PDA

View Full Version : Mobile Worm (Virus)


cmo
01/24/08, 04:59 PM
from AHTC email:

New SymbianOS Worm Spreading In-The-Wild

The FortiGuardGlobal Security Research Team discovered a new SymbianOS Worm actively spreading on various mobile phone networks.

The worm, deemed SymbOS/Beselo.A!worm is able to run on several Symbian S60 enabled devices. These devices include, but may not be limited to, Nokia 6600, 6630, 6680, 7610, N70 and N72 phones.

After an installation phase, the worm engages in a propagation routine: phone numbers located in the contact list of the devices are harvested, and targeted by viral MMS carrying a SIS-packed (Symbian Installation Source) version of the worm. However, the SIS file does not bear a .sis file extension -- rather, it is disguised as a multimedia file with an evocative name: either Beauty.jpg, Sex.mp3 or Love.rm.

Unlike Microsoft Windows, SymbianOS types files based on their contents and not their extensions, so it is worth noting that recipients of infected MMS would still be presented with an installation dialogue upon "clicking" on the attachment. Therefore, users could easily be deceived by the extension and unknowingly install the malicious piece of software.

In addition to harvesting the numbers stored in the phone address book as mentioned above, the Beselo worm sends itself to generated numbers as well. Interestingly, all those numbers are located in China and belong to the same mobile phone operator. Some of those numbers have been verified to belong to actual customers, rather than being premium service numbers. The whys and hows of such a routine are still under investigation.

Albeit the prevalence of this mobile malware incident is still low, the FortiGuard Global Security Research Team will continue to monitor the situation and update the description with new findings as needed.

Users may know they have been infected if they see unrecognized sent messages in their MMS outboxes (the device needs to be configured to save such messages). FortiClient Mobile automatically detects and removes the Beselo worm. For users without FortiClient Mobile who believe they may be infected, please contact your mobile carrier or phone manufacturer for technical support in manually removing the virus.

For more information on SymbOS/Beselo.A!worm, visit the Virus Encyclopedia.

neeruam
01/24/08, 08:26 PM
hmmm... this has produced a lot of customers dropping by our shop.

how would u know if u are infected?

hmmm its either your mobile phone automatically sends MMS message to either thru your bluetooth device or your MMS sending.. (causing your load to be consumed without you using it.)

or

there is a logo ( a new operator logo ) like comwarrior.. or infected by comwarrior..

is thats the case..

what must u do?

bring it right away to a service center and ask them to remove the virus for if you will not mind it you might lose all the information u have in your mobile phone or worse you will have a unit that would not power on anymore.



how can u prevent this?

hmm never ever accept any bluetooth transfer if u dont know the one sending it to u,

virus is not directly installed to your mobile phone.

if u are not going to accept it,

u will not be infected.

hope u gained some knowledge.

feel free to asko questions., if there are any.

cmo
01/24/08, 09:12 PM
hmmm... this has produced a lot of customers dropping by our shop.

how would u know if u are infected?

hmmm its either your mobile phone automatically sends MMS message to either thru your bluetooth device or your MMS sending.. (causing your load to be consumed without you using it.)

or

there is a logo ( a new operator logo ) like comwarrior.. or infected by comwarrior..

is thats the case..

what must u do?

bring it right away to a service center and ask them to remove the virus for if you will not mind it you might lose all the information u have in your mobile phone or worse you will have a unit that would not power on anymore.



how can u prevent this?

hmm never ever accept any bluetooth transfer if u dont know the one sending it to u,

virus is not directly installed to your mobile phone.

if u are not going to accept it,

u will not be infected.

hope u gained some knowledge.

feel free to asko questions., if there are any.

For sure if it happens to my mobile, I will bring to your shop. :smilie3:

ayumie
05/26/08, 11:38 AM
my w8010 is acting weird i receive some messages a day late , messages are sometimes sent to different people , after reading a message and no reply was made it gets lost but comes back after a few hours or a day ... it's just a year since i bought the unit . what do you think is wrong with my phone ? and yes my grand daughter is also using the phone she's 9. :waah:
thank you

s a m
06/11/08, 02:44 PM
hi..

try to reset your unit by going to settings-master reset.. but, be sure to backup all your contacts and other important data from your mobile becuse it will surely be gone..

trailblazerstravelntours
06/11/08, 11:27 PM
Thanks for the info about mobile worms and mobile phones. :fishin:

DarrelCorn
08/16/11, 03:28 PM
Cabir is a network virus that affects phones commanding the Symbian mobile phone operating system by Symbian.Cabir extents within mobile phones using a particularly Symbian operating system distribution (or SIS) file disguised as a security authority function.

DarrelMartin
01/23/12, 10:25 PM
The best mobile security software offers security from a variety of trojans, Malware, trojans and other destructive risks. If you spend a lot of time surfing around the web on your mobile phone, powerful firewall program security will safeguard your phone from those should hanging out on the internet.

Fedricwalls
05/10/12, 09:37 PM
Now, there are so many anti virus software are available in the market which are very useful for the keep securing your mobile from various types of viruses and worms quickly. I am currently using Norton safety for my iPhone 4S.