Esato

Forum > General discussions > General > Skulls Trojan for Symbian

Author Skulls Trojan for Symbian
axxxr
K700
Joined: Mar 21, 2003
Posts: > 500
From: Londinium
PM, WWW
Posted: 2004-11-19 20:01
Reply with quoteEdit/Delete This PostPrint this post
Their have been some isolated reports of users who've been hit by the new Skulls trojan on their phones.

This trojan has been distributed on some Symbian shareware download sites as "Extended Theme Manager" by "Tee-222". If you see it, don't install it on your phone. It will make you're phone useless and it will prevent it from booting up. Recovery could get tricky, especially if you don't have a third-party file manager software already installed on your phone.

The most obvious symptom of the trojan is that the typical programs on the phone won't work any more, and that their icons get replaced with a a picture of a skull. See below:



Skulls is a malicious SIS file that will replace the system applications with non-functional versions, so that all but the phone functionality will be disabled.

The Skulls SIS file is named "Extended theme.SIS", it claims to be theme manager for Nokia 7610 smart phone, written by "Tee-222".

If Skulls is installed it will cause all application icons to be replaced with picture of skull and cross bones, and the icons don't refer to the actual applications any more so none of the Phone System applications will be able to start.

This basically means that if Skulls is installed only the calling from the phone and answering calls works. All functions which need some system application, such as SMS and MMS messaging, web browsing and camera no longer function.

If you have installed Skulls, the most important thing is not to reboot the phone and follow the disinfection instruction in this description.


Disinfection

If you have installed F-Secure Anti-Virus but have not yet received database update

1.Open Applications menu
2.Click F-Secure Anti-Virus
3.Select update Anti-Virus from options # 4. Scan your device to remove malicious AIF files
5. Go to application manager
6. Uninstall "Extended theme.sis"

If you have not rebooted the phone after installing "Extended theme.sis"

Currently the only known method of uninstall works if you have some third party file manager installed into your phone.

1. Go to c:Systemappsappinst and delete Appinst.aif and AppInst.app
2. Open the applications menu
3. Look for web browser, it's icon should still be normal
4. Open http://mobile.f-secure.com
5. Download F-Secure Mobile Anti-Virus for your device
6. Install F-Secure Mobile Anti-Virus
7. Scan your device to remove malicious AIF files
8. Go to application manager
9. Uninstall "Extended theme.sis"


[addsig]
Jim
T39 black
Joined: Jan 20, 2002
Posts: > 500
From: Belgium
PM
Posted: 2004-11-19 20:25
Reply with quoteEdit/Delete This PostPrint this post
Those virii kiddies .... how lame
Lembo
Satio Black
Joined: Mar 13, 2004
Posts: > 500
From: East London
PM
Posted: 2004-11-19 20:32
Reply with quoteEdit/Delete This PostPrint this post
So Norton Anti-Virus 2005 mobile Edition won't be long then
hyperken
Samsung Galaxy Note
Joined: Jun 24, 2002
Posts: > 500
From: Malaysia
PM
Posted: 2004-11-19 20:44
Reply with quoteEdit/Delete This PostPrint this post
dam those ppl should go else with the programming skill !

This message was posted from a WAP device

axxxr
K700
Joined: Mar 21, 2003
Posts: > 500
From: Londinium
PM, WWW
Posted: 2004-11-30 12:49
Reply with quoteEdit/Delete This PostPrint this post
F-Secure is reporting a new Skulls Virus variant Skulls.B. Skulls.B not only disables applications on the phone but carries with it Cabir.B, a variant of the mobile phone virus spread between Symbian Series 60 OS based phones over Bluetooth.The Skulls virus targets Nokia 7610 smart phones.

[addsig]
coolfighter
P910
Joined: Jun 02, 2002
Posts: 176
From: coolfighter
PM, WWW
Posted: 2004-11-30 13:33
Reply with quoteEdit/Delete This PostPrint this post
and where i find this virus Skulls Trojan for Symbian
lol


Gigs
P1
Joined: Jan 19, 2004
Posts: > 500
From: The planet Snibertron!
PM, WWW
Posted: 2004-12-01 00:32
Reply with quoteEdit/Delete This PostPrint this post
well at least activating nortons by phone will get easier
Whats next, "malicous adware affects symbian phones running opera, users report new hotbar and claims of longer battery life and increased phone insurance levels are appearing on their phones screen" :/

Access the forum with a mobile phone via esato.mobi