Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Android.SmsSend.20629

Добавлен в вирусную базу Dr.Web: 2017-07-14

Описание добавлено:

Technical information

Malicious functions:
Sends SMS messages:
  • 10086: 40411
  • 10658000: XDQYWH
  • 1065842232: BN2[bbbbDlDznvAFKzGC0DDDkD_zbbxcvT>CUvb+DX9{DXbHC?GYIqM)8Qbu7bnqiDHbFFFbFb>bb&0bbbP3AJrUa:]PxE75j M0bM3+d)/Ieb=
  • 10658423: mvwlan,e250c528fb9d92be3e7f2af183102278,BlQg
  • 106585765001: KTDY5
  • 10662566: 16
Network activity:
Connecting to:
  • 1####.####.147
  • 1####.####.147:8080
  • 1####.####.91
  • 1####.####.91:8080
  • a####.####.com
  • a####.####.top
  • oa5cv####.####.com
  • p####.####.com
  • p####.####.com:8080
HTTP GET requests:
  • 1####.####.147/xmld/HttpService!service?paramMap=####
  • 1####.####.91/mm/HttpService!service?paramMap=####
  • 1####.####.91:8080/xad/resService!service?paramMap=####
  • a####.####.top/apk/xiuc03.apk
  • a####.####.top/getApk/xiuc03/xiuc03/apk/ruk
  • oa5cv####.####.com/ic_clsb3.png
  • p####.####.com/res/novel/app/content/9.txt
  • p####.####.com:8080/res/novel/app/content/3.txt
HTTP POST requests:
  • 1####.####.147:8080/xmld/HttpService
  • a####.####.com/app_logs
Modified file system:
Creates the following files:
  • <Package Folder>/app_payload_odex/<Package>.jar
  • <Package Folder>/app_process_lock/1122152074160.98
  • <Package Folder>/app_process_lock/1122152074160.98 (deleted)
  • <Package Folder>/app_process_lock/1122152074429.4
  • <Package Folder>/app_process_lock/1122152074429.4 (deleted)
  • <Package Folder>/app_process_lock/1122152074441.02
  • <Package Folder>/app_process_lock/1122152074441.02 (deleted)
  • <Package Folder>/app_process_lock/1122152074447.53
  • <Package Folder>/app_process_lock/1122152074447.53 (deleted)
  • <Package Folder>/app_process_lock/1122152074621.09
  • <Package Folder>/app_process_lock/1122152074621.09 (deleted)
  • <Package Folder>/app_process_lock/1122152074656.47
  • <Package Folder>/app_process_lock/1122152074656.47 (deleted)
  • <Package Folder>/app_process_lock/1122152074937.75
  • <Package Folder>/app_process_lock/1122152074937.75 (deleted)
  • <Package Folder>/app_process_lock/1132.30089999093
  • <Package Folder>/app_process_lock/1132.30089999093 (deleted)
  • <Package Folder>/app_process_lock/1132.34542065845
  • <Package Folder>/app_process_lock/1132.34542065845 (deleted)
  • <Package Folder>/app_process_lock/1132.38994132597
  • <Package Folder>/app_process_lock/1132.38994132597 (deleted)
  • <Package Folder>/app_process_lock/1132.43446199348
  • <Package Folder>/app_process_lock/1132.43446199348 (deleted)
  • <Package Folder>/app_process_lock/1132.478982661
  • <Package Folder>/app_process_lock/1132.478982661 (deleted)
  • <Package Folder>/app_process_lock/1132.52350332852
  • <Package Folder>/app_process_lock/1132.52350332852 (deleted)
  • <Package Folder>/app_process_lock/1132.56802399603
  • <Package Folder>/app_process_lock/1132.56802399603 (deleted)
  • <Package Folder>/app_process_lock/161.918512514603
  • <Package Folder>/app_process_lock/161.918512514603 (deleted)
  • <Package Folder>/app_process_lock/2325853024547.37
  • <Package Folder>/app_process_lock/2325853024547.37 (deleted)
  • <Package Folder>/app_process_lock/2325853025432.34
  • <Package Folder>/app_process_lock/2325853025432.34 (deleted)
  • <Package Folder>/app_process_lock/2325853025913.84
  • <Package Folder>/app_process_lock/2325853025913.84 (deleted)
  • <Package Folder>/app_process_lock/2325853026432.46
  • <Package Folder>/app_process_lock/2325853026432.46 (deleted)
  • <Package Folder>/app_process_lock/2325853026608.61
  • <Package Folder>/app_process_lock/2325853026608.61 (deleted)
  • <Package Folder>/app_process_lock/2325853027038.83
  • <Package Folder>/app_process_lock/2325853027038.83 (deleted)
  • <Package Folder>/app_process_lock/2325853031158.53
  • <Package Folder>/app_process_lock/2325853031158.53 (deleted)
  • <Package Folder>/app_process_lock/261210484284.692
  • <Package Folder>/app_process_lock/261210484284.692 (deleted)
  • <Package Folder>/app_process_lock/261210484384.081
  • <Package Folder>/app_process_lock/261210484384.081 (deleted)
  • <Package Folder>/app_process_lock/261210484438.157
  • <Package Folder>/app_process_lock/261210484438.157 (deleted)
  • <Package Folder>/app_process_lock/261210484496.401
  • <Package Folder>/app_process_lock/261210484496.401 (deleted)
  • <Package Folder>/app_process_lock/261210484516.184
  • <Package Folder>/app_process_lock/261210484516.184 (deleted)
  • <Package Folder>/app_process_lock/261210484564.501
  • <Package Folder>/app_process_lock/261210484564.501 (deleted)
  • <Package Folder>/app_process_lock/261210485027.174
  • <Package Folder>/app_process_lock/261210485027.174 (deleted)
  • <Package Folder>/app_process_lock/2965462630575.29
  • <Package Folder>/app_process_lock/2965462630575.29 (deleted)
  • <Package Folder>/app_process_lock/2965462631284.64
  • <Package Folder>/app_process_lock/2965462631284.64 (deleted)
  • <Package Folder>/app_process_lock/2965462631315.36
  • <Package Folder>/app_process_lock/2965462631315.36 (deleted)
  • <Package Folder>/app_process_lock/2965462631332.56
  • <Package Folder>/app_process_lock/2965462631332.56 (deleted)
  • <Package Folder>/app_process_lock/2965462631791.23
  • <Package Folder>/app_process_lock/2965462631791.23 (deleted)
  • <Package Folder>/app_process_lock/2965462631884.73
  • <Package Folder>/app_process_lock/2965462631884.73 (deleted)
  • <Package Folder>/app_process_lock/2965462632628.04
  • <Package Folder>/app_process_lock/2965462632628.04 (deleted)
  • <Package Folder>/app_process_lock/4666917.8413941
  • <Package Folder>/app_process_lock/4666917.8413941 (deleted)
  • <Package Folder>/app_process_lock/4666918.14184867
  • <Package Folder>/app_process_lock/4666918.14184867 (deleted)
  • <Package Folder>/app_process_lock/668266.292786374
  • <Package Folder>/app_process_lock/668266.292786374 (deleted)
  • <Package Folder>/app_process_lock/690289620898.487
  • <Package Folder>/app_process_lock/690289620898.487 (deleted)
  • <Package Folder>/app_process_lock/690289621161.138
  • <Package Folder>/app_process_lock/690289621161.138 (deleted)
  • <Package Folder>/app_process_lock/690289621304.042
  • <Package Folder>/app_process_lock/690289621304.042 (deleted)
  • <Package Folder>/app_process_lock/690289621457.963
  • <Package Folder>/app_process_lock/690289621457.963 (deleted)
  • <Package Folder>/app_process_lock/690289621510.242
  • <Package Folder>/app_process_lock/690289621510.242 (deleted)
  • <Package Folder>/app_process_lock/690289621637.927
  • <Package Folder>/app_process_lock/690289621637.927 (deleted)
  • <Package Folder>/app_process_lock/690289622860.613
  • <Package Folder>/app_process_lock/690289622860.613 (deleted)
  • <Package Folder>/app_process_lock/889.37042982576
  • <Package Folder>/app_process_lock/889.37042982576 (deleted)
  • <Package Folder>/app_process_lock/889.414950493276
  • <Package Folder>/app_process_lock/889.414950493276 (deleted)
  • <Package Folder>/app_process_lock/889.459471160793
  • <Package Folder>/app_process_lock/889.459471160793 (deleted)
  • <Package Folder>/app_process_lock/889.503991828309
  • <Package Folder>/app_process_lock/889.503991828309 (deleted)
  • <Package Folder>/app_process_lock/889.548512495826
  • <Package Folder>/app_process_lock/889.548512495826 (deleted)
  • <Package Folder>/app_process_lock/889.593033163343
  • <Package Folder>/app_process_lock/889.593033163343 (deleted)
  • <Package Folder>/app_process_lock/889.637553830859
  • <Package Folder>/app_process_lock/889.637553830859 (deleted)
  • <Package Folder>/app_process_lock/889.682074498376
  • <Package Folder>/app_process_lock/889.682074498376 (deleted)
  • <Package Folder>/app_process_lock/889.726595165892
  • <Package Folder>/app_process_lock/889.726595165892 (deleted)
  • <Package Folder>/databases/cc.db
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/databases/ua.db
  • <Package Folder>/databases/ua.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/xUtils_http_cache.db
  • <Package Folder>/databases/xUtils_http_cache.db-journal
  • <Package Folder>/databases/xUtils_http_cache.db-journal (deleted)
  • <Package Folder>/databases/xUtils_http_cookie.db
  • <Package Folder>/databases/xUtils_http_cookie.db-journal
  • <Package Folder>/databases/xUtils_http_cookie.db-journal (deleted)
  • <Package Folder>/files/####/exchangeIdentity.json
  • <Package Folder>/files/.imprint
  • <Package Folder>/files/exid.dat
  • <Package Folder>/files/umeng_it.cache
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <SD-Card>/Android/####/01b00af66ffcf44877a9a7ff38c8ae53
  • <SD-Card>/Android/####/031f04ef44c86d37888b9206208ab7ff
  • <SD-Card>/Android/####/110b6dcd7a403d3581b21c2d9d50f95c
  • <SD-Card>/Android/####/300f50dfb16e035d7ba2ebd4753b36b8
  • <SD-Card>/Android/####/462c6fe262fbb413352a85f2a5d6ec4c
  • <SD-Card>/Android/####/4ad58299b25cbab8661f9b6373c57b49
  • <SD-Card>/Android/####/614b01e4628d6b78f36743a3105948fe
  • <SD-Card>/Android/####/641396e85bf54468fe7cee3296fab1be
  • <SD-Card>/Android/####/64b32d73ebb72859c154bc9c1afcdf8c
  • <SD-Card>/Android/####/725237df2d775b9a6b82760a4923d8d1
  • <SD-Card>/Android/####/897f47697ee1e6f740a2bff65a9d1b9e
  • <SD-Card>/Android/####/8acf08558ad9a62966ddb70b9a7b29a0
  • <SD-Card>/Android/####/b3962df18972e8e0a65f0050fa10cfce
  • <SD-Card>/Android/####/f78ec8f63034be09a6a028f3a8214882
  • <SD-Card>/Android/1.txt.tmp
  • <SD-Card>/Android/10.txt.tmp
  • <SD-Card>/Android/11.txt.tmp
  • <SD-Card>/Android/12.txt.tmp
  • <SD-Card>/Android/13.txt.tmp
  • <SD-Card>/Android/14.txt.tmp
  • <SD-Card>/Android/15.txt.tmp
  • <SD-Card>/Android/16.txt
  • <SD-Card>/Android/2.txt
  • <SD-Card>/Android/3.txt.tmp
  • <SD-Card>/Android/4.txt.tmp
  • <SD-Card>/Android/5.txt.tmp
  • <SD-Card>/Android/6.txt.tmp
  • <SD-Card>/Android/7.txt
  • <SD-Card>/Android/8.txt.tmp
  • <SD-Card>/Android/9.txt.tmp
  • <SD-Card>/Android/com.mmzb.wrw.yol.png.tmp
  • <SD-Card>/Android/com.mzb.wriw.hgtseeiooui.apk.tmp
  • <SD-Card>/Android/com.mzb.wriw.hgtseeiooui.png.tmp
  • <SD-Card>/dp.jar.tmp
  • <SD-Card>/updateApkDemo/FrameCore.jar
Miscellaneous:
Executes next shell scripts:
  • <dexopt>
  • <su-internal:request>
  • <su-internal:result>
  • app_process /system/bin com.android.commands.pm.Pm install -r /system/app/com.mzb.wriw.hgtseeiooui.apk
  • chmod 644 /system/app/com.mzb.wriw.hgtseeiooui.apk
  • cp /storage/emulated/0/Android/com.mzb.wriw.hgtseeiooui.apk /system/app/
  • mount -o rw,remount /system
  • sh
  • su
Uses elevated priveleges.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке