Home / malwarePDF  

AppDisabler.A


First posted on 07 September 2007.
Source: SecurityHome

Aliases :

AppDisabler.A is also known as Trojan:SymbOS/AppDisabler.A, SymbOS/AppDisabler.A.

Explanation :

Appdisabler.A is a malicious SIS file dropper, which is dropped by the Skulls.J trojan.

Appdisabler.A tries to disable third party file managers and drops
Trojan:SymbOS/Locknut.B and Bluetooth-Worm:SymbOS/Cabir.Y.

Installation to the System

When installed, AppDisabler.A will replace many third-party file managers as well as other third party applications with non-functional application files. It also drops Locknut.B and Cabir.Y onto the system.

Cabir.Y will not start automatically, but it will attempt to start at the next boot. However, on most devices Locknut.B will cause application loading to fail. This prevent Cabir.Y from starting.

Appdisabler.A also contains a bootstrap component that attempts to start a component of Skulls.J showing animation of flashing skull. But this functionality is also hampered by Locknut.B.

Payload

Disables following applications:

Last update 07 September 2007

 

TOP

Malware :

Family: