マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.5511

Added to the Dr.Web virus database: 2018-12-01

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) ti####.c####.l####.####.com:80
  • TCP(HTTP/1.1) pub-####.qin####.com:80
  • TCP(HTTP/1.1) a####.b####.qq.com:8012
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) cgi.con####.qq.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) nav.cn.ron####.com:80
  • TCP(HTTP/1.1) a####.b####.qq.com:8011
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(TLS/1.0) api.w####.com:443
  • TCP(TLS/1.0) a####.m####.com.cn:443
  • TCP(TLS/1.0) s####.ml####.cc:443
  • TCP(TLS/1.0) st####.my####.com.cn:443
  • TCP(TLS/1.0) s####.cn.ron####.com:443
  • TCP c####.g####.ig####.com:5225
  • TCP 1####.92.89.152:8604
  • TCP sdk.o####.t####.####.com:5224
DNS requests:
  • 7j####.c####.z0.####.com
  • a####.b####.qq.com
  • a####.m####.com.cn
  • aexcep####.b####.qq.com
  • and####.b####.qq.com
  • api.w####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cgi.con####.qq.com
  • nav.cn.ron####.com
  • pub-####.qin####.com
  • s####.cn.ron####.com
  • s####.ml####.cc
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • st####.my####.com.cn
HTTP GET requests:
  • cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?sdkv=####&appid=###...
  • pub-####.qin####.com/tdata_EDT356
  • t####.c####.q####.####.com/tdata_bca864
  • t####.c####.q####.####.com/tdata_fyR930
  • ti####.c####.l####.####.com/config/hz-hzv3.conf
HTTP POST requests:
  • a####.b####.qq.com:8011/rqd/async
  • a####.b####.qq.com:8012/rqd/async
  • and####.b####.qq.com/rqd/async
  • and####.b####.qq.com/rqd/async?aid=####
  • c-h####.g####.com/api.php?format=####&t=####
  • nav.cn.ron####.com/navipush.json
  • sdk.o####.p####.####.com/api.php?format=####&t=####
File system changes:
Creates the following files:
  • /data/data/####/1.png
  • /data/data/####/1004
  • /data/data/####/14d8e88085be
  • /data/data/####/2.png
  • /data/data/####/3.png
  • /data/data/####/AppPrefs_prefs.xml
  • /data/data/####/COUNTLY_STORE.xml
  • /data/data/####/CachedGeoposition.db
  • /data/data/####/CachedGeoposition.db-journal
  • /data/data/####/Camera.js
  • /data/data/####/CameraConstants.js
  • /data/data/####/CameraPopoverHandle.js
  • /data/data/####/CameraPopoverOptions.js
  • /data/data/####/Connection.js
  • /data/data/####/Contact.js
  • /data/data/####/ContactAddress.js
  • /data/data/####/ContactError.js
  • /data/data/####/ContactField.js
  • /data/data/####/ContactFieldType.js
  • /data/data/####/ContactFindOptions.js
  • /data/data/####/ContactName.js
  • /data/data/####/ContactOrganization.js
  • /data/data/####/DirectoryEntry.js
  • /data/data/####/DirectoryReader.js
  • /data/data/####/Entry.js
  • /data/data/####/File.js
  • /data/data/####/FileEntry.js
  • /data/data/####/FileError.js
  • /data/data/####/FileReader.js
  • /data/data/####/FileSystem.js
  • /data/data/####/FileUploadOptions.js
  • /data/data/####/FileUploadResult.js
  • /data/data/####/FileWriter.js
  • /data/data/####/Flags.js
  • /data/data/####/LocalFileSystem.js
  • /data/data/####/MAds.js
  • /data/data/####/MAliyunOSS.js
  • /data/data/####/MBugly.js
  • /data/data/####/MCloudAssistant.js
  • /data/data/####/MDownloader.js
  • /data/data/####/MFileManager.js
  • /data/data/####/MHotUpdate.js
  • /data/data/####/MILayoutImage.js
  • /data/data/####/MISign.js
  • /data/data/####/MIUtils.js
  • /data/data/####/MImageBrowser.js
  • /data/data/####/MMagicWindow.js
  • /data/data/####/MPhoto.js
  • /data/data/####/MQQ.js
  • /data/data/####/MRongCloudCaigou.js
  • /data/data/####/MUploader.js
  • /data/data/####/MUtils.js
  • /data/data/####/MWebview.js
  • /data/data/####/MWeiBo.js
  • /data/data/####/MWeixin.js
  • /data/data/####/Metadata.js
  • /data/data/####/MicCore.js
  • /data/data/####/MultiDex.lock
  • /data/data/####/ProgressEvent.js
  • /data/data/####/README
  • /data/data/####/RongCloudLibPlugin.js
  • /data/data/####/RongPush.xml
  • /data/data/####/SQLitePlugin-Android.js
  • /data/data/####/Statistics.xml
  • /data/data/####/_action-sheet.scss
  • /data/data/####/_animations.scss
  • /data/data/####/_backdrop.scss
  • /data/data/####/_badge.scss
  • /data/data/####/_bar.scss
  • /data/data/####/_button-bar.scss
  • /data/data/####/_button.scss
  • /data/data/####/_checkbox.scss
  • /data/data/####/_form.scss
  • /data/data/####/_grid.scss
  • /data/data/####/_ionicons-font.scss
  • /data/data/####/_ionicons-icons.scss
  • /data/data/####/_ionicons-variables.scss
  • /data/data/####/_items.scss
  • /data/data/####/_list.scss
  • /data/data/####/_loading.scss
  • /data/data/####/_log.db
  • /data/data/####/_log.db-journal
  • /data/data/####/_menu.scss
  • /data/data/####/_mixins.scss
  • /data/data/####/_modal.scss
  • /data/data/####/_platform.scss
  • /data/data/####/_popover.scss
  • /data/data/####/_popup.scss
  • /data/data/####/_progress.scss
  • /data/data/####/_radio.scss
  • /data/data/####/_range.scss
  • /data/data/####/_refresher.scss
  • /data/data/####/_reset.scss
  • /data/data/####/_scaffolding.scss
  • /data/data/####/_select.scss
  • /data/data/####/_slide-box.scss
  • /data/data/####/_spinner.scss
  • /data/data/####/_tabs.scss
  • /data/data/####/_toggle.scss
  • /data/data/####/_transitions.scss
  • /data/data/####/_type.scss
  • /data/data/####/_util.scss
  • /data/data/####/_variables.scss
  • /data/data/####/about-controller.js
  • /data/data/####/about.html
  • /data/data/####/about.png
  • /data/data/####/ad-page-service.js
  • /data/data/####/add-batch-problem-model.js
  • /data/data/####/add-batch-problem.scss
  • /data/data/####/add-group-member-controller.js
  • /data/data/####/add-problem-controller.js
  • /data/data/####/add-problem-model.js
  • /data/data/####/add-problem.html
  • /data/data/####/add-problem.scss
  • /data/data/####/add-search-checkitem-controller.js
  • /data/data/####/add-select-checkitem-controller.js
  • /data/data/####/add-select-contractor-controller.js
  • /data/data/####/add-select-desc-controller.js
  • /data/data/####/add-select-position-controller.js
  • /data/data/####/add-select-responsible-company-controller.js
  • /data/data/####/add-special-problem-controller.js
  • /data/data/####/adpage-popup-view.html
  • /data/data/####/all-problem-list-controller.js
  • /data/data/####/all-problem-list-model.js
  • /data/data/####/all-problem-list-service.js
  • /data/data/####/all-problem-list-service.test.js
  • /data/data/####/all-problem-list.html
  • /data/data/####/all-problem-list.scss
  • /data/data/####/angular-animate.js
  • /data/data/####/angular-animate.min.js
  • /data/data/####/angular-ios9-uiwebview.patch.js
  • /data/data/####/angular-mocks.js
  • /data/data/####/angular-resource.js
  • /data/data/####/angular-resource.min.js
  • /data/data/####/angular-sanitize.js
  • /data/data/####/angular-sanitize.min.js
  • /data/data/####/angular-ui-router.js
  • /data/data/####/angular-ui-router.min.js
  • /data/data/####/angular.js
  • /data/data/####/angular.min.js
  • /data/data/####/app-chat-info.scss
  • /data/data/####/app-chat-list.scss
  • /data/data/####/app-chat-user.scss
  • /data/data/####/app-contact-directive.js
  • /data/data/####/app-desktop.scss
  • /data/data/####/app-frequently-problem-model-directive.js
  • /data/data/####/app-important-checkitem-modal-directive.js
  • /data/data/####/app-list-menu-directive.js
  • /data/data/####/app-list-menu.scss
  • /data/data/####/app-paper-directive.js
  • /data/data/####/app-project-selector-directive.js
  • /data/data/####/app-project-selector-model.js
  • /data/data/####/app-qr-code-app-store.png
  • /data/data/####/app-qr-code.png
  • /data/data/####/app-restore-service.js
  • /data/data/####/app-room-check-list.js
  • /data/data/####/app-room-design-change-directive.js
  • /data/data/####/app-room-filter-directive.js
  • /data/data/####/app-room-fitment-style-list.js
  • /data/data/####/app-room-huxing-directive.js
  • /data/data/####/app-room-list-directive.js
  • /data/data/####/app-update-service.js
  • /data/data/####/app-upload-status-service.js
  • /data/data/####/app.js
  • /data/data/####/app.png
  • /data/data/####/app.run.js
  • /data/data/####/app.scss
  • /data/data/####/auth-right-service.js
  • /data/data/####/av_01.png
  • /data/data/####/av_02.png
  • /data/data/####/av_03.png
  • /data/data/####/av_04.png
  • /data/data/####/av_05.png
  • /data/data/####/avg_01.png
  • /data/data/####/avg_02.png
  • /data/data/####/avg_03.png
  • /data/data/####/avg_04.png
  • /data/data/####/avg_05.png
  • /data/data/####/back.svg
  • /data/data/####/base-data-ui-service.js
  • /data/data/####/base.scss
  • /data/data/####/base.scssc
  • /data/data/####/batch-add-problem-controller.js
  • /data/data/####/batch-add-problem.html
  • /data/data/####/batch-back-problem-model.js
  • /data/data/####/batch-check-item-repository.js
  • /data/data/####/batch-select-checkitem-controller.js
  • /data/data/####/batch-select-checkitem.html
  • /data/data/####/batch-select-contractor-controller.js
  • /data/data/####/batch-select-contractor.html
  • /data/data/####/batch-select-desc-controller.js
  • /data/data/####/batch-select-desc.html
  • /data/data/####/batch-select-position-controller.js
  • /data/data/####/batch-select-position.html
  • /data/data/####/batch-unit-repository.js
  • /data/data/####/batch-unit-update-service.js
  • /data/data/####/bd.svg
  • /data/data/####/behavior-repository.js
  • /data/data/####/behavior-track-service.js
  • /data/data/####/boot.js
  • /data/data/####/bottom.html
  • /data/data/####/bugly_db_-journal
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/build.js
  • /data/data/####/building-list-controller.js
  • /data/data/####/building-list-model.js
  • /data/data/####/building-list.html
  • /data/data/####/building-repository.js
  • /data/data/####/cancel-problem-controller.js
  • /data/data/####/chat-data-repository.js
  • /data/data/####/chat-group-model.js
  • /data/data/####/chat-group-service.js
  • /data/data/####/chat-info-controller.js
  • /data/data/####/chat-info-model.js
  • /data/data/####/chat-info.html
  • /data/data/####/chat-list-controller.js
  • /data/data/####/chat-list-model.js
  • /data/data/####/chat-list.html
  • /data/data/####/chat-model.js
  • /data/data/####/chat-service.js
  • /data/data/####/chat-user-info-controller.js
  • /data/data/####/chat-user-info.html
  • /data/data/####/chat-user-model.js
  • /data/data/####/chat-user-service.js
  • /data/data/####/check-data-changed-model.js
  • /data/data/####/check-item-guide-repository.js
  • /data/data/####/check-item-guide-service.js
  • /data/data/####/check-item-repository.js
  • /data/data/####/check-item-service.js
  • /data/data/####/check-list-desc-controller.js
  • /data/data/####/check-list-desc.html
  • /data/data/####/checkitem-remark-history-model.js
  • /data/data/####/checkitem-remark-history-repository.js
  • /data/data/####/checkitem-remark-history-service.js
  • /data/data/####/checkitem-search-history-service.js
  • /data/data/####/checkitem-search-history-service.test.js
  • /data/data/####/checkitem-search.html
  • /data/data/####/checkitem-select.html
  • /data/data/####/checkmark-child-error.png
  • /data/data/####/checkmark-child-succ.png
  • /data/data/####/checkmark-parent-error.png
  • /data/data/####/checkmark-parent-succ.png
  • /data/data/####/checkroom-batch-repository.js
  • /data/data/####/checkroom-problem-operate-log.js
  • /data/data/####/checkroom.png
  • /data/data/####/chevron-down.png
  • /data/data/####/chevron-down2-check.png
  • /data/data/####/chevron-down2.png
  • /data/data/####/chevron-right-white.png
  • /data/data/####/chevron-right.png
  • /data/data/####/chevron-up.png
  • /data/data/####/chevron-up2-check.png
  • /data/data/####/close-problem-controller.js
  • /data/data/####/close.svg
  • /data/data/####/cloud-assistant-service.js
  • /data/data/####/cls.jpg
  • /data/data/####/com.tencent.open.config.json.prod
  • /data/data/####/common-ready-service.js
  • /data/data/####/common-upload-service.js
  • /data/data/####/common.scss
  • /data/data/####/common.scssc
  • /data/data/####/config.js
  • /data/data/####/confirmed.png
  • /data/data/####/console.js
  • /data/data/####/construction-repository.js
  • /data/data/####/construction-service.js
  • /data/data/####/contact-service.js
  • /data/data/####/contact.html
  • /data/data/####/contacts.js
  • /data/data/####/context.js
  • /data/data/####/contractor-select.html
  • /data/data/####/convertUtils.js
  • /data/data/####/cordova.js
  • /data/data/####/cordova_loader.js
  • /data/data/####/cordova_plugins.js
  • /data/data/####/crashrecord.xml
  • /data/data/####/customer-assess-repository.js
  • /data/data/####/customer-room-repository.js
  • /data/data/####/customer-room-service.js
  • /data/data/####/customer-tag-controller.js
  • /data/data/####/customer-tag-model.js
  • /data/data/####/customer-tag-repository.js
  • /data/data/####/customer-tag-service.js
  • /data/data/####/customer-tag.html
  • /data/data/####/customer-tag.scss
  • /data/data/####/data-clear-controller.js
  • /data/data/####/data-clear.html
  • /data/data/####/data-download-log-repository.js
  • /data/data/####/data-download-service.js
  • /data/data/####/data-increment-repository.js
  • /data/data/####/data-repair-service.js
  • /data/data/####/data-task-service.js
  • /data/data/####/data-task-service.test.js
  • /data/data/####/data-up.png
  • /data/data/####/data-upload-service.js
  • /data/data/####/dataBuild.js
  • /data/data/####/dataBuild.test.js
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/date-format-filter.js
  • /data/data/####/day-delivery-service.js
  • /data/data/####/db.js
  • /data/data/####/default_img.png
  • /data/data/####/default_img_big.png
  • /data/data/####/delivering-room-model.js
  • /data/data/####/delivering-room-service.js
  • /data/data/####/delivery-config-controller.js
  • /data/data/####/delivery-config.html
  • /data/data/####/delivery-confirmed-controller.js
  • /data/data/####/delivery-process-confirmed.html
  • /data/data/####/delivery-process-customer-info-directive.js
  • /data/data/####/delivery-process-no-list-controller.js
  • /data/data/####/delivery-process-no-list-model.js
  • /data/data/####/delivery-process-no-list.html
  • /data/data/####/delivery-process-node-model.js
  • /data/data/####/delivery-process-refuse-controller.js
  • /data/data/####/delivery-process-retransacted-reason-controller.js
  • /data/data/####/delivery-process-retransacted-reason.html
  • /data/data/####/delivery-process-room-controller.js
  • /data/data/####/delivery-process-room-log-controller.js
  • /data/data/####/delivery-process-room-log-model.js
  • /data/data/####/delivery-process-room-log.html
  • /data/data/####/delivery-process-room-transacted-controller.js
  • /data/data/####/delivery-process-room-transacted-model.js
  • /data/data/####/delivery-process-room-transacted.html
  • /data/data/####/delivery-process-room.html
  • /data/data/####/delivery-process-room.scss
  • /data/data/####/delivery-process.scss
  • /data/data/####/delivery-refuse-controller.js
  • /data/data/####/delivery-refuse.html
  • /data/data/####/delivery-review-controller.js
  • /data/data/####/delivery-review.html
  • /data/data/####/delivery-service.js
  • /data/data/####/delivery-storage.js
  • /data/data/####/delivery-todo-service.js
  • /data/data/####/delivery-view-controller.js
  • /data/data/####/delivery-view.html
  • /data/data/####/delivery.png
  • /data/data/####/desc-construction-repository.js
  • /data/data/####/desc-repository.js
  • /data/data/####/desc-select.html
  • /data/data/####/desc-service.js
  • /data/data/####/desc-service.test.js
  • /data/data/####/desktop-controller.js
  • /data/data/####/desktop-delivery-service.js
  • /data/data/####/desktop-service.js
  • /data/data/####/desktop.html
  • /data/data/####/device.js
  • /data/data/####/dispatch.png
  • /data/data/####/download-by-page-service.js
  • /data/data/####/download-chat-data-service.js
  • /data/data/####/download-image-service.js
  • /data/data/####/download-insterface-service.js
  • /data/data/####/download-timestamp-repository.js
  • /data/data/####/download-timestamp-service.js
  • /data/data/####/edit-problem-controller.js
  • /data/data/####/exceptionHandler.js
  • /data/data/####/exceptionHandler.test.js
  • /data/data/####/exec.js
  • /data/data/####/feedback-common-service.js
  • /data/data/####/feedback-controller.js
  • /data/data/####/feedback-popup-view.html
  • /data/data/####/feedback-service.js
  • /data/data/####/feedback-storage.js
  • /data/data/####/feedback-title.png
  • /data/data/####/feedback.html
  • /data/data/####/feedback.scss
  • /data/data/####/feedback.scssc
  • /data/data/####/feedback_mail.png
  • /data/data/####/file-upload-service.js
  • /data/data/####/fileSystemPaths.js
  • /data/data/####/fileSystems-roots.js
  • /data/data/####/fileSystems.js
  • /data/data/####/file__0.localstorage-journal
  • /data/data/####/finance.png
  • /data/data/####/find-pass-controller.js
  • /data/data/####/find-pass-step1.html
  • /data/data/####/find-pass-step2.html
  • /data/data/####/find-pwd-controller.js
  • /data/data/####/find-pwd-service.js
  • /data/data/####/fitment-style-checkitem-repository.js
  • /data/data/####/fitment-style-detail-controller.js
  • /data/data/####/fitment-style-detail-model.js
  • /data/data/####/fitment-style-detail.html
  • /data/data/####/fitment-style-repository.js
  • /data/data/####/fitment-style-service.js
  • /data/data/####/fonts.scss
  • /data/data/####/footer-directive.js
  • /data/data/####/frequently-problem-controller.js
  • /data/data/####/frequently-problem-view.html
  • /data/data/####/frequently-problem.scss
  • /data/data/####/frequently.png
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gift.png
  • /data/data/####/global-storage-repository.js
  • /data/data/####/global-storage-service.js
  • /data/data/####/go_top.png
  • /data/data/####/guide.png
  • /data/data/####/guide_01.png
  • /data/data/####/guide_02.png
  • /data/data/####/guide_03.png
  • /data/data/####/gulpfile.js
  • /data/data/####/gx_sp.xml
  • /data/data/####/hasTag.png
  • /data/data/####/help-delivery.png
  • /data/data/####/help-feedback-controller.js
  • /data/data/####/help-feedback.html
  • /data/data/####/help-opening.png
  • /data/data/####/help-simulate.png
  • /data/data/####/hidpi-canvas.js
  • /data/data/####/hot-check-service.js
  • /data/data/####/http.ext.js
  • /data/data/####/http.js
  • /data/data/####/huxing.jpg
  • /data/data/####/huxing.js
  • /data/data/####/ic_accept_act.png
  • /data/data/####/ic_back.png
  • /data/data/####/ic_back@2x.png
  • /data/data/####/ic_back@3x.png
  • /data/data/####/ic_back@hdpi.png
  • /data/data/####/ic_back@mdpi.png
  • /data/data/####/ic_back@xhdpi.png
  • /data/data/####/ic_back@xxhdpi.png
  • /data/data/####/ic_chat.png
  • /data/data/####/ic_chat_act.png
  • /data/data/####/ic_check_act.png
  • /data/data/####/ic_delivery_act.png
  • /data/data/####/ic_delivery_process.png
  • /data/data/####/ic_desktop.png
  • /data/data/####/ic_desktop_act.png
  • /data/data/####/ic_disabled.png
  • /data/data/####/ic_group.png
  • /data/data/####/ic_group@2x.png
  • /data/data/####/ic_group@3x.png
  • /data/data/####/ic_group@hdpi.png
  • /data/data/####/ic_group@mdpi.png
  • /data/data/####/ic_group@xhdpi.png
  • /data/data/####/ic_group@xxhdpi.png
  • /data/data/####/ic_menu.png
  • /data/data/####/ic_no_notice.png
  • /data/data/####/ic_no_wifi.png
  • /data/data/####/ic_opening_act.png
  • /data/data/####/ic_phone.png
  • /data/data/####/ic_phone_act.png
  • /data/data/####/ic_private.png
  • /data/data/####/ic_private@2x.png
  • /data/data/####/ic_private@3x.png
  • /data/data/####/ic_private@hdpi.png
  • /data/data/####/ic_private@mdpi.png
  • /data/data/####/ic_private@xhdpi.png
  • /data/data/####/ic_private@xxhdpi.png
  • /data/data/####/ic_report.png
  • /data/data/####/ic_share.png
  • /data/data/####/ic_simulate_act.png
  • /data/data/####/ic_slient.png
  • /data/data/####/ic_todo.png
  • /data/data/####/ic_todo_act.png
  • /data/data/####/ic_user.png
  • /data/data/####/ic_user_act.png
  • /data/data/####/icomoon.ttf
  • /data/data/####/icon_01.png
  • /data/data/####/iconfont.css
  • /data/data/####/iconfont.eot
  • /data/data/####/iconfont.svg
  • /data/data/####/iconfont.ttf
  • /data/data/####/iconfont.woff
  • /data/data/####/iconkong.png
  • /data/data/####/iconxuan.png
  • /data/data/####/image-download-setting-controller.js
  • /data/data/####/image-download-setting.html
  • /data/data/####/image-service.js
  • /data/data/####/image.js
  • /data/data/####/img_blank.png
  • /data/data/####/important-checkitem-controller.js
  • /data/data/####/important-checkitem-model.js
  • /data/data/####/important-checkitem-repository.js
  • /data/data/####/important-checkitem-service.js
  • /data/data/####/important-checkitem-service.test.js
  • /data/data/####/important-checkitem-view.html
  • /data/data/####/important-checkitem.scss
  • /data/data/####/important.png
  • /data/data/####/important_read.png
  • /data/data/####/index
  • /data/data/####/index-controller.js
  • /data/data/####/index.html
  • /data/data/####/init.pid
  • /data/data/####/init.sql
  • /data/data/####/initDB.js
  • /data/data/####/initDB.test.js
  • /data/data/####/init_c1.pid
  • /data/data/####/input-clear.png
  • /data/data/####/inspect-guide-controller.js
  • /data/data/####/inspect-guide-view-controller.js
  • /data/data/####/inspect-guide-view.html
  • /data/data/####/inspect-guide.html
  • /data/data/####/ion-ditem-guide.tmpl.html
  • /data/data/####/ion-dtree-list.css
  • /data/data/####/ion-dtree-list.js
  • /data/data/####/ion-dtree-list.tmpl.html
  • /data/data/####/ionic-angular.js
  • /data/data/####/ionic-angular.min.js
  • /data/data/####/ionic.bundle.js
  • /data/data/####/ionic.bundle.min.js
  • /data/data/####/ionic.css
  • /data/data/####/ionic.fix.css
  • /data/data/####/ionic.js
  • /data/data/####/ionic.min.css
  • /data/data/####/ionic.min.js
  • /data/data/####/ionic.png
  • /data/data/####/ionic.scss
  • /data/data/####/ionicons.eot
  • /data/data/####/ionicons.scss
  • /data/data/####/ionicons.svg
  • /data/data/####/ionicons.ttf
  • /data/data/####/ionicons.woff
  • /data/data/####/iosx.scss
  • /data/data/####/isChrome.js
  • /data/data/####/jasmine-html.js
  • /data/data/####/jasmine.css
  • /data/data/####/jasmine.js
  • /data/data/####/jasmine_favicon.png
  • /data/data/####/journal.tmp
  • /data/data/####/jquery-1.11.1.min.js
  • /data/data/####/karma.conf.js
  • /data/data/####/keyboard.js
  • /data/data/####/layout-history-service.js
  • /data/data/####/layout-image-service.js
  • /data/data/####/layout-img-controller.js
  • /data/data/####/layout-img-special-controller.js
  • /data/data/####/layout-img-special-model.js
  • /data/data/####/layout-img-web-special.html
  • /data/data/####/layout-img-web.html
  • /data/data/####/layout-img.html
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.9.1.0.so
  • /data/data/####/libufix.so
  • /data/data/####/list-controller.js
  • /data/data/####/list.html
  • /data/data/####/loading-background.png
  • /data/data/####/loading-star.png
  • /data/data/####/loading.gif
  • /data/data/####/loadingNew.gif
  • /data/data/####/loadingbar-service.js
  • /data/data/####/local-config-repository.js
  • /data/data/####/localDB.js
  • /data/data/####/localStorage.js
  • /data/data/####/localStorage.keys.js
  • /data/data/####/localStorage.test.js
  • /data/data/####/local_crash_lock
  • /data/data/####/login-controller.js
  • /data/data/####/login-service.js
  • /data/data/####/login.html
  • /data/data/####/loginbg.png
  • /data/data/####/m-paper-directive.js
  • /data/data/####/m-ready-directive.js
  • /data/data/####/mGTPush.js
  • /data/data/####/magic-window-service.js
  • /data/data/####/matcher.js
  • /data/data/####/material.png
  • /data/data/####/md5.js
  • /data/data/####/memory-setting-controller.js
  • /data/data/####/memory-setting.html
  • /data/data/####/message-detail.png
  • /data/data/####/mix.dex
  • /data/data/####/mobile-edit-controller.js
  • /data/data/####/mobile-edit.html
  • /data/data/####/mobiscroll.core.js
  • /data/data/####/mobiscroll.css
  • /data/data/####/mobiscroll.select.js
  • /data/data/####/mock.js
  • /data/data/####/more.png
  • /data/data/####/multidex.version.xml
  • /data/data/####/mwsdk_analytics.db-journal
  • /data/data/####/my-project-repository.js
  • /data/data/####/my-project.scss
  • /data/data/####/native_record_lock
  • /data/data/####/nativeapiprovider.js
  • /data/data/####/network-check-service.js
  • /data/data/####/network.js
  • /data/data/####/new.png
  • /data/data/####/ng-cordova-mocks.js
  • /data/data/####/ng-cordova-mocks.min.js
  • /data/data/####/ng-cordova.js
  • /data/data/####/ng-cordova.min.js
  • /data/data/####/no-auth.png
  • /data/data/####/no-data.png
  • /data/data/####/no-permission.png
  • /data/data/####/no_init.png
  • /data/data/####/no_issue.png
  • /data/data/####/no_todo.png
  • /data/data/####/no_wifi.png
  • /data/data/####/notice-new.png
  • /data/data/####/notice-repository.js
  • /data/data/####/onlie-help-tel-bg.png
  • /data/data/####/online-help-model.js
  • /data/data/####/online-help-service.js
  • /data/data/####/online-help.scss
  • /data/data/####/onlinehelp.png
  • /data/data/####/opening.png
  • /data/data/####/package-lock.json
  • /data/data/####/package.json
  • /data/data/####/paper.min.js
  • /data/data/####/password-hide.png
  • /data/data/####/password-show.png
  • /data/data/####/path.js
  • /data/data/####/persistent_data.xml
  • /data/data/####/platform.js
  • /data/data/####/plugin-data-service.js
  • /data/data/####/pluginApi.js
  • /data/data/####/popup.js
  • /data/data/####/position-repository.js
  • /data/data/####/position-select.html
  • /data/data/####/position-service-test.js
  • /data/data/####/position-service.js
  • /data/data/####/problem-add.html
  • /data/data/####/problem-cancel.html
  • /data/data/####/problem-checkitem-model.js
  • /data/data/####/problem-close.html
  • /data/data/####/problem-controller.js
  • /data/data/####/problem-edit.html
  • /data/data/####/problem-image-repository.js
  • /data/data/####/problem-list-controller.js
  • /data/data/####/problem-list-data-service.js
  • /data/data/####/problem-list-filter-model.js
  • /data/data/####/problem-list-model.js
  • /data/data/####/problem-list-service.js
  • /data/data/####/problem-list.html
  • /data/data/####/problem-list.scss
  • /data/data/####/problem-list.scssc
  • /data/data/####/problem-log-repository.js
  • /data/data/####/problem-pass-confirm-controller.js
  • /data/data/####/problem-pass-confirm-model.js
  • /data/data/####/problem-pass-confirm.html
  • /data/data/####/problem-position-controller.js
  • /data/data/####/problem-position.html
  • /data/data/####/problem-process-repository.js
  • /data/data/####/problem-reason-repository.js
  • /data/data/####/problem-reason-service.js
  • /data/data/####/problem-repository.js
  • /data/data/####/problem-sendback.html
  • /data/data/####/problem-service.js
  • /data/data/####/problem-view-controller.js
  • /data/data/####/problem-view.html
  • /data/data/####/problem.html
  • /data/data/####/problemStorage.js
  • /data/data/####/project-selector-controller.js
  • /data/data/####/project-selector.html
  • /data/data/####/project-service.js
  • /data/data/####/promptbasednativeapi.js
  • /data/data/####/property.png
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/pwd-edit-controller.js
  • /data/data/####/pwd-edit.html
  • /data/data/####/pwd-service.js
  • /data/data/####/pwd-service.test.js
  • /data/data/####/qq.png
  • /data/data/####/qq_kj.png
  • /data/data/####/receive-record-controller.js
  • /data/data/####/receive-record.html
  • /data/data/####/receive-service.js
  • /data/data/####/receive-storage.js
  • /data/data/####/receive-view-controller.js
  • /data/data/####/receive-view.html
  • /data/data/####/refresh.svg
  • /data/data/####/refuse-list-controller.js
  • /data/data/####/refuse-list.html
  • /data/data/####/reinspected.png
  • /data/data/####/report-service.js
  • /data/data/####/report.png
  • /data/data/####/requestFileSystem.js
  • /data/data/####/resolveLocalFileSystemURI.js
  • /data/data/####/responsible-company-select.html
  • /data/data/####/room-check-list-controller.js
  • /data/data/####/room-check-list-model.js
  • /data/data/####/room-check-list-repository.js
  • /data/data/####/room-check-list-service.js
  • /data/data/####/room-check-list.html
  • /data/data/####/room-check-list.scss
  • /data/data/####/room-delivery-rejection-repository.js
  • /data/data/####/room-design-change-model.js
  • /data/data/####/room-design-change-repository.js
  • /data/data/####/room-design-change.html
  • /data/data/####/room-design-change.scss
  • /data/data/####/room-detail-controller.js
  • /data/data/####/room-detail-design-change-controller.js
  • /data/data/####/room-detail-huxing-controller.js
  • /data/data/####/room-detail-list-controller.js
  • /data/data/####/room-detail-mark-position-controller.js
  • /data/data/####/room-detail.scss
  • /data/data/####/room-empty.png
  • /data/data/####/room-filter.html
  • /data/data/####/room-fitment-style-list-controller.js
  • /data/data/####/room-fitment-style-list.html
  • /data/data/####/room-fitment-style-model.js
  • /data/data/####/room-fitment-style.scss
  • /data/data/####/room-huxing-model.js
  • /data/data/####/room-huxing.html
  • /data/data/####/room-list-controller.js
  • /data/data/####/room-list-model.js
  • /data/data/####/room-list-service.js
  • /data/data/####/room-list.html
  • /data/data/####/room-mark-position.html
  • /data/data/####/room-model.js
  • /data/data/####/room-operate-model.js
  • /data/data/####/room-problem-list.html
  • /data/data/####/room-process-model.js
  • /data/data/####/room-process-repository.js
  • /data/data/####/room-repository.js
  • /data/data/####/room-service.js
  • /data/data/####/room-type-repository.js
  • /data/data/####/room.html
  • /data/data/####/rotate.png
  • /data/data/####/router-name.js
  • /data/data/####/router.js
  • /data/data/####/rule.define.js
  • /data/data/####/rule.js
  • /data/data/####/rule.test.js
  • /data/data/####/run.pid
  • /data/data/####/satisfaction-repository.js
  • /data/data/####/search-before.png
  • /data/data/####/search-checkitem-controller.js
  • /data/data/####/search-checkitem.scss
  • /data/data/####/search-nodata.png
  • /data/data/####/security_info
  • /data/data/####/select-checkitem-controller.js
  • /data/data/####/select-contractor-controller.js
  • /data/data/####/select-desc-controller.js
  • /data/data/####/select-position-controller.js
  • /data/data/####/select-responsible-company-controller.js
  • /data/data/####/sendback-problem-controller.js
  • /data/data/####/sendback.png
  • /data/data/####/setting-controller.js
  • /data/data/####/setting-service.js
  • /data/data/####/setting.html
  • /data/data/####/setting.png
  • /data/data/####/shake-service.js
  • /data/data/####/shake.js
  • /data/data/####/share.svg
  • /data/data/####/simulate.png
  • /data/data/####/smile.png
  • /data/data/####/sorry.png
  • /data/data/####/special.png
  • /data/data/####/statusbar.js
  • /data/data/####/style.css
  • /data/data/####/style.scss
  • /data/data/####/style.scssc
  • /data/data/####/summary-directive.js
  • /data/data/####/summary-services.js
  • /data/data/####/summary.png
  • /data/data/####/summary2016.png
  • /data/data/####/swiper.jquery.min.js
  • /data/data/####/swiper.min.css
  • /data/data/####/swiper.min.js
  • /data/data/####/take-photo.png
  • /data/data/####/task-empty.png
  • /data/data/####/tdata_bca864
  • /data/data/####/tdata_bca864.jar
  • /data/data/####/tdata_fyR930
  • /data/data/####/tdata_fyR930.jar
  • /data/data/####/tel-close.png
  • /data/data/####/tempData.js
  • /data/data/####/tempData.keys.js
  • /data/data/####/timer.js
  • /data/data/####/timer.test.js
  • /data/data/####/tip-error.png
  • /data/data/####/tip-popup-view.html
  • /data/data/####/tip-popup-view.scss
  • /data/data/####/tip-succ.png
  • /data/data/####/tip-warn.png
  • /data/data/####/todo-batch-list-controller.js
  • /data/data/####/todo-batch-list.html
  • /data/data/####/todo-batch-room-list.scss
  • /data/data/####/todo-construction-select.scss
  • /data/data/####/todo-contractor-select-controller.js
  • /data/data/####/todo-contractor-select-model.js
  • /data/data/####/todo-contractor-select.html
  • /data/data/####/todo-dispatch-problem-controller.js
  • /data/data/####/todo-dispatch-problem-model.js
  • /data/data/####/todo-dispatch-problem.html
  • /data/data/####/todo-dispatch-repository.js
  • /data/data/####/todo-dispatch-service.js
  • /data/data/####/todo-list-controller.js
  • /data/data/####/todo-list-model.js
  • /data/data/####/todo-list-service.js
  • /data/data/####/todo-list.html
  • /data/data/####/todo-problem-list.scss
  • /data/data/####/todo-reinspect-problem-model.js
  • /data/data/####/todo-reinspect-problem.html
  • /data/data/####/todo-reinspect-problem.js
  • /data/data/####/todo-reinspect-repository.js
  • /data/data/####/todo-reinspect-room-model.js
  • /data/data/####/todo-reinspect-service.js
  • /data/data/####/todo-room-list-controller.js
  • /data/data/####/todo-room-list-model.js
  • /data/data/####/todo-room-list.html
  • /data/data/####/todo-room-service.js
  • /data/data/####/todo-sendback-problem-controller.js
  • /data/data/####/todo-sendback-problem-model.js
  • /data/data/####/todo-sendback-problem.html
  • /data/data/####/todo-sendback-repository.js
  • /data/data/####/todo-sendback-service.js
  • /data/data/####/todo.scss
  • /data/data/####/underscore-min.js
  • /data/data/####/underscore.string.min.js
  • /data/data/####/unit-list-service.js
  • /data/data/####/update-data-service.js
  • /data/data/####/update-icon.png
  • /data/data/####/update.png
  • /data/data/####/upgrade-detail-controller.js
  • /data/data/####/upgrade-detail.html
  • /data/data/####/upgrade-info-controller.js
  • /data/data/####/upgrade-info-model.js
  • /data/data/####/upgrade-info-service.js
  • /data/data/####/upgrade-info.html
  • /data/data/####/upgrade-popup-title.png
  • /data/data/####/upgrade-popup-view.html
  • /data/data/####/upgrade-service.js
  • /data/data/####/upgrade.scss
  • /data/data/####/upload-contractor-service.js
  • /data/data/####/upload-success.png
  • /data/data/####/url-format-filter.js
  • /data/data/####/user-info-controller.js
  • /data/data/####/user-info.html
  • /data/data/####/user-log-service.js
  • /data/data/####/user-repository.js
  • /data/data/####/user-service.js
  • /data/data/####/user.scss
  • /data/data/####/utils.js
  • /data/data/####/utils.scss
  • /data/data/####/utils.test.js
  • /data/data/####/variable.js
  • /data/data/####/version.json
  • /data/data/####/view-scroll-directive.js
  • /data/data/####/wait-upload.png
  • /data/data/####/webApi.js
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/wifi.png
  • /data/data/####/wx-share-service.js
  • /data/data/####/wx-share-view.html
  • /data/data/####/wx.png
  • /data/data/####/wx_pyq.png
  • /data/data/####/yf_yuanxiaojie_android.jpg
  • /data/media/####/.nomedia
  • /data/media/####/app.db
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.mysoft.mobilecheckroom.bin
  • /data/media/####/com.mysoft.mobilecheckroom.db
  • /data/media/####/tdata_bca864
  • /data/media/####/tdata_fyR930
  • /data/media/####/test.log
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/sh -c getprop
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.mysoft.plugin.getuipush.GTPushService 25672 300 0
  • cat /sys/class/net/wlan0/address
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.9.1.0.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • mount
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.mysoft.plugin.getuipush.GTPushService 25672 300 0
Loads the following dynamic libraries:
  • Bugly
  • RongIMLib
  • getuiext3
  • libnfix
  • libshella-2.9.1.0
  • libufix
  • nfix
  • sqliteX
  • ufix
  • weibosdkcore
Uses the following algorithms to encrypt data:
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about APN settings.
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android