UMU Mobile Security Banner
SymbOS/AVKiller.A
Green Tick UMU Scan protects against this virus.
Threat Level:
Low
Type:
Trojan
SDB Version:
147
SDB Release Date:
27/02/2008
Description Date:
14/05/2008
What does this virus do?
Arriving on your phone disguised as an application to help you remove the Cabir virus from your phone, once run it claims to find Cabir and asks you if you want to disinfect your phone. If you do, the virus disables your antivirus protection and puts your phone at risk from other viruses.

SymbOS/AVKiller.A arrives disguised as a SIS installer for an application that cleans Cabir infections:


Once installed, it appears in the device’s list of applications as F-Cabir and even uses the logo of F-Secure to trick users into executing it:

It drops the following files: 
 
!:\System\Apps\Disinfect\Disinfect.app
!:\System\Apps\Disinfect\Disinfect.lst
!:\System\Apps\Disinfect\Disinfect.rsc
!:\System\Apps\Disinfect\Disinfect_Caption.rsc
!:\System\Apps\Disinfect\Disinfect.aif 

* ! signifies a user defined installation drive

 

When executed, it displays a fake message that says that it will scan the device for Cabir infection. It even displays an option to scan:





Choosing to run the scan will always have a fake result of a Cabir infection being found in the system:


If, at this point, the user chooses the option to disinfect the phone, SymbOS/AVKiller.A then proceeds to disable any installed antivirus programs that are included in its target list (Disinfect.lst). The list is as follows: 

Avira
BitDefender
Bullguard
CalvinSettinger
Disinfector
ExoVirusStop
F-Secure
FB-4 Virus Guard
Fonoinfo
Jamanda
Jiangmin
Kaspersky
McAfee
Netqin
SimWorks
Symantec
TrendMicro
ZeonAntiVirus 

SymbOS/AVKiller.A disables these antivirus programs by deleting the following folders where their components are located: 

!\mcafee\mcs\
!\system\AntiVirus\
!\system\apps\Anti-Virus\
!\system\apps\AntiVirMobile\
!\system\apps\BdMobile\
!\system\apps\Bullguard\
!\system\apps\Cabirfix\
!\system\apps\CalvinStinger\
!\system\apps\Disinfector\
!\system\apps\EVS\
!\system\apps\KSMobile\
!\system\apps\KVMobileS60\
!\system\apps\MAV\
!\system\apps\MobileSecurity\
!\system\apps\NetQin\
!\system\apps\NEWFILESCAN\
!\system\apps\symcs\
!\system\apps\VirusGuard\
!\system\apps\VirusScan\
!\system\apps\ZeonAntiVirus\
!\system\help\
!\system\install\
!\system\libs\
!\system\programs\
!\system\recogs\ 

* ! signifies a user defined installation drive 

 

Manual Disinfection 

  1. Scan your mobile device using UMU Scan and delete all files detected as SymbOS/AVKiller.A.
  2. Reboot your device to kill malware residue processes.
  3. Download a third party File Explorer.
  4. Locate and delete the following files and folders if they exist:
!:\System\Apps\Disinfect\Disinfect.app
!:\System\Apps\Disinfect\Disinfect.lst
!:\System\Apps\Disinfect\Disinfect.rsc
!:\System\Apps\Disinfect\Disinfect_Caption.rsc
!:\System\Apps\Disinfect\Disinfect.aif

* ! signifies a user defined installation drive

Virus Definitions

List of virus definitions
Report a new virus/spyware