Commwarrior
Commwarrior
Known Versions
SymbOS/Comwar.v10!worm
SymbOS/Comwar.v10b!worm
SymbOS/Comwar.v20pro!worm
SymbOS/Comwar.v30!worm
SymbOS/Comwar.v30lite!worm
About
"Commwarrior" is a virus family affecting cell phones operating Symbian OS S60 2nd edition. The virus goal is to spread to other phones, using MMS, Bluetooth,
and Memory Cards as transport avenues.
Currently, it is being reported in over 18 different countries around Europe, Asia and North America.
Infection routines
- The virus extracts numbers from the contact list of the infected phone, and sends those an MMS carrying an infected installation file. This file usually
poses as a recreative (game, ringtones, porn...) or utiltary (antivirus, desktop manager...) application. To effectively become infected, the target has
to execute it, besides reading the malicious MMS.
- The virus also resorts to Bluetooth as an alternative propagation method: it searches for bluetooth-enabled device in its vicinity, and tries to send
itself to those, hammering the recipient until he/she selects "yes" in the file transfer dialog.
- Certain versions drop a copy of the virus on the memory card of the infected device. Upon insertion of the infected memory card, a compatible device
is in turn automatically infected.
- Certain versions search for Symbian installation files (".sis" files) on the infected device and inject a copy of the virus in those. An infected user
may therefore unwillingly infect friends by manually sending them installation files (which he believes to be clean).
Visible Symptoms
- rapid battery power loss due to propagation attempts via Bluetooth.
- Abnormally high bill, due to propagation attempts via MMS messages.
- Some variants of the virus display a page upon infection, exhibiting the following message: Surprise! Your phone infected by CommWarrior worm v3.0.
Disinfection
Download and run our automatic removal tool:
here