Home Malware Programs Trojans Trojan:SymbOS/ConBot.A

Trojan:SymbOS/ConBot.A

Posted: November 21, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 75
First Seen: November 21, 2011
Last Seen: August 7, 2023
OS(es) Affected: Windows

Trojan:SymbOS/ConBot.A is a premium rate SMS Trojan that shares a code with Spitmo. Trojan:SymbOS/ConBot.A contains bot characteristics. Trojan:SymbOS/ConBot.A also contains a package named SystemService that contains an embedded package named AppBoot. Trojan:SymbOS/ConBot.A does not add an icon to the applications menu. Once the installation is finished, Trojan:SymbOS/ConBot.A does not report the PC user of its occurrence. Trojan:SymbOS/ConBot.A is self-signed with a certificate by "JoeBloggs" from "Acme". AppBoot.exe is automatically executed every time the phone starts because of the [2005A60D].rsc file. AppBoot.exe then decrypts the SystemService.boot file. AppBoot.exe runs whatever files the decrypted .boot files point to. Delete Trojan:SymbOS/ConBot.A as soon as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\System\AppBoot\SystemService.boot File name: c:\System\AppBoot\SystemService.boot
Mime Type: unknown/boot
Group: Malware file
c:\sys\bin\AppBoot.exe File name: c:\sys\bin\AppBoot.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\private\101f875a\import\[2005A60D].rsc File name: c:\private\101f875a\import\[2005A60D].rsc
Mime Type: unknown/rsc
Group: Malware file
c:\Private\EE1DCDAA\first File name: c:\Private\EE1DCDAA\first
Group: Malware file
c:\Private\EE1DCDAA\start.xml File name: c:\Private\EE1DCDAA\start.xml
Mime Type: unknown/xml
Group: Malware file
c:\sys\bin\SystemService.exe File name: c:\sys\bin\SystemService.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...