Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 mobogenie - is it malware, it downloaded itself

views
     
SUSEdBaaBaa
post Nov 14 2013, 10:45 AM, updated 13y ago

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
Past week or so, whilst surfing on my mobile, i get pop-up ads re mobogenie about 2x a day. Gives option to download or cancel - i always cancel. Tried to find a way to stop the pop-up but couldnt.

Then last nite, mobogenie just downloaded itself without any notice and definitely no permission from me. The DL was so fast i could not stop it.

However, i went immediately to the "downloads" folder and deleted it.

I have googled it but there's not much on it - its an apk file, android manager. 1 site states that it is a scam.

Some sites lauds it as some great app but I detest that it DL itself without consent and am suspicious of those "reviews".

Q:

1. Anyone else encountered this?

2. Is it malware?

3. Have i eradicated it effectively? If not yet, how do i do it?

Tks

Andrew_1980
post Nov 14 2013, 10:47 AM

Look at all my stars!!
*******
Senior Member
6,196 posts

Joined: Nov 2012


This?

https://play.google.com/store/apps/details?...bogenie.markets
SUSEdBaaBaa
post Nov 14 2013, 11:16 AM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
Yep, that's the one.

Btw, the "review/comment" by Skanda Kumar there expresses my disgust with its sneaky self-download.

Even if it us not malware, wtf does it self-download? Like my mobile being raped!!
Andrew_1980
post Nov 14 2013, 11:19 AM

Look at all my stars!!
*******
Senior Member
6,196 posts

Joined: Nov 2012


QUOTE(EdBaaBaa @ Nov 14 2013, 11:16 AM)
Yep, that's the one.

Btw, the "review/comment" by Skanda Kumar there expresses my disgust with its sneaky self-download.

Even if it us not malware, wtf does it self-download? Like my mobile being raped!!
*
Can't stop it or uninstall it? it seems like market apps hmm.gif
SUSEdBaaBaa
post Nov 14 2013, 11:29 AM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
After it downloaded, a pop-up asked to verify n install.

Of course i didnt, went to download folder and deleted it.

Is that the end of it?? I hope i have killed it for good.

I am curious how it manages to self-download? Is it Google?

I hate google+, can i unistall it without any repercussions?
axxer
post Nov 14 2013, 04:22 PM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
obviously one of your app or game did that. probably they collaborate with that mobogenie and try to download it.
an app that's still not install yet can't download its installation files, that doesn't make sense at all, other app or game is triggering the download.

This post has been edited by axxer: Nov 14 2013, 04:23 PM
Andy Allen
post Nov 15 2013, 06:48 PM

New Member
*
Newbie
1 posts

Joined: Nov 2013
I just registered on this forum because I just got bitten by mobogenie myself a few hours ago.
Circumstances different though - I'm browsing on a PC. Using Seamonkey browser with adblock plus, but somehow
mobogenie got downloaded to the PC *and* a USB attached Android tablet. (My phone, also android was
attached at the same time, but didn't get "infected").

Pretty sure I didn't see a visible installer....

(I did have MyPhoneExplorer, and hence google's ADB loaded, but I wasn't uploading anything - I just load that to keep an eye on it while it charges).

So, beware, looks as if it is a drive by download - should be considered malware since I saw no installer dialog, and didn't go clicky on any adverts...

But... I also had the sysinternals process explorer loaded, and it looks as if the "malware" uses a custom version
of the Google ADB program (with a slightly different name) to upload itself to usb connected android devices.

Andy
(Old old retired programmer)

LEVIATHAN
post Nov 15 2013, 07:04 PM

Master Chief Carl M. Brashear
*******
Senior Member
2,281 posts

Joined: Oct 2006
From: Littleroot Town



A very good 1st post.
SUSEdBaaBaa
post Nov 15 2013, 09:32 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
Andrew_1980 Andy Allen

tq for the information.

Well, at my end, the news just gets better.

Last night mofogenie tried to DL itself again. So obviously my earlier action of deleting the DL file does not kill it.

This morning, when i sent a watsapp message, an advert was attached to the message. No indication of it whilst i was keying in the message. Only saw it when after it was sent and recipient replied to me.

So i've had to voice call every party who messaged me in fear of spreading some malware if i replied online.

I seldom tether my mobile to my pc but having read Andy's experience, i recall that i did once over the past 2 weeks. I use firefox with adblock. Praying very hard that my pc has not been infected.

Just for info, i have not DL any new games in the relevant period but did DL a mp3 downloader app and 2 financial services app (both rated v well) - 1 of which has been used by a friend fir some time without any issue at all.

May i know the name of the Google ADB program file that mofogenie uses? Can i delete it safely?

If i factory reset my mobile, will all issues with mofogenie n unwanted ads be resolved?

Tks

Andrew_1980
post Nov 15 2013, 09:33 PM

Look at all my stars!!
*******
Senior Member
6,196 posts

Joined: Nov 2012


QUOTE(EdBaaBaa @ Nov 15 2013, 09:32 PM)
Andrew_1980 Andy Allen

» Click to show Spoiler - click again to hide... «

*
Too long to read.. tongue.gif If you factory reset your phone (clean internal storage data) should be fine. Not sure but you can try.
xDjWanNabex
post Nov 15 2013, 09:38 PM

Enthusiast
*****
Senior Member
932 posts

Joined: Sep 2008
Try downloading malware bytes and run a scan.
SUSEdBaaBaa
post Nov 15 2013, 09:39 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
Btw, just completeness, i do not click on adverts either.nor do i frequent any iffy websites.

Just that while searching info on mofogenie, i did go to crappy websites that promote it.

