Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.23889

Добавлен в вирусную базу Dr.Web: 2017-06-28

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.HiddenAds.125.origin
Загружает из Интернета следующие детектируемые угрозы:
  • Android.HiddenAds.125.origin
Сетевая активность:
Подключается к:
  • a####.####.com
  • a####.####.org
  • admobim####.com
  • ap####.####.com
  • b####.com
  • d####.####.com
  • i####.####.com
  • j####.####.com
  • m####.####.com
  • mmmmmm####.com
  • p####.####.com
  • panda####.####.com
  • pl####.####.com
  • poket####.com
  • r####.####.com
  • real####.####.org
  • s####.####.com
  • st####.####.ly
  • t####.####.info
  • trackme####.com
  • u####.####.com
Запросы HTTP GET:
  • a####.####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=####&sd...
  • a####.####.org/rule?platform=####&os_version=####&package_name=####&app_...
  • b####.com/notifications/render?bnptrigger=####&IG=####&IID=####
  • d####.####.com/M01/01/AB/CvJMDVlCXICAY6YrAAVgxKJvq9E665.zip
  • i####.####.com/tiezhi/2017/02/24/a61ec39141ae4408ade900f114c3bc77_icon.png
  • j####.####.com/?s1=####&noaudio=####&noalert=####&noexit=####&nodl=####&...
  • p####.####.com/da2Y_n84HwxbcnIOTn4QMyNm2DQ=/filters:format(webp)/2017/03...
  • poket####.com/d/23304208e4c0b615b67?sub=####
  • r####.####.com/2017/03/22/9d145dc1b3524f758cea90daf2f4de3a.zip
  • real####.####.org/realtime?platform=####&os_version=####&package_name=##...
  • st####.####.ly/themes/metronic3/assets/frontend/site/index/prod/20151027...
  • t####.####.info/click?_type=####&sdk_redir=####&campid=####&sub_channel=...
  • trackme####.com/r/fb3c61cc-5bbe-11e7-9289-1142236d81fb/0/
  • u####.####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&prod...
Запросы HTTP POST:
  • admobim####.com/surl/api2_reg.action
  • ap####.####.com/api2.ashx
  • m####.####.com/detail/getOfferListNew?enc=####
  • mmmmmm####.com/osp/oaen_reg.action
  • panda####.####.com/action.ashx/wallpaperaction/4017
  • pl####.####.com/ad_dex.php
  • s####.####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.mbj/####/classes.zip
  • <Package Folder>/cache/####/-8SYRxNOZ6qkz8FfzOnBPj3971c.23456374.tmp
  • <Package Folder>/cache/####/-U99IHnAtDH575rGcf7m4moVFvc.-1792434648.tmp
  • <Package Folder>/cache/####/-Xp5yQW4Zx2OK_LH4ws5wz3fjpw.1650331722.tmp
  • <Package Folder>/cache/####/-xSngEHfaHxCBG47xrfZ-mX0Akw.213685169.tmp
  • <Package Folder>/cache/####/0kSuA0ZInQGyuQMSqSw0eK4aK_I.59582231.tmp
  • <Package Folder>/cache/####/1icYiyoJkQJJlZ1a69e0nH2i7uc.-757525254.tmp
  • <Package Folder>/cache/####/2OnJDs8KrvqUMiaR161xSNvIz9A.-1121360383.tmp
  • <Package Folder>/cache/####/3XSwoTPVfH3dAPHqtK2ffxgPzuA.-757638024.tmp
  • <Package Folder>/cache/####/4zMK_Bs6n8l5mOYzhGv3Ibe67oA.1854208883.tmp
  • <Package Folder>/cache/####/50KP1NKBpfPI3EmL_zuHxAFdtWo.-3426229.tmp
  • <Package Folder>/cache/####/5CUkG8LnEjZ4Az379JB4DsjqT9Q.95296462.tmp
  • <Package Folder>/cache/####/6TVu4jvd0xHXYHGAUrBuH47voDA.-992605477.tmp
  • <Package Folder>/cache/####/6U1MAS5W_3AGW37rZPjcLCQYD1M.1524400723.tmp
  • <Package Folder>/cache/####/8s1ucVFYvDD2rHL6txvx1IZl4L0.513775266.tmp
  • <Package Folder>/cache/####/9KREQLvwM08M3iDvbj7uqNtc6uE.-913420164.tmp
  • <Package Folder>/cache/####/9axAOcs301ovaUCk_gbSuElkSkU.-552229079.tmp
  • <Package Folder>/cache/####/9v9NvTCmhXXxVGDXsv-p8dxFheM.-255562815.tmp
  • <Package Folder>/cache/####/APrC000StKwc0taeNeCTjEyg26U.954233300.tmp
  • <Package Folder>/cache/####/Aj01tusLMrCVgv-jmDu9qu1mQo0.-1837661248.tmp
  • <Package Folder>/cache/####/C74LOEQSvvRs5bFZmntln_UoAwg.607491784.tmp
  • <Package Folder>/cache/####/CXMSBlpGB9wUzuzTO7nUPPUMMlA.807321757.tmp
  • <Package Folder>/cache/####/CbA3v4ZH4lsxaknS9Gt0D23_81U.90452052.tmp
  • <Package Folder>/cache/####/CesHH9xhiG9VlPZ5mWcQyhDwG5U.-118020749.tmp
  • <Package Folder>/cache/####/DAGlD4EeW_N4yevwI92y_SZpdbg.-1260967262.tmp
  • <Package Folder>/cache/####/DSn0tYe2ocGcDbR8kMGyEwLn6Is.616190811.tmp
  • <Package Folder>/cache/####/DeEThP1Ve9YE9HOYdKAHF7Pdbv4.170180408.tmp
  • <Package Folder>/cache/####/DhXe49VcBxOg6bggF5bdnL5w6s0.491497413.tmp
  • <Package Folder>/cache/####/Di55OGMFf6B-Cz8qkxC9eBNldp8.567833317.tmp
  • <Package Folder>/cache/####/DjlSmnO8eX1g_-gTuLhn8wTLLNs.950769943.tmp
  • <Package Folder>/cache/####/E9U5rZrpCK9rcLuoVaokJLEO3ps.-642828900.tmp
  • <Package Folder>/cache/####/EpuqiRaupzlFwZ-1bH4NtmQZsHk.169289333.tmp
  • <Package Folder>/cache/####/FI-VkgjMXwj7i036H5LCfVwJ-Fk.-590589623.tmp
  • <Package Folder>/cache/####/Fm-UiMr8ad7j2O97wMOWXYMpQFA.182906104.tmp
  • <Package Folder>/cache/####/GElnCm5obZc_o-WM2J26BUN3Ufs.-60023649.tmp
  • <Package Folder>/cache/####/H1e8_TeDZkV13Ws4CMzFW4fKuMQ.-883916422.tmp
  • <Package Folder>/cache/####/HoE3KzzNuPYaio3Cpk8e-1vFbjo.1369062695.tmp
  • <Package Folder>/cache/####/IlALKgUKmJkzzUNbBygkFFHszVU.823885173.tmp
  • <Package Folder>/cache/####/IvziHcAPu_eE1BsXXTFOKQmEsVU.978528662.tmp
  • <Package Folder>/cache/####/JrBD5gYhHwKCAr920DCZc8GEYaM.-95944826.tmp
  • <Package Folder>/cache/####/KNGzMKWCno503jM-BjZYYuQw3pU.1023065740.tmp
  • <Package Folder>/cache/####/L7tJ2ArEHgl0BaV-YPsoH1iXVs0.1187562423.tmp
  • <Package Folder>/cache/####/LGAWSJLXUXYO3KAl7LW0DtoiQfY.-1550962533.tmp
  • <Package Folder>/cache/####/LOQbFyEHWR6eEgNAVRqTNipa10Q.1782776716.tmp
  • <Package Folder>/cache/####/LcQS_HmYoWcEkNP_V5mEr85X7_0.-1149380361.tmp
  • <Package Folder>/cache/####/Mcnom4vRPtcq5bkuhLubxA8vFFI.-387558705.tmp
  • <Package Folder>/cache/####/MjGi4lBrbJvRXIr9gMrJjV-9GT4.-808943164.tmp
  • <Package Folder>/cache/####/N3sDw0ZFLtIJw8u_Map9C3Pcg3g.1280466003.tmp
  • <Package Folder>/cache/####/N87w8pIS-fnWv5jdkjTW7__k8zY.-1793558330.tmp
  • <Package Folder>/cache/####/NBTeUIEG3qjZQITu-uEXJ8qyHH0.-373009449.tmp
  • <Package Folder>/cache/####/O-bmsytYgmW8738nrNWRzHrLJfo.-783832382.tmp
  • <Package Folder>/cache/####/OGmMj5sDUcHooLZ72ZLkMmK1FJY.1779298031.tmp
  • <Package Folder>/cache/####/OLOZ6Y6fnkmJeJTrDV3wkmN7_Dc.-1014201179.tmp
  • <Package Folder>/cache/####/OjC4K00wusorNPRv45ntPthvbnY.754782534.tmp
  • <Package Folder>/cache/####/P3MFoS0Vy-jiKn2ay1rixx7FOXQ.-308071103.tmp
  • <Package Folder>/cache/####/PBacLDQCica8u4ZYIi9F-5f1-qk.484427319.tmp
  • <Package Folder>/cache/####/PXQbWzsCoMl6VyQQVTxYxea6CoU.-458126547.tmp
  • <Package Folder>/cache/####/PvVjUJ7oyyxeZJotihchRSK7kv8.2132943108.tmp
  • <Package Folder>/cache/####/QaESpJOicJ3B_DjdtVDHMwSHz2Q.2112209085.tmp
  • <Package Folder>/cache/####/R31REyat3Zh91lVlWaY9tCYZIac.-1956808270.tmp
  • <Package Folder>/cache/####/RtkA1dwDl9SziLsP0mrrdmPEki4.-301916773.tmp
  • <Package Folder>/cache/####/SD-YolZYfBnKnYh7LjikE0ioJJI.1703953995.tmp
  • <Package Folder>/cache/####/SXVaniNqLv3OyAm5v-_jJV5b9VI.343951587.tmp
  • <Package Folder>/cache/####/SdtLJITOh_HUjTH_4BZrSfLfdBo.236468133.tmp
  • <Package Folder>/cache/####/ShFEdJmHwF3xqHXy4esTgNLDLw8.915473897.tmp
  • <Package Folder>/cache/####/Sy4M8GZS6vN2T8dshcUZn2Jwrbg.-158732577.tmp
  • <Package Folder>/cache/####/T6UbB7rfNq9aQwzP3aDkD2-9-y0.420445789.tmp
  • <Package Folder>/cache/####/TXOvdhGWk1LW5SP-EEDi_TPTQow.-252135178.tmp
  • <Package Folder>/cache/####/TdNwRvkYxH3nLBVUad-dr3rdg3M.-329923035.tmp
  • <Package Folder>/cache/####/TyzGYW8X1P9xd_6zPn8OrvvRZ_g.960277473.tmp
  • <Package Folder>/cache/####/Vn7t6NWxa0LHdUsWsd4x8zYGpHU.-1468304666.tmp
  • <Package Folder>/cache/####/VokEUcj-DHZChQWrxUDjazS-BqI.-479880389.tmp
  • <Package Folder>/cache/####/VrgjM02WG65cmmZC8uPHHi8WyRs.-47137056.tmp
  • <Package Folder>/cache/####/Vz1A-ft5Bb-jKOvwYKKtiVXb1ng.1695545343.tmp
  • <Package Folder>/cache/####/W1b5waAITY9eLKo4pirFNYzihvw.1345763792.tmp
  • <Package Folder>/cache/####/W8n6uvNjWNPx9Ou4nDv7c_VoQIc.1432769864.tmp
  • <Package Folder>/cache/####/Wp0sK9ljyoM8HdQOgQPzHf-ZuvQ.-1413853120.tmp
  • <Package Folder>/cache/####/WxLjEcyB6THO0dKFx5-vC04UT6k.-1771857163.tmp
  • <Package Folder>/cache/####/X4HNN4qobdz2in7DZaepwVCR3G0.1242250598.tmp
  • <Package Folder>/cache/####/XTfNUGNMy5HC6G87gzJm81HUK44.107609525.tmp
  • <Package Folder>/cache/####/XdT5mIlDuE7pmUH_U47adnAHfDY.2112356229.tmp
  • <Package Folder>/cache/####/XnpWrehy3anfutuL4lM4X96MvNE.1221467038.tmp
  • <Package Folder>/cache/####/YOWvJb2sS_taCGW2p2xw_t7dd2s.388220648.tmp
  • <Package Folder>/cache/####/YSdg90mW4nYfBo6mUS7Lqh5ofgo.-1251694108.tmp
  • <Package Folder>/cache/####/Yg-K8NfceGGvq5P_mqDP7EB3PC4.-624474031.tmp
  • <Package Folder>/cache/####/ZKDju76YkUlJEiYz2hagZCUrudA.-1941574534.tmp
  • <Package Folder>/cache/####/ZVdngtYaxDbzkHo8XoFdIfEt9hQ.2139132350.tmp
  • <Package Folder>/cache/####/aLMT04GKop1WUeCqfI8piTMdTqg.-1067152695.tmp
  • <Package Folder>/cache/####/ayTK83SY156h80sjcFZ4UIUAngA.1832340083.tmp
  • <Package Folder>/cache/####/az86DMLrFks88azBUgrkfwKgiXY.-474601229.tmp
  • <Package Folder>/cache/####/bxMsFjT9p5PzDxDqkKeSC1JBp_E.-134519566.tmp
  • <Package Folder>/cache/####/c5RR9TCTNwe909ReN_G09H1QMpQ.-493862591.tmp
  • <Package Folder>/cache/####/c9YumsejDTTS5wmZ4YDA0C-nqTQ.-1034596717.tmp
  • <Package Folder>/cache/####/ckWG9hdHn677M_21mAusvpKt9iA.-1104441318.tmp
  • <Package Folder>/cache/####/d-pWkggFzDjG4KxmayWjVQNfipw.-554937043.tmp
  • <Package Folder>/cache/####/dVaRBza1QEWYEF7XmVXCJ16FcRA.43505788.tmp
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/do191waq0TspgQyEl_-8vjorOCU.1283536534.tmp
  • <Package Folder>/cache/####/dx_Gp6X61rWC0BGJzq4GLqNNVzQ.-143485098.tmp
  • <Package Folder>/cache/####/fBvB9dSrbtACwJpY1ejB7tesnJM.-1375864895.tmp
  • <Package Folder>/cache/####/fLr6ixQlKdCkUmsCholB8OVqG8c.378602758.tmp
  • <Package Folder>/cache/####/fSEnJ4PIP-xaRD0YxLHTEHmSvpI.-2074502595.tmp
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/fcYFMIMh_fNf5-aKTa6_OaEuvkM.544350760.tmp
  • <Package Folder>/cache/####/fiw5jtT6AUj_VwJ9rVNvvw8h_Ic.-1576190197.tmp
  • <Package Folder>/cache/####/folVcrWHoBpvr81qprjM527IdbE.-1318390601.tmp
  • <Package Folder>/cache/####/gFOXplRe_b301sh7s94o-vhmuyU.-1058418376.tmp
  • <Package Folder>/cache/####/hOBjA3krYe0rZqUmW25OATCY1TY.-2119770500.tmp
  • <Package Folder>/cache/####/hZ6mN9fad6XdsA8cmrfh5lQIxCQ.1210509486.tmp
  • <Package Folder>/cache/####/ih4DcTyBNYn8Jb91ju-PltCT3X0.-1610977623.tmp
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/j2qGUw-cfBeSY23Karcb6lb5z7g.-354877857.tmp
  • <Package Folder>/cache/####/k5V0JqhfKXudSjj_wRLqbxOpY2k.1778709092.tmp
  • <Package Folder>/cache/####/kH5BuL3d9ebOd2peJLieSx_pH40.1985735423.tmp
  • <Package Folder>/cache/####/kVy0qvZjMpEDMgUBNPuQgJW3vKE.-814339630.tmp
  • <Package Folder>/cache/####/kZhSUUmZHerR3mzCaUr_0QfFh7c.708202210.tmp
  • <Package Folder>/cache/####/l-Vkzb-G6xpt_MLpY6SziLWXjbE.1610389441.tmp
  • <Package Folder>/cache/####/lFUK2pATSCUqbsriEnQpZ2JWH2o.-823919177.tmp
  • <Package Folder>/cache/####/lIV8x3ENg6ceNtahzc_JxDlinTw.991833593.tmp
  • <Package Folder>/cache/####/lU4MGPFV90a9d2RG18gLRpiNqHc.-1055350981.tmp
  • <Package Folder>/cache/####/lqgn7aJgeZQyUA9Oe7F7QdE3K9c.-320663165.tmp
  • <Package Folder>/cache/####/mDTFoF0WO3pqjWPz0CN-lu_itw4.-953003879.tmp
  • <Package Folder>/cache/####/mJenXc4RX2Ml3yiPv4RU-bX9Hzw.-2102709275.tmp
  • <Package Folder>/cache/####/mLqH5LxhEdHn0lK6Sc0JPU28ox0.478761653.tmp
  • <Package Folder>/cache/####/mnERag6gUUqetuv4xkSP0fRzn3A.817500108.tmp
  • <Package Folder>/cache/####/n1pcOC6xq7LeQN7q6ofefsqAZIA.256227788.tmp
  • <Package Folder>/cache/####/oH30LPMYb7QEpQOy4tyrE0ii9DU.-587839895.tmp
  • <Package Folder>/cache/####/oUnLneo88Voj5p5KpoIn5UF4QcQ.-1796230208.tmp
  • <Package Folder>/cache/####/o_Z3dJWxRutBoag14mzFNw3i3-Y.316867329.tmp
  • <Package Folder>/cache/####/okHgriwSZNeJnKlFEzegxBFbmMo.-1735370886.tmp
  • <Package Folder>/cache/####/pdZQTENByrTp2EkZ1j0oiuzxvPg.912590995.tmp
  • <Package Folder>/cache/####/pgBmAip3WkpDhnRZtuX1WlRJpes.412769541.tmp
  • <Package Folder>/cache/####/puzc6pHT3JJElkCfRAEtw3Tt3GA.-334519517.tmp
  • <Package Folder>/cache/####/q6Kuu2wy9tK8XyDWJRPCXlKW59k.1671150690.tmp
  • <Package Folder>/cache/####/rkdMuGfvKeA8u0lCP2-3aI-42B0.760860908.tmp
  • <Package Folder>/cache/####/rr6EP0SfMWN3bnHxaR8iCHvnxCY.879283991.tmp
  • <Package Folder>/cache/####/sH_wuu5DNSGB1Ro-cD64mgGPGIM.737130124.tmp
  • <Package Folder>/cache/####/sRXZlmvLYivYHZfRgeP-44IftBw.1803354348.tmp
  • <Package Folder>/cache/####/sSUSCyEZgUc-m5A9VF1RlKUE7lk.-2127473748.tmp
  • <Package Folder>/cache/####/sSby8x6MH91797FQteJDdYnoTxQ.1687832920.tmp
  • <Package Folder>/cache/####/sfnosvy_iHsaP_ZY3QFvHINsoIs.-273411384.tmp
  • <Package Folder>/cache/####/snTc4gtouyl2yDZzP5IDIrGoG0I.-1434965054.tmp
  • <Package Folder>/cache/####/spguWtIy3aMVejyVIsK1S0cA46A.744670763.tmp
  • <Package Folder>/cache/####/tK7Jdwm5PsMAU7OMVFQ1Cu2tNyk.-456372425.tmp
  • <Package Folder>/cache/####/tP1Lb2iA_TMOEIXALEfUplXQrDA.-1336887735.tmp
  • <Package Folder>/cache/####/tZOGUylWA9QlHm1wpqQZiTD30uU.1127943246.tmp
  • <Package Folder>/cache/####/tf0wsub50ANEhkic8YWzfiH9AE4.863045965.tmp
  • <Package Folder>/cache/####/u5rGJ2Q9dpk1ADoL0YVmcUdbBdU.-1185792840.tmp
  • <Package Folder>/cache/####/uBbyZ8ZZDQIu3wx6yDEiizahKus.-493413715.tmp
  • <Package Folder>/cache/####/wTk1F-ygf2tnvsnz-0_L1gs2kak.-593832569.tmp
  • <Package Folder>/cache/####/w__xWDL27kOn2WitQjSIlaGFOvk.-1424639647.tmp
  • <Package Folder>/cache/####/x3zGZNYHJUa6s8R0Z5AGEjPrANA.1259752732.tmp
  • <Package Folder>/cache/####/yY59j091eKuLYphENkuuFDSydrc.-1630923320.tmp
  • <Package Folder>/cache/####/zhscxOy_9En5GiUmHaJMMV_E1Og.1056280338.tmp
  • <Package Folder>/cache/####/zvvkMKq9UDwdVGN15OYj5UXI3eY.1758146146.tmp
  • <Package Folder>/cache/1478228129219.jar
  • <Package Folder>/cache/1478228129219.tmp
  • <Package Folder>/cache/ApplicationCache.db-journal (deleted)
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes-363648989.zip
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes1069955533.zip
