Trojan

About “Trojan.Win32.Mabezat.a” infection

Malware Removal

The Trojan.Win32.Mabezat.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mabezat.a virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Catalan
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Mabezat.a?


File Info:

name: 1DB63F687FD054DD2DDB.mlw
path: /opt/CAPEv2/storage/binaries/02fcc29e07b496b677839adaac1354d09ca8a9248b57597befbb341c8598bc45
crc32: 563C3FD7
md5: 1db63f687fd054dd2ddbe347012d0891
sha1: 7ea2f268a9907e9f0c8785181f761c78bd070cd3
sha256: 02fcc29e07b496b677839adaac1354d09ca8a9248b57597befbb341c8598bc45
sha512: aa46db0cf42c73e9387df489844f90e684d1b4540586e25e309d3e36126b234b72b734d6d0d98d6c3c8f9ba72202523069248bc804827c11f43de3568df6680b
ssdeep: 3072:jLIYDPdfxMT2cWl99X5kdT8FLSpJ4n5EmVCpI2yZJKywSL:jLn1KT2z99X5kdT8FLSpJ4nSmVc6z1wi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119F36BEE29074139C26879784F6426485BBA9BE45BF310FBF68C339944BF2C0E974C56
sha3_384: 913ab04be8813e9afea69ffc30c20c57c765a7b4ed78b143eddb7b664fea154223288970d9c40a3049a43501e0c00587
ep_bytes: 5383ec44b823104000b9000000008a18
timestamp: 2007-10-29 06:17:05

Version Info:

0: [No Data]

Trojan.Win32.Mabezat.a also known as:

BkavW32.Pharoh.Worm
MicroWorld-eScanWin32.Worm.Mabezat.S
CAT-QuickHealW32.Mabezat.Dr
ALYacWin32.Worm.Mabezat.S
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 000ad08b1 )
K7GWVirus ( 000ad08b1 )
Cybereasonmalicious.87fd05
BaiduWin32.Worm.Mabezat.b
VirITWorm.Win32.Mabezat.A
CyrenW32/Mabezat.FRWO-1177
SymantecW32.Mabezat.B
Elasticmalicious (high confidence)
ESET-NOD32Win32/Mabezat.A
APEXMalicious
ClamAVWin.Trojan.Mabezat-1
KasperskyWorm.Win32.Mabezat.b
BitDefenderWin32.Worm.Mabezat.S
NANO-AntivirusVirus.Win32.Mabezat.kfroy
SUPERAntiSpywareTrojan.Agent/Gen-Worm
AvastWin32:Agent-AVCE [Trj]
TencentTrojan.Win32.Mabezat.a
Ad-AwareWin32.Worm.Mabezat.S
TACHYONWorm/W32.Mabezat
SophosML/PE-A + W32/Mabezat-B
ComodoWorm.Win32.Mabezat.b@14k3c8
F-SecureWorm.WORM/Mabezat.b
DrWebWin32.HLLW.Tazebama
ZillyaWorm.MabezatGen.Win32.3
TrendMicroPE_MABEZAT.B-O
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.1db63f687fd054dd
EmsisoftWin32.Worm.Mabezat.S (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Mabezat.S
JiangminTrojan/Mabezat.g
AviraWORM/Mabezat.b
Antiy-AVLTrojan/Generic.ASVirus.28
ArcabitWin32.Worm.Mabezat.S
ViRobotWorm.Win32.Mabezat.154751
MicrosoftVirus:Win32/Mabezat.B
CynetMalicious (score: 100)
AhnLab-V3Win32/Mabezat
McAfeeW32/Mabezat
MAXmalware (ai score=87)
VBA32Trojan.Win32.Mabezat.a
MalwarebytesSality.Virus.FileInfector.DDS
TrendMicro-HouseCallPE_MABEZAT.B-O
RisingTrojan.Generic@AI.100 (RDMK:cmRtazqCL8tTg/lLrEjVmCLjVcG8)
YandexTrojan.GenAsa!0z4t/44RHDE
IkarusWorm.Win32.Mabezat
MaxSecureVirus.Mabezat.B
FortinetW32/Mabezat.B!worm
BitDefenderThetaAI:FileInfector.72161D3514
AVGWin32:Agent-AVCE [Trj]
PandaW32/Mabezat.C.worm
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Mabezat.a?

Trojan.Win32.Mabezat.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment