Home Malware Programs Trojans Trojan:SymbOS/OpFake.A

Trojan:SymbOS/OpFake.A

Posted: October 28, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 5
First Seen: October 28, 2011
OS(es) Affected: Windows

Trojan:SymbOS/OpFake.A is a malicious Trojan that poses as an Opera Mini updater using the file names such as 'OperaUpdater.sisx' and 'Update6.1.sisx'. The Trojan:SymbOS/OpFake.A installer adds an Opera icon to the application menu. When executed, it will show a menu and a bogus download progress bar. Trojan:SymbOS/OpFake.A also has a so-called license which can be illustrated. When Trojan:SymbOS/OpFake.A is initiated and before the PC user advances through any of the menus, Trojan:SymbOS/OpFake.A is already sending text messages to Russian premium rate numbers. The numbers and the content of the messages come from an encrypted configuration file named 'sms.xml.' Trojan:SymbOS/OpFake.A tracks whether it has been executed before, and won't do anything except for the first time it is run.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



sms.xml File name: sms.xml
Mime Type: unknown/xml
Group: Malware file
Loading...