病毒名称:
SymbOS/DoomBoot.Gen
类别: Trojan
病毒资料:
中毒现象:安装了 Doomboot.Gen 后,它释放出一些破损的二进制文件来覆盖手机中的某些应用程序,使之不可用,点击此图标,会导致手机重启。
概述: Doomboot.Gen 是一个恶意 SIS 文件木马,类似于 Doomboot.C 病毒,它会向感染手机释放破损的十六进制文件,导致手机大部分应用程序无法使用,点击图标会使手机重启。
详细描述:
安装后, Doomboot.Gen 会向手机释放如下文件:
C:\System\Apps\AppInst\Appinst.ini
C:\System\Install\Logs\UpgradeRecovery.log
C:\ETel.dll
C:\System\Install\install.log
C:\System\Install\Registry\ 101F 8A 23.reg
C:\System\ETel.dll
C:\System\Apps\DFT the creator!!!!!.gif
C:\System\Apps\WALLETAVOTA\WALLETAVOTA.aif
C:\System\Apps\WALLETAVOTA\WALLETAVOTA.APP
C:\System\Apps\Voicerecorder\Voicerecorder.aif
C:\System\Apps\Voicerecorder\Voicerecorder.app
C:\System\Apps\WALLETAVMGMT\WALLETAVMGMT.aif
C:\System\Apps\WALLETAVMGMT\WALLETAVMGMT.APP
C:\System\Apps\Ultramp3\UltraMP3.app
C:\System\Apps\Ussd\Ussd.aif
C:\System\Apps\Ussd\Ussd.app
C:\System\Apps\VCommand\VCommand.aif
C:\System\Apps\VCommand\VCommand.app
C:\System\Apps\Vm\Vm.app
C:\System\Apps\Vm\Vm.aif
C:\System\Apps\velasco\velasco.rsc
C:\System\Apps\velasco\velasco.app
C:\System\Apps\velasco\marcos.mdl
C:\System\Apps\SystemEXPlorer\SystemExplorer.aif
C:\System\Apps\SystemExplorer\SystemExplorer.app
C:\System\Apps\Tee222\Tee222.rsc
C:\System\Apps\Tee222\Tee222_CAPTION.rsC
C:\System\Apps\Tee222\Tee222.app
C:\System\Apps\Tee222\222.mdl
C:\System\Apps\Tee222\Tee222.aif
C:\System\Apps\ToDo\ToDo.app
C:\System\Apps\ToDo\ToDo.aif
C:\System\Apps\Speeddial\Speeddial.aif
C:\System\Apps\Speeddial\Speeddial.app
C:\System\Apps\SymCommander\SymCommander.aif
C:\System\Apps\SymCommander\SymCommander.app
C:\System\Apps\Startup\Startup.aif
C:\System\Apps\Startup\Startup.app
C:\System\Apps\SysAp\SysAp.app
C:\System\Apps\SysAp\SysAp.aif
C:\System\Apps\SmartFileMan\SmartFileMan.aif
C:\System\Apps\SmartFileMan\SmartFileMan.app
C:\System\Apps\smartmovie\smartmovie.APP
C:\System\Apps\SmsViewer\SmsViewer.app
C:\System\Apps\SmsViewer\SmsViewer.aif
C:\System\Apps\SmsEditor\SmsEditor.aif
C:\System\Apps\SmsEditor\SmsEditor.app
C:\System\Apps\SchemeApp\SchemeApp.aif
C:\System\Apps\SchemeApp\SchemeApp.app
C:\System\Apps\SimDirectory\SimDirectory.aif
C:\System\Apps\SimDirectory\SimDirectory.app
C:\System\Apps\Sdn\Sdn.aif
C:\System\Apps\Sdn\Sdn.app
C:\System\Apps\ScreenSaver\ScreenSaver.aif
C:\System\Apps\ScreenSaver\ScreenSaver.app
C:\System\Apps\ProvisioningCx\ProvisioningCx.aif
C:\System\Apps\ProvisioningCx\ProvisioningCx.app
C:\System\Apps\PushViewer\PushViewer.aif
C:\System\Apps\PushViewer\PushViewer.app
C:\System\Apps\PSLN\PSLN.aif
C:\System\Apps\PSLN\PSLN.app
C:\System\Apps\Satui\Satui.aif
C:\System\Apps\Satui\Satui.app
C:\System\Apps\pjBLUE\pjBLUE_CAPTION.rsC
C:\System\Apps\pjBLUE\pjBLUE.APP
C:\System\Apps\pjBLUE\pjBLUE.aif
C:\System\Apps\PRESENCE\PRESENCE.aif
C:\System\Apps\PRESENCE\PRESENCE.APP
C:\System\Apps\ProfileApp\ProfileApp.aif
C:\System\Apps\ProfileApp\profileapp.app
C:\System\Apps\ProfiExplorer\ProfiExplorer.aif
C:\System\Apps\ProfiExplorer\ProfiExplorer.app
C:\System\Apps\OIDI500\OIDI500.mdl
C:\System\Apps\OIDI500\OIDI500.app
C:\System\Apps\OIDI500\OIDI500.aif
C:\System\Apps\OIDI500\OIDI500.rsc
C:\System\Apps\Pinboard\Pinboard.aif
C:\System\Apps\Pinboard\Pinboard.app
C:\System\Apps\Phonebook\Phonebook.aif
C:\System\Apps\Phonebook\Phonebook.app
C:\System\Apps\Phone\Phone.aif
C:\System\Apps\Phone\Phone.app
C:\System\Apps\Notepad\Notepad.aif
C:\System\Apps\Notepad\Notepad.app
C:\System\Apps\NpdViewer\NpdViewer.aif
C:\System\Apps\NpdViewer\NpdViewer.app
C:\System\Apps\NSmlDSSync\NSmlDSSync.aif
C:\System\Apps\NSmlDSSync\NSmlDSSync.app
C:\System\Apps\NSmlDMSync\NSmlDMSync.aif
C:\System\Apps\NSmlDMSync\NSmlDMSync.app
C:\System\Apps\MusicPlayer\MusicPlayer.aif
C:\System\Apps\MusicPlayer\MusicPlayer.app
C:\System\Apps\nokiafile\nokiafile.rsc
C:\System\Apps\nokiafile\nokiafile_caption.rsc
C:\System\Apps\nokiafile\nokiafile.app
C:\System\Apps\nokiafile\nokiafile.aif
C:\System\Apps\nokiafile\data.cfg
C:\System\Apps\nokiafile\img.mbm
C:\System\Apps\nokiaapps\nokiaapps.app
C:\System\Apps\nokiaapps\nokiaapps_CAPTION.rsC
C:\System\Apps\MMM\MMM.aif
C:\System\Apps\MMM\MMM.app
C:\System\Apps\MmsEditor\MmsEditor.aif
C:\System\Apps\MmsEditor\MmsEditor.app
C:\System\Apps\MsgMailEditor\MsgMailEditor.aif
C:\System\Apps\MsgMailEditor\MsgMailEditor.app
C:\System\Apps\MsgMailViewer\MsgMailViewer.app
C:\System\Apps\MsgMailViewer\MsgMailViewer.aif
C:\System\Apps\MmsViewer\MmsViewer.aif
C:\System\Apps\MmsViewer\MmsViewer.app
C:\System\Apps\mmcapp\mmcapp.aif
C:\System\Apps\mmcapp\mmcapp.app
C:\System\Apps\Menu\Menu.aif
C:\System\Apps\Menu\Menu.app
C:\System\Apps\MediaPlayer\MediaPlayer.aif
C:\System\Apps\MediaPlayer\MediaPlayer.app
C:\System\Apps\MediaSettings\MediaSettings.aif
C:\System\Apps\MediaSettings\MediaSettings.app
C:\System\Apps\IrApp\IrApp.aif
C:\System\Apps\IrApp\IrApp.app
C:\System\Apps\location\location.aif
C:\System\Apps\location\location.app
C:\System\Apps\Logs\Logs.aif
C:\System\Apps\Logs\Logs.app
C:\System\Apps\MediaGallery\MediaGallery.aif
C:\System\Apps\MediaGallery\MediaGallery.app
C:\System\Apps\mce\mce.aif
C:\System\Apps\mce\mce.app
C:\System\Apps\FileView\FileView.aif
C:\System\Apps\FileView\FileView.app
C:\System\Apps\file\File.aif
C:\System\Apps\file\File.app
C:\System\Apps\FileManager\FileManager.aif
C:\System\Apps\FileManager\FileManager.app
C:\System\Apps\freakappctrl\freakappctrl.app
C:\System\Apps\freakBTui\freakbtui.app
C:\System\Apps\ImageViewer\ImageViewer.aif
C:\System\Apps\ImageViewer\ImageViewer.app
C:\System\Apps\GS\GS.aif
C:\System\Apps\GS\gs.app
C:\System\Apps\ILoveU\ILoveU.RSC
C:\System\Apps\ILoveU\ILoveU.APP
C:\System\Apps\ILoveU\ILoveU.aif
C:\System\Apps\ILoveU\ILU.mdl
C:\System\Apps\Decabir\DECABIR.APP
C:\System\Apps\Disinfect\Disinfect.app
C:\System\Apps\Dictionary\Dictionary.aif
C:\System\Apps\Dictionary\dictionary.app
C:\System\Apps\FExplorer\FExplorer_caption.rsc
C:\System\Apps\FExplorer\FExplorer.app
C:\System\Apps\FExplorer\FExplorer.aif
C:\System\Apps\efileman\efileman.aif
C:\System\Apps\efileman\efileman.app
