SymbOS.Commwarrior.A - Removal

Risk Level 1: Very Low

March 7, 2005
February 13, 2007 12:34:51 PM
Also Known As:
Commwarrior.A [F-Secure], SymbOS/Commwarrior.a [McAfee], SYMBOS_COMWAR.A [Trend Micro]
Systems Affected:

Removal using the Symantec Mobile Threats Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of SymbOS.Commwarrior.A. Use this removal tool first, as it is the easiest way to remove this threat.

Manual Removal:

To remove SymbOS.Commwarrior.A:
  1. Install a file manager program on the phone.
  2. Enable the option to view the files in the system directory.
  3. Search the drives, A through Y, for the \system\apps\commwarrior directory.
  4. Delete the files commwarrior.exe and commrec.mdl.
  5. Go to the \system\updates\commwarrior directory.
  6. Delete the files commwarrior.exe, commrec.mdl, and commw.sis.
  7. Go to the \system\recogs directory.
  8. Delete the file commrec.mdl.

Writeup By: Frederic Perriot, Peter Ferrie

