
Subscribe to
Computerworld November 23, 2004 (IDG News Service) -- DUSSELDORF, Germany -- Users of Nokia Corp.'s 7610 smart phone and possibly other phones running Symbian Ltd.'s Series 60 software should be aware of a new Trojan program on the Internet.
"We have located several freeware and shareware sites offering a program, called Extended Theme Manager, that contains a Trojan horse," Mikko Hypponen, director of antivirus research at Helsinki-based F-Secure Corp., said today in an interview. "The virus writer is going by the name Tee-222."
The malicious code, called Skulls, deactivates all links to Symbian system applications, such as e-mail and calendar, by replacing their menu icons with images of skulls, Hypponen said. Users of affected phones can only send or receive calls, he said.
F-Secure issued a warning on Friday.
Hypponen said the Extended Theme Manager program looked "pretty convincing" as a freeware maintenance tool and that many sites had not bothered to verify it or even try it out. Most monitored sites, he said, have since removed the program.
When installing the file "extended theme.sis," Symbian phone users are informed by the operating system that the software is not Symbian Signed -- a trusted software application program initiated by the OS developer -- and asked if they want to continue, Hypponen said.
"This is definitely a good warning but the problem is that any advanced PC user who downloads software regularly sees this kind of warning 99% of the time and simply clicks OK," he said. "So the warning isn't really protecting much."
One way to correct the problem, Hypponen said, is a hard reset, which restores affected phones to their default factory setting. Unfortunately, all private data, such as phone books and calendars, is lost in the process.
Earlier this year, the Symbian operating system software was the target of the Cabir virus, which, like Skulls, transmits a .sis file. But unlike Cabir, which scans for accessible phones within Bluetooth range and makes a copy of itself, Skulls is not self-replicating.
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
|
|
All Zones Application Performance Zone Business Continuity Zone Data Center Management Zone Enterprise-Class Security Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone Business Intelligence and Analytics Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|


| XenServer FREE trial Citrix XenServer is the simplest and most effective way to virtualize and provision servers. XenServer combines comprehensive server virtualization capabilities with unparalleled scalability, performance, economics, and ease-of-use. Based on the open source Xen hypervisor, XenServer delivers fast performance, easy management, and advanced features such as live migration. |

| Try Fluke Networks'
EtherScope Analyzer on your network FREE Quickly solve the wide range of problems you encounter - 10, 100 and Gigabit, twisted pair and optical fiber, LAN or wireless LAN. The EtherScope Analyzer combines the essential tools you need to monitor network traffic and switch interfaces, discover devices, networks, VLANs, access points, mobile clients and more. See the power of this portable network analyzer on your network. Request free trial now
*Terms and conditions: Evaluation units are available only for a limited time and will be scheduled on a first-come first-served basis. Not available in all geographies. Limited quantities available; customers requesting evaluation units may be waitlisted for the next available unit. It will be at the discretion of Fluke Networks to accept or decline requests for this free evaluation. |
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |