Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Malware Information Pages: Cabir.AD

[Summary] | [Disinfection] | [Detailed Description] | [Detection]

Name : Cabir.AD
Type:Virus
Category:Malware
Platform:SymbOS
Date of Discovery:January 25, 2006
Radar

Summary
Cabir.AD is a minor variant of Cabir.B. The only significant difference is that Cabir.AD spreads as a file named Mario-.SIS instead of a file named Cabir.SIS. For more details, see description of Cabir http://www.f-secure.com/v-descs/cabir.shtml
Back to the Top

Disinfection

F-Secure Mobile Anti-Virus will detect Cabir.AD and delete the worm components. After deleting the worm files you can delete this directory: C:\system\apps\Mario-\ .

If your phone is infected with Cabir.AD and you cannot install files over bluetooth, you can download F-Secure Mobile Anti-Virus directly to your phone:

  1. Open the phone's web browser
  2. Go to http://mobile.f-secure.com
  3. Select link "Download F-Secure Mobile Anti-Virus" and then select phone model
  4. Download the file and select open after download
  5. Install F-Secure Mobile Anti-Virus
  6. Go to applications menu and start Anti-Virus
  7. Activate Anti-Virus and scan all files

Back to the Top

Detailed Description
Cabir.AD is a minor hexedit variant of Cabir.B, and with the exception of a new filename and different text being displayed at the beginning of the worm's code, Cabir.AD behaves identically to Cabir.B.
Back to the Top

Detection

F-Secure Mobile Anti-Virus for Symbian detects this malware starting from the update build number 15.


Back to the Top



F-Secure Corporation

Last Modified: March 16, 2006