How to remove Android.Becu.1.origin and Android.Becu.3.origin

Recently, DR. WEB reported that smartphones from some companies may have a virus located directly in the firmware system files. They called it Android.Becu.1.origin and Android.Becu.3.origin

I won't describe in detail what the virus does. You can read about it on the Dr.Web website. In this article I want to describe in detail how to remove Android.Becu.1.origin and Android.Becu.3.origin

Screenshot_2015-03-30-23-27-45

Since this program is a system program, it is not so easy to remove it. But do not be upset. You can remove Android.Becu.1.origin and Android.Becu.3.origin by installing just a couple of programs.

  1. ES Explorer - we will need it to get to system files
  2. Framroot - we will need it to edit system files
  3. Dr. WEB — for detecting infected files

All necessary files that will help to remove Android.Becu.1.origin and Android.Becu.3.origin can be downloaded from Yandex.disk

After you have downloaded and installed these programs, you need to run the Framroot program.

I would like to separately note that the Framroot program works mainly on devices with a MediaTek chip. If you have another device, you can read the instructions for obtaining Root rights on it in a separate article

After launching the program, you need to select one of the items. If the message "Success" appears, you need to reboot the device. If it does not appear, use another item.

Screenshot_2015-03-30-23-29-10

After rebooting, launch the ES Explorer program. In it, activate root and access to system files. Open "Tools" and enable "Root Explorer"

Screenshot_2015-03-30-23-30-36

In the pop-up window, click provide

Screenshot_2015-03-30-23-30-31

Now we need to allow overwriting of system files. Click again on "Root Explorer" and select "Connect as R/W"

Screenshot_2015-03-30-23-30-46

And we set the values as in the picture

Screenshot_2015-03-30-23-31-00

Then you need to go to the system files and delete Android.Becu.1.origin. To do this, go to "Device"

Screenshot_2015-03-30-23-31-31

There we find the folder "system" and in it the folder "app". In this folder we need to find the files that the antivirus detected. In our case, these are Cube_CJIA01.apk and uuapush.apk

If your antivirus has detected the 3rd file Android.Becu.3.origin, then delete it too.

Android.Becu.1.origin
Android.Becu.1.origin

Select them and click delete. That's it! The intrusive viruses are removed.

Now all that remains is to clear the system of root rights.

Find the SuperSU app with a hash icon among your apps and launch it. Scroll down to the very bottom and click on “Full Root Removal”

Screenshot_2015-03-30-23-35-16

Now open settings-applications and select "Framroot". In the window that opens, select delete application.

After scanning with antivirus you will see a pleasant result

Screenshot_2015-03-30-23-40-21

If you have any questions, I will be happy to answer them in the comments.

SEO Expert and Web Developer

Rate author
iNevidimka Blog
en_USEnglish