This backdoor application monitors the Short Message System (SMS) messages of an affected Symbian phone and forwards the message if the sender is listed in its monitored list. It interprets a specific list of messages as its backdoor commands.
It sends and receives information from a specific phone number. It sends a list of messages to the said number to notify the remote malicious user of the malware's current status.
This spyware may be dropped by other malware.
27 Sep 2010
Steals information, Compromises system security
This spyware may be dropped by the following malware:
This spyware creates the following folders:
This spyware drops the following files wherein it saves the information it gathers:
Based on analysis of the codes, it has the following capabilities:
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Remove malware files dropped/downloaded by SYMBOS_ZBOT.A
Scan your computer with your Trend Micro product to delete files detected as SYMBOS_ZBOT.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Search and delete this folder
Trend Micro Mobile Security Solution
Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.