マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.DownLoader.1904

Added to the Dr.Web virus database: 2017-03-15

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.HiddenAds.79.origin
Downloads the following detected threats from the Web:
  • Android.HiddenAds.79.origin
Network activity:
Connecting to:
  • c####.####.com
  • xml-epg####.####.ru
  • f####.####.ru
  • a####.####.com
HTTP GET requests:
  • f####.####.ru/beevideo/100x100/otr.png
  • f####.####.ru/beevideo/100x100/kultura_3.png
  • xml-epg####.####.ru/EPGService/hs/epg/pic/276988
  • xml-epg####.####.ru/EPGService/hs/epg/pic/310089
  • f####.####.ru/beevideo/100x100/5_3.png
  • f####.####.ru/beevideo/100x100/ort_3.png
  • a####.####.com/api/ads/check?md5=####&secret=####&app_v=####&app=####&ch=####&key=####&
  • xml-epg####.####.ru/EPGService/hs/epg/pic/571517
  • f####.####.ru/beevideo/100x100/karusel_3.png
  • f####.####.ru/beevideo/100x100/tvm_2.png
  • f####.####.ru/beevideo/100x100/tv_centr.png
  • f####.####.ru/beevideo/100x100/match.png
  • xml-epg####.####.ru/EPGService/hs/epg/pic/175069
  • xml-epg####.####.ru/EPGService/hs/epg/pic/397214
  • xml-epg####.####.ru/EPGService/hs/epg/pic/53804
  • xml-epg####.####.ru/EPGService/hs/epg/pic/282633
  • f####.####.ru/beevideo/100x100/ros1_3.png
  • xml-epg####.####.ru/EPGService/hs/epg/pic/123048
  • f####.####.ru/beevideo/100x100/ntv_3.png
  • xml-epg####.####.ru/EPGService/hs/epg/pic/374896
  • f####.####.ru/beevideo/100x100/ros24_3.png
  • c####.####.com/files/9449bcb5201aeb0502ec952a50416abb
  • xml-epg####.####.ru/EPGService/hs/epg/pic/688391
HTTP POST requests:
  • a####.####.com/api/ads/fetch?_s=####
  • a####.####.com/api/ads/connect
Modified file system:
Creates the following files:
  • /data/data/####/app_dex/reach-sdk.zip.tmp
  • /data/data/####/app_tmpdex/reach-sdk.zip
  • /data/data/####/shared_prefs/Appodeal.xml
  • /data/data/####/cache/picasso-cache/f191aa82859f4f520b425c940e338fd6.0.tmp
  • /data/data/####/cache/picasso-cache/e1a906161256235b957c86f6b1e37b60.1.tmp
  • /data/data/####/cache/picasso-cache/a2cae600be923eb5370647de1e081248.0.tmp
  • /data/data/####/cache/picasso-cache/65551d33b67a4e4a43713671f4a71c0d.1.tmp
  • /data/data/####/cache/picasso-cache/96c87a17691c536f37e58cbc3aa1924c.0.tmp
  • /data/data/####/databases/reach.database.ad-journal
  • /data/data/####/app_working/vungle.dex
  • /data/data/####/cache/1468357373244.jar
  • /data/data/####/shared_prefs/com.google.android.gms.measurement.prefs.xml.bak
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_WdZp63h7Eopd9a7_pU_OJjjEi1WlKiK6mdmHyXikYHUs1DSyS1y_x3Mi91EVcOpFRSA_h900
  • /data/data/####/cache/picasso-cache/9fc501fe81e5f23748a9f577ecd8127d.0.tmp
  • /data/data/####/no_backup/com.google.android.gms.appid-no-backup
  • /data/data/####/shared_prefs/####_servertimeoffset.xml
  • /data/data/####/cache/picasso-cache/e187203ad2b272e955bd7156aca941e0.1.tmp
  • /data/data/####/shared_prefs/freq.xml
  • /data/data/####/shared_prefs/####_startupinfopreferences.xml.bak
  • /data/data/####/cache/picasso-cache/074fad4ded8107ae47a1c4fde722753f.0.tmp
  • /data/data/####/cache/picasso-cache/bd40f4f00617765bb62f159a92bb0e78.1.tmp
  • /data/data/####/shared_prefs/multidex.version.xml
  • /data/data/####/cache/picasso-cache/7d66be391084d1007d9c5f62ea3c4958.0.tmp
  • /data/data/####/shared_prefs/####_startupinfopreferences.xml
  • /data/data/####/cache/picasso-cache/501a0a4814bfae934a1c3603e5853db7.0.tmp
  • /data/data/####/shared_prefs/cached_values.xml
  • /data/data/####/app_working/facebook.dex
