|
Friday, 08 April 2005 |
SymbOS.Fontal.A is a Trojan horse that replaces system files, which disables the application manager and prevents the device from restarting if it is switched off.
Also Known As: Fontal.A [F-Secure], SYMBOS_FONTAL.A [Trend Micro]
Type: Trojan Horse
Infection Length: 25,078 bytes
Systems Affected: EPOC
When SymbOS.Fontal.A is executed, it performs the following actions:
Installs the following files:
C:systemFontsKill sadam font.gdr
C:systemappsKill SadamzKill sadam.aif
C:systemappsKill Sadamkill sadam1.rsc
C:systemappsKill SadamKill sadam.rsc
C:systemappsKill SadamKill sadam.app
C:systemappsAppMngrAppmngr.app
Overwrites the application manager.
Installs a third-party, font-removing tool.
Prevents the device from restarting, if the device is switched off.
Removal Instructions:
Install a file manager program on the phone.
Enable the option to view the files in the system directory.
Delete the following files:
C:systemFontsKill sadam font.gdr
C:systemappsKill SadamzKill sadam.aif
C:systemappsKill Sadamkill sadam1.rsc
C:systemappsKill SadamKill sadam.rsc
C:systemappsKill SadamKill sadam.app
C:systemappsAppMngrAppmngr.app
Exit the file manager.
Open the application manager.
Uninstall the following application:
*Kill Saddam By OID500.sis
Exit the application manager.
|