EmailEmail
PrintPrint
Worry Watch: Skulls.L threatens cell phone users
Saturday, June 18, 2005

Average consumers of new technology are constantly warned to upgrade their virus protection against the seemingly endless barrage of stronger, more dangerous threats to their computers and electronic devices. Skulls.L, a new cell-phone threat, preys upon this routine downloading by posing as anti-virus software.

 
 

WEEKLY REPORTS

Solutions, Prevention & Remedies

Top 10 Threats

   
 

This Trojan targets Nokia smartphones by taking on the name and several other characteristics of software created by the Anti-virus vendor F-Secure.

Once downloaded onto your cell phone, Skulls.L displays a message reading, "F-Secure Antivirus protects you against the virus. And don't forget to update this!" Once the Trojan is run, the smartphone is still capable of receiving and sending phone calls. However, the Trojan releases worms which disable legitimate anti-virus programs and all other applications.

F-Secure has developed a removal tool for the virus and suggests that users only download F-Secure software from its Web site in order to avoid the risk of unsafe, pirated software.


Worry Watch Plus Online only:

Information, Protection and Prevention -- Skulls.L
Is your cell phone at risk?

F-Secure Skulls.L description


Microsoft?s Latest Security Releases:

Name

Number

For Users of:

Priority

Cumulative Security Update for Internet Explorer

KB883939

Windows 98, 2000 (SP3 and SP4), ME, XP (SP1 and SP2), Internet Explorer*

Critical

Vulnerability in HTML Help

KB896358

Windows 98, 2000 (SP3 and SP4), ME, XP (SP1 and SP2)*

Critical

Vulnerability in Outlook Web Access for Exchange Server 5.5

KB895179

Microsoft Exchange Server 5.5 (SP4)

Important

Cumulative Security Update in Outlook Express

KB897715

Windows 98, 2000 (SP3 and SP4), ME, XP (SP1), Outlook Express

Important

Vulnerability in Step-by-Step Interactive Training

KB898458

Windows 98, 2000 (SP3 and SP4), ME, XP (SP1 and SP2)

Important

Vulnerability in Web Client Service

KB896426

Windows XP (SP1)

Important

Vulnerability in Server Message Block

KB896422

Windows 2000 (SP3 and SP4), XP (SP1 and SP2)*

Critical

Vulnerability in Microsoft Agent

KB890046

Windows 98, 2000 (SP3 and SP4), ME, XP (SP1 and SP2)

Moderate

Cumulative Security Update for ISA Server 2000

KB899753

ISA Server 2000 (SP2), Microsoft Small Business 2000 and 2003

Moderate

Vulnerability in Telnet Client

KB896428

XP (SP1 and SP2), Unix 2.2 for Windows 2000

Moderate

Windows Malicious Software Removal Tool

KB890830

Windows 2000, XP*

Go back

* Reading: Solutions, Prevention & Remedies
Additional summary information related to a specific type of solution or prevention that you should be considering. Depending upon the week, this section may have:
• Recent Windows security releases from Microsoft
• Recent updates to widely used anti-spyware programs
• Recent updates to widely used anti-virus programs
• Recent updates to other security programs & devices (ex: Firewalls, routers)
• Recent updates to various applications in wide use


Top 10 Threats:

Name

Type

Affects

Alert Level

Mhtredir.gen

MORE

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Medium

Netsky.P

MORE

Worm

Windows 95, 98, 2000, ME, NT, XP*

Severe

Sdbot.ftp

MORE

Worm

Windows 95, 98, 2000, ME, NT, XP

Medium

Qhost.gen

MORE

Trojan

Windows 2000, NT, XP*

Medium

sdbot.DYO

MORE

Worm

Windows 95, 98, 2000, ME, NT, XP

Medium

Smitfraud.A

MORE

Virus

Windows 95, 98, 2000, ME, NT, XP*

Medium

Gaobot.gen -

MORE

Worm

Windows 2000, NT, XP*

High

Startpage.JY

MORE

Spyware

Windows 95, 98, 2000, ME, NT, XP*

Medium

Small.GV

MORE

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Medium

Psyme.C

MORE

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Go back

Read: Top Threats
These are viruses that are currently on the watch lists of major anti-virus software companies.

Name
What the threat is called. We use the name given each virus by Panda Software. Sometimes other anti-virus companies give the same threat a different name. Usually they use similar names.

Type
There are different characteristics associated with different types of threats.
• Virus - has the ability to replicate or infect computers or other programs
• Trojan Horse (or Trojan) - appear to be harmless programs when you get them. They unleash their payload when you double-click, open, or execute them.
• Phishing - a Web site or e-maill message posing as another company - usually one you know to fool you into giving the sender personal information.
• Worm - self replicates onto additional disks, computers or networks
• Spyware - installs on your system to collect information about your activity, preferences or interests
• Hoax - false messages sent by e-maill to mislead the recipient
• Backdoors - opens a security hole that allows outsiders to take control of your computer
• Dialer - uses your telephone to dial an outside number - sometimes a number that costs you money when dialed

Affects
Not all viruses affect all types of systems. Some, for example may affect only Windows 98 and 95, but not Windows XP or NT. Others affect all Windows systems, but not Macintosh. In this column, we show you the consumer systems that the threat is known to affect. We don't always include the servers that operate in your company's backroom.

Alert level
The level of awareness that anti-virus vendors suggest you need to have for each threat listed.
For each threat listed, we'll post a corresponding link here, so you can get more information to help you recognize, diagnose, prevent, and repair the problem.

Worry Watch is compiled by David Radin & Jes Scherder using data and reports from Microsoft, CERT, Panda, and other sources. To contact the compilers of Worry Watch, go to http://www.megabyteminute.com/contactdavid.html

First published on June 18, 2005 at 12:00 am
Worry Watch is compiled by David Radin & Jes Scherder using data and reports from Microsoft, CERT, Panda, and other sources. To contact the compilers of Worry Watch, go to http://www.megabyteminute.com/contactdavid.html)