マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.Packed.46584

Added to the Dr.Web virus database: 2019-08-12

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.589.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) c.appj####.com:80
  • TCP(HTTP/1.1) a.appj####.com:80
  • TCP(TLS/1.0) sett####.crashly####.com:443
  • TCP(TLS/1.0) c####.superma####.top:443
DNS requests:
  • a.appj####.com
  • c####.superma####.top
  • c.appj####.com
  • cdn.img.p####.top
  • rep####.crashly####.com
  • sett####.crashly####.com
HTTP POST requests:
  • a.appj####.com/jiagu/check/upgrade
  • c.appj####.com/ad/splash/stats.html
File system changes:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50924C00D0-0001-085D-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50924E02BC-0002-085D-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50924E02BC-0002-085D-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50924E02BC-0002-085D-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50924E02BC-0002-085D-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925001FD-0001-08B8-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D509251038A-0002-08B8-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509251038A-0002-08B8-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509251038A-0002-08B8-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509251038A-0002-08B8-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925302FA-0001-08EF-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D509255011F-0002-08EF-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509255011F-0002-08EF-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509255011F-0002-08EF-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509255011F-0002-08EF-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509256012E-0001-0934-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D5092580148-0002-0934-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D5092580148-0002-0934-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D5092580148-0002-0934-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D5092580148-0002-0934-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925A02D6-0001-0977-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50925C00A3-0002-0977-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925C00A3-0002-0977-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925C00A3-0002-0977-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925C00A3-0002-0977-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50925D0156-0001-09AE-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50925E02BC-0002-09AE-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50925E02BC-0002-09AE-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50925E02BC-0002-09AE-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50925E02BC-0002-09AE-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509261005B-0001-09E5-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50926201F2-0002-09E5-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926201F2-0002-09E5-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926201F2-0002-09E5-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926201F2-0002-09E5-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926402C7-0001-0A22-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D509266011C-0002-0A22-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509266011C-0002-0A22-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509266011C-0002-0A22-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509266011C-0002-0A22-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D5092670163-0001-0A58-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50926803DF-0002-0A58-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926803DF-0002-0A58-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926803DF-0002-0A58-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926803DF-0002-0A58-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926B01EE-0001-0A9B-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50926D0352-0002-0A9B-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926D0352-0002-0A9B-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926D0352-0002-0A9B-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926D0352-0002-0A9B-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50926F002C-0001-0ADF-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50927003A3-0002-0ADF-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927003A3-0002-0ADF-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927003A3-0002-0ADF-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927003A3-0002-0ADF-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927201C9-0001-0B20-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D5092730391-0002-0B20-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D5092730391-0002-0B20-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D5092730391-0002-0B20-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D5092730391-0002-0B20-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D509276009F-0001-0B58-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D5092770316-0002-0B58-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D5092770316-0002-0B58-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D5092770316-0002-0B58-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D5092770316-0002-0B58-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927803A8-0001-0B90-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50927A01E2-0002-0B90-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927A01E2-0002-0B90-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927A01E2-0002-0B90-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927A01E2-0002-0B90-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927C0141-0001-0BD1-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50927D02CB-0002-0BD1-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927D02CB-0002-0BD1-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927D02CB-0002-0BD1-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927D02CB-0002-0BD1-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50927E034C-0001-0C08-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D50928001E1-0002-0C08-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50928001E1-0002-0C08-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50928001E1-0002-0C08-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50928001E1-0002-0C08-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50928300B8-0001-0C4A-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D5092840270-0002-0C4A-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D5092840270-0002-0C4A-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D5092840270-0002-0C4A-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D5092840270-0002-0C4A-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1SessionCrash.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/5D50928502D3-0001-0C82-D27D1581D9B1SessionUser.cls_temp
  • /data/data/####/5D509287010B-0002-0C82-D27D1581D9B1BeginSession.cls_temp
  • /data/data/####/5D509287010B-0002-0C82-D27D1581D9B1SessionApp.cls_temp
  • /data/data/####/5D509287010B-0002-0C82-D27D1581D9B1SessionDevice.cls_temp
  • /data/data/####/5D509287010B-0002-0C82-D27D1581D9B1SessionOS.cls_temp
  • /data/data/####/TwitterAdvertisingInfoPreferences.xml
  • /data/data/####/WORLD_SHARED.xml
  • /data/data/####/ad_show_time.xml
  • /data/data/####/apprater.xml
  • /data/data/####/com.crashlytics.prefs.xml
  • /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
  • /data/data/####/com.crashlytics.settings.json
  • /data/data/####/com.fjdklsafds.afjdksing_preferences.xml
  • /data/data/####/crash_marker
  • /data/data/####/initialization_marker
  • /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.andr...ng.xml
  • /data/data/####/jg_app_update_settings_random.xml
  • /data/data/####/jg_app_update_settings_random.xml.bak
  • /data/data/####/kr.xml
  • /data/data/####/ky.xml
  • /data/data/####/libjiagu.so
  • /data/data/####/qihoo_jiagu_crash_report.xml
  • /data/data/####/sa_59ef8701-371d-40bd-bc63-4e035ef58103_1565561420597.tap
  • /data/data/####/session_analytics.tap
  • /data/data/####/session_analytics.tap (deleted)
  • /data/data/####/session_analytics.tap.tmp
  • /data/data/####/t_u.db-journal
  • /data/media/####/498c0e30625669150412fcc3fe6f5545.zip
  • /data/media/####/Painter.dat
  • /data/media/####/journal
  • /data/media/####/journal.tmp
  • /data/media/####/t.dat
Miscellaneous:
Executes the following shell scripts:
  • chmod 755 <Package Folder>/.jiagu/libjiagu.so
Loads the following dynamic libraries:
  • libjiagu
Uses the following algorithms to encrypt data:
  • RSA
  • RSA-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • DES
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about running apps.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android