main

First Pocket PC (Windows CE) Virus Discovered

Tom Warren   on 17 July 2004 - 12:58 · 34 comments & 7138 views

Advertisement (Why?)
BitDefender (Romanian AntiVirus company) have discovered the first virus that affects millions of Pocket PCs, smartphones, and other Internet appliances users.

Called WinCE4.Dust, "it infects pocket pc's PE files (ARM) in root (My Device) directory", as the virus author himself noted in a message addressed, probably, to most antivirus laboratories. The virus author, by his nickname Ratter, is part of the famous 29A VX group and created this virus "not meant to spread", just as "a proof of concept code".

In order to run, the virus needs a mobile compatible device running Microsoft Windows CE operating system. The virus displays a message box, asking for user's permission to spread to other files.

Since Microsoft do not offer hotfixes for Pocket PC and only offer Service Packs through OEM channels, how will this effect end users in the next coming months/years?

Screenshot: >> Click here <<
View: Virus Description
News source: In-House


We are pleased to announce the release of Windows Installer v3.0 (MSI3.0) RC2. This is the final beta release for MSI3.0.

Note: The redist package will not install on WinXP/SP2. WinXP/SP2 has native support for MSI3.0.


Download:
The RC2 release is available at http://beta.microsoft.com . Sign in using your Passport account.

Bug Reporting/Feedback:
Use the Bug Reporting tool on http://beta.microsoft.com to submit your bugs to Microsoft. Post your technical support related questions and comments to the Microsoft private newsgroups created for this program.

Newsgroups:
You will need a newsreader program such as Outlook Express to participate in the newsgroups. To access the newsgroups you will need to configure your newsreader program with the account information listed below. If you do not already have a password, you can create a newsgroup password on , under the "Modify Your Info/Modify Newsgroup Login Info". More detailed information about accessing the newsgroups is available on .


All newsgroups for this beta program begin with: microsoft.beta.WindowsInstaller Newsgroup Account Name: Newsgroup Password: News Server: betanews.microsoft.com
*Note: If you forget the newsgroup password you create on Microsoft Beta, you will need to go to Microsoft Beta to create a new one.

If you need assistance, please send e-mail to msibeta@microsoft.com alias.

Thank you for participating in this beta program. We look forward to your valuable feedback.


Windows Installer Group

Post a comment · Send to friend Comments · There are 34 additional comments
(6 replies) #1 Toxikk on 17 Jul 2004 - 12:59
oh noes. thats sucky.
#1.1 scaredmogwai on 17 Jul 2004 - 13:05
yes, but how dumb can you get?

QUOTE
In order to run, the virus needs a mobile compatible device running Microsoft Windows CE operating system. The virus displays a message box, asking for user's permission to spread to other files.
#1.2 creamhackered on 17 Jul 2004 - 13:06
More the point that these have already started and Microsoft doesn't offer hotfixes.
#1.3 Jon on 17 Jul 2004 - 14:12
1) It's proof of concept. That REALLY should be more noticable in this news article.
2) It has actually been called DUTS officially. Virus writers don't get to choose the name.
#1.4 Caelamia on 17 Jul 2004 - 15:05
In reply to #2:

Have you seen the screenshot then? Guess not! It displays the name of the virus and the author in the message box title.
#1.5 Jon on 17 Jul 2004 - 16:08
I'll let you off because I wouldn't expect most normal users to know things like this, but it's a long standing tradition with AV companies that the VXr does *not* get to name the virus, so even if they try, like in this case, the AV companies name it something different.

The official name for the POC code is DUTS.
#1.6 dkldkldkl on 19 Jul 2004 - 14:42
when you're proven wrong you don't have to justify yourself
#2 Trix on 17 Jul 2004 - 13:03
damn that pic made me laugh XD but atleast it isnt a dangerous thing only proof of concept
#3 Jaz on 17 Jul 2004 - 13:26
about time we had polite virri
(1 reply) #4 DoNuTsİ on 17 Jul 2004 - 13:39
Atleast it's asking

#4.1 Hurmoth on 18 Jul 2004 - 19:13
Yup
#5 56kmanV3 on 17 Jul 2004 - 13:41
/ NO Fix avalible.
(1 reply) #6 Colonel_Angus on 17 Jul 2004 - 14:09
Palm OS has the same market share as Windows CE. Are there any Palm OS viruses?
#6.1 MegaManXcalibur on 17 Jul 2004 - 20:42
I believe there has been a total of three malware programs for Palm OS. I think all of them are relativly old and won't run on modern OS 5 devices (and I'm guessing they won't run on OS 4 either but I could be wrong on both accounts).
#7 Tom Servo on 17 Jul 2004 - 14:26
So what now? The description site doesn't even mention any loopholes the virus might use. Is this another virus based on user negligence a.k.a. big red button syndrome?
#8 ghostwind on 17 Jul 2004 - 15:12
I created my own virus.... well sorrta.... my upgrade failed, and my pda has to be re-flashed
#9 StaticX on 17 Jul 2004 - 15:13
whatelse is new
#10 Sn1p3t on 17 Jul 2004 - 15:41
QUOTE

Since Microsoft do not offer hotfixes for Pocket PC and only offer Service Packs through OEM channels, how will this effect end users in the next coming months/years?


