SymbOS/Bootton.E!tr - Released May 12, 2006 - Last Updated May 18, 2009
|
Alias/esTrojan.SymbOS.Bootton.e (KAV) |
Detection Availability
|
Visible SymptomsThe mobile phone will reboot. |
Detailed AnalysisIt is a Symbian SIS archive. The following message will show on the screen during the installation:
Figure 1: Post-install display Upon installation, it drops the following files (528 Bytes):
- !:\System\Data\Profiles\Profile0.dat
- !:\System\Data\Profiles\Profile1.dat
- !:\System\Data\Profiles\Profile2.dat
- !:\System\Data\Profiles\Profile3.dat
- !:\System\Data\Profiles\Profile4.dat
- !:\System\Data\Profiles\Profile5.dat
which will overwrite the default profile settings. Then, it drops and executes the following EXE files to make the phone reboot:
- !:\System\Data\Profiles\Profiles.exe
- !:\System\Data\Profiles\Remove.exe
|
Recommended ActionDelete the EXE files with a file manager application - or run FortiClient Mobile Security. |