Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.23791

Добавлен в вирусную базу Dr.Web: 2017-06-26

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.HiddenAds.125.origin
Загружает из Интернета следующие детектируемые угрозы:
  • Android.HiddenAds.125.origin
Перекрывает экран собственным окном, блокируя доступ к графическому интерфейсу.
Сетевая активность:
Подключается к:
  • 5####.####.141
  • a####.####.com
  • a####.####.net
  • a####.####.org
  • admobim####.com
  • api####.####.com
  • bestpho####.mobi
  • c####.####.com
  • cdn####.####.com
  • cleando####.com
  • con####.####.com
  • d####.####.com
  • gl####.####.com
  • i####.####.com
  • ma####.####.com
  • mmmmmm####.com
  • mobotoo####.####.com
  • n####.####.com
  • o####.####.com
  • p####.####.com
  • pass####.####.com
  • pl####.####.com
  • r####.####.com
  • real####.####.org
  • s####.####.com
  • sc####.####.com
  • se####.####.com
  • set####.####.com
  • t####.####.com
  • trac####.####.com
  • u####.####.com
  • up####.####.com
Запросы HTTP GET:
  • 5####.####.141/ttc?h=####&p=####&q=####
  • a####.####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=####&sd...
  • a####.####.com/mpapi/ad?model=####&fomat=####&mcc=####&os_v=####&directi...
  • a####.####.net/api/v2/template/get?slot_id=####&update_time=####
  • a####.####.org/rule?platform=####&os_version=####&package_name=####&app_...
  • bestpho####.mobi/?sl=####&data3=####
  • c####.####.com/click?transaction_id=####&aff_sub=####&aff_sub2=####&aff_...
  • cdn####.####.com/cdn-adn/html/common/2016/02/22/22/03/com.qihoo.security...
  • cleando####.com/
  • d####.####.com/M00/01/AB/CvJMDVlBJNyAE3AUAAVgxYzjtNE875.zip
  • gl####.####.com/trace?offer_id=####&app_id=####&type=####&aff_sub=####&a...
  • i####.####.com/1380229154.js
  • ma####.####.com/frontend/cardList.htm?isrecmd=####&ran=####&ismsg=####&i...
  • mobotoo####.####.com/mobotoolpush/textoperation.json?version_name=####&n...
  • n####.####.com/impression?k=####&p=####&q=####&x=####
  • n####.####.com/mu/2017/5/24/playpicture/2f8d354c72e2407096b874fe736bc320...
  • o####.####.com/ipo/api/gray/status?appvc=####&os=####&appvn=####&avn=###...
  • p####.####.com/ads-service/ads/service/getAdlist.do?adnum=####&adid=####...
  • p####.####.com/notification/android/message.json?pname=####&version=####...
  • pass####.####.com/android/v2/getDoSignInfo.htm?uid=####&versionCode=####...
  • r####.####.com/2.0/ad?v1=####&model=####&etf=####&dx=####&dy=####&accept...
  • r####.####.com/o903c61a/e49f325a0ff6347a4820c77a06c211bbbc99419a_raw11.gif
  • real####.####.org/realtime?platform=####&os_version=####&package_name=##...
  • sc####.####.com/v1/scheme/placement?model=####&mcc=####&os_v=####&direct...
  • set####.####.com/appwall/setting?app_id=####&sign=####&platform=####&os_...
  • t####.####.com/agentapi/click?cid=####&aid=####&mb_mac=####&mb_devid=###...
  • t####.####.com/click?_type=####&sdk_redir=####&campid=####&sub_channel=#...
  • trac####.####.com/aff_c?offer_id=####&aff_id=####&aff_sub=####&aff_sub2=...
  • trac####.####.com/click?mb_pl=####&mb_nt=####&mb_campid=####&mb_package=...
  • u####.####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&prod...
Запросы HTTP POST:
  • a####.####.com/amdc/mobileDispatch?appkey=####&platform=####&v=####&devi...
