SymbOS/Skuller.R!tr

description-logoAnalysis

SymbOS/Skuller.R!tr - 06-08-01


General Info:

This threat has a file size: 72992

More Info:

1. When install,it will display the following message: This Installation was created with KVT Symbian Installer. Get it free from : www.kvtsoft.vze.com by Kheng Vantha --------------- www.mobileworld.com.my ~##battam hacker### www.f-secure.com www.lowyat.net MALAYSIA HACKER TEAM, TOWUT, Dotsis, fucker?? 2. The virus drop the following files and folders on the mobile phone to block access to the normal application : !:\System\Apps\Anti-Virus\backup\FSBioMessageParser.dll !:\System\Apps\Anti-Virus\backup\FSBioMessage.bif !:\System\Apps\Anti-Virus\backup\AVBioIcons.mbm !:\System\Apps\Voicerecorder\Voicerecorder.aif !:\System\Apps\VCommand\VCommand.aif !:\System\Apps\Ussd\Ussd.aif !:\System\Apps\ToDo\ToDo.aif !:\System\Apps\Speeddial\Speeddial.aif !:\System\Apps\SmsViewer\SmsViewer.aif !:\System\Apps\SmsEditor\SmsEditor.aif !:\System\Apps\SmartFileMan\SmartFileMan.aif !:\System\Apps\SimDirectory\SimDirectory.aif !:\System\Apps\Sdn\Sdn.aif !:\System\Apps\ScreenSaver\ScreenSaver.aif !:\System\Apps\SchemeApp\SchemeApp.aif !:\System\Apps\Satui\Satui.aif !:\System\Apps\PushViewer\PushViewer.aif !:\System\Apps\PSLN\PSLN.aif !:\System\Apps\ProvisioningCx\ProvisioningCx.aif !:\System\Apps\PRESENCE\PRESENCE.aif !:\System\Apps\Pinboard\Pinboard.aif !:\System\Apps\Phonebook\Phonebook.aif !:\System\Apps\NSmlDSSync\NSmlDSSync.aif !:\System\Apps\NSmlDMSync\NSmlDMSync.aif !:\System\Apps\NpdViewer\NpdViewer.aif !:\System\Apps\Notepad\Notepad.aif !:\System\Apps\MusicPlayer\MusicPlayer.aif !:\System\Apps\MsgMailViewer\MsgMailViewer.aif !:\System\Apps\MsgMailEditor\MsgMailEditor.aif !:\System\Apps\MmsViewer\MmsViewer.aif !:\System\Apps\About\About.aif !:\System\Apps\Anti-Virus\Anti-Virus.aif !:\System\Apps\Anti-Virus\Anti-Virus.app !:\System\Apps\Anti-Virus\Anti-Virus.rsc !:\System\Apps\Anti-Virus\FSAV.dll !:\System\Apps\Anti-Virus\FSAVDT.exe ... (Note :too many too list all of them) All of the above applications icon changes to skull icon.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR