This application requires Javascript for optimal performance.

SymbOS/Comwar.v10b.VAR!worm - Released Jun 13, 2007 - Last Updated Mar 11, 2008

Alias/es

Worm.SymbOS.Comwar.c, SymbOS/Commwarrior.f!sis, SYMBOS_CMWAR.GEN, SymbOS.Worm.ComWar.F, SymbOS.Worm.CommWar.B, SymbOS/CommWarrior.B, SymbOS/Commdropper.C, SymbOS.Worm.Comwar.c, SYMBOS/Comwar.a.1, SymbOS/Comwar.1.0.B.VAR!worm

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

  • An infected phone may experience rapid battery power loss due to the constant efforts by the virus to infect other phones via a Bluetooth seek-and-connect outreach.

  • The most common dropped files for this malware are:
    • c:\system\updates\commrec.mdl
    • c:\system\updates\commw.sis
    • c:\system\updates\commwarrior.exe

    Detailed Analysis

  • This detection is for samples that are very similar to SymbOS/Comwar.v10b!worm. These are usually binary edited samples of the original worm.

  • The most common dropped files for this malware are:
    • c:\system\updates\commrec.mdl
    • c:\system\updates\commw.sis
    • c:\system\updates\commwarrior.exe

    The receiving phone may receive one of several hard-coded messages - the actual message depends on which one the virus chooses, based on a randomizer routine. Below are the noted most common message that the malware may send to targeted phones (subject, message):

    Norton AntiVirus
    Released now for mobile, install it!

    MatrixRemover
    Matrix has you. Remove matrix!

    3DGame
    3DGame from me. It is FREE !

    MS-DOS
    MS-DOS emulator for SymbvianOS. Nokia series 60 only. Try it!

    PocketPCemu
    PocketPC *REAL* emulator for Symbvian OS! Nokia only.

    Nokia ringtoner
    Nokia RingtoneManager for all models.

    Security update #12
    Significant security update. See www.symbian.com

    Display driver
    Real True Color mobile display driver!

    Audio driver
    Live3D driver with polyphonic virtual speakers!

    Symbian security update
    See security news at www.symbian.com

    SymbianOS update
    OS service pack #1 from Symbian inc.

    Happy Birthday!
    Happy Birthday! It is present for you!

    Free SEX!
    Free *SEX* software for you!

    Virtual SEX
    Virtual SEX mobile engine from Russian hackers!

    Porno images
    Porno images collection with nice viewer!

    Internet Accelerator
    Internet accelerator, SSL security update #7.

    WWW Cracker
    Helps to *CRACK* WWW sites like hotmail.com

    Internet Cracker
    It is *EASY* to *CRACK* provider accounts!

    PowerSave Inspector
    Save you battery and *MONEY*!

    3DNow!
    3DNow!(tm) mobile emulator for *GAMES*.

    Desktop manager
    Official Symbian desctop manager.

    CheckDisk
    *FREE* CheckDisk for SymbianOS released!MobiComm

    MobiComm, Mobile communications inspector. Try it!

    The MMS message will have an attachment of a randomized name with a .SIS extension. If the user runs the attached file, it will install the virus.

    Recommended Action

  • Scan the infected device and delete all modules related to this worm.

  • Reference: ID - 431450