SymbOS.Bootton.E
Last update:  26-01-06 Submitted by ahbao
Views: 959 Home Security


SymbOS.Bootton.E is a Trojan horse that restarts the mobile device when executed. However, as it also drops corrupted components, the device is unable to restart. The Trojan runs on the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones. The Trojan reportedly arrives as Restart.S60.SIS. When the user clicks on the .sis file, the phone installer displays a dialog box to warn the user that the application may be coming from an untrusted source and may cause potential problems.

Technical Details

When SymbOS.Bootton.E is executed, it performs the following actions:

  1. Displays the following message:

    Restart
  2. Drops the following files on the compromised device:

    [DRIVE LETTER]:\Restart.dll
    [DRIVE LETTER]:\LayoutInst.dll
    [DRIVE LETTER]:\System\Apps\Restart\Restart.APP
    [DRIVE LETTER]:\System\Apps\Restart\Restart.AIF

    Note:
    The files restart the mobile device when executed, but due to the presence of the corrupted components, the device is unable to restart.
    The [DRIVE LETTER] variable refers to the drive letter that is used to represent the device itself or the memory card. The actual value will depend on the choice the user makes during the installation process.
  3. The following file is also created by the Installer, not the threat:

    \system\install\Restart.S60.SIS
  4. Displays the following message during installation:

    This app can restart your phone by only clicking on the restart icon. It is suitable for S60 phones. Enjoy!!
    Created By:
    Symbian Corporation ©2006

Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current
  • Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

Removal Instructions

  1. Install a file manager program on the device.
  2. Enable the option to view the files in the system folder.
  3. Navigate to and delete the following malicious files:

    [DRIVE LETTER]:\Restart.dll
    [DRIVE LETTER]:\LayoutInst.dll
    [DRIVE LETTER]:\System\Apps\Restart\Restart.APP
    [DRIVE LETTER]:\System\Apps\Restart\Restart.AIF
  4. Exit the file manager.

http://www.symantec.com/avcenter/venc/data/symbos.bootton.e.html





 Lastest News in this category

AhnLab exports a vaccine for mobile phones overseas for the first time
AhnLab recently entered into an agreement for OEM (original equipment manufacturing) supply of its security product 'AhnLab Mobile Security' to Tai...

Kaspersky Mobile Security 7.0 will Catch Phone Thief Now
Kaspersky Lab announced the release of a new product for the integrated protection of smartphones running Symbian and Windows Mobile. Kaspersky Mob...

McAfee Research Reveals Majority of Consumers Concerned Over Mobile Safety
McAfee announced findings from new research that reveals that almost three out of four mobile consumers (72%) are concerned about the security of t...

SMobile Announces Solution for Beselo Worm Virus
SMobile Systems announced that it has prepared and tested a mobile anti-virus update and disinfection tool for its Security Shield platform to help...

F-Secure and Sony Ericsson partner to deliver Mobile Security for UIQ
F-Secure Corporation is today announcing the availability of its Mobile Security product for the UIQ platform. F-Secure and Sony Ericsson are partn...



 Free Mobile Phone Wallpaper

dwqp_189

128w_2741

shum_097

Colorful Apple


Recommend: SlashGear / Instinct Phone cases / iPhone 3G cases / iPod touch 2G / MY iTablet / PHONE Magazine / Android Community Store
Samsung Instinct Accessories / BlackBerry Touch / Storm Accessories / T-Mobile G1 / G1 Cases /iPhone 3G Accessories
iPod Touch Store / Apple-Touch.com / iPhone 3G Price / iPhone Buzz / Everything Dream / Macbook touch / Treo Pro / Palm Treo Pro
Android Community / Dream Accessories / Dream Cases / Touch Diamond Cases / Touch Diamond Accessories / XPERIA Accessories / BlackBerry Aurora / HTC Touch pro / Touch Diamond / HTC Diamond phone / HTC Diamond / HTC Dream / BlackBerry Bold / BlackBerry Bold Accessories / BlackBerry Bold cases / BlackBerry Thunder / BlackBerry Bold Accessories / BlackBerry Thunder Accessories / Samsung OMNIA / Bold Cases / Dare Accessories / Thunder Accessories / Thunder Cases / Android Market
Treo Pro Accessories / Treo Pro Cases / Treo Pro Store / Sprint Diamond Accessories / Sprint Diamond Cases
SlashGear.TV / the Instinct Phone / LG Dare Accessories / LG Dare Cases / iPod nano 4G / Treo 800w Cases / iPhone 3G Accessories / iPhone 3G Cases / iPhone nano Accessories / iPhone nano Cases / Google Chrome Browser / BlackBerry Pearl 8220 / BlackBerry 9530 / G1 Accessories / HTC G1 / Microsoft Skymarket
Logos & trademarks in this site are property of their respective owner(s). The comments are property of their posters, the rest © SlashPhone.
Privacy Policy | Terms of Use | Got Suggestions?: SlashPhone Tipline / SlashPhone Editor / Vincent Nguyen
Designed and Developed by Ewdison Then. SlashPhone is part of Aradius and Powered by Madserve.com
.