All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog



 
Malware Description Search

 

  Home / Viruses / Virus Encyclopedia / Malware Descriptions / Network Worms / Internet Worms

Worm.SymbOS.Cabir.d

Other versions: .a, .b, .c, .k

Aliases
Worm.SymbOS.Cabir.d (Kaspersky Lab) is also known as: SymbOS.Cabir!dr (Symantec),   Symb/Cabir-C (Sophos),   SymbOS_CABIR.C (Trend Micro),   SymbOS.Worm.Cabir.C (SOFTWIN),   SymbOS/Cabir.D (Panda)
Detection added Dec 14 2004
Description added Jun 26 2007
Behavior Internet Worm

Technical details

This malicious program is a worm which runs under Symbian. The worm itself is a SIS file. The file is 15092 bytes in size.

It spreads via Bluetooth.

Payload

In order for a device to become infected, the user has to accept the malicious file twice.

When installing, the worm will display the following messages:

During installation, the program will drop the following files to the smartphone:

  • C:\SYSTEM\apps\MYTITI\MYTITI.app is an executable EPOC file, and is 11,932 bytes in size. This is the main worm file;
  • C:\SYSTEM\apps\MYTITI\MYTITI.rsc is the worm's resource file;
  • C:\SYSTEM\apps\MYTITI\flo.mdl ensures that the malicous program will be automatically started if the device is rebooted.

In order to function, the worm uses functions from the following system libraries:

BAFL.DLL
BLUETOOTH.DLL
CONE.DLL
EFSRV.DLL
EIKCORE.DLL
ESOCK.DLL
EUSER.DLL
IROBEX.DLL

Once the device has been infected, a file called "C:\SYSTEM\SYMBIANSECUREDATA\MYTITISECURITYMANAGER\MYTITI.SIS" is created. It is this file which will be transmitted in order to infect other devices.

The worm then scans for accessible devices which have Bluetooth enabled. The worm will choose the first accessible device in the list and attempt to send "MYTITI.SIS" to this device.

Apart from its propagation routine, this worm has no malicious payload. However, this worm can cause a device to become unstable due to the presence of the worm file in memory, and the constant scanning for accessible Bluetooth devices.

Removal instructions

In order to delete this malicious program, install a file manager application which provides the option to view hidden and system files. Then delete the files listed below.

C:\SYSTEM\apps\MYTITI\flo.mdl
C:\SYSTEM\apps\MYTITI\MYTITI.app
C:\SYSTEM\apps\MYTITI\MYTITI.rsc
C:\SYSTEM\SYMBIANSECUREDATA\MYTITISECURITYMANAGER\MYTITI.SIS

Once you have done this, reboot the device.

 

Copyright © 1996 - 2009
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com