Worm:SymbOS/Beselo

Classification

Malware

Bluetooth-Worm

SymbOS

Worm:SymbOS/Beselo.D, Worm:SymbOS/Beselo.E, Worm:SymbOS/Beselo.C, Beselo, Beselo.gen

Summary

Beselo is a MMS and Bluetooth worm family that operates on Symbian S60 Second Edition devices. The Beselo family is very similar to the Commwarrior family but contains enough differences in the code base and behavior that it is counted as separate family.

Disinfecting using F-Secure Mobile Security

  • Download F-Secure Mobile Security and activate it
  • Scan the phone and remove any components of the malware
  • Reboot the phone to remove memory resident components

Suspect a file is incorrectly detected (a False Positive)?

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest detection database updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    NOTE If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note You need administrative rights to change the settings.

For more Support

Community

Find the latest advice in our Community.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

Beselo worms spread via Bluetooth and MMS as Symbian SIS installation files.

The installation file is not labeled with the .SIS extension. The SIS file is named with MP3, JPG, or RM extensions in order to trick the recipient into thinking that it is multimedia file.

If the phone user attempts to open the file, Symbian will recognize it as an installation file and will start the application installer.

Please see the following variant descriptions for additional details:

Additional Notes:

Variants Beselo.C, Beselo.D and Beselo.E are closely related to Beselo.B.