Summary
Muma.B variant of the worm has been discovered in the wild. The modifications are minimal and mainly lie in the script files controlling the behavior of the worm. Although without affecting to the general actions performed. The changes might have been aimed to render the scripts undetectable.
F-Secure Anti-Virus detects most of the files as they are basically identical to the ones contained in the previous variant.
Removal
Disinfection Instructions for Muma.A worm
It is strongly recommended to use FSAV 5.40 or later version to disinfect Muma worm. Disinfection procedure should be as follows:
1. Disable network sharing or kill a network (this is recommended, but not obligatory if you have FSAV 5.40 or later version).
2. Scan all computers with FSAV and the latest updates.
3. Select 'Disinfect' action for all found worm's files. The infected files should be renamed instantly or after system restart.
4. Restart disinfected computers. Make sure that FSAV's on-access scanner is active before restart.
5. After restart it is recommended to re-scan all hard drives with FSAV to make sure that no infections are left.
6. Re-enable network connections (if you disabled them) only after you clean all infected computers.
Important notes:
FSAV might not rename a hacker's tool Hucline if you select 'Disinfect' action. You can either select 'Rename' action for this file or remove that file manually. That file is not dangerous without worm's scripts anyway.
If you do not want to take down a network, make sure that all computers have FSAV's on-access scanner enabled and that they have the latest updates. In this case FSAV will rename infected files coming from a network before they can be activated - a computer would be protected from infection. Keep in mind that all unprotected computers might become re-infected if you keep a network alive with at least one infected system.
Disinfection Instructions for Muma.B worm
It should suffice with following the instructions given above for the previous variant.
Additionally, after those steps have been completed, the user can manually remove any files that appear in the lists given in this description as belonging to the worm, as some non malicious files bundled with the worm are not removed by the Anti-Virus.
Disinfection Instructions for Muma.C worm
To manually disinfect a computer from Muma.C worm please follow these instructions:
1. Disable network sharing.
2. Kill processes of MUMU.EXE, BBOY.EXE and LAST.EXE files.
3. Delete the above mentioned files from a system together with BBOY.DLL file. You can also delete PSEXEC.EXE and KAVFIND.EXE files.
4. Change passwords and logins on an infected computer, do not use 'weak' passwords that are simple to guess.
5. Re-enable network only after all infected computers are cleaned.
Disinfection Instructions for Muma.D worm
Disinfection of this variant follow a similar pattern as for previous ones:
1. Disable network sharing.
2. Kill processes of MUMU.EXE, BBOY.EXE and LAST.EXE files.
3. Remove any running executables detected by FASV.
4. Change passwords and logins on an infected computer, do not use 'weak' passwords that are simple to guess.
5. Re-enable network only after all infected computers are cleaned.
A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:
- Check for the latest database updatesFirst, check if your F-Secure security program is using the latest updates, then try scanning the file again.
- Submit a sampleAfter checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.
- Exclude a file from further scanningIf you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.Note: You need administrative rights to change the settings.
Technical Details
Protect your devices from malware with F‑Secure Total
Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.
- Award‑winning antivirus and malware protection
- Online browsing, banking, and shopping protection
- 24/7 online identity and data breach monitoring
- Unlimited VPN service to safeguard your privacy
- Password manager with private data protection
Choose how many devices you want to protect to get started.
- Free customer support
- Cancel anytime
- The trial does not obligate you to buy the product
After 30 days your subscription will renew automatically for one year at €69.99.
More Support
Community
Ask questions in our Community.
User guides
Check the user guide for instructions.
Contact Support
Chat with with or call an agent.
Submit a Sample
Submit a file or URL for analysis.
)
)