Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Malware Information Pages: Cabir.C

[Summary] | [Disinfection] | [Detailed Description]

Name : Cabir.C
Alias:SymbOS/Cabir.C, EPOC/Cabir.C, Worm.Symbian.Cabir.C, Ni&Ai- virus
Type:Bluetooth-Worm
Category:Malware
Platform:SymbOS
Radar

Summary
Cabir.C is a minor variant of Cabir.B. The only significant differences are that Cabir.C displays different text on the start dialog when worm starts and that the Cabir.C spreads as Ni&Ai-.SIS instead of Cabir.SIS.

Cabir.C displays the text "Ni&Ai-" while Cabir.B displays text that contains just "Caribe".

For more details, see description of Cabir.A.
Back to the Top

Disinfection

Disinfecting using F-Secure Mobile Anti-Virus

F-Secure Mobile Anti-Virus will detect Cabir.C and delete the worm components. After deleting the worm's files you
can delete this directory:

  • c:\system\symbiansecuredata\Ni&Ai-securitymanager\

If your phone is infected with Cabir.C and you cannot install files via bluetooth, you can download F-Secure Mobile Anti-Virus directly
to your phone:

  1. Download F-Secure Mobile Anti-Virus from http://f-secure.mobi
    and activate the Anti-Virus
  2. Scan the phone and remove any components of the malware
  3. Reboot the phone to remove memory resident components
Back to the Top

Detailed Description
Cabir.C is a minor hexedit variant of Cabir.B, with the exception of a new filename and different text displayed during the worm's start. Cabir.C behaves identically Cabir.B.
Back to the Top



F-Secure Corporation

Last Modified: January 01, 2006