Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.25665

Добавлен в вирусную базу Dr.Web: 2017-07-27

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.HiddenAds.125.origin
Загружает из Интернета следующие детектируемые угрозы:
  • Android.HiddenAds.125.origin
Сетевая активность:
Подключается к:
  • a####.####.com
  • a####.####.net
  • a####.####.org
  • admobim####.com
  • api####.####.com
  • c####.####.com
  • cdn####.####.com
  • con####.####.com
  • cpgnrot####.com
  • d####.####.com
  • f####.####.com
  • face####.com
  • gl####.####.com
  • i####.####.com
  • ma####.####.com
  • mmmmmm####.com
  • mobilem####.me
  • mobotoo####.####.com
  • n####.####.com
  • o####.####.com
  • p####.####.com
  • pag####.####.com
  • pass####.####.com
  • pl####.####.com
  • r####.####.com
  • real####.####.org
  • s####.####.com
  • sc####.####.com
  • se####.####.com
  • serv####.####.com
  • set####.####.com
  • synct####.com
  • t####.####.com
  • t####.####.online
  • technol####.####.uk
  • u####.####.com
  • up####.####.com
Запросы HTTP GET:
  • a####.####.com/impression?k=####&p=####&q=####&x=####
  • a####.####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=####&sd...
  • a####.####.net/api/v2/template/get?slot_id=####&update_time=####
  • a####.####.org/rule?platform=####&os_version=####&package_name=####&app_...
  • c####.####.com/?utm_medium=####&utm_campaign=####&cid=####&1=####
  • cdn####.####.com/cdn-adn/offersync/17/03/13/16/16/58c6554b5544a.png
  • cpgnrot####.com/campaign/2292%7C518?tag=####&website=####&placement=####
  • d####.####.com/M00/01/AB/CvJMDVlBJNyAE3AUAAVgxYzjtNE875.zip
  • d####.####.com/impression?k=####&p=####&q=####&x=####
  • f####.####.com/css?family=####&ver=####
  • f####.####.com/s/robotoslab/v6/dazS1PrQQuCxC3iOAJFEJTdGNerWpg2Hn6A-BxWgZ...
  • face####.com/plugins/likebox.php?href=####&w####&height=####&colorscheme...
  • gl####.####.com/trace?offer_id=####&app_id=####&type=####&aff_sub=####&a...
  • i####.####.com/jquery-1.9.1.min.js
  • ma####.####.com/frontend/cardList.htm?isrecmd=####&ran=####&ismsg=####&i...
  • mobilem####.me/r/e1c142b2-72cf-11e7-b1d0-11422473fc9a/1/
  • mobotoo####.####.com/mobotoolpush/deskiconpush.json?version_name=####&ad...
  • n####.####.com/mu/2017/5/24/playpicture/2f8d354c72e2407096b874fe736bc320...
  • n####.####.com/openapi/ad/v3?app_id=####&unit_id=####&category=####&req_...
  • o####.####.com/engine/a.aspx?id=####
  • o####.####.com/ipo/api/gray/status?appvc=####&os=####&appvn=####&avn=###...
  • p####.####.com/notification/android/message.json?pname=####&version=####...
  • pag####.####.com/pagead/js/adsbygoogle.js
  • pass####.####.com/android/v2/getDoSignInfo.htm?uid=####&versionCode=####...
  • r####.####.com/2.0/ad?v1=####&model=####&etf=####&dx=####&dy=####&accept...
  • real####.####.org/realtime?platform=####&os_version=####&package_name=##...
  • s####.####.com/ads-service/ads/service/getAdlist.do?adnum=####&adid=####...
  • sc####.####.com/v1/scheme/app?model=####&mcc=####&os_v=####&direction=##...
  • serv####.####.com/119987?t=####&ref=####&lu=####
  • set####.####.com/setting?app_id=####&sign=####&platform=####&os_version=...
  • synct####.com/gw?url=####&vId=####&ef=####&ch=####&nid=####&sub=####
  • t####.####.com/click?_type=####&sdk_redir=####&campid=####&sub_channel=#...
  • t####.####.online/?utm_medium=####&utm_campaign=####&1=####&cid=####&_uu...
  • technol####.####.uk/wp-content/plugins/wp-share-buttons/Front_end/js/cus...
  • u####.####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&prod...
Запросы HTTP POST:
  • a####.####.com/amdc/mobileDispatch?appkey=####&platform=####&v=####&devi...
  • a####.####.com/detail/getOfferListNew?enc=####
  • admobim####.com/surl/api2_reg.action
  • api####.####.com/v3/log/init
  • con####.####.com/log/log_apps
  • ma####.####.com/android/requestForUpdate.htm
  • mmmmmm####.com/osp/oaen_reg.action
  • p####.####.com/getList.htm
  • p####.####.com/getShowWindow.htm
  • pl####.####.com/ad_dex.php
  • s####.####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
  • se####.####.com/initRequestDomain.htm
  • se####.####.com/social/getPraiseNum.htm
  • up####.####.com/upload?orientation=####&platform=####&model=####&userage...
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.mbj/####/classes.zip
  • <Package Folder>/cache/####/0548391082cfd49909b29fe2d1b80226.0.tmp
  • <Package Folder>/cache/####/0548391082cfd49909b29fe2d1b80226.1.tmp
  • <Package Folder>/cache/####/09ac570d10a28c0c08ecee080ceb90a7.0.tmp
  • <Package Folder>/cache/####/09ac570d10a28c0c08ecee080ceb90a7.1.tmp
  • <Package Folder>/cache/####/09e3d260657721556d28193060b177b6.0.tmp
  • <Package Folder>/cache/####/09e3d260657721556d28193060b177b6.1.tmp
  • <Package Folder>/cache/####/10010602e6ab7307f418ae533d9eabd9.0.tmp
  • <Package Folder>/cache/####/10010602e6ab7307f418ae533d9eabd9.1.tmp
  • <Package Folder>/cache/####/10d0f4fe07dbedb0d0b344981a7a89a4.0.tmp
  • <Package Folder>/cache/####/10d0f4fe07dbedb0d0b344981a7a89a4.1.tmp
  • <Package Folder>/cache/####/20552ea704f9a20813210f42adc63e58.0
  • <Package Folder>/cache/####/20552ea704f9a20813210f42adc63e58.1
  • <Package Folder>/cache/####/2059e716def740632c3fc5a2fb76d9fc.0.tmp
  • <Package Folder>/cache/####/2059e716def740632c3fc5a2fb76d9fc.1
  • <Package Folder>/cache/####/36b1415f32617f2d92ae4c77a9f1dad4.0.tmp
  • <Package Folder>/cache/####/36b1415f32617f2d92ae4c77a9f1dad4.1.tmp
  • <Package Folder>/cache/####/3c253ffb4fbb5e6123f87eab107e88f1.0
  • <Package Folder>/cache/####/3c253ffb4fbb5e6123f87eab107e88f1.1
  • <Package Folder>/cache/####/3c99d9e5f33f91011a491614e91669be.0.tmp
  • <Package Folder>/cache/####/3c99d9e5f33f91011a491614e91669be.1.tmp
  • <Package Folder>/cache/####/48c6318a5a067fb9b7234f8e4074eb41.0.tmp
  • <Package Folder>/cache/####/48c6318a5a067fb9b7234f8e4074eb41.1.tmp
  • <Package Folder>/cache/####/5285044de8e4db72b86e7246f9aee7c2.0.tmp
  • <Package Folder>/cache/####/5285044de8e4db72b86e7246f9aee7c2.1.tmp
  • <Package Folder>/cache/####/540c949e71e07a10e25944b1162f27a7.0.tmp
  • <Package Folder>/cache/####/540c949e71e07a10e25944b1162f27a7.1
  • <Package Folder>/cache/####/5670072ddbb8cd406d6ae4e0a6e75464.0.tmp
