1. Home
  2. Computing & Technology
  3. Antivirus Software

Zafi.B
Virus Description

By Mary Landesman, About.com

Jun 14 2004
Zafi.B is a mass-mailing email worm that also spreads by copying itself to folders containing 'share' or 'upload' in the folder name. Zafi.B has a malicious payload, overwriting executables associated with antivirus and firewall software with copies of itself. The worm also disables the execution of processes containing any of the following strings: 'regedit', 'msconfig', or 'task'.

When sent via email, the worm composes its message using the language signified by the top level domain of the intended recipient. For example, those with a .COM domain will be sent an English version, those with a .DE domain will be sent a German version, etc. The message body and text vary. The attachment will have either a .pif file, .com, or .exe extension. The attachment name may be disguised to appear as if it is a link to a website.

In order to spread via shared folders and Peer-to-Peer (P2P) networks, Zafi.B copies itself as 'winamp 7.0 full_install.exe' and 'Total Commander 7.0 full_install.exe'.

When the Zafi.b worm is executed, it copies itself to the Windows System directory as both a .dll and an .exe. Filenames are random. Zafi.B modifies the System Registry, adding the value _Hazafibb to the HKLM\..\Run key to load the worm when Windows is started.

Zafi.b harvests email addresses from a range of file types found on the infected user's system and creates additional .dll files in the Windows System folder that contain these collected email addresses.

Explore Antivirus Software
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.