  • <Package Folder>/databases/91analytics_v4.db
  • <Package Folder>/databases/91analytics_v4.db-journal
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/arrkii.asa.sdk.db-journal
  • <Package Folder>/databases/my.db-journal
  • <Package Folder>/databases/trafficmonestats_v4.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
  • <Package Folder>/files/google.db
  • <Package Folder>/shared_prefs/91Analytics_Config.xml
  • <Package Folder>/shared_prefs/91Analytics_Config.xml.bak
  • <Package Folder>/shared_prefs/ActivatePreUtil.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/LoginPreUtil.xml
  • <Package Folder>/shared_prefs/RESOURCE_LIST.xml
  • <Package Folder>/shared_prefs/SSPPrefe.xml
  • <Package Folder>/shared_prefs/SSPPrefe.xml.bak
  • <Package Folder>/shared_prefs/admob.xml
  • <Package Folder>/shared_prefs/adsdk.xml
  • <Package Folder>/shared_prefs/adsdk.xml.bak
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml.bak
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/shared_prefs/apsad.xml.bak
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/shared_prefs/batsdk_app_life.xml
  • <Package Folder>/shared_prefs/batsdk_crash_switch.xml
  • <Package Folder>/shared_prefs/batsdk_user_info.xml
  • <Package Folder>/shared_prefs/device_info.xml
  • <Package Folder>/shared_prefs/hunter_config.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/other_config.xml
  • <Package Folder>/shared_prefs/service_config.xml
  • <Package Folder>/shared_prefs/service_config.xml.bak
  • <Package Folder>/shared_prefs/sp_config.xml
  • <Package Folder>/shared_prefs/t_ini.xml
  • <SD-Card>/.androidsystem/####/49.x-3.0.1.apk
  • <SD-Card>/.androidsystem/####/PlugShareData
  • <SD-Card>/.androidsystem/####/files.db
  • <SD-Card>/.androidsystem/####/gads.db
  • <SD-Card>/.androidsystem/####/plugxml.xml
  • <SD-Card>/.androidsystem/####/syncfiles.db
  • <SD-Card>/.androidsystem/Plugin.zip
  • <SD-Card>/Android/####/.nomedia
  • <SD-Card>/Android/####/0.png
  • <SD-Card>/Android/####/1.png
  • <SD-Card>/Android/####/2.png
  • <SD-Card>/Android/####/21551d6ae40a64cc74137ae387f2f912.zip
  • <SD-Card>/Android/####/3.png
  • <SD-Card>/Android/####/4.png
  • <SD-Card>/Android/####/4c783eef95398d09641e069749b06f29.zip
  • <SD-Card>/Android/####/5.png
  • <SD-Card>/Android/####/c005225a619b7fb0ebc93c71a717073c.zip
  • <SD-Card>/Android/####/collage_list.json
  • <SD-Card>/Android/####/preview.png
  • <SD-Card>/Android/####/profile.plist
  • <SD-Card>/DCIM/####/1496213085869.jpg
  • <SD-Card>/DCIM/####/1496213126389.jpg
  • <SD-Card>/LogN/####/sp
  • <SD-Card>/baidu/####/journal.tmp
  • <SD-Card>/baidu/.cuid
Другие:
Запускает следующие shell-скрипты:
  • <dexopt>

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке