Threat Database Viruses Virus:Win32/Mabezat.B!ofd

Virus:Win32/Mabezat.B!ofd

By JubileeX in Viruses

Virus:Win32/Mabezat.B!ofd is a virus, which proliferates via malevolent encrypted files. While being installed on the infected computer system, Virus:Win32/Mabezat.B!ofd makes system modifications by restricting attacked PC users from opening some of system files. Virus:Win32/Mabezat.B!ofd corrupts Windows executable files. Virus:Win32/Mabezat.B!ofd also aims at circulating via infected spam email attachments, removable drives, network shares and by CD-burning. Virus:Win32/Mabezat.B!ofd carries a date-based payload that encrypts files with certain extensions. Virus:Win32/Mabezat.B!ofd checks for an Internet connection by aiming at connecting to certain websites. Virus:Win32/Mabezat.B!ofd may strive to use archiving program 'Winrar' to archive itself when creating attachments. Virus:Win32/Mabezat.B!ofd may search for 'Winrar' by inquiring the registry entry. For using 'Winrar' Virus:Win32/Mabezat.B!ofd initially creates a folder, which includes a copy of Virus:Win32/Mabezat.B!ofd. Virus:Win32/Mabezat.B!ofd also downloads potentially harmful files.

File System Details

Virus:Win32/Mabezat.B!ofd may create the following file(s):
# File Name Detections
1. %USERPROFILE%\Local Settings\Application Data\Microsoft\CD Burning\zPharaoh.exe
2. %USERPROFILE%\Local Settings\Application Data\Microsoft\CD Burning\autorun.inf
3. %SystemDrive%\Documents and Settings\hook.dl_
4. %SystemDrive%\Documents and Settings\tazebama.dl_
5. %USERPROFILE%\Application Data\tazebama\zPharaoh.dat

Registry Details

Virus:Win32/Mabezat.B!ofd may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe

Trending

Most Viewed

Loading...