Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 0 gostiju pregledaju ovu temu.
Idi dole
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: Virus Strike ... Import so read this  (Pročitano 680 puta)
21. Sep 2005, 22:19:31
Prijatelj foruma
Jet set burekdzija


Zodijak Gemini
Pol Muškarac
Poruke 7441
Zastava Krusevac
Virus Strike ... Import so read this

Virus Characteristics:
This threat is a malicious .SIS file targeting Nokia series 60 based devices. The virus masquerades as a variety of benign applications, including games, porn, and cross platform emulators. See “Table 1 - MMS Message Text” for a more complete list of subjects and message content.

It replicates by sending itself to nearby Bluetooth devices as well as via MMS. The MMS recipient appears to be selected from the host address book. Once it is in the host inbox the user can view the message and must approve the installation of the SIS. Once installed several files are dropped (see Table 1 - MMS Message Text) and the virus sets itself up for automatic execution at system start.

Affected Platforms:
Series 60 devices

Confirmed devices:
Nokia 7610
Nokia 6600

Symptoms

Upon installation of the .SIS file, the user will be presented with the misleading dialogue for installing the virus SIS . See Figure 1 - Figure 4 , below. See also ‘Table 1 - MMS Message Text ’ for a list of the possible MMS subject and messages.



Figure 1 - Bluetooth Receive Prompt



Figure 2 - SIS Installer Prompt



Figure 3 - Inbox



Figure 4 - Installer Details



Table 1 - MMS Message Text

Immediately after installation, the worm copies itself to c:\system\updates\commwarrior.exe and places a boot hook in c:\system\recogs\commrec.mdl . Finally, it copies its installation SIS file (which will be sent to target systems) to c:\system\updates\commw.sis .

Note that because the worm does not install an application, no user-visible indication of infection is present.

Once running, the application probes the Bluetooth network for nearby devices with an "OBEX push" (i.e. "file beaming") profile and sends the commw.sis file to them, renamed with a random-looking file name.

Note that unlike earlier worms, this worm properly uses the Bluetooth SDP protocol to detect devices. It will therefore successfully spread to (but not run on) devices other than Nokia Series 60 phones. It will also not exhibit the "hang" behavior observed with SymbOS/Cabir worms that try to infect devices that are not listening.

The worm retries to infect nearby devices every ~1 minute.

Presumably (this has not been verified yet) the worm also sends MMS messages containing the same infected content to recipients listed in the phone and/or SIM's address books. Because MMS is a message (not file) based protocol, it attaches itself as an attachment to a message with text indented to entice the target user into installing the file.

Upon reboot, the "recognizer" file in c:\system\recogs\commrec.mdl runs and starts an instance of commwarrior.exe running, ensuring that the process continues.

The following files are installed by CommWarrior:
c:\system\apps\commwarrior\commrec.mdl - 2,152 bytes
c:\system\apps\commwarrior\commwarrior.exe - 27,936 bytes
c:\system\apps\commwarrior\commrec.mdl - 2,152 bytes
c:\system\recogs\commrec.mdl - 2,152 bytes
c:\system\updates\commrec.mdl - 2,152 bytes
c:\system\updates\commwarrior.exe - 27,936 bytes
c:\system\updates\commw.sis - 30,582 bytes

Payload:
Rapid battery drain.
Propagates via MMS to addresses in the user address book.
Propagates to nearby Bluetooth devices.

Method Of Infection

This virus replicates via MMS to addresses in the user address book and to nearby Bluetooth devices.

Removal Instructions

Use a file manager to delete:
c:\system\recogs\commrec.mdl
Reboot the handset.
Delete the following (now inert) files:
c:\system\updates\commrec.mdl
c:\system\updates\commw.sis
c:\system\updates\commrwarrior.exe
c:\system\apps\CommWarrior\commwarrior.exe
c:\system\apps\CommWarrior\commrec.mdl
IP sačuvana
social share
Nabijem na kurac ceo ovaj forum i zelim svima sve najgore i da bog da svi imali retardacije i da bog da vam se svima desilo isto ko i meni sto se desilo
Pogledaj profil Skype
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Krajnje beznadezan


Long live Rock n' Roll

Zodijak
Pol
Poruke 11469
Zastava
mob
HTC HD2
Mislim da imam negde ovaj u kolekciji. Ako je neko zainteresovan za proučavanje virusa samo u edukativne svrhe, neka javi, postovacu ga.
« Poslednja izmena: 21. Sep 2005, 22:26:54 od Cigla tel. »
IP sačuvana
social share

Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Jet set burekdzija


Zodijak Gemini
Pol Muškarac
Poruke 7441
Zastava Krusevac
Ma virusi nisu problem, glej kolko ih ja imam brate!

IP sačuvana
social share
Nabijem na kurac ceo ovaj forum i zelim svima sve najgore i da bog da svi imali retardacije i da bog da vam se svima desilo isto ko i meni sto se desilo
Pogledaj profil Skype
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
nazadnapred
Prebaci se na:  
Oznake: commw exe sis

Poslednji odgovor u temi napisan je pre više od 6 meseci.  

Temu ne bi trebalo "iskopavati" osim u slučaju da imate nešto važno da dodate. Ako ipak želite napisati komentar, kliknite na dugme "Odgovori" u meniju iznad ove poruke. Postoje teme kod kojih su odgovori dobrodošli bez obzira na to koliko je vremena od prošlog prošlo. Npr. teme o određenom piscu, knjizi, muzičaru, glumcu i sl. Nemojte da vas ovaj spisak ograničava, ali nemojte ni pisati na teme koje su završena priča.

web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Nova godina Beograd :: nova godina restorani :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Sudski tumač Novi Beograd

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.065 sec za 17 q. Powered by: SMF. © 2005, Simple Machines LLC.