Skip to main content

Worm:SymbOS/Yxe

Classification

Category:

Malware

Platform:

SymbOS

Type:

Worm

Aliases:

  • Worm:SymbOS/Yxe
  • SymbOS.Worm.Yxe.A
  • Worm:SymbOS/Yxe.gen
  • SymbOS/Yxes.A!worm
  • Transmitter (Other)

Summary

Worm:SymbOS/Yxe is the first malicious software to target Symbian S60 3rd Edition Phones.

Removal

Technical Details

Worm:SymbOS/Yxe variants are complied for S60 3rd Edition phones and will not install on older Symbian phones.

Variants of Worm:SymbOS/Yxe include:

  • Worm:SymbOS/Yxe.gen
  • Worm:SymbOS/Yxe.A
  • Worm:SymbOS/Yxe.B
  • Worm:SymbOS/Yxe.C
  • Worm:SymbOS/Yxe.D

Installation

Social engineering is used to entice the user into installing Yxe.

The installer prompts the user to install "Sexy View" by the vendor "Play Boy".

The user is offered English and Chinese language options. However, there is no user interface.

Yxe variants have been Symbian signed using a valid certificate. They will install normally on S60 3rd Edition phones. The certificate used by Yxe are in the process of being revoked. The disinfection section contains additional details regarding certificates.

Actions

Yxe starts automatically when the phone boots and attempts to terminate:

  • AppMngr

Yxe attempts to avoid debugging and terminates the processes of many third party file/process viewing utilities.

  • ActiveFile
  • TaskMan
  • TaskSpy
  • Y-Tasks

Yxe collects data about the phone.

It will attempt to open an HTTP connection in order to upload the data and keeps the connection open at all times.

The domain list to which Yxe attempts to connect is encrypted within the code of Yxe.

Once connected it starts writing a log file called mr.log. It creates a sis file named "c:\data\root.sisx".

Yxe modifies the file C:\system\data\System.ini.

It will attempt to send SMS messages to the phone's contact list.

Removal

Worm:SymbOS/Yxe will uninstall itself. The name in the application manager depends on the variant.

The name "Sexy View" has been used by early Yxe variants. See the disinfection section for additional details.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.