Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Was.10739

Added to the Dr.Web virus database: 2022-05-05

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Was.1.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) a.da####.com:9127
  • TCP(HTTP/1.1) api.ad.xi####.com:80
  • TCP(HTTP/1.1) xi####.edges####.net:80
  • TCP(HTTP/1.1) g####.62####.com:8001
  • TCP(TLS/1.0) f.ma####.c.####.com:443
  • TCP(TLS/1.0) 1####.251.39.106:443
  • TCP(TLS/1.0) api.ad.xi####.com:443
  • TCP(TLS/1.0) xi####.edges####.net:443
  • TCP(TLS/1.0) kk####.oss-cn-####.aliy####.com:443
  • TCP(TLS/1.0) 1####.250.179.138:443
  • TCP(TLS/1.0) sdkco####.ad.xi####.com:443
  • TCP(TLS/1.2) 1####.250.179.138:443
  • TCP(TLS/1.2) 1####.251.39.106:443
  • TCP(TLS/1.2) 1####.251.36.46:443
  • UDP rr1---s####.g####.com:443
  • UDP 1####.251.39.106:443
DNS requests:
  • a.da####.com
  • api.ad.xi####.com
  • f####.ma####.xi####.com
  • f4.ma####.xi####.com
  • f5.ma####.xi####.com
  • g####.62####.com
  • kk####.oss-cn-####.aliy####.com
  • m####.go####.com
  • rr1---s####.g####.com
  • sdkco####.ad.xi####.com
  • z####.ad.xi####.com
HTTP GET requests:
  • a.da####.com:9127/ll/gs?baseversion=####&version=####&channel=####&appid...
  • f.ma####.c.####.com:443/download/AdCenter/0e830c372382e473d94ba4667b014d...
  • kk####.oss-cn-####.aliy####.com:443/unity_xm_lp_39917.action
  • sdkco####.ad.xi####.com:443/api/checkupdate/lastusefulversion2?av=####&c...
  • xi####.edges####.net:443/download/AppStore/0b03c468e99cd7327ccf099da4abb...
HTTP POST requests:
  • a.da####.com:9127/ll//uu?t=####
  • api.ad.xi####.com/union/fetchAds
  • api.ad.xi####.com:443/client/upgrade/mimo/v1
  • g####.62####.com:8001/adStatistics
  • g####.62####.com:8001/addNewApp
  • g####.62####.com:8001/gameState
File system changes:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/.jgck
  • /data/data/####/1
  • /data/data/####/2
  • /data/data/####/20
  • /data/data/####/3
  • /data/data/####/_m_rec.xml
  • /data/data/####/_m_rec.xml.bak
  • /data/data/####/analytics.apk.tmp
  • /data/data/####/analytics_updater.xml
  • /data/data/####/apprater.xml
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cheuu
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.oat
  • /data/data/####/classes.oat.flock (deleted)
  • /data/data/####/kva
  • /data/data/####/libjiagu.so
  • /data/data/####/mimo_asset.apk
  • /data/data/####/mimo_asset.dex
  • /data/data/####/mimo_asset.dex.flock (deleted)
  • /data/data/####/mimo_download.apk.tmp
  • /data/data/####/plugin_updater.xml
  • /data/data/####/proc_auxv
  • /data/data/####/qihoo_jiagu_crash_report.xml
  • /data/data/####/shortcut.xml
  • /data/data/####/tmd
  • /data/data/####/tv
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/uuloi
  • /data/data/####/vva
  • /data/data/####/vva.dex
  • /data/data/####/vva.dex.flock (deleted)
  • /data/data/####/vva.jar
  • /data/data/####/yg_cache_prefs.xml
  • /data/data/####/zeus_crash_info.xml
  • /data/data/####/zeus_pms.xml
  • /data/data/####/zeus_pms.xml.bak (deleted)
  • /data/media/####/1.0
  • /data/media/####/COGLES2FixedPipeline.fsh
  • /data/media/####/COGLES2FixedPipeline.vsh
  • /data/media/####/COGLES2NormalMap.fsh
  • /data/media/####/COGLES2NormalMap.vsh
  • /data/media/####/COGLES2ParallaxMap.fsh
  • /data/media/####/COGLES2ParallaxMap.vsh
  • /data/media/####/COGLES2Renderer2D.fsh