  • <Package Folder>/cache/####/5670072ddbb8cd406d6ae4e0a6e75464.1.tmp
  • <Package Folder>/cache/####/5aced3429b4f38cef4f8dc1dd54239fb.0.tmp
  • <Package Folder>/cache/####/5aced3429b4f38cef4f8dc1dd54239fb.1.tmp
  • <Package Folder>/cache/####/637bcf779e8a476965fb4296552b99c7.0.tmp
  • <Package Folder>/cache/####/637bcf779e8a476965fb4296552b99c7.1.tmp
  • <Package Folder>/cache/####/67ced3b1a2a44e6df8ca2277eec023f1.0.tmp
  • <Package Folder>/cache/####/67ced3b1a2a44e6df8ca2277eec023f1.1.tmp
  • <Package Folder>/cache/####/70594694b795809267b00a383e3a0e3e.0.tmp
  • <Package Folder>/cache/####/70594694b795809267b00a383e3a0e3e.1.tmp
  • <Package Folder>/cache/####/71bd5e215c19e55403412e9d82bf69e0.0.tmp
  • <Package Folder>/cache/####/71bd5e215c19e55403412e9d82bf69e0.1.tmp
  • <Package Folder>/cache/####/8b28946b0cae0e61566694ee6d0dea3a.0.tmp
  • <Package Folder>/cache/####/8b28946b0cae0e61566694ee6d0dea3a.1.tmp
  • <Package Folder>/cache/####/9420055e6b8ba1a3065a3f70f57b44bb.0.tmp
  • <Package Folder>/cache/####/9420055e6b8ba1a3065a3f70f57b44bb.1.tmp
  • <Package Folder>/cache/####/94afbb626216e963e246cd11291f2416.0.tmp
  • <Package Folder>/cache/####/94afbb626216e963e246cd11291f2416.1.tmp
  • <Package Folder>/cache/####/9834676845c32bd7cdee16195d2d4b58.0.tmp
  • <Package Folder>/cache/####/9834676845c32bd7cdee16195d2d4b58.1.tmp
  • <Package Folder>/cache/####/9e209adabfa62c2a1b9491a84034584e.0.tmp
  • <Package Folder>/cache/####/9e209adabfa62c2a1b9491a84034584e.1.tmp
  • <Package Folder>/cache/####/a64e4940b33d43d5a587d9716add3915.0
  • <Package Folder>/cache/####/a64e4940b33d43d5a587d9716add3915.1
  • <Package Folder>/cache/####/a9412cf8e19ce1d974da7adbc0e8b6d1.0
  • <Package Folder>/cache/####/a9412cf8e19ce1d974da7adbc0e8b6d1.1
  • <Package Folder>/cache/####/aa88bfd94ed8ac24d0a4cb1da8f405b3.0
  • <Package Folder>/cache/####/aa88bfd94ed8ac24d0a4cb1da8f405b3.1
  • <Package Folder>/cache/####/abd533e10e9b8d67d9f14347a3c2e213.0
  • <Package Folder>/cache/####/abd533e10e9b8d67d9f14347a3c2e213.1
  • <Package Folder>/cache/####/b684a1df8e6e9cf3ecfd65d14240b55a.0.tmp
  • <Package Folder>/cache/####/b684a1df8e6e9cf3ecfd65d14240b55a.1
  • <Package Folder>/cache/####/d149467676fd959a5a11be2498d059cc.0
  • <Package Folder>/cache/####/d149467676fd959a5a11be2498d059cc.1
  • <Package Folder>/cache/####/d36ec3a6c36de659290d2d6532b62faf.0
  • <Package Folder>/cache/####/d36ec3a6c36de659290d2d6532b62faf.1
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/dbf3659627f20c26b2049b02ea268e04.0
  • <Package Folder>/cache/####/dbf3659627f20c26b2049b02ea268e04.1
  • <Package Folder>/cache/####/ebbf79453bcf2cf9cf8336d61debe165.0.tmp
  • <Package Folder>/cache/####/ebbf79453bcf2cf9cf8336d61debe165.1.tmp
  • <Package Folder>/cache/####/ef6d93a73c25fee4e4bf514cdf6ad155.0.tmp
  • <Package Folder>/cache/####/ef6d93a73c25fee4e4bf514cdf6ad155.1.tmp
  • <Package Folder>/cache/####/f4e6a92813f10e718225f9e9078ea1af.0.tmp
  • <Package Folder>/cache/####/f4e6a92813f10e718225f9e9078ea1af.1
  • <Package Folder>/cache/####/f6fd6936ee65918b5035e185ada6ad88.0.tmp
  • <Package Folder>/cache/####/f6fd6936ee65918b5035e185ada6ad88.1.tmp
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/f_000004
  • <Package Folder>/cache/####/f_000005
  • <Package Folder>/cache/####/f_000006
  • <Package Folder>/cache/####/f_000007
  • <Package Folder>/cache/####/f_000008
  • <Package Folder>/cache/####/f_000009
  • <Package Folder>/cache/####/f_00000a
  • <Package Folder>/cache/####/f_00000b
  • <Package Folder>/cache/####/f_00000c
  • <Package Folder>/cache/####/f_00000d
  • <Package Folder>/cache/####/f_00000e
  • <Package Folder>/cache/####/f_00000f
  • <Package Folder>/cache/####/f_000010
  • <Package Folder>/cache/####/f_000011
  • <Package Folder>/cache/####/f_000012
  • <Package Folder>/cache/####/f_000013
  • <Package Folder>/cache/####/f_000014
  • <Package Folder>/cache/####/f_000015
  • <Package Folder>/cache/####/f_000016
  • <Package Folder>/cache/####/f_000017
  • <Package Folder>/cache/####/f_000018
  • <Package Folder>/cache/####/f_000019
  • <Package Folder>/cache/####/f_00001a
  • <Package Folder>/cache/####/f_00001b
  • <Package Folder>/cache/####/f_00001c
  • <Package Folder>/cache/####/f_00001d
  • <Package Folder>/cache/####/f_00001e
  • <Package Folder>/cache/####/f_00001f
  • <Package Folder>/cache/####/f_000020
  • <Package Folder>/cache/####/fb7348f738ba26e895761c7027fe737a.0.tmp
  • <Package Folder>/cache/####/fb7348f738ba26e895761c7027fe737a.1.tmp
  • <Package Folder>/cache/####/fe5c93839b1d1122297543ab980f0ecd.0.tmp
  • <Package Folder>/cache/####/fe5c93839b1d1122297543ab980f0ecd.1.tmp
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes-757989056.zip
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes1833036815.zip
  • <Package Folder>/databases/MessageStore.db-journal
  • <Package Folder>/databases/MsgLogStore.db-journal
  • <Package Folder>/databases/accs.db-journal
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/arrkii.asa.sdk.db-journal
  • <Package Folder>/databases/cc.db
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/databases/download_file.db-journal
  • <Package Folder>/databases/evernote_jobs.db-journal
  • <Package Folder>/databases/message_accs_db
  • <Package Folder>/databases/message_accs_db-journal
  • <Package Folder>/databases/mobogenie.db
  • <Package Folder>/databases/mobogenie.db-journal
  • <Package Folder>/databases/mobogenie_music.db
  • <Package Folder>/databases/mobogenie_music.db-journal
  • <Package Folder>/databases/mobogenie_update.db
  • <Package Folder>/databases/mobogenie_update.db-journal
  • <Package Folder>/databases/mobpower.db-journal
  • <Package Folder>/databases/mobvista.msdk.db-journal
  • <Package Folder>/databases/my.db
  • <Package Folder>/databases/my.db-journal
  • <Package Folder>/databases/self_ad_db
  • <Package Folder>/databases/self_ad_db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
  • <Package Folder>/databases/webviewCookiesChromiumPrivate.db-journal (deleted)
  • <Package Folder>/databases/ztrack.db-journal
  • <Package Folder>/eudemon
