マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Dangbei.4

Added to the Dr.Web virus database: 2019-01-12

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Dangbei.1.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) a####.b####.qq.com:8011
  • TCP(HTTP/1.1) a####.b####.qq.com:8012
  • TCP(HTTP/1.1) esw.ty####.com:80
  • TCP(HTTP/1.1) i####.doub####.com:80
  • TCP(HTTP/1.1) e####.ty####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) up####.dan####.net:80
  • TCP(HTTP/1.1) edan####.b0.a####.com:80
  • TCP(HTTP/1.1) pic.dan####.net:80
  • TCP(HTTP/1.1) es####.dan####.net:80
  • TCP(HTTP/1.1) img1-do####.b0.a####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) reso####.msg.xi####.net:80
  • TCP(HTTP/1.1) api.map.b####.com:80
  • TCP(HTTP/1.1) im####.b0.a####.com:80
  • TCP(HTTP/1.1) vod####.dan####.net.####.com:80
  • TCP(HTTP/1.1) ap####.t####.com:80
  • TCP(HTTP/1.1) hq####.dan####.com.####.com:80
  • TCP(SSL/3.0) s####.j####.cn:443
  • TCP(TLS/1.0) av1.x####.com:443
  • TCP(TLS/1.0) loc.map.b####.com:443
  • TCP(TLS/1.0) o####.map.b####.com:443
  • TCP(TLS/1.0) regi####.xm####.xi####.com:443
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) s####.j####.cn:443
  • TCP(TLS/1.0) e####.ty####.com:443
  • TCP 4####.62.94.2:443
  • TCP 1####.230.236.46:7005
  • UDP s.j####.cn:19000
  • TCP 47.74.1####.158:5222
DNS requests:
  • 254.16.246.####.arpa
  • a####.b####.qq.com
  • a####.u####.com
  • aexcep####.b####.qq.com
  • and####.b####.qq.com
  • ap####.t####.com
  • api.map.b####.com
  • av1.x####.com
  • dt.t####.com
  • e####.ty####.com
  • e####.ty####.com
  • es####.dan####.net
  • esw.ty####.com
  • hq####.dan####.com
  • i####.dan####.net
  • i####.doub####.com
  • i####.doub####.com
  • i.t####.com
  • im####.b0.upa####.com
  • im####.dan####.com
  • k####.d####.com
  • loc.map.b####.com
  • o####.map.b####.com
  • pic.dan####.net
  • regi####.xm####.xi####.com
  • reso####.msg.xi####.net
  • s####.j####.cn
  • s.j####.cn
  • sm.dan####.com
  • up####.dan####.net
  • up####.sdk.jig####.cn
  • vod####.dan####.net
HTTP GET requests:
  • ap####.t####.com/Admin/FastsouVEncrypt/getplayers/?isencry####&compact=#...
  • ap####.t####.com/admin/fastsouVEncrypt/getVodList/?isencry####&topId=e##...
  • ap####.t####.com/admin/fastsouVEncrypt/getVodList/?isencry####&vodId=Z##...
  • ap####.t####.com/fastsouauth/authconfig/?channel####&child=r####&compact...
  • ap####.t####.com/fsrecommend/pgrecommend/?channel####&child=r####&compac...
  • ap####.t####.com/v2/fastsou/config/?channel####&child=r####&compact=####...
  • ap####.t####.com/v2/fastsou/detail/?channel####&child=r####&compact=####...
  • ap####.t####.com/v2/fastsou/getplayers/?aid=04G####&channel####&child=r#...
  • ap####.t####.com/v2/fastsou/pagecomment/?aid=04G####&channel####&child=r...
  • ap####.t####.com/v2/fastsouhome/adRec?channel####&child=r####&compact=##...
  • ap####.t####.com/v2/fastsouhome/homerec/?channel####&child=r####&compact...
  • ap####.t####.com/v2/fastsouhome/homesvd/?channel####&child=r####&compact...
  • ap####.t####.com/v2/fastsouhome/hometop/?channel####&child=r####&compact...
  • ap####.t####.com/v2/fastsouhome/nav/?channel####&child=r####&compact=###...
  • ap####.t####.com/v2/fastsouhome/recout/?channel####&child=r####&compact=...
  • ap####.t####.com/v2/fastsoulive/hot/?isencry####&compact=####&time=IZ###...
  • ap####.t####.com/v2/fastsoulive/liverec/?isencry####&compact=####&vname=...
  • ap####.t####.com/v2/fastsoulive/timetable/?isencry####&time=IZ####&compa...
  • ap####.t####.com/v2/fastsoun/live/?isencry####&compact=####&vname=M####&...
  • ap####.t####.com/v2/fastsoun/pushrec/?channel####&child=r####&compact=##...
  • ap####.t####.com/v2/fastsoun/start?channel####&child=r####&compact=####&...
  • ap####.t####.com/v2/fastsoun/time/?channel####&child=r####&compact=####&...
  • ap####.t####.com/v2/fastsourec/childrenrec/?channel####&child=r####&comp...
  • ap####.t####.com/v2/fastsourec/childrentop/?channel####&child=r####&comp...
  • ap####.t####.com/v2/fastsourec/childrentype/?channel####&child=r####&com...
  • ap####.t####.com/v2/fastsourec/movierec/?channel####&child=r####&compact...
  • ap####.t####.com/v2/fastsourec/movietop/?channel####&child=r####&compact...
  • ap####.t####.com/v2/fastsourec/movietype/?channel####&child=r####&compac...
  • ap####.t####.com/v2/fastsourec/tvrec/?channel####&child=r####&compact=##...
  • ap####.t####.com/v2/fastsourec/tvtop/?channel####&child=r####&compact=##...
  • ap####.t####.com/v2/fastsourec/tvtype/?channel####&child=r####&compact=#...
  • ap####.t####.com/v2/fastsourec/varietyrec/?channel####&child=r####&compa...
  • ap####.t####.com/v2/fastsourec/varietytop/?channel####&child=r####&compa...
  • ap####.t####.com/v2/fastsourec/varietytype/?channel####&child=r####&comp...
  • api.map.b####.com/location/ip?ak=####&coor=####&output=####&mcode=####&v...
  • edan####.b0.a####.com/image/20190112/98852ed526b218024b7d34ea47839e0f.jpg
  • edan####.b0.a####.com/image/20190112/c00178fb7354fb9ecc89c2b279ea0f1a.jpg
  • esw.ty####.com/dbGold/v1/sdkSwitch.do?appkey=####&channel=####&device_na...
  • hq####.dan####.com.####.com/jietu/20190111/f5c387182770ec.jpg@style@h236
  • hq####.dan####.com.####.com/jietu/20190111/f5c38727095b37.jpg@style@h236
  • hq####.dan####.com.####.com/jietu/20190111/f5c38785f456ad.jpg@style@h236
  • hq####.dan####.com.####.com/jietu/20190111/f5c387ca4e0995.jpg@style@h236
  • hq####.dan####.com.####.com/jietu/20190111/f5c3880bc01582.jpg@style@h236
  • i####.doub####.com/icon/u141720657-2.jpg
  • i####.doub####.com/icon/u143558765-1.jpg
  • i####.doub####.com/icon/u1439016-510.jpg
  • i####.doub####.com/icon/u158220822-2.jpg
  • i####.doub####.com/icon/u160305541-4.jpg
  • i####.doub####.com/icon/u162064907-3.jpg
  • i####.doub####.com/icon/u166078747-1.jpg
  • i####.doub####.com/icon/u173057200-3.jpg
  • i####.doub####.com/icon/u179464857-3.jpg
  • i####.doub####.com/icon/u3763981-23.jpg
  • i####.doub####.com/icon/u47720455-10.jpg
  • i####.doub####.com/icon/u48609689-15.jpg
  • i####.doub####.com/icon/u49422504-21.jpg
  • i####.doub####.com/icon/u51255549-4.jpg
  • i####.doub####.com/icon/u79119266-6.jpg
  • i####.doub####.com/icon/u82880498-2.jpg
  • i####.doub####.com/icon/user_normal_f.jpg
  • im####.b0.a####.com/images/20001/00/202879.jpg!266350
  • im####.b0.a####.com/images/20001/01/143789.jpg!266350
  • im####.b0.a####.com/images/20001/09/96566.jpg!266350
  • im####.b0.a####.com/images/20001/21/984264.jpg!266370
  • im####.b0.a####.com/images/20001/22/499806.jpg!266370
  • im####.b0.a####.com/images/20001/28/985599.jpg!266370
  • im####.b0.a####.com/images/20001/29/971858.jpg!266350
  • im####.b0.a####.com/images/20001/30/984587.jpg!266370
  • im####.b0.a####.com/images/20001/39/966294.jpg!266350
  • im####.b0.a####.com/images/20001/5f/983263.jpg!266370
  • im####.b0.a####.com/images/20001/71/984680.jpg!266370
  • im####.b0.a####.com/images/20001/99/985674.jpg!266370
  • im####.b0.a####.com/images/20001/ad/983266.jpg!266370
  • im####.b0.a####.com/images/20001/cb/834896.jpg!266350
  • im####.b0.a####.com/images/20001/e8/985315.jpg!266370
  • im####.b0.a####.com/images/20001/ed/488864.jpg!266370
