WinCE.Duts.a is the first virus for devices running under Windows CE .NET.
It can infect devices running the following operating systems: PocketPC 2000, PocketPC 2002, PocketPC 2003.
The virus itself is an ARM processor program and is 1520 bytes in size. When run, the program displays the following message:
"Dear User, am I allowed to spread?"
Infection routine
If confirmation is given, the virus will infect executable files which correspond to the following criteria: ARM processor, more than 4KB in size, located in the device's root directory (My device).
The virus writes itself to the last section of these files and establishes an entry point at the beginning of the file. Infected files will contain the signature 'atar' in an unused PE header.
Other
The body of the virus contains the copyright text string:
WinCE4.Dust by Ratter/29A
Group 29a is well-known for writing proof-of-concept viruses, including the first worm for mobile phones, Worm.SymbOS.Cabir.a
The body of the virus also contains the following text:
This is proof of concept code. Also, i wanted to make avers happy.The situation when Pocket PC antiviruses detect only EICAR file had to end ...
:
This code arose from the dust of Permutation City.
Check out if we have free
removal tool for this virus