Esato

Forum > General discussions > Non mobile discussion > I got a Virus on my PC through Bluetooth!

12  Next
Author I got a Virus on my PC through Bluetooth!
p900 lover
W960
Joined: Jan 08, 2004
Posts: > 500
From: London
PM
Posted: 2005-12-28 16:25
Reply with quoteEdit/Delete This PostPrint this post
I was sitting at home doin mmy stuff and all of a suden i get the pop up window saying sucessfull conection to bt .............
I was like WTF no1 is sending anything to my PC then i get this pop up message


And the virus deffinition is:
SymbOS.Commwarrior.B is a worm that replicates on the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones. It attempts to spread using Multimedia Messaging Service (MMS) and Bluetooth as a randomly named .sis file. If it is the first hour of the 14th of any month, the threat resets the device.
From http://securityresponse.syman[....]data/symbos.commwarrior.b.html

I have herd about these before but never realised it "could" actually happen. So im guessing sum 1 was walking past my house and their phone detected my PC's BT was on and sent it?
whizkidd
W950 Blue
Joined: May 14, 2004
Posts: > 500
From: India
PM, WWW
Posted: 2005-12-28 16:33
Reply with quoteEdit/Delete This PostPrint this post
Hmmm... how on earth did the sender transferr the file without pairing his bt device with ur pc??
T230 >> T610 >> Ngage QD >> N73 >> N85 >> Omnia HD >> And countless other review units
Pradhika
T610
Joined: Jan 11, 2005
Posts: > 500
From: India
PM
Posted: 2005-12-28 16:37
Reply with quoteEdit/Delete This PostPrint this post
Someone has done something more than naughty it seems. Now have you rectified it? :-(

This message was posted from a J300

p900 lover
W960
Joined: Jan 08, 2004
Posts: > 500
From: London
PM
Posted: 2005-12-28 16:38
Reply with quoteEdit/Delete This PostPrint this post
Thats wha i was thinking..............
Im doin a virus scan now. Not usre hoe to get rid of this as the way im told to do it on that website is only for phones, i think there forgeting PC's can have BT too.
EastCoastStar
S700
Joined: Dec 07, 2003
Posts: > 500
From: orlando fl US
PM
Posted: 2005-12-28 16:59
Reply with quoteEdit/Delete This PostPrint this post
i wonder how it will affect your computer... 2 different OS's... weird...
Its good to be back!
gojnik064
LG Optimus 3D P920
Joined: Sep 18, 2003
Posts: 167
From: Subotica, Serbia
PM
Posted: 2005-12-28 17:27
Reply with quoteEdit/Delete This PostPrint this post
Heh,I received commwarrior twice in my old school,it was in march as I remember. And it cant do any harm to your PC,dont worry.

This message was posted from a Nokia

p900 lover
W960
Joined: Jan 08, 2004
Posts: > 500
From: London
PM
Posted: 2005-12-28 18:04
Reply with quoteEdit/Delete This PostPrint this post
Isit, but how do u get rid or it?
In norton virus scan it doesnt come up with anything, so cos do i clean my PC from it if i cant find it?

thanks
blayv
W810 black
Joined: Oct 24, 2004
Posts: > 500
From: Srbija
PM
Posted: 2005-12-28 18:08
Reply with quoteEdit/Delete This PostPrint this post
Try kaspersky or panda anti-virus

This message was posted from a T610

whizkidd
W950 Blue
Joined: May 14, 2004
Posts: > 500
From: India
PM, WWW
Posted: 2005-12-28 18:12
Reply with quoteEdit/Delete This PostPrint this post
Go to "start" menu and right click on it and from the resulting menu select "search" and when the search page is opened, write 9cpmwxqfa0.sis or simply .sis and search for it in all the local harddrives...

should give you the location of the virus file.. and then delete it manually..
T230 >> T610 >> Ngage QD >> N73 >> N85 >> Omnia HD >> And countless other review units
gojnik064
LG Optimus 3D P920
Joined: Sep 18, 2003
Posts: 167
From: Subotica, Serbia
PM
Posted: 2005-12-28 18:14
Reply with quoteEdit/Delete This PostPrint this post
I dont know, maybe it was allready moved to quarantine by AV software. I use NOD.

This message was posted from a Nokia

mario2002
J200
Joined: Feb 15, 2004
Posts: > 500
From: Jeffrey's-Bay ,South Africa
PM, WWW
Posted: 2005-12-28 18:22
Reply with quoteEdit/Delete This PostPrint this post
So , you are telling us that someone send a file to your pc over bluetooth without first establishing a connection ? Are you sure it was the bluetooth and not your wifi or even more possible the infrared connection ? There is absolutely no way of exchanging any data over bluetooth without your input.Not even a visit card. Never mind a program.If you only understand the basics of a bluetooth connection you will see that what you said is nonsens. I am not even bothering to give you any further advice on how to remove the 'virus'.There is a better chance for your pc to get the 'aids virus' then a s60 one the way how you explain it :-) if you see what I mean.

This message was posted from a Nokia 7650

p900 lover
W960
Joined: Jan 08, 2004
Posts: > 500
From: London
PM
Posted: 2005-12-28 18:41
Reply with quoteEdit/Delete This PostPrint this post
It was deffinitly BT as my BT popup thingy came up from the tray menu.
gojnik064
LG Optimus 3D P920
Joined: Sep 18, 2003
Posts: 167
From: Subotica, Serbia
PM
Posted: 2005-12-28 18:47
Reply with quoteEdit/Delete This PostPrint this post
Mario u r wrong, pairing is not required for object push. I just tryed it out, i unpaired my pc with phone, and phone with pc. Object push worked just fine without any intervention the pc.

This message was posted from a Nokia

Johnex
P990
Joined: Nov 26, 2002
Posts: > 500
From: Stockholm/Sweden
PM, WWW
Posted: 2005-12-28 18:50
Reply with quoteEdit/Delete This PostPrint this post
It is proven that bluetooth has security holes that the comwarrior viruses take advantage of. This appears to be a series60 problem, so se doesn't seem to be affected.

This message was posted from a Z1010

whizkidd
W950 Blue
Joined: May 14, 2004
Posts: > 500
From: India
PM, WWW
Posted: 2005-12-28 18:59
Reply with quoteEdit/Delete This PostPrint this post
Quote:

On 2005-12-28 18:50:23, Johnex wrote:
It is proven that bluetooth has security holes that the comwarrior viruses take advantage of. This appears to be a series60 problem, so se doesn't seem to be affected.


This message was posted from a Z1010



Bang on!!
I've seen the commwarrior spreading like wildfire thru all possible means as mms and bluetooth.. in some cases i get a "receive bluetooth messege from ..." message from a nearby infected s60 device and the surprising thing is that this thing spreads even if the bluetooth is switched off!
T230 >> T610 >> Ngage QD >> N73 >> N85 >> Omnia HD >> And countless other review units
Access the forum with a mobile phone via esato.mobi