Threat Description

Mabtal

Details

Aliases:Mabtal, SymbOS/Mabtal.A
Category: Malware
Type:
Platform: W32

Summary



Mabtal.A is a SIS file trojan. It has been distributed as a cracked version of a legitimate email application, Profimail. The application filename we've seen has been "Profimail v2.75_FULL.sis".



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



When installed, this trojan will drop the Mabir.A virus and the Fontal.A and Locknut.B trojans to the system.

Mabtal.A contains this text:

Profimail v2.25 multilingual pack cracked by UAE cracker team!
  If you like it, please buy it, just crack for fun! ^_^


Detection


Generic detection that detects Cabir.F was published for F-Secure Mobile Anti-Virus on December 13th, 2004 in
Detection Type: Mobile
Database: database build number 15



Description Created: Mikko Hypponen, 12th of July 2005
Description Last Modified: Jarno Niemela, 27th of Septebmer 2005


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More