  • /data/media/####/COGLES2Renderer2D.vsh
  • /data/media/####/DroidSansFallbackFull.ttf
  • /data/media/####/abilities.lua
  • /data/media/####/anvil.lua
  • /data/media/####/api.lua
  • /data/media/####/armor_copper_boots.png
  • /data/media/####/armor_copper_chestplate.png
  • /data/media/####/armor_copper_helm.png
  • /data/media/####/armor_copper_leggings.png
  • /data/media/####/armor_diamond_boots.png
  • /data/media/####/armor_diamond_chestplate.png
  • /data/media/####/armor_diamond_helm.png
  • /data/media/####/armor_diamond_leggings.png
  • /data/media/####/armor_iron_boots.png
  • /data/media/####/armor_iron_chestplate.png
  • /data/media/####/armor_iron_helm.png
  • /data/media/####/armor_iron_leggings.png
  • /data/media/####/armor_skin_copper_boots.png
  • /data/media/####/armor_skin_copper_chestplate.png
  • /data/media/####/armor_skin_copper_helm.png
  • /data/media/####/armor_skin_copper_leggings.png
  • /data/media/####/armor_skin_diamond_boots.png
  • /data/media/####/armor_skin_diamond_chestplate.png
  • /data/media/####/armor_skin_diamond_helm.png
  • /data/media/####/armor_skin_diamond_leggings.png
  • /data/media/####/armor_skin_iron_boots.png
  • /data/media/####/armor_skin_iron_chestplate.png
  • /data/media/####/armor_skin_iron_helm.png
  • /data/media/####/armor_skin_iron_leggings.png
  • /data/media/####/async_event.lua
  • /data/media/####/auth.lua
  • /data/media/####/background.png
  • /data/media/####/birchtree1.mts
  • /data/media/####/birchtree2.mts
  • /data/media/####/blueprint_blueprint.png
  • /data/media/####/blueprint_empty.png
  • /data/media/####/bubble.png
  • /data/media/####/buttonbar.lua
  • /data/media/####/character.mtl
  • /data/media/####/character.obj
  • /data/media/####/character.png
  • /data/media/####/character.x
  • /data/media/####/character_editor_blue_shirt.png
  • /data/media/####/character_editor_red_shirt.png
  • /data/media/####/character_editor_yellow_shirt.png
  • /data/media/####/character_layout.png
  • /data/media/####/chatcommands.lua
  • /data/media/####/common.lua
  • /data/media/####/components.lua
  • /data/media/####/constants.lua
  • /data/media/####/crack_anylength.png
  • /data/media/####/craft.lua
  • /data/media/####/crafting_guide_book.png
  • /data/media/####/crafting_guide_lens.png
  • /data/media/####/craftitems.lua
  • /data/media/####/crosshair.png
  • /data/media/####/cube.po
  • /data/media/####/cube.pot
  • /data/media/####/default_alt_dirt.png
  • /data/media/####/default_andesite.png
  • /data/media/####/default_axe.png
  • /data/media/####/default_axe_copper.png
  • /data/media/####/default_axe_diamond.png
  • /data/media/####/default_axe_stone.png
  • /data/media/####/default_basic_hammer.png
  • /data/media/####/default_blade.png
  • /data/media/####/default_box_front.png
  • /data/media/####/default_box_side.png
  • /data/media/####/default_brick.png
  • /data/media/####/default_click_1.ogg
  • /data/media/####/default_coal_dust.png
  • /data/media/####/default_coal_lump.png
  • /data/media/####/default_coalblock.png
  • /data/media/####/default_coalblock_glowing.png
  • /data/media/####/default_cobble.png
  • /data/media/####/default_compressed_sandstone.png
  • /data/media/####/default_diamond.png
  • /data/media/####/default_dirt.png
  • /data/media/####/default_dirt_1.ogg
  • /data/media/####/default_dirt_with_snow.png
  • /data/media/####/default_dry_grass.png
  • /data/media/####/default_flint.png
  • /data/media/####/default_flint_pick.png
  • /data/media/####/default_floor.png
  • /data/media/####/default_flower_1.png
  • /data/media/####/default_flower_2.png
  • /data/media/####/default_frame.png
  • /data/media/####/default_frame_detail.png
  • /data/media/####/default_glass.png
  • /data/media/####/default_glass_detail.png
  • /data/media/####/default_grass.png
  • /data/media/####/default_grass_flowers.png
  • /data/media/####/default_grass_wet.png
  • /data/media/####/default_gravel.png
  • /data/media/####/default_ice.png
  • /data/media/####/default_jungle_tree.png
  • /data/media/####/default_jungle_tree_top.png
  • /data/media/####/default_jungle_wood.png
  • /data/media/####/default_knife.png
  • /data/media/####/default_ladder.png
  • /data/media/####/default_lamp.png
  • /data/media/####/default_leaves_1.png
  • /data/media/####/default_leaves_2.png
  • /data/media/####/default_leaves_3.png
  • /data/media/####/default_leaves_4.png
  • /data/media/####/default_leaves_5.png
  • /data/media/####/default_liana.png
  • /data/media/####/default_log.png
  • /data/media/####/default_log_birch.png
  • /data/media/####/default_log_birch_top.png
  • /data/media/####/default_log_top.png
  • /data/media/####/default_mossy_stonebrick.png
  • /data/media/####/default_mushroom.png
  • /data/media/####/default_mushroom_inv.png
  • /data/media/####/default_pick.png
  • /data/media/####/default_pick_copper.png
  • /data/media/####/default_pick_diamond.png
  • /data/media/####/default_plant_grass.png
  • /data/media/####/default_plant_grass_2.png
  • /data/media/####/default_plant_grass_3.png
  • /data/media/####/default_plant_grass_4.png
  • /data/media/####/default_plant_grass_5.png
  • /data/media/####/default_quartz.png
  • /data/media/####/default_rail.png
  • /data/media/####/default_rail_cross.png
  • /data/media/####/default_rail_curve.png
  • /data/media/####/default_rail_t.png
  • /data/media/####/default_rope.png
  • /data/media/####/default_ruby.png
  • /data/media/####/default_sand.png
  • /data/media/####/default_sandstone.png
  • /data/media/####/default_sandstone_brick.png
  • /data/media/####/default_sapling.png
  • /data/media/####/default_sapling_2.png
  • /data/media/####/default_saw.png
  • /data/media/####/default_saw_copper.png
  • /data/media/####/default_saw_diamond.png
  • /data/media/####/default_shears.png
  • /data/media/####/default_shovel.png
  • /data/media/####/default_shovel_copper.png
  • /data/media/####/default_shovel_diamond.png
  • /data/media/####/default_small_stone_tile.png
  • /data/media/####/default_snow.png
  • /data/media/####/default_stick.png
  • /data/media/####/default_stone.png
  • /data/media/####/default_stone_1.ogg
  • /data/media/####/default_stone_2.ogg
  • /data/media/####/default_stone_item.png
  • /data/media/####/default_stone_tile.png
  • /data/media/####/default_stone_with_coal.png
  • /data/media/####/default_stone_with_copper.png
  • /data/media/####/default_stone_with_diamond.png
  • /data/media/####/default_stone_with_gold.png
  • /data/media/####/default_stone_with_iron.png
  • /data/media/####/default_stone_with_ruby.png
  • /data/media/####/default_stone_with_silver.png
  • /data/media/####/default_stone_with_zinc.png
  • /data/media/####/default_stonebrick.png
  • /data/media/####/default_stones_on_floor.png
  • /data/media/####/default_straw_side.png
  • /data/media/####/default_straw_top.png
  • /data/media/####/default_string.png
  • /data/media/####/default_string_strong.png
  • /data/media/####/default_string_top.png
  • /data/media/####/default_treasure_chest.png
  • /data/media/####/default_twig.png
  • /data/media/####/default_water.png
  • /data/media/####/default_wet_sand.png
  • /data/media/####/default_wet_stone.png
  • /data/media/####/default_wire.png
  • /data/media/####/default_wire_cross.png
  • /data/media/####/default_wire_curve.png
  • /data/media/####/default_wire_t.png
  • /data/media/####/default_wood.png
  • /data/media/####/default_wood_1.ogg
  • /data/media/####/default_wood_birch.png
  • /data/media/####/default_wooden_planks.png
  • /data/media/####/default_wooden_planks_2.png
  • /data/media/####/default_wooden_planks_2_birch.png
  • /data/media/####/default_wooden_planks_2_jungle.png
  • /data/media/####/default_wooden_planks_birch.png
  • /data/media/####/default_wooden_planks_jungle.png
  • /data/media/####/default_wool.png
  • /data/media/####/default_workbench_top.png
  • /data/media/####/default_workbench_v2_top.png
  • /data/media/####/default_xp.png
  • /data/media/####/depends.txt
  • /data/media/####/deprecated.lua
  • /data/media/####/description.txt
  • /data/media/####/detached_inventory.lua
  • /data/media/####/dialog.lua
  • /data/media/####/dlg_config_world.lua
  • /data/media/####/dlg_create_world.lua
  • /data/media/####/dlg_delete_mod.lua
  • /data/media/####/dlg_delete_world.lua
  • /data/media/####/dlg_rename_modpack.lua
  • /data/media/####/dlg_settings_advanced.lua
  • /data/media/####/drytree1.mts
  • /data/media/####/drytree2.mts
  • /data/media/####/falling.lua
  • /data/media/####/farm.mts
  • /data/media/####/farming_apple.png
  • /data/media/####/farming_bowl.png
  • /data/media/####/farming_bowl_with_water.png
  • /data/media/####/farming_cactus.png
  • /data/media/####/farming_cactus_soup.png
  • /data/media/####/farming_cactus_top.png
  • /data/media/####/farming_carrot.png
  • /data/media/####/farming_carrot_1.png
  • /data/media/####/farming_carrot_2.png
  • /data/media/####/farming_carrot_3.png
  • /data/media/####/farming_cookie.png
  • /data/media/####/farming_flour.png
  • /data/media/####/farming_mushroom_soup.png
  • /data/media/####/farming_slice_of_bread.png
  • /data/media/####/farming_sugar.png
  • /data/media/####/farming_sugarcane.png
  • /data/media/####/farming_wheat_1.png
  • /data/media/####/farming_wheat_2.png
  • /data/media/####/farming_wheat_3.png
  • /data/media/####/farming_wheat_4.png
  • /data/media/####/farming_wheat_5.png
  • /data/media/####/farming_wheat_seeds.png
  • /data/media/####/features.lua
  • /data/media/####/filterlist.lua
  • /data/media/####/fishing_cooked_fish.png
  • /data/media/####/fishing_fish.png
  • /data/media/####/fishing_fish_1.png
  • /data/media/####/fishing_fish_2.png
  • /data/media/####/fishing_fishing_rod.png
  • /data/media/####/fishing_fishing_rod_wield.png
  • /data/media/####/forceloading.lua
  • /data/media/####/functions.lua
  • /data/media/####/furnace.lua
  • /data/media/####/furnace_anvil_front.png
  • /data/media/####/furnace_anvil_side.png
  • /data/media/####/furnace_anvil_top.png
  • /data/media/####/furnace_copper_block.png
  • /data/media/####/furnace_copper_plate.png
  • /data/media/####/furnace_copper_rod.png
