Alias/esWorm.SymbOS.Cabir.m [KAV], Symb/Cabir-K [Sophos], SYMBOS_CABIR.M [Trend], SymbOS/Cabir.M worm [NOD32] | ||||||||||||
Detection Availability
| ||||||||||||
Visible Symptoms
![]() Figure 1: Post-install display (note: we blurred it on purpose) | ||||||||||||
Detailed AnalysisThis variant of Cabir is similar to SymbOS/Cabir.A!worm.However, the installation paths below are specific to that variant: C:\SYSTEM\APPS\spookyNote the attempt to disguise as an Antivirus product. FInally, the picture spooky.mbm (Fig 1 above) is displayed upon successful installation, in order to tame infected users suspicion. | ||||||||||||
Recommended ActionDelete all the virus files with a file manager application - or run FortiClient Mobile Security. |