  • im####.b0.a####.com/images/20001/ff/966044.jpg!266350
  • im####.b0.a####.com/images/20180720/5b5156bd46006.jpg!266370
  • im####.b0.a####.com/images/20180820/5b7ab08bdc769.jpg!266370
  • im####.b0.a####.com/images/20180820/5b7ab08bdc769.jpg!410540
  • im####.b0.a####.com/images/20181031/5bd99115eff51.jpg!266370
  • im####.b0.a####.com/images/20181113/5bea60b954c52.jpg!266370
  • im####.b0.a####.com/images/yy/20181211/5c0f48ee87b12.jpg!266370
  • im####.b0.a####.com/images/yy/20181226/5c22e7630a10d.jpg!266370
  • im####.b0.a####.com/images/yy/20190103/5c2d6ac3421f5.jpg!266370
  • im####.b0.a####.com/images/yy/20190104/5c2ec1d4240cd.jpg!266370
  • im####.b0.a####.com/images/yy/20190107/5c32bba61791c.jpg!266370
  • im####.b0.a####.com/images/yy/20190111/5c37f504f0360.jpg!266370
  • im####.b0.a####.com/uploads/20180112/1515740148_8538264.png!998
  • im####.b0.a####.com/uploads/20180112/1515740198_1255761787.png!998
  • im####.b0.a####.com/uploads/20180112/1515740269_1934796326.png!998
  • im####.b0.a####.com/uploads/20180112/1515740283_1351860666.png!998
  • im####.b0.a####.com/uploads/20180112/1515740491_641815309.png!292299
  • im####.b0.a####.com/uploads/20180112/1515740551_268345993.png!292299
  • im####.b0.a####.com/uploads/20180112/1515740707_505855402.png!292299
  • im####.b0.a####.com/uploads/20180112/1515740790_1680420177.png!292299
  • im####.b0.a####.com/uploads/20180112/1515740821_1503499285.png!292299
  • im####.b0.a####.com/uploads/20180223/1519379679_1772549623.png!998
  • im####.b0.a####.com/uploads/20180517/1526538556_1228943630.png!998
  • im####.b0.a####.com/uploads/20180517/1526538568_1711093048.png!998
  • im####.b0.a####.com/uploads/20180517/1526538806_990574189.png!998
  • im####.b0.a####.com/uploads/20180517/1526538814_1900891873.png!998
  • im####.b0.a####.com/uploads/20180517/1526538822_696975391.png!998
  • im####.b0.a####.com/uploads/20180517/1526538831_656290901.png!998
  • im####.b0.a####.com/uploads/20180517/1526538967_1062257850.png!998
  • im####.b0.a####.com/uploads/20180517/1526538978_980467631.png!998
  • im####.b0.a####.com/uploads/20180517/1526539011_487640477.png!998
  • im####.b0.a####.com/uploads/20180517/1526539043_1012345386.png!998
  • im####.b0.a####.com/uploads/20180607/1528341363_587490114.png!292299
  • im####.b0.a####.com/uploads/20181012/1539335341_1562901760.png!998
  • im####.b0.a####.com/uploads/20181012/1539335435_975273668.png!998
  • im####.b0.a####.com/uploads/20181012/1539337578_193109591.png!998
  • im####.b0.a####.com/uploads/20181213/1544685088_621816741.jpg!0
  • im####.b0.a####.com/uploads/20181220/1545297038_116994010.jpg!0
  • im####.b0.a####.com/uploads/20181225/1545715159_311944715.png
  • im####.b0.a####.com/uploads/20181226/1545793731_904286197.jpg!264366
  • im####.b0.a####.com/uploads/20181226/1545818937_1421971316.jpg!0
  • im####.b0.a####.com/uploads/20181229/1546049896_1614404120.jpg!264366
  • im####.b0.a####.com/uploads/20190102/1546407470_1373979655.jpg!264366
  • im####.b0.a####.com/uploads/20190103/1546501623_2106105589.jpg!264366
  • im####.b0.a####.com/uploads/20190104/1546594982_24599060.jpg!684450
  • im####.b0.a####.com/uploads/20190104/1546595124_1494996309.jpg!0
  • im####.b0.a####.com/uploads/20190107/1546796717_1031505959.jpg!264366
  • im####.b0.a####.com/uploads/20190108/1546923765_1235027032.jpg!264366
  • im####.b0.a####.com/uploads/20190109/1546998611_19365929.jpg!264366
  • im####.b0.a####.com/uploads/20190109/1546998654_591573853.jpg!264366
  • im####.b0.a####.com/uploads/20190109/1547000786_765418949.jpg!264366
  • im####.b0.a####.com/uploads/20190110/1547083128_1385548902.jpg!724366
  • im####.b0.a####.com/uploads/20190110/1547083524_951606764.jpg!0
  • im####.b0.a####.com/uploads/20190110/1547085912_402483775.jpg!264366
  • im####.b0.a####.com/uploads/20190110/1547086624_1047700907.jpg!264366
  • im####.b0.a####.com/uploads/20190110/1547121664_1646842850.jpg!264366
  • im####.b0.a####.com/uploads/20190111/1547171675_984635711.jpg!0
  • im####.b0.a####.com/uploads/20190111/1547173134_593063757.jpg!724366
  • im####.b0.a####.com/uploads/20190111/1547173235_556793936.jpg!724366
  • im####.b0.a####.com/uploads/20190111/1547173514_1511582065.jpg!0
  • im####.b0.a####.com/uploads/20190111/1547173544_1595755260.jpg!0
  • im####.b0.a####.com/uploads/20190111/1547173615_2127414504.jpg!0
  • im####.b0.a####.com/uploads/20190111/1547174187_439639338.jpg!724366
  • im####.b0.a####.com/uploads/20190111/1547195672_1104169805.jpg!724366
  • im####.b0.a####.com/uploads/20190111/1547197003_1708920956.jpg!0
  • im####.b0.a####.com/uploads/20190112/1547256737_1726159285.jpg!0
  • img1-do####.b0.a####.com/icon/u63688511-18.jpg
  • img1-do####.b0.a####.com/icon/u78102063-19.jpg
  • img1-do####.b0.a####.com/icon/user_normal.jpg
  • img1-do####.b0.a####.com/malltemp/vouchers_1_1.png
  • img1-do####.b0.a####.com/malltemp/vouchers_2_2.png
  • img1-do####.b0.a####.com/malltemp/优酷-半年卡.png
  • img1-do####.b0.a####.com/malltemp/优酷-季卡.png
  • img1-do####.b0.a####.com/malltemp/优酷-年卡2.png
  • img1-do####.b0.a####.com/malltemp/优酷-月卡.png
  • img1-do####.b0.a####.com/malltemp/腾讯-季卡 (2).png
  • img1-do####.b0.a####.com/malltemp/腾讯-年卡.png
  • img1-do####.b0.a####.com/malltemp/腾讯-月卡.png
  • pic.dan####.net/uploads/new/160803/9-160P31F233360.png
  • pic.dan####.net/uploads/new/181128/9-1Q12QA42N96.png
  • pic.dan####.net/uploads/new/181212/9-1Q2121343395L.png
  • reso####.msg.xi####.net/gslb/?ver=4.0&type=wap&conpt=dvidpodv >>4>>4>>4...
  • up####.dan####.net/api/updatea?appkey=####&code=oh####&token=####&channe...
  • vod####.dan####.net.####.com/video/20190112/88d7816a372a6719fe4231c65ca6...
  • vod####.dan####.net.####.com/video/20190112/b09e6ccdaa8b248de07e640a85f9...
HTTP POST requests:
  • a####.b####.qq.com:8011/rqd/async
  • a####.b####.qq.com:8012/rqd/async
  • a####.u####.com/app_logs
  • and####.b####.qq.com/rqd/async
  • ap####.t####.com/fastsourealtime/pgrealinfo/
  • ap####.t####.com/v2/fastsoulive/top/
  • ap####.t####.com/v2/fastsourec/viewinc/
  • ap####.t####.com/v2/mall/index
  • ap####.t####.com/v2/mall/popvouchers
  • ap####.t####.com/v2/wx/login/
  • e####.ty####.com/dbGold/v1/deviceRegister.do
  • e####.ty####.com/dbGold/v1/liveReveal.do
  • es####.dan####.net/dbzs/m1/appInfo.do
  • es####.dan####.net/dbzs/m1/terminalInfo.do
  • esw.ty####.com/dbGold/v1/diskAuth.do
  • up####.dan####.net/page/viewrcds
File system changes:
Creates the following files:
  • /data/data/####/-3377459debug.db
  • /data/data/####/-3377459debug.db-journal
  • /data/data/####/.imprint
  • /data/data/####/061c8332c2a29b5ff8128dfa0b2734b93b910f18d0b171b....0.tmp
  • /data/data/####/06ae391334d5fff55efdc177b4d97fb9b9dd74990efbc42....0.tmp
  • /data/data/####/0c185e2ec0c430795e26aa2def4d96cd027a55b87dfce65....0.tmp
  • /data/data/####/118faff7ad85ff3ac409c21e0321a6790f696380bf688da....0.tmp
  • /data/data/####/1331f37f2f32b4007be44c5b1a072213.mp4
  • /data/data/####/1462e74e169787838d4b2f8bf6b5c9993d33434678a80f2....0.tmp
  • /data/data/####/15416ff27e01a926fb45898db6bc5b0756cb9a815f2795c....0.tmp
  • /data/data/####/1547306769667_2285
  • /data/data/####/1547306769737_2285
  • /data/data/####/1547306770083_2285
  • /data/data/####/1547306770353_2285
  • /data/data/####/1547306771736_2285
  • /data/data/####/1547306772663_2285
  • /data/data/####/1547306773727_2285
  • /data/data/####/1547306773839_2285
  • /data/data/####/1547306776023_2569
  • /data/data/####/1547306776412_2569
  • /data/data/####/1547306777176_2569
  • /data/data/####/1547306782566_2569
  • /data/data/####/1547306782580_2569
  • /data/data/####/1547306784684_2931
  • /data/data/####/1547306785416_2931
  • /data/data/####/1547306790357_2931
  • /data/data/####/1547306790447_2931
  • /data/data/####/1547306791009_2931
  • /data/data/####/1547306791857_2931
  • /data/data/####/1547306794920_2931
  • /data/data/####/1547306796767_2931
  • /data/data/####/1547306797379_2931
  • /data/data/####/1547306797990_2931
  • /data/data/####/1547306798384_2931
  • /data/data/####/1547306798401_2931
  • /data/data/####/1547306799552_2931
  • /data/data/####/1547306800645_2931
  • /data/data/####/1547306809891_2931
  • /data/data/####/1547306809925_2931
  • /data/data/####/1547306810012_2931
  • /data/data/####/1547306810306_2931
  • /data/data/####/1547306814019_2931
  • /data/data/####/1547306814141_2931
  • /data/data/####/1547306814295_2931
  • /data/data/####/1547306814319_2931
  • /data/data/####/1547306814644_2931
  • /data/data/####/1547306817315_2931
  • /data/data/####/1547306841980_2845
  • /data/data/####/16381f4759bf946e1bc8e5dcfbd4964911441fe5541aae3....0.tmp
  • /data/data/####/16d2b6e79507037f09f2251d15286aafeab88377e67d9a5....0.tmp
  • /data/data/####/1a246b5596330a567ef696a5d500c87a8241b117420fc1c....0.tmp
  • /data/data/####/1bd9b096b0b15126bf354b2e579e695eae10ae50ff5c8cc....0.tmp
  • /data/data/####/1c196877d94995f9d655f7010d9ca83ba426e4392601976....0.tmp
  • /data/data/####/1d7503606c3d3050f9ea8ac1e4ef0635f010cf5975812f1....0.tmp
  • /data/data/####/21995dc3343563d382c5d665bc572579be4b0cb58393e56....0.tmp
  • /data/data/####/227a3ba58b98c3eddfe7d7bba2ca122594d172d34b453fe....0.tmp
  • /data/data/####/22db594e2b273bad89f83ea4034f324fa963b8424ffe6ab....0.tmp
  • /data/data/####/24d057e38958caf838f86c96dbf3da4609eff2ffce39ebf....0.tmp
  • /data/data/####/2751aa4fa96c1e49999f47bbcf28cf774e10a2b9839a21e....0.tmp
  • /data/data/####/2786430eecd97bdad5aad8629b384874a78ffaebbc9b09e....0.tmp
  • /data/data/####/289aa9ed0832518abef6be0e330dfaac85405bae6d220e5....0.tmp
  • /data/data/####/2aa9da16583f9071fd289aad75681bb7c2ffe58709aefcd....0.tmp
  • /data/data/####/2dac7b50dca601b58c96978abefd9b03293e5167db67be7....0.tmp
  • /data/data/####/319aeecb94d4e722bf221051605145891acdb476376d1fc....0.tmp
  • /data/data/####/33ec5f6113fe4de7a9df395780032124e2aa31ea01145cd....0.tmp
  • /data/data/####/33f8ac0a7380fca5badf30d4582a081bdb4ffcd4f995fac....0.tmp
  • /data/data/####/35c3bc5d483bb6858e902e77e151a6f7216ef61c75d78fa....0.tmp
  • /data/data/####/38f0b7ebb049dd40a72d2f1b088437fc88d5d0ea972804d....0.tmp
  • /data/data/####/3d9ab758e4a26478b526dffabcd1be01aa7a4875a12c95c....0.tmp
  • /data/data/####/40202f109edaf984a23f0a0624f091decf63b9a8d355471....0.tmp
  • /data/data/####/419a56c0ca5e9a1d69cef9ac367e72623b48df144e58428....0.tmp
  • /data/data/####/42cb78e35a823a4b3504d8c3becd2448f0124c0ac36b928....0.tmp
  • /data/data/####/43da5177f9495663fbf4253a50e7d196e2f330a2c98fd4a....0.tmp
  • /data/data/####/44491b355fab1c4b85f583443dd1a5d53c556ffff245ee4....0.tmp
  • /data/data/####/47e1fce5da3aa8fcd71dd26fa49feafa2eeaee754cbf85f....0.tmp
  • /data/data/####/4a4dc87b8bb31e2ef139f73513fb87e35945e783bd927e3....0.tmp
  • /data/data/####/533acef2840cc3ea8b8f94bea7a9968e1e497a14f5d493e....0.tmp
  • /data/data/####/53470fdaeb13daa9555e2071248aa0c38cb853b3b24230f....0.tmp
  • /data/data/####/540f3a7d10c2f1cb757b3715774a2d83aead5ea15609c75....0.tmp
  • /data/data/####/543424ec13cbaa8b1067c639d6d5584ae448f76f944d1a4....0.tmp
  • /data/data/####/5727434b65b7b4c9a2ceb2d116aa89a584e5879e2c76b14....0.tmp
  • /data/data/####/577b52833bd226aa6d8ddec8e726833efa03a21f289212e....0.tmp
  • /data/data/####/5abcce169ef0cec09f2dfd2cd7548e82bce5991f385b3fa....0.tmp
  • /data/data/####/5b49a283a7feba79e959e5ad4565a3e83e57627340101cb....0.tmp
  • /data/data/####/5b69ebb67bd261df9c0d1984d023ea5b628d789682ed201....0.tmp
  • /data/data/####/5c9703ed5a9bda4cf201d71ce73a35312dd17901a805604....0.tmp
  • /data/data/####/68d1e91ccfcd0cb76ab8b03d5112ccc8dd84e14d7ed5a5f....0.tmp
  • /data/data/####/6d6c54e96dd590f69d4639edc435a9c8d5f564230634557....0.tmp
  • /data/data/####/6de5b09d66f23d346dc2e3f49ec1c14a.mp4
  • /data/data/####/6f28cb61ac1a01c33a18d7ea965c7eabd6bd1e251ce7319....0.tmp
  • /data/data/####/7035a611663c11233a06649be1cbb9a7b1e121d9434efe5....0.tmp
  • /data/data/####/7108c4c52f19aef35bb6834f35064101b5aa43178260151....0.tmp
  • /data/data/####/71d14a0ff487f6003169eaf2b5d9d9eb3d1bd1722557565....0.tmp
  • /data/data/####/74137f048018e5eb3e2d042519d53891cc9f543c689f97a....0.tmp
  • /data/data/####/743cb7afb298bbf8e840f0d9762cdb5a7194a85a3709c96....0.tmp
  • /data/data/####/7546e19c77fee57b3e2b9ce6d48e59374b51568c878a607....0.tmp
  • /data/data/####/761f352200d96ebbad8c67b4dc8a4e24a9044b8838978c3....0.tmp
  • /data/data/####/78d1281a5437c83cf2a3d2d17ca9361ed3b6f44483215ce....0.tmp
  • /data/data/####/7911f07de84c97679423e2ee86aa9180e78ff0e4a1403f5....0.tmp
  • /data/data/####/816251c73bac89706efb5545a7492743a03342341acd5e9....0.tmp
  • /data/data/####/81829339ba61aff8963ce1432aeea17a749d90526a561e8....0.tmp
  • /data/data/####/81b0f04e1285c2a382b9d968b9fe63cdd844c7277c799eb....0.tmp
  • /data/data/####/88bb6b99d45c82715491f23a81969e48705e70177261469....0.tmp
  • /data/data/####/8e2243dd64404c603ffbb524c61dbaa1418b9b6fdca4096....0.tmp
  • /data/data/####/8f8b52b0f340af30f99c16d255386c19ae3f95068c435c6....0.tmp
  • /data/data/####/9149e9e2e1663f5ffd8869d70894db8da8b3dd751693acc....0.tmp
  • /data/data/####/9254a54011eedd71dcaec3313321c3c7556035c131acda3....0.tmp
  • /data/data/####/92c42799d3284dc4146d1537e58449daef086b3682a8d34....0.tmp
  • /data/data/####/9376afc4d3d916c8079596e13ec3ce066c87b16ba847ec8....0.tmp
  • /data/data/####/97b7073b5d3cd0f97df37e0940150de64f5cbccc961268a....0.tmp
  • /data/data/####/9b477ee7cf38f19d21928b424bcb5d68e554b409425b241....0.tmp
  • /data/data/####/9eda23e56f81e9cb7a7e1f506afed0de303145f552b3141....0.tmp
  • /data/data/####/9fe44683d1e54f5017e3117d19698d93844d2521859db9c....0.tmp
  • /data/data/####/Alvin2.xml
  • /data/data/####/AntiCheatingLock
  • /data/data/####/ContextData.xml
  • /data/data/####/JPushSA_Config.xml
  • /data/data/####/Lock0
  • /data/data/####/Lock2
  • /data/data/####/Lock7
  • /data/data/####/MessageStore.db
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/MultiDex.lock
  • /data/data/####/TD_app_pefercen_profile.xml
  • /data/data/####/TDpref_longtime.xml
  • /data/data/####/TDpref_longtime0.xml
  • /data/data/####/TDpref_shorttime.xml
  • /data/data/####/TDpref_shorttime0.xml
  • /data/data/####/XMPushServiceConfig.xml
  • /data/data/####/a0b88001c9a691163f78ded9af12bf2c479fe1468aa2d87....0.tmp
  • /data/data/####/a0d2ecca6fa84e50d0ea22f6abe8977590416234b49a4fc....0.tmp
  • /data/data/####/a29ac36e709cc7c29dce9cca68de97b926fc1da10035622....0.tmp
  • /data/data/####/a5b858126fd80207999ca9e8d67b3859b4fd757966616ba....0.tmp
  • /data/data/####/a6c2128dd3f96f93ceec1940cd2091e2e4c0b98c9002ef1....0.tmp
  • /data/data/####/a6eb380c085f63d20b7e1741137d7429941283493783cf1....0.tmp
  • /data/data/####/a735167a10db672b48a2a51d816992921159a7203ec468f....0.tmp
  • /data/data/####/a7e95703f085460b4ad32c3511f46a2fce3d7fd4de193d1....0.tmp
  • /data/data/####/ab134dc69fb2d6e7fc726028e41be1a4bb274e5d7929c6f....0.tmp
  • /data/data/####/appPackageNames
  • /data/data/####/authStatus_com.tv.kuaisou;remote.xml
  • /data/data/####/b179fd845ac8945d465ee39eeae35458aed664e3c6952e2....0.tmp
  • /data/data/####/b49d666e3082187bd9a18a413dc6250ae6b9940d620c92e....0.tmp
  • /data/data/####/b4f11f7f93f983c43abd487dc2a67eb12380ca3e8eb37f1....0.tmp
  • /data/data/####/b64250ac82d7857281eeba57a589da3f1f2dbe9e87f6c74....0.tmp
  • /data/data/####/ba17c1b3d19c1b308bf634831b1dc13822e24a8adf1eaf2....0.tmp
  • /data/data/####/ba9646d00ef3c830b4171f53b278aa02e0eb45aca05b9ec....0.tmp
  • /data/data/####/baaacf32f6c50d971c477ebf0f94092105f0888853c24d1....0.tmp
  • /data/data/####/befad38ce489b599c21764cfbd84defed55447f33e85652....0.tmp
  • /data/data/####/bf5b5b47087a4f792a4b438c203a864f70b7f991e871b04....0.tmp
  • /data/data/####/bf7628b9a488c536210a80a8d2c0a64dae2fd4f68185843....0.tmp
  • /data/data/####/bugly_db_legu
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/c022d72d8c9466ac87b3a191f8cc685442e7acaee61d115....0.tmp
  • /data/data/####/c1f3c4af6e12e5160d4de6f9a4e789af082a54313733e96....0.tmp
  • /data/data/####/c20d1bfda5338b5b67b0e206d9b8d1d578d1bae0c385166....0.tmp
  • /data/data/####/c3903028541062b48ed173ad955cce03b22e8578d1f5ea9....0.tmp
  • /data/data/####/c5f1efa6d0e9b319a9940445b4d2bc0af2eb050198de97e....0.tmp
  • /data/data/####/cacbaf066eaa073f76b4d5722ffa66bc985e4cdfbd5b637....0.tmp
  • /data/data/####/cbf64462777781971d94ae6feb7bfc6547d2e545963f021....0.tmp
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cd7cc721349527edea1c27317e81b79ee72c57b14a3027a....0.tmp
  • /data/data/####/cn.jpush.android.user.profile.xml
  • /data/data/####/cn.jpush.preferences.v2.rid.xml
  • /data/data/####/cn.jpush.preferences.v2.xml
  • /data/data/####/cn.jpush.preferences.v2.xml (deleted)
  • /data/data/####/com.tv.kuaisou;xmpushservice
  • /data/data/####/com.tv.kuaisou_preferences.xml
  • /data/data/####/config.xml
  • /data/data/####/d2003895d44cda27c2365f10abd47cada484675da843b01....0.tmp
  • /data/data/####/d36420f7273cb13644a3bc34a7078bb8fa7236394634c5b....0.tmp
  • /data/data/####/d4d3e93e97a0a9476c82d3a995eb50c862cda5e079df438....0.tmp
  • /data/data/####/d5ba3327bb285d1c41f6e6efc0f3aaa94a3faa789fa49ce....0.tmp
  • /data/data/####/d6c1651d39f7b92d2b54ed05d767f4f3d77d6669fedfcda....0.tmp
  • /data/data/####/d787696e7cc62350fdeb0c9102e6fc94ae27aa43a7c4f29....0.tmp
  • /data/data/####/dangbei_market_global_prefs.xml
  • /data/data/####/dbfile.xml
  • /data/data/####/dce7f3797f406a9949316e8f079864c5a08df9e0446bd5f....0.tmp
  • /data/data/####/ddbf00e650dbcc8b18a328d6cb6f96f522b42e8ce09cad5....0.tmp
  • /data/data/####/e0e9893526c0b550091ddbc11d02a92915763e0e1aa8679....0.tmp
  • /data/data/####/ea62405d8780011da075311e2a40b4eb58c31c032dbb185....0.tmp
  • /data/data/####/ee4627df66fd1b7af9f300de2cf1ea2a6070ec9b2fd6e7a....0.tmp
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f15349471ce2d178f9a5d4c7637f1f25a2bfc139193bdb4....0.tmp
  • /data/data/####/f86f45338e9446775a29eb0a76a9428be452986a97c3eac....0.tmp
  • /data/data/####/f958e5bf317565c2ca8816ff3800eae37da7b9efc8d3c86....0.tmp
  • /data/data/####/fbb4da063b6dbf99854bd5a271dba9622313e40ca0ebacd....0.tmp
  • /data/data/####/ffe5ddfee605fabe99c8c380a4c83ef02222ba666b6d811....0.tmp
  • /data/data/####/firll.dat
  • /data/data/####/gal.db
  • /data/data/####/gal.db-journal
  • /data/data/####/geofencing.db
  • /data/data/####/geofencing.db-journal
  • /data/data/####/hst.db
  • /data/data/####/hst.db-journal
  • /data/data/####/journal.tmp
  • /data/data/####/jpush_local_notification.db
  • /data/data/####/jpush_local_notification.db-journal
  • /data/data/####/jpush_local_notification.db-wal
  • /data/data/####/jpush_stat_cache.json
  • /data/data/####/jpush_stat_cache_history.json
  • /data/data/####/jpush_statistics.db
  • /data/data/####/jpush_statistics.db-journal
  • /data/data/####/jpush_statistics.db-shm (deleted)
  • /data/data/####/jpush_statistics.db-wal
  • /data/data/####/jpush_uncaughtexception_file
  • /data/data/####/ksdevice_id.xml.xml
  • /data/data/####/kuaisou_downloader-journal
  • /data/data/####/libcuid.so
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.9.0.2.so
  • /data/data/####/libufix.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mipush.xml
  • /data/data/####/mipush_account.xml
  • /data/data/####/mipush_extra.xml
  • /data/data/####/mix.dex
  • /data/data/####/mix.so
  • /data/data/####/multidex.version.xml
  • /data/data/####/native_record_lock
  • /data/data/####/ofl.config
  • /data/data/####/ofl_location.db
  • /data/data/####/ofl_location.db-journal
  • /data/data/####/ofl_statistics.db
  • /data/data/####/ofl_statistics.db-journal
  • /data/data/####/player_visit_record.db-journal
  • /data/data/####/pref_registered_pkg_names.xml
  • /data/data/####/security_info
  • /data/data/####/set.xml
  • /data/data/####/tdid.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/media/####/.D1C593128F43E2D009A968D7C663F774
  • /data/media/####/.D1C593128F43E2D009A968D7C663F774-journal
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.nomedia
  • /data/media/####/.probe
  • /data/media/####/.push_deviceid
  • /data/media/####/.tcookieid
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/afinalCache.0
  • /data/media/####/afinalCache.1
  • /data/media/####/afinalCache.idx
  • /data/media/####/conlts.dat
  • /data/media/####/ls.db
  • /data/media/####/ls.db-journal
  • /data/media/####/temp
  • /data/media/####/yoh.dat
  • /data/media/####/yol.dat
  • /data/media/####/yom.dat
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • cat /proc/meminfo
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • chmod 777 /storage/emulated/0/Android/data/<Package>/cache/afinalCache
  • chmod 777 <Package Folder>/cache/video
  • getprop
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • ping -c 1 -w 2 update.dangbei.net
Loads the following dynamic libraries:
  • Bugly
  • euthenia-lib
  • jcore117
  • libnfix
  • libshella-2.9.0.2
  • libufix
  • locSDK7a
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-NoPadding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android