|
Appdisabler.B (RAGHU.sis) |
|
|
|
|
Written by Administrator
|
|
Saturday, 20 September 2008 |
|
Appdisabler.B (RAGHU.sis) - Virus
Recently, I've received suspicious file from user who complained to me that those suspicious files were badly attacked their phone. One of them is RAGHU.sis which based on the previous mobile trojan--Skulls trojan principal to attack the phone. This malware has tested using NOKIA Symbian OS 6.1 and Symbian OS 8.0 device, both of these handsets proof to be attacked by this malware!
When users have installed this suspicious file, his phone should look like the above image:- When this trojan has successfully installs into the targeted directory, some of the application may be not function because this trojan has replace the original and functional files into a text file which will display '33' if user use File Explorer to view those files. This trojan also includes the following image and text:
| Code: | ----R A G H U---- VIRUS BORN IN SURAT(GUJRAT/INDIA/ASIA). THE NAME OF THIS VIRUS IS RAGHU.... U KNOW WHY....???????? BECAUSE I LIKE VASTAV MOVIE AND SANJU BABA. U LIKE THIS VIRUS? SO MANY SOFTWARE CRACKS AND VIRUS AVAILABLE SOON.... RAGHU NAM HE RAGHU... | | Code: | MY NAME IS -----R A G H U----- FROM SURAT/GUJARAT/INDIA/ASIA/WORLD/HEVEN/ U LIKE THIS VIRUS? HA.......HAHA............HAHAHA WARNING-NEVER INSTALL RAGHU.SIS ITS HARMFULL FOR YOUR MOBILE | It creates a non-functional application named RAGHU by installing the above file: \apps\RAGHU\RAGHU.app Payload Disables the following applications: Sounder SmartAnswer realplayer PhotoSafe Photographer PhotoEditor photoacute mmp MIDIED logoMan Launcher irremote CallManager callcheater BlueJackX BlackList AnswRec AD7650 HantroCP KPCaMain PVPlayer RallyProContest SmsMachine sSaver UVSMStyle Camcoder camerafx ETICamcorder ETIMovieAlbum ETIPlayer extendedrecorder FaceWarp FExplorer FSCaller Mp3Go Mp3Player PhotoSMS RingMaster SmartMovie SystemExplorer UltraMP3 WILDSKIN Hair Jelly Spreading in: RAGHU.sis
|