SymbOS.Skulls.P - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: December 13, 2005
Updated: February 13, 2007 12:49:57 PM
Type: Trojan Horse
Systems Affected: EPOC


  1. Install a file manager program on the device.

  2. Enable the option to view the files in the system folder.

  3. Delete the following malicious files:

    • Nokia_Space_Cadet_Pinball.sis
    • \system\install\Nokia_Space_Cadet_Pinball.sis
    • .\Space_Cadet_Pinball-Created_by-JoN.sis

  4. Delete the following files if GameMgrUI is no longer required:

    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.aif
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.rsc4
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.rsc3
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.rsc2
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.rsc1
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi_caption.rsc4
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi_caption.rsc3
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi_caption.rsc2
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi_caption.rsc1
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.mbm
    • [DRIVE LETTER]:\system\apps\GameMgrUi\GameMgrUi.app
    • [DRIVE LETTER]:\system\libs\GameMgr.dll

  5. Exit the file manager.


Writeup By: Yana Liu
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security