Executes next shell scripts:
- /data/data/tc4.krv.fgi/files/.snow/exp /data/data/tc4.krv.fgi/files/.snow /data/data/tc4.krv.fgi/files/.work
- /system/bin/sh ./mkdevsh
- app_process /system/bin com.android.commands.pm.Pm disable com.android.tools.receiver
- app_process /system/bin com.android.commands.pm.Pm disable com.android.upon.hash
- app_process /system/bin com.android.commands.pm.Pm disable com.master.main.yaogirl.longe.wei
- app_process /system/bin com.android.commands.pm.Pm disable com.qiu.qing.bing.shuo.tu
- app_process /system/bin com.android.commands.pm.Pm disable com.setting.dysdtool
- app_process /system/bin com.android.commands.pm.Pm disable com.slave.wuw.yiyi.ranran.fang
- app_process /system/bin com.android.commands.pm.Pm enable com.android.tools.receiver
- app_process /system/bin com.android.commands.pm.Pm enable com.android.upon.hash
- app_process /system/bin com.android.commands.pm.Pm enable com.master.main.yaogirl.longe.wei
- app_process /system/bin com.android.commands.pm.Pm enable com.qiu.qing.bing.shuo.tu
- app_process /system/bin com.android.commands.pm.Pm enable com.setting.dysdtool
- app_process /system/bin com.android.commands.pm.Pm enable com.slave.wuw.yiyi.ranran.fang
- chcon u:object_r:system_file:s0 /system/bin/debuggerd
- chcon u:object_r:system_file:s0 /system/lib/libsoon.so
- chcon u:object_r:system_file:s0 /system/xbin/.rainin
- chmod 777 <Package Folder>/files/.snow/.catr.apk
- chmod 777 <Package Folder>/files/.snow/.client
- chmod 777 <Package Folder>/files/.snow/.dg
- chmod 777 <Package Folder>/files/.snow/.service
- chmod 777 <Package Folder>/files/.snow/.ukd
- chmod 777 <Package Folder>/files/.snow/.uks
- chmod 777 <Package Folder>/files/.snow/.uok
- chmod 777 <Package Folder>/files/.snow/.zip/
- chmod 777 <Package Folder>/files/.snow/.zip/mkdevsh
- chmod 777 <Package Folder>/files/.snow/.zip/r1
- chmod 777 <Package Folder>/files/.snow/.zip/r2
- chmod 777 <Package Folder>/files/.snow/.zip/r3
- chmod 777 <Package Folder>/files/.snow/.zip/r4
- chmod 777 <Package Folder>/files/.snow/.zip/rsh
- chmod 777 <Package Folder>/files/.snow/.zip/rt8
- chmod 777 <Package Folder>/files/.snow/a.xml
- chmod 777 <Package Folder>/files/.snow/b.png
- chmod 777 <Package Folder>/files/.snow/busybox
- chmod 777 <Package Folder>/files/.snow/myshell
- chmod 777 <Package Folder>/files/.snow/supolicy
- chmod 777 <Package Folder>/files/.work/postroot.sh
- chown 0.0 /data/local/tmp/.catr.apk
- chown 0.0 /data/local/tmp/busybox
- chown 0.0 /system/app/Dingps.apk
- chown 0.0 /system/app/Linkcai.apk
- chown 0.0 /system/app/MainMaster.apk
- chown 0.0 /system/app/oneshs.apk
- chown 0.0 /system/bin/debuggerd
- chown 0.0 /system/lib/libsoon.so
- chown 0.0 /system/xbin/.ci.pm
- chown 0.0 /system/xbin/.cp
- chown 0.0 /system/xbin/.rainin
- chown 0:0 /data/local/tmp/.catr.apk
- chown 0:0 /data/local/tmp/busybox
- chown 0:0 /system/app/Dingps.apk
- chown 0:0 /system/app/Linkcai.apk
- chown 0:0 /system/app/Lowerp.apk
- chown 0:0 /system/app/MainMaster.apk
- chown 0:0 /system/app/WelSlave.apk
- chown 0:0 /system/app/oneshs.apk
- chown 0:0 /system/bin/.author
- chown 0:0 /system/bin/debuggerd
- chown 0:0 /system/lib/libsoon.so
- chown 0:0 /system/xbin/.ci.pm
- chown 0:0 /system/xbin/.cp
- chown 0:0 /system/xbin/.rainin
- chown 0:0 /system/xbin/supolicy
- df /system
- mount -o remount ro /system
- mount -o remount rw /system
- mount -o remount,ro /system
- mount -ro remount ro /system
- mount -ro remount,ro /system
- mount -wo remount rw /system
- mount -wo remount,rw /system
- rm /system/bin/debuggerd
- sh
Loads the following dynamic libraries:
Uses the following algorithms to encrypt data:
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
Uses the following algorithms to decrypt data:
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
Gains access to network information
Gains access to telephone information (number, imei, etc.)
Gains access to information about installed applications
Gains access to information about running applications
Adds tasks to the system scheduler
Displays its own windows over windows of other applications