China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-06-25 12:38
中国DOS联盟论坛 » 贴图灌水、文学娱乐专区 » Latest Powerful Virus Alert! View 719 Replies 4
Original Poster Posted 2003-10-03 00:00 ·  中国 台湾 远传电信
元老会员
★★★★★
Credits 8,312
Posts 3,551
Joined 2003-03-22 00:00
23-year member
UID 1225
Gender Male
Status Offline
Latest powerful virus alert! (If you get infected, the computer is finished)

If you receive an email with an attachment named "Come draw a fortune stick!" (an .exe file), do not open it, and delete it immediately. It will turn all the icons at the lower right of your taskbar into plum blossoms, make the computer unable to shut down, and it will also send itself to friends in your address book. I'm notifying friends at the earliest possible moment, hope it's still in time!

Please forward this message to everyone in your address book!

Latest powerful virus alert

A truly powerful virus has arrived. In the past, for seriously infected users, it was enough to format the hard disk and reinstall, but people infected with the Magistr variant virus can only buy another computer! Symantec antivirus company announced that the Magistr virus, which infected many computers in April, now has a variant (W32.Magistr.39921@mm). Since this variant likewise has the characteristic of using non-fixed subjects and attachments, the number of infections has increased.

At the same time, before connecting to the network, the Magistr virus modifies the user's browser security settings, giving hackers many opportunities to break into the user's computer. Symantec has raised the danger level of the Magistr variant virus (W32.Magistr.39921@mm) from level 2 to level 3. This variant infects all windows programs. Infected users will have it copy itself and spread it to all recipients in the infected person's address book, causing mail servers to slow down. After infection it causes system instability, puts a severe load on the hard disk, and deletes CMOS and FlashBIOS, making the computer harder to repair and possibly requiring the purchase of a new one. At the same time it will send out confidential MicrosoftWord files on its own, and it will automatically modify browser security settings (lowering them from medium security to low security), increasing the chance of being hacked while browsing websites.

Because the subject and attachment are not fixed, it is very hard to detect. Its attachment name may arbitrarily use different file types such as exe, bat, pif, com, etc. Users can only be more careful not to open files from unknown sources at will! The virus is out, please forward this message to everyone in your address book! It is currently being spread by email, under the name: "A.I.D.SVIRUS"!! It will destroy your memory, sound card, speakers, and hard disk, and it will also affect the cursor keys on your mouse or keyboard, making you unable to type, so you can't record anything on the screen. After eating 5MB of hard disk space and destroying all programs, it will Format by itself and finish things off. It comes along with an email named "OPEN:VERYCOOL!", so if you receive it, delete it at once. It really will break your computer.
MSN:tiqit2@hotmail.com
Floor 2 Posted 2003-10-04 00:00 ·  中国 河南 驻马店 联通
金牌会员
★★★★
龙哥DOS
Credits 4,289
Posts 1,501
Joined 2003-02-23 00:00
23-year member
UID 983
Gender Male
From 河南省
Status Offline
DD, are you kidding internationally? A virus can't directly damage hardware, unless those chips have built-in vulnerabilities! Why didn't I find this news on the Rising website? Maybe this virus hasn't spread to China yet?
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
C++ ☆☆☆ 中国DOS联盟成员 ☆☆☆ C++
C++ ★★★ 爱提问的红色狂想 ★★★ C++
C++C++C++C++C++C++C++C++C++C++C++C++C++C++C++
Floor 3 Posted 2003-10-04 00:00 ·  中国 福建 泉州 电信
高级用户
★★
Credits 524
Posts 118
Joined 2003-02-08 00:00
23-year member
UID 868
Gender Male
Status Offline
失物招领:前天捡到100万人民币,如果没人招领的话我就收下了~~E-mail:andaoe@sohu.com
Floor 4 Posted 2003-10-04 00:00 ·  中国 福建 泉州 电信
高级用户
★★
Credits 524
Posts 118
Joined 2003-02-08 00:00
23-year member
UID 868
Gender Male
Status Offline
On Rising's website: http://www.rising.com.cn/antivirus/net_virus/net206.htm
New Magistr variant: W32.Magistr.39921@mm
(translated by Rising)
Virus name: W32.Magistr.39921@mm
Aliases: I-Worm.Magistr.b, W32.Magistr.B@mm, W32/Magistr.b@MM
Size: 39,921 bytes

The worm W32.Magistr.39921@mm is the latest variant of W32.Magistr.24876@mm.
This worm differs from W32.Magistr.24876@mm in that:


It takes control of the Eudora address book;

It deletes *.NTZ while searching files;

It terminates ZoneAlarm before connecting to the INTERNET;

It adds the entry Shell=explore.exe to the BOOT section of the system.ini file, invoking W32.Magistr.Trojan;

It searches all windows directories (WINNT, WINDOWS, WIN95, WIN98, WINME, WIN2000, WIN2K, WINXP.);

The attachments it sends have random extensions (exe, bat, pif, com);

Occasionally the attachment extension it sends is .gifs;

W32.Magistr.Trojan has a destructive module that overwrites the ntldr and win.com files on all drives, enabling these files to overwrite the first sector of the first IDE hard disk with garbage code.
At the same time, celebrating becoming a forum drifter









失物招领:前天捡到100万人民币,如果没人招领的话我就收下了~~E-mail:andaoe@sohu.com
Floor 5 Posted 2003-10-04 00:00 ·  中国 福建 泉州 电信
高级用户
★★
Credits 524
Posts 118
Joined 2003-02-08 00:00
23-year member
UID 868
Gender Male
Status Offline
On Dayoo Forum:
(2001-09-08 23:18 Dayoo Forum)
  Dayoo News — The Magistr worm, which appeared back in April, has not weakened at all over the past half year, and variants have even appeared. This worm is really frightening: after infection it may damage CMOS and Flash BIOS, and even reinstalling cannot save it. Even virus experts can only shake their heads and tell you to buy a new computer.

  The Magistr variant worm named W32.Magistr.39921@mm likewise has the characteristic of non-fixed subjects and attachments, so it easily tricks people into falling for it. This worm also modifies your browser security settings before connecting to the network, creating opportunities for hackers to invade your computer. Symantec has now raised the danger level of the Magistr variant worm from level 2 to level 3.

  The Magistr variant worm infects all Windows programs. Its means of spreading are through the email addresses in Eudora and Outlook Express address books, and Netscape sent mail folders. If unfortunately infected, the system may become unstable and the hard disk may suffer a severe burden. Once CMOS and Flash BIOS are deleted, the computer may become difficult to repair and be forced into scrap.

  Even if the computer can still be used, the Magistr variant worm may still arbitrarily send out Microsoft Word files, causing confidential data to leak.

  Because its subject is not fixed, it is extremely hard to judge whether an email is infected. Its attachment name may arbitrarily use different file types such as exe, bat, pif, com, etc. Other than being extra careful, netizens can only wish themselves luck.
失物招领:前天捡到100万人民币,如果没人招领的话我就收下了~~E-mail:andaoe@sohu.com
Forum Jump: