|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Magistr.B is a dangerous variation By Robert Vamosi, 0 September 05, 2001 URL: http://www.zdnet.com.au/news/soa/Magistr-B-is-a-dangerous-variation/0,139023165,120258669,00.htm
Designed to bypass current antivirus scanners, this variation can spread via Eudora, Outlook, Netscape and other Internet email clients. A new version of the polymorphic worm Magistr is lurking on the Internet. This new variation, Magistr.B (w32.Magistr.39921), has been reworked to evade most current antivirus software scanners. Like the original worm, Magistr.B features a payload that overwrites hard drives with garbage, erases CMOS and flashes the BIOS on the infected system, rendering the computer unusable. Unlike the original worm, Magistr.B can also infect Eudora address books and terminate the popular ZoneAlarm firewall before connecting to the Internet.
How it works Subject: [random] Body: [random] Attached: [random file with an exe, bat, pif, com extension] When executed, Magistr.B displays the following message from the original Magistr worm.
YOU THINK YOU ARE GOD , BUT YOU ARE ONLY A CHUNK OF SH-- Magistr.B then searches for all sent email addresses from Eudora, Outlook, Netscape Messenger and other Internet email clients, and sends randomly constructed messages to up to 100 people. Magistr.B contains its own SMTP email to send copies, bypassing Microsoft's Outlook Security Patch. Magistr.B also searches network resources, searching for Windows installations such as Windows 95, 98, Me, NT, and 2000, and infects all portable executable files found on remote systems. Magistr.B will destroy the contents of the computer's hard drive and CMOS/BIOS information on Windows 95, 98, Me, NT, and 2000 systems.
Removal
Prevention
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |