Current:

Three new Symbian trojans in one day!!!

Name:

Email:

Website:

Message:




..help..


+ Three new Symbian trojans in one day!!

24 March 2005


Today F-Secure found three new Symbian trojans.
Drever.B, Drever.C and Skulls.F

The Drever.B is a simplified version of Drever.A that attacks only Simworks Anti-Virus, it is likely that Drever.B is actually earlier case than Drever.A, but was found only later. The Skulls.F is still under analysis, it is detected with generic detection from December 15th 2004, so it's a minor case. The Drever.C is interesting case as in addition of attacking Kaspersky and Simworks Symbian Anti-Viruses, it also attacks F-Secure Mobile Anti-Virus.
Drever.C tries to damage the bootloader and application binaries of F-Secure Mobile Anti-Virus. However, the F-Secure Mobile Anti-Virus has protection against any attempts to modify it's files so the attack will not succeed. If Drever.C SIS file is installed into Symbian device with F-Secure Mobile Anti-Virus running in Real-Time scan mode, as it is by default. The installation will terminate when the system installer tries to replace Anti-Virus files. The hexedited files that Drever.C tries to use to damage F-Secure Mobile Anti-Virus, contain message intended to F-Secure.

FSECURE MUST DIE!!!!!!
Please, don't make new antiviruses for my viruses and I stop make
viruses for your antiviruses. My target is Simworks!

NAME: Skulls.F
ALIAS: SymbOS/Skulls.F


Summary
Skulls.F is an edited version of Skulls.D SIS file trojan, it contains several variants of Cabir worm, and several copies of Locknut.B trojan.
Skulls.F is still under analysis, detailed information will be provided in near future.
Spreading in Simworks.SIS
Payload Replaces built in and third party applications with non-functional ones, installs Cabir worm variants, Locknut.B trojan and starts animation that shows flashing skull picture.

Detection

Generic detection that detects Skulls.F was published for F-Secure Mobile Anti-Virus on December 13th, 2004 in database build number 15.


NAME: Drever.B
ALIAS: SymbOS/Drever.B

Summary
Drever.B is a malicious SIS file trojan that disables the automatic startup from Simworks Symbian Anti-Virus software.
Drever.B does not affect F-Secure Mobile Anti-Virus.

Disinfection
Drever.B can be disinfected easily by using F-Secure Mobile Anti-Virus available from http://www.f-secure.com/estore/avmobile.shtml
Or you can uninstall it by uninstalling the SIS file in which Drever.C was installed from using application manager
1. Open the application manager
2. Uninstall Simworks_update.sis
3. Re-install your Anti-Virus

Spreading in Simworks_update.sis
Payload Drever.B drops non-functional copy of the bootloader used by Simworks Symbian Anti-Virus. This non-functional copy overwrites the original file, causing target software not to load automatically when the phone boots.


NAME: Drever.C
ALIAS: SymbOS/Drever.C


Summary
Drever.C is a malicious SIS file trojan that attacks bootloader files of several mobile Anti-Virus programs, and tries to attack F-Secure Mobile Anti-Virus by overwriting its files.
The Drever.C attacks bootloader files of Kaspersky, Simworks and F-Secure Symbian Anti-Virus products.
In addition of trying to overwrite the bootloaders, the Drever.C will also try to cripple F-Secure Mobile Anti-Virus by replacing it's binaries with corrupted ones.
However as F-Secure Mobile Anti-Virus contains protection against any modification attempts of its own files, both attacks will fail when Anti-Virus is in realtime scan mode as it is by default.
If the F-Secure Mobile Anti-Virus is switched off, or in manual scan mode, which is basically same as switched off. The attack will damage Anti-Virus, but user can recover easily by re-installing Anti-Virus.

Disinfection
Drever.C can be disinfected easily by using F-Secure Mobile Anti-Virus available from http://www.f-secure.com/estore/avmobile.shtml


Source: F-secure Author: Apocalypso

Back to news..


copyright (c) Symbian freak 2005,
all rights reserved