1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Trojan:SymbOS/Doomboot.Q

Name : Trojan:SymbOS/Doomboot.Q
Detection Names : SymbOS/Doomboot.Q
Category:Malware
Type:Trojan
Platform:SymbOS
Date of Discovery:April 22, 2007

Summary

Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate.

Disinfection

F-Secure Mobile Anti-Virus will detect and disinfect Doomboot.Q
  • Remove the SIS file in which the Doomboot.Q was installed
  • Open web browser on the phone
  • Go to http://phoneav.com
  • Select link "Download antivirus software for your smartphone" and then
  • Select phone model
  • Download the file and select open after download
  • Install F-Secure Mobile Anti-Virus
  • Go to applications menu and start Anti-Virus
  • Activate Anti-Virus and scan all files
Disinfection for the cases when phone is already rebooted and cannot start up

CAUTION! this method will remove all data on the device including calendar and phone numbers

Sometimes Doomboot.Q installs the corrupted file on memory card, so try to boot without the card. If the phone still does not boot use the instructions below.
  • Power off the phone
  • Hold following three buttons down "answer call" + "*" + "3"
  • Keep holding the buttons and power on the phone
  • Depending on the model, you either get text "formatting" or startup dialog that asks for initial phone settings
  • Your phone is now formatted and can be used again

Additional Details

Trojan:SymbOS/Doomboot.Q affects devices running the Symbian S60 operating system. It is distributed in a malicious SIS file and when executed, installs corrupted system binary files. If the device is rebooted, on startup it will load the corrupted binaries, which then cause the phone to crash.

Technically, Doomboot.Q is very similar to the previously released variant, Trojan:SymbOS/Doomboot.C.



Note

If the device has been infected with Doomboot.Q, it is important not to restart it before disinfection has been completed. Follow the disinfection instructions below.

If the device has been rebooted and will not start again, it may be recovered with teh hard format key code that is entered during the phone's startup.



Detection

F-Secure Mobile Anti-Virus will detect and disinfect Doomboot.Q if it is in the default Enabled setting.