SymbOS.Cabir.B - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: November 22, 2004
Updated: February 13, 2007 12:31:31 PM
Type: Worm
Systems Affected: EPOC


Removal using the Symantec Mobile Threats Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of SymbOS.Cabir.B. Use this removal tool first, as it is the easiest way to remove this threat.

Manual Removal:

To remove SymbOS.Cabir.B:
  1. Install a file manager program on the phone.
  2. Enable the option to view the files in the system directory.
  3. Search the drives, A through Y, for the \SYSTEM\APPS\CARIBE directory.
  4. Delete the files CARIBE.APP, CARIBE.RSC, and FLO.MDL from the \CARIBE directory.
  5. Go to the C:\SYSTEM\SYMBIANSECUREDATA\CARIBESECURITYMANAGER directory.
  6. Delete the files CARIBE.APP, CARIBE.RSC, and CARIBE.SIS.
  7. Go to the C:\SYSTEM\RECOGS directory.
  8. Delete the file, FLO.MDL.
  9. Go to the C:\SYSTEM\INSTALLS directory.
  10. Delete the file, CARIBE.SIS.

    Note: You cannot delete the file CARIBE.RSC when the program is running.

    If you cannot delete this file in steps 4 and 6, delete all the files that you can, restart the phone, and then delete the CARIBE.RSC file.


Writeup By: Robert X Wang
Search by name
Example: W32.Beagle.AG@mm
Limited Time Offers! Save up to 50%
Windows Vista Security