  • <Package Folder>/files/####/5979A2380105-0001-083E-0AFCE5B1C38EBeginSession.cls_temp
  • <Package Folder>/files/####/5979A2380105-0001-083E-0AFCE5B1C38ESessionApp.cls_temp
  • <Package Folder>/files/####/5979A2380105-0001-083E-0AFCE5B1C38ESessionDevice.cls_temp
  • <Package Folder>/files/####/5979A2380105-0001-083E-0AFCE5B1C38ESessionOS.cls_temp
  • <Package Folder>/files/####/5979A2380105-0001-083E-0AFCE5B1C38ESessionUser.cls_temp
  • <Package Folder>/files/####/5979A2380114-0001-085A-2828A98EF838BeginSession.cls
  • <Package Folder>/files/####/5979A2380114-0001-085A-2828A98EF838SessionApp.cls_temp
  • <Package Folder>/files/####/5979A2380114-0001-085A-2828A98EF838SessionDevice.cls_temp
  • <Package Folder>/files/####/5979A2380114-0001-085A-2828A98EF838SessionOS.cls_temp
  • <Package Folder>/files/####/com.crashlytics.settings.json
  • <Package Folder>/files/####/initialization_marker
  • <Package Folder>/files/####/mp_agent_log
  • <Package Folder>/files/####/sa_406e874a-03f2-4166-b5eb-7a6eb06670fc_1501143611831.tap
  • <Package Folder>/files/####/sa_980322dc-ff61-4b71-a640-69e5ee700131_1501143608505.tap
  • <Package Folder>/files/####/session_analytics.tap
  • <Package Folder>/files/####/session_analytics.tap (deleted)
  • <Package Folder>/files/####/session_analytics.tap.tmp
  • <Package Folder>/files/DaemonServer
  • <Package Folder>/files/agoo.pid
  • <Package Folder>/files/cwd
  • <Package Folder>/files/google.db
  • <Package Folder>/files/mobclick_agent_cached_<Package>302152
  • <Package Folder>/files/rk.jar
  • <Package Folder>/files/uninstall
  • <Package Folder>/files/watch_server
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/<Package>_ui_preferences.xml
  • <Package Folder>/shared_prefs/ACCS_BIND.xml
  • <Package Folder>/shared_prefs/ACCS_SDK.xml
  • <Package Folder>/shared_prefs/ACCS_SDK_CHANNEL.xml
  • <Package Folder>/shared_prefs/AGOO_BIND.xml
  • <Package Folder>/shared_prefs/ActivatePreUtil.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/Agoo_AppStore.xml
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/FirstNewUninstallTime.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml.bak
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml (deleted)
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml.bak
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml.bak (deleted)
  • <Package Folder>/shared_prefs/PUSH_PRE.xml
  • <Package Folder>/shared_prefs/PUSH_PRE.xml.bak
  • <Package Folder>/shared_prefs/SCORE_PRE.xml
  • <Package Folder>/shared_prefs/SCORE_PRE.xml.bak
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml.bak
  • <Package Folder>/shared_prefs/SETTING_PRE.xml
  • <Package Folder>/shared_prefs/SETTING_PRE.xml (deleted)
  • <Package Folder>/shared_prefs/SETTING_PRE.xml.bak
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml
  • <Package Folder>/shared_prefs/TOKEN.xml
  • <Package Folder>/shared_prefs/TwitterAdvertisingInfoPreferences.xml
  • <Package Folder>/shared_prefs/USERINFO.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml.bak
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/shared_prefs/apsad.xml.bak
