Threat Description



Aliases:Mabtal, SymbOS/Mabtal.A
Category: Malware
Platform: W32


Mabtal.A is a SIS file trojan. It has been distributed as a cracked version of a legitimate email application, Profimail. The application filename we've seen has been "Profimail v2.75_FULL.sis".


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.

Technical Details

When installed, this trojan will drop the Mabir.A virus and the Fontal.A and Locknut.B trojans to the system.

Mabtal.A contains this text:

Profimail v2.25 multilingual pack cracked by UAE cracker team!
  If you like it, please buy it, just crack for fun! ^_^


Generic detection that detects Cabir.F was published for F-Secure Mobile Anti-Virus on December 13th, 2004 in
Detection Type: Mobile
Database: database build number 15

Description Created: Mikko Hypponen, 12th of July 2005
Description Last Modified: Jarno Niemela, 27th of Septebmer 2005


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More