F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Doomboot.J

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:Doomboot.J
ALIAS:SymbOS/Doomboot.J

Summary

Doomboot.J is close variant to Doomboot.B. The major difference between Doomboot.J and Doomboot.B is that the Doomboot.J does contain also application files from Fontal.A.

If you have installed Doomboot.J, the most important thing is not to reboot the phone and follow the disinfection instruction in this description.

If you have rebooted the phone and the phone will not start again, the phone can be recovered with hard format key code that is entered in the phone boot. Please refer to your phone manual for the code.

Disinfection

Disinfection with two Series 60 phones

Download F-Skulls tool from ftp://ftp.f-secure.com/anti-virus/tools/f-skulls.zip or directly with phone http://www.europe.f-secure.com/tools/f-skulls.sis

1. Install F-Skulls.sis into infected phones memory card with a clean phone
2. Put the memory card with F-Skulls into infected phone
3. Start up the infected phone, the application menu should work now
4. Go to application manager and uninstall the SIS file in which you installed the Doomboot variant
5. Download and install F-Secure Mobile Anti-Virus to remove any files dropped by the Doomboot variant http://www.f-secure.com/wireless/download or with phone web browser http://mobile.f-secure.com
6. Activate Anti-Virus and scan all files to make sure that your phone is clean from malware

Disinfection for the cases when phone is already rebooted and cannot start up

CAUTION! this method will remove all data on the device including calendar and phone numbers

1. Power off the phone
2. Hold following three buttons down "answer call" + "*" + "3"
3. Keep holding the buttons and power on the phone
4. Depending on the model, you either get text "formatting" or startup dialog that asks for initial phone settings
5. Your phone is now formatted and can be used again


Back to the Top


Detailed Description

Installation to system Doomboot.J installs corrupted system binaries into C:\ drive of the phone. When phone boots this corrupted binaries will be loaded instead of the correct ones, and the phone will crash at boot.

In addition of installing the corrupted system binaries the Doomboot.J also damages the application manager so that it cannot be uninstalled, and no new applications can be installed before the phone is disinfected.

Spreading in Symbian_DFT v1.0.sis

Payload Installs corrupted system binaries.


Back to the Top


Detection

Generic detection that detects Doomboot.J was published for F-Secure Mobile Anti-Virus on March 7th, 2005 in database build number 28.


Back to the Top


Write-up: Mika Tolvanen November 29th, 2005;

F-Secure Corporation