Library
My library

+ Add to library

Profile

Android.Xiny.1614

Added to the Dr.Web virus database: 2018-05-06

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Xiny.20
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) com####.505####.com.####.com:80
  • TCP(HTTP/1.1) aserver####.m.ta####.com:80
  • TCP(HTTP/1.1) mo####.b####.com:80
  • TCP(HTTP/1.1) vt####.y####.com:80
  • TCP(HTTP/1.1) g.al####.com:80
  • TCP(HTTP/1.1) wc.find####.cc.####.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) c.c####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) log.mm####.com:80
  • TCP(HTTP/1.1) z####.505####.com.####.com:80
  • TCP(HTTP/1.1) s.un####.com:80
  • TCP(HTTP/1.1) af.al####.com:80
  • TCP(HTTP/1.1) wild####.al####.com.####.net:80
  • TCP(HTTP/1.1) pco####.y####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) i4.w####.com:80
  • TCP(HTTP/1.1) www.43####.com.####.com:80
  • TCP(HTTP/1.1) st####.y####.com:80
  • TCP(HTTP/1.1) m.43####.com.####.com:80
  • TCP(TLS/1.0) mobads-####.b####.com:443
  • TCP(TLS/1.0) h####.b####.com.####.com:443
  • TCP(TLS/1.0) sh.wagbr####.ali####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) aserver####.m.ta####.com:443
  • TCP(TLS/1.0) log.mm####.com:443
DNS requests:
  • a####.u####.com
  • a.img####.com
  • aeu.al####.com
  • af.al####.com
  • api.y####.com
  • c.c####.com
  • cdn.com####.43####.com
  • com####.505####.com
  • fou####.ali####.com
  • g.al####.com
  • h####.b####.com
  • hm.b####.com
  • i4.w####.com
  • log.mm####.com
  • m.43####.com
  • m.y####.com
  • mf.atm.y####.com
  • mo####.b####.com
  • mobads-####.b####.com
  • pco####.y####.com
  • pl####.y####.com
  • s.un####.com
  • s25.c####.com
  • st####.api.3g.####.com
  • st####.y####.com
  • ups.y####.com
  • v####.505####.com
  • vt####.y####.com
  • wc.find####.cc
  • www.43####.com
  • www.439####.com
  • z####.505####.com
  • z####.c####.com
HTTP GET requests:
  • af.al####.com/js/uac.js
  • aserver####.m.ta####.com/embed/XMjI1MTU2NjA4
  • aserver####.m.ta####.com/embed/XMzA0NjQ0NzIzMg==
  • aserver####.m.ta####.com/embed/XMzAxOTkzNTY0OA==
  • aserver####.m.ta####.com/iframeapi
  • aserver####.m.ta####.com/mf?aw=####&vs=####&pver=####&tict=####&vr=####&...
  • aserver####.m.ta####.com/openapi-wireless/statis/recall_app_service
  • aserver####.m.ta####.com/unifull/css/unifull.min.css
  • aserver####.m.ta####.com/unifull/images/new_loading.png
  • aserver####.m.ta####.com/unifull/images/new_player_icons.png
  • aserver####.m.ta####.com/unifull/js/unifull.min.js
  • aserver####.m.ta####.com/video/js/yksmartbanner.min.js?_t=####
  • aserver####.m.ta####.com/video/libs/sb/smartbannerConfig.js?_t=####
  • aserver####.m.ta####.com/video/libs/sb/smartbannerText.js?_t=####
  • c.c####.com/core.php?web_id=####&t=####
  • c.c####.com/stat.php?id=####&web_id=####
  • com####.505####.com.####.com/images/02.gif
  • com####.505####.com.####.com/images/03.gif
  • com####.505####.com.####.com/images/09.gif
  • com####.505####.com.####.com/images/douwa/21.gif
  • com####.505####.com.####.com/zhaojiao/1582/1582_1_js.html
  • com####.505####.com.####.com/zhaojiao/3567/153567_1_js.html
  • com####.505####.com.####.com/zhaojiao/3622/153622_1_js.html
  • com####.505####.com.####.com/zhaojiao/8444/118444_1_js.html
  • com####.505####.com.####.com/zhaojiao/985/985_1_js.html
  • g.al####.com/alilog/??s/7.6.2####
  • g.al####.com/player/player-collina/0.0.2/player-collina.min.js
  • g.al####.com/secdev/entry/index.js?t=####
  • g.al####.com/secdev/sufei_data/3.4.1/index.js
  • hm.b####.com/h.js?2eb9199####
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.gif?cc=0&ck=1&cl=16-bit&ds=800x600&vl=928&ep=3322,1853&e...
  • hm.b####.com/hm.gif?cc=0&ck=1&cl=16-bit&ds=800x600&vl=928&ep={"netAll":0...
  • hm.b####.com/hm.gif?cc=0&ck=1&cl=16-bit&ds=800x600&vl=928&et=0&ja=0&ln=e...
  • i4.w####.com/item/1508/21/55d6af11a5296_wx.jpg
  • log.mm####.com/eg.js
  • log.mm####.com/yt.gif?logtype=####&title=####&pre=####&cache=####&scr=##...
  • m.43####.com.####.com/
  • m.43####.com.####.com/css/m.comment.css
  • m.43####.com.####.com/css/wap_mp3161122.css
  • m.43####.com.####.com/ergeapp/?w####
  • m.43####.com.####.com/gushi/hbgs/20150709-118444.html
  • m.43####.com.####.com/images/app_tuiguang_wap/bg2.jpg
  • m.43####.com.####.com/images/app_tuiguang_wap/mxs.jpg
  • m.43####.com.####.com/images/wap/com_icons.png
  • m.43####.com.####.com/images/wap_mp3/default.jpg
  • m.43####.com.####.com/images/wap_mp3/default.png
  • m.43####.com.####.com/js/fastclick.js
  • m.43####.com.####.com/js/m.comment.js
  • m.43####.com.####.com/js/wap/m.comment.js
  • m.43####.com.####.com/xzt/
  • m.43####.com.####.com/xzt/kldgs/
  • m.43####.com.####.com/xzt/tfboysgqdq/
  • mo####.b####.com/ads/ads.appcache
  • mo####.b####.com/ads/css/min/main.css
  • mo####.b####.com/ads/index.htm
  • mo####.b####.com/ads/js/ads.trunk.js
  • mo####.b####.com/ads/js/c.js
  • mo####.b####.com/ads/pa/__pasys.apk
  • mo####.b####.com/ads/pa/__pasys.php
  • mo####.b####.com/ads/pa/__pasys_remote_banner.jar
  • mo####.b####.com/ads/pa/__pasys_remote_banner.php?v=####&tp=####&os=####...
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1525572460326=####
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1525572490668=####
  • pco####.y####.com/app.gif?&cna=####
  • st####.y####.com/h5/html/sb/ykbannerLoader/ykbannerLoader.min.js
  • vt####.y####.com/0541040851E7507D6A0A4F68ACFC414F
  • wc.find####.cc.####.com/2011/rio.jar
  • wild####.al####.com.####.net/js/cj/107.js
  • wild####.al####.com.####.net/js/cj/108.js
  • www.43####.com.####.com/2533558379/small
  • www.43####.com.####.com/allimg/140402/13_140402112004_1.jpg
  • www.43####.com.####.com/allimg/140402/14_140402144246_1.jpg
  • www.43####.com.####.com/allimg/141223/13_141223094623_1.jpg
  • www.43####.com.####.com/allimg/150701/14_150701104907_1.jpg
  • www.43####.com.####.com/allimg/150731/14_150731114739_1.jpg
  • www.43####.com.####.com/allimg/151207/14_151207114957_1.jpg
  • www.43####.com.####.com/css/wap/commons/m.dialog.css
  • www.43####.com.####.com/datainc/1524/jujilist.js
  • www.43####.com.####.com/datainc/1582/jujilist.js
  • www.43####.com.####.com/datainc/wap_data.js?1####
  • www.43####.com.####.com/images/jiujiu/05.gif
  • www.43####.com.####.com/images/jiujiu/13.gif
  • www.43####.com.####.com/imgsdir/allimg/150625/14_150625095829_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150701/14_150701102431_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150709/14_150709101325_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150717/14_150717104818_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150728/14_150728103159_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150806/14_150806101100_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150817/14_150817110246_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150827/14_150827102455_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/150907/14_150907104322_2.jpg
  • www.43####.com.####.com/imgsdir/allimg/170602/23_170602175310_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170627/24_170627144418_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170731/24_170731111252_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170816/24_170816112508_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170915/24_170915113502_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170919/24_170919113121_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170925/24_170925112742_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170926/24_170926111039_1.jpg
  • www.43####.com.####.com/imgsdir/allimg/170927/24_170927160737_1.jpg
  • www.43####.com.####.com/js/trace_news.js
  • www.43####.com.####.com/music/zjflash/4399erApp/anzhuangbao/eg_ergewap_2...
  • z####.505####.com.####.com/0/small
  • z####.505####.com.####.com/2633749451/small
  • z####.505####.com.####.com/allimg/130619/13_130619115845_1.jpg
  • z####.505####.com.####.com/allimg/140519/12_140519203908_6.jpg
  • z####.505####.com.####.com/allimg/140611/12_140611104031_1.jpg
  • z####.505####.com.####.com/allimg/140611/12_140611150041_3.jpg
  • z####.505####.com.####.com/allimg/140611/12_140611174446_1.jpg
  • z####.505####.com.####.com/allimg/140714/16_140714160002_2.jpg
  • z####.505####.com.####.com/allimg/141112/16_141112143323_2.jpg
  • z####.505####.com.####.com/allimg/141125/14_141125111302_5.jpg
  • z####.505####.com.####.com/allimg/150513/14_150513112729_4.jpg
  • z####.505####.com.####.com/allimg/150530/16_150530143938_2.jpg
  • z####.505####.com.####.com/allimg/150625/14_150625095829_1.jpg
  • z####.505####.com.####.com/allimg/150701/14_150701102431_1.jpg
  • z####.505####.com.####.com/allimg/150709/14_150709101324_1.jpg
  • z####.505####.com.####.com/allimg/150717/14_150717104817_1.jpg
  • z####.505####.com.####.com/allimg/150728/14_150728103159_1.jpg
  • z####.505####.com.####.com/allimg/150806/14_150806101100_1.jpg
  • z####.505####.com.####.com/allimg/150817/14_150817110246_1.jpg
  • z####.505####.com.####.com/allimg/150827/14_150827102455_1.jpg
  • z####.505####.com.####.com/allimg/150907/14_150907104322_1.jpg
  • z####.505####.com.####.com/allimg/150910/16_150910112905_1.jpg
  • z####.505####.com.####.com/allimg/160906/12_160906153141_1.png
  • z####.505####.com.####.com/allimg/160906/12_160906153141_2.png
  • z####.505####.com.####.com/allimg/160906/12_160906153141_3.png
  • z####.505####.com.####.com/allimg/160909/16_160909174228_1.png
  • z####.505####.com.####.com/allimg/160909/16_160909174228_2.png
  • z####.505####.com.####.com/allimg/160909/16_160909174228_3.png
  • z####.505####.com.####.com/allimg/160909/16_160909174516_1.png
  • z####.505####.com.####.com/allimg/160909/16_160909174516_2.png
  • z####.505####.com.####.com/allimg/160909/16_160909174516_3.png
  • z####.505####.com.####.com/allimg/160909/16_160909174632_1.png
  • z####.505####.com.####.com/allimg/160920/16_160920104727_1.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117112924_1.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117135734_1.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117135734_2.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117135735_4.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117135735_5.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117140251_1.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117140251_2.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117140251_3.jpg
  • z####.505####.com.####.com/allimg/161117/12_161117140251_4.jpg
  • z####.505####.com.####.com/allimg/170408/25_170408103031_1.jpg
  • z####.505####.com.####.com/allimg/170417/25_170417091235_2.jpg
  • z####.505####.com.####.com/allimg/170509/25_170509095042_2.jpg
  • z####.505####.com.####.com/allimg/170516/24_170516180006_1.jpg
  • z####.505####.com.####.com/allimg/170523/24_170523145011_1.jpg
  • z####.505####.com.####.com/allimg/170523/24_170523145232_1.jpg
  • z####.505####.com.####.com/allimg/170525/24_170525202051_1.jpg
  • z####.505####.com.####.com/allimg/170607/24_170607143651_1.jpg
  • z####.505####.com.####.com/allimg/170608/24_170608163848_1.jpg
  • z####.505####.com.####.com/allimg/170615/23_170615173936_1.jpg
  • z####.505####.com.####.com/allimg/170617/23_170617142222_1.jpg
