Sophos

Symb/Cabir-E

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from February 2005 (3.90)
Protection available since 10 December 2004 21:51:07 (GMT)
Detected by All Sophos products

More Information

Symb/Cabir-E spreads as a Symbian SIS package named ni&ai-.sis. The package contains the following components extracted to ./System/Apps, ./System/ni&ai-SECURITYMANAGER and ./System/Recogs:

./system/apps/ni&ai-/flo.mdl
./system/apps/ni&ai-/nieai-.rsc
./system/apps/ni&ai-/nieai-.app
./system/ni&ai-SECURITYMANAGER/ni&ai-.rsc
./system/ni&ai-SECURITYMANAGER/ni&ai-.app
./system/ni&ai-SECURITYMANAGER/ni&ai-.sis
./system/RECOGS/flo.mdl

Flo.mdl is a DLL that uses the EZBoot mechanism to attempt to launch the Symb/Cabir-E application file ni&ai-.app when the device is powered on.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer