Trojan.SymbOS.Romride.a
Detected Jun 01 2006 14:23 GMT
Released Jun 01 2006 14:23 GMT
Published Apr 24 2007 09:39 GMT
Technical Details
Payload
Removal instructions
Technical Details
This Trojan program is designed to run on smartphones running Symbian.
The Trojan is a SIS file called Nokia Live.sis. The file is 3233 bytes in size.
The Trojan has no self replication routine.
Payload
During installation, the Trojan will display the following messages. The user has to confirm each action for the Trojan to be installed to the phone:
During installation, the Trojan will drop the following files to the phone:
C:\System\Bootdata\CommonData.D00
C:\System\Bootdata\FirstBoot.dat
C:\System\Bootdata\LocaleData.D01
C:\System\Mail\00001000
C:\System\Mail\00100000
C:\System\Mail\00100001
C:\System\Schedules\Schedules.dat
C:\System\Shareddata\101f857a.ini
C:\System\Shareddata\10005a40.ini
C:\System\Shareddata\100056c6.ini
C:\System\Shareddata\100058f1.ini
C:\System\Shareddata\10005943.ini
C:\System\Shareddata\reserve.bin
These files are corrupted or have an inappropriate format or name. These factors will cause the phone to become unstable.
Once installed, the Trojan will cause the following message to be displayed:
The Task Manager of the smartphone will show that the program has been installed.
Removal instructions
In order to delete this Trojan, you should install a file manager application which provides the option to view hidden and system files. Then delete the files listed below.
C:\System\Bootdata\CommonData.D00
C:\System\Bootdata\FirstBoot.dat
C:\System\Bootdata\LocaleData.D01
C:\System\Mail\00001000
C:\System\Mail\00100000
C:\System\Mail\00100001
C:\System\Schedules\Schedules.dat
C:\System\Shareddata\101f857a.ini
C:\System\Shareddata\10005a40.ini
C:\System\Shareddata\100056c6.ini
C:\System\Shareddata\100058f1.ini
C:\System\Shareddata\10005943.ini
C:\System\Shareddata\reserve.bin
Once the files have been deleted, reboot the phone.