Edited by Chundoundo at 2016-10-29 14:27 \n\n
Just the same adwares in firmware even afrer SPFT updated from 160719 to 160826.
I found this apps not safe (as it connected to chinese IPs):
s=system, a=app, p-a=priv-app
/s/p-a/Launcher3.apk - built-in launcher - Trojan.Android.Agent.dqfsll
/s/a/FineSearch.apk - chinese fake search Cooee - Android-PUP/Cooee.197d1 \ not-a-virus:HEUR:AdWare.AndroidOS.Coee.a
/s/a/FineVideoPlayer.apk - built-in chinese videoplayer - Android/Inmobi.D
/s/a/webcore.apk - fake Opera Store
/s/a/AdupsFota.apk - OTA
/s/a/LovelyFonts.apk - chinese fonts
/s/p-a/LovelyFontsService.apk - the same
/s/p-a/SystemUI.apk - modified System interface that try to connect to chinese IP and load ads and make strange folder bcjwq Andr/Dropr-FY
- you can't delete SysUI, but can block with firewall
cn adware
cn adware
SystemUI try connect to cn IP
SystemUI try connect to cn IP
Check this IPs from SystemUI:
http://geoiplookup.net/ip/103.235.47.74
http://geoiplookup.net/ip/106.39.162.36
http://geoiplookup.net/ip/114.55.145.117
http://geoiplookup.net/ip/120.55.179.179
http://geoiplookup.net/ip/121.69.49.133
http://geoiplookup.net/ip/122.224.95.58
http://geoiplookup.net/ip/180.76.153.60
http://geoiplookup.net/ip/180.97.33.30
|