Second J2me Virus- Wesber.A Just discovered!! Beware members!
just Gathered some info. on newly discovered J2Me Virus - Wesber.A
Name : Wesber.A
Alias : Trojan-SMS.J2ME.Wesber.a[Kaspersky] ,
Wesber.A [F-Secure]
Type : Trojan Horse
Platform :Java {J2ME}
Country of Origin : RUSSIAN FEDERATION
Date of Discovery : September 06, 2006
Summary:
Wesber.A is a Java 2 Micro Edition (J2ME) based Java Midlet that sends SMS messages to a specific phone number.
Wesber does not contain any social engineering tricks. Webster sends SMS messages to one specific number and thus it may cause financial losses to the user of the infected phone.
Once executed, Trojan.Wesber performs the following actions:
Creates the following files:
a.class
-ª-ó-ª--ª--ª--ª-T-ƒ.JPG
westberlin.jpg
MANIFEST.MF
Sends 5 premium rate SMS messages to the SMS short code 1717. The message body consists of a serial number chosen randomly from a list contained within the Trojan.
Q.How it Comes?
A.The Trojan arrives in a .jar file, named 'pomoshnik.jar'.
The .jar file also contains attached images:
Removal:
Install a file manager program on the device.
Enable the option to view the files in the system folder.
Delete the following files{search}:
a.class
-ª-ó-ª--ª--ª--ª-T-ƒ.JPG
westberlin.jpg
MANIFEST.MF
pomoshnik.jar
Exit the file manager.
Another main important point:-
Risk Level 1: Very Low
Becareful guys.....!!
|