Virus Profile: W32/Magistr.b@MM

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Medium | Corporate Medium
Date Discovered: 9/3/2001
Date Added: 9/3/2001
Origin: Unknown
Length: N/A
Type: Virus
Subtype: File Infector
DAT Required: 4158
Removal Instructions
   
 
 
   

Description

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Indication of Infection

See W32/Magistr.a@MM description.

Methods of Infection

See W32/Magistr.a@MM description.

Aliases

I-Worm.Magistr.b (AVP) , PE_MAGISTR.B (Trend), Qzap195, W32.Magistr.39921@mm (NAV), W32/Magistr.b.dam1, Win32.Magistr.B (CA)
   

Virus Characteristics

This variant of W32/Magistr.a@MM is considered a medium risk due to the number of samples received by AVERT.

The variant differs in several ways.

- It uses a more complex encryption technique.
- It deletes all .NTZ files on the local machine.
- It terminates the ZoneAlarm firewall user interface process if it is running (not the entire program).
- It creates a SYSTEM.INI [boot]shell value to run itself at startup.
- It uses random file extensions on the executables which it sends (.bat, .com, .exe, .pif)
- The file name of the attachment that it sends out may be derived from a word within files on the infected system
- It has also been reported to retrieve email addresses from Eudora mailbox files (.MBX), overwrite the WIN.COM/NTLDR file with a program to erase data from the hard disk (the trojan is detected as QZap195, the WIN.COM or NTLDR must be replaced from backups), and send .GIF files found on the local machine to others along with itself.

The characteristics mentioned above are in addition to those found under the W32/Magistr.a@MM description.

   

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations