マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.SmsSend.18167

Added to the Dr.Web virus database: 2017-04-28

Virus description added:

Technical information

Malicious functions:
Sends SMS messages:
  • 1065800830195386: U,hd00000000000000000200
Network activity:
Connecting to:
  • i####.####.com
  • c####.com
  • p####.####.com
  • a####.####.cn
  • x####.####.com
  • i####.####.cc
HTTP GET requests:
  • p####.####.com/handao_img/newsp/zuan_3.jpg
  • x####.####.com/comment/3.jpg
  • p####.####.com/handao_img/newsp/zuan_44.jpg
  • x####.####.com/comment/26.jpg
  • x####.####.com/comment/36.jpg
  • p####.####.com/handao_img/newsp/zhi_15.jpg
  • x####.####.com/banner/banner2.jpg
  • x####.####.com/comment/29.jpg
  • x####.####.com/try/ty5.jpg
  • x####.####.com/zr/zr4.jpg
  • i####.####.cc/handao_img/app_img/face/c4851e8e264415c4094e4e85b0baa7cc.jpg
  • x####.####.com/try/ty3.jpg
  • x####.####.com/zr/zr1.jpg
  • x####.####.com/comment/21.jpg
  • x####.####.com/comment/5.jpg
  • x####.####.com/comment/15.jpg
  • x####.####.com/comment/17.jpg
  • x####.####.com/comment/13.jpg
  • i####.####.cc/handao_img/app_img/face/3.jpg
  • x####.####.com/comment/33.jpg
  • i####.####.cc/handao_img/app_img/face/51.jpg
  • x####.####.com/comment/19.jpg
  • x####.####.com/picture/pindao3.png
  • x####.####.com/picture/pindao2.png
  • i####.####.cc/handao_img/app_img/face/81e5f81db77c596492e6f1a5a792ed53.jpg
  • x####.####.com/comment/37.jpg
  • x####.####.com/try/ty12.jpg
  • x####.####.com/try/ty10.jpg
  • i####.####.cc/handao_img/app_img/face/171.jpg
  • c####.com/
  • x####.####.com/comment/30.jpg
  • i####.####.cc/handao_img/app_img/face/59.jpg
  • x####.####.com/comment/27.jpg
  • x####.####.com/comment/4.jpg
  • x####.####.com/comment/38.jpg
  • i####.####.cc/handao_img/app_img/face/32.jpg
  • i####.####.cc/handao_img/app_img/face/2c6ae45a3e88aee548c0714fad7f8269.jpg
  • i####.####.cc/handao_img/app_img/face/17.jpg
  • x####.####.com/try/ty6.jpg
  • p####.####.com/json2/comments.php?id=####
  • x####.####.com/try/ty9.jpg
  • x####.####.com/comment/7.jpg
  • i####.####.cc/handao_img/app_img/face/61.jpg
  • i####.####.cc/handao_img/app_img/face/19.jpg
  • x####.####.com/picture/pindao8.png
  • x####.####.com/comment/1.jpg
  • x####.####.com/picture/pindao1.png
  • x####.####.com/comment/8.jpg
  • x####.####.com/comment/12.jpg
  • x####.####.com/comment/20.jpg
  • x####.####.com/comment/22.jpg
  • x####.####.com/comment/2.jpg
  • p####.####.com/handao_img/newsp/zhi_21.jpg
  • x####.####.com/banner/banner1.jpg
  • x####.####.com/picture/pindao5.png
  • x####.####.com/picture/pindao6.png
  • i####.####.cc/handao_img/app_img/face/82f2b308c3b01637c607ce05f52a2fed.jpg
  • p####.####.com/handao_img/newsp/guan_28.jpg
  • x####.####.com/try/ty7.jpg
  • i####.####.cc/handao_img/app_img/face/126.jpg
  • i####.####.cc/handao_img/app_img/face/18.jpg
  • x####.####.com/comment/32.jpg
  • i####.####.cc/handao_img/app_img/face/41.jpg
  • x####.####.com/comment/35.jpg
  • i####.####.cc/handao_img/app_img/face/26.jpg
  • x####.####.com/comment/18.jpg
  • x####.####.com/zr/zr7.jpg
  • i####.####.cc/handao_img/app_img/face/b495ce63ede0f4efc9eec62cb947c162.jpg
  • x####.####.com/zr/zr8.jpg
  • x####.####.com/comment/25.jpg
  • x####.####.com/try/ty4.jpg
  • i####.####.com/a/3ea2abf829442e5968fa8d96dfc3b1513
  • x####.####.com/picture/pindao4.png
  • x####.####.com/comment/24.jpg
  • x####.####.com/zr/zr9.jpg
  • x####.####.com/comment/34.jpg
  • i####.####.cc/handao_img/app_img/face/28.jpg
  • x####.####.com/comment/14.jpg
  • x####.####.com/banner/banner0.jpg
  • i####.####.cc/handao_img/app_img/face/1.jpg
  • x####.####.com/zr/zr6.jpg
  • x####.####.com/zr/zr5.jpg
  • x####.####.com/comment/28.jpg
  • x####.####.com/try/ty1.jpg
  • x####.####.com/picture/pindao7.png
  • p####.####.com/handao_img/newsp/zhi_38.jpg
  • x####.####.com/comment/23.jpg
  • x####.####.com/comment/10.jpg
  • x####.####.com/try/ty8.jpg
  • x####.####.com/zr/zr2.jpg
  • x####.####.com/comment/6.jpg
  • x####.####.com/comment/11.jpg
  • x####.####.com/try/ty11.jpg
  • x####.####.com/comment/31.jpg
  • x####.####.com/comment/9.jpg
  • i####.####.cc/handao_img/app_img/face/93.jpg
  • x####.####.com/banner/banner3.jpg
  • x####.####.com/zr/zr3.jpg
  • x####.####.com/try/ty2.jpg
  • x####.####.com/banner/banner4.jpg
  • x####.####.com/comment/16.jpg
  • p####.####.com/json2/visitor2.php?pay_Id=####&package=####&appid=####&pa...
HTTP POST requests:
  • x####.####.com/sdkServer/sdkconfig
  • x####.####.com/sdkServer/pay
  • x####.####.com/sdkServer/makeOrder
  • p####.####.com/api/q/a/3ea2abf829442e5968fa8d96dfc3b1513
  • p####.####.com/api/statis/3ea2abf829442e5968fa8d96dfc3b1513/game-F5A9C59...
  • a####.####.cn/sdkconfig
  • a####.####.cn/thirdpaySupportList
Modified file system:
Creates the following files:
  • /sdcard/Android/data/####/cache/uil-images/4v0acb07rhgg2qtal0an03jzx.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/6v084atsd9ersuhhkc6zy6zts.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/8j4jyn2w64yq04t5n5uzokqt.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/2t3xd147rztict5xnwditcqxq.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/xbtqt6xarnyex7p9ty3wr91e.0.tmp
  • /data/data/####/shared_prefs/Alvin2.xml
  • /sdcard/Android/data/####/cache/uil-images/6i9az7bbutg9f29qgcrx5ty1a.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5a8grdjy8hwfapkqxylcsrijh.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/2n1c6fu3rhtjnxw4fecujrv8c.0.tmp
  • /data/data/####/shared_prefs/TD_app_pefercen_profile.xml
  • /sdcard/Android/data/####/cache/uil-images/4q3aj6ctnqgsf1zqgx1kp7xqr.0.tmp
  • /data/data/####/databases/xl_props.db
  • /sdcard/Android/data/####/cache/uil-images/6louoaz1xle8uaj0p5k79b2o0.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5ziz8p5wtc41hodr4kdm0m0mp.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/6y8xwvptk0vghceote0pljqbb.0.tmp
  • /data/data/####/shared_prefs/com_xl_shared_preferences.xml.bak
  • /sdcard/Android/data/####/cache/uil-images/4tw92dtt39zfhkqix4k126lil.0
  • /sdcard/Android/data/####/cache/uil-images/4pov5sfu8co5wvbp0td2aopmo.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4e9d9q9wc6qb022056x6el6ou.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3ru4cb7u01o85t7zo6r66yoaz.0.tmp
  • /sdcard/.DataStorage/ContextData.xml
  • /sdcard/Android/data/####/cache/uil-images/17q7lfwa4006xpntchbaz2llx.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3pi1gkglofzna3dsercyuf1lp.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/59g3nisqtgyfnkjnhrm3kl2up.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4yt6l94kc3gls7hpsb3z3m9fc.0.tmp
  • /data/data/####/shared_prefs/TalkingData_Push_SharedPreferences.xml
  • /sdcard/Android/data/####/cache/uil-images/5mfzypj65e537ymyi3oj763f3.0.tmp
  • /data/data/####/shared_prefs/pref_file.xml.bak
  • /sdcard/Android/data/####/cache/uil-images/3apnp4kdychnwnfrl3kk5iew1.0.tmp
  • /data/data/####/shared_prefs/gost.xml
  • /sdcard/Android/data/####/cache/uil-images/2k5vnkbo9zn6yyql62wswqsqq.0
  • /sdcard/Android/data/####/cache/uil-images/5qejvwcri0io86cy3cfma615d.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/59s6ielu76nh5dvwbodhtknbo.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3sohrfxboacmzquu0zqq9lpwq.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1727rbah0qmnsp31bv2584gxs.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/6bwxpjy872spyfq0aodn4460v.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/7bdyi4hexcv1ielod4r56j2dl.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/427u21n0sb8q7bk6bibgql0mq.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3ae7wq4ajdv4xier35qfjdcyu.0.tmp
  • /data/data/####/shared_prefs/td_pefercen_profile.xml.bak
  • /data/data/####/files/talkingdata_app_version_preferences_file
  • /sdcard/Android/data/####/cache/uil-images/4mivd5oskvwl2hxl53dytvvvu.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5tsigv7o6fqgdgqx2wpf0g57.0.tmp
  • /sdcard/.UTSystemConfig/Global/Alvin2.xml
  • /sdcard/Android/data/####/cache/uil-images/43l7qgwnqeryj3szstrjowkjf.0.tmp
  • /data/data/####/databases/xl_single_operator.db-journal
  • /sdcard/Android/data/####/cache/uil-images/45lilmrp5lvmio6b60m2tcdxu.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3y748v49hrj4b66thn4mf5uno.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/sx1tr17aozncc5ouslp9uzka.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1x9fkqytc54khob02w6x09njp.0.tmp
  • /data/data/####/databases/xUtils_http_cookie.db-journal
  • /sdcard/Android/data/####/cache/uil-images/kzg1oe58p6dhc5gri0pq5n6y.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/6knwvx7ifk9uqbksl8ct081tl.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/2knf84851qmrpicoq43cix9vn.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/2k9qdgcxx621jm4be90nkd58c.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/15x0u6q1szlpwjvfu0ak4ka5d.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/txy3pif3fmui8o0nu88k39x7.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4v45mqbv2isb92gith80pit21.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/6r6fuz4rft3wi9q5h85mpl0lc.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5gi6714wzfouaehsajeqa8uof.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4b7c3xzfnm51cqaco12nu2f15.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/374wak0kjira6anzwy23qhny9.0.tmp
  • /data/data/####/databases/xl_props.db-journal
  • /sdcard/Android/data/####/cache/uil-images/5wcbril5hlyr33fd07u9glk0y.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1e26wmh745mkx7yb0cvrg2tzw.0.tmp
  • /data/data/####/shared_prefs/TD_app_pefercen_profile.xml.bak
  • /sdcard/Android/data/####/cache/uil-images/6zhdyehu88tttem3tb4w4oisu.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1p0ekh3ff148pvqzejafu42b.0.tmp
  • /data/data/####/shared_prefs/com_yf_shared_preferences.xml.bak
  • /sdcard/Android/data/####/cache/uil-images/7jmwvx6d3gcj3vgtrn40km6wm.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4ta4m6g1e166jatqihaya64n1.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1mww8n42j0y71aeuek5uqmigm.0.tmp
  • /data/data/####/databases/xl_thirdpay.db-journal
  • /sdcard/Android/data/####/cache/uil-images/vnslh37pxxg3fysaej1bgyan.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5wgteeok595v6441z3fn23heb.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1ywz55njufynkqkchsdy7kpfp.0.tmp
  • /data/data/####/shared_prefs/pref_file.xml
  • /sdcard/Android/data/####/cache/uil-images/20zork3pvqtc8a2erkdmcgs1q.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/412epvo8ih1ly4vrykfdgtz5h.0.tmp
  • /sdcard/.tcookieid
  • /sdcard/Android/data/####/cache/uil-images/3b9sx4ycth3yrzorj0j4jsksy.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/o5bq0tu8o3ockm24s5m11zg2.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3s3afuaz9cdpstub3916ntlte.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/7jiad4vw6g79lcz97oszaxkn0.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/2jjtytp7j8ozo16y0v7yh5s2q.0.tmp
  • /data/data/####/files/talkingdata_app_process_preferences_file
  • /sdcard/Android/data/####/cache/.nomedia
  • /sdcard/Android/data/####/cache/uil-images/1gjz2wtzdfqmx4qr5lgm9o3d1.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/31b2mrpxwuhw9g0wgmwuy0899.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/77x4no19wm9ou31wi588zzg7b.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/l6u1i0jdziflacuglobdelgf.0.tmp
  • /data/data/####/shared_prefs/td_pefercen_profile.xml
  • /data/data/####/shared_prefs/com_yf_shared_preferences.xml
  • /sdcard/Android/data/####/cache/uil-images/23w5jruvijgm1zx3wuvf22qaw.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5oioz66j74q7oy8nisycq40f1.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/h7x7jdrm2n5qltxs2ceneo4y.0.tmp
  • /data/data/####/databases/xl_single_operator.db
  • /sdcard/Android/data/####/cache/uil-images/4tdobizgzflt2a2vhhll7ahcu.0.tmp
  • /data/data/####/shared_prefs/####_preferences.xml
  • /data/data/####/databases/xUtils_http_cookie.db
  • /data/data/####/databases/talkingdata_app.db-journal
  • /sdcard/Android/data/####/cache/uil-images/38j0xwtfnv58rlx3rw6ykwjzl.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/67tevun8641rsjkcmr1hejw65.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/3rvblhtdveh3kxbde6ry46zxi.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1gmfetaxhu7achlpm9aod8d79.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/coy689f728q8fnupt0fy2qqw.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/5srpuzoiib4bmmn1zqjagkaoc.0.tmp
  • /data/data/####/shared_prefs/|account_file.xml
  • /sdcard/Android/data/####/cache/uil-images/1b6oodux2kvess8x6e2l9n2wt.0.tmp
  • /data/data/####/shared_prefs/ContextData.xml
  • /data/data/####/databases/xl_thirdpay.db
  • /sdcard/Android/data/####/cache/uil-images/1u9cgh3ve3zny55r67kd9udz8.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/jtw1ahohw80s5onkm83rf68v.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/pifnp9ijhkkwrtadmhd4bt5e.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4qttwm7duhzo3ymzoorof7osm.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/59ys54z4npf044wlv52bjgcso.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/14vw14u5ysxotpas4lzl0801m.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4ikflyep6fj3zx6us63vza55g.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/4zz019f6j8b80e874kv9iajy1.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1dd3m8781e2rpqg5m7zwe5e00.0.tmp
  • /data/data/####/shared_prefs/talkingdata_file_prefence.xml
  • /data/data/####/shared_prefs/tdid.xml
  • /data/data/####/shared_prefs/com_xl_shared_preferences.xml
  • /sdcard/Android/data/####/cache/uil-images/5jydjeh7da6c3q5i4vaudbuc6.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/journal.tmp
  • /sdcard/Android/data/####/cache/uil-images/58gv3doswnccxnlygkr1nl6iu.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/1z1em7dogpvog4oavn90grnet.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/42mjjnmrv6s96wsoow1x8vkyj.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/34tvp5chc6t6jialtv4uhd5dq.0.tmp
  • /sdcard/Android/data/####/cache/uil-images/59dkomdx7ug3ons4hk6m4yhe1.0.tmp
Miscellaneous:
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android