The reviews and star rating for MOFOgenie in playstore are mostly fake - done in return for some dubious reward. I hope that those who gave given such fake reviews/stars are suitably visited by karma.
Andrewtst
post Nov 15 2013, 09:43 PM

Forgiveness is Happiness
*********
All Stars
29,780 posts

Joined: Jan 2009
From: Johor, Malaysia.


Hi, Andy Allen and EdBaaBaa,

I notice you both had install similar thing at PC, probably that software trigger it.

adblock Try uninstall this software see problem solved or not.
mudkipryan94
post Nov 15 2013, 10:03 PM

someone need a sarcasm meter?
********
All Stars
12,000 posts

Joined: Feb 2010
From: Banting, Puchong, KL



QUOTE(Andrewtst @ Nov 15 2013, 09:43 PM)
Hi, Andy Allen and EdBaaBaa,

I notice you both had install similar thing at PC, probably that software trigger it.

adblock Try uninstall this software see problem solved or not.
*
yeah.. ADblock can blocks tons of rubbish icon_idea.gif
ripegoat
post Nov 17 2013, 10:17 AM

New Member
*
Newbie
3 posts

Joined: May 2013
QUOTE(Andy Allen @ Nov 15 2013, 06:48 PM)
I just registered on this forum because I just got bitten by mobogenie myself a few hours ago.
Circumstances different though - I'm browsing on a PC. Using Seamonkey browser with adblock plus, but somehow
mobogenie got downloaded to the PC *and* a USB attached Android tablet. (My phone, also android was
attached at the same time, but didn't get "infected").

Pretty sure I didn't see a visible installer....

(I did have MyPhoneExplorer, and hence google's ADB loaded, but I wasn't uploading anything - I just load that to keep an eye on it while it charges).

So, beware, looks as if it is a drive by download - should be considered malware since I saw no installer dialog, and didn't go clicky on any adverts...

But... I also had the sysinternals process explorer loaded, and it looks as if the "malware" uses a custom version
of the Google ADB program (with a slightly different name) to upload itself to usb connected android devices.

Andy
(Old old retired programmer)
*
Hi, I don't think a program drive-by to your PC AND your tablet is technically possible. I would think that for that to happen, a dialog would at least show up.
axxer
post Nov 17 2013, 12:32 PM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
QUOTE(ripegoat @ Nov 17 2013, 10:17 AM)
Hi, I don't think a program drive-by to your PC AND your tablet is technically possible. I would think that for that to happen, a dialog would at least show up.
*
no, its possible.
if adb debugging is enable on the phone, when its connected to pc, a simple
CODE
adb install filename.apk

from cmd would install any app via adb to that connected phone, no prompt, no confirmation dialog, completely invisible to user.
ripegoat
post Nov 17 2013, 12:44 PM

New Member
*
Newbie
3 posts

Joined: May 2013
QUOTE(axxer @ Nov 17 2013, 12:32 PM)
no, its possible.
if adb debugging is enable on the phone, when its connected to pc, a simple
CODE
adb install filename.apk

from cmd would install any app via adb to that connected phone, no prompt, no confirmation dialog, completely invisible to user.
*
Oh, so does it work the other way (phone installing on the PC)? Because if I read correctly, Andy mentioned the mobogenie being installed on his PC?

Another question.. If the Mobogenie app was installed on the android tablet/phone, won't it mean that the PC is infected with a malware of some sort for the the installation/command to run?
axxer
post Nov 17 2013, 12:53 PM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
QUOTE(ripegoat @ Nov 17 2013, 12:44 PM)
Oh, so does it work the other way (phone installing on the PC)? Because if I read correctly, Andy mentioned the mobogenie being installed on his PC?

Another question.. If the Mobogenie app was installed on the android tablet/phone, won't it mean that the PC is infected with a malware of some sort for the the installation/command to run?
*
yes, my best bet would be the pc is infected. some process is running in backgroud and when it detect an android phone is connected it'll issue the adb install command.

try to googling using "mobogenie" and "malware" keyword, got many interesting result, especially this one
http://www.exedb.com/exefiles/mobogenie.exe.html
my guts tell me thats the process that trying to install the apk when phone is connected.

anyway, the mobogenie thingy is not an alternative android market per se like what it said on the mobogenie app description on playstore.
from its site,
http://www.mobogenie.com
its self proclaim as "an alternative android all in one manager". got pc client, and the mobogenie.exe process is its pc client process. look and sound as legit, but not when its trying to install an app to user's phone without user consent.

This post has been edited by axxer: Nov 17 2013, 01:05 PM
ripegoat
post Nov 17 2013, 01:09 PM

New Member
*
Newbie
3 posts

Joined: May 2013
QUOTE(axxer @ Nov 17 2013, 12:53 PM)
yes, my best bet would be the pc is infected. some process is running in backgroud and when it detect an android phone is connected it'll issue the adb install command.

try to googling using "mobogenie" and "malware" keyword, got many interesting result, especially this one
http://www.exedb.com/exefiles/mobogenie.exe.html
my guts tell me thats the process that trying to install the apk when phone is connected.
*
Thanks! That definitely looks suspicious.

Since we are on this topic, I have a question.. I was doing some searching and found this link: http://askleo.com/can-my-pc-get-a-virus-from-my-smartphone/ .. I was wondering if it is possible that instead of virusus, can smart phones nowadays install entire rougue exectable programs (without the installer popping up) on PCs this way?

This post has been edited by ripegoat: Nov 17 2013, 01:10 PM
axxer
post Nov 17 2013, 01:26 PM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
http://phys.org/news/2013-02-kaspersky-use...ng-malware.html

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0189sec    0.32    6 queries    GZIP Disabled
Time is now: 21st December 2025 - 06:57 PM