マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.10397

Added to the Dr.Web virus database: 2019-03-17

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.3.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) ser####.dc####.net.cn:80
  • TCP(HTTP/1.1) ti####.c####.l####.####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
  • TCP(HTTP/1.1) wq.nd####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) api.map.b####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) ser####.dc####.net.cn:443
  • TCP sdk.o####.t####.####.com:5224
  • TCP c####.g####.ig####.com:5227
DNS requests:
  • a####.b####.qq.com
  • aexcep####.b####.qq.com
  • and####.b####.qq.com
  • api.map.b####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • s####.nd####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • ser####.dc####.net.cn
  • st####.dc####.net.cn
  • wq.nd####.com
HTTP GET requests:
  • api.map.b####.com/?qt=####&ak=####&callback=####
  • api.map.b####.com/getscript?v=####&ak=####
  • api.map.b####.com/images/blank.gif?product=####&sub_product=####&v=####&...
  • ti####.c####.l####.####.com/config/hz-hzv3.conf
  • wq.nd####.com/app.php?c=####&a=####&city_name=####
HTTP POST requests:
  • aexcep####.b####.qq.com:8011/rqd/async
  • aexcep####.b####.qq.com:8012/rqd/async
  • and####.b####.qq.com/rqd/async
  • c-h####.g####.com/api.php?format=####&t=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • ser####.dc####.net.cn/device/location
  • wq.nd####.com/app.php?c=####&a=####
  • wq.nd####.com/news/index/hotkeywrod
File system changes:
Creates the following files:
  • /data/data/####/.imei.txt
  • /data/data/####/H51752B1C.xml
  • /data/data/####/README.md
  • /data/data/####/_adio.dcloud.feature.ad.a.a.xml
  • /data/data/####/add-bank-icon.png
  • /data/data/####/add-num.png
  • /data/data/####/add1.png
  • /data/data/####/addImg.png
  • /data/data/####/add_concern.png
  • /data/data/####/add_concern1.png
  • /data/data/####/address-active.png
  • /data/data/####/address.png
  • /data/data/####/address_icon.png
  • /data/data/####/adverse-rent.png
  • /data/data/####/advertise-icon.png
  • /data/data/####/agreement.css
  • /data/data/####/agreement.html
  • /data/data/####/agreement.js
  • /data/data/####/ajax.js
  • /data/data/####/ali_icon.png
  • /data/data/####/aliiconfont.ttf
  • /data/data/####/apply-checkedFailed.html
  • /data/data/####/apply-checkedFailed.js
  • /data/data/####/apply-checkedSuc.html
  • /data/data/####/apply-checkedSuc.js
  • /data/data/####/apply-checking.css
  • /data/data/####/apply-checking.html
  • /data/data/####/apply-org.js
  • /data/data/####/apply-organization.css
  • /data/data/####/apply-organization.html
  • /data/data/####/apply-personal.css
  • /data/data/####/apply-personal.html
  • /data/data/####/apply-personal.js
  • /data/data/####/article-jubao.css
  • /data/data/####/article-jubao.html
  • /data/data/####/article-jubao.js
  • /data/data/####/article-news.css
  • /data/data/####/article-news.html
  • /data/data/####/article-news.js
  • /data/data/####/article_collect.png
  • /data/data/####/article_like1.png
  • /data/data/####/article_like2.png
  • /data/data/####/article_qq.png
  • /data/data/####/article_transfer.png
  • /data/data/####/article_wx.png
  • /data/data/####/article_wxfriend.png
  • /data/data/####/authStatus_com.nongduoshou.nds.xml
  • /data/data/####/author1.png
  • /data/data/####/author2.png
  • /data/data/####/author_icon.png
  • /data/data/####/bank-icon.png
  • /data/data/####/beMerchant_icon.png
  • /data/data/####/bind-phone.css
  • /data/data/####/bind-phone.js
  • /data/data/####/bottom_arrow.png
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/card_icon.png
  • /data/data/####/checked_failed.png
  • /data/data/####/chongzhi.png
  • /data/data/####/choose-agreement.png
  • /data/data/####/choose.png
  • /data/data/####/choose_active.png
  • /data/data/####/city.data-3.js
  • /data/data/####/classify-icon.png
  • /data/data/####/clientid_igexin.xml
  • /data/data/####/close-goods-type.png
  • /data/data/####/collect_grey.png
  • /data/data/####/collect_icon.png
  • /data/data/####/comment.png
  • /data/data/####/comment_icon.png
  • /data/data/####/common-fontSize.js
  • /data/data/####/common.js
  • /data/data/####/daifahuo.png
  • /data/data/####/daifukuan.png
  • /data/data/####/daipingjia.png
  • /data/data/####/daishouhuo.png
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dc_ad_type_key.xml
  • /data/data/####/delete-comment-icon.png
  • /data/data/####/delete_img.png
  • /data/data/####/delete_search_history.png
  • /data/data/####/dianpu.png
  • /data/data/####/dingdan.png
  • /data/data/####/distance.js
  • /data/data/####/eje3cnc
  • /data/data/####/ewm.png
  • /data/data/####/ewm_bg1.png
  • /data/data/####/ewm_bg2.png
  • /data/data/####/ewm_default.png
  • /data/data/####/f_000001
  • /data/data/####/fenxiao.png
  • /data/data/####/format.js
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getBank.js
  • /data/data/####/getui_sp.xml
  • /data/data/####/goods-details-transfer.png
  • /data/data/####/goods-detrails-back.png
  • /data/data/####/gouwuche.png
  • /data/data/####/guide.css
  • /data/data/####/guide.html
  • /data/data/####/guide1.png
  • /data/data/####/guide2.png
  • /data/data/####/guide3.png
  • /data/data/####/gx_sp.xml
  • /data/data/####/had_concerned.png
  • /data/data/####/has_collected.png
  • /data/data/####/history_icon.png
  • /data/data/####/home-article-reply.css
  • /data/data/####/home-article-reply.html
  • /data/data/####/home-article-reply.js
  • /data/data/####/home-article-replyComment.html
  • /data/data/####/home-article-replyComment.js
  • /data/data/####/home-articleDetails.css
  • /data/data/####/home-articleDetails.html
  • /data/data/####/home-articleDetails.js
  • /data/data/####/home-articleDetails_sub.css
  • /data/data/####/home-main.css
  • /data/data/####/home-main.html
  • /data/data/####/home-main.js
  • /data/data/####/home-scanner.css
  • /data/data/####/home-search-result.css
  • /data/data/####/home-search-result.html
  • /data/data/####/home-search-result.js
  • /data/data/####/home-search.css
  • /data/data/####/home-search.html
  • /data/data/####/home-search.js
  • /data/data/####/home-selectCity.css
  • /data/data/####/home-selectCity.html
  • /data/data/####/home.png
  • /data/data/####/home_active.png
  • /data/data/####/html5Geo.xml
  • /data/data/####/icon_search.png
  • /data/data/####/iconfont.css
  • /data/data/####/iconfont.ttf
  • /data/data/####/index
  • /data/data/####/index-no-content.png
  • /data/data/####/index.css
  • /data/data/####/index.html
  • /data/data/####/index.js
  • /data/data/####/info-news.png
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/invite-details-icon.png
  • /data/data/####/jquery.min.js
  • /data/data/####/jubao.png
  • /data/data/####/kaquan-list-bg.png
  • /data/data/####/kaquan.png
  • /data/data/####/kefu_gery.png
