This application requires Javascript for optimal performance.

SymbOS/Arifat.A!tr - Released Mar 20, 2007 - Last Updated Jun 22, 2007

Alias/es

Trojan.SymbOS.Arifat.a, SYMBOS_ARIFAT.A, SymbOS/Arifat trojan

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

Detailed Analysis

  • This is a Symbian virus, packed in SIS format.

  • Displays the following message, prompting the user to install:
  • install Bu uygulama?
  • Upon installing, it drops the following files:
    • C:\system\apps\s32cnr\s32cnr.app
    • C:\system\apps\s32cnr\s32cnr.aif
    • C:\system\apps\s32cnr\s32cnr_caption.rsc
  • Pretends to be an MSN application. It comes into effect if the HandyMSN application is installed. Once the user executes it and inputs the account and password, these information are sent to a remote user by SMS. The infected mobile phone can then be controlled by the remote attacker.
  • Recommended Action

  • Delete all the dropped files using a file manager program.

  • Reference: ID - 341900