マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.384

Added to the Dr.Web virus database: 2018-07-20

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) t####.me####.com:80
  • TCP(HTTP/1.1) sh####.360t####.com:80
  • TCP(HTTP/1.1) up####.sdk.jig####.cn:80
  • TCP(HTTP/1.1) qos.l####.360.cn:80
  • TCP(HTTP/1.1) trac####.v.tf.####.cn:80
  • TCP(HTTP/1.1) m3.s.3####.cn:80
  • TCP(HTTP/1.1) api.k.36####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) p9.q####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) s####.s.360.cn:80
  • TCP(HTTP/1.1) p1.q####.com:80
  • TCP(HTTP/1.1) u.api.l####.####.cn:80
  • TCP(HTTP/1.1) ab####.m.s.####.cn:80
  • TCP(HTTP/1.1) amdc####.m.ta####.com:80
  • TCP(HTTP/1.1) p10.qhi####.com:80
  • TCP(HTTP/1.1) sni.c####.q####.####.net:80
  • TCP(HTTP/1.1) sdk.l####.360.cn:80
  • TCP(HTTP/1.1) p.s.3####.cn:80
  • TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.net:80
  • TCP(HTTP/1.1) s####.l####.360.####.com:80
  • TCP(HTTP/1.1) app.v.k.####.com:80
  • TCP(HTTP/1.1) k####.36####.com:80
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP(TLS/1.0) t####.me####.com:443
  • TCP(TLS/1.0) app.k.36####.com:443
  • TCP(TLS/1.0) mdm.ope####.360.cn:443
  • TCP(TLS/1.0) 2####.107.1.97:443
  • TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
  • TCP(TLS/1.0) s####.tf.360.cn:443
  • TCP(TLS/1.0) sdkc####.e.360.cn:443
  • TCP(TLS/1.0) cc.p####.dc.####.cn:443
  • TCP(TLS/1.0) api####.me####.com:443
  • TCP(TLS/1.0) s####.j####.cn:443
  • TCP c####.g####.ig####.com:5224
  • TCP 1####.163.230.187:80
  • TCP sdk.o####.t####.####.com:5224
  • UDP s.j####.cn:19000
  • TCP 1####.121.49.99:7007
  • TCP 1####.205.60.10:80
  • TCP ope####.m.ta####.com:443
DNS requests:
  • 7j####.c####.z0.####.com
  • a####.man.aliy####.com
  • ab####.m.s.####.cn
  • amdc####.m.ta####.com
  • api####.me####.com
  • api.k.36####.com
  • app.k.36####.com
  • app.v.k.####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cc.p####.dc.####.cn
  • k####.36####.com
  • m####.me####.com
  • m3.s.3####.cn
  • mdm.ope####.360.cn
  • msg.umengc####.com
  • p.s.3####.cn
  • p0.q####.com
  • p1.q####.com
  • p10.qhi####.com
  • p15.q####.com
  • p2.q####.com
  • p3.q####.com
  • p4.q####.com
  • p5.q####.com
  • p6.q####.com
  • p7.q####.com
  • p8.q####.com
  • p9.q####.com
  • plb####.u####.com
  • qos.l####.360.cn
  • s####.j####.cn
  • s####.l####.360.cn
  • s####.s.360.cn
  • s####.tf.360.cn
  • s.j####.cn
  • sdk.c####.ig####.com
  • sdk.l####.360.cn
  • sdk.l####.360.cn
  • sdk.me####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sdkc####.e.360.cn
  • sh####.360t####.com
  • sh####.me####.com
  • t####.me####.com
  • trac####.v.tf.####.cn
  • u####.u####.com
  • u.api.l####.####.cn
  • umen####.m.ta####.com
  • up####.sdk.jig####.cn
HTTP GET requests:
  • ab####.m.s.####.cn/abtest/cloud.so?appkey=####&dt=####&os=####&ov=####&m...
  • app.v.k.####.com/vod-xinxiliu-tv-q2-bj/43690288_18631413f-3b4b-4d82-95ed...
  • app.v.k.####.com/vod-xinxiliu-tv-q2-bj/51661207_1de45a085-f342-4aed-8a18...
  • k####.36####.com//k2/appconfig/getjar?appid=####&m=####&m2=####&ch=####&...
  • k####.36####.com/hotrizon2/appConfig?os=####&use_gear=####&time=####&sys...
  • k####.36####.com/hotrizon2/channelnew?m2=####&appid=####&m=####&ch=####&...
  • k####.36####.com/hotrizon2/list?svc=####&kw=####&os=####&ckw=####&sys=##...
  • k####.36####.com/hotrizon2/list?svc=####&os=####&sys=####&direction=####...
  • k####.36####.com/hotrizon2/myfollower?appid=####&maxOffset=####&m=####&m...
  • k####.36####.com/hotrizon2/play?id=####&m2=####&strategy=####&appid=####...
  • k####.36####.com/k2/api/privacy/config?appid=####&m=####&m2=####&ch=####...
  • k####.36####.com/k2/appconfig/getAbRole?os=####&time=####&sys=####&m2=##...
  • k####.36####.com/k2/appconfig/getNewinfo?appid=####&m=####&m2=####&ch=##...
  • k####.36####.com/k2/appconfig/getRedpackPop?appid=####&m=####&m2=####&ch...
  • k####.36####.com/k2/appconfig/getplugin?appid=####&m=####&m2=####&ch=###...
  • k####.36####.com/k2/appconfig/getpopup?appid=####&m=####&m2=####&ch=####...
  • k####.36####.com/k2/hotrizon2/aconfig?appid=####&m=####&m2=####&ch=####&...
  • k####.36####.com/k2/hotrizon2/gettime?os=####&sys=####&m2=####&appid=###...
  • p1.q####.com/dr/160_160_/t01af4701a7af69e1c9.png
  • p1.q####.com/dr/_100_70/t014ca9fd1bcbdd29d9.jpg
  • p1.q####.com/dr/_100_70/t017037ac66bbed1a72.jpg
  • p1.q####.com/dr/_100_70/t01bdafbf05a3413357.jpg
  • p1.q####.com/dr/_100_70/t01f9be2f9869b26f0e.jpg
  • p1.q####.com/t0127b908eb2a7b7ab2.jpg
  • p1.q####.com/t01368485bff87e3e5b.jpg
  • p1.q####.com/t013db82533aa9e5a9a.jpg
  • p1.q####.com/t0147eeb331a280d627.jpg
  • p1.q####.com/t0178bccfe750f110a1.jpg
  • p1.q####.com/t018a091efca6865662.jpg
  • p1.q####.com/t018a76b42c2a942173.jpg
  • p1.q####.com/t019f6478307ad0eea6.jpg
  • p1.q####.com/t01ae70f3f6372b712d.jpg
  • p1.q####.com/t01c1ff533a19145140.jpg
  • p1.q####.com/t01c284e24d09f6b14d.jpg
  • p1.q####.com/t01e69681fa8d4220ab.jpg
  • p1.q####.com/t01f9458c7931fe73bc.jpg
  • p1.q####.com/video/568_320_70/t01447940af14834e87.webp
  • p1.q####.com/video/568_320_70/t014d55017066b5dbda.webp
  • p1.q####.com/video/568_320_70/t01d854a3e8d69a7fdf.webp
  • p1.q####.com/video/568_320_70/t01f834b85bbffdd726.webp
  • p10.qhi####.com/dr/_100_70/t012bfcd889da98891f.jpg
  • p10.qhi####.com/dr/_100_70/t01a6f2b3fd0ccebd19.jpg
  • p10.qhi####.com/dr/_280_50/t0125d9b1b5ed96de24.webp
  • p10.qhi####.com/dr/_280_50/t015dc1b8bff1c9499b.webp
  • p10.qhi####.com/dr/_280_50/t018905e6990c4760d4.webp
  • p10.qhi####.com/dr/_280_50/t01cc6b1a18a15672a4.webp
  • p10.qhi####.com/dr/_280_50/t01de1aeb7ba66f57c0.webp
  • p10.qhi####.com/dr/_280_50/t01e83e55a8a5c694a4.webp
  • p10.qhi####.com/dr/_280_50/t01f5b2ac34cb96c3f8.webp
  • p9.q####.com/dr/_100_70/t010b7ba5540c9b6ab6.png
  • p9.q####.com/dr/_100_70/t0113c2577d0b48755c.jpg
  • p9.q####.com/dr/_100_70/t01168a66d2383c832c.jpg
  • p9.q####.com/dr/_100_70/t011a386935e86576cd.jpg
  • p9.q####.com/dr/_100_70/t013a77d32cb2187cad.jpg
  • p9.q####.com/dr/_100_70/t01404fb3066bd156ef.jpg
  • p9.q####.com/dr/_100_70/t014ad2662b5d1fce01.jpg
  • p9.q####.com/dr/_100_70/t014b5eff39f7348569.jpg
  • p9.q####.com/dr/_100_70/t015651c2d711a4fd59.jpg
  • p9.q####.com/dr/_100_70/t016f3dad96dfdbf246.jpg
  • p9.q####.com/dr/_100_70/t0174cba29cf91308b8.jpg
  • p9.q####.com/dr/_100_70/t017553aa836290fa32.jpg
  • p9.q####.com/dr/_100_70/t017974289365f11185.jpg
  • p9.q####.com/dr/_100_70/t0182e62aa4ec59d0d2.jpg
  • p9.q####.com/dr/_100_70/t018abf6517ed41e6a4.jpg
  • p9.q####.com/dr/_100_70/t019f8abc53abcfa200.jpg
  • p9.q####.com/dr/_100_70/t01d17228d829694a88.png
  • p9.q####.com/dr/_100_70/t01ddb5c274314e60ca.jpg
  • p9.q####.com/dr/_100_70/t01e6bdaf5d4ed288dc.jpg
  • p9.q####.com/dr/_100_70/t01ff1c0eac40229c5a.jpg
  • p9.q####.com/t01153c265593f3258e.jpg
  • p9.q####.com/t017fdd27104b8c3a54.png
  • p9.q####.com/t0183a202dd8e4b801d.png
  • p9.q####.com/t01b19228c70bf4078c.jpg
  • p9.q####.com/video/568_320_70/t0100ca9ad444514417.webp
  • p9.q####.com/video/568_320_70/t01154843efc3cfb619.webp
  • p9.q####.com/video/568_320_70/t011c0ee87c07f8b742.webp
  • p9.q####.com/video/568_320_70/t011c4b896e75f23ddc.webp
  • p9.q####.com/video/568_320_70/t0120ee14f0153d184d.webp
  • p9.q####.com/video/568_320_70/t0121dd65b2f5e96d53.webp
  • p9.q####.com/video/568_320_70/t012644526a92fc4be5.webp
  • p9.q####.com/video/568_320_70/t01277d588ad5bf6fca.webp
  • p9.q####.com/video/568_320_70/t012ed5310c862dba55.webp
  • p9.q####.com/video/568_320_70/t0130794d2102386d83.webp
  • p9.q####.com/video/568_320_70/t0131778b0ff030c791.webp
  • p9.q####.com/video/568_320_70/t0134a4047c82156964.webp
  • p9.q####.com/video/568_320_70/t01382ae02bad188d22.webp
  • p9.q####.com/video/568_320_70/t014e13b98cea9cefca.webp
  • p9.q####.com/video/568_320_70/t0150deccc7fe3b6745.webp
  • p9.q####.com/video/568_320_70/t015503c0f3214b7214.webp
  • p9.q####.com/video/568_320_70/t015780ea6d98dde3bc.webp
  • p9.q####.com/video/568_320_70/t015dc1b8bff1c9499b.webp
  • p9.q####.com/video/568_320_70/t01713c24fcd62efcca.webp
  • p9.q####.com/video/568_320_70/t0179c3b2d8a71f6c2c.webp
  • p9.q####.com/video/568_320_70/t018322f8a4af176f25.webp
  • p9.q####.com/video/568_320_70/t0187fb083e4a8c20b3.webp
  • p9.q####.com/video/568_320_70/t018905e6990c4760d4.webp
  • p9.q####.com/video/568_320_70/t0192c29cac818a18f8.webp
  • p9.q####.com/video/568_320_70/t019f7f995367968764.webp
  • p9.q####.com/video/568_320_70/t01a6006f9645f789bd.webp
  • p9.q####.com/video/568_320_70/t01a8da8a590c5b175c.webp
  • p9.q####.com/video/568_320_70/t01a98ce9c41a20116a.webp
  • p9.q####.com/video/568_320_70/t01ad6a59ac988f77d3.webp
  • p9.q####.com/video/568_320_70/t01b1666b062f2aa845.webp
  • p9.q####.com/video/568_320_70/t01b201bce0d351b2df.webp
  • p9.q####.com/video/568_320_70/t01b906f21de387730d.webp
  • p9.q####.com/video/568_320_70/t01bb1d595e1fcde9d2.webp
  • p9.q####.com/video/568_320_70/t01bbd40079d5b38aba.webp
  • p9.q####.com/video/568_320_70/t01c32c2d89c1df2536.webp
  • p9.q####.com/video/568_320_70/t01c79e0e8bf187d70c.webp
  • p9.q####.com/video/568_320_70/t01ca608b74315992da.webp
  • p9.q####.com/video/568_320_70/t01cc6b1a18a15672a4.webp
  • p9.q####.com/video/568_320_70/t01cd2ba2d4f56a0845.webp
  • p9.q####.com/video/568_320_70/t01d0e6d7c24eada713.webp
  • p9.q####.com/video/568_320_70/t01daeb4a05f6b11fa5.webp
  • p9.q####.com/video/568_320_70/t01de1aeb7ba66f57c0.webp
  • p9.q####.com/video/568_320_70/t01df80a20d22f3fc3e.webp
  • p9.q####.com/video/568_320_70/t01e0f1737186d07b06.webp
  • p9.q####.com/video/568_320_70/t01e83e55a8a5c694a4.webp
  • p9.q####.com/video/568_320_70/t01e846fbb4d579a8e6.webp
  • p9.q####.com/video/568_320_70/t01f52fcaed1f73354e.webp
  • p9.q####.com/video/568_320_70/t01f5a52f736dbd84bf.webp
  • p9.q####.com/video/568_320_70/t01f5b2ac34cb96c3f8.webp
  • p9.q####.com/video/568_320_70/t01fa456f529cef7974.webp
  • qos.l####.360.cn/vc.gif?&bid=####&pid=####&ver=####&c_ver=####&os=####&m...
  • s####.l####.360.####.com/Object.getFile/livecloudsdk/YW5kcm9pZF9wbHVnaW5...
  • s####.l####.360.####.com/Object.getFile/livecloudsdk/cGx1Z2luX3lmX3AycF8...
  • s####.s.360.cn/ak/6766aa2750c19aad2fa1b32f36ed4aee.html?m2=####
  • s####.s.360.cn/su/index.php?k=####&av=####&slv=####&sv=####&be=####&cv=#...
  • sdk.l####.360.cn/codec?os=####&tm=####&model=####&r=####&package=####&pi...
  • sdk.l####.360.cn/rtc?os=####&tm=####&model=####&r=####&package=####&pid=...
  • sdk.l####.360.cn/sdkconf/videoplace?sign=####&u=####&version=####&sdk_ve...
  • sdk.l####.360.cn/xinxiliu_tv_android_10228.conf?os=####&tm=####&r=####&p...
  • sh####.360t####.com/171122/c867c6e2f627a813302a3a0d0d891203/FZLTHK.TTF
  • sni.c####.q####.####.net/config/hz-hzv3.conf
  • t####.c####.q####.####.net/tdata_jVg168
  • t####.c####.q####.####.net/tdata_pSF696
  • t####.me####.com/rtb?type=####&d=####&b=####&p=####&l=####&s=####&m=####...
  • trac####.v.tf.####.cn/s?type=####&r=####&tid=####&finfo=####&enup=####&m...
HTTP POST requests:
  • amdc####.m.ta####.com/amdc/mobileDispatch?appkey=####&deviceId=####&plat...
  • api.k.36####.com/k2/api/lockscreen/config?os=####&time=####&sys=####&m2=...
  • c-h####.g####.com/api.php?format=####&t=####
  • k####.36####.com/hotrizon2/report2?os=####&time=####&sys=####&m2=####&ap...
  • k####.36####.com/k2/appconfig/getjarlist?appid=####&curEnv=####&m=####&m...
  • k####.36####.com/k2/hotrizon2/getSInfo?os=####&sys=####&psw2=QL####&ssid...
  • m3.s.3####.cn/api/v1/newid
  • p.s.3####.cn/pstat/plog.php
  • p.s.3####.cn/update/update.php?p=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
  • t####.me####.com/adsdk?pver=####&skey=Hg####
  • t####.me####.com/adsdk?pver=####&skey=Tk####
  • u.api.l####.####.cn/comment/lists
  • up####.sdk.jig####.cn/v1/push/sdk/postlist
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/01656d9c14b80f111d1d92a3a8c8ce14d11
  • /data/data/####/09370837-e50a-4626-ba1b-d8c0f2b1d853
  • /data/data/####/1489f3af-1bdc-40db-9a4b-c4175b0f073c
  • /data/data/####/2033145970-602345128
  • /data/data/####/256f604e-cd0a-4793-9ab7-6ffc94e6a76d
  • /data/data/####/38d4a656-a064-4fb6-9bb5-8a3114077e6f
  • /data/data/####/417a0ae9-ac84-4945-a703-22c4c6dbe9dc
  • /data/data/####/ACCS_BINDumeng;5a56c9198f4a9d0c2f0001a8.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/AKTorchDownload.db
  • /data/data/####/AKTorchDownload.db-journal
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alliance.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/JPushSA_Config.xml
  • /data/data/####/MENU_CACHE.xml
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/PendantConfig.xml
  • /data/data/####/QHA_JSON_PERSISTER_42998cf32d552343bc8e460416382dca
  • /data/data/####/QHDeviceFile
  • /data/data/####/QHDeviceID.lock
  • /data/data/####/QH_DeviceSDK.xml
  • /data/data/####/QH_SDK_M2.xml
  • /data/data/####/QH_SDK_UserData42998cf32d552343bc8e460416382dca.xml
  • /data/data/####/QH_SDK_UserData6766aa2750c19aad2fa1b32f36ed4aee.xml
  • /data/data/####/QH_SDK_sessionID42998cf32d552343bc8e460416382dca.xml
  • /data/data/####/TAB_CACHE.xml
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/Y29tLmxpZ2h0c2t5LnZpZGVv.tick.lock
  • /data/data/####/ab_test_config.xml
  • /data/data/####/abtest_base_sp_filename42998cf32d552343bc8e4604...ca.xml
  • /data/data/####/accs.db-journal
  • /data/data/####/ad_config_file.xml
  • /data/data/####/agoo.pid
  • /data/data/####/android_player_20180720_025004_000.log_0
  • /data/data/####/appPackageNames_v2
  • /data/data/####/app_globel_config_file.xml
  • /data/data/####/auth_guide_config_sdk.xml
  • /data/data/####/auth_guide_config_sdk.xml.bak
  • /data/data/####/b94a18bc-912c-45a2-ad49-b448147eda44
  • /data/data/####/banner.db-journal
  • /data/data/####/cache.ttf
  • /data/data/####/cd9a0bd0-3171-4a1c-b1bb-e75be769a049
  • /data/data/####/channel_webview.db-journal
  • /data/data/####/cloud_config_file.xml
  • /data/data/####/cloud_push_config_file.xml
  • /data/data/####/cloud_switch_cache
  • /data/data/####/cn.jpush.android.user.profile.xml
  • /data/data/####/cn.jpush.preferences.v2.rid.xml
  • /data/data/####/cn.jpush.preferences.v2.xml
  • /data/data/####/com.qihoo.livecloud.settings.GPWebrtcSettings.pref.xml
  • /data/data/####/core_update
  • /data/data/####/core_update_locker
  • /data/data/####/critical_service_config.xml
  • /data/data/####/d0efee03-e2b0-4611-ab45-41123c701fb9
  • /data/data/####/daemon_webview.db-journal
  • /data/data/####/dbfocus-journal
  • /data/data/####/device_collector
  • /data/data/####/device_collector_locker
  • /data/data/####/download-journal
  • /data/data/####/dso_deps
  • /data/data/####/dso_lock
  • /data/data/####/dso_manifest
  • /data/data/####/dso_state
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f3957002-fe29-46ce-adae-6539ceb0021a
  • /data/data/####/finalcore.jar
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/hotrizon_sharepref.xml
  • /data/data/####/httpdns_config_cache.xml
  • /data/data/####/i==1.2.0&&1.2.28_1532054967280_envelope.log
  • /data/data/####/info.xml
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/jpush_device_info.xml
  • /data/data/####/jpush_local_notification.db
  • /data/data/####/jpush_local_notification.db-journal
  • /data/data/####/jpush_local_notification.db-wal
  • /data/data/####/jpush_stat_cache.json
  • /data/data/####/jpush_stat_cache_history.json
  • /data/data/####/jpush_statistics.db
  • /data/data/####/jpush_statistics.db-journal
  • /data/data/####/jpush_statistics.db-shm (deleted)
  • /data/data/####/jpush_statistics.db-wal
  • /data/data/####/jpushservice_webview.db-journal
  • /data/data/####/libdvrender.so.tmp
  • /data/data/####/libjiagu-71411075.so
  • /data/data/####/libjplayer.so.tmp
  • /data/data/####/liblocalserver.so.tmp
  • /data/data/####/libmyssl.so.1.1.tmp
  • /data/data/####/libtranscore.so.tmp
  • /data/data/####/libviewer.so.tmp
  • /data/data/####/libyfnet_360.so.tmp
  • /data/data/####/light_sky_avast.xml
  • /data/data/####/localserver_2.0.3.18042602.zip
  • /data/data/####/locker
  • /data/data/####/log_reupload_task
  • /data/data/####/log_reupload_task_locker
  • /data/data/####/message.db-journal
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/msg_queue
  • /data/data/####/msplugin_ksp.xml
  • /data/data/####/multidex.version.xml
  • /data/data/####/p.l
  • /data/data/####/player_20180720_025004_000.log_0
  • /data/data/####/player_record_2.0.3.18051401.zip
  • /data/data/####/privacy_config_file.xml
  • /data/data/####/profile_task
  • /data/data/####/profile_task_locker
  • /data/data/####/profile_torch_platform
  • /data/data/####/push.db-journal
  • /data/data/####/push.pid
  • /data/data/####/push_share.xml
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/qhvc_plugin.xml
  • /data/data/####/qpush_msg.xml
  • /data/data/####/run.pid
  • /data/data/####/safe_user_info_file.xml
  • /data/data/####/screen_conf.xml
  • /data/data/####/session_base_sp_filename42998cf32d552343bc8e460...ca.xml
  • /data/data/####/session_base_sp_filenameandroidID.xml
  • /data/data/####/share_data.xml
  • /data/data/####/sp.livecloud.database.xml
  • /data/data/####/sp_file_recommend_upload.xml
  • /data/data/####/tab_request_name.xml
  • /data/data/####/tdata_jVg168
  • /data/data/####/tdata_jVg168.jar
  • /data/data/####/tdata_pSF696
  • /data/data/####/tdata_pSF696.jar
  • /data/data/####/tools_2.0.3.18051401.zip
  • /data/data/####/torch_sdk_config.xml
  • /data/data/####/trans_20180720_025004_000.log_0
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/umeng_message_state.xml
  • /data/data/####/uninstall_apk
  • /data/data/####/uninstall_apk_locker
  • /data/data/####/universalPopup.xml
  • /data/data/####/videolist.db-journal
  • /data/data/####/waitingDown
  • /data/data/####/waitingDown_locker
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/yf_p2p_201804191558.zip
  • /data/media/####/-4eeRi3fq3ipQP79PNV8v36hYhc.1433659402.tmp
  • /data/media/####/-Rw6fFDEyIKYXe-2Oo33wVISE7Y.-54485274.tmp
  • /data/media/####/-eCl1wWA15A9Mv0v77nJ16v98Es.316952293.tmp
  • /data/media/####/-gzYBi1zcXzEebBJ-XEV7dZVPiE.-44082293.tmp
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.deviceId
  • /data/media/####/.iddata
  • /data/media/####/.nomedia
  • /data/media/####/.push_deviceid
  • /data/media/####/.sfp
  • /data/media/####/.testf
  • /data/media/####/.umm.dat
  • /data/media/####/0WGEO_aqq5WSSRKUQbFt0x5-Y7s.-1104282257.tmp
  • /data/media/####/0pb
  • /data/media/####/0pb (deleted)
  • /data/media/####/1F4dXkxNxrF6At1UF4OrLnLOtp4.1280668579.tmp
  • /data/media/####/1N7RFm6N3roJmBPO53pBZcIbuGw.-724632565.tmp
  • /data/media/####/1v-3aKWlhvYKblSCzIvPXk87G5s.1808360351.tmp
  • /data/media/####/205d7786579d4652b07673732aa0c361
  • /data/media/####/266a80a45af34c58824c0a84de2718ab
  • /data/media/####/3AZ_Bj2WlH6-GOG73D0io7SSHcg.124605984.tmp
  • /data/media/####/3VpXjcicf2HD-4SlCIOFXoyP8KE.-116261891.tmp
  • /data/media/####/42998cf32d552343bc8e460416382dca
  • /data/media/####/4aDyu0lQFsI4825hxtkHc6v6NFU.-1928642255.tmp
  • /data/media/####/5-ec6h-Qv3i3rdt5E7om9pyTh7I.1055418881.tmp
  • /data/media/####/5IHgRMW8HRbWpc9xxCTgGN8ASGE.-984014783.tmp
  • /data/media/####/5UR91GU6P5kJZI0r34fctFGM9hw.1162759344.tmp
  • /data/media/####/610886680a5e436887bf2a6a471e4970
  • /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee
  • /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee (deleted)
  • /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee.tmp
  • /data/media/####/6VzzC07JSEQODUKPvcU_1em1xjk.-1255975870.tmp
  • /data/media/####/6yDfdU_KN76S_5oZYZL8mmQMBKI.-1309363588.tmp
  • /data/media/####/7L0SkyaGmG8W0rjZwW0sGsNL-zg.387531912.tmp
  • /data/media/####/7nCgR0I_vGm-g0qjzwWb7bpnJ8w.762740764.tmp
  • /data/media/####/7zx1HT9yTpO-Vq1DyNjA6Kpfink.-1357436772.tmp
  • /data/media/####/800c8SykBtYHpAYB8P5wK2qnofo.-1100936350.tmp
  • /data/media/####/8Pzr8GKYRxA4ERENMusX7mK0LJQ.590326411.tmp
  • /data/media/####/8RVNy-FOCmqzTnndd_0-nlDPxCg.-1541828255.tmp
  • /data/media/####/8lgK7EuChO80vxRtfeYcHDSBy50.-1944149762.tmp
  • /data/media/####/9a2aa78470cc4bfd8066366f9752ca81
  • /data/media/####/Alvin2.xml
  • /data/media/####/BAnzPAB1V9JRsKVskxSO0Ru5SeE.-533876317.tmp
  • /data/media/####/BbFznD36e6qadEEw5eSl05X4qrk.-1333595916.tmp
  • /data/media/####/BvL_ek29PU6yY-4NcVYn6aznZMA.-1097941625.tmp
  • /data/media/####/BxPgXS3P9aw96wUTPsEsJ9iDXKs.-496753613.tmp
  • /data/media/####/CK5
  • /data/media/####/CK5 (deleted)
  • /data/media/####/CSlfxg3E6JhdQwL4R0ptLtp72bw.-1564193023.tmp
  • /data/media/####/CbeuvfjnqfcrKs5uNui6ucCxP20.-956527606.tmp
  • /data/media/####/ContextData.xml
  • /data/media/####/D0v7OZdusL9bJNr0cbhSqJRylow.-207339902.tmp
  • /data/media/####/ElIa3F_OK-dPqUTQf-Vsu7s-T9g.940993240.tmp
  • /data/media/####/EptBds47taChbCANO6aUNC7jqf8.1913419734.tmp
  • /data/media/####/FRb30yjj7cULpgryXL0lUj5mJcE.-1009308275.tmp
  • /data/media/####/FZALMo0DS3NCd1Tm16zxgipTWX0.2032514985.tmp
  • /data/media/####/FbIkhKvCktM6mzPdF_aQfsI_eAA.1263475881.tmp
  • /data/media/####/Gi237f0nHbG7g4WiRB3nDuAgYcE.553901637.tmp
  • /data/media/####/HCFu4Rnsdniu4n9y0lU2juJU5Hg.-684707244.tmp
  • /data/media/####/HPQwtA_35-9J4gvsehy5Lq5kOc8.-876386716.tmp
  • /data/media/####/HjQFlyyfIp43LR6wQHnY2X3Hovs.-653846535.tmp
  • /data/media/####/IvjWPhuPiXMR2ol0Y-KBAlUkCdI.-456777081.tmp
  • /data/media/####/MdzkIMMnw-Pqb_s9BIRWUNs4v1g.-1508662487.tmp
  • /data/media/####/MiozPhSPpekqg-Fk_6w6vqQ3XJo.1540184110.tmp
  • /data/media/####/NfK-NDYFstFJPuwYWKBpSUvJAJw.-262139936.tmp
  • /data/media/####/O7POjiYSLIDQRf4hz94WDD3likk.-875871243.tmp
  • /data/media/####/OBsFdNaPqU7Efx_jWRsSbOorSBk.1139768234.tmp
  • /data/media/####/OtP4iEeO5mnnEzyb2jbBD6hhMPU.-703433569.tmp
  • /data/media/####/PEebUAx__T9QGD2hDqMRX_0thQw.1794590490.tmp
  • /data/media/####/PIdHOprcf1myCJ9HJo_j4xBIvFw.1091918978.tmp
  • /data/media/####/PqfzxfqpQXQfsIuu1G6HTRnKECA.860688047.tmp
  • /data/media/####/Qt6RAt3fQzVpYav-E6MTKs3Jwo8.1454867719.tmp
  • /data/media/####/RvRAj1JRWykxjWPDXQV-9Y-jem4.1235321283.tmp
  • /data/media/####/TAd5Ro9SFkHyZHpAydRuQ67vYOM.-17040281.tmp
  • /data/media/####/ToNUVSDQK6k3uLwk7tMobOXXtV8.-136883771.tmp
  • /data/media/####/VPK_z7EUvnYFwWT_BW_2STZqdnU.-231062763.tmp
  • /data/media/####/VVE6oN4OggNpl7Klr6BcacCg87k.336333858.tmp
  • /data/media/####/VXxtRELNAHHRtRdQmimdnYSRwrk.-1153551444.tmp
  • /data/media/####/VtwWXEKC6HuFyR9WpAAQ31ZI-ro.-1719782022.tmp
  • /data/media/####/W1s2y4DvoyLbSH5Y_ml_RWXx5Sc.-1527560171.tmp
  • /data/media/####/WYyIhksfybSdr2grMzvle2mm4Y8.701046194.tmp
  • /data/media/####/XbWxovvcL40rU4tvfunwOEE__ak.-2070790870.tmp
  • /data/media/####/XyINpNdKxAwZKPkGU5Xw82aZDxI.-469409944.tmp
  • /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv
  • /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv (deleted)
  • /data/media/####/YK6
  • /data/media/####/YK6 (deleted)
  • /data/media/####/ZrmJVAZ5awO5izFi0lGC9LA6T-o.213964349.tmp
  • /data/media/####/_J_5MNa9Kxf6c9FMEppSY1Ye2yI.-661323695.tmp
  • /data/media/####/_Z1wxYmJ2YwFa5W456VEC1G7N94.603045279.tmp
  • /data/media/####/__VERSION__
  • /data/media/####/aAOCUeU5XjCfm-Cok_c79Qc2tmg.-1302450755.tmp
  • /data/media/####/akAi0BCQ7hK4yoqHpA2kCaSJkrc.-1142675685.tmp
  • /data/media/####/akiFloRask_Z8NmSG1IzQ2SCocY.-760034571.tmp
  • /data/media/####/app.db
  • /data/media/####/avast_done
  • /data/media/####/b05ce39c1fe9e72dc1df70989e7e6d14
  • /data/media/####/bFNZEotToIU9De6jhZFhIl_UJIE.-841036521.tmp
  • /data/media/####/bQfpUoiksxXoNEnyBWxdL2iApyg.-561231514.tmp
  • /data/media/####/c4g6Ib-_BYpu8zggxqJlNQxrdz8.-440939326.tmp
  • /data/media/####/ccGUyyrw64wD2zDfAKEcnnaqeNk.1077332189.tmp
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.lightsky.video.bin
  • /data/media/####/com.lightsky.video.db
  • /data/media/####/data.lock
  • /data/media/####/deviceToken
  • /data/media/####/dsKELlPcuCoa5gehb7nNxuwDG-U.-262752979.tmp
  • /data/media/####/e-36e1VbdBhXaetJzUxOvnI9N3Q.491703254.tmp
  • /data/media/####/eFu3S_5mKZfSl4Vf-5-bVHlYXzY.-1430702535.tmp
  • /data/media/####/fA-hyLAlJwtu3P67Hp6JHA_rKAI.409644097.tmp
  • /data/media/####/fze8PCKONHmvNCVKA1UNoMuLBwM.-172280845.tmp
  • /data/media/####/gR3Yz91V09RVoxPe20H80gQQKSM.-414248138.tmp
  • /data/media/####/gk8pIXGxMrmdxAsopRZNgdigm28.-1128023216.tmp
  • /data/media/####/hW4m2sedYhmJTzY8M48ULTHxwK4.839342631.tmp
  • /data/media/####/iqRbaB-hZK4LcRlPadV6Q4x874c.1440839774.tmp
  • /data/media/####/jcSAOr9jGZwkhQZMXMgqUBAFH0c.-436016314.tmp
  • /data/media/####/kQ-VFFyvGW6NUVS3_qiL_22_mz4.767497838.tmp
  • /data/media/####/lrI57F_ujPybED25NJHerjH5Y6I.-75474476.tmp
  • /data/media/####/mteJfD9QgOaxhWvBktObVp1jHk8.288337625.tmp
  • /data/media/####/n9hGh0rBjIKZ3GB78LvZ1iAHtow.-1747552887.tmp
  • /data/media/####/nDqKUjpyDlSrZSx8uudo0a0IY1U.-1866190524.tmp
  • /data/media/####/o8Fjl6p1BXM-3pL8Gvp-x-5lHpo.-1805205102.tmp
  • /data/media/####/pIHOuRtzqAS7LxxhG4X_w-EKO1I.1883619643.tmp
  • /data/media/####/pxX_qvjYXLkfIeQI9UWS83vmSbQ.-832434769.tmp
  • /data/media/####/q9PmmVOXTEJH3tlCzCje2ZCdDGE.-763382162.tmp
  • /data/media/####/qQY
  • /data/media/####/qQY (deleted)
  • /data/media/####/rDLm_dEYNhN3wXw3mM0Piq25UVA.1265708186.tmp
  • /data/media/####/rXKgkA0pBbWmkviqgncW70etqTY.-2010286970.tmp
  • /data/media/####/report.lock
  • /data/media/####/s9EzI9OEKf2vplzSZRdr4wgGsjY.1662149151.tmp
  • /data/media/####/sMbU7Zh8eDvkoTkQqsGkzrrvPW0.508903432.tmp
  • /data/media/####/sRsgKo0i9NHJ80AIi1-xMllmVdE.-1316817315.tmp
  • /data/media/####/sdAMIADVwUKbXdCF1vMJ9wf1Q5E.1013919637.tmp
  • /data/media/####/tH5ldq2RNMeZ0BoZ4kyaqR0ex4k.-1593901582.tmp
  • /data/media/####/tdata_jVg168
  • /data/media/####/tdata_pSF696
  • /data/media/####/test.log
  • /data/media/####/uhKjdjXh8risy3SZyQYgLPu0OEE.-837984086.tmp
  • /data/media/####/uninstall_apk_list
  • /data/media/####/vUHvKwqBJ8gaaEECHQQEmYLluHo.-907701678.tmp
  • /data/media/####/w7P11-Kd-XJS7UKlzSTwGIQNCAg.2070409208.tmp
  • /data/media/####/wyXvWBOt4QFjSnptrH-qVM5q2tA.1028587601.tmp
  • /data/media/####/xUm-uHLZseen7-xzU1dB1QKFots.1501708801.tmp
  • /data/media/####/xmZkxaCvMTZOhJJc1hpt-w0274Y.1355660491.tmp
  • /data/media/####/yZq
  • /data/media/####/yZq (deleted)
  • /data/media/####/yfFMXnrqCHvSJARY905GANoH0Ag.-1378753419.tmp
  • /data/media/####/yiDEbnuRI0nmWDX1xnqwPzJ32k0.-442535053.tmp
  • /data/media/####/yiZwx2jmcHLlu_fvJRIhInQUrMc.-1301061567.tmp
Miscellaneous:
Executes next shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/xbin/which su
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:5a56c9198f4a9d0c2f0001a8","utdid":"W1FNtBBnHTsDAGdzx1H8pQes","sdkVersion":"221"} -I agoodm.m.taobao.com -O 80 -T -Z
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.qihoo.qpush.sdk.GeTuiPushService 24825 300 0
  • cat /proc/version
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 755 <Package Folder>/.jiagu/libjiagu-71411075.so
  • ls /
  • ls /sys/class/thermal
  • sh
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.qihoo.qpush.sdk.GeTuiPushService 24825 300 0
Loads the following dynamic libraries:
  • GPBreakpad
  • getuiext2
  • jcore120
  • libdvrender
  • libimagepipeline
  • libjiagu-71411075
  • libjplayer
  • liblocalserver
  • libtranscore
  • libviewer
  • libyfnet_360
  • tnet-3.1
Uses the following algorithms to encrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-NoPadding
  • DES
Uses elevated priveleges.
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Gains access to information about accounts (Google, Facebook, etc.) registered on the device.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android