UMU Mobile Security Banner
SymbOS/Beselo.D
Green Tick UMU Scan protects against this virus.
Threat Level:
High
Type:
Worm
SDB Version:
153
SDB Release Date:
09/04/2008
Description Date:
24/04/2008
What does this virus do?
Arriving on your phone as part of SymbOS/Kiazha.A, this virus infects your Multi Media Card and spreads itself when the MMC is inserted into a different phone. It creates what look like media files, but they are the virus installer. Once installed on your phone, it replicates itself and sends it to the nearest Bluetooth device it can find. It also waits for incoming SMS messages and replies to the number with an infected MMS at your cost. This virus also sends infected MMS to random numbers in China at your cost.

SymbOS/Beselo.D arrives as a dropped component of SymbOS/Kiazha.A named ZN.EXE. 

Upon execution, it drops the following copies of itself and components: 

C:\System\Apps\DATA\ZN.exe
C:\System\Apps\DATA\ZN.sis - sis installer
C:\System\Bootdata\SIMILanguage.dat
C:\System\Data\DATA\ZN.dat
C:\System\Data\DATA\ZN.ini
C:\System\Recogs\DATA.mdl
E:\System\Apps\DATA\ZN.exe
E:\System\Recogs\DATA.mdl 

The copies it dropped in the phone’s Multi Media Card (drive E) helps this worm to propagate. When the compromised MMC is inserted in a new phone, Beselo.D infects that phone.

It also drops the following files in C:\System\Install:

In spite of the file extensions of these files suggesting that these are media files, this is just a trick and the files are actually SIS installers for this Symbian worm. 

Once installed, it searches for an available Bluetooth device, connects to the device, and sends a copy of its SIS installer.


SymbOS/Beselo.D waits for incoming SMS messages then sends an MMS message as a reply. This tricks the receiver into thinking that the compromised MMS came from a trusted source. The MMS has a subject of “photo” and a copy of SymbOS/Beselo.D’s SIS installer.

As an additional payload, every few minutes this worm sends a copy of its SIS installer via MMS to random numbers in China. The costs of these MMS messages are charged to the infected phone’s owner.


SymbOS/Beselo.D affects phones running the Symbian S60 platform. Some affected phones include the following: 

Nokia 3650, 3600
Nokia 3660, 3620
Nokia 6600
Nokia 6620
Nokia 7610
Nokia 7650
Nokia N-Gage
Panasonic X700
Sendo X
Siemens SX1
 

Manual Disinfection 

  1. Scan your mobile device using UMU Scan and delete all files detected as SymbOS/Beselo.D.
  2. Reboot your device to kill malware residue processes.
Virus Definitions

List of virus definitions
Report a new virus/spyware