It is a trojan that affects the functioning of your computer.
The virus code runs which creates "c:\Documents and Settings\tazebama.dll" and loads the dll and runs it. The dll creates "c:\Documents and Settings\tazebama.dl_" which is actually an executable and executes it. The infected exes run as they wud have if they were not infected.
After execution, tazebama.dl_ searches for infectable exesin all drives and infects them. It also creates various exes with various names from its database It also creates autorun.inf in all drives and zPharaoh.exe in all the drives. It also creates autorun.inf and zPharaoh.exe in "C:\Documents and Settings\%username%\Local Settings\Application Data\Microsoft\CD Burning" so if you burn a CD, the CD gets infected too.
The removal of this trojan is virtually impossible because it encrypts the original exe data.
Answered by
Kannan
, an ibibo Specialist,
at
12:00 PM on March 25, 2009