  • /data/media/####/furnace_diamond_plate.png
  • /data/media/####/furnace_diamond_rod.png
  • /data/media/####/furnace_gold_block.png
  • /data/media/####/furnace_gold_plate.png
  • /data/media/####/furnace_gold_rod.png
  • /data/media/####/furnace_iron_block.png
  • /data/media/####/furnace_iron_plate.png
  • /data/media/####/furnace_iron_rod.png
  • /data/media/####/furnace_pattern_blade.png
  • /data/media/####/furnace_pattern_plate.png
  • /data/media/####/furnace_pattern_rod.png
  • /data/media/####/furnace_pick_top.png
  • /data/media/####/furnace_steel_frame.png
  • /data/media/####/furnace_steel_frame_detail.png
  • /data/media/####/furnace_stone_front.png
  • /data/media/####/game.conf
  • /data/media/####/gamemgr.lua
  • /data/media/####/garden.mts
  • /data/media/####/generate_from_settingtypes.lua
  • /data/media/####/gui_bg.png
  • /data/media/####/gui_hotbar.png
  • /data/media/####/gui_hotbar_selected.png
  • /data/media/####/gui_itemslot_bg.png
  • /data/media/####/header.png
  • /data/media/####/heart.png
  • /data/media/####/house1.mts
  • /data/media/####/house2.mts
  • /data/media/####/house_1.mts
  • /data/media/####/house_2.mts
  • /data/media/####/icon.png
  • /data/media/####/init.lua
  • /data/media/####/init_simple.lua
  • /data/media/####/instrumentation.lua
  • /data/media/####/item.lua
  • /data/media/####/item_entity.lua
  • /data/media/####/juice_apple.png
  • /data/media/####/juice_cactus.png
  • /data/media/####/juice_glass.png
  • /data/media/####/juice_strawberry.png
  • /data/media/####/juice_water.png
  • /data/media/####/jungletree.mts
  • /data/media/####/lava_basalt.png
  • /data/media/####/lava_lava.png
  • /data/media/####/legendary_items_old_battle_axe.png
  • /data/media/####/legendary_items_old_hammer.png
  • /data/media/####/legendary_items_paper.png
  • /data/media/####/legendary_items_paper_green.png
  • /data/media/####/legendary_items_sugar_sword.png
  • /data/media/####/legendary_items_sword.png
  • /data/media/####/legendary_items_tp.png
  • /data/media/####/liberationmono.ttf
  • /data/media/####/liberationsans.ttf
  • /data/media/####/lucida_sans_10.xml
  • /data/media/####/lucida_sans_100.png
  • /data/media/####/lucida_sans_11.xml
  • /data/media/####/lucida_sans_110.png
  • /data/media/####/lucida_sans_12.xml
  • /data/media/####/lucida_sans_120.png
  • /data/media/####/lucida_sans_14.xml
  • /data/media/####/lucida_sans_140.png
  • /data/media/####/lucida_sans_16.xml
  • /data/media/####/lucida_sans_160.png
  • /data/media/####/lucida_sans_18.xml
  • /data/media/####/lucida_sans_180.png
  • /data/media/####/lucida_sans_20.xml
  • /data/media/####/lucida_sans_200.png
  • /data/media/####/lucida_sans_22.xml
  • /data/media/####/lucida_sans_220.png
  • /data/media/####/lucida_sans_24.xml
  • /data/media/####/lucida_sans_240.png
  • /data/media/####/lucida_sans_26.xml
  • /data/media/####/lucida_sans_260.png
  • /data/media/####/lucida_sans_28.xml
  • /data/media/####/lucida_sans_280.png
  • /data/media/####/lucida_sans_36.xml
  • /data/media/####/lucida_sans_360.png
  • /data/media/####/lucida_sans_4.xml
  • /data/media/####/lucida_sans_40.png
  • /data/media/####/lucida_sans_48.xml
  • /data/media/####/lucida_sans_480.png
  • /data/media/####/lucida_sans_56.xml
  • /data/media/####/lucida_sans_560.png
  • /data/media/####/lucida_sans_6.xml
  • /data/media/####/lucida_sans_60.png
  • /data/media/####/lucida_sans_8.xml
  • /data/media/####/lucida_sans_80.png
  • /data/media/####/lucida_sans_9.xml
  • /data/media/####/lucida_sans_90.png
  • /data/media/####/mapgen.lua
  • /data/media/####/minetest.conf
  • /data/media/####/minimap_mask_round.png
  • /data/media/####/minimap_mask_square.png
  • /data/media/####/minimap_overlay_round.png
  • /data/media/####/minimap_overlay_square.png
  • /data/media/####/misc.lua
  • /data/media/####/misc_helpers.lua
  • /data/media/####/missing.png
  • /data/media/####/mobs.lua
  • /data/media/####/mobs_angry_cloud.png
  • /data/media/####/mobs_blue_cube.png
  • /data/media/####/mobs_book.png
  • /data/media/####/mobs_coal_monster.png
  • /data/media/####/mobs_dungeon_guardian.png
  • /data/media/####/mobs_grass_monster.png
  • /data/media/####/mobs_hedgehog.png
  • /data/media/####/mobs_lava_flower.png
  • /data/media/####/mobs_slime.png
  • /data/media/####/mobs_spawn.png
  • /data/media/####/mobs_spawner.png
  • /data/media/####/mobs_spawner_side.png
  • /data/media/####/mod_profiling.lua
  • /data/media/####/modmgr.lua
  • /data/media/####/money_coin.png
  • /data/media/####/money_shop.png
  • /data/media/####/money_shop_bottom.png
  • /data/media/####/money_shop_top.png
  • /data/media/####/money_silver_coin.png
  • /data/media/####/mono_dejavu_sans_10.xml
  • /data/media/####/mono_dejavu_sans_100.png
  • /data/media/####/mono_dejavu_sans_11.xml
  • /data/media/####/mono_dejavu_sans_110.png
  • /data/media/####/mono_dejavu_sans_12.xml
  • /data/media/####/mono_dejavu_sans_120.png
  • /data/media/####/mono_dejavu_sans_14.xml
  • /data/media/####/mono_dejavu_sans_140.png
  • /data/media/####/mono_dejavu_sans_16.xml
  • /data/media/####/mono_dejavu_sans_160.png
  • /data/media/####/mono_dejavu_sans_18.xml
  • /data/media/####/mono_dejavu_sans_180.png
  • /data/media/####/mono_dejavu_sans_20.xml
  • /data/media/####/mono_dejavu_sans_200.png
  • /data/media/####/mono_dejavu_sans_22.xml
  • /data/media/####/mono_dejavu_sans_220.png
  • /data/media/####/mono_dejavu_sans_24.xml
  • /data/media/####/mono_dejavu_sans_240.png
  • /data/media/####/mono_dejavu_sans_26.xml
  • /data/media/####/mono_dejavu_sans_260.png
  • /data/media/####/mono_dejavu_sans_28.xml
  • /data/media/####/mono_dejavu_sans_280.png
  • /data/media/####/mono_dejavu_sans_4.xml
  • /data/media/####/mono_dejavu_sans_40.png
  • /data/media/####/mono_dejavu_sans_6.xml
  • /data/media/####/mono_dejavu_sans_60.png
  • /data/media/####/mono_dejavu_sans_8.xml
  • /data/media/####/mono_dejavu_sans_80.png
  • /data/media/####/mono_dejavu_sans_9.xml
  • /data/media/####/mono_dejavu_sans_90.png
  • /data/media/####/moon.png
  • /data/media/####/nodes.lua
  • /data/media/####/npc.x
  • /data/media/####/opengl_fragment.glsl
  • /data/media/####/opengl_vertex.glsl
  • /data/media/####/paraglider_item.png
  • /data/media/####/pets_pig.png
  • /data/media/####/pets_pig.x
  • /data/media/####/pets_pig_spawn.png
  • /data/media/####/pets_sheep.png
  • /data/media/####/pets_sheep.x
  • /data/media/####/pets_sheep_spawn.png
  • /data/media/####/pets_wolf_spawn.png
  • /data/media/####/pinetree1.mts
  • /data/media/####/pinetree2.mts
  • /data/media/####/player.lua
  • /data/media/####/player.png
  • /data/media/####/player_back.png
  • /data/media/####/player_marker.png
  • /data/media/####/po.xml
  • /data/media/####/potions_black.png