There's no information on how you can get this virus. If you have to download it and install it, WHATS THE BIG DEAL? What the hell could Microsoft release a hotfix for? You don't release a patch for every virus that comes out, you release patches for vulnerabilities that exist in the OS. If this article went into a little more description it MIGHT warrent a news posting. Otherwise it's just a program with some malicious code.
(2 replies) #11 nic on 17 Jul 2004 - 15:46
Maybe this will force OEMs to update the PocketPC's that they didn't want to update (like my h1945).

My question is: how does one get this virus? Can it infect my PC and then wait to be activly-synced to my pocketpc. Does it come from just installing software from the virus? Can there be a worm or something, for when my pocket pc is connected to the internet via bluetooth or somthing?
#11.1 markjensen on 17 Jul 2004 - 15:51
I think you would have to ASK the writer for the virus. It was a proof-of-concept, just to show it *can* be done.
#11.2 Synapse` on 17 Jul 2004 - 16:04
Yeah, that was my question.

They're going to have to do something now, they can't let this virus spread on and on...

It's like blaster worm....

If you reformat and go on the internet, you'll most probably get blaster worm...

It's like a virus that never goes away, and will always be there...

But atleast this way, they can stop it by updating...
#12 Sawyer12 on 17 Jul 2004 - 16:39
At the end of the day nearly anything you can write code for you are going to get someone writing malicious code.
#13 altermind on 17 Jul 2004 - 18:03
so how do u catch this vires then
#14 Overlord368 on 17 Jul 2004 - 19:24
well alot of the new pocket pcs have 802.11, bluetooth, and sync docks. hell wouldnt it be possible to pass a virus around just by walking close to someone who has another pocket pc?
(2 replies) #15 chacho on 17 Jul 2004 - 20:03
phones, pocketPC, pc, what's next?
#15.1 saralk on 18 Jul 2004 - 19:31
LG Internet Fridge?
#15.2 smp on 19 Jul 2004 - 00:37
well at least linux will not be next thanks to there being some many *standers* that unless you want to make your virus only run on red hat based distro using rmp.... BLAH BLAH BLAH
#16 c e 3 2 0 on 17 Jul 2004 - 20:13
It's removable using the 4378 DAT and McAfee Virus Scan 6+

What I'd like to know is whether it is suitably written to infect any ARM generation device or if it's API calls are specifally for CE 4.
Any one tried it on PPC2002 / PPC2000 / HPC2000 / HPC Pro?
#17 Tai on 17 Jul 2004 - 20:31
well, this is just great ..... (was only a matter of time i guess anyway though) ...

but with regards to this bit ....."Since Microsoft do not offer hotfixes for Pocket PC and only offer Service Packs through OEM channels, how will this effect end users in the next coming months/years?" ..

... I don't think we, as users, can be that reliant on OEM channels for fixes OR updates for PDA's and the like, especially in the wake of HP & now Dell now apparently refusing to update some of their still current pda models to wm2003SE (after promises to the contrary) .....
(1 reply) #18 MipScript on 17 Jul 2004 - 22:26
There is already over 100 virus's out for PPC as I have an antivirus for my PPC that lists over 100 virus signatures so how can this be the first virus for PPC if there is already antivirus software out with fixes for over 100 Virus's. I wish I knew why people don't do research before they release news. Oh yer I forgot this is the internet ...
#18.1 Jon on 18 Jul 2004 - 10:44
They could hardly sell PPC AV with no sigs now could they? People MIGHT question its worth =)

This is the first PPC specific virus, check out NAI,F-Secure etc's sites. They all confirm this.
#19 c e 3 2 0 on 17 Jul 2004 - 23:04
This is the first PPC2003 virus.
PocketPC isn't the only class of windows ce device out there.
The Handheld PC is the oldest class: http://www.hpcfactor.com/newsgroup/
I think that it is probably the first ce 4 virus too.
#20 Hurmoth on 18 Jul 2004 - 19:14
Such a nice virus! I wish all of 'em were like this!
#21 finalcoolman on 18 Jul 2004 - 19:35
Just get this. It's PC-Cillin for wireless. It looks like it's free: PC-Cillin for Wireless

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)