Trojan:SymbOS/SrvSender

Classification

Category :

Malware

Type :

Trojan

Platform :

SymbOS

Aliases :

Trojan:SymbOS/SrvSender, Trojan:SymbOS/SrvSender

Summary

Trojan:SymbOS/SrvSender affects Symbian Series 60 Second Edition devices.SrvSender responds to all incoming messages and phone calls with a random SMS message and removes all traces of some incoming messages.

Removal

Disinfecting using F-Secure Mobile Security

  • Download F-Secure Mobile Security and activate it
  • Scan the phone and remove any components of the malware
  • Reboot the phone to remove memory resident components

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

Trojan:SymbOS/SrvSender affects Symbian Series 60 Second Edition devices.

SrvSender responds to all incoming messages and voice calls with a random SMS message. It removes all traces of all incoming SMS messages.

SymbOS/SrvSender.A has following features.

It attempts to kill the following processes:

  • Euninstall
  • Ewapstore

It attempts to remove the following files:

  • \system\recogs\AppToolkit.mdl
  • \system\recogs\RecMemCard.mdl

It deletes incoming MMS messages containing attachments with the following extension:

  • install
  • sis
  • app
  • exe
  • jar
  • jad

SrvSender.A creates a file containing logs of some of its activities in the following location:

  • C:\system\data\apple.txt.