病毒資料
別名: SymbOS/Skulls.B
病毒FAQ:Symbian系統下的病毒。
發現日期:2007-2-15
概述: Skulls.B 是 SymbOS/Skulls.A 木馬的一個變種,與 Skulls.A 功能相似但使用不同檔案。
Skulls.B 是一個惡意 SIS 檔案木馬,用無法使用的版本替換系統應用程式,並向手機釋放 SymbOS/Cabir.B 蠕蟲。
Skulls.B 釋放的 Cabir 不會自動激活,但如果用戶在手機選單中點擊 cabir 圖示運行 Cabir , Cabir.c 會激活並試圖感染其他手機。
原始 Skulls.B SIS 檔案命名為 "Icons.SIS" 。與 Skulls.A 不同,安裝時 Skulls.B 變種不顯示任何彈出的信息(除了作業系統顯示的 " 安裝安全警告 - 無法驗證提供者 " 信息)。
Skulls.B 用一般的應用程式圖示,而不是骷髏與十字骨頭圖示,替換標準應用程式圖示。
如果安裝 Skulls.B ,手機只有呼叫和應答可以使用。所有需要某個系統統應用程式的功能,如 SMS 和 MMS 信息、網頁瀏覽和照相都將無法使用。除了應用程式無法使用以外,手機也會感染 Cabir.B ,幸運的是它不能自動激活。
如果你已經安裝 Skulls.B ,最重要的是不要重啟手機。
詳細描述:
Skulls.B 會產生以下檔案來覆蓋系統程式,使系統無法正常工作:
c:/system/apps/about/about.aif
c:/system/apps/about/about.app
c:/system/apps/appinst/appinst.aif
c:/system/apps/appinst/appinst.app
c:/system/apps/appmngr/appmngr.aif
c:/system/apps/appmngr/appmngr.app
c:/system/apps/autolock/autolock.aif
c:/system/apps/autolock/autolock.app
c:/system/apps/browser/browser.aif
c:/system/apps/browser/browser.app
c:/system/apps/btui/btui.aif
c:/system/apps/btui/btui.app
c:/system/apps/bva/bva.aif
c:/system/apps/bva/bva.app
c:/system/apps/calcsoft/calcsoft.aif
c:/system/apps/calcsoft/calcsoft.app
c:/system/apps/calendar/calendar.aif
c:/system/apps/calendar/calendar.app
c:/system/apps/camcorder/camcorder.aif
c:/system/apps/camcorder/camcorder.app
c:/system/apps/camtimer/camtimer.app
c:/system/apps/camtimer/camtimer.rsc
c:/system/apps/caribe/caribe.app
c:/system/apps/caribe/caribe.rsc
c:/system/apps/caribe/flo.mdl
c:/system/apps/cbsuiapp/cbsuiapp.aif
c:/system/apps/cbsuiapp/cbsuiapp.app
c:/system/apps/certsaver/certsaver.aif
c:/system/apps/certsaver/certsaver.app
c:/system/apps/chat/chat.aif
c:/system/apps/chat/chat.app
c:/system/apps/clockapp/clockapp.aif
c:/system/apps/clockapp/clockapp.app
c:/system/apps/codviewer/codviewer.aif
c:/system/apps/codviewer/codviewer.app
c:/system/apps/connectionmonitorui/connectionmonitorui.aif
c:/system/apps/connectionmonitorui/connectionmonitorui.app
c:/system/apps/converter/converter.aif
c:/system/apps/converter/converter.app
c:/system/apps/cshelp/cshelp.aif
c:/system/apps/cshelp/cshelp.app
c:/system/apps/ddviewer/ddviewer.aif
c:/system/apps/ddviewer/ddviewer.app
c:/system/apps/filemanager/filemanager.aif
c:/system/apps/filemanager/filemanager.app
c:/system/apps/gs/gs.aif
c:/system/apps/gs/gs.app
c:/system/apps/imageviewer/imageviewer.aif
c:/system/apps/imageviewer/imageviewer.app
c:/system/apps/location/location.aif
c:/system/apps/location/location.app
c:/system/apps/logs/logs.aif
c:/system/apps/logs/logs.app
c:/system/apps/mce/mce.aif
c:/system/apps/mce/mce.app
c:/system/apps/mediagallery/mediagallery.aif
c:/system/apps/mediagallery/mediagallery.app
c:/system/apps/mediaplayer/mediaplayer.aif
c:/system/apps/mediaplayer/mediaplayer.app
c:/system/apps/mediasettings/mediasettings.aif
c:/system/apps/mediasettings/mediasettings.app
c:/system/apps/menu/menu.aif
c:/system/apps/menu/menu.app
c:/system/apps/mmcapp/mmcapp.aif
c:/system/apps/mmcapp/mmcapp.app
c:/system/apps/mmm/mmm.aif
c:/system/apps/mmm/mmm.app
c:/system/apps/mmseditor/mmseditor.aif
c:/system/apps/mmseditor/mmseditor.app
c:/system/apps/mmsviewer/mmsviewer.aif
c:/system/apps/mmsviewer/mmsviewer.app
c:/system/apps/msgmaileditor/msgmaileditor.aif
c:/system/apps/msgmaileditor/msgmaileditor.app
c:/system/apps/msgmailviewer/msgmailviewer.aif
c:/system/apps/msgmailviewer/msgmailviewer.app
c:/system/apps/musicplayer/musicplayer.aif
c:/system/apps/musicplayer/musicplayer.app
c:/system/apps/notepad/notepad.aif
c:/system/apps/notepad/notepad.app
c:/system/apps/npdviewer/npdviewer.aif
c:/system/apps/npdviewer/npdviewer.app
c:/system/apps/nsmldmsync/nsmldmsync.aif
c:/system/apps/nsmldmsync/nsmldmsync.app
c:/system/apps/nsmldssync/nsmldssync.aif
c:/system/apps/nsmldssync/nsmldssync.app
c:/system/apps/phone/phone.aif
c:/system/apps/phone/phone.app
c:/system/apps/phonebook/phonebook.aif
c:/system/apps/phonebook/phonebook.app
c:/system/apps/pinboard/pinboard.aif
c:/system/apps/pinboard/pinboard.app
c:/system/apps/presence/presence.aif
c:/system/apps/presence/presence.app
c:/system/apps/profileapp/profileapp.aif
c:/system/apps/profileapp/profileapp.app
c:/system/apps/provisioningcx/provisioningcx.aif
c:/system/apps/provisioningcx/provisioningcx.app
c:/system/apps/psln/psln.aif
c:/system/apps/psln/psln.app
c:/system/apps/pushviewer/pushviewer.aif
c:/system/apps/pushviewer/pushviewer.app
c:/system/apps/satui/satui.aif
c:/system/apps/satui/satui.app
c:/system/apps/schemeapp/schemeapp.aif
c:/system/apps/schemeapp/schemeapp.app
c:/system/apps/screensaver/screensaver.aif
c:/system/apps/screensaver/screensaver.app
c:/system/apps/SDN/sdn.aif
c:/system/apps/sdn/sdn.app
c:/system/apps/simdirectory/simdirectory.aif
c:/system/apps/simdirectory/simdirectory.app
c:/system/apps/smseditor/smseditor.aif
c:/system/apps/smseditor/smseditor.app
c:/system/apps/smsviewer/smsviewer.aif
c:/system/apps/smsviewer/smsviewer.app
c:/system/apps/speeddial/speeddial.aif
c:/system/apps/speeddial/speeddial.app
c:/system/apps/startup/startup.aif
c:/system/apps/startup/startup.app
c:/system/apps/sysap/sysap.aif
c:/system/apps/sysap/sysap.app
c:/system/apps/todo/todo.aif
c:/system/apps/todo/todo.app
c:/system/apps/ussd/ussd.aif
c:/system/apps/ussd/ussd.app
c:/system/apps/vcommand/vcommand.aif
c:/system/apps/vcommand/vcommand.app
c:/system/apps/vm/vm.aif
c:/system/apps/vm/vm.app
c:/system/apps/voicerecorder/voicerecorder.aif
c:/system/apps/voicerecorder/voicerecorder.app
c:/system/apps/walletavmgmt/walletavmgmt.aif
c:/system/apps/walletavmgmt/walletavmgmt.app
c:/system/apps/walletavota/walletavota.aif
c:/system/apps/walletavota/walletavota.app
c:/system/caribesecuritymanager/camtimer.sis
c:/system/caribesecuritymanager/caribe.app
c:/system/caribesecuritymanager/caribe.rsc
c:/system/recogs/flo.mdl
Skulls 自帶的Cabir.c蠕蟲安裝時不會自動運行,但是如果重新啟動手機後會自動運行。
複製和傳播方式:
skulls.b 本身不會對外傳播,也不會複製自身。但是它釋放出來的cabir.c蠕蟲會複製自身並通過藍牙傳播(更多 cabir.c 細節請參看cabir.c病毒介紹)。
參考資料:http://www.viruschina.com/news/Vdatabase_detail.asp?id=5366