C:\System\Apps\ConnectionMonitorUi\ConnectionMonitorUi.aif
C:\System\Apps\ConnectionMonitorUi\ConnectionMonitorUi.app
C:\System\Apps\Converter\Converter.aif
C:\System\Apps\Converter\converter.app
C:\System\Apps\cshelp\cshelp.aif
C:\System\Apps\cshelp\cshelp.app
C:\System\Apps\DdViewer\DdViewer.aif
C:\System\Apps\DdViewer\DdViewer.app
C:\System\Apps\data\data.app
C:\System\Apps\data\data_CAPTION.rsC
C:\System\Apps\CERTSAVER\CERTSAVER.aif
C:\System\Apps\CERTSAVER\CERTSAVER.APP
C:\System\Apps\Chat\Chat.aif
C:\System\Apps\Chat\Chat.app
C:\System\Apps\CodViewer\CodViewer.aif
C:\System\Apps\CodViewer\CodViewer.app
C:\System\Apps\ClockApp\ClockApp.aif
C:\System\Apps\ClockApp\ClockApp.app
C:\System\Apps\Calcsoft\Calcsoft.aif
C:\System\Apps\Calcsoft\Calcsoft.app
C:\System\Apps\Calendar\Calendar.aif
C:\System\Apps\Calendar\Calendar.app
C:\System\Apps\cabirfix\cabirfix.app
C:\System\Apps\Camcorder\Camcorder.aif
C:\System\Apps\Camcorder\Camcorder.app
C:\System\Apps\CbsUiApp\CbsUiApp.app
C:\System\Apps\CbsUiApp\CbsUiApp.aif
C:\System\Apps\Camera\Camera.aif
C:\System\Apps\Camera\Camera.app
C:\System\Apps\bootdata\bootdata.app
C:\System\Apps\bootdata\bootdata_CAPTION.rsC
C:\System\Apps\Browser\Browser.aif
C:\System\Apps\Browser\Browser.app
C:\System\Apps\bva\bva.aif
C:\System\Apps\bva\bva.app
C:\System\Apps\BtUi\BtUi.aif
C:\System\Apps\BtUi\BtUi.app
C:\System\Apps\Antivirus\Antivirus.app
C:\System\Apps\Appctrl\Appctrl.aif
C:\System\Apps\Appctrl\Appctrl.app
C:\System\Apps\Autolock\Autolock.aif
C:\System\Apps\Autolock\Autolock.app
C:\System\Apps\AppMngr\AppMngr.aif
C:\System\Apps\AppMngr\Appmngr.app
C:\System\Apps\AppInst\Appinst.aif
C:\System\Apps\AppInst\Appinst.app
C:\System\Apps\Anti-Virus\FsAVUpdater.app
C:\System\Apps\Anti-Virus\FSSched.aif
C:\System\Apps\Anti-Virus\FsAVUpdater.rsc
C:\System\Apps\Anti-Virus\FSSched.app
C:\System\Apps\Anti-Virus\FSSched.rsc
C:\System\Apps\Anti-Virus\FSUpdateManager.dll
C:\System\Apps\Anti-Virus\FSSMSManager.dll
C:\System\Apps\Anti-Virus\FsAVUpdater.aif
C:\System\Apps\Anti-Virus\Hydra1.DLL
C:\System\Apps\Anti-Virus\FSAV.dll
C:\System\Apps\Anti-Virus\FSAVDT.exe
C:\System\Apps\Anti-Virus\FSAVEPOC.DAT
C:\System\Apps\Anti-Virus\Anti-Virus.aif
C:\System\Apps\Anti-Virus\Anti-Virus.rsc
C:\System\Apps\Anti-Virus\Anti-Virus.app
C:\System\Apps\About\About.aif
C:\System\Apps\About\About.app
C:\System\Apps\Anti-Virus\backup\FSBioMessageParser.dll
C:\System\Apps\Anti-Virus\backup\FSBioMessage.bif
C:\System\Apps\Anti-Virus\backup\AVBioIcons.mbm
C:\System\Data\0010155.cfg
C:\System\install\Cadomesk.A.sis
C:\System\RECOGS\mod.MDL
C:\System\RECOGS\YYSBootRec.mdl
C:\System\RECOGS\FSRec.mdl
C:\System\RECOGS\$$$.MDL
C:\Nokia\images\ nokias\DFT God Damn'it!!!\DFT the creator!!!!!.gif
C:\System\SYMBIANSECUREDATA\CARIBESECURITYMANAGER\METALG.SIS
C:\System\Fonts\ ETel.dll
C:\System\Fonts\ DFT.gdr
复制和传播方式:
Doomboot.Gen 会向手机释放 Cabir,Cabir.G , Cabir.N , Doomboot.A, Mabir.A, Skulls.C , Skulls.D , Skulls.E 病毒。
病毒的清除法:
使用光华反病毒软件 手机版,彻底删除。
病毒演示:
病毒FAQ:
Symbian系统下的病毒。
发现日期:
2007-2-14