  • /data/media/####/potions_blue.png
  • /data/media/####/potions_glass.png
  • /data/media/####/potions_green.png
  • /data/media/####/potions_red.png
  • /data/media/####/potions_yellow.png
  • /data/media/####/privileges.lua
  • /data/media/####/quests_glowing_ray.png
  • /data/media/####/quests_map.png
  • /data/media/####/quests_map_top.png
  • /data/media/####/redtree1.mts
  • /data/media/####/redtree2.mts
  • /data/media/####/register.lua
  • /data/media/####/reporter.lua
  • /data/media/####/road.mts
  • /data/media/####/sampling.lua
  • /data/media/####/serialize.lua
  • /data/media/####/server_flags_damage.png
  • /data/media/####/server_flags_pvp.png
  • /data/media/####/settingtypes.txt
  • /data/media/####/skills_abilities_book.png
  • /data/media/####/skills_abilities_energy.png
  • /data/media/####/skills_abilities_grow.png
  • /data/media/####/skills_abilities_heal.png
  • /data/media/####/skills_abilities_lift.png
  • /data/media/####/skills_abilities_run.png
  • /data/media/####/skills_abilities_smooth_fall.png
  • /data/media/####/skills_abilities_super_jump.png
  • /data/media/####/skills_bow.png
  • /data/media/####/skills_bow_wield.png
  • /data/media/####/skills_chemical_spear.png
  • /data/media/####/skills_hoe.png
  • /data/media/####/skills_lock_pick.png
  • /data/media/####/skills_pitchfork.png
  • /data/media/####/skills_shield.png
  • /data/media/####/skills_spear.png
  • /data/media/####/skills_stick.png
  • /data/media/####/skills_sword.png
  • /data/media/####/skills_sword_copper.png
  • /data/media/####/smoke_puff.png
  • /data/media/####/sneak_1.png
  • /data/media/####/spawner.lua
  • /data/media/####/stairs_chisel.png
  • /data/media/####/statbars.lua
  • /data/media/####/static_spawn.lua
  • /data/media/####/store.lua
  • /data/media/####/strict.lua
  • /data/media/####/sun.png
  • /data/media/####/sunrisebg.png
  • /data/media/####/tab_credits.lua
  • /data/media/####/tab_mods.lua
  • /data/media/####/tab_multiplayer.lua
  • /data/media/####/tab_server.lua
  • /data/media/####/tab_settings.lua
  • /data/media/####/tab_simple_main.lua
  • /data/media/####/tab_singleplayer.lua
  • /data/media/####/tab_texturepacks.lua
  • /data/media/####/tabview.lua
  • /data/media/####/textures.lua
  • /data/media/####/tools.lua
  • /data/media/####/torch_torch_ceiling.png
  • /data/media/####/torch_torch_floor.png
  • /data/media/####/torch_torch_inv.png
  • /data/media/####/torch_torch_wall.png
  • /data/media/####/tree1.mts
  • /data/media/####/tree2.mts
  • /data/media/####/tree3.mts
  • /data/media/####/trees.lua
  • /data/media/####/ui.lua
  • /data/media/####/ui.plist
  • /data/media/####/ui.png
  • /data/media/####/unknown_item.png
  • /data/media/####/unknown_node.png
  • /data/media/####/unknown_object.png
  • /data/media/####/vector.lua
  • /data/media/####/village.mts
  • /data/media/####/village_create.png
  • /data/media/####/village_spawn.png
  • /data/media/####/voxelarea.lua
  • /data/media/####/wieldhand.png
  • /data/media/####/wolf_black.png
  • /data/media/####/wolf_wolf.x
  • /data/media/####/xp_xp.png
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • cat /sys/class/net/wlan0/address
Loads the following dynamic libraries:
  • libMine
  • libjiagu
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.
Requests the system alert window permission.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android