1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Worm:SymbOS/Commwarrior

Name : Worm:SymbOS/Commwarrior
Category:Malware
Type:Worm
Platform:SymbOS
Origin:Russia

Summary

Commwarrior is a worm that operates on Symbian Series 60 2nd Edition devices.

The worm is capable of spreading itself via Bluetooth and MMS.

Disinfection

Disinfection with F-Secure Mobile Anti-Virus

F-Secure Mobile Anti-Virus detects Commwarrior and will delete the worm's components.

  • Download F-Secure Mobile Anti-Virus from http://f-secure.mobi
and activate the Anti-Virus
  • Scan the phone and remove any components of the malware
  • Reboot the phone to remove memory resident components

After disinfection, you can remove any remaining empty directories by opening the phone's application manager and uninstalling the SIS file in which Commwarrior arrived (either commw.sis or a random name).

Variants C and Q require the use of a disinfection tool named F-Commwarrior. The tool and instructions can be obtained from
http://mobile.f-secure.com/disinfection/fcommwarrior.html.

Additional Details

Phones infected with Commwarrior will start searching for other devices within Bluetooth wireless range and will attempt to send infected SIS files to the discovered devices.

The SIS files that Commwarrior transmits are randomly named so that phone users cannot be warned to avoid files with any particular given name.

In addition to using Bluetooth, Commwarrior will also read the user's local address book for phone numbers and will then start sending MMS messages containing Commwarrior.

Please see the following descriptions for additional details:

  • Commwarrior.B
  • Commwarrior.C
  • Commwarrior.D
  • Commwarrior.E
  • Commwarrior.F
  • Commwarrior.G
  • Commwarrior.H
  • Commwarrior.I
  • Commwarrior.J
  • Commwarrior.K
  • Commwarrior.L
  • Commwarrior.M
  • Commwarrior.N
  • Commwarrior.Q

Additional Notes:

Variant Commwarrior.Z is closely related to Commwarrior.C