SymbOS/Cabir.E!worm - Released Mar 22, 2007 - Last Updated Jul 14, 2008
|
Alias/esSymb/Cabir-E [Sophos], SymbOS.Worm.Cabir.C [BitDefender], SymbOS/Cabir.R.worm [Panda] |
Detection Availability
|
Visible SymptomsRapid battery power loss due to repeated propagation attempts via Bluetooth.
Presence of the following files in \SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER:
- ni&ai-.app
- ni&ai-.rsc
- ni&ai-.sis
|
Detailed AnalysisThis variant of Cabir is similar to SymbOS/Cabir.A!worm.
The difference is that it is installed in the following folder with file name ni&ai-:
\SYSTEM\APPS\ni&ai-
and that the the virus files are copied to the following folder:
\SYSTEM\SYMBIANSECUREDATA\ni&ai-SECURITYMANAGER
|
Recommended ActionDelete all the virus files with a file manager application - or run FortiClient Mobile Security. |