Threat Description



Aliases: Trojan:SymbOS/AppDisabler.A
Category: Malware
Type: Trojan
Platform: SymbOS


Trojan:SymbOS/Appdisabler.A is a malicious SIS file dropper, which is dropped by the Skulls.J trojan.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.

Technical Details

Appdisabler.A tries to disable third party file managers and drops two other malwares:

  • Trojan:SymbOS/Locknut.B
  • Bluetooth-Worm:SymbOS/Cabir.Y.

When installed, AppDisabler.A will replace many third-party file managers as well as other third party applications with non-functional application files. It also drops Locknut.B and Cabir.Y onto the system.


When active, Appdisabler.A disables following applications:

  • EFileman
  • FExplorer
  • File
  • SmartFileManager
  • Smartmovie
  • SystemExplorer
  • Yewsprite
  • UltraMP3

The dropped malware Cabir.Y will not start automatically, but will attempt to start at the next boot. However, on most devices Locknut.B will cause application loading to fail. This prevent Cabir.Y from starting.

Appdisabler.A also contains a bootstrap component that attempts to start a component of Skulls.J showing animation of flashing skull. This functionality is also hampered by Locknut.B.


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Keep your mobile device protected

F-Secure Mobile Security will keep your mobile device protected on the go and enable you to find it in case you lose it

Learn More