マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.4546

Added to the Dr.Web virus database: 2018-11-08

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) m1.pand####.cn:80
  • TCP(TLS/1.0) m1.pand####.cn:443
  • TCP sdk.o####.t####.####.com:5224
  • TCP c####.g####.ig####.com:5226
DNS requests:
  • 7j####.c####.z0.####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • h5.pand####.cn
  • i####.pand####.cn
  • l####.tbs.qq.com
  • m1.pand####.cn
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • u.pand####.cn
HTTP GET requests:
  • m1.pand####.cn/Api/PlatProps/CheckAppVersion?AppType=####
  • m1.pand####.cn/Api/PlatProps/CheckAppVersion?isDiff=####&android=####&ap...
  • m1.pand####.cn/assets/2018/04/30/34445b91613-11097_png!100x100.png
  • m1.pand####.cn/assets/2018/04/30/344a57e3093-13357_png!100x100.png
  • m1.pand####.cn/assets/2018/04/30/344c36d5249-13357_png!100x100.png
  • m1.pand####.cn/assets/2018/04/30/344f7449582-10445_png!100x100.png
  • m1.pand####.cn/assets/2018/05/25/2b1b2c01005-333809_jpg!1500x1500.jpg
  • m1.pand####.cn/assets/2018/06/09/17785741169-207933_jpg!1181x1181.jpg
  • m1.pand####.cn/assets/2018/06/09/565c7073129-165210_jpg!1181x1181.jpg
  • m1.pand####.cn/assets/2018/06/11/3371cf62134-367579_jpg!1600x1600.jpg
  • m1.pand####.cn/assets/2018/06/13/51728ba6527-197721_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/14/1315d5c5096-215221_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/14/14e9b2c2154-142140_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/15/2818b762328-328732_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/22/262c1bd6158-146419_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/22/2aedeb87633-216248_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/28/342ea739109-182276_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/07/04/34014673366-203384_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/07/14/2a6476c6096-373514_jpg!750x750.jpg
  • m1.pand####.cn/assets/2018/07/14/347400a9206-141520_jpg!800x800.jpg
  • m1.pand####.cn/assets/2018/07/14/34ad2862347-245984_jpg!750x1177.jpg
  • m1.pand####.cn/assets/2018/08/14/5715ae04022-35587_jpg!800x800.jpg
  • m1.pand####.cn/assets/2018/08/27/57123821718-290079_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/28/628900e8944-139555_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/29/62291bf5449-109299_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/30/33e34ed4478-130518_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/01/5a5b8d01922-180883_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/03/5874de58368-117046_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/04/57ef4827425-114543_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/06/592eed18056-210562_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/18a84157246-211032_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/1d1f0538775-176727_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/1d6d10b6814-151158_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/ee16714760-146089_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/13/1e557413222-160942_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/14/4fa69649668-245612_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/137bec73744-180351_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/29051744113-140275_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/29960c89336-159524_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/501c4315248-136623_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/6191cd86355-114949_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/6278cd05919-194070_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/28/2ffb8fc7959-163274_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/28/32a88e21272-217080_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/1d610909992-132631_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/2a332f79768-255004_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/2af74082374-168568_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/325d75c5044-196936_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1df915b5994-191289_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1f33ea57956-127155_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1f928ff3061-265100_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/262602c9237-102782_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/5938bc47285-226848_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/5abfe936231-131478_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/08/20d21773581-166755_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/08/20d5b159420-156031_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/282a8622908-107628_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/288a3e06127-145888_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/288efec9379-106344_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/15f1dc36934-176141_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/174a84d9447-156758_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1e29b8e6001-283360_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1edbd794089-162030_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1fad5666541-171888_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/16/c12b3a5743-165130_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/57147283964-92240_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/57e1c3f9196-104311_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/58513237529-182692_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/58b2b119447-238972_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/592c01c5341-82139_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/59758ff7768-285152_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/5a212bc1594-118462_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/62c06e14770-168174_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/25/d2b1388362-242666_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/13a72104914-102764_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/13f81991765-157005_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/14504da7434-118339_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/620e94b3164-124487_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/1cd403b3372-8575_png!100x100.png
  • m1.pand####.cn/assets/2018/10/31/34302387639-39225_jpg!640x640.jpg
  • m1.pand####.cn/assets/2018/10/31/60b86e54371-289239_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/64592a14871-281087_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/64a40234519-289230_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/6500bd72414-272329_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/699cafe3271-266959_jpg!640x320.jpg
  • m1.pand####.cn/assets/2018/10/31/6e496546531-8575_png!100x100.png
  • m1.pand####.cn/assets/2018/11/01/5ad66b32483-322016_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5ae5dd54029-339823_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5aef7654207-97310_jpg!750x360.jpg
  • m1.pand####.cn/assets/2018/11/01/5b044962288-333528_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5b1d5f32974-96877_jpg!750x360.jpg
  • m1.pand####.cn/assets/2018/11/01/5fe4b227674-41336_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff16a05899-41464_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff3da04814-39560_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff66d33667-42265_jpg!200x200.jpg
  • m1.pand####.cn/assets/images/loading-74-74.gif
  • t####.c####.q####.####.com/config/hz-hzv3.conf
  • t####.c####.q####.####.com/tdata_YYn966
  • t####.c####.q####.####.com/tdata_eOt091
HTTP POST requests:
  • c-h####.g####.com/api.php?format=####&t=####
  • l####.tbs.qq.com/ajax?c=####&k=####
  • m1.pand####.cn/Api/Ad/IndexAd
  • m1.pand####.cn/Api/Article/HeadLine
  • m1.pand####.cn/Api/Order/LastOrderBarrage
  • m1.pand####.cn/Api/Product/Index
  • m1.pand####.cn/Api/PromotionRule/PromotionActivity
  • m1.pand####.cn/Api/ShoppingCart/ShoppingCart
  • m1.pand####.cn/Api/Slide/IndexBanner
  • m1.pand####.cn/api/PlatProps/PlatVendor
  • m1.pand####.cn/api/PlatProps/SetUserMenuStates
  • m1.pand####.cn/api/PlatProps/UserMenuStates
  • sdk.o####.p####.####.com/api.php?format=####&t=####
File system changes:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/BMWEEXOPEN_NATIVE_SP.xml
  • /data/data/####/CookiePrefsFile.xml
  • /data/data/####/MultiDex.lock
  • /data/data/####/Updater.xml
  • /data/data/####/WXStorage-journal
  • /data/data/####/core_info
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/libjiagu1390117721.so
  • /data/data/####/multidex.version.xml
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/run.pid
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/tdata_YYn966
  • /data/data/####/tdata_YYn966.jar
  • /data/data/####/tdata_eOt091
  • /data/data/####/tdata_eOt091.jar
  • /data/media/####/.nomedia
  • /data/media/####/014c133d3ebbd6e94c9b0aa58bb07488780143bb30bc92....0.tmp
  • /data/media/####/039b8d87f5cc8d88d1261e851c08d100f163d5f43f7f6f....0.tmp
  • /data/media/####/06ac7d1b62f49081c4bb6b7685466d0bd6d481094d1be3....0.tmp
  • /data/media/####/07992ed9ba244b53cdd852786b7d6d2621dfabc04cd1c4....0.tmp
  • /data/media/####/0b64ce14b17f10e210b31193214fde1f1845e616660ac5....0.tmp
  • /data/media/####/0ceff1c986f9a91d45820132d3e582de8b95dd48759c96....0.tmp
  • /data/media/####/0e71219f59472eb1ad673d7e52014a3ba666da1909a0b8....0.tmp
  • /data/media/####/1241399989b91df928b20f29ebad29bf2da7f153c32d5f....0.tmp
  • /data/media/####/13c8b657e7f56640086bc69632bdcf846ad261c1a153b0....0.tmp
  • /data/media/####/17bafc8588015ba4f030fa94fc4d31b8524683e3f9b128....0.tmp
  • /data/media/####/1f8086999562fb1ea8846057e8f754bdf4efabeb81a846....0.tmp
  • /data/media/####/2017185346998a4cad420267a00abbf8261a2f957a49ae....0.tmp
  • /data/media/####/263873980fa88e829c6db97b9a8b3c0d379f4e086f57ae....0.tmp
  • /data/media/####/29a397d8bee17938933261a49102c384452f40957d1d32....0.tmp
  • /data/media/####/2bc84f344867893e142c0fd7bf4bcb3a261feff0012860....0.tmp
  • /data/media/####/340bf0b1faaa6a08e53a92580eeef7c02016b2fe279019....0.tmp
  • /data/media/####/34f5911b648464c13559a37e4a59ae67b2a66696169420....0.tmp
  • /data/media/####/3759f66d0fcdda9292ad54f0efd9bec05cb8928391c9a2....0.tmp
  • /data/media/####/38621109dc8351a50e47128b3aff90616525e5f17dca34....0.tmp
  • /data/media/####/3b9f687f434782e56fa6a8cb80020cbde7bfe21ef288d2....0.tmp
  • /data/media/####/3cf953c05328e44677b5117e4d5a7aab93e6b7e0b7fdb7....0.tmp
  • /data/media/####/4145d620b3f9e47758e90e4fbf89c16845a7f499935d92....0.tmp
  • /data/media/####/438f41d196916d351ecbead185ec49b70b9475af21062d...4371.0
  • /data/media/####/4423c6f185a0ece56868205f6f239c282431643bacf590....0.tmp
  • /data/media/####/44b3da73a463cf596d9e64c2b791f03c3ea8a64d3c3ba2....0.tmp
  • /data/media/####/48b3a3b709395d82d043ff5a9a0be22ce47bb8db6b3024....0.tmp
  • /data/media/####/504a4d96a94b0292e359b640e8eb446a19c52223f6a53e....0.tmp
  • /data/media/####/534bc5ccee51db33c809c83b75c5113f4edebe721ed7c0....0.tmp
  • /data/media/####/54b6aee401fdd4dcb368fed9c31c4d49a2705b62610ce6....0.tmp
  • /data/media/####/551766938674fcc51eaaa4791d35c6d17a2b37e756bb3d....0.tmp
  • /data/media/####/557a2b062c18624720fdd01501da04750695a6342b2bb1....0.tmp
  • /data/media/####/55e11d94f2b2395f1afb5884e67beb5fbf083fda7c7fa8....0.tmp
  • /data/media/####/57e2053e88bee38685928d0fa6d5afd0750015e35be7aa....0.tmp
  • /data/media/####/581a29acbe503fb534261f2cc12135812ac5bf1c3f85af....0.tmp
  • /data/media/####/5833415c715dbe1991231032311cdfb3895cfcca7adf89...e1e3.0
  • /data/media/####/583afdf63fdb8831bd9a7fcf831052574c7dc9d819d91a....0.tmp
  • /data/media/####/59c49f33c286e7d47e73daefc0fde586a9272e0d830258....0.tmp
  • /data/media/####/5b085a69866f9a41d267d87e3ada3b1c1906ff747cf839....0.tmp
  • /data/media/####/5b1993cadfaf07a9d709a685288c87e80a15f322525372....0.tmp
  • /data/media/####/61de52b9fb054fe6018c932b8969736592b7cd96feb225....0.tmp
  • /data/media/####/66e6b0086ec394a3b8acdafec981c71ed314911dcb0618....0.tmp
  • /data/media/####/68a63322e3d1c47c88f1867b0371a8c0ed019f2c6d7070....0.tmp
  • /data/media/####/68d228e02ced2250d08a196aa71bb5f3af76db36883ec0....0.tmp
  • /data/media/####/693bf7f99963dc322ad67f429fc0cf5802ddd0207d645f....0.tmp
  • /data/media/####/6ae5e836a902b6cba1a0bb0191506ae182442aa7a3748a....0.tmp
  • /data/media/####/6ef632cef4d7739904089449c0bbae8b4a0e4ef417f012....0.tmp
  • /data/media/####/6fa95f15c9ca91762e168d69d19e764eb65e634abd4c48....0.tmp
  • /data/media/####/7325e18de1ca702429f502e6d08079fb452445372deb00....0.tmp
  • /data/media/####/745af2f0d5f6f3976aaf3f1f182f047cdf067ea557d8be....0.tmp
  • /data/media/####/74dfb4d4f708f7e22e7415401dce606e3a6557e33ffed0....0.tmp
  • /data/media/####/753227d6c4573805ac740d20c23899d5e58eb9ddf01d68....0.tmp
  • /data/media/####/759f45d1a215c55a3b715085b6e4342d02be4410f3f2e1....0.tmp
  • /data/media/####/7a067f9805f3b564d6c680badf15f7e53fcd5b0698a771....0.tmp
  • /data/media/####/7c1c6ed32ca2219e01eba4c868d1c9aa23d623ff275d2c....0.tmp
  • /data/media/####/7c42a80ae32b8bdf0edc0a05fe9fd59263b92c2f7b3890....0.tmp
  • /data/media/####/7d41bc32d25be31ca534e5cee87ac2d1c875948ca870e9....0.tmp
  • /data/media/####/8118819997bb20507a1f5e07c14d9e88b3dcab548d0df3....0.tmp
  • /data/media/####/865af199e9265b4919b4acd75b7a0f3395b2d1b1428057....0.tmp
  • /data/media/####/867d3b6a60022bd2edbefaac0d8b4d78ba8f760ab8c177....0.tmp
  • /data/media/####/87550ebbcaeef5261e60f1b5957f8c901d9f4eb458bc57....0.tmp
  • /data/media/####/8d1b2616e42504db0025904301aecf4a4300f2b7ef9a51...ca1f.0
  • /data/media/####/8dec42eb9afb6c0a531b84e89f411aca6760c2cac9e94c....0.tmp
  • /data/media/####/8e9e228df065dcd09adcde3b5d71bd97bc390a18e252ba....0.tmp
  • /data/media/####/9337cb9cf24d5d15ea637bd8711a4035c1e08baee39ede....0.tmp
  • /data/media/####/967bf131ec91ad5e5abd61fc907e7920848152b32bc4e6....0.tmp
  • /data/media/####/96e1bab7c725f185f45e2ef3606b21b2934a7802485d11....0.tmp
  • /data/media/####/9a6275330ab5356f77b0674181fa7c476a7812748907af....0.tmp
  • /data/media/####/9b8f9a71c90087bfdf8b5d7d9d6c560069764d233cd857....0.tmp
  • /data/media/####/9bda328134df5e49dba2449842d00c37bf0db06c236858....0.tmp
  • /data/media/####/9bfc5e3229284e83edbeb01491dc59b5a63326943f3ebf....0.tmp
  • /data/media/####/9fd484f3d9410417a41ee982599e117be0ee79e00b9437....0.tmp
  • /data/media/####/Share.png
  • /data/media/####/a1110162fed518ba4b7c4fc18937703acc0f10ee6dab75....0.tmp
  • /data/media/####/a2b393dd933830a32fa3f576865848cd1396a289ce2193....0.tmp
  • /data/media/####/a5c17f4c1fdf053f84cef5b5779be8bd2725cec3e48897....0.tmp
  • /data/media/####/a5d9282efd831f5ca39c3ca3ac60b5d8c220c5e62f7494....0.tmp
  • /data/media/####/a714f4fd48b24849701579c089a6a0763598ede10f4557....0.tmp
  • /data/media/####/a7bff7a9e91f2d164e91b5c479e9536750a20b19a6b03c....0.tmp
  • /data/media/####/a93705e2fa6a96f2d64abf29f41be65909d2bb7f0a64ca....0.tmp
  • /data/media/####/abb50b5f4e7b8310e0f6a655c50f693276d3ad62c5acb3....0.tmp
  • /data/media/####/ad1f142ed52b972a5e2d9fde5727e6e4b84f3b36589302....0.tmp
  • /data/media/####/ad_sel.png
  • /data/media/####/add.png
  • /data/media/####/addAddress.js
  • /data/media/####/addressEdit.js
  • /data/media/####/agencyArea.js
  • /data/media/####/agencyAreaStat.js
  • /data/media/####/agentDistribution.js
  • /data/media/####/app.db
  • /data/media/####/appSaveImageSlider.js
  • /data/media/####/applyAgent.js
  • /data/media/####/applyUpgrade.js
  • /data/media/####/arror.png
  • /data/media/####/award.js
  • /data/media/####/b1.png
  • /data/media/####/b10.png
  • /data/media/####/b11.png
  • /data/media/####/b12.png
  • /data/media/####/b2.png
  • /data/media/####/b3.png
  • /data/media/####/b38a1ce4ffe4062e31afc68298ecfefb982455f4b9dc59....0.tmp
  • /data/media/####/b4.png
  • /data/media/####/b5.png
  • /data/media/####/b6.png
  • /data/media/####/b7.png
  • /data/media/####/b8.png
  • /data/media/####/b9.png
  • /data/media/####/bankEdit.js
  • /data/media/####/bbb2fc5aa772ae3629ff457e8340fb817149194f275685....0.tmp
  • /data/media/####/bc57703ae9f69e5af63f5b2bb599f89c09a4b453ebbab7....0.tmp
  • /data/media/####/bcf3727edfde36824316539d82ff430340fa25d4f4dc54....0.tmp
  • /data/media/####/bdbe67324a323515003d24e5631008db279d5b05863a44...0d47.0
  • /data/media/####/bf75bfded0d4991c17acda41afc274babf38c1ffd9533a...4db6.0
  • /data/media/####/bfc49c207723b15a435acdc04d50a4e78a63c429a9bc5c....0.tmp
  • /data/media/####/blank.html
  • /data/media/####/blank.png
  • /data/media/####/bot_arrow_1.png
  • /data/media/####/bot_arrow_2.png
  • /data/media/####/bundle.zip
  • /data/media/####/buy.png
  • /data/media/####/c10_ico.png
  • /data/media/####/c11_ico.png
  • /data/media/####/c12_ico.png
  • /data/media/####/c139f1bf2a7c616753e608043f383a194f5b67148fefe9....0.tmp
  • /data/media/####/c13_ico.png
  • /data/media/####/c14_ico.png
  • /data/media/####/c14a9d7ee6dc6a8bd2d280ff81b0dc3bc4acdfdae80e3e....0.tmp
  • /data/media/####/c15_ico.png
  • /data/media/####/c16_ico.png
  • /data/media/####/c17_ico.png
  • /data/media/####/c18_ico.png
  • /data/media/####/c19_ico.png
  • /data/media/####/c1_ico.png
  • /data/media/####/c1d4ee002ddda519818d0cd19e56f9b9e3f76f892c93a8....0.tmp
  • /data/media/####/c20_ico.png
  • /data/media/####/c21_ico.png
  • /data/media/####/c21bdee9362252858c2b06a360369aeaeffef299d59b83....0.tmp
  • /data/media/####/c22_ico.png
  • /data/media/####/c23_ico.png
  • /data/media/####/c24_ico.png
  • /data/media/####/c25_ico.png
  • /data/media/####/c26_ico.png
  • /data/media/####/c27_ico.png
  • /data/media/####/c2_ico.png
  • /data/media/####/c2ec2f21fc740424a555d29855bc0251474e1ff5cb7c9c....0.tmp
  • /data/media/####/c31_ico.png
  • /data/media/####/c32_ico.png
  • /data/media/####/c33_ico.png
  • /data/media/####/c3_ico.png
  • /data/media/####/c4_ico.png
  • /data/media/####/c5_ico.png
  • /data/media/####/c62237e570b949fbed6946d588d0c039012e95a6ac2984....0.tmp
  • /data/media/####/c6_ico.png
  • /data/media/####/c7_ico.png
  • /data/media/####/c898873fc057a3d58c1808c147457a182303e1fd4de380....0.tmp
  • /data/media/####/c8_ico.png
  • /data/media/####/c9686f18ffd5e82d1a4aa30bfc40817a16493410eea230....0.tmp
  • /data/media/####/c9_ico.png
  • /data/media/####/ca68c95a9e7f33704d52bc8fd14a39f241ec023651fa2a....0.tmp
  • /data/media/####/card.png
  • /data/media/####/card_pic.png
  • /data/media/####/cb308fb45c0f5ce79605fdc15cc7006ed850a40902a809....0.tmp
  • /data/media/####/center_bg.png
  • /data/media/####/close.png
  • /data/media/####/close2.png
  • /data/media/####/code.png
  • /data/media/####/code_ico.png
  • /data/media/####/collect_off.png
  • /data/media/####/collect_on.png
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.huixhui.xzplats.bin
  • /data/media/####/com.huixhui.xzplats.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/commission.js
  • /data/media/####/cumulativeInventory.js
  • /data/media/####/d1050b248d59ef8bf43aec7d5af1f308f234237f999d47....0.tmp
  • /data/media/####/d29134e497aa3cdcc5a5cb3c50cbb2185808858308d344....0.tmp
  • /data/media/####/d3fb35063e13c0b0ba813973d8dd8fde4ed34188bbbff4....0.tmp
  • /data/media/####/d69737d2719a911f70963ab0b3cb67bc26aa199b8b3be6....0.tmp
  • /data/media/####/dbca87c42f8fbdfb9c08db9dd1e9f703f5139307ed108a....0.tmp
  • /data/media/####/de5eed8ca38dcf07d88c4dbfd3a2818e952f5f35e6aedf....0.tmp
  • /data/media/####/df36c67faa7cb6a05c3616e4ba73c4c6f44e3de7db4c77....0.tmp
  • /data/media/####/e54a14ace895cb3a5b33855fed84338f955ccc8a99cf2d....0.tmp
  • /data/media/####/eb9b5bdfea0bd9a1398efefa3b51861f7139d1a13afac9....0.tmp
  • /data/media/####/ed1db85e2d493e9cdf84e27ccde7a9cd3401c9b2ce60d4....0.tmp
  • /data/media/####/ed8fed4a8d0751f1c48f5904bccf46b7028e1b15d34a9a...367c.0
  • /data/media/####/evaluationList.js
  • /data/media/####/evaluationSubmission.js
  • /data/media/####/exchange.js
  • /data/media/####/f56cf0e7b669de6d8dce928907f1c9d6c53fbf6f8a74c5....0.tmp
  • /data/media/####/f7ca666fa18b24dd55346ad8580e7d4a5ed29dd72ce555....0.tmp
  • /data/media/####/face.jpg
  • /data/media/####/face.png
  • /data/media/####/face1.jpg
  • /data/media/####/face1.png
  • /data/media/####/face2.png
  • /data/media/####/fb3c1df5754717ad5060ab4152e41023953d096670553a....0.tmp
  • /data/media/####/fhadd.png
  • /data/media/####/font_1469606063_76593.ttf
  • /data/media/####/font_1469606522_9417143.woff
  • /data/media/####/font_zn5b3jswpofuhaor.ttf
  • /data/media/####/forget.js
  • /data/media/####/fx_ico1.png
  • /data/media/####/fx_ico2.png
  • /data/media/####/fx_ico3.png
  • /data/media/####/gamesList.js
  • /data/media/####/home_ico.png
  • /data/media/####/icon_close.png
  • /data/media/####/iconfont-eros.ttf
  • /data/media/####/iconfont.ttf
  • /data/media/####/index.js
  • /data/media/####/index_banner_bg.png
  • /data/media/####/integral.js
  • /data/media/####/join.js
  • /data/media/####/joininfo.js
  • /data/media/####/journal.tmp
  • /data/media/####/kefu.js
  • /data/media/####/kefu.png
  • /data/media/####/kejian.png
  • /data/media/####/libweexjsb.so
  • /data/media/####/list-card.png
  • /data/media/####/lmtt_ico.png
  • /data/media/####/loading-50-50.gif
  • /data/media/####/loading-74-74.gif
  • /data/media/####/login.js
  • /data/media/####/logo.png
  • /data/media/####/md5.json
  • /data/media/####/messageDetail.js
  • /data/media/####/messages.js
  • /data/media/####/modifyPwd.js
  • /data/media/####/msg_agent.png
  • /data/media/####/msg_distribution.png
  • /data/media/####/msg_finance.png
  • /data/media/####/msg_ico.png
  • /data/media/####/msg_order.png
  • /data/media/####/msg_other.png
  • /data/media/####/msg_system.png
  • /data/media/####/myCollect.js
  • /data/media/####/myFans.js
  • /data/media/####/myTeam.js
  • /data/media/####/n1_ico.png
  • /data/media/####/n2_ico.png
  • /data/media/####/n3_ico.png
  • /data/media/####/n4_ico.png
  • /data/media/####/n5_ico.png
  • /data/media/####/nav1.png
  • /data/media/####/nav2.png
  • /data/media/####/nav3.png
  • /data/media/####/nav4.png
  • /data/media/####/nav5.png
  • /data/media/####/nearbyStores.js
  • /data/media/####/none_ico.png
  • /data/media/####/off_check.png
  • /data/media/####/off_radio.png
  • /data/media/####/onlinekefu.png
  • /data/media/####/orderDetail.js
  • /data/media/####/orderList.js
  • /data/media/####/orderLogistics.js
  • /data/media/####/orderPay.js
  • /data/media/####/orderPut.js
  • /data/media/####/parentchildComment.js
  • /data/media/####/parentchildLive.js
  • /data/media/####/parentchildTV.js
  • /data/media/####/parentchildTVList.js
  • /data/media/####/paySuccess.js
  • /data/media/####/pcode_ico.png
  • /data/media/####/photo_ico.png
  • /data/media/####/pl_ico.png
  • /data/media/####/pl_ico1.png
  • /data/media/####/post_ico.png
  • /data/media/####/post_icoy.png
  • /data/media/####/price.png
  • /data/media/####/pro.png
  • /data/media/####/pro1.png
  • /data/media/####/pro2.png
  • /data/media/####/proDetail.js
  • /data/media/####/proList.js
  • /data/media/####/pro_1.png
  • /data/media/####/pro_2.png
  • /data/media/####/product1.png
  • /data/media/####/psd.png
  • /data/media/####/purchase.js
  • /data/media/####/purchaseApplications.js
  • /data/media/####/purchaseMoney.js
  • /data/media/####/q1.png
  • /data/media/####/q2.png
  • /data/media/####/q3.png
  • /data/media/####/q4.png
  • /data/media/####/qou.png
  • /data/media/####/qq_ico.png
  • /data/media/####/quan.png
  • /data/media/####/rebate.js
  • /data/media/####/rebatePerformance.js
  • /data/media/####/rebateStat.js
  • /data/media/####/rebateTable.js
  • /data/media/####/recharge.js
  • /data/media/####/recommendFriends.js
  • /data/media/####/register.js
  • /data/media/####/remittanceCertificate.js
  • /data/media/####/resetpwd.js
  • /data/media/####/saixuan.png
  • /data/media/####/salesSend.js
  • /data/media/####/saveImageSlider.js
  • /data/media/####/search.png
  • /data/media/####/search_ico.png
  • /data/media/####/sel_check.png
  • /data/media/####/sel_radio.png
  • /data/media/####/sendBackProduct.js
  • /data/media/####/sendGoods.js
  • /data/media/####/set_face.png
  • /data/media/####/setting.js
  • /data/media/####/sfz1.png
  • /data/media/####/sfz2.png
  • /data/media/####/share.js
  • /data/media/####/share_wx_circle.png
  • /data/media/####/share_wx_friend.png
  • /data/media/####/ship1.js
  • /data/media/####/ship2.js
  • /data/media/####/ship3.js
  • /data/media/####/shipOrder.js
  • /data/media/####/shipmentMoney.js
  • /data/media/####/shop.png
  • /data/media/####/shop_ico.png
  • /data/media/####/signIn.js
  • /data/media/####/star-off.png
  • /data/media/####/star-on.png
  • /data/media/####/star.png
  • /data/media/####/statistics.js
  • /data/media/####/stock.js
  • /data/media/####/stockRecord.js
  • /data/media/####/storeDetail.js
  • /data/media/####/storeManage.js
  • /data/media/####/subordinate.js
  • /data/media/####/suc_pic.png
  • /data/media/####/t_bg.png
  • /data/media/####/tabPage.js
  • /data/media/####/tdata_YYn966
  • /data/media/####/tdata_eOt091
  • /data/media/####/teamOrder.js
  • /data/media/####/tel.png
  • /data/media/####/test.log
  • /data/media/####/tj_banner.png
  • /data/media/####/top_arrow_1.png
  • /data/media/####/top_arrow_2.png
  • /data/media/####/tvDetail.js
  • /data/media/####/tv_ico.png
  • /data/media/####/tz1.png
  • /data/media/####/tz2.png
  • /data/media/####/up.jpg
  • /data/media/####/upgrade.js
  • /data/media/####/userBill.js
  • /data/media/####/userinfo.js
  • /data/media/####/vip_ico.png
  • /data/media/####/warehouseStock.js
  • /data/media/####/webView.js
  • /data/media/####/weix_ico.png
  • /data/media/####/withdraw.js
  • /data/media/####/withdrawList.js
  • /data/media/####/wx_ico.png
  • /data/media/####/xz_ico.png
  • /data/media/####/xzlogo.png
  • /data/media/####/yuer_ico.png
  • /data/media/####/zan.png
  • /data/media/####/zan1.png
  • /data/media/####/zt_ico1.png
  • /data/media/####/zt_ico2.png
  • /data/media/####/zy_img.png
Miscellaneous:
Executes the following shell scripts:
  • /data/app-lib/<Package>-1/libweexjsb.so 51 0
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.benmu.erosplugingt.GetuiPushService 24973 300 0
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • getprop ro.product.cpu.abi
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.benmu.erosplugingt.GetuiPushService 24973 300 0
Loads the following dynamic libraries:
  • Patcher
  • getuiext2
  • libjiagu1390117721
  • weexjsc
Uses the following algorithms to encrypt data:
  • RSA-ECB-NoPadding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android