  • a####.####.com/detail/getOfferListNew?enc=####
  • admobim####.com/surl/api2_reg.action
  • api####.####.com/v3/log/init
  • con####.####.com/log/log_apps
  • ma####.####.com/android/requestForUpdate.htm
  • mmmmmm####.com/osp/oaen_reg.action
  • p####.####.com/getUpMessage.htm
  • pl####.####.com/ad_dex.php
  • s####.####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
  • se####.####.com/initRequestDomain.htm
  • se####.####.com/social/getPraiseNum.htm
  • up####.####.com/upload?orientation=####&platform=####&model=####&userage...
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.mbj/####/classes.zip
  • <Package Folder>/cache/####/0548391082cfd49909b29fe2d1b80226.0.tmp
  • <Package Folder>/cache/####/0548391082cfd49909b29fe2d1b80226.1.tmp
  • <Package Folder>/cache/####/06412384bd500638162d0ba15dc9f81a.0.tmp
  • <Package Folder>/cache/####/06412384bd500638162d0ba15dc9f81a.1.tmp
  • <Package Folder>/cache/####/077f14bdeec8756e1bff0ea5f00ce023.0.tmp
  • <Package Folder>/cache/####/077f14bdeec8756e1bff0ea5f00ce023.1
  • <Package Folder>/cache/####/10d0f4fe07dbedb0d0b344981a7a89a4.0.tmp
  • <Package Folder>/cache/####/10d0f4fe07dbedb0d0b344981a7a89a4.1.tmp
  • <Package Folder>/cache/####/1e51124889785cfd62378f2d029f38be.0.tmp
  • <Package Folder>/cache/####/1e51124889785cfd62378f2d029f38be.1.tmp
  • <Package Folder>/cache/####/404d99382f27a8b38fef0bf97fbeff66.0
  • <Package Folder>/cache/####/404d99382f27a8b38fef0bf97fbeff66.1
  • <Package Folder>/cache/####/43aadefe45661e86665877a1790d7f62.0.tmp
  • <Package Folder>/cache/####/43aadefe45661e86665877a1790d7f62.1.tmp
  • <Package Folder>/cache/####/48e1122edf638c3c50176a003a2d362d.0.tmp
  • <Package Folder>/cache/####/48e1122edf638c3c50176a003a2d362d.1.tmp
  • <Package Folder>/cache/####/6fc9aa4690e84efaf508d08270ff6b90.0.tmp
  • <Package Folder>/cache/####/6fc9aa4690e84efaf508d08270ff6b90.1.tmp
  • <Package Folder>/cache/####/70594694b795809267b00a383e3a0e3e.0.tmp
  • <Package Folder>/cache/####/70594694b795809267b00a383e3a0e3e.1.tmp
  • <Package Folder>/cache/####/98666326e90145de4488db5f3a06ff58.0
  • <Package Folder>/cache/####/98666326e90145de4488db5f3a06ff58.1
  • <Package Folder>/cache/####/a037d3b20df5ce42671791090fa65063.0.tmp
  • <Package Folder>/cache/####/a037d3b20df5ce42671791090fa65063.1.tmp
  • <Package Folder>/cache/####/c52ddf0c35b52594fc99cad6a0e46eca.0.tmp
  • <Package Folder>/cache/####/c52ddf0c35b52594fc99cad6a0e46eca.1
  • <Package Folder>/cache/####/cf443a23cd9ec5376623b09348edc247.0.tmp
  • <Package Folder>/cache/####/cf443a23cd9ec5376623b09348edc247.1.tmp
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_0 (deleted)
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_1 (deleted)
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_2 (deleted)
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/data_3 (deleted)
  • <Package Folder>/cache/####/ebb2c23211b941e8ceedd839e65b3398.0
  • <Package Folder>/cache/####/ebb2c23211b941e8ceedd839e65b3398.1
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/fe5c93839b1d1122297543ab980f0ecd.0.tmp
  • <Package Folder>/cache/####/fe5c93839b1d1122297543ab980f0ecd.1.tmp
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/index (deleted)
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes-1156726991.zip
  • <Package Folder>/databases/MessageStore.db-journal
  • <Package Folder>/databases/MsgLogStore.db-journal
  • <Package Folder>/databases/accs.db-journal
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/arrkii.asa.sdk.db-journal
  • <Package Folder>/databases/cc.db
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/databases/download_file.db-journal
  • <Package Folder>/databases/evernote_jobs.db-journal
  • <Package Folder>/databases/message_accs_db
  • <Package Folder>/databases/message_accs_db-journal
  • <Package Folder>/databases/mobogenie.db
  • <Package Folder>/databases/mobogenie.db-journal
  • <Package Folder>/databases/mobogenie_music.db
  • <Package Folder>/databases/mobogenie_music.db-journal
  • <Package Folder>/databases/mobogenie_update.db
  • <Package Folder>/databases/mobogenie_update.db-journal
  • <Package Folder>/databases/mobpower.db-journal
  • <Package Folder>/databases/mobvista.msdk.db-journal
  • <Package Folder>/databases/my.db-journal
  • <Package Folder>/databases/self_ad_db
  • <Package Folder>/databases/self_ad_db-journal
  • <Package Folder>/databases/trackreferrer.db
  • <Package Folder>/databases/trackreferrer.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
  • <Package Folder>/databases/webviewCookiesChromiumPrivate.db-journal
  • <Package Folder>/databases/webviewCookiesChromiumPrivate.db-journal (deleted)
  • <Package Folder>/databases/ztrack.db-journal
  • <Package Folder>/eudemon
  • <Package Folder>/files/####/592E793701C1-0001-0835-22F5F914F77EBeginSession.cls_temp
  • <Package Folder>/files/####/592E793701C1-0001-0835-22F5F914F77ESessionApp.cls_temp
  • <Package Folder>/files/####/592E793701C1-0001-0835-22F5F914F77ESessionDevice.cls_temp
  • <Package Folder>/files/####/592E793701C1-0001-0835-22F5F914F77ESessionOS.cls_temp
  • <Package Folder>/files/####/592E793701C1-0001-0835-22F5F914F77ESessionUser.cls_temp
  • <Package Folder>/files/####/592E7937020A-0001-0851-22F5F914F77EBeginSession.cls_temp
  • <Package Folder>/files/####/592E7937020A-0001-0851-22F5F914F77ESessionApp.cls_temp
  • <Package Folder>/files/####/592E7937020A-0001-0851-22F5F914F77ESessionDevice.cls_temp
  • <Package Folder>/files/####/592E7937020A-0001-0851-22F5F914F77ESessionOS.cls_temp
  • <Package Folder>/files/####/com.crashlytics.settings.json
  • <Package Folder>/files/####/initialization_marker
  • <Package Folder>/files/####/mp_agent_log
  • <Package Folder>/files/####/sa_8df3b8e7-21c6-4925-9769-1e14a0849697_1496217911945.tap
  • <Package Folder>/files/####/session_analytics.tap
  • <Package Folder>/files/####/session_analytics.tap.tmp
  • <Package Folder>/files/DaemonServer
  • <Package Folder>/files/agoo.pid
  • <Package Folder>/files/cwd
  • <Package Folder>/files/google.db
  • <Package Folder>/files/mobclick_agent_cached_<Package>302151
  • <Package Folder>/files/rk.jar
  • <Package Folder>/files/uninstall
  • <Package Folder>/files/watch_server
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml.bak
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/<Package>_ui_preferences.xml
  • <Package Folder>/shared_prefs/ACCS_BIND.xml
  • <Package Folder>/shared_prefs/ACCS_SDK.xml
  • <Package Folder>/shared_prefs/ACCS_SDK_CHANNEL.xml
  • <Package Folder>/shared_prefs/AGOO_BIND.xml
  • <Package Folder>/shared_prefs/ActivatePreUtil.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/Agoo_AppStore.xml
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/FLOAT_WINDOW.xml
  • <Package Folder>/shared_prefs/FirstNewUninstallTime.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml.bak
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml (deleted)
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml.bak
  • <Package Folder>/shared_prefs/PUSH_PRE.xml
  • <Package Folder>/shared_prefs/PUSH_PRE.xml.bak
  • <Package Folder>/shared_prefs/SCORE_PRE.xml
  • <Package Folder>/shared_prefs/SCORE_PRE.xml.bak
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml.bak
  • <Package Folder>/shared_prefs/SETTING_PRE.xml
  • <Package Folder>/shared_prefs/SETTING_PRE.xml.bak
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml.bak
  • <Package Folder>/shared_prefs/TOKEN.xml
  • <Package Folder>/shared_prefs/TwitterAdvertisingInfoPreferences.xml
  • <Package Folder>/shared_prefs/USERINFO.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml.bak
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/shared_prefs/apsad.xml.bak
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/shared_prefs/arrkiiad.xml
  • <Package Folder>/shared_prefs/arrkiiad.xml.bak
  • <Package Folder>/shared_prefs/clean.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml.bak (deleted)
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml.bak
  • <Package Folder>/shared_prefs/com.crashlytics.prefs.xml
  • <Package Folder>/shared_prefs/com.crashlytics.sdk.android;answers;settings.xml
  • <Package Folder>/shared_prefs/com.facebook.internal.preferences.APP_SETTINGS.xml
  • <Package Folder>/shared_prefs/com.mobpower.xml
  • <Package Folder>/shared_prefs/ct_default.xml
  • <Package Folder>/shared_prefs/dcSharedPreferences.dat.xml
  • <Package Folder>/shared_prefs/device_info.xml
  • <Package Folder>/shared_prefs/evernote_jobs.xml
  • <Package Folder>/shared_prefs/hunter_config.xml
  • <Package Folder>/shared_prefs/install.xml
  • <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.q.xml
  • <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.q.xml.bak
  • <Package Folder>/shared_prefs/last_know_location.xml
  • <Package Folder>/shared_prefs/mobvista.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/other_config.xml
  • <Package Folder>/shared_prefs/self_adextend.xml
  • <Package Folder>/shared_prefs/self_adextend.xml.bak
  • <Package Folder>/shared_prefs/service_config.xml
  • <Package Folder>/shared_prefs/service_config.xml.bak
  • <Package Folder>/shared_prefs/share_date.xml
  • <Package Folder>/shared_prefs/share_date.xml.bak
  • <Package Folder>/shared_prefs/sp_config.xml
  • <Package Folder>/shared_prefs/sp_config.xml.bak
  • <Package Folder>/shared_prefs/strategy_sp.xml
  • <Package Folder>/shared_prefs/t_ini.xml
  • <Package Folder>/shared_prefs/t_ini.xml.bak
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.androidsystem/####/49.x-3.0.1.apk
  • <SD-Card>/.androidsystem/####/PlugShareData
  • <SD-Card>/.androidsystem/####/files.db
  • <SD-Card>/.androidsystem/####/gads.db
  • <SD-Card>/.androidsystem/####/plugxml.xml
  • <SD-Card>/.androidsystem/####/syncfiles.db
  • <SD-Card>/.androidsystem/Plugin.zip
  • <SD-Card>/Android/####/.0.tmp (deleted)
  • <SD-Card>/Android/####/.nomedia
  • <SD-Card>/Android/####/0548391082cfd49909b29fe2d1b80226.0.tmp
  • <SD-Card>/Android/####/09ac570d10a28c0c08ecee080ceb90a7.0.tmp
  • <SD-Card>/Android/####/10d0f4fe07dbedb0d0b344981a7a89a4.0.tmp
  • <SD-Card>/Android/####/1380229154.js
  • <SD-Card>/Android/####/1e51124889785cfd62378f2d029f38be.0.tmp
  • <SD-Card>/Android/####/277fc9f3b641cf2b26953632dddd7e8f5cd195f5_v23_phone.mp4
  • <SD-Card>/Android/####/32517931460d7c6de8f1d98b37b5a41f.0.tmp
  • <SD-Card>/Android/####/36b1415f32617f2d92ae4c77a9f1dad4.0.tmp
  • <SD-Card>/Android/####/44f0af0637bd634b756a5d1d06fdf697.0.tmp
  • <SD-Card>/Android/####/46904b506b3a8a211c4b954defb6b113.0.tmp
  • <SD-Card>/Android/####/5285044de8e4db72b86e7246f9aee7c2.0.tmp
  • <SD-Card>/Android/####/6fc9aa4690e84efaf508d08270ff6b90.0.tmp
  • <SD-Card>/Android/####/70594694b795809267b00a383e3a0e3e.0.tmp
  • <SD-Card>/Android/####/71bd5e215c19e55403412e9d82bf69e0.0.tmp
  • <SD-Card>/Android/####/9f10a940fc0ca7fa2574ff739d41882d.0.tmp
  • <SD-Card>/Android/####/a037d3b20df5ce42671791090fa65063.0.tmp
  • <SD-Card>/Android/####/b292bd32c3b74de28094a4c01838cf2d
  • <SD-Card>/Android/####/cf443a23cd9ec5376623b09348edc247.0.tmp
  • <SD-Card>/Android/####/e9e34ae453e84000935390e626eaefb3
  • <SD-Card>/Android/####/f41f788b39f24bf584eed8c38f7d9b3d
  • <SD-Card>/Android/####/f6fd6936ee65918b5035e185ada6ad88.0.tmp
  • <SD-Card>/Android/####/fe5c93839b1d1122297543ab980f0ecd.0.tmp
  • <SD-Card>/Android/####/journal
  • <SD-Card>/Android/####/journal.tmp
  • <SD-Card>/Android/####/jquery-1.9.1.min.js
  • <SD-Card>/Android/####/jquery.knob.js
  • <SD-Card>/Android/####/o903c61a_e49f325a0ff6347a4820c77a06c211bbbc99419a_raw11.gif
  • <SD-Card>/Android/####/sound_off.png
  • <SD-Card>/Android/####/sound_on.png
  • <SD-Card>/Download/####/accs_election
  • <SD-Card>/LogN/####/sp
  • <SD-Card>/baidu/####/journal.tmp
  • <SD-Card>/baidu/.cuid
  • <SD-Card>/mobogenie/####/all_search_hotwords.json
  • <SD-Card>/mobogenie/####/facebook_ads_position.json
  • <SD-Card>/mobogenie/####/gl_app_home_all_json
  • <SD-Card>/mobogenie/####/mobogenie.uuid
  • <SD-Card>/mobogenie/####/splashbanner.png
  • <SD-Card>/mobogenie/mobosd.bin
  • <SD-Card>/mobogenie/mobosd.bin-journal
Другие:
Запускает следующие shell-скрипты:
  • /data/data/com.mobogenie/files/cwd 0
  • /data/data/com.mobogenie/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=2016&uuid=c4122df9-c7b7-412f-9db7-c15a9852725c&android=d8acaa6b5680a853&imei=356507059351895&versionCode=302151&versionName=3.2.15.1&site=GL
  • /data/data/com.mobogenie/files/watch_server /data/data/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302151&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • /data/user/0/com.mobogenie/files/watch_server /data/user/0/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302151&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D %7B%22package%22%3A%22<Package>%22%2C%22appKey%22%3A%22umeng%3A57b1919c67e58e3b8a00022f%22%2C%22utdid%22%3A%22WS55OHIzKXsDAGdzx1F7eILF%22%2C%22sdkVersion%22%3A%22212%22%7D -I agoodm.m.taobao.com -O 80 -T -Z
  • <dexopt>
  • cat /proc/cpuinfo
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 755 /data/data/com.mobogenie/files/watch_server
  • chmod 755 /data/user/0/<Package>/files/watch_server
  • chmod 755 /data/user/0/com.mobogenie/files/watch_server
  • chmod 755 <Package Folder>/files/watch_server
  • sh
  • sh /data/user/0/<Package>/files/watch_server /data/user/0/<Package> http://redirect.mobogenie.com?pn=<Package>&v=302151&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • sh <Package Folder>/files/cwd 0
  • sh <Package Folder>/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=2016&uuid=c4122df9-c7b7-412f-9db7-c15a9852725c&android=d8acaa6b5680a853&imei=<IMEI>&versionCode=302151&versionName=3.2.15.1&site=GL
  • sh <Package Folder>/files/watch_server <Package Folder> http://redirect.mobogenie.com?pn=<Package>&v=302151&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке