Symbian Virus

(Visited 1908 times)

Today, early in the morning, about 5 am, I received an MMS from my brother-in-law, who are now studying in Multimedia College in KL.

worm-symbian.gifThe MMS subject is : CheckDisk
Message: *FREE* CheckDisk for SymbianOS released MobiComm

And then my N70 displayed a shot notice, to press option to see the attachment.

Smelling something very fishy with the message.

Luckily, at that time, I was infront of my computer. I just open the web browser and go to Google and search for “Symbian checkdisk“, and my feeling was true. It is a worm, called Commwarrior.

According to F-Secure website, Commwarrior is a worm that operates on Symbian Series 60 devices, and capable of spreading both over Bluetooth and MMS messages.

When Commwarrior infects a phone it will start searching other phones that in can reach over Bluetooth and send infected SIS files to the phones it finds. Comwarrior will also read the users local address book for phone numbers, and start sending MMS messages containing the commwarrior SIS file with random file names. But, according to the website again, Commwarrior replicates over MMS only from 00:00 to 06:59, based on the phone’s own clock.

After I found out about the worm, I just deleted the message and sent a message to my brother-in-law to tell him about the worm that had infected his Nokia N-Gage.

Later today, he told me that he already formatted his handphone. :)

From Symantec website on how to remove the worm;

To remove SymbOS.Commwarrior.A:

1. Install a “file manager” program on the phone, e.g.: Fexplorer 

2. Enable the option to view the files in the system directory.

3. Search the drives, A through Y, for the \system\apps\commwarrior directory.

4. Delete the files commwarrior.exe and commrec.mdl.

5. Go to the \system\updates\commwarrior directory.

6. Delete the files commwarrior.exe, commrec.mdl, and commw.sis.

7. Go to the \system\recogs directory.

8. Delete the file commrec.mdl.

Category: Gadget, Mobile Phone

Leave a Reply

You must be logged in to post a comment.