub\wwwroot directory and creates Web.exe within.

Then, it renames the file Default.htm in Redesi.htm and creates a new file named Default.htm containing the following text:
"We Are Forever
Anyone who views this page will be asked to download the Web.exe file."
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .