Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Android.Spy.3372

Added to the Dr.Web virus database: 2020-05-13

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Spy.635.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) sett####.crashly####.com:443
  • TCP(TLS/1.0) www.google####.com:443
  • TCP(TLS/1.0) md####.google####.com:443
  • TCP(TLS/1.0) and####.cli####.go####.com:443
  • TCP(TLS/1.2) and####.google####.com:443
  • TCP(TLS/1.2) 1####.217.19.195:443
  • TCP(TLS/1.2) 2####.58.208.106:443
  • TCP(TLS/1.2) 1####.217.17.142:443
DNS requests:
  • and####.cli####.go####.com
  • and####.google####.com
  • android####.go####.com
  • app-mea####.com
  • instant####.google####.com
  • m####.go####.com
  • md####.google####.com
  • p####.google####.com
  • sett####.crashly####.com
  • www.google####.com
File system changes:
Creates the following files:
  • /data/data/####/.cl
  • /data/data/####/.jg.ic
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB6299038B-0001-0C96-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FBeginSession.cls
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB629F030B-0001-0D27-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62A2039E-0001-0D9E-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62A60038-0001-0E27-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62AA008C-0001-0E8A-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62AD019B-0001-0EEF-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62B1025C-0001-0F61-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62B5010C-0001-0FD8-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62BA030E-0001-1073-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62BE00D6-0001-10FA-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62C10178-0001-1156-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62C4030A-0001-11D9-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62C702DC-0001-1242-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62CA0270-0001-12A8-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62CE007B-0001-1319-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62D1025A-0001-137A-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62D401B8-0001-13E6-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62D8005A-0001-1447-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62DF00F7-0001-14A0-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62E503AF-0001-151B-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62E80215-0001-1585-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62ED00BA-0001-15F9-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62F10283-0001-1673-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62F602E4-0001-16F9-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62FA013C-0001-174D-C4F5C0BF200FSessionOS.json
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FBeginSession.cls_temp
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FBeginSession.json
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionApp.cls_temp
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionApp.json
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionDevice.cls_temp
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionDevice.json
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionOS.cls_temp
  • /data/data/####/5EBB62FE03A2-0001-1792-C4F5C0BF200FSessionOS.json
  • /data/data/####/K_CONFIG.xml
  • /data/data/####/K_CONFIG.xml.bak
  • /data/data/####/TwitterAdvertisingInfoPreferences.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.dex;classes3.dex
  • /data/data/####/com.crashlytics.prefs.xml
  • /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml.bak
  • /data/data/####/com.mms.mapstsw_preferences.xml
  • /data/data/####/crash_reports-journal
  • /data/data/####/firebase_inter_process_mutex-lock_write_report_...e.lock
  • /data/data/####/initialization_marker
  • /data/data/####/libjiagu.so
  • /data/data/####/metrics_guid
  • /data/data/####/proc_auxv
  • /data/data/####/session_analytics.tap.tmp
Miscellaneous:
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Gets information about incoming/outgoing calls.
Gets information about sent/received SMS.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android