W32.Magistr.39921@mm
Discovered on: September 3, 2001
Last Updated on: March 8, 2002 at 07:31:44 AM PST
Printer-friendly version Tell a Friend
Due to an increased number of submissions, Symantec has upgraded this virus to a Category 3 rating on September 6, 2001.
W32.Magistr.39921@mm is a variant of W32.Magistr.24876@mm.
Also Known As: I-Worm.Magistr.b, W32.Magistr.B@mm, W32/Magistr.b@MM, Magistr.32768@mm, PE_Magistr.B, W95/Magistr.28672@mm
Type: Virus, Worm
Infection Length: 39,921 bytes
Virus Definitions (Intelligent Updater): September 4, 2001
Virus Definitions (LiveUpdateTM): September 4, 2001
Wild:
Number of infections: 50 - 999
Number of sites: 3 - 9
Geographical distribution: Medium
Threat containment: Moderate
Removal: Moderate
Damage:
Payload:
Large scale e-mailing: Uses email addresses from the Windows and Eudora Address Book files, Outlook Express Sent Items folder, and Netscape Sent Items files.
Causes system instability: Overwrites hard drives, erases CMOS, flashes the BIOS.
Releases confidential info: It could send confidential Microsoft Word documents to others.
Distribution:
Subject of email: Randomly generated text that can be up to 60 characters long.
Name of attachment: One randomly named infected executable and several randomly selected text or document files
Target of infection: All Windows PE files that are not .dll files.
Technical description:
Here is a list of the additional features and behavioral differences between W32.Magistr.39921@mm and W32.Magistr.24876@mm:
Aware of Eudora address books (listed in Eudora.ini.)
Deletes *.ntz while searching for files.
Attempts to disable ZoneAlarm's user interface (this does not disable the ZoneAlarm firewall functionality).
Adds an entry to the Shell=explorer.exe line in the Boot section of System.ini, calling the W32.Magistr.Trojan. In some cases, it may add one or more registry entries.
Searches for more Windows folders (Winnt, Windows, Win95, Win98, Winme, Win2000, Win2k, Winxp.)
Emails an attachment that has a random extension (.exe, .bat, .pif, or .com.)
Occasionally attaches .gifs to emails.
The payload overwrites the files Ntldr (Windows NT/2000/XP) and Win.com (all Windows 32 OSs) on all drives with code that causes it to store garbage data in the first sector of the first IDE hard drive.
Removal instructions:
To remove W32.Magistr.39921@mm and the Trojan that it drops, run NAV and repair any infected files. Files that cannot be repaired should be deleted. Then remove the W32.Magistr.Trojan entry in the Shell= line of System.ini and any entries that it added to the registry.
To remove W32.Magistr.39921@mm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. If any files are detected as infected by W32.Magistr.39921@mm, write down the file names and then click Repair. Files that cannot be repaired should be deleted. If necessary, restore any deleted files from a clean backup.
CAUTION: Files detected as W32.Magistr.Trojan (note the Trojan extension) must be restored from backup copies or extracted from the original installation CD. (These are the system files Ntldr and Win.com. Ntldr is found on Windows NT/2000/XP computers. Win.com is found on all Windows 32 OSs). Your system will not function properly without them. For information on how to do this, refer to your Windows documentation, or to one of the following documents:
How to extract files in Windows 98 and Windows Me.
How to extract files using Windows 2000 or Windows NT 4.0.
To remove the W32.Magistr.Trojan entry from the System.ini:
1. During the scan with NAV, note the name of any files infected by W32.Magistr.Trojan.
2. Click Start, and click Run.
3. Type the following, and then click OK.
edit c:\windows\system.ini
The MS-DOS Editor opens.
NOTE: If Windows is installed in a different location, make the appropriate path substitution.
4. In the [boot] section of the file, look for the following entry
shell=Explorer.exe
5. Position the cursor immediately to the right of Explorer.exe.
6. Press Shift+End to select all of the text to the right of Explorer.exe and then press Delete.
7. Click File, and Exit.
8. Click Yes when you are prompted whether to save the changes.
NOTE: If you still have problems after following these removal instructions, follow the instructions in the Removal section of W32.Magistr.24876@mm.
To edit the registry:
CAUTION: We strongly recommend that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify only the keys that are specified. Read the document How to back up the Windows registry for instructions.
1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:
HKEY_Local_Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
4. In the right pane, look for a value that has a random file name with the .exe extension, and that points to the \WinNT\System or \Windows\System folder. This may be the name of a file that was detected as W32.Magistr.39921@mm when you ran the full system scan.
5. Delete any such values that you find.
6. Do one of the following:
If you are running Windows 95/98/Me, click Registry, and then click Exit.
If you are running Windows NT/2000/XP, go on the step 7.
7. Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon
8. In the right pane, double-click the following value:
Shell
9. Look in the value data box. It should contain only the text Explorer.exe, as shown.
10. If it contains any text to the right of Explorer.exe, for example, warm.exe,
remove that text so that only Explorer.exe remains, as shown in step 9.
11. Click Registry, and then click Exit.