UMU Mobile Security Banner
SymbOS/Beselo.C
Green Tick UMU Scan protects against this virus.
Threat Level:
High
Type:
Worm
SDB Version:
153
SDB Release Date:
09/04/2008
Description Date:
24/04/2008
What does this virus do?
Arriving
on your phone disguised as a media file, once installed on your phone, it replicates itself and sends it to the nearest Bluetooth device it can find. It also waits for incoming SMS messages and replies to the number with an infected MMS at your cost. This virus also sends infected MMS to random numbers in China at your cost.

SymbOS/Beselo.C arrives as a SIS installation package disguised as a media file. This tricks users into executing this Worm on their phones. The SIS installer may be named as any one of the following: 

Beauty.jpg
Love.rm
Sex.mp3
 
An example of Beselo.C being installed:


 
It drops the following components: 

c:\system\data\<random letters>.exe
c:\system\data\<random letters>.dat
c:\system\data\<random letters>.ini 

This EXE component in turn drops a copy of itself in C:\SYSTEM\APPS and E:\SYSTEM\APPS as well as a matching file:

\SYSTEM\Recogs\<1st 4 letters of EXE component’s name>.mdl 

that automatically executes the exe component at the phone’s startup. 

It also creates its own SIS installation package: 

C:\SYSTEM\APPS\<random letters>.SIS 

Once installed, it searches for an available Bluetooth device, connects to the device, and sends a copy of its SIS installer.

SymbOS/Beselo.C waits for incoming SMS messages then sends an MMS message as a reply. This tricks the receiver into thinking that the compromised MMS came from a trusted source. The MMS has a subject of “photo” and a copy of SymbOS/Beselo.C’s SIS installer.

As an additional payload, every few minutes this worm sends a copy of its SIS installer via MMS to random numbers in China. The costs of these MMS messages are charged to the infected phone’s owner.


SymbOS/Beselo.C affects phones running the Symbian S60 platform. Some affected phones include the following: 

Nokia 3650, 3600
Nokia 3660, 3620
Nokia 6600
Nokia 6620
Nokia 7610
Nokia 7650
Nokia N-Gage
Panasonic X700
Sendo X
Siemens SX1
 

Manual Disinfection 

  1. Scan your mobile device using UMU Scan and delete all files detected as SymbOS/Beselo.C.
  2. Reboot your device to kill malware residue processes.
Virus Definitions

List of virus definitions
Report a new virus/spyware