Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Malware Information Pages: Trojan:SymbOS/SrvSender

[Summary] | [Disinfection] | [Detailed Description]

Name : Trojan:SymbOS/SrvSender
Alias:Trojan:SymbOS/SrvSender.A
Type:Trojan
Category:Malware
Platform:SymbOS
Radar

Summary
Trojan:SymbOS/SrvSender affects Symbian Series 60 Second Edition devices.

SrvSender responds to all incoming messages and phone calls with a random SMS message and removes all traces of some incoming messages.
Back to the Top

Disinfection

Disinfecting using F-Secure Mobile Anti-Virus
  1. Download F-Secure Mobile Anti-Virus from http://f-secure.mobi
    and activate the Anti-Virus
  2. Scan the phone and remove any components of the malware
  3. Reboot the phone to remove memory resident components

Disinfection for the cases when phone cannot start up

CAUTION! this method will remove all data on the device including calendar and phone numbers:

  1. Power off the phone
  2. Hold the following three buttons down - "answer call" + "*" + "3"
  3. Keep holding down the buttons and power on the phone
  4. Depending on the model, you will either get text that reads "formatting" or a start-up dialog that asks for the initial phone settings
  5. Your phone is now formatted and can be used again

To prevent future infections, please download F-Secure Mobile Anti-Virus from here: http://f-secure.mobi.
Back to the Top

Detailed Description
Trojan:SymbOS/SrvSender affects Symbian Series 60 Second Edition devices.

SrvSender responds to all incoming messages and voice calls with a random SMS message. It removes all traces of all incoming SMS messages.

SymbOS/SrvSender.A has following features.

It attempts to kill the following processes:

  • Euninstall
  • Ewapstore

It attempts to remove the following files:

  • \system\recogs\AppToolkit.mdl
  • \system\recogs\RecMemCard.mdl

It deletes incoming MMS messages containing attachments with the following extension:

  • install
  • sis
  • app
  • exe
  • jar
  • jad

SrvSender.A creates a file containing logs of some of its activities in the following location:

  • C:\system\data\apple.txt.
Back to the Top



F-Secure Corporation

Last Modified: March 07, 2008