  • z####.505####.com.####.com/allimg/170617/23_170617142401_1.jpg
  • z####.505####.com.####.com/allimg/170617/23_170617142830_1.jpg
  • z####.505####.com.####.com/allimg/170619/24_170619160039_1.jpg
  • z####.505####.com.####.com/allimg/170622/24_170622135805_1.jpg
  • z####.505####.com.####.com/allimg/170622/24_170622163055_1.jpg
  • z####.505####.com.####.com/allimg/170623/24_170623105757_1.jpg
  • z####.505####.com.####.com/allimg/170626/23_170626111029_1.jpg
  • z####.505####.com.####.com/allimg/170627/24_170627144436_1.jpg
  • z####.505####.com.####.com/allimg/170707/12_170707104504_1.jpg
  • z####.505####.com.####.com/allimg/170708/12_170708105936_1.png
  • z####.505####.com.####.com/allimg/170711/15_170711160349_1.jpg
  • z####.505####.com.####.com/allimg/170711/15_170711160349_2.jpg
  • z####.505####.com.####.com/allimg/170711/18_170711150925_1.jpg
  • z####.505####.com.####.com/allimg/170713/23_170713144218_1.jpg
  • z####.505####.com.####.com/allimg/170715/23_170715142024_2.jpg
  • z####.505####.com.####.com/allimg/170715/24_170715151417_1.jpg
  • z####.505####.com.####.com/allimg/170720/24_170720110156_1.jpg
  • z####.505####.com.####.com/allimg/170725/24_170725113548_1.jpg
  • z####.505####.com.####.com/allimg/170731/24_170731111304_1.jpg
  • z####.505####.com.####.com/allimg/170801/23_170801144813_3.jpg
  • z####.505####.com.####.com/allimg/170810/23_170810102917_1.jpg
  • z####.505####.com.####.com/allimg/170816/24_170816112522_1.jpg
  • z####.505####.com.####.com/allimg/170822/24_170822103554_1.jpg
  • z####.505####.com.####.com/allimg/170829/24_170829102445_1.jpg
  • z####.505####.com.####.com/allimg/170830/24_170830103225_1.jpg
  • z####.505####.com.####.com/allimg/170905/24_170905112350_1.jpg
  • z####.505####.com.####.com/allimg/170906/24_170906095054_1.jpg
  • z####.505####.com.####.com/allimg/170914/24_170914093342_1.jpg
  • z####.505####.com.####.com/allimg/170915/24_170915113514_1.jpg
  • z####.505####.com.####.com/allimg/170919/24_170919113134_1.jpg
  • z####.505####.com.####.com/allimg/170919/24_170919165734_1.jpg
  • z####.505####.com.####.com/allimg/170925/24_170925112806_1.jpg
  • z####.505####.com.####.com/allimg/170926/24_170926111053_1.jpg
  • z####.505####.com.####.com/allimg/170927/24_170927160755_1.jpg
  • z####.505####.com.####.com/allimg/171113/23_171113152435_1.jpg
  • z####.505####.com.####.com/allimg/180108/23_180108152721_3.jpg
  • z####.505####.com.####.com/allimg/180108/24_180108172847_3.jpg
  • z####.505####.com.####.com/allimg/180109/23_180109111418_3.jpg
  • z####.505####.com.####.com/allimg/180109/23_180109162354_3.jpg
  • z####.505####.com.####.com/allimg/180109/24_180109142010_3.jpg
  • z####.505####.com.####.com/allimg/180109/24_180109190542_3.jpg
  • z####.505####.com.####.com/allimg/180115/23_180115153505_3.jpg
  • z####.505####.com.####.com/allimg/180122/23_180122170843_3.jpg
  • z####.505####.com.####.com/allimg/180412/15_180412153919_1.jpg
  • z####.505####.com.####.com/allimg/180416/23_180416153359_1.jpg
  • z####.505####.com.####.com/allimg/180417/23_180417160104_1.jpg
  • z####.505####.com.####.com/allimg/180418/15_180418111418_1.jpg
  • z####.505####.com.####.com/allimg/180425/15_180425112826_1.jpg
  • z####.505####.com.####.com/allimg/180426/15_180426164004_1.jpg
  • z####.505####.com.####.com/allimg/180503/15_180503105732_1.jpg
  • z####.505####.com.####.com/allimg/180504/15_180504110002_1.jpg
  • z####.505####.com.####.com/cookie/abc_xiaozhuti_llcs.php?r=####&typeid=#...
  • z####.505####.com.####.com/css/m.dialog.css
  • z####.505####.com.####.com/css/wap/app_tuiguang_wap.css?18####
  • z####.505####.com.####.com/css/wap_mp3161122.css?1####
  • z####.505####.com.####.com/datainc/wap_fenlei_daohang.js
  • z####.505####.com.####.com/erge/egty/20170925-153567.html
  • z####.505####.com.####.com/ergeapp/?w####
  • z####.505####.com.####.com/gushi/xgs/20170926-153622.html
  • z####.505####.com.####.com/images/app_tuiguang_wap/bg1.jpg
  • z####.505####.com.####.com/images/app_tuiguang_wap/bg3.jpg
  • z####.505####.com.####.com/images/app_tuiguang_wap/bg4.jpg
  • z####.505####.com.####.com/images/app_tuiguang_wap/icon1.png
  • z####.505####.com.####.com/images/video_under.gif
  • z####.505####.com.####.com/images/wap150828/img_b.png
  • z####.505####.com.####.com/images/wap_mp3161122/new_icons.png
  • z####.505####.com.####.com/images/wap_mp3161122/sprites.png
  • z####.505####.com.####.com/images/wap_mp3161122/w-ico.png
  • z####.505####.com.####.com/js/abccount.js
  • z####.505####.com.####.com/js/baiduTemplate.js
  • z####.505####.com.####.com/js/env.js
  • z####.505####.com.####.com/js/iscroll.js
  • z####.505####.com.####.com/js/ks.lazyimg_v2.js
  • z####.505####.com.####.com/js/m.arwscroll.js
  • z####.505####.com.####.com/js/m.carousel.js
  • z####.505####.com.####.com/js/m.dialog2.js
  • z####.505####.com.####.com/js/m.slidePager.js
  • z####.505####.com.####.com/js/mp3cookie161122.js
  • z####.505####.com.####.com/js/mpage161112.js
  • z####.505####.com.####.com/js/mpage171017.js?1####
  • z####.505####.com.####.com/js/mpage_mp3161122.js
  • z####.505####.com.####.com/js/wap/app_tuiguang_wap_page.js
  • z####.505####.com.####.com/js/wap/baiduTemplate.js
  • z####.505####.com.####.com/js/wap/hammer.js
  • z####.505####.com.####.com/js/wap/m.dialog.js
  • z####.505####.com.####.com/js/zepto.cookie.js
  • z####.505####.com.####.com/js/zepto.min.js
  • z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
  • z.c####.com/stat.htm?id=4381083&r=http://m.4399er.com/ergeapp/?w####&lg=...
HTTP POST requests:
  • a####.u####.com/app_logs
  • s.un####.com/cw/cp.action?requestId=####&g=####
  • s.un####.com/cw/interface!u2.action?protocol=####&version=####
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/W_Key.xml
  • /data/data/####/WebViewSettings.xml
  • /data/data/####/__pasys.apk.beforesign.tm
  • /data/data/####/__pasys_remote_banner.jar.beforesign.tm
  • /data/data/####/__pasys_remote_banner.tmp.jar
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/downloadswc
  • /data/data/####/downloadswc-journal
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/http_m.4399er.com_0.localstorage-journal
  • /data/data/####/http_mobads.baidu.com_0.localstorage-journal
  • /data/data/####/index
  • /data/data/####/mobclick_agent_online_setting_com.moon.hao2.boys.xml
  • /data/data/####/st.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/media/####/3.6_rio.jar.tmp
  • /data/media/####/assetstime.dat
Miscellaneous:
Loads the following dynamic libraries:
  • ke
Uses the following algorithms to decrypt data:
  • RSA-ECB-PKCS1Padding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android