Mobogenie Screenshot 1Mobogenie is a file management program supposedly intended to let you upload pictures from your mobile phone to your PC, for example. Although its marketing makes Mobogenie sound harmless enough, Mobogenie has been classified by malware researchers as adware, and its removal usually should be considered a high priority, due to the prevalence of its advertising functions.

The Genie Whose Wishes Turn Sour

The original genie of myth is known for granting ‘ironic’ wishes that turn to bite their wisher, and Mobogenie, as a cyber genie for the Internet era, certainly has done its part in playing to that role. As a multi-platform program for both Android phones and Windows PCs, Mobogenie does provide the features Mobogenie claims to have, but also displays the traits of a typical adware product. Advertisements by Mobogenie are displayed with a noticeably high frequency, even compared to other adware programs, and have been confirmed to be displayed in Android environments, as well as on personal computers.

The fact that Mobogenie is adware should be enough to convince you to remove Mobogenie and find another way to transfer your files, but Mobogenie also has had the mildly surprising development of being involved in other kind of attacks. Rather than using them, Mobogenie is a beneficiary of them, with a history of being installed on Android phones by seemingly self-downloaded APK files. While many PC users are somewhat familiar with the use of several kinds of attacks against computers, phone users aren’t necessarily so aware of the similar dangers in a smart phone Web-browsing environment.

Putting the Mobogenie Back in Its Bottle

Although mobile phones are somewhat more difficult to protect than PCs (as a natural consequence of the obtuseness of the application-development environment, limited screen space and related factors), there’s no excuse for allowing Mobogenie, or any other adware, to be installed on your phone. Appropriate smart phone security suites should be able to provide some defense against attacks that try to download threats or PUPs, and malware researchers also would recommend avoiding any advertisements with misleading presentations (such as imitating your phone’s incoming message alert).

Whether you have Mobogenie on your PC or your phone, you should delete Mobogenie with appropriate anti-malware programs as soon as you’ve realized the extent of the situation. Even if, by some unusual circumstance, Mobogenie’s advertisements don’t harm your Web-surfing experiences, its recorded acts of using ‘threat lite’ distribution methods only stress how potentially unsafe this program is.


Adware/Agent [Fortinet]Win32/Mobogenie.B [ESET-NOD32]Adware.NewNextMe [VIPRE]Adware.NextLive.2 [DrWeb]ApplicUnwnt.Win32.NextLive.~A [Comodo]NewNext [Sophos]NSIS:NextLive-A [Adw] [Avast]TROJ_GE.7F9C90F1 [TrendMicro-HouseCall]Adware.NewNextMe.A [MicroWorld-eScan]PE:Trojan.Win32.Generic.16594EEF!374951663 [Rising]

Technical Details

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}.DEFAULT\Software\MobogenieMobogenieAPKFileMobogenieMPKFileSOFTWARE\Classes\MobogenieAPKFileSOFTWARE\Classes\MobogenieMPKFileSoftware\MGinstallSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exeSoftware\MobogenieSOFTWARE\Mobogenie3Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files\MobogenieSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files (x86)\MobogenieSoftware\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files\MobogenieSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\MobogenieSoftware\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files\MobogenieSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAddSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run, value: mobilegeni daemonSOFTWARE\Wow6432Node\Mobogenie3SYSTEM\ControlSet001\services\MgAssistServiceSYSTEM\ControlSet002\services\MgAssistServiceSYSTEM\CurrentControlSet\services\MgAssistServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}MobogenieMobogenie3
Posted: November 15, 2013 | By
Threat Metric
Threat Level: 1/10
Detection Count: 747,303


