Skulls: a new Trojan for Symbian OS

All the information described here are taken from F-Secure site. Check them for latest/updated information.

skulls_skulls.jpgSkulls trojan has been distributed on some Symbian shareware download sites as "Extended Theme Manager" by "Tee-222". If you see it, don't install it on your phone. It will make you're phone useless and it will prevent it from booting up. Recovery could get tricky, especially if you don't have a third-party file manager software already installed on your phone.

The most obvious symptom of the trojan is that the typical programs on the phone won't work any more, and that their icons get replaced with a a picture of a skull. This basically means that if Skulls is installed only the calling from the phone and answering calls works. All functions which need some system application, such as SMS and MMS messaging, web browsing and camera no longer function.

If you have installed Skulls, the most important thing is not to reboot the phone and follow the disinfection instruction in this description.

Disinfection

If you have installed F-Secure Anti-Virus but have not yet received database update

  1. .Open Applications menu
  2. .Click F-Secure Anti-Virus
  3. .Select update Anti-Virus from options
  4. . Scan your device to remove malicious AIF files
  5. . Go to application manager
  6. . Uninstall "Extended theme.sis"

If you have not rebooted the phone after installing "Extended theme.sis"

Currently the only known method of uninstall works if you have some third party file manager installed into your phone.

  1. Go to c:\System\apps\appinst and delete Appinst.aif and AppInst.app
  2. Open the applications menu
  3. Look for web browser, it's icon should still be normal
  4. Open http://mobile.f-secure.com
  5. Download F-Secure Mobile Anti-Virus for your device
  6. Install F-Secure Mobile Anti-Virus
  7. Scan your device to remove malicious AIF files
  8. Go to application manager
  9. Uninstall "Extended theme.sis"

More information

You can also get further information regarding this trojan from Symbian.