病毒名称:
Symbian.Skulls.B
类别: Trojan
病毒资料:
别名: SymbOS/Skulls.B
概述: Skulls.B 是 SymbOS/Skulls.A 木马的一个变种,与 Skulls.A 功能相似但使用不同文件。
Skulls.B 是一个恶意 SIS 文件木马,用无法使用的版本替换系统应用程序,并向手机释放 SymbOS/Cabir.B 蠕虫。
Skulls.B 释放的 Cabir 不会自动激活,但如果用户在手机菜单中点击 cabir 图标运行 Cabir , Cabir.c 会激活并试图感染其他手机。
原始 Skulls.B SIS 文件命名为 "Icons.SIS" 。与 Skulls.A 不同,安装时 Skulls.B 变种不显示任何弹出的信息(除了操作系统显示的 " 安装安全警告 - 无法验证提供者 " 信息)。
Skulls.B 用一般的应用程序图标,而不是骷髅与十字骨头图标,替换标准应用程序图标。
如果安装 Skulls.B ,手机只有呼叫和应答可以使用。所有需要某个系统统应用程序的功能,如 SMS 和 MMS 信息、网页浏览和照相都将无法使用。除了应用程序无法使用以外,手机也会感染 Cabir.B ,幸运的是它不能自动激活。
如果你已经安装 Skulls.B ,最重要的是不要重启手机。
详细描述:
Skulls.B 会产生以下文件来覆盖系统程序,使系统无法正常工作:
c:/system/apps/about/about.aif
c:/system/apps/about/about.app
c:/system/apps/appinst/appinst.aif
c:/system/apps/appinst/appinst.app
c:/system/apps/appmngr/appmngr.aif
c:/system/apps/appmngr/appmngr.app
c:/system/apps/autolock/autolock.aif
c:/system/apps/autolock/autolock.app
c:/system/apps/browser/browser.aif
c:/system/apps/browser/browser.app
c:/system/apps/BTui/btui.aif
c:/system/apps/btui/btui.app
c:/system/apps/bva/bva.aif
c:/system/apps/bva/bva.app
c:/system/apps/calcsoft/calcsoft.aif
c:/system/apps/calcsoft/calcsoft.app
c:/system/apps/calendar/calendar.aif
c:/system/apps/calendar/calendar.app
c:/system/apps/camcorder/camcorder.aif
c:/system/apps/camcorder/camcorder.app
c:/system/apps/camtimer/camtimer.app
c:/system/apps/camtimer/camtimer.rsc
c:/system/apps/caribe/caribe.app
c:/system/apps/caribe/caribe.rsc
c:/system/apps/caribe/flo.mdl
c:/system/apps/cbsuiapp/cbsuiapp.aif
c:/system/apps/cbsuiapp/cbsuiapp.app
c:/system/apps/certsaver/certsaver.aif
c:/system/apps/certsaver/certsaver.app
c:/system/apps/chat/chat.aif
c:/system/apps/chat/chat.app
c:/system/apps/clockapp/clockapp.aif
c:/system/apps/clockapp/clockapp.app
c:/system/apps/codviewer/codviewer.aif
c:/system/apps/codviewer/codviewer.app
c:/system/apps/connectionmonitorui/connectionmonitorui.aif
c:/system/apps/connectionmonitorui/connectionmonitorui.app
c:/system/apps/converter/converter.aif
c:/system/apps/converter/converter.app
c:/system/apps/cshelp/cshelp.aif
c:/system/apps/cshelp/cshelp.app
c:/system/apps/ddviewer/ddviewer.aif
c:/system/apps/ddviewer/ddviewer.app
c:/system/apps/filemanager/filemanager.aif
c:/system/apps/filemanager/filemanager.app
c:/system/apps/gs/gs.aif
c:/system/apps/gs/gs.app
c:/system/apps/imageviewer/imageviewer.aif
c:/system/apps/imageviewer/imageviewer.app
c:/system/apps/location/location.aif
c:/system/apps/location/location.app
c:/system/apps/logs/logs.aif
c:/system/apps/logs/logs.app
c:/system/apps/mce/mce.aif
c:/system/apps/mce/mce.app
c:/system/apps/mediagallery/mediagallery.aif
c:/system/apps/mediagallery/mediagallery.app
c:/system/apps/mediaplayer/mediaplayer.aif
c:/system/apps/mediaplayer/mediaplayer.app
c:/system/apps/mediasettings/mediasettings.aif
c:/system/apps/mediasettings/mediasettings.app
c:/system/apps/menu/menu.aif
c:/system/apps/menu/menu.app
c:/system/apps/mmcapp/mmcapp.aif
c:/system/apps/mmcapp/mmcapp.app
c:/system/apps/mmm/mmm.aif