  • /data/data/####/shared_prefs/io.fabric.sdk.android:fabric:io.fabric.sdk.android.Onboarding.xml
  • /data/data/####/cache/picasso-cache/2da96e4e70f115c8acb69c8e0fd6ba3d.1.tmp
  • /data/data/####/cache/picasso-cache/e46640ce58067d64ed383675890fb205.0.tmp
  • /data/data/####/cache/picasso-cache/9fc501fe81e5f23748a9f577ecd8127d.1.tmp
  • /data/data/####/databases/webview.db-journal
  • /data/data/####/cache/picasso-cache/42fecdb6e1a98ef083c65c560b51eb9b.1.tmp
  • /data/data/####/cache/picasso-cache/2cce60c2e49e14365a653b6d9e62a7a5.1.tmp
  • /data/data/####/cache/picasso-cache/5d81d256768b54628e17bc99fabc102d.1
  • /data/data/####/cache/picasso-cache/6eed8fee37f036463ac31e044f659a4f.1.tmp
  • /data/data/####/cache/picasso-cache/f6173720b9e737a716505685470a0641.0.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD0183-0001-0866-1445BD8FC4A7SessionApp.cls_temp
  • /data/data/####/shared_prefs/####_serviceproviderspreferences.xml
  • /data/data/####/cache/picasso-cache/journal.tmp
  • /data/data/####/cache/picasso-cache/759bd8c088e1d64eb5c1f05a7f6b5155.1.tmp
  • /data/data/####/cache/picasso-cache/a2cae600be923eb5370647de1e081248.1.tmp
  • /data/data/####/cache/picasso-cache/074fad4ded8107ae47a1c4fde722753f.1
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap.tmp
  • /data/data/####/cache/picasso-cache/d82206a341801fd39323e6b290f605ca.1.tmp
  • /data/data/####/cache/picasso-cache/96c87a17691c536f37e58cbc3aa1924c.1.tmp
  • /data/data/####/cache/picasso-cache/2d3c07331f80a73edb6b918700fef090.1.tmp
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_KyRWhVHv6S2GAapCHOt0KFjAKs_gzqndFZwk9smz7QYX3jSAs2KSWfk8hF18KaK8ybA_w300
  • /data/data/####/shared_prefs/com.google.android.gms.appid.xml
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD001B-0001-0826-1445BD8FC4A7BeginSession.cls_temp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD001B-0001-0826-1445BD8FC4A7SessionOS.cls_temp
  • /data/data/####/cache/picasso-cache/a42b42d96e6e34c931c2ca27dc527586.0.tmp
  • /data/data/####/shared_prefs/####_startupserviceinfopreferences.xml
  • /data/data/####/shared_prefs/####_migrationpreferences.xml
  • /data/data/####/cache/picasso-cache/bcfbd25df72c05483cbd453eb7de3282.0.tmp
  • /data/data/####/cache/picasso-cache/212a9e2bf6ccedf0628eb0832946c957.0.tmp
  • /data/data/####/cache/picasso-cache/a895cc01519e9ae57d3f71f0243c0a6f.0.tmp
  • /data/data/####/shared_prefs/####_boundentrypreferences.xml.bak
  • /data/data/####/cache/picasso-cache/f191aa82859f4f520b425c940e338fd6.1
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD001B-0001-0826-1445BD8FC4A7SessionApp.cls_temp
  • /data/data/####/cache/picasso-cache/316d44584f36dd348bea9b2299b834c7.1.tmp
  • /data/data/####/cache/picasso-cache/a42b42d96e6e34c931c2ca27dc527586.1.tmp
  • /data/data/####/shared_prefs/####_boundentrypreferences.xml
  • /data/data/####/cache/picasso-cache/bd40f4f00617765bb62f159a92bb0e78.0.tmp
  • /data/data/####/shared_prefs/####_startupserviceinfopreferences.xml.bak
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics_to_send/sa_40491925-621c-4dce-9fef-59b76bb4714d_1485415901563.tap
  • /data/data/####/cache/picasso-cache/aa5210ea7414b0e29f5a87ee24ade86e.0.tmp
  • /data/data/####/cache/picasso-cache/23950abe14ede98fcae5532a55f7a106.0.tmp
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_bSM3fvFmluJytEmT8On6LnD5CCwGfTKZ2D3CU7YaRWaT_Aj4qkkjxtcPZR6VAcFO_tA_w300
  • /data/data/####/app_working/startapp.dex
  • /data/data/####/shared_prefs/####_initpreferences.xml.bak
  • /data/data/####/cache/picasso-cache/2d3c07331f80a73edb6b918700fef090.0.tmp
  • /data/data/####/cache/picasso-cache/64e9bae863e9d4ff49f84922a92a67c3.0.tmp
  • /data/data/####/cache/picasso-cache/6d7cd11cc624bfa7f9b87c6c6dcd864d.1.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD0183-0001-0866-1445BD8FC4A7SessionOS.cls_temp
  • /data/data/####/cache/picasso-cache/64f47a08b8e858563036366c19708551.1.tmp
  • /data/data/####/cache/picasso-cache/501a0a4814bfae934a1c3603e5853db7.1
  • /data/data/####/cache/picasso-cache/e187203ad2b272e955bd7156aca941e0.0.tmp
  • /data/data/####/cache/picasso-cache/42fecdb6e1a98ef083c65c560b51eb9b.0.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics_to_send/sa_16422910-dadb-43b2-b0e4-480365623a69_1485415903957.tap
  • /data/data/####/shared_prefs/####_initpreferences.xml
  • /data/data/####/shared_prefs/exceptions.xml
  • /data/data/####/cache/picasso-cache/dd81857732d495703404b0a9e06ad615.0.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD001B-0001-0826-1445BD8FC4A7SessionDevice.cls_temp
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com__0HwgEkA2nfIvtX9nDCkG1bo2F89_nYOy0Hg_TGxYJKAICh2PZ1fEs44HJRj2H54e_Q_h900
  • /data/data/####/cache/picasso-cache/bcfbd25df72c05483cbd453eb7de3282.1.tmp
  • /data/data/####/cache/picasso-cache/2fa6b4cd8fff0b6f26bf0fa91d0bf371.1
  • /data/data/####/shared_prefs/appodeal.xml.bak
  • /data/data/####/shared_prefs/TwitterAdvertisingInfoPreferences.xml
  • /data/data/####/cache/picasso-cache/49e28dd11b8fc67551102882a194e03d.1
  • /data/data/####/shared_prefs/com.crashlytics.prefs.xml
  • /data/data/####/cache/picasso-cache/211c4adccbd673c071cab93e0a88bb1e.0.tmp
  • /data/data/####/cache/picasso-cache/316d44584f36dd348bea9b2299b834c7.0.tmp
  • /data/data/####/cache/picasso-cache/e1a906161256235b957c86f6b1e37b60.1
  • /data/data/####/app_working/tapjoy.dex
  • /sdcard/Android/data/.nomedia
  • /data/data/####/cache/picasso-cache/2cce60c2e49e14365a653b6d9e62a7a5.0.tmp
  • /data/data/####/cache/picasso-cache/2b8495711af8730a0b79d81b934dd81b.0.tmp
  • /data/data/####/cache/picasso-cache/f039b9c043d9f3e4d16ad1388ef39965.0.tmp
  • /data/data/####/cache/picasso-cache/5d81d256768b54628e17bc99fabc102d.0.tmp
  • /data/data/####/cache/picasso-cache/7d66be391084d1007d9c5f62ea3c4958.1.tmp
  • /data/data/####/shared_prefs/Reach.xml
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_rKw2kHM19yItUtQJfWbG24qDMI1NubLdwvFk7Bw5cCrffOQKkNcURYpQyvfTkTufng_w300
  • /data/data/####/shared_prefs/Reach.xml.bak
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_ZyoMnABO0VBZwVHIM7436SDa5XClxbC3SMDQvB6t_oFK_A_Q5HGUeLQmy_RrqBHfgQ_h900
  • /data/data/####/cache/picasso-cache/759bd8c088e1d64eb5c1f05a7f6b5155.0.tmp
  • /data/data/####/cache/picasso-cache/211c4adccbd673c071cab93e0a88bb1e.1.tmp
  • /data/data/####/cache/picasso-cache/dd81857732d495703404b0a9e06ad615.1
  • /data/data/####/cache/picasso-cache/c531e60c36a5f64c69c72c337747098d.0.tmp
  • /data/data/####/cache/picasso-cache/2da96e4e70f115c8acb69c8e0fd6ba3d.0.tmp
  • /data/data/####/cache/1468357373244.tmp
  • /data/data/####/databases/cache-journal
  • /data/data/####/shared_prefs/com.crashlytics.sdk.android:answers:settings.xml
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_TmV1KGJgi01ymfkojgbzByfQbjDrt7lLqj6i3ltQ47i36tkgMzHk5LzlGUcC8Say1sE_w300
  • /data/data/####/cache/picasso-cache/212a9e2bf6ccedf0628eb0832946c957.1.tmp
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_JR6_w4vizlkaJ8Rit0LGS_aS3C84f_JloKRiandkZYyAV0305CJSGMhITO2I_ev29ng_h900
  • /data/data/####/cache/picasso-cache/00470633f6cb02192d916a82ffb9df09.0.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap
  • /data/data/####/cache/picasso-cache/64e9bae863e9d4ff49f84922a92a67c3.1.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD0183-0001-0866-1445BD8FC4A7BeginSession.cls_temp
  • /sdcard/.appodeal
  • /data/data/####/cache/picasso-cache/23950abe14ede98fcae5532a55f7a106.1
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/initialization_marker
  • /data/data/####/shared_prefs/appodeal.xml
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_6tCFoEITPyLAURIEV04ftBezC8OvubaDbGDJvaqW_HZiMFhIlF5m3fwnS90Ss4FV1g_h900
  • /data/data/####/files/credentials.dat
  • /data/data/####/cache/picasso-cache/e4241571885672971bc2cbf09a2d9f7c.0.tmp
  • /data/data/####/databases/metrica_data.db-journal
  • /data/data/####/cache/picasso-cache/e1a906161256235b957c86f6b1e37b60.0.tmp
  • /data/data/####/files/.Fabric/io.fabric.sdk.android:fabric/com.crashlytics.settings.json
  • /data/data/####/cache/picasso-cache/aa5210ea7414b0e29f5a87ee24ade86e.1
  • /data/data/####/app_working/revmob.dex
  • /data/data/####/cache/picasso-cache/6d7cd11cc624bfa7f9b87c6c6dcd864d.0.tmp
  • /data/data/####/cache/picasso-cache/49e28dd11b8fc67551102882a194e03d.0.tmp
  • /data/data/####/app_working/avocarrot.dex
  • /data/data/####/app_dex/reach-sdk.zip
  • /data/data/####/cache/picasso-cache/77b8fd4dc4bcbace0fd7895de38b8e8c.1.tmp
  • /data/data/####/shared_prefs/cached_data.xml
  • /sdcard/Android/data/####/cache/reach.image.service/lh3.googleusercontent.com_arhybrDSDtJf1qdUQdcnLhNXnJjL7nBinyyfrE_ir34JJeep49yf_fP3vxzYnu_PMenI_w300
  • /data/data/####/cache/picasso-cache/16a329850581f6953aa6bf49190cc4bb.0.tmp
  • /data/data/####/cache/picasso-cache/65551d33b67a4e4a43713671f4a71c0d.0.tmp
  • /data/data/####/cache/picasso-cache/2fa6b4cd8fff0b6f26bf0fa91d0bf371.0.tmp
  • /data/data/####/cache/picasso-cache/e46640ce58067d64ed383675890fb205.1.tmp
  • /data/data/####/cache/picasso-cache/6eed8fee37f036463ac31e044f659a4f.0.tmp
  • /data/data/####/cache/picasso-cache/00470633f6cb02192d916a82ffb9df09.1
  • /data/data/####/cache/picasso-cache/c531e60c36a5f64c69c72c337747098d.1.tmp
  • /data/data/####/cache/picasso-cache/77b8fd4dc4bcbace0fd7895de38b8e8c.0.tmp
  • /data/data/####/cache/picasso-cache/64f47a08b8e858563036366c19708551.0.tmp
  • /data/data/####/cache/picasso-cache/f6173720b9e737a716505685470a0641.1.tmp
  • /data/data/####/code_cache/secondary-dexes/####-1.apk.classes252182920.zip
  • /data/data/####/databases/db_metrica_####-journal
  • /data/data/####/cache/picasso-cache/f039b9c043d9f3e4d16ad1388ef39965.1.tmp
  • /data/data/####/cache/picasso-cache/d82206a341801fd39323e6b290f605ca.0.tmp
  • /data/data/####/cache/picasso-cache/93d6cc2190605e8278a77240ff97f7f1.0.tmp
  • /data/data/####/cache/picasso-cache/2b8495711af8730a0b79d81b934dd81b.1.tmp
  • /data/data/####/shared_prefs/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/cache/picasso-cache/93d6cc2190605e8278a77240ff97f7f1.1
  • /data/data/####/cache/picasso-cache/e4241571885672971bc2cbf09a2d9f7c.1.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD0183-0001-0866-1445BD8FC4A7SessionDevice.cls_temp
  • /data/data/####/cache/picasso-cache/16a329850581f6953aa6bf49190cc4bb.1.tmp
  • /data/data/####/cache/picasso-cache/a895cc01519e9ae57d3f71f0243c0a6f.1.tmp
  • /data/data/####/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5889A5DD001B-0001-0826-1445BD8FC4A7SessionUser.cls_temp
Miscellaneous:
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android