What is the Mabezat / Tazebama infection?



Introduction:

Mabezat is a Virus for the Windows Platform that spreads by copying itself to network shares and removable media.
Mabezat  copies itself to removable/fixed media with one or more of the following names:

- Adjust Time.exe
- AmericanOnLine.exe
- Antenna2Net.exe
- BrowseAllUsers.exe
- CD Burner.exe
- Crack_GoogleEarthPro.exe
- Disk Defragmenter.exe
- FaxSend.exe
- FloppyDiskPartition.exe
- GoogleToolbarNotifier.exe
- HP_LaserJetAllInOneConfig.exe
- IDE Connector P2P.exe
- InstallMSN1Ar.exe
- InstallMSN1En.exe
- Audio dump.exe
- Lock Folder.exe
- LockWindowsPartition.exe
- Make Widowows Original.exe
- MakeUrOwnFamilyTree.exe
- Microsoft Windows Network.exe
- msjavx86.exe
- NokiaN73Tools.exe
- Office2007 Serial.exe
- PanasonicDVD_DigitalCam.exe
- RadioTV.exe
- Recycle Bin.exe
RecycleBinProtect.exe
- ShowDesktop.exe
- Sony Erikson Digitalcam.exe
- Win98compatibleXp.exe
- Windows Keys Secrets.exe
- WindowsXP StartMenu Settings.exe
- WinRarSerialInstall.exe


Mabezat created on removable/fixed media .rar files with the following filenames:

- backup.rar
- documents_backup.rar
- imp_data.rar
- MyDocuments.rar
- office_crack.rar
- passwords.rar
- serials.rar
- source.rar
- windows.rar
- windows_secrets.rar

These archieve contain a file dropper: Readme.doc. 
Exe W32/Mabezat-B When installed, the files are created:

%Profile%\hook.dl_
%Profile%\tazebama.dl_ 
%Profile%\tazebama.dll
%SystemDrive%\1.taz
%SystemDrive%\autorun.inf
%SystemDrive%\zPharaoh.exe
%AppData%\Microsoft\CD Burning\1.taz
%AppData%\Microsoft\CD Burning\autorun.inf
%AppData%\Microsoft\CD Burning\zPharaoh.exe
%appdata%\tazebama\zpharaoh.dat
%appdata%\tazebama\zpharaoh.exe
%appdata%\tazebama\zpharaoh.log
%appdata%\tazebama

The infection is spread by:

  • Removable Storage Drives
  • Network Shares
  • Files Infected
Example in a report Hijack This infected Mabezat:


C:\Documents and Settings\tazebama.dl_

Example Mabezat infection found:

C:\DOCUME~1\PROPRI~1\APPLIC~1\tazebama
C:\Documents and Settings\tazebama.dll
C:\Documents and Settings\KSR\Appplication Data\tazabama\zPharaoh.dat
C:\Documents and Settings\hook.dl_
C:\zPharaoh.exe
C:\zPharaoh.inf
C:\Program Files\Microsoft Works\WkDStore.exe[Result] WORM/Mabezat.B.91 found
C:\Start Menu\Programs\Startup\zPharaoh.exe
C:\Documents and Settings\[User Name]\Appplication Data\tazabama\zPharaoh.dat 
C:\Documents and Settings\My Documents\readme.doc.exe

Message of this type may appear:

"This application or DLL C:\documents and settings\tazebama.dll is not a valid windows image"

If you have Vista or 7:
You must disable UAC during disinfection.

Methods of Disinfection:

Several solutions are possible:

Method: Usbfix

The infection spread by removale drives, usbfix to able to remove a large part, however it is advisable to run Malwarebyte's Antimalware and Superantispyware afterwards.

UsbFix: Option 1

  • Option 1 of Usbfix can find infection on the Computer and on all removale drives that you previously connected without opening them.
  • Download "UsbFix" on the desktop.
  • Connecting data souces external to the PC(USB,external hard drive, SD card, etc..) without opening them.
  • Double-click the program UsbFix.exe on the desktop, the software will install automatically.
  • Choose Option 1 (Search).
  • After Completion on a Usbfix.txt report is saved in the root drive (C:\UsbFix.txt).
"Process.exe" , a component of the tool is detected by some antivirus programs (AntiVirDr.WebKaspersky Anti-Virus) as a RiskTool. It is not a Virus but a utility to terminate processes.

UsbFix: Option 2 

  • Option 2 UsbFix cleans infection found.
  •  Connecting data sources external to the PC (USB, External Hard Drive, SD card, etc...) without opening them.
  • Double-Click the program UsbFix on the desktop.
  • Choose Option 2 (Delete)
  • The Desktop will disappear and restart the PC.
  • Upon restart, UsbFix scan your PC, let the tool work.
  • Again a report will be generated, simply post it on the appropriate forum.
 MalwareBytes Anti-Malware

  • Download and install Malwarebyte's Anti-Malware .
  • At the end of the installation, make sure the option "update Malwarebyte's Anti-Malware" is checked.
  • Run program and let the update process be comleted.
  • Then go to the "Search" tab, check "Run a quick" then "Search".
  • At the end of the scan, click on "Show Results".
  • Check all items found and click "Remove Selected".
  • The report is saved in the Report tab-Log Malwarebytes.
  • If you are prompted to restart, accept.
Similarly, other third party softwares from them to be fixed.....
Online Scan
  • Online Scan BitDifender
  • Online Scan TrendMicro
  • Online Scan Computer Associates
  • Online Scan F-Secure
  • Online Scan Kaspersky
More about this question
Continue Reading...

Check if your PC is infected or not...

A Simple Method to find out if your PC is infected or not:

  • Go to the Start Menu, open the 'Run' Tab
and type the system.ini , confirm by clicking OK.

  • A Window will open:

  1. If you have the following message:



  • It means that your PC is clean !!

  • But if you have this message with red stars, is means that the PC is infected.
  • It is therefore necessary to scan and disinfect your Computer or PC.
So Now Test Yourself Your System Health Without Any AV.@@@@@
Continue Reading...

Limited hours for kids[Parental control]


You find your kids spending too much time on your computer. Here is how to restrict their use to times
that you yourself decided :
  • To begin, each person you want to restrict the use of the PC must have its own account
  • Click "Start " then "All Programs" "Accessories" and finally click on "Command Prompt".
  • In the window that opens, then enter the following command:
  • Net user[name]/time[days and hours]
  • Replace[name] by the name of the user for which you want to restrict the use of the computer and then[day and time] by the restriction values.
  • For example, to prohibit the user to log on 'Karan' weekdays between 9 AM  and 20 PM and weekends between 18 PM and 20 PM, type the following command:
  • Karan net user / time: Monday-Friday , 09:00-20:00, Saturday-Sunday , 18:00-20:00
  • You can also apply these rules for each day of the week and to go faster to just write the initials on day like this (for my Tuesday and Wednesday for me).
  • Karan net user / time: L, 6:00 p.m. to 8:00 p.m.; Ma, 6:00 p.m. to 9:00 p.m.; Me, 10:00 a.m. to 8:00 p.m.
  • Then confirm with OK
  • The day you want to remove all restrictions so that a user can log in anytime, enter the command:
  • Karan net user / time: all                          
Continue Reading...