c:/system/apps/mmm/mmm.app
c:/system/apps/mmseditor/mmseditor.aif
c:/system/apps/mmseditor/mmseditor.app
c:/system/apps/mmsviewer/mmsviewer.aif
c:/system/apps/mmsviewer/mmsviewer.app
c:/system/apps/msgmaileditor/msgmaileditor.aif
c:/system/apps/msgmaileditor/msgmaileditor.app
c:/system/apps/msgmailviewer/msgmailviewer.aif
c:/system/apps/msgmailviewer/msgmailviewer.app
c:/system/apps/musicplayer/musicplayer.aif
c:/system/apps/musicplayer/musicplayer.app
c:/system/apps/notepad/notepad.aif
c:/system/apps/notepad/notepad.app
c:/system/apps/npdviewer/npdviewer.aif
c:/system/apps/npdviewer/npdviewer.app
c:/system/apps/nsmldmsync/nsmldmsync.aif
c:/system/apps/nsmldmsync/nsmldmsync.app
c:/system/apps/nsmldssync/nsmldssync.aif
c:/system/apps/nsmldssync/nsmldssync.app
c:/system/apps/phone/phone.aif
c:/system/apps/phone/phone.app
c:/system/apps/phonebook/phonebook.aif
c:/system/apps/phonebook/phonebook.app
c:/system/apps/pinboard/pinboard.aif
c:/system/apps/pinboard/pinboard.app
c:/system/apps/presence/presence.aif
c:/system/apps/presence/presence.app
c:/system/apps/profileapp/profileapp.aif
c:/system/apps/profileapp/profileapp.app
c:/system/apps/provisioningcx/provisioningcx.aif
c:/system/apps/provisioningcx/provisioningcx.app
c:/system/apps/psln/psln.aif
c:/system/apps/psln/psln.app
c:/system/apps/pushviewer/pushviewer.aif
c:/system/apps/pushviewer/pushviewer.app
c:/system/apps/satui/satui.aif
c:/system/apps/satui/satui.app
c:/system/apps/schemeapp/schemeapp.aif
c:/system/apps/schemeapp/schemeapp.app
c:/system/apps/screensaver/screensaver.aif
c:/system/apps/screensaver/screensaver.app
c:/system/apps/sdn/sdn.aif
c:/system/apps/sdn/sdn.app
c:/system/apps/simDirectory/simdirectory.aif
c:/system/apps/simdirectory/simdirectory.app
c:/system/apps/smseditor/smseditor.aif
c:/system/apps/smseditor/smseditor.app
c:/system/apps/smsviewer/smsviewer.aif
c:/system/apps/smsviewer/smsviewer.app
c:/system/apps/speeddial/speeddial.aif
c:/system/apps/speeddial/speeddial.app
c:/system/apps/startup/startup.aif
c:/system/apps/startup/startup.app
c:/system/apps/sysap/sysap.aif
c:/system/apps/sysap/sysap.app
c:/system/apps/todo/todo.aif
c:/system/apps/todo/todo.app
c:/system/apps/ussd/ussd.aif
c:/system/apps/ussd/ussd.app
c:/system/apps/vcommand/vcommand.aif
c:/system/apps/vcommand/vcommand.app
c:/system/apps/vm/vm.aif
c:/system/apps/vm/vm.app
c:/system/apps/voicerecorder/voicerecorder.aif
c:/system/apps/voicerecorder/voicerecorder.app
c:/system/apps/walletavmgmt/walletavmgmt.aif
c:/system/apps/walletavmgmt/walletavmgmt.app
c:/system/apps/walletavota/walletavota.aif
c:/system/apps/walletavota/walletavota.app
c:/system/caribesecuritymanager/camtimer.sis
c:/system/caribesecuritymanager/caribe.app
c:/system/caribesecuritymanager/caribe.rsc
c:/system/recogs/flo.mdl
Skulls 自带的Cabir.c蠕虫安装时不会自动运行,但是如果重新启动手机后会自动运行。
复制和传播方式:
skulls.b 本身不会对外传播,也不会复制自身。但是它释放出来的cabir.c蠕虫会复制自身并通过蓝牙传播(更多 cabir.c 细节请参看cabir.c病毒介绍)。
病毒的清除法:
使用光华反病毒软件 手机版,彻底删除。
病毒演示:
病毒FAQ:
Symbian系统下的病毒。
发现日期:
2007-2-15