F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Doomboot.B

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:Doomboot.B
ALIAS:SymbOS/Doomboot.B

Summary

Doomboot.B is close variant to Doomboot.A. The major difference between Doomboot.B and Doomboot.A is that the Doomboot.B does not contain Commwarrior and contains application that reboots the phone.

Doomboot.B pretends to be an utility that can be used to reboot a phone. The Doomboot.B actually contains an utility that is used to reboot the phone, but when user uses this application, the corrupted binaries in Doomboot prevent the phone from booting again.

If you have installed Doomboot.B, the most important thing is not to reboot the phone and follow the disinfection instruction in this description.

If you have rebooted the phone and the phone will not start again, the phone can be recovered with hard format key code that is entered in the phone boot. Please refer to your phone manual for the code.

Disinfection

Disinfection with F-Secure Anti-Virus

F-Secure Mobile Anti-Virus will detect and disinfect Doomboot.B

1. Open web browser on the phone
2. Go to http://phoneav.com
3. Select link "Download antivirus software for your smartphone" and then select phone model
4. Download the file and select open after download
5. Install F-Secure Mobile Anti-Virus
6. Go to applications menu and start Anti-Virus
7. Activate Anti-Virus and scan all files

Disinfection for the cases when phone is already rebooted and cannot start up

CAUTION! this method will remove all data on the device including calendar and phone numbers

1. Power off the phone
2. Hold following three buttons down "answer call" + "*" + "3"
3. Keep holding the buttons and power on the phone
4. Depending on the model, you either get text "formatting" or startup dialog that asks for initial phone settings
5. Your phone is now fomatted and can be used again


Back to the Top


Detailed Description

Installation to system Doomboot.B installs corrupted system binaries into C:\ drive of the phone. When phone boots this corrupted binaries will be loaded instead of the correct ones, and the phone will crash at boot.

Spreading in Restart_20.sis

Payload Installs corrupted system binaries.


Back to the Top


Detection

Generic detection that detects Doomboot.B was published for F-Secure Mobile Anti-Virus on March 7th, 2005 in database build number 28.


Back to the Top


Write-up: Jarno Niemela August 26th, 2005;

Description updated: Jarno Niemela September 7th, 2005;

F-Secure Corporation