Wednesday, April 13, 2011

Remove Mabezat.b.Worm.c

Remove Mabezat.b.Worm.c

Also Known As:
Win32/Mabezat.worm.32768 (AhnLab)
W32/AutoRun.APZ (Norman)
W32/Mabezat-B (Sophos)
W32.Mabezat-3 (Clam AV)
Win32/Mabezat.A (ESET)
Worm.Win32.Mabezat.b (other)
Worm.Win32.Mabezat.b (Kaspersky)
Win32.Worm.Mabezat.C (Sunbelt Software)
W32/Mabezat.a (McAfee)
Summary
Virus:Win32/Mabezat.B is a polymorphic virus that infects PE files. Apart from spreading via file infection, it also attempts to spread via network shares, removable drives and by CD-burning. It contains a date-based payload that encrypts files with particular extensions.

Technical Information
Virus:Win32/Mabezat.B is a polymorphic virus that infects PE files. Apart from spreading via file infection, it also attempts to spread via network shares, removable drives and by CD-burning. It contains a date-based payload that encrypts files with particular file extensions.
Installation
Upon execution, Virus:Win32/Mabezat.B drops the file '%Root%\Documents and Settings\tazebama.dll'. It then loads an installation module from tazebama.dll, that drops the following copies of the virus:
%Root%\Documents and Settings\hook.dl_
%Root%\Documents and Settings\tazebama.dl_
It creates a process for tazebama.dl_, and then executes the original code of the host file.
Spreads Via…
E-mail
The virus checks for an Internet connection by attempting to connect to the following sites:
http://www.britishcouncil.com
http://www.yahoo.com
http://www.hotmail.com
http://www.microsoft.com

It avoids sending mail to e-mail addresses that contain the following strings:
MICROSOFT
KASPER
PANDA


E-mail sent by the virus are variable. The virus may send e-mail with the following characteristics:

Subject:
ABOUT PEOPLE WITH WHOM MATRIMONY IS PROHIBITED
Message Body:
1 : If a man commits adultery with a woman, then it is not permissible for him to marry her mother or her daughters.
2 : If a woman out of sexual passion and with evil intent commits sexual intercourse with a man, then it is not permissible for the mother or daughters of that woman to merry that man. In the same way, the man who committed sexual intercourse with a woman, because prohibited for her mother and daughters.
Download the attached article to read.
Attachment:
PROHIBITED_MATRIMONY.rar

Subject:
Windows secrets
Message Body:
The attached article is on
how to make a folder password
. If your are interested in this article download it, if you are not delete it.
Attachment:
FolderPW_CH(1).rar

Subject:
Canada immigration
Message Body:
The debate is no longer about whether Canada should remain open to immigration. That debate became moot when Canadians realized that low birth rates and an aging population would eventually lead to a shrinking populace. Baby bonuses and other such incentives couldn't convince Canadians to have more kids, and demographic experts have forecasted that a Canada without immigration would pretty much disintegrate as a nation by 2050. Download the attached file to know about the required forms.
The sender of this email got this article from our side and forwarded it to you.
Attachment:
IMM_Forms_E01.rar

Subject:
Viruses history
Message Body:
Nowadays, the viruses have become one of the most dangerous systems to attack the computers. There are a lot of kinds of viruses. The common and popular kind is called Trojan.Backdoor
which runs as a backdoor of the victim machine. This enables the virus to have a full remote administration of the victim machine. To read the full story about the viruses history since 1970 download the attached and decompress It by WinRAR.
The sender has red the story and forwarded it to you.
Attachment:
virushistory.rar

Subject:
Web designer vacancy
Message Body:
Fortunately, we have recently received your CV/Resume from moister web site
and we found it matching the job requirements we offer.
If your are interested in this job Please send us an updated CV showing the required items with the attached file that we sent.
Thanks
Regards,
Ajy Bokra
Computer department.
AjyBokra@webconsulting.com
Attachment:
JobDetails.rar

Aside from the predefined attachments described above, it may use one of the following as a filename for its attachment:
GoogleToolbarNotifier.exe
PanasonicDVD_DigitalCam.exe
Antenna2Net.exe
RadioTV.exe
Microsoft MSN.exe
Sony Erikson DigitalCam.exe
IDE Conector P2P.exe
Windows Keys Secrets.exe
FaxSend.exe
RecycleBinProtect.exe
Disk Defragmenter.exe
CD Burner.exe
ShowDesktop.exe
BrowseAllUsers.exe
LockWindowsPartition.exe
Win98compatibleXP.exe
MakeUrOwnFamilyTree.exe
WindowsXp StartMenu Settings.exe
Recycle Bin.exe
Adjust Time.exe
Microsoft Windows Network.exe
HP_LaserJetAllInOneConfig.exe
FloppyDiskPartion.exe
msjavx86.exe
AmericanOnLine.exe
Crack_GoogleEarthPro.exe
Lock Folder.exe
InstallMSN11En.exe
InstallMSN11Ar.exe
JetAudio dump.exe
KasperSky6.0 Key.doc.exe
Office2007 Serial.txt.exe
Office2003 CD-Key.doc.exe
Make Windows Original.exe
NokiaN73Tools.exe
WinrRarSerialInstall.exe
My Documents
.exe Readme.doc .exe
My documents .exe

Archived files may use one of the following filenames:
windows.rar
office_crack.rar
serials.rar
passwords.rar
windows_secrets.rar
source.rar
imp_data.rar
documents_backup.rar
backup.rar
MyDocuments.rar

File Infection
Virus:Win32/Mabezat.B is a polymorphic virus that infects PE files with the following extensions:
.lnk
.exe
.scr

Recovery Steps Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (http://safety.live.com).

No comments:

Post a Comment