Wednesday, May 27, 2009

Mobile Viruses And your Symbian Devices

Mobile Viruses....Whats the damage? Whats the antivirus ?

Whats the threat?

Imagine if someone were to erase your phone book - or worse still, steal it?

Imagine if someone were reading your text messages and personal emails - how would you feel?

Imagine if someone could trace your bank details, or other sensitive information from your phone.

Imagine if someone could add just 10p a month to your bill. Would you notice? How much could they regularly take from your account before you would be alerted to it?

Imagine if someone stole your identity? Without virus protection you run the risk of ID theft, these details are easy to obtain from your mobile.

Imagine if you simply could not use your phone.

This list above is what is under threat by a mobile virus getting into your cell or symbian devices, once in your Phone, PDA , Pocket Pc or what ever you call you device any or all of the above could happen.

Many Of the Threats Listed Below can be avoided by being careful what texts and emails you open. Have you ever received a text message offering a free mp3, software download or something more suggestive? you may have downloaded a virus.

Here are some examples Of the viruses out there and what they do

Doomed : What does this virus do?

This virus arrives disguised as an installer for a normal application, when run it stops normal applications on your phone from working, prevents your phone from restarting properly and introduces and runs SymbOS/Skulls, SymbOS/CardBlock, SymbOS/CardTrap, SymbOS/Fontal, SymbOS/CommWarrior and SymbOS/Cabir. The virus can also sometimes cause other Bluetooth devices in the vicinity of the infected one to restart.

SymbOS/Doomed arrives as a SIS installer disguised as a normal application. Some known applications it uses for cover are:

Double Process Speed v6.1.3 by DFT
Effects v1.05 by Dj 6230
exoVirusStop v2.13.16
Doom 2

It usually has three primary payloads:

  • Disable normal applications
  • Prevents proper phone boot
  • Drops and executes other Symbian viruses
CommWarrior : What does this virus do?

This virus will reset your phone on the first hour of the 14th of every month. It spreads using Bluetooth and MMS utilising your phonebook contacts to send the MMS to.

SymbOS/CommWarrior is the first known mobile malware that spreads via both Bluetooth and Multimedia Messaging Service (MMS). It can also be downloaded from malicious web sites as an archive file named COMMWARRIOR.ZIP.

It affects phones running the Symbian S60 platform. Some phones affected by SymbOS/CommWarrior include the following:

Nokia 3650, 3600
Nokia 3660, 3620
Nokia 6600
Nokia 6620
Nokia 7610
Nokia 7650
Nokia N-Gage
Panasonic X700
Sendo X
Siemens SX1

Bluetooth Propagation

Once running in a device, SymbOS/CommWarrior searches for other phones with Bluetooth. Once a target phone is found, it sends a randomly named SIS file to the target.

The SIS file enters the target phone’s Inbox attached to a message. When the message is opened, it activates the SIS file and installs the following:

!:systemappsCommWarriorcommwarrior.exe
!:systemappsCommWarriorcommrec.mdl

2 comments:

Anonymous said...

Wіth hаvin so muсh written content
ԁο you eveг run іnto any pгoblems of plagorism or copyright infringemеnt?
My site has a lot of exсlusіνe cοntent I've either authored myself or outsourced but it appears a lot of it is popping it up all over the internet without my authorization. Do you know any ways to help reduce content from being ripped off? I'd really appreciate іt.


Visit my web ѕite http://www.dallasautoinsurance1.com/
My webpage ; carrollton car insurance

Anonymous said...

Doh! I ωas ԁomаin shopping at
namecheаp.com аnd ωent to typе in the domain name:
http://wwω.blogger.com/comment.g?blogID=1684491319680066712&postID=4043152175351757306 and guess who alгeady purchasеԁ it?

You ԁid! lol ј/k. I wаs about
to purchasе this domain name but reаlized it was taken so
I figured I'd come check it out. Nice blog!

http://blog.lgmedsupply.com/?p=312/