F-secure Detected Three New Symbian Trojans!!
21 January 2006
F-secure and Symantec
warns of three new Symbian trojans!
Pbstealer in action
(10x to CALVIN for screens)
Anti-virus vendors have detected a new batch of Trojans spreading on Symbian Series 60 smartphone devices.
According to definitions from Symantec and F-secure, the latest malware samples are capable of seriously disrupting the operations on Bluetooth-enabled Symbian devices.
The trojans crash phones, attempt to install other malicious software or try to wirelessly transmit personal data to other gadgets.
Sendtool.A is used to propagate other malware such as PBStealer.C. Files are being sent to other devices via Bluetooth and user interaction is required to spread the files. The Sendtool.A trojan spreads in Fspreader.SIS.
F-Secure Mobile Anti-Virus is capable to detecting and deleting the Sendtool.A trojan. Sendtool.A can also be removed by uninstalling it with Symbian Application Manager.
For more information, please see:
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Pbstealer.D is a trojan application that runs under Symbian S60 platform. Pbstealer.D pretends to be an utility software that compacts the phone's contact database. Instead of compacting the information, Pbstealer.D reads the contact information database, and sends the contents as a text file to the first Bluetooth device it finds.
Pbstealer.D is a very close variant to PBStealer.C and it does not spread by itself. In order to be infected, the user has to install the .SIS package that contains Pbstealer.D. Although Pbstealer.D uses Bluetooth for sending the phone book data, this data is pure text and cannot infect the receiving device.
For more information, please see:
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Bootton.E is a SIS file trojan that installs a small software component that resets the device if executed. This component is being installed as a reset application. Bootton.E installs also corrupted system components that cause reboot to fail and leave the phone in an unusable state. F-Secure Mobile Anti-Virus is capable of detecting and deleting the Bootton.E trojan. Bootton.E can also be removed by uninstalling it with Symbian Application Manager.
Disinfection:
Disinfection for the cases when the phone is already rebooted and cannot start up:
1. Power off the phone
2. Hold the following three buttons down: "answer call" + "*" + "3"
3. Keep holding the buttons down and power on the phone
4. Depending on the model, you either get the text "formatting" or start-up dialog that asks for the initial phone settings
CAUTION! This method will remove all data on the device including calendar and phone numbers
For more information, please see:
[Only Registered and Activated Users Can See Links. Click Here To Register...]