W32.Magistr.39921 @mm
| Discovered on: September 3, 2001 |
| Last Updated on: September 10, 2001 at
02:27:52 PM PDT |
Due to an increased number of submissions, Symantec has upgraded this virus
to a Category 3 rating on 9/6/2001.
W32.Magistr.39921@mm is a new variant of W32.Magistr.24876@mm.
Also
Known As: I-Worm.Magistr.b, W32.Magistr.B@mm, W32/Magistr.b@MM
Type: Virus,
Worm
Infection
Length: 39,921 bytes
Virus
Definitions: September 4, 2001
Threat
Assessment:
Wild:
Damage:
Distribution:
Technical
description:
Here is a list of the additional features and behavioral differences between
W32.Magistr.39921@mm and W32.Magistr.24876@mm:
- Aware of Eudora address books (listed in Eudora.ini.)
- Deletes *.ntz while searching for files.
- Attempts to disable ZoneAlarm's user interface (this does not disable
the ZoneAlarm firewall functionality).
- Adds an enty to the Shell=explore.exe line in the Boot section of
System.ini, calling the W32.Magistr.Trojan.
- Searches for more Windows folders (Winnt, Windows, Win95, Win98, Winme,
Win2000, Win2k, Winxp.)
- Emails an attachment that has a random extension (.exe, .bat, .pif, or
.com.)
- Occasionally attaches .gifs to emails.
- The payload overwrites Ntldr.exe and Win.com on all drives with code
that causes it to store garbage data in the first sector of the first IDE
hard drive.
Removal
instructions:
To remove W32.Magistr.39921@mm and the Trojan that it drops, run NAV and delete
any infected files. Then remove the W32.Magistr.Trojan entry in the Shell= line
of System.ini.
To remove W32.Magistr.39921@mm:
1. Run LiveUpdate to make sure that you have the most recent virus
definitions.
2. Start Norton AntiVirus (NAV), and run a full system scan. Be sure that NAV
is configured to scan all files.
3. Delete all files that are detected as W32.Magistr.39921@mm. If necessary,
restore any W32.Magistr.39921@mm infected files from a clean backup.
NOTE: Files detected as W32.Magistr.Trojan must be restored from
backup copies or extracted from the original installation CD. (These are the
system files Ntldr.exe and Win.com.) Your system will not function properly
without them. For information on how to do this, refer to your Windows
documentation, or to one of the following documents:
Remove the W32.Magistr.Trojan entry from the System.ini:
1. During the scan with NAV, note the name of any files infected by
W32.Magistr.Trojan.
2. Click Start, and click Run.
3. Type the following, and then click OK.
edit c:\windows\system.ini
The MS-DOS Editor opens.
NOTE: If Windows is installed in a different location, make the
appropriate path substitution.
4. In the [boot] section of the file, look for the following entry
shell=Explorer.exe
5. Position the cursor immediately to the right of Explorer.exe.
6. Press Shift+End to select all of the text to the right of Explorer.exe and
then press Delete.
7. Click File, and Exit.
8. Click Yes when you are prompted whether to save the changes.
Write-up by: Peter Ferrie