Advertisement
Promo

Online business Toolkit

Magistr.B's European focus baffles experts

Wendy McAuliffe ZDNet.co.uk

Published: 05 Sep 2001 12:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UPDATE Europe has been hit by a new, even more destructive variant of the Magistr virus, but so far America has baffled experts by remaining immune.

The Magistr.B virus arrives as an email, and is contained in an executable file entitled readme.exe. While it does not appear to have spread as widely as its predecessor, observers say it could cause more damage to those who have been infected. Magistr.A itself remains active, with UK security firm MessageLabs detecting 93,000 cases since 14 March, including 28,000 cases in the UK.

Security firms say that there is no reason why the US should not see a Magistr.B infection, raising the possibility that an outbreak could still occur there. "I can't understand why [Magistr.B] is not going to the US -- we can never tell where such a virus is going to go, as the world has no boundaries with an email-borne worm," said Peter Cooper, UK support manager at antivirus firm Sophos.

Magistr.B spreads by email and generates random subject lines and body texts, and attaches itself as a random file with an .exe, .bat, .bif, .pif or.com extension. Unlike the typical mass-mailing virus, the new variant can pull addresses from the files of several email clients, including Outlook, Outlook Express, Eudora, Netscape Messenger and some Web-based email clients.

The trend in .exe email viruses is growing steadily, due to the ease with which modified versions of existing worms can be created. "With email viruses, you receive an email as well as an actual copy of the virus," said Cooper. "It is apparent that it is a virus by its .vbs or .doc extension. People who receive one may decide to tweak it for their own deviance, and call it their own."

This approach was used for the virulent Loveletter worm, which was written in plain text English -- making it simple for anyone to make minor variations.

Virus experts suspect that the variant was not created by the same author as the original. Cooper speculated that Magistr.B may have originated from the US, but was sent to Europe as a diversion tactic.

Like the original worm, Magistr.B overwrites hard drives, erases CMOS and flashes the BIOS on the affected system, rendering the computer unusable. It adds the ability to infect Eudora address books and disable the ZoneAlarm personal firewall before connecting to the Internet.

See the Viruses and Hacking News Section for the latest headlines.

See the Internet News Section for full coverage.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
36 out of 52 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters