マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.4780

Added to the Dr.Web virus database: 2018-11-12

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) pub-####.qin####.com:80
  • TCP(HTTP/1.1) pv####.baom####.com:80
  • TCP(HTTP/1.1) inter####.v####.baom####.com:80
  • TCP(HTTP/1.1) ub####.baidust####.com:80
  • TCP(HTTP/1.1) pi####.qq.com:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) i####.v####.baom####.####.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) v.g####.qq.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) mo####.b####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) wn.pos.b####.com:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(HTTP/1.1) app.inter####.baom####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) p####.baom####.com:80
  • TCP(HTTP/1.1) cfg.i####.qq.com:80
  • TCP(HTTP/1.1) cgi.con####.qq.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) mobads-####.b####.com:443
  • TCP(TLS/1.0) c####.baidust####.com:443
  • TCP(TLS/1.0) s####.e.qq.com:443
  • TCP(TLS/1.0) inter####.v####.baom####.com:443
  • TCP(TLS/1.0) h####.b####.com:443
  • TCP sdk.o####.t####.####.com:5224
  • TCP c####.g####.ig####.com:5226
DNS requests:
  • 7j####.c####.z0.####.com
  • a####.u####.com
  • and####.b####.qq.com
  • app.inter####.baom####.com
  • c####.baidust####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cfg.i####.qq.com
  • cgi.con####.qq.com
  • h####.b####.com
  • i####.v####.baom####.com
  • i####.v####.baom####.com
  • i####.v####.baom####.com
  • i####.v####.baom####.com
  • imgc####.qq.com
  • inter####.v####.baom####.com
  • l####.tbs.qq.com
  • log.u####.com
  • mi.g####.qq.com
  • mo####.b####.com
  • mobads-####.b####.com
  • p####.baom####.com
  • p####.baom####.com
  • p####.ugd####.com
  • pi####.qq.com
  • pub-####.qin####.com
  • pv####.baom####.com
  • qzones####.g####.cn
  • s####.e.qq.com
  • s####.u####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • ub####.baidust####.com
  • v####.inter####.baom####.com
  • v.g####.qq.com
  • wn.pos.b####.com
HTTP GET requests:
  • app.inter####.baom####.com/xiuquapp.ashx?dataType=####
  • app.inter####.baom####.com/xiuquapp.ashx?imeiCode=####&videoId=####&data...
  • cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?sdkv=####&appid=###...
  • i####.v####.baom####.####.com/230_130/10416447.jpg
  • i####.v####.baom####.####.com/230_130/12854805.jpg
  • i####.v####.baom####.####.com/230_130/13547377.jpg
  • i####.v####.baom####.####.com/230_130/14533066.jpg
  • i####.v####.baom####.####.com/230_130/15738846.jpg
  • i####.v####.baom####.####.com/230_130/15763600.jpg
  • i####.v####.baom####.####.com/230_130/15991038.jpg
  • i####.v####.baom####.####.com/230_130/15999898.jpg
  • i####.v####.baom####.####.com/230_130/16004658.jpg
  • i####.v####.baom####.####.com/230_130/16035280.jpg
  • i####.v####.baom####.####.com/230_130/16052215.jpg
  • i####.v####.baom####.####.com/230_130/16272639.jpg
  • i####.v####.baom####.####.com/230_130/16297512.jpg
  • i####.v####.baom####.####.com/230_130/16305781.jpg
  • i####.v####.baom####.####.com/230_130/16306398.jpg
  • i####.v####.baom####.####.com/230_130/16306420.jpg
  • i####.v####.baom####.####.com/230_130/16330326.jpg
  • i####.v####.baom####.####.com/230_130/1641495.jpg
  • i####.v####.baom####.####.com/230_130/16543947.jpg
  • i####.v####.baom####.####.com/230_130/16729851.jpg
  • i####.v####.baom####.####.com/230_130/17945500.jpg
  • i####.v####.baom####.####.com/230_130/18095829.jpg
  • i####.v####.baom####.####.com/230_130/18827832.jpg
  • i####.v####.baom####.####.com/230_130/20121331.jpg
  • i####.v####.baom####.####.com/230_130/20389861.jpg
  • i####.v####.baom####.####.com/230_130/20754316.jpg
  • i####.v####.baom####.####.com/230_130/20839126.jpg
  • i####.v####.baom####.####.com/230_130/2190706.jpg
  • i####.v####.baom####.####.com/230_130/35761224.jpg
  • i####.v####.baom####.####.com/230_130/36989254.jpg
  • i####.v####.baom####.####.com/230_130/37191799.jpg
  • i####.v####.baom####.####.com/230_130/6106258.jpg
  • inter####.v####.baom####.com/230_130/37298704.jpg
  • inter####.v####.baom####.com/230_130/37359706.jpg
  • inter####.v####.baom####.com/230_130/37370479.jpg
  • inter####.v####.baom####.com/230_130/37440946.jpg
  • inter####.v####.baom####.com/230_130/37449948.jpg
  • inter####.v####.baom####.com/230_130/37481773.jpg
  • inter####.v####.baom####.com/230_130/37688663.jpg
  • inter####.v####.baom####.com/230_130/37703739.jpg
  • inter####.v####.baom####.com/230_130/37975707.jpg
  • inter####.v####.baom####.com/230_130/38055551.jpg
  • inter####.v####.baom####.com/230_130/38113726.jpg
  • inter####.v####.baom####.com/230_130/38397940.jpg
  • inter####.v####.baom####.com/230_130/38506394.jpg
  • inter####.v####.baom####.com/230_130/38610009.jpg
  • inter####.v####.baom####.com/230_130/38693739.jpg
  • inter####.v####.baom####.com/640_360/38675919.jpg
  • inter####.v####.baom####.com/640_360/38679563.jpg
  • inter####.v####.baom####.com/640_360/38679608.jpg
  • inter####.v####.baom####.com/640_360/38679657.jpg
  • inter####.v####.baom####.com/640_360/38687073.jpg
  • inter####.v####.baom####.com/640_360/38691387.jpg
  • inter####.v####.baom####.com/640_360/38691391.jpg
  • inter####.v####.baom####.com/640_360/38691394.jpg
  • mi.g####.qq.com/gdt_mview.fcg?actual_width=####&count=####&r=####&templa...
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
  • mo####.b####.com/ads/pa/8/__pasys_remote_banner.php?bdr=####&os=####&v=#...
  • mo####.b####.com/ads/pa/8/__xadsdk__remote__8.8008.jar
  • mo####.b####.com/ads/preload.php
  • mo####.b####.com/ads/sec.php
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1541994849082=####
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1541994855381=####
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1541994856688=####
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1541994866123=####
  • mo####.b####.com/cpro/ui/mads.php?code2=####&b1541994875886=####
  • p####.baom####.com/230_130/13411341.jpg
  • p####.baom####.com/230_130/14500421.jpg
  • p####.baom####.com/230_130/15564119.jpg
  • p####.baom####.com/230_130/18858179.jpg
  • p####.baom####.com/230_130/19432835.jpg
  • p####.baom####.com/230_130/19721772.jpg
  • p####.baom####.com/230_130/19900886.jpg
  • p####.baom####.com/230_130/19977890.jpg
  • p####.baom####.com/230_130/20456297.jpg
  • p####.baom####.com/230_130/30118613.jpg
  • p####.baom####.com/230_130/31407735.jpg
  • p####.baom####.com/230_130/37115532.jpg
  • p####.baom####.com/230_130/37197791.jpg
  • p####.baom####.com/230_130/37221767.jpg
  • p####.baom####.com/230_130/37253535.jpg
  • p####.baom####.com/230_130/8169887.jpg
  • p####.baom####.com/25f9eecc-61ae-4b4c-9b6f-df4ab8eb3079_7102.jpg
  • p####.baom####.com/eaf00297-9b6f-4020-8af9-2754ad5e0718_7102.jpg
  • p####.baom####.com/getvideourl.aspx?flvid=####&devicetype=####
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android03/js-release/1.1.0/nati...
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • pub-####.qin####.com/tdata_EDT356
  • pv####.baom####.com/datagather.aspx?ext=####&bcode=####&siteid=####&refu...
  • pv####.baom####.com/videogather.aspx?siteid=####&playerid=####&type=####...
  • s####.tc.qq.com/gdt/0/DAAVW-pAUAALQABOBbWtVhCDS8uUfF.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAZFV7AUAALQABWBbH20LA0ILHl7j.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAbSKOAUAALQABhBb3sDbBorVSL01.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAcm9SAUAALQABiBbBNb6Bto2v0ne.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAf_cCAUAALQABiBb4o4IBw0SZ7Za.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAfs1OAKAAPAABRBb1rdRBrJx9-c2.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAgPB_AUAALQABZBb2Cf3A96k0kfK.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAgPB_AUAALQABbBbmLNYC-PcUJ1z.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAgR4oAUAALQABOBb2osOA6l7JoLo.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAiUSfAUAALQABNBb6CTgC_27WCmF.jpg/0?ck=####
  • t####.c####.q####.####.com/config/hz-hzv3.conf
  • t####.c####.q####.####.com/tdata_Soq141
  • t####.c####.q####.####.com/tdata_vxj811
  • ub####.baidust####.com/media/v1/0f0000RikY7HaDHZAebS-s.jpg
  • v.g####.qq.com/gdt_stats.fcg?viewid=####&i=####&os=####&xp=####&gap=####
  • wn.pos.b####.com/adx.php?c=####&ext=####
HTTP POST requests:
  • a####.u####.com/app_logs
  • and####.b####.qq.com/rqd/async
  • app.inter####.baom####.com/ChannelInfo.asmx/GetPgcInfo
  • app.inter####.baom####.com/dataGrand.asmx/ReportData
  • app.inter####.baom####.com/getlist.asmx/GetCommentList
  • app.inter####.baom####.com/getlist.asmx/GetRecommendMhh
  • app.inter####.baom####.com/getlist.asmx/GetVersionChannelInfo
  • c-h####.g####.com/api.php?format=####&t=####
  • cfg.i####.qq.com/tbs?v=####&mk=####
  • l####.tbs.qq.com/ajax?c=####&v=####&k=####
  • pi####.qq.com/mstat/report
  • s####.e.qq.com/activate
  • s####.e.qq.com/msg
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • v.g####.qq.com/gdt_stats.fcg
File system changes:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/00ab327abbb9a4546c50c18049bf437af33528f0eae739a....0.tmp
  • /data/data/####/01ca8ed1d0de3a6fb5604c8205029c6d2e362f17932aa1a....0.tmp
  • /data/data/####/02e72b6ecdde4a6bdb29c5d11ae58a20039061e39e1a98c....0.tmp
  • /data/data/####/03dd30d10552
  • /data/data/####/067838d6a4fe8dc0cf3abf0d3f506fc9c467b1d50ccc82a....0.tmp
  • /data/data/####/06bd795dbfb90f58ea938df86f81b89ca398d5f47ef8353....0.tmp
  • /data/data/####/07a559269e019daa63b5d54639f051622dd2ba4b1096549....0.tmp
  • /data/data/####/08eef414e56d4bd012b8e6468b5965a7026e54d3ebd2786....0.tmp
  • /data/data/####/0a00402b4d7464969446307c827121a70fc006eb4fb33d1....0.tmp
  • /data/data/####/0c64a6d739ca6ff995d1011ed1cc731378a092957324343....0.tmp
  • /data/data/####/0cbee501a8919b41558eb9509c0c00bb010000119d5fb68....0.tmp
  • /data/data/####/0d872e0b9e505188922b40b4b468d3ff6f8c729bdfd05a6....0.tmp
  • /data/data/####/125194271de670043caac6b9845f2ea4be69382f0b9cf1d....0.tmp
  • /data/data/####/1358836d0245cadda89ac42dca839e5fcef0fee1858c426....0.tmp
  • /data/data/####/13815523cca3fa712d2e0f9f759931f304a3d9107033ee6....0.tmp
  • /data/data/####/142577f63fe280a30787153e1147210af23a7eff6d86c9e....0.tmp
  • /data/data/####/15059564a3df45491457511edf0fd19fc4c87fc8c79544b....0.tmp
  • /data/data/####/1541994828846.log
  • /data/data/####/15a88b599973b40ffdb3f1ca28645676787cccbbea00cc6....0.tmp
  • /data/data/####/1896572a000100dfb83c8074c1fff2020d8a788e1d7c259....0.tmp
  • /data/data/####/19a0c08404e506e96f1b2166e64240e85b0799849873096....0.tmp
  • /data/data/####/19f11dc1126ac3064a2f46be17982a5b8b60a2179c9cf9b....0.tmp
  • /data/data/####/1a3a94a9d6f44c19fb9a76a30cc3450b59573103253fe56....0.tmp
  • /data/data/####/1ad6945c92e0b1494b043b0589403e455d93a1b3d019bbe....0.tmp
  • /data/data/####/1dd8a77f82dd6911298ed3cf92f8def4ab9fd4f75bfd14c....0.tmp
  • /data/data/####/2120bfef3803b302d818976d89757cfa671bcbde4be2d39....0.tmp
  • /data/data/####/223c40ebb448aa33d8a6abf459ceddcd845e1e45ebf85e9....0.tmp
  • /data/data/####/2276.yaqcookie
  • /data/data/####/25ece50ded92ee59f5bbbcc01799e15081217b38485e106....0.tmp
  • /data/data/####/2785440901854ee2717882ebc4792a076deec03bb1a6d7f....0.tmp
  • /data/data/####/290136372f540023a3429942b44d9ba32dbb083f698442a....0.tmp
  • /data/data/####/2a9ff15ae9111de858f37af53451a221e78b33a67db2934....0.tmp
  • /data/data/####/2c04fd42d8194390e37442d65a3fd288f0cc48dc5188203....0.tmp
  • /data/data/####/2cf84381751def9f292e416591fff319a11360423296751....0.tmp
  • /data/data/####/2ed0a72544bfe725fea924e0542d8838769d755c78f09bc....0.tmp
  • /data/data/####/2ee52fab44e4ee61b8e434aa3b7169a55cc7a5d51248400....0.tmp
  • /data/data/####/32c49055a6d9dad539bae07f25cfefadabdfff7e20213a8....0.tmp
  • /data/data/####/35003f46cb560dde66678eb4032fe970b4e4ecfe538b71b....0.tmp
  • /data/data/####/36787cc26b4438caf734c5ab0aff0f81f286a118d03bb39....0.tmp
  • /data/data/####/395a705d49eba3cca87b836c3932cd90384e86f8d3b4023....0.tmp
  • /data/data/####/396005c858b9db1a9b15098fc73239a5b4a7fde9c48755f....0.tmp
  • /data/data/####/399e5e3225a6030a783bce1ffff6495a0adee140523a364...890f.0
  • /data/data/####/3b37a14d2519d9f5d8dbadb9779604da976004f0c635825....0.tmp
  • /data/data/####/3df20cc4f4998faf910d1b8d9e03d43c4852a3c50a0ac72....0.tmp
  • /data/data/####/416164cb95adebc40b7fed9fd67520f27f2a68cf3d59221....0.tmp
  • /data/data/####/41a2e4a70ec97005d297bbefd7573a2c1844824ea3bb94c....0.tmp
  • /data/data/####/41f832c210fce4a02baece588e6402c47c325f39aa1782c....0.tmp
  • /data/data/####/4605a309414f35a8ac5100f5bf5e79be7aab6c08c87c816....0.tmp
  • /data/data/####/461553bd9714e09c51746a5c8405cf693a19339db812076....0.tmp
  • /data/data/####/462dd7200ce2bc8092da69edff45e86bcca1fdea5f8b646....0.tmp
  • /data/data/####/479e6a61fdf969b1770c5f8762f4ceded9f72a0c8dd7ec7....0.tmp
  • /data/data/####/490e3cb1f9140488ed479ea7fac4aed1493fff580c39fb3....0.tmp
  • /data/data/####/492bd60fbc49e11e93f0ed8e04bf3f4524db0c7aa5961ed....0.tmp
  • /data/data/####/4a3184c78094a84dafb49d7ad53913bcc05266ac64ad205....0.tmp
  • /data/data/####/4a9b3022ec0200c83a5cc7b4c6324ad057f783ccd936ebc....0.tmp
  • /data/data/####/4b050504ca347ff3815de2e7e7c436795b5888ee69e4eb4....0.tmp
  • /data/data/####/4d66cc16f6522c9e1214ba659401e23e88aef8db8c1caf0....0.tmp
  • /data/data/####/4e03799acf498996454ee00a771605bf3a96942de1a6722....0.tmp
  • /data/data/####/4f084e67d50ed2c5e7a24787502745205e0d173587d479a....0.tmp
  • /data/data/####/4ff69ecd7a6fcdfd1aa8b99b6bcc6c79d904327df53f677....0.tmp
  • /data/data/####/50e244cc079903e5b032f93b559c041022d289286ed5575....0.tmp
  • /data/data/####/52652fdff1ff224cc28bf72abaa3324b10e41e985a0e90f....0.tmp
  • /data/data/####/52749f8c528441b06f8c6c86c6dbb3b39eef035b7493ea9....0.tmp
  • /data/data/####/52f73cecf3e8bc06c1178891b6380fa2a386ede04f63487....0.tmp
  • /data/data/####/52ffa91d50717dc736a1d6927aa83060ee7380b075d8dd5....0.tmp
  • /data/data/####/55ea21f6562a63088995dd5a97bd84adcdece074649823d....0.tmp
  • /data/data/####/57d2d8ed124e094ed5b1ebbe2d31b329f8a4eb70007510c....0.tmp
  • /data/data/####/590e0a610e80cd0b3798357117ff525f1b399a246a0c438....0.tmp
  • /data/data/####/5af49cc6b4ede63372a07765e7762a1312aeaa2082c6e39....0.tmp
  • /data/data/####/5b0db07b52d9b7c68bb14233278c7f3ae1b995c95d412bd....0.tmp
  • /data/data/####/5c230f97aa7f18920288c64bf3fd7ebf0a810db31be6b41....0.tmp
  • /data/data/####/5d8058ffb9b60ea21d7179622138825c1082f297fdd733a....0.tmp
  • /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
  • /data/data/####/5fe52170f22a81ea3a415ab73164f7b67b8021a21e743e8....0.tmp
  • /data/data/####/61018e7a0545bc9bfac71e41c5a356c30c8d585bca17a69....0.tmp
  • /data/data/####/641a6c7dc0f91dd187ec959228f67c622119b38e1ed6d7d....0.tmp
  • /data/data/####/64adeef36394a0515866f662514b3cd2ce265601b837e4a....0.tmp
  • /data/data/####/64dd4753f63cecece0ba2ffb36520407d5b0072528c86fe....0.tmp
  • /data/data/####/64e913602c350752d5a3b7dfd2a497f369d4d43412b433d....0.tmp
  • /data/data/####/681462e3f48a255b34bad44330d0bb5a1664df302c339f0....0.tmp
  • /data/data/####/6a036a80885c2776a0b9a27d0a008a41f33c01bbc9351a3....0.tmp
  • /data/data/####/6a5fbe4f5612dcaa4f91b64865a9f163.temp
  • /data/data/####/6c1e63a0d7a4525190db4a786a2556c43f6ec35fd0ebcec....0.tmp
  • /data/data/####/6de422ea51e5fb6b05960e34c3e0e299bf6c4cc1aa356b1....0.tmp
  • /data/data/####/6e85f2fef5f5809913d238c50ad5c1a608dfb51681de097....0.tmp
  • /data/data/####/6fff747576f182687a9ff74893614995b58f33021d356af....0.tmp
  • /data/data/####/7024f16529f8d23ae64cb2e85695c59bed0ec45bb1ec148....0.tmp
  • /data/data/####/70ab66c27835ddf7e762d349f9744b9356dde34bca12e4c....0.tmp
  • /data/data/####/714fa785e7b8086fe79c3473e7696a90cb7bc4c80f42242....0.tmp
  • /data/data/####/71d33c26b1a081bb4839ed38a14e9117a0dca7f34e467e9....0.tmp
  • /data/data/####/7417bb503a24478524a6ab17f97a32cc5b052f1b9c12b4f....0.tmp
  • /data/data/####/749ca6dd256aebdeb37816705449d0a7a522a159678ac4d....0.tmp
  • /data/data/####/74bdbb8fde2e2c66e36d9d9cd32d2e036a7757f9a690600....0.tmp
  • /data/data/####/74d71282b0edcc5d23daabaf8facfb0f416d6f7c423e472....0.tmp
  • /data/data/####/762d0e6ee2974036b0451a287ee55641a5541c91ab0952a....0.tmp
  • /data/data/####/77d092052c0a7f9da4a7bf58eaf3969558b1a6195dcfc96....0.tmp
  • /data/data/####/79caf5c3d3f69d1040bb65ddd48f52576dbcd8d6a25ba48....0.tmp
  • /data/data/####/7bc101cdeefea4bd2cbd82ed64551f993565b78415be433....0.tmp
  • /data/data/####/7be833d48a602fb26350ab7c7f18386c3cec8b27e395284....0.tmp
  • /data/data/####/7beb38b5ec69a84dbab35aa5be7071036001b9be9fdbcbc....0.tmp
  • /data/data/####/7cdcaba7f98256c677559aa54ffa248e42b92915a0773f8....0.tmp
  • /data/data/####/7e2f0e3013460e1f2b79874d98b847127953114bd78504a....0.tmp
  • /data/data/####/80312e5093f0f52f2ab1f551133b582542b6bf38952d196....0.tmp
  • /data/data/####/80cd5303123ee2ea549e4966608360fe5a845492969d885....0.tmp
  • /data/data/####/8198112b2c9c025a99e28e3d803084fe9ad4defc0eeb4b9....0.tmp
  • /data/data/####/83891ec837819c3fe5e6aa326d965c80477fda39be1a04e...918c.0
  • /data/data/####/846656207d0fa137a8a25c9231dfd07d52351cbbb4451e3....0.tmp
  • /data/data/####/85065adcd18967541f999682c1c19dfc266e5c495c91309....0.tmp
  • /data/data/####/87e83d6997bf3e0055f6bc5415d6903446a442e41a3779b....0.tmp
  • /data/data/####/89c85a63fed3ce63cd45fa81f02b6de88cd1b3080602b36....0.tmp
  • /data/data/####/8ab38dd7029d3a40bc9a2c0e83d07663c253b473ada5523....0.tmp
  • /data/data/####/8bd936e4786ff8b435ef98394b64261bd154fac7065d16f....0.tmp
  • /data/data/####/8c6fe096ecef8bdf0f29fb6f6152b443d135de4b7c72a2a....0.tmp
  • /data/data/####/8e53712261cc0731cc72505fcb496777519c026c8966f44....0.tmp
  • /data/data/####/8ea8d7b29068ebbfb4c13c5f1ed3107543a10b38d561f6f....0.tmp
  • /data/data/####/8fea9b428961e561ffb1b136ab46aa3d6bb5b5c9b83e206....0.tmp
  • /data/data/####/91dfb12be82103fbf3217422313569a3abb5bd072fffec1....0.tmp
  • /data/data/####/933458b308358067b784b1e7a0c7e05a1ded431a8b22d7c....0.tmp
  • /data/data/####/9484c56f78a073369fa4b6b3dacd8a1b6648048dd22621b....0.tmp
  • /data/data/####/963999a80aba21eb19f34d1688ab6ced3e8c805c38d347c....0.tmp
  • /data/data/####/9af63fdff51648773f436e52dac14316fd2996a71011412....0.tmp
  • /data/data/####/9de613b70780180746ef6073da614c6838e8587d1b73ef1....0.tmp
  • /data/data/####/9ecda90465f26c1de515c46897b208e0ac9f82356010f01....0.tmp
  • /data/data/####/9fcb86810e2ea6d6ff9a3c9323aab22548211f1db71e6a5....0.tmp
  • /data/data/####/Alvin2.xml
  • /data/data/####/BmhUserId.xml
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/CookiePersistence.xml
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/LastHistoryInterceptor.xml
  • /data/data/####/LastHistoryInterceptor.xml.bak
  • /data/data/####/PersonInfo.xml
  • /data/data/####/User_XiuQu.xml
  • /data/data/####/__Baidu_Stat_SDK_SendRem.xml
  • /data/data/####/__local_ap_info_cache.json
  • /data/data/####/__local_last_session.json
  • /data/data/####/__local_stat_cache.json
  • /data/data/####/__send_data_1541994827777
  • /data/data/####/__x_adsdk_agent_header__.xml
  • /data/data/####/__xadsdk__remote__final__a3e6df24-d472-4f4c-9c2...78.jar
  • /data/data/####/__xadsdk__remote__final__builtin__.jar
  • /data/data/####/__xadsdk__remote__final__builtinversion__.jar
  • /data/data/####/__xadsdk__remote__final__running__.jar
  • /data/data/####/__xadsdk_downloaded__version__.xml
  • /data/data/####/a0075c86b718209cb89ef590f33b9d5a04c500962c6235f....0.tmp
  • /data/data/####/a2655aa24237881774ada54004de43248cd3b51aa1571b7....0.tmp
  • /data/data/####/a339fb5c5dfe783d03cb8c1e7b7f87ce9e81cf653807f77....0.tmp
  • /data/data/####/a5998025332f6f3faee7f40977aa55a3045f3b79a43e729....0.tmp
  • /data/data/####/a5c3c58d84195b0be3045f6643df9dab5e41fd4feb5a88f....0.tmp
  • /data/data/####/aa6fff45988276f0463169b5e35503a67d6c5d60a83dda2....0.tmp
  • /data/data/####/ac0dc1f935afd7d407a249aa8b27981b61d3c1b9fbd863c....0.tmp
  • /data/data/####/acaa7f543a19b7054ff5bf27e7921cbf707de5375a8da64....0.tmp
  • /data/data/####/af56033eafc831f614e158848e4561924efe97b9a7511e3....0.tmp
  • /data/data/####/b03e692d4dc49a8d9d70891cc067b035637284f12309d59....0.tmp
  • /data/data/####/b06b7e1ad0bee742baa788943f0a4688f884b8b74831cda....0.tmp
  • /data/data/####/b37f1a0f5bd4c7a643a39207a83f4b586d76c26b96a8239....0.tmp
  • /data/data/####/b38c6105d037cc2f1ce93baa3222630c5c45176d1fcc884....0.tmp
  • /data/data/####/b71ffba76054e3f532711153825d21f98e236586d1a8d53....0.tmp
  • /data/data/####/b7612ee92964b705f07eb3a819921085b388c61dc47b8e9....0.tmp
  • /data/data/####/b9f11fd1a6f843de8e22511411711b1a7c9481f4491928b....0.tmp
  • /data/data/####/ba600ea7a772f56fc3fa3ff338d70756a36fe27295f75e5....0.tmp
  • /data/data/####/bb5279c1965fcff86c307b356efc8ec22876bc7f08da48e....0.tmp
  • /data/data/####/bbbc8e2ec4c56fe6ec09f8f2b902e7ce07f49845471c5dc....0.tmp
  • /data/data/####/bd590ec04d908f9535db2090bc77e749cc45dd7ca01869b....0.tmp
  • /data/data/####/be7fcf57eec629e1213df2e9b1a879d9378c3cdf172cec6....0.tmp
  • /data/data/####/bfaddb1848d616d77ab207f60edeeac66d62d686d62d06e....0.tmp
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/c01007c777762c9350ab2d6938b4255d1b725f0268f8f4f....0.tmp
  • /data/data/####/c50d81c6e43c2580abbad516ad12924df55617903d213df....0.tmp
  • /data/data/####/c65a8f9b5534a8de2239d4cc74084da39df417400ccb8b2....0.tmp
  • /data/data/####/c6e131f59624b6645bd1a8fc9efefd6a356a61c293e0ab0....0.tmp
  • /data/data/####/c72a176d5e90d074eb46078cb0ecf50c2592a6d3343c381....0.tmp
  • /data/data/####/c80e6131d000bf63d0d9ae29624c48795ea27e90833aeda....0.tmp
  • /data/data/####/c840a77a2c43b622f34ed5d41c3846f196d718d30afe04c....0.tmp
  • /data/data/####/c870cadf0e9d127146e067f090a577f5bf494b2038c18d9....0.tmp
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/com.baidu.mobads.loader.xml
  • /data/data/####/com.com.baomihuawang.androidclient_preferences.xml
  • /data/data/####/com.com.baomihuawang.androidclient_preferences.xml.bak
  • /data/data/####/com.tencent.open.config.json.1105254905
  • /data/data/####/core_info
  • /data/data/####/cube_ptr_classic_last_update.xml
  • /data/data/####/d009cc796ffbba61519096f90a1fd49aaa3b1b3cbf39a1e....0.tmp
  • /data/data/####/d03dc3cc880e48529c3c3836ceea7d91c142a35f9ca958e....0.tmp
  • /data/data/####/d0ade5455876f1824179a6f8f2a818ac0f4af5715265e0d....0.tmp
  • /data/data/####/d3846893e27844ee063a1751294f1782c64406d292dc949....0.tmp
  • /data/data/####/d48799eb37f6a175f4ecb582eea636ab17507f3881484cd....0.tmp
  • /data/data/####/d5fc63c4c02ffb37b9a330923f45902ceef465d765d9f15....0.tmp
  • /data/data/####/d668f0fe757e21f367250df9c2e2bf8934974d671d69fba....0.tmp
  • /data/data/####/d803c387610818fd4875185a2988cf8f50bde835644de17....0.tmp
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dc5d2765b12af46c8bb315a27d5f3fff8c5a310049c63fa....0.tmp
  • /data/data/####/de3974ffb5467847f3ab84e710bfa1d77767f4eff38d8b4....0.tmp
  • /data/data/####/debug.conf
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/dexMethod.82894129.dat
  • /data/data/####/e03a5ef58453533bcf05ee84ddb97dea04062ff636fff3f....0.tmp
  • /data/data/####/e17afd50b564577f1f116c8b5cc41ac76386b24212eebde....0.tmp
  • /data/data/####/e2e53e31d88bfc731095b0e17a53a773727c4fbbbff5759....0.tmp
  • /data/data/####/e35106cfbac9cc1b98c13bc9ae11772494945a2a893e049....0.tmp
  • /data/data/####/e39af25157e19be377e9909c3562f48eeb0b57d749e3e39....0.tmp
  • /data/data/####/e4788146ceaecf0971b802d8363ac1680da8c9ba1b32c0b....0.tmp
  • /data/data/####/e481d8e7a90e7cb93da2fd63e49a6feb4bbe3ee560d3d3f....0.tmp
  • /data/data/####/e58017f520ad6fe6f3c819ee31bc54558b4369327409fcb....0.tmp
  • /data/data/####/e6cb62f66488aac29dfac4d4e4e43307bec989729fc0066....0.tmp
  • /data/data/####/e6e617860318b024bb805f9e72368b2556be1085365fc6c....0.tmp
  • /data/data/####/e7827c85e434d2fd2b8726c8f6e0a3c2a4647266d04f0df....0.tmp
  • /data/data/####/e80b783283082fa44d99545a1fb3b3549e927d1c72bb847....0.tmp
  • /data/data/####/e864274bf52c3895ff268ad1056e615425fb07651b1bc6f....0.tmp
  • /data/data/####/eafb0044ca9877c958405145e0395dbff785da8eeba1ca0...3c1d.0
  • /data/data/####/eec716ccfbdd3cf19757288e74e46d2a1d357025e6c7c85....0.tmp
  • /data/data/####/eec7bdf9432a0808550bd89ff57fbd5d893c93f343ae45a...53ef.0
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f25bdf7ca76ef243ee813bf4b78641f52bed6b8ad4b6d69....0.tmp
  • /data/data/####/f48df77daf2e214fa7f596ebfaa29ec87f497ea197db314....0.tmp
  • /data/data/####/f60bcdb34e7988452dd8fa55a86c5aa8626922d339fd6cc....0.tmp
  • /data/data/####/f7851b905f0f13ee0a494b2c7e3e94f60a5eb06f83820ee....0.tmp
  • /data/data/####/f836e4023b5a5396a68aa9b5d1c684928f84cfe952ab710....0.tmp
  • /data/data/####/f864a90073b0bdeab0a50554f3b314e0c9a02e3abc994db....0.tmp
  • /data/data/####/f8651af087a0c07ac625d0f2724d3cac3c0f1e9407885e3....0.tmp
  • /data/data/####/f872367b1b9aaa377ef39066c98d9e7a554dc7ebf164591....0.tmp
  • /data/data/####/f88ece34ab80d7f395fc9f2193cf49411c66424a3afa0dc....0.tmp
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/fb8b1048aba65ab54207e4492d20f2df1d2190cb2d91bcb....0.tmp
  • /data/data/####/fc8a90d5c63cf08b9107b8cfe6f21ec8b07a5330d2217cd....0.tmp
  • /data/data/####/fd69ddb2c643b397816e5a0e81f2572f3bb07500e091bcf....0.tmp
  • /data/data/####/fe23792cdf3c35cedcc04696c53569371aba990d601f9fe....0.tmp
  • /data/data/####/fe5796e07a408f2d76ac88d6c0f454a5bf1398ad1dc2b06....0.tmp
  • /data/data/####/feef13ae48d75357ff40c4e5e8e7d52d4a2f42abdea12be....0.tmp
  • /data/data/####/gdaemon_20161017
  • /data/data/####/gdt_config.cfg
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_stat.db
  • /data/data/####/gdt_stat.db-journal
  • /data/data/####/gdt_suid
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/index
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/isNewInstall.xml
  • /data/data/####/journal.tmp
  • /data/data/####/libcuid.so
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.9.0.2.so
  • /data/data/####/libufix.so
  • /data/data/####/libyaqbasic.82894129.so
  • /data/data/####/libyaqpro.82894129.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mix.dex
  • /data/data/####/multidex.version.xml
  • /data/data/####/native_record_lock
  • /data/data/####/net_sp_name.xml
  • /data/data/####/permission.xml
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/run.pid
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/security_info
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/tdata_Soq141
  • /data/data/####/tdata_Soq141.jar
  • /data/data/####/tdata_vxj811
  • /data/data/####/tdata_vxj811.jar
  • /data/data/####/tencent_analysis.db-journal
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/umeng_socialize.xml
  • /data/data/####/update_lc
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/yaqsdkcookie
  • /data/media/####/.confd
  • /data/media/####/.confd-journal
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.timestamp
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/ad9615c670732582282d303b573cabf3
  • /data/media/####/app.db
  • /data/media/####/com.com.baomihuawang.androidclient.bin
  • /data/media/####/com.com.baomihuawang.androidclient.db
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/d71e4a7588f489b8079758099d498fdd
  • /data/media/####/fe112b4ce4a2e9cc33c4e1feb0c7e090
  • /data/media/####/tdata_Soq141
  • /data/media/####/tdata_vxj811
  • /data/media/####/test.log
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.ui.service.GePushService 26419 300 0
  • cat /sys/class/net/wlan0/address
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.product.cpu.abi
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • mount
Loads the following dynamic libraries:
  • Bugly
  • MtaNativeCrash
  • crash_analysis
  • getuiext2
  • ijkffmpeg
  • ijkplayer
  • ijksdl
  • libnfix
  • libshella-2.9.0.2
  • libufix
  • libyaqbasic.82894129
  • libyaqpro.82894129
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DESede-ECB-PKCS5Padding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DESede-ECB-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android