Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.21649

Добавлен в вирусную базу Dr.Web: 2017-05-18

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.HiddenAds.76.origin
  • Android.HiddenAds.67.origin
Сетевая активность:
Подключается к:
  • trac####.####.com
  • set####.####.com
  • r####.####.com
  • lo####.####.net
  • s####.####.com
  • so####.####.com
  • u####.####.com
  • i####.####.com
  • pl####.####.com
  • real####.####.org
  • p####.####.com
  • ma####.####.com
  • gl####.####.com
  • a####.####.org
  • o####.####.com
  • a####.####.net
  • up####.####.com
  • api####.####.com
  • cdn####.####.com
  • a####.####.com
  • pass####.####.com
  • t####.####.com
  • t####.####.info
  • se####.####.com
  • d####.####.com
  • mobotoo####.####.com
  • con####.####.com
  • n####.####.com
Запросы HTTP GET:
  • ma####.####.com/frontend/cardList.htm?isrecmd=####&ran=####&ismsg=####&i...
  • n####.####.com/mu3/game/20170315/10/1489545890968/icon/icon_o.png
  • i####.####.com/sound_on.png
  • i####.####.com/sound_off.png
  • s####.####.com/ads-service/ads/service/getAdlist.do?adnum=####&adid=####...
  • n####.####.com/mu3/game/20161112/00/1478882027637/icon/icon_o.png
  • real####.####.org/realtime?platform=####&os_version=####&package_name=##...
  • r####.####.com/nad?v1=####&model=####&dx=####&dy=####&accept=####&slot_c...
  • t####.####.com/agentapi/click?cid=####&aid=####&mb_mac=####&mb_devid=###...
  • up####.####.com/mu3/app/20170415/09/1492218060239/icon/icon_o.png
  • a####.####.net/api/v2/template/get?slot_id=####&update_time=####
  • p####.####.com/notification/android/message.json?pname=####&version=####...
  • i####.####.com/91f0cd69a777e3a265585241b3c9348b31c5d658_768x1024_opt_v1....
  • i####.####.com/1380229154.js
  • n####.####.com/mu3/game/20160929/18/1475144052975/icon/icon_o.png
  • pass####.####.com/android/v2/getDoSignInfo.htm?uid=####&versionCode=####...
  • d####.####.com/M01/01/AA/CvJMDVkcNv6AXk2-AAP-y3A0ROc859.zip
  • t####.####.com/ttc?h=####&p=####&q=####
  • n####.####.com/mu3/app/20170212/04/1486844423329/icon/icon_o.png
  • trac####.####.com/click?mb_pl=####&mb_nt=####&mb_campid=####&aff_sub=###...
  • mobotoo####.####.com/mobotoolpush/addispsort.json?facebook=####&language...
  • n####.####.com/mu/homepage/quick/card/1488782443673/50_50.jpg
  • d####.####.com/onlyImpression?k=####&p=####
  • cdn####.####.com/cdn-adn/offersync/17/03/13/16/11/58c6543ca78b3.png
  • a####.####.org/rule?platform=####&os_version=####&package_name=####&app_...
  • n####.####.com/mu/2017/4/5/playpicture/0553e6de36454a97a4ba4d98e898abe6....
  • n####.####.com/mu/2016/11/16/1112349/icon/icon_o.png
  • gl####.####.com/trace?offer_id=####&app_id=####&type=####&aff_sub=####&a...
  • n####.####.com/mu/2017/1/20/playpicture/cbff381ba1e844d09badd66117a36dc8...
  • i####.####.com/jquery-1.9.1.min.js
  • r####.####.com/2.0/ad?v1=####&model=####&dx=####&dy=####&accept=####&v2=...
  • o####.####.com/ipo/api/gray/status?appvc=####&os=####&appvn=####&avn=###...
  • set####.####.com/setting?app_id=####&sign=####&platform=####&os_version=...
  • mobotoo####.####.com/mobotoolpush/textoperation.json?version_name=####&n...
  • n####.####.com/mu/2017/4/26/playpicture/cd2ddc5b79c149dfb4e6690063547575...
  • n####.####.com/mu3/app/20150908/16/1441709283401/icon/icon_o.png
  • n####.####.com/mu/mobotoolpush_admin/icon/1493377391/clash
  • i####.####.com/8ffdf24f25a2bbf38d2cfc0027487b58b995bf22_570x320_opt_v1.mp4
  • mobotoo####.####.com/mobotoolpush/whitelist.json?tag=####&language=####&...
  • i####.####.com/jquery.knob.js
  • a####.####.net/api/v2/cache/get?dml=####&dt=####&nt=####&mcc=####&bast=#...
  • u####.####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&prod...
  • n####.####.com/mu/2017/1/23/playpicture/0018a76f59e54fcd82110288889b6d50...
  • n####.####.com/mu3/game/20170406/04/1491423524694/icon/icon_o.png
  • cdn####.####.com/cdn-adn/html/common/2016/02/22/22/03/com.qihoo.security...
  • n####.####.com/mu/2017/3/16/playpicture/cd9e44a45efd49b5bf84ed65e13b2363...
  • mobotoo####.####.com/mobotoolpush/notibarpush.json?version_name=####&adi...
  • up####.####.com/mu3/game/20170420/23/1492702658031/icon/icon_o.png
  • r####.####.com/2.0/ad?v1=####&model=####&etf=####&dx=####&dy=####&accept...
  • n####.####.com/mu/2017/4/5/playpicture/7634fdc80fc84dce8debfc02055abd20....
  • set####.####.com/setting?unit_ids=####&app_id=####&sign=####&platform=##...
  • mobotoo####.####.com/mobotoolpush/downloadsilent.json?version_name=####&...
  • n####.####.com/mu3/game/20170310/16/1489134680401/icon/icon_o.png
  • n####.####.com/mu/homepage/quick/card/1488782692558/50_50.jpg
  • d####.####.com/impression?k=####&p=####&q=####&x=####
  • up####.####.com/mu3/game/20161112/00/1478882027637/icon/icon_o.png
  • a####.####.com/strategy/api/v1/rule/get?p=####&hp=####&l=####&c=####&pro...
  • n####.####.com/mu3/game/20170225/09/1487986575517/icon/icon_o.png
  • n####.####.com/openapi/ad/v3?app_id=####&unit_id=####&category=####&req_...
  • mobotoo####.####.com/mobotoolpush/deskiconpush.json?version_name=####&ad...
  • n####.####.com/openapi/ad/v3?app_id=####&unit_id=####&req_type=####&sign...
  • a####.####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=####&sd...
  • t####.####.info/click?_type=####&sdk_redir=####&campid=####&sub_channel=...
Запросы HTTP POST:
  • ma####.####.com/frontend/allmixhotword.htm
  • so####.####.com/moboapi/switch.htm
  • pass####.####.com/android/v2/getUserInfo.htm
  • ma####.####.com/android/requestForUpdate.htm
  • ma####.####.com/json/map
  • a####.####.com/detail/getOfferListNew?enc=####
  • so####.####.com/social/getPraiseNum.htm
  • lo####.####.net/debug/v2/android
  • s####.####.com/ads-service/ads/service/getListAd.do
  • con####.####.com/log/log_apps
  • r####.####.com/pix?event=####&ts=####&platform=####&model=####&package_n...
  • ma####.####.com/frontend/adentry.htm
  • se####.####.com/getList.htm
  • ma####.####.com/frontend/playhotword.htm
  • api####.####.com/v3/log/init
  • r####.####.com/device?api_key=####
  • ma####.####.com/json/list
  • se####.####.com/moboapi/switch.htm
  • ma####.####.com/json/multimap
  • se####.####.com/getUpMessage.htm
  • s####.####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
  • se####.####.com/getWeather.htm
  • s####.####.com/ads-service/ads/service/referUpload.do
  • pl####.####.com/ad_dex.php
  • ma####.####.com/android/upgradeAppInfo.htm
  • se####.####.com/initRequestDomain.htm
  • a####.####.com/detail/getPrStrategy?product=####&adid=####&appVer=####&d...
  • ma####.####.com/android/checkIn.htm
  • p####.####.com/getShowWindow.htm
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/cache/picasso-cache/a5ba553928c8194a8f15520824c19664.1.tmp
  • <Package Folder>/databases/mobogenie_music.db
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C02A3-0001-085A-E2DADA2635EBSessionOS.cls_temp
  • <Package Folder>/cache/picasso-cache/3c769b58b4054b10006b53e7709f405f.0.tmp
  • <Package Folder>/cache/picasso-cache/09ac570d10a28c0c08ecee080ceb90a7.1.tmp
  • <Package Folder>/cache/picasso-cache/2cda05553e7e09ccc36bef2c0710a3ca.0.tmp
  • <Package Folder>/shared_prefs/install.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9D035A-0001-08CF-E2DADA2635EBSessionOS.cls_temp
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android;answers/session_analytics.tap.tmp
  • <Package Folder>/shared_prefs/dcSharedPreferences.dat.xml
  • <Package Folder>/cache/picasso-cache/71bd5e215c19e55403412e9d82bf69e0.0.tmp
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C035E-0001-0877-E2DADA2635EBSessionOS.cls_temp
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml.bak
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/files/DaemonServer
  • <Package Folder>/shared_prefs/SSPPrefe.xml
  • <Package Folder>/cache/picasso-cache/09ac570d10a28c0c08ecee080ceb90a7.0.tmp
  • <Package Folder>/cache/picasso-cache/b79611a441a1fb4bcd80a8b29978f372.1.tmp
  • <Package Folder>/shared_prefs/AGOO_BIND.xml
  • <Package Folder>/databases/mobogenie.db-journal
  • <Package Folder>/cache/picasso-cache/bfee08dfb0218bd98a89d477a684bc45.1.tmp
  • <Package Folder>/shared_prefs/Agoo_AppStore.xml
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C035E-0001-0877-E2DADA2635EBSessionDevice.cls_temp
  • <Package Folder>/cache/picasso-cache/0c9de3e36fa1fc6b90d838e49384676d.1.tmp
  • <Package Folder>/shared_prefs/self_adextend.xml
  • <Package Folder>/files/.Fabric/io.fabric.sdk.android;fabric/com.crashlytics.settings.json
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/initialization_marker
  • <Package Folder>/databases/mobogenie_update.db
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C02A3-0001-085A-E2DADA2635EBBeginSession.cls_temp
  • <Package Folder>/cache/picasso-cache/b684a1df8e6e9cf3ecfd65d14240b55a.1
  • <Package Folder>/cache/picasso-cache/b684a1df8e6e9cf3ecfd65d14240b55a.0
  • <Package Folder>/databases/mobogenie.db
  • <Package Folder>/cache/picasso-cache/71bd5e215c19e55403412e9d82bf69e0.1.tmp
  • <Package Folder>/databases/mobvista.msdk.db-journal
  • <Package Folder>/databases/accs.db-journal
  • <Package Folder>/shared_prefs/TwitterAdvertisingInfoPreferences.xml
  • <Package Folder>/cache/picasso-cache/82257c0a1e3eadfd884dcbc37bd79c82.0.tmp
  • <Package Folder>/shared_prefs/SCORE_PRE.xml
  • <Package Folder>/databases/message_accs_db-journal
  • <Package Folder>/databases/cc.db
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml.bak
  • <Package Folder>/cache/picasso-cache/9f10a940fc0ca7fa2574ff739d41882d.0.tmp
  • <Package Folder>/cache/picasso-cache/a5ba553928c8194a8f15520824c19664.0.tmp
  • <Package Folder>/databases/trackreferrer.db-journal
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/com.crashlytics.prefs.xml
  • <Package Folder>/shared_prefs/com.crashlytics.sdk.android;answers;settings.xml
  • <Package Folder>/cache/picasso-cache/0548391082cfd49909b29fe2d1b80226.1.tmp
  • <Package Folder>/cache/picasso-cache/4fe59794cc4b77066171331c97829983.0
  • <Package Folder>/cache/picasso-cache/4fe59794cc4b77066171331c97829983.1
  • <Package Folder>/files/google.db
  • <Package Folder>/cache/picasso-cache/0a9c328cb689b5891bed292058707b01.1.tmp
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml
  • <Package Folder>/shared_prefs/mobvista.xml
  • <Package Folder>/cache/picasso-cache/2059e716def740632c3fc5a2fb76d9fc.0.tmp
  • <Package Folder>/cache/picasso-cache/eaff1385719d6a36d89413c760d51987.0.tmp
  • <Package Folder>/.mbj/dex/classes.zip
  • <Package Folder>/cache/picasso-cache/bfee08dfb0218bd98a89d477a684bc45.0.tmp
  • <Package Folder>/cache/picasso-cache/48c6318a5a067fb9b7234f8e4074eb41.0.tmp
  • <Package Folder>/shared_prefs/ACCS_SDK_CHANNEL.xml
  • <Package Folder>/cache/picasso-cache/a9412cf8e19ce1d974da7adbc0e8b6d1.1
  • <Package Folder>/cache/picasso-cache/a9412cf8e19ce1d974da7adbc0e8b6d1.0
  • <Package Folder>/eudemon
  • <Package Folder>/cache/picasso-cache/a22cc786c79c4467ada02f7c4573814e.1.tmp
  • <Package Folder>/shared_prefs/FLOAT_WINDOW.xml
  • <Package Folder>/cache/picasso-cache/0c9de3e36fa1fc6b90d838e49384676d.0.tmp
  • <Package Folder>/cache/webviewCacheChromium/index
  • <Package Folder>/cache/picasso-cache/9420055e6b8ba1a3065a3f70f57b44bb.0.tmp
  • <Package Folder>/cache/picasso-cache/2f0d01236fb7e50ab8cdd0e1ea1dd95f.0.tmp
  • <Package Folder>/cache/picasso-cache/2059e716def740632c3fc5a2fb76d9fc.1.tmp
  • <Package Folder>/shared_prefs/share_date.xml
  • <Package Folder>/cache/picasso-cache/fe5c93839b1d1122297543ab980f0ecd.1.tmp
  • <Package Folder>/files/rk.jar
  • <Package Folder>/databases/arrkii.asa.sdk.db-journal
  • <Package Folder>/cache/picasso-cache/b79611a441a1fb4bcd80a8b29978f372.0.tmp
  • <Package Folder>/cache/picasso-cache/48c6318a5a067fb9b7234f8e4074eb41.1.tmp
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml.bak
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android;answers/session_analytics.tap
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C035E-0001-0877-E2DADA2635EBBeginSession.cls_temp
  • <Package Folder>/cache/picasso-cache/5a8b75c54c36d194cb24f283b724389d.1.tmp
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/files/watch_server
  • <Package Folder>/cache/picasso-cache/637bcf779e8a476965fb4296552b99c7.0.tmp
  • <Package Folder>/cache/picasso-cache/0a9c328cb689b5891bed292058707b01.0.tmp
  • <Package Folder>/files/uninstall
  • <Package Folder>/databases/download_file.db-journal
  • <Package Folder>/cache/picasso-cache/5aced3429b4f38cef4f8dc1dd54239fb.0.tmp
  • <Package Folder>/cache/picasso-cache/637bcf779e8a476965fb4296552b99c7.1.tmp
  • <Package Folder>/cache/picasso-cache/5a8b75c54c36d194cb24f283b724389d.0.tmp
  • <Package Folder>/shared_prefs/com.facebook.internal.preferences.APP_SETTINGS.xml
  • <Package Folder>/cache/picasso-cache/82257c0a1e3eadfd884dcbc37bd79c82.1.tmp
  • <Package Folder>/databases/MessageStore.db-journal
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml.bak
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml.bak
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml
  • <Package Folder>/cache/picasso-cache/06412384bd500638162d0ba15dc9f81a.0.tmp
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C02A3-0001-085A-E2DADA2635EBSessionApp.cls_temp
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <Package Folder>/cache/picasso-cache/5285044de8e4db72b86e7246f9aee7c2.0.tmp
  • <Package Folder>/files/agoo.pid
  • <Package Folder>/shared_prefs/PUSH_PRE.xml
  • <Package Folder>/cache/picasso-cache/06412384bd500638162d0ba15dc9f81a.1.tmp
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9D035A-0001-08CF-E2DADA2635EBBeginSession.cls_temp
  • <Package Folder>/cache/picasso-cache/0c74b481dab2fc95d00cbb1209fb27b5.0.tmp
  • <Package Folder>/cache/picasso-cache/43aadefe45661e86665877a1790d7f62.0.tmp
  • <Package Folder>/cache/picasso-cache/2f0d01236fb7e50ab8cdd0e1ea1dd95f.1.tmp
  • <Package Folder>/shared_prefs/PUSH_PRE.xml.bak
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9D035A-0001-08CF-E2DADA2635EBSessionDevice.cls_temp
  • <Package Folder>/databases/self_ad_db-journal
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9C035E-0001-0877-E2DADA2635EBSessionApp.cls_temp
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/databases/self_ad_db
  • <Package Folder>/cache/picasso-cache/9420055e6b8ba1a3065a3f70f57b44bb.1.tmp
  • <Package Folder>/shared_prefs/ct_default.xml
  • <Package Folder>/shared_prefs/<Package>_ui_preferences.xml
  • <Package Folder>/cache/picasso-cache/a64e4940b33d43d5a587d9716add3915.1
  • <Package Folder>/cache/picasso-cache/a64e4940b33d43d5a587d9716add3915.0
  • <Package Folder>/cache/picasso-cache/a22cc786c79c4467ada02f7c4573814e.0.tmp
  • <Package Folder>/cache/picasso-cache/9f10a940fc0ca7fa2574ff739d41882d.1.tmp
  • <Package Folder>/shared_prefs/last_know_location.xml
  • <Package Folder>/databases/ztrack.db-journal
  • <Package Folder>/shared_prefs/USERINFO.xml
  • <Package Folder>/shared_prefs/postTime.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml.bak
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/cache/picasso-cache/3c769b58b4054b10006b53e7709f405f.1
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/TOKEN.xml
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml
  • <Package Folder>/cache/picasso-cache/5aced3429b4f38cef4f8dc1dd54239fb.1.tmp
  • <Package Folder>/cache/picasso-cache/0548391082cfd49909b29fe2d1b80226.0.tmp
  • <Package Folder>/cache/picasso-cache/eaff1385719d6a36d89413c760d51987.1.tmp
  • <Package Folder>/shared_prefs/SETTING_PRE.xml.bak
  • <Package Folder>/code_cache/secondary-dexes/<Package>-1.apk.classes-1542642610.zip
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/cache/picasso-cache/5285044de8e4db72b86e7246f9aee7c2.1.tmp
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml
  • <Package Folder>/databases/message_accs_db
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml
  • <Package Folder>/shared_prefs/ACCS_BIND.xml
  • <Package Folder>/cache/picasso-cache/70594694b795809267b00a383e3a0e3e.0.tmp
  • <Package Folder>/shared_prefs/clean.xml
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/mobogenie_update.db-journal
  • <Package Folder>/shared_prefs/SSPPrefe.xml.bak
  • <Package Folder>/shared_prefs/SETTING_PRE.xml
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/cache/picasso-cache/43aadefe45661e86665877a1790d7f62.1.tmp
  • <Package Folder>/databases/trackreferrer.db
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android;answers/session_analytics_to_send/sa_7d860a84-8a0b-4927-8cf6-ff4951074561_1495006110058.tap
  • <Package Folder>/files/mobclick_agent_cached_<Package>302121
  • <Package Folder>/shared_prefs/FirstNewUninstallTime.xml
  • <Package Folder>/shared_prefs/ACCS_SDK.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/cache/picasso-cache/d149467676fd959a5a11be2498d059cc.1
  • <Package Folder>/cache/picasso-cache/d149467676fd959a5a11be2498d059cc.0
  • <Package Folder>/databases/mobogenie_music.db-journal
  • <Package Folder>/shared_prefs/apsad.xml.bak
  • <Package Folder>/shared_prefs/strategy_sp.xml
  • <Package Folder>/cache/picasso-cache/0c74b481dab2fc95d00cbb1209fb27b5.1
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/cache/picasso-cache/2cda05553e7e09ccc36bef2c0710a3ca.1
  • <Package Folder>/databases/webviewCookiesChromiumPrivate.db-journal
  • <Package Folder>/cache/webviewCacheChromium/data_2
  • <Package Folder>/cache/picasso-cache/fe5c93839b1d1122297543ab980f0ecd.0.tmp
  • <Package Folder>/files/cwd
  • <Package Folder>/cache/picasso-cache/70594694b795809267b00a383e3a0e3e.1.tmp
  • <Package Folder>/cache/picasso-cache/journal.tmp
  • <Package Folder>/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/591BFB9D035A-0001-08CF-E2DADA2635EBSessionApp.cls_temp
  • <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.q.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/cache/webviewCacheChromium/data_3
  • <Package Folder>/databases/MsgLogStore.db-journal
  • <Package Folder>/cache/webviewCacheChromium/data_1
  • <Package Folder>/cache/webviewCacheChromium/data_0
Другие:
Запускает следующие shell-скрипты:
  • chmod 755 /data/data/####/files/watch_server
  • chmod 755 /data/user/0/<Package>/files/watch_server
  • /data/data/####/files/cwd 0
  • sh <Package Folder>/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1029&uuid=bbddbcc0-5f12-44b1-86ad-c7f08ee9e0f8&android=81399a04b6199337&imei=<IMEI>&versionCode=302121&versionName=3.2.12.1&site=GL
  • <dexopt>
  • cat /proc/cpuinfo
  • chmod 755 /data/user/0/####/files/watch_server
  • sh <Package Folder>/files/cwd 0
  • sh <Package Folder>/files/watch_server <Package Folder> http://redirect.mobogenie.com?pn=<Package>&v=302121&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • sh
  • /data/data/####/files/watch_server /data/data/#### http://redirect.mobogenie.com?pn=####&v=302121&an=####&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • chmod 755 <Package Folder>/files/watch_server
  • /data/data/####/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1029&uuid=bbddbcc0-5f12-44b1-86ad-c7f08ee9e0f8&android=81399a04b6199337&imei=####&versionCode=302121&versionName=3.2.12.1&site=GL
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.
  • /data/user/0/####/files/watch_server /data/user/0/#### http://redirect.mobogenie.com?pn=####&v=302121&an=####&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • chmod 500 <Package Folder>/files/DaemonServer
Может автоматически отправлять СМС-сообщения.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке