Fandom

Malware Wiki

Fontal

1,335pages on
this wiki
Add New Page
Comments0 Share

Fontal is a SymbOS (Symbian OS) Trojan that can only spread in Nokia, and this virus is based on Bluetooth with the PC. It is very similar to the 1970 iPhone Bug and Doomboot. It is one of the only viruses on the mobile device known as Nokia.

Payload

Fontal spreads by Bluetooth. When connected the user will see a new message titled "kill saddam.sis" (which means a trojan based "Fontal").

After installing the trojan, if the Nokia reboots, the boot will be stuck due to loading of the corrupted font file it installed.

The files installed are listed:

  • Kill sadam font.gdr
  • zKill sadam.aif
  • kill sadam1.rsc
  • Kill sadam.rsc
  • Kill sadam.app

Since the boot will fail, the device's storage needs to be formatted, causing the device to lose all of its data and load the factory settings.

Variants

This trojan has 8 variants, most that is simply renames.

Fontal.A

It will also corrupt the Application Manager with AppManager, which when opened, nothing happens.

Fontal.B and Fontal.G

It undergoes a name of "Nokia Anti-Virus.sis", and displays a message after installation:

Nokia Anti-Virus keep your phone protected from mobile virus. Please restart
your phone after installation complete to activate your anti-virus product.
If you found any problem regarding this software, please call :

Fontal.C

It disables Application Manager, Messaging, and Installing.

Fontal.D

It also drops Commwarrior.B and another copy of itself.

Fontal.E

It undergoes a name of "EICAR Anti-Virus.sis".

Fontal.F

It undergoes a name of "Nokia Update By 0ID500.sis".

Fontal.H

It undergoes a name of "T-VIRUS.sis". This makes it obvious that it is a virus, though it can be confused for anti-malware.

Videos

Trojan.SymbOS04:15

Trojan.SymbOS.Fontal

Fontal.A

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.