Select local site

| Japanese | Simplified Chinese | Traditional Chinese (Hong Kong) | Traditional Chinese (Taiwan)

F-Secure Malware Information Pages: Commwarrior.H

[Summary] | [Disinfection] | [Detailed Description] | [Detection]

Name : Commwarrior.H
Type:Virus
Category:Malware
Platform:SymbOS
Date of Discovery:April 10, 2006
Radar

Summary

SymbOS/Commwarrior.H is a worm that operates on Symbian Series 60 devices. The worm is capable of spreading both over Bluetooth and MMS messages. When Commwarrior infects a phone it will start searching for other phones that are within Bluetooth range and send infected SIS files to the found phones. The SIS files that Commwarrior sends are randomly named, so that users cannot be warned to avoid files with any given name. In addition to spreading over Bluetooth, Commwarrior will also read the users' local address book for phone numbers and start sending MMS messages containing the commwarrior SIS file to those numbers.

MMS messages are multimedia messages that can be sent between Symbian phones and other phones that support MMS messaging. As the name implies, MMS messages are intended to contain only media content, such as pictures, audio or video, but they can contain anything, including  infected Symbian installation files.

Commwarrior.H is close variant to Commwarrior.D. For more details please see http://www.f-secure.com/v-descs/commwarrior_d.shtml.

Back to the Top

Disinfection

F-Secure Mobile Anti-Virus will detect Commwarrior and delete the virus components.

If your phone is infected with Commwarrior and you cannot install files over bluetooth, you can download F-Secure Mobile Anti-Virus directly to your phone:

  1. Open the phone's web browser
  2. Go to http://mobile.f-secure.com
  3. Select link "Download F-Secure Mobile Anti-Virus" and then select phone model
  4. Download the file and select open after download
  5. Install F-Secure Mobile Anti-Virus
  6. Go to applications menu and start Anti-Virus
  7. Activate Anti-Virus and scan all files
  8. Reboot the phone to remove any Commwarrior processes that are still running
After disinfecting the phone, you can remove any remaining empty directories by going to the application manager and uninstalling the SIS file in which Commwarrior arrived.

Back to the Top

Detailed Description
Infection

Commwarrior.H uses MMC (e: drive on the phone) as temporary storage for building the files to be sent further. Removing MMC from the phone will stop Commwarrior.H until MMC is re-inserted onto the phone.
Back to the Top

Detection

F-Secure Mobile Anti-Virus for Symbian detects this malware starting from the update build number 28.


Back to the Top



F-Secure Corporation

Last Modified: April 11, 2006