Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Malware Information Pages: Trojan:WinCE/InfoJack

[Summary] | [Disinfection] | [Detailed Description]

Name : Trojan:WinCE/InfoJack
Alias:WCE/Meiti, WinCE/Mepos, Trojan:WinCE/InfoJack.A, WinCE.Infomeiti
Type:Trojan
Category:Malware
Platform:WinCE
Radar

Summary
Trojan:WinCE/InfoJack a trojan effecting Windows Mobile devices.
Back to the Top

Disinfection

Disinfecting using F-Secure Mobile Anti-Virus
  1. Download F-Secure Mobile Anti-Virus from http://f-secure.mobi
    and activate the Anti-Virus
  2. Scan the phone and remove any components of the malware
  3. Reboot the phone to remove memory resident components
Back to the Top

Detailed Description
InfoJack is a trojan effecting Windows Mobile devices that leaks information from the device to a home server when the device connects to the Internet.

As a part of its activity, InfoJack alters the security settings on the device. This causes all software installations to complete without any warning of possible safety precautions.

Trojan:WinCE/InfoJack is a multiple part malware.

The first part is attached to many (.cab) installation files containing legitimate software such as games, mapping software, et cetera. InfoJack pretends to be an additional setup program.

Once InfoJack has infected the device it waits for the device to make an Internet connection. When the device is connected, InfoJack connects to its home server and downloads additional parts for its functionality. While doing so leaks information from the device to the server.

As a component of its functionality, InfoJack changes the security settings on the device to allow all software installations to complete without any warnings.

InfoJack.A was discovered in February 2008.

On the device InfoJack.A installs following files:

  • \windows\mservice.exe
  • \windows\setup.cfg

Initial analysis indicates that InfoJack.A attempts to download a zip file which contains at least the following:

  • \windows\mservice2.exe

As of February 29, 2008, the site from which InfoJack.A attempts to connect is offline and is not available. This prevents further analysis of the zip file.
Back to the Top



F-Secure Corporation

Last Modified: February 29, 2008