Win32/Magistr virus| Name | Win32/Magistr virus | | Aliases | W32.Magistr.24876, MAGISTR.A, TROJ_ARF_JUDGE.A, ARF_JUDGE | | Discovered on | March
2001 |
Virus Information - Win32/Magistr virus:
This virus is found under 32-bit environment
(Windows 95, Windows98, Windows NT based systems). This virus also possess
worm characteristics. This virus spreads through email or file. Infected
mail contains following text string:
ARF! ARF! I GOT YOU! v1rus: Judges Disemboweler.
by The Judges Disemboweler written in Malmo (Sweden)
It can also be combination of these words:
sentences you
sentences him to
sentence you to
ordered to prison
convict
judge
circuit judge
trial judge
found guilty
find him guilty
affirmed
judgment of conviction
verdict
guilty plea
trial court
trial chamber
sufficiency of proof
sufficiency of the evidence
proceedings
against the accused
habeas corpus
jugement
Infected attachment name will be a random
name.
Opening the infected attachment, virus
will become memory resident. It infects Windows PE files. Later on it tries
to send mails using its own SMTP engine. It picks up email addresses from
Outlook Express, MS Outlook and Netscape Navigator addressbook and sends
the infected mails.
It modifies registry and the file WIN.INI
to load itself during next start up. The file WIN.INI will be
modified at RUN= and the Registry will be modified at the following location:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

|