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/shared_prefs/clean.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml.bak
  • <Package Folder>/shared_prefs/com.crashlytics.prefs.xml
  • <Package Folder>/shared_prefs/com.crashlytics.sdk.android;answers;settings.xml
  • <Package Folder>/shared_prefs/com.facebook.internal.preferences.APP_SETTINGS.xml
  • <Package Folder>/shared_prefs/com.mobpower.xml
  • <Package Folder>/shared_prefs/com.mobpower.xml.bak
  • <Package Folder>/shared_prefs/ct_default.xml
  • <Package Folder>/shared_prefs/dcSharedPreferences.dat.xml
  • <Package Folder>/shared_prefs/device_info.xml
  • <Package Folder>/shared_prefs/evernote_jobs.xml
  • <Package Folder>/shared_prefs/hunter_config.xml
  • <Package Folder>/shared_prefs/install.xml
  • <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.q.xml
  • <Package Folder>/shared_prefs/last_know_location.xml
  • <Package Folder>/shared_prefs/mobvista.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/other_config.xml
  • <Package Folder>/shared_prefs/other_config.xml.bak
  • <Package Folder>/shared_prefs/self_adextend.xml
  • <Package Folder>/shared_prefs/self_adextend.xml.bak
  • <Package Folder>/shared_prefs/service_config.xml
  • <Package Folder>/shared_prefs/service_config.xml.bak
  • <Package Folder>/shared_prefs/share_date.xml
  • <Package Folder>/shared_prefs/share_date.xml.bak
  • <Package Folder>/shared_prefs/share_date.xml.bak (deleted)
  • <Package Folder>/shared_prefs/sp_config.xml
  • <Package Folder>/shared_prefs/sp_config.xml.bak
  • <Package Folder>/shared_prefs/strategy_sp.xml
  • <Package Folder>/shared_prefs/t_ini.xml
  • <Package Folder>/shared_prefs/t_ini.xml.bak
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.androidsystem/####/49.x-3.0.1.apk
  • <SD-Card>/.androidsystem/####/PlugShareData
  • <SD-Card>/.androidsystem/####/files.db
  • <SD-Card>/.androidsystem/####/plugxml.xml
  • <SD-Card>/.androidsystem/####/syncfiles.db
  • <SD-Card>/.androidsystem/Plugin.zip
  • <SD-Card>/Android/####/.0.tmp (deleted)
  • <SD-Card>/Android/####/.nomedia
  • <SD-Card>/Android/####/0548391082cfd49909b29fe2d1b80226.0.tmp
  • <SD-Card>/Android/####/09ac570d10a28c0c08ecee080ceb90a7.0.tmp
  • <SD-Card>/Android/####/09e3d260657721556d28193060b177b6.0.tmp
  • <SD-Card>/Android/####/10d0f4fe07dbedb0d0b344981a7a89a4.0.tmp
  • <SD-Card>/Android/####/1380229154.js
  • <SD-Card>/Android/####/277fc9f3b641cf2b26953632dddd7e8f5cd195f5_v23_phone.mp4
  • <SD-Card>/Android/####/36b1415f32617f2d92ae4c77a9f1dad4.0.tmp
  • <SD-Card>/Android/####/40b7c9aa62af4a28a5e7dea8ee0c690d
  • <SD-Card>/Android/####/48c6318a5a067fb9b7234f8e4074eb41.0.tmp
  • <SD-Card>/Android/####/5285044de8e4db72b86e7246f9aee7c2.0.tmp
  • <SD-Card>/Android/####/5aced3429b4f38cef4f8dc1dd54239fb.0.tmp
  • <SD-Card>/Android/####/637bcf779e8a476965fb4296552b99c7.0.tmp
  • <SD-Card>/Android/####/67ced3b1a2a44e6df8ca2277eec023f1.0
  • <SD-Card>/Android/####/69464fa9d6ba40a1b640dc57b1c9224f
  • <SD-Card>/Android/####/70594694b795809267b00a383e3a0e3e.0.tmp
  • <SD-Card>/Android/####/71bd5e215c19e55403412e9d82bf69e0.0.tmp
  • <SD-Card>/Android/####/9420055e6b8ba1a3065a3f70f57b44bb.0.tmp
  • <SD-Card>/Android/####/94afbb626216e963e246cd11291f2416.0.tmp
  • <SD-Card>/Android/####/9e209adabfa62c2a1b9491a84034584e.0.tmp
  • <SD-Card>/Android/####/e7175c09c30e4fae89d5d24c15df6df4
  • <SD-Card>/Android/####/f6fd6936ee65918b5035e185ada6ad88.0.tmp
  • <SD-Card>/Android/####/fb7348f738ba26e895761c7027fe737a.0.tmp
  • <SD-Card>/Android/####/fe5c93839b1d1122297543ab980f0ecd.0.tmp
  • <SD-Card>/Android/####/journal.tmp
  • <SD-Card>/Android/####/jquery-1.9.1.min.js
  • <SD-Card>/Android/####/jquery.knob.js
  • <SD-Card>/Android/####/o903c61a_e49f325a0ff6347a4820c77a06c211bbbc99419a_raw11.gif
  • <SD-Card>/Android/####/sound_off.png
  • <SD-Card>/Android/####/sound_on.png
  • <SD-Card>/Download/####/accs_election
  • <SD-Card>/LogN/####/sp
  • <SD-Card>/baidu/####/journal
  • <SD-Card>/baidu/.cuid
  • <SD-Card>/mobogenie/####/all_search_hotwords.json
  • <SD-Card>/mobogenie/####/facebook_ads_position.json
  • <SD-Card>/mobogenie/####/gl_app_home_all_json
  • <SD-Card>/mobogenie/####/mobogenie.uuid
  • <SD-Card>/mobogenie/####/splashbanner.png
  • <SD-Card>/mobogenie/mobosd.bin
  • <SD-Card>/mobogenie/mobosd.bin-journal
Другие:
Запускает следующие shell-скрипты:
  • /data/data/com.mobogenie/files/cwd 0
  • /data/data/com.mobogenie/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1031&uuid=3fa637ce-e7aa-43c6-97bb-f74219b83fce&android=57611bfab2e4c694&imei=356507059351895&versionCode=302152&versionName=3.2.15.2&site=GL
  • /data/data/com.mobogenie/files/watch_server /data/data/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302152&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • /data/user/0/com.mobogenie/files/watch_server /data/user/0/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302152&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D %7B%22package%22%3A%22<Package>%22%2C%22appKey%22%3A%22umeng%3A57b1919c67e58e3b8a00022f%22%2C%22utdid%22%3A%22WXmiOJ7oZt0DAGdzx1HifgCS%22%2C%22sdkVersion%22%3A%22212%22%7D -I agoodm.m.taobao.com -O 80 -T -Z
  • <dexopt>
  • cat /proc/cpuinfo
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 755 /data/data/com.mobogenie/files/watch_server
  • chmod 755 /data/user/0/<Package>/files/watch_server
  • chmod 755 /data/user/0/com.mobogenie/files/watch_server
  • chmod 755 <Package Folder>/files/watch_server
  • sh
  • sh /data/user/0/<Package>/files/watch_server /data/user/0/<Package> http://redirect.mobogenie.com?pn=<Package>&v=302152&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • sh <Package Folder>/files/cwd 0
  • sh <Package Folder>/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1031&uuid=3fa637ce-e7aa-43c6-97bb-f74219b83fce&android=57611bfab2e4c694&imei=<IMEI>&versionCode=302152&versionName=3.2.15.2&site=GL
  • sh <Package Folder>/files/watch_server <Package Folder> http://redirect.mobogenie.com?pn=<Package>&v=302152&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке