SymbOS/Cabir.E!worm

Alias/esSymb/Cabir-E [Sophos], SymbOS.Worm.Cabir.C [BitDefender], SymbOS/Cabir.R.worm [Panda]
Release DateMar 22, 2007
Detection Availability
Active DatabaseExtended Database
FortiGatelowhigh
FortiClient
FortiMailN/A
Current Antivirus Definition Database Version: 12.339
Description

Visible Symptoms

  • Rapid battery power loss due to repeated propagation attempts via Bluetooth.

  • Presence of the following files in \SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER:
    • ni&ai-.app
    • ni&ai-.rsc
    • ni&ai-.sis

    Detailed Analysis

    This variant of Cabir is similar to SymbOS/Cabir.A!worm.

    The difference is that it is installed in the following folder with file name ni&ai-:
    \SYSTEM\APPS\ni&ai-
    and that the the virus files are copied to the following folder:
    \SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER

    Description Last Updated Date: Jul 14, 2008
    Reference: ID - 345151