SymbOS.Romride.A - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: June 2, 2006
Updated: February 13, 2007 12:56:01 PM
Also Known As: Romride.A [F-Secure]
Type: Trojan Horse
Systems Affected: Symbian OS


  1. Install a file manager program on the device.

  2. Enable the option to view the files in the system folder.

  3. Navigate to and delete the following files:

    • [DRIVELETTER]\System\Bootdata\LocaleData.D01
    • [DRIVELETTER]\System\Bootdata\FirstBoot.dat
    • [DRIVELETTER]\System\Bootdata\CommonData.D00
    • [DRIVELETTER]\System\Mail\00100001
    • [DRIVELETTER]\System\Mail\00100000
    • [DRIVELETTER]\System\Mail\00001000
    • [DRIVELETTER]\System\Schedules\Schedules.dat
    • [DRIVELETTER]\System\Shareddata\101f857a.ini
    • [DRIVELETTER]\System\Shareddata\10005a40.ini
    • [DRIVELETTER]\System\Shareddata\10005943.ini
    • [DRIVELETTER]\System\Shareddata\100058f1.ini
    • [DRIVELETTER]\System\Shareddata\100056c6.ini
    • [DRIVELETTER]\System\Shareddata\reserve.bin
    • \system\install\Nokia Live.sis

  4. Exit the file manager.

Writeup By: Yana Liu
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security