Magistr worm emerges, scarce but deadly

Magistr differs from similar recent headline-grabbers Anna Kournikova and NakedWife -- this one is really mean.

Kournikova clogged e-mail servers and NakedWife damaged operating systems, but the victims could make repairs. Magistr goes way beyond that, trying to expose your private files, destroy your data, and cripple your PC so it won't even reboot.

"It's similar to other worms, but it's more sophisticated and destructive," says Pete Privateer, president of Pelican Security. Users of Pelican Security's SafeTnet product are already safe from the virus, he says.

Users of Norton Antivirus are also protected "if they download the latest virus signatures that can detect Magistr," says Stephen Trilling, director of Symantec's Antivirus Research Center.

How it spreads

Magistr can spread three ways: by e-mail, on a local area network, or through shared disks, Privateer says. As with most viruses, a victim gets stung by opening an infected attachment. When the virus is triggered, Magistr scans the user's Outlook Express address book, then runs its own internal e-mail program to send messages to everyone in the book. The worm generates random subject headings, using text files from the PC as well as various English and Spanish phrases it carries along. The result: garbled, random messages that offer no telltale word combination for confused recipients of the correspondence.

Attached to each infected message is up to six files. Most of the files are text or Microsoft Word files, taken directly from the hard drive of the PC that sent it, he says. That means an attachment could be anything from a personal letter to a private financial document. The sixth file is an infected offspring of Magistr that may at first glance appear to be a harmless bitmap file -- but a closer examination reveals a series of spaces followed by the .exe extension of an executable program. If the person who receives the message opens this infected executable file, Magistr begins again.

Magistr's spread may be limited because it requires a user action to initiate the worm's move to another machine, Privateer says. That means it won't likely be as prolific as its earlier siblings, which essentially exist to spread. But what Magistr lacks in quantity it makes up for in patience -- and sheer destructive power.

One nasty payload

After sitting dormant for one month after arriving at a PC, the worm's payload activates -- and begins destroying data and system files. Not only does it erase these files, it also rewrites an unfriendly phrase repeatedly in their place, making later retrieval of the deleted files nearly impossible, Privateer says.

The worm then attacks the CMOS and Flash BIOS of machines running Windows 95, 98, and ME, which is less secure than Windows NT and 2000 machines, he says. The CMOS is necessary to boot the PC.

"Once [the CMOS] is gone, the computer is useless, and you need to send it back to the vendor for repair," he says.

Once the worm has done its dirty work, and assuming the PC is still functional, it posts another nasty message, then enacts a final measure of cruelty: runaway icons. When a user tries to click on the icons, they move away from the cursor.

The work of pros?

The worm's intricate payload indicates it's no amateur production, Privateer says. While many worms are the products of wannabe hackers using virus-writing kits, Magistr appears to be the work of someone with programming knowledge. Some suggest a hacker or hacker group in Sweden called "The Judges Disembowler" wrote the worm.

Symantec's Trilling isn't sure what to make of the worm yet, noting that you can "sort of see previous types of viruses in there." However, that it carries its own e-mail handler does indicate a high level of sophistication, he adds.

Privateer says it's that level of sophistication that's most daunting, because this is just the stuff such high-level worm writers want us to see. Imagine what they're out there doing that we can't see, he says.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tom Mainelli

PC World
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?