This application requires Javascript for optimal performance.

SymbOS/Cabir.E!worm - Released Mar 22, 2007 - Last Updated Jul 14, 2008

Alias/es

Symb/Cabir-E [Sophos], SymbOS.Worm.Cabir.C [BitDefender], SymbOS/Cabir.R.worm [Panda]

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

  • Rapid battery power loss due to repeated propagation attempts via Bluetooth.

  • Presence of the following files in \SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER:
    • ni&ai-.app
    • ni&ai-.rsc
    • ni&ai-.sis

    Detailed Analysis

    This variant of Cabir is similar to SymbOS/Cabir.A!worm.

    The difference is that it is installed in the following folder with file name ni&ai-:
    \SYSTEM\APPS\ni&ai-
    and that the the virus files are copied to the following folder:
    \SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER

    Recommended Action

    Delete all the virus files with a file manager application - or run FortiClient Mobile Security.

    Reference: ID - 345151