病毒名称:
SymbOS.Cardtrp.A
类别: 手机病毒
病毒资料:
该病毒长度 168,784 字节,感染使用 Symbin S60 系统的智能手机,当感染此病毒的手机中的记忆卡插入电脑的读卡器时,病毒会给电脑安装一个木马 Backdoor.Berbew.N ,此病毒还释放手机病毒 SymbOS.Cabir.B,破坏手机程序运行,当收到、打开此病毒时,有以下危害:
A 生成以下列表中的文件,破坏手机程序执行
E:\System\Apps\WILDSKIN\WILDSKIN.App
C:\System\Apps\WALLETAVMGMT\WALLETAVMGMT.App
C:\System\Apps\Voicerecorder\Voicerecorder.app
C:\System\Apps\VoiceRec\VoiceRec.app
C:\System\Apps\VM\Vm.app
C:\System\Apps\Videorecorder\VideoRecorder.app
C:\System\Apps\VCommand\VCommand.app
E:\System\Apps\UVSMStyle\UVSMStyle.App
E:\System\Apps\Ultramp3\UltraMP3.App
C:\System\Apps\Todo\Todo.app
E:\System\Apps\SystemEXPlorer\SystemExplorer.App
C:\System\Apps\sSaver\sSaver.App
C:\System\Apps\SpeedDial\Speeddial.app
E:\System\Apps\Sounder\Sounder.App
C:\System\Apps\SnakeEx\SnakeEx.app
E:\System\Apps\SmsMachine\SmsMachine.App
E:\System\Apps\SmartMovie\SmartMovie.App
E:\System\Apps\SmartAnswer\SmartAnswer.App
C:\System\Apps\SimDir\SimDir.app
E:\System\Apps\ScreenCap\ScreenCap.app
C:\System\Apps\SatUi\Satui.app
E:\System\Apps\RingMaster\RingMaster.App
C:\System\Apps\RealPlayer\RealPlayer.app
E:\System\Apps\RallyProContest\RallyProContest.App
E:\System\Apps\PVPlayer\PVPlayer.App
C:\System\Apps\Psln\PSLN.app
C:\System\Apps\ProfileApp\ProfileApp.app
C:\System\Apps\Pinboard\Pinboard.app
E:\System\Apps\PhotoSMS\PhotoSMS.App
E:\System\Apps\PhotoSafe\PhotoSafe.App
E:\System\Apps\Photographer\Photographer.app
E:\System\Apps\PhotoEditor\PhotoEditor.app
C:\System\Apps\PhotoAlbum\PhotoAlbum.app
E:\System\Apps\photoacute\photoacute.App
C:\System\Apps\PhoneBook\PhoneBook.app
\System\Apps\Phone\FREAKPHONE_CAPTION.RSC
\System\Apps\Phone\FREAKPHONE.RSC
E:\System\Apps\Phone\FREAKPHONE.APP
E:\System\Apps\Phone\FreakPhone.aif
C:\System\Apps\NSmlDSSync\NSmlDSSync.app
C:\System\Apps\Notepad\Notepad.app
C:\System\Apps\MusicPlayer\MusicPlayer.app
E:\System\Apps\Mp3Player\Mp3Player.App
E:\System\Apps\Mp3Go\Mp3Go.App
C:\System\Apps\mmp\mmp.App
C:\System\Apps\MMCApp\MMCApp.app
C:\System\Apps\MixPix\MixPix.app
C:\System\Apps\MidpUi\MidpUi.app
E:\System\Apps\MIDIED\MIDIED.App
\System\Apps\Menu\FreakMenu_caption.rsc
\System\Apps\Menu\FREAKMENU.RSC
\System\Apps\Menu\FREAKMENU.APP
E:\System\Apps\Menu\FreakMenu.aif
C:\System\Apps\Mediaplayer\MediaPlayer.app
C:\System\Apps\MediaGallery\MediaGallery.app
C:\System\Apps\MCE\MCE.app
C:\System\Apps\Logs\Logs.app
E:\System\Apps\logoMan\logoMan.app
E:\System\Apps\Launcher\Launcher.app
E:\System\Apps\KPCaMain\KPCaMain.App
E:\System\Apps\Jelly\Jelly.App
E:\System\Apps\irremote\irRemote.App
C:\System\Apps\IrApp\IrApp.app
E:\System\Apps\HantroCP\HantroCP.App
E:\System\Apps\Hair\Hair.App
C:\System\Apps\GS\GS.app
E:\System\Apps\FSCaller\FSCaller.App
C:\System\Apps\FMRadio\FMRadio.app
C:\System\Apps\FileManager\FileManager.app
E:\System\Apps\FExplorer\FExplorer.App
C:\System\Apps\Fdn\FDN.app
C:\System\Apps\FaxModemUi\FaxModemUi.app
E:\System\Apps\FaceWarp\FaceWarp.App
E:\System\Apps\extendedrecorder\extendedrecorder.App
E:\System\Apps\ETIPlayer\ETIPlayer.App
E:\System\Apps\ETIMovieAlbum\ETIMovieAlbum.App
E:\System\Apps\ETICamcorder\ETICamcorder.App
C:\System\Apps\CSHelp\CSHelp.app
C:\System\Apps\Converter\Converter.app
C:\System\Apps\ConnectionMonitorUi\ConnectionMonitorUi.app
C:\System\Apps\Composer\Composer.app
C:\System\Apps\ClockApp\ClockApp.app
E:\System\Apps\CF\CF.app
E:\System\Apps\camerafx\CameraFX.App
C:\System\Apps\Camera\Camera.app
C:\System\Apps\Camcorder\Camcorder.app
E:\System\Apps\Camcoder\Camcoder.App
E:\System\Apps\CallManager\CallManager.App
E:\System\Apps\callcheater\callcheater.app
C:\System\Apps\Calendar\Calendar.app
C:\System\Apps\CalcSoft\CalcSoft.app
C:\System\Apps\Browser\Browser.app
E:\System\Apps\BlueJackX\BlueJackX.App
E:\System\Apps\BlackList\BlackList.App
C:\System\Apps\AppMngr\AppMngr.app
C:\System\Apps\AppCtrl\AppCtrl.app
E:\System\Apps\AnswRec\AnswRec.App
E:\System\Apps\AD7650\AD7650.App
C:\System\Apps\About\About.app
B 释放手机病毒 SymbOS.Cabir.B 到以下文件:
CARIBE.SIS
\system\apps\caribe\caribe.app
\system\apps\caribe\flo.mdl
\system\apps\caribe\caribe.rsc
C 复制以下文件到手机记忆卡:
SYSTEM.exe (一个蠕虫病毒)
fsb.exe (木马Backdoor.Berbew.N)
buburuz.ICO ,图标如下:
autorun.inf (启动木马 fsb.exe 的配置文件)
D 如果计算机的自动执行(autorun 默认为开)打开,感染此病毒的手机中的记忆卡插入电脑的读卡器时,病毒会给电脑安装木马 Backdoor.Berbew.N
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
Windows下的PE病毒。
发现日期:
2005-9-26