Advertentie | |
|
![]() |
|
bron: http://www.norman.nl
Further comments W32/Magistr.B@mm is a very polymorphic virus. It does seem to be quite destructive, utilizing both hard disk erasure and BIOS flashing. W32/Magistr.B use the method first seen in Win95/CIH to erase hard disk data and flash memory. Magistr.B uses different encryption techniques than its predecessor, and it is difficult to analyse, detect, and remove. It infects Win32 executables and mass mails itself over email by direct SMTP as well as spreads through network resources. It picks up email addresses from Microsoft address book and other files containing email addresses. The subject, body and name of attachment are randomly created by the virus. This Magistr.B variant has some other characteristics, which distinguishes it from the former Magistr.A: it may install a trojan, which can overwrite files on local and network hard disks. it deletes files that has the extension *.NTZ (such files may belong to the security product Invircible). it disables the ZoneAlarm personal firewall it has added functionality to make virus removal difficult Magistr A@mm: W32/Magistr.A@mm is a very polymorphic virus. It does seem to be quite destructive, utilizing both hard disk erasure and BIOS flashing. W32/Magistr use the same method as Win95/CIH to erase hard disk data and flash memory. Spreading mechanism W32/Magistr.A infects Win32 executables and mass mails itself over email by direct SMTP as well as spreading through network resources. It picks up email addresses from Microsoft address book and other files containing email addresses. The virus will usually arrive in email as an EXE file with a random file name. If you execute an infected file your system will be infected and the virus will start its mass mailing routine to propagate itself. It enumerates all network resources looking for folders with the following names: WIN98 WIN95 WINNT WINDOWS If a folder with either these names is found, it copies itself to these folders and adds an entry to Win.ini to load itself at next system startup. It will create an entry in win.ini as well as in the Windows Registry to run itself at each Windows startup. To do that it create the following Registry key: HKEY_LOCAL_MACHINE\Software\Microsof\Window\CurrentVersion\Run [path\name of infected files] The virus contains the following encrypted text: ARF! ARF! I GOT YOU! v1rus: Judges Disemboweler. by: The Judges Disemboweler. written in Malmo (Sweden)
__________________
Fuck you! and you, and you and everybody else
|
![]() |
|
![]() |
een apart fix programmatje downloaden van Http://www.norton.com
die in veilige modus uitvoeren en hoepen dat je systeem weer weerkt. w32.magistr zit in de versies die ik heb verwijdert in veel word uitvoerbestanden verstopt word.exe, office.exe ect. meer info bij norton of via mijn emeel Groeten Edwin
__________________
Http://www.edjuh.nl -->> mijn Site Http://f4rum.tk --> HET forum ..Edjuh de rapper..
|
![]() |
||
![]() |
Citaat:
Ik kan op www.norton.com niet dat programaatje niet vinden. En verder luk het niet met het verwijderen ervan. Heb je nog meer tips voor me? Alvast bedankt iig. Groetjes Stefan |
Advertentie |
|
![]() |
|
|