Commwarrior

Commwarrior

Known Versions

SymbOS/Comwar.v10!worm
SymbOS/Comwar.v10b!worm
SymbOS/Comwar.v20pro!worm
SymbOS/Comwar.v30!worm
SymbOS/Comwar.v30lite!worm

About

"Commwarrior" is a virus family affecting cell phones operating Symbian OS S60 2nd edition. The virus goal is to spread to other phones, using MMS, Bluetooth, and Memory Cards as transport avenues.
Currently, it is being reported in over 18 different countries around Europe, Asia and North America.

Infection routines

- The virus extracts numbers from the contact list of the infected phone, and sends those an MMS carrying an infected installation file. This file usually poses as a recreative (game, ringtones, porn...) or utiltary (antivirus, desktop manager...) application. To effectively become infected, the target has to execute it, besides reading the malicious MMS.

- The virus also resorts to Bluetooth as an alternative propagation method: it searches for bluetooth-enabled device in its vicinity, and tries to send itself to those, hammering the recipient until he/she selects "yes" in the file transfer dialog.

- Certain versions drop a copy of the virus on the memory card of the infected device. Upon insertion of the infected memory card, a compatible device is in turn automatically infected.

- Certain versions search for Symbian installation files (".sis" files) on the infected device and inject a copy of the virus in those. An infected user may therefore unwillingly infect friends by manually sending them installation files (which he believes to be clean).

Visible Symptoms

- rapid battery power loss due to propagation attempts via Bluetooth.
- Abnormally high bill, due to propagation attempts via MMS messages.
- Some variants of the virus display a page upon infection, exhibiting the following message: Surprise! Your phone infected by CommWarrior worm v3.0.

Disinfection

Download and run our automatic removal tool: here

[ Back to main page ]

site powered byFortiGuard Center | ©2008 Fortinet Inc. All Rights reserverd