TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WINCE_INFOJACK.A
Overview

Malware type: Worm

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows CE and Windows Mobile

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

Low

Description: 

Trend Micro threat researchers post findings and analyses on various threats in real-time at the Malware Blog. Users can find more information about this specific threat here.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

BKDR_AGENT.AKJZ Behavior Diagram

Malware Overview

This worm is designed to run in the Windows CE environment used in mobile devices. It drops file(s)/component(s).

It creates registry key(s)/entry(ies).

It connects Web sites to send and receive information.

When an affected mobile device is connected to the Internet, this worm steals system information and sends the gathered them to a home server.

It accesses Web site(s) to download files.

It also downloads an updated copy of itself from a certain Web site. However, as of this writing, the said URL is inaccessible.

This worm randomly alters the security settings on the affected mobile. This causes all software installations to complete without giving any safety precaution. It may also send SMS from the compromised device to randomly selected contacts.

It drops copies of itself on memory cards inserted in an affected device.

For additional information about this threat, see:
Solution
Technical Details

Description created: Mar. 4, 2008 11:33:07 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.