Malware

Should I remove “W32/Mabezat-B”?

Malware Removal

The W32/Mabezat-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Mabezat-B virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Catalan
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/Mabezat-B?


File Info:

name: 6890E025027F0AB84A9F.mlw
path: /opt/CAPEv2/storage/binaries/ea8b4e57124cabdd3fc3f2586fdee42a94b56c330a5440ef4fe376f8de605670
crc32: 4748DE3B
md5: 6890e025027f0ab84a9f524db84826a7
sha1: c0ce8496a4887ed0fa224c3d8659d6083841716c
sha256: ea8b4e57124cabdd3fc3f2586fdee42a94b56c330a5440ef4fe376f8de605670
sha512: 3ace22ca95c6b7ba8882fe1139b01576f2f40d61f5ce147f6a3db9b58580d332dfecc0e7bbb43ecc32b46e61f7bd208a46be6c8fc79e16638d5a2547075825d7
ssdeep: 3072:r7/64aQcwAAvVydHxZISJ5gxmw7A2z7R/5z01WHu:X6avsdHxyS/hGDZu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9F37B03F61246D3E3BCA27DED463EB553D6B66CA12109CB53C9434C26622F66442FEE
sha3_384: e28847fe2621388d76392534eeadb2adba37ad55341064018067e5440de978902164a1a4eff10759fe7b4f23d77c210f
ep_bytes: 5383ec44b823104000b9000000008a18
timestamp: 2007-10-29 06:17:05

Version Info:

0: [No Data]

W32/Mabezat-B also known as:

BkavW32.Pharoh.Worm
LionicWorm.Win32.Mabezat.li99
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Mabezat.S
FireEyeGeneric.mg.6890e025027f0ab8
CAT-QuickHealW32.Mabezat.Dr
SkyhighBehavesLike.Win32.Mabezat.ch
ALYacWin32.Worm.Mabezat.S
Cylanceunsafe
ZillyaWorm.MabezatGen.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 000ad08b1 )
K7GWVirus ( 000ad08b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Worm.Mabezat.S
BaiduWin32.Worm.Mabezat.b
VirITWorm.Win32.Mabezat.A
SymantecW32.Mabezat.B
ESET-NOD32Win32/Mabezat.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Mabezat-1
KasperskyWorm.Win32.Mabezat.b
BitDefenderWin32.Worm.Mabezat.S
NANO-AntivirusVirus.Win32.Mabezat.kfroy
SUPERAntiSpywareTrojan.Agent/Gen-Worm
AvastWin32:Agent-AVCE [Trj]
TencentTrojan.Win32.Mabezat.a
TACHYONWorm/W32.Mabezat
EmsisoftWin32.Worm.Mabezat.S (B)
F-SecureWorm.WORM/Mabezat.b
DrWebWin32.HLLW.Tazebama
VIPREWin32.Worm.Mabezat.S
TrendMicroPE_MABEZAT.B-O
Trapminemalicious.high.ml.score
SophosW32/Mabezat-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Mabezat.g
WebrootW32.Mabezat.Gen
VaristW32/Mabezat.FRWO-1177
AviraWORM/Mabezat.b
Antiy-AVLWorm/Win32.Mabezat.b
KingsoftWin32.Mabezat.b.1038191
XcitiumWorm.Win32.Mabezat.b@14k3c8
MicrosoftVirus:Win32/Mabezat.B
ViRobotWorm.Win32.Mabezat.154751
ZoneAlarmWorm.Win32.Mabezat.b
GDataWin32.Worm.Mabezat.S
GoogleDetected
AhnLab-V3Win32/Mabezat
Acronissuspicious
McAfeeW32/Mabezat
MAXmalware (ai score=83)
VBA32Trojan.Win32.Mabezat.a
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Mabezat.C.worm
TrendMicro-HouseCallPE_MABEZAT.B-O
RisingWorm.Mabezat!1.995D (CLASSIC)
YandexTrojan.GenAsa!0z4t/44RHDE
IkarusWorm.Win32.Mabezat
MaxSecureVirus.Mabezat.B
FortinetW32/Mabezat.B!worm
BitDefenderThetaAI:FileInfector.72161D3514
AVGWin32:Agent-AVCE [Trj]
Cybereasonmalicious.6a4887
DeepInstinctMALICIOUS

How to remove W32/Mabezat-B?

W32/Mabezat-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment