UMU Mobile Security Banner
SymbOS/LianFeng.A
Green Tick UMU Scan protects against this virus.
Threat Level:
Low
Type:
Trojan
SDB Version:
176
SDB Release Date:
18/09/2008
Description Date:
23/10/2008
What does this virus do?
This mobile Trojan, once installed monitors your incoming SMS and MMS message and attempts to delete them.

SymbOS/LianFeng.A is a mobile Trojan. When executed, it drops the following files: 

C:\System\Apps\Install\Euninstall.exe
C:\System\Data\Wapstore\Settings\Ewapstore.exe 

Once installed, they monitor incoming SMS and MMS messages and attempts to delete them. 

The following components of this Trojan appear to be missing but may be present in the wild: 

c:\system\apps\install\Euninstall.exe
c:\system\data\Calendar.dat
c:\system\data\wapstore\settings\Ewapstore.exe
c:\system\recogs\AppToolkit.mdl
e:\system\apps\install\Euninstall.exe
e:\system\apps\install\install.log
e:\system\recogs\RecMemCard.mdl 

SymbOS/LianFeng.A affects phones running the Symbian S60 platform. Some affected phones include the following: 

Nokia 3650, 3600
Nokia 3660, 3620
Nokia 6600
Nokia 6620
Nokia 7610
Nokia 7650
Nokia N-Gage
Panasonic X700
Sendo X
Siemens SX1
 

Manual Disinfection 

  1. Scan your mobile device using UMU Scan and delete all files detected as SymbOS/LianFeng.A.
  2. Reboot your device to kill malware residue processes.
  3. Download a third party File Explorer.
  4. Locate and delete the following files and folders if they exist: 
C:\System\Apps\Install\Euninstall.exe
C:\System\Data\Wapstore\Settings\Ewapstore.exe
c:\system\apps\install\Euninstall.exe
c:\system\data\Calendar.dat
c:\system\data\wapstore\settings\Ewapstore.exe
c:\system\recogs\AppToolkit.mdl
e:\system\apps\install\Euninstall.exe
e:\system\apps\install\install.log
e:\system\recogs\RecMemCard.mdl
Virus Definitions

List of virus definitions
Report a new virus/spyware