  • /data/data/####/keyboard-icon.png
  • /data/data/####/keyword_icon.png
  • /data/data/####/kuadi_address.png
  • /data/data/####/kuaidi_addInfo.png
  • /data/data/####/kw-and-advertise.js
  • /data/data/####/lazy.png
  • /data/data/####/lazyload.min.js
  • /data/data/####/libcuid.so
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-3.0.0.0.so
  • /data/data/####/libufix.so
  • /data/data/####/like.png
  • /data/data/####/like_active.png
  • /data/data/####/list-common.css
  • /data/data/####/loading.gif
  • /data/data/####/local_crash_lock
  • /data/data/####/location-failed.png
  • /data/data/####/location.png
  • /data/data/####/location_active.png
  • /data/data/####/login.css
  • /data/data/####/login.html
  • /data/data/####/login.js
  • /data/data/####/logo.png
  • /data/data/####/mall-advertise-buy.html
  • /data/data/####/mall-advertise-buy.js
  • /data/data/####/mall-advertise-goodsList.html
  • /data/data/####/mall-advertise-goodsList.js
  • /data/data/####/mall-advertise-paySuccessful.html
  • /data/data/####/mall-advertise-paySuccessful.js
  • /data/data/####/mall-advertise-storeList.html
  • /data/data/####/mall-advertise-storeList.js
  • /data/data/####/mall-confirmOrder.css
  • /data/data/####/mall-confirmOrder.html
  • /data/data/####/mall-confirmOrder.js
  • /data/data/####/mall-goods-details.css
  • /data/data/####/mall-goods-details.html
  • /data/data/####/mall-goods-orderCommon.css
  • /data/data/####/mall-join-pintuan.html
  • /data/data/####/mall-join-pintuan.js
  • /data/data/####/mall-keyword-buy.css
  • /data/data/####/mall-keyword-buy.html
  • /data/data/####/mall-keyword-buy.js
  • /data/data/####/mall-keyword-goodsList.css
  • /data/data/####/mall-keyword-goodsList.html
  • /data/data/####/mall-keyword-goodsList.js
  • /data/data/####/mall-keyword-paySuccessful.html
  • /data/data/####/mall-keyword-paySuccessful.js
  • /data/data/####/mall-keyword-storeList.css
  • /data/data/####/mall-keyword-storeList.html
  • /data/data/####/mall-keyword-storeList.js
  • /data/data/####/mall-merchant-entry-common.js
  • /data/data/####/mall-merchantChecked.html
  • /data/data/####/mall-merchantChecked.js
  • /data/data/####/mall-merchantEntrySucceed.js
  • /data/data/####/mall-merchantEntry_1.js
  • /data/data/####/mall-merchantEntry_2.js
  • /data/data/####/mall-merchantEntry_3.js
  • /data/data/####/mall-merchantEntry_4.js
  • /data/data/####/mall-merchantFailed.html
  • /data/data/####/mall-merchantFailed.js
  • /data/data/####/mall-merchantSuccessful.html
  • /data/data/####/mall-my-addAddress.css
  • /data/data/####/mall-my-addAddress.html
  • /data/data/####/mall-my-addAddress.js
  • /data/data/####/mall-my-address.css
  • /data/data/####/mall-my-address.html
  • /data/data/####/mall-my-address.js
  • /data/data/####/mall-my-adverList.css
  • /data/data/####/mall-my-advertiseList.html
  • /data/data/####/mall-my-advertiseList.js
  • /data/data/####/mall-my-bankCardList.html
  • /data/data/####/mall-my-bankCardList.js
  • /data/data/####/mall-my-bankCradList.css
  • /data/data/####/mall-my-bindBankCard.css
  • /data/data/####/mall-my-bindBankCard.html
  • /data/data/####/mall-my-bindBankCard.js
  • /data/data/####/mall-my-ewm.html
  • /data/data/####/mall-my-ewm.js
  • /data/data/####/mall-my-fenxiao-details.css
  • /data/data/####/mall-my-fenxiao-withdraw.html
  • /data/data/####/mall-my-fenxiao-withdraw.js
  • /data/data/####/mall-my-fenxiaoManage.css
  • /data/data/####/mall-my-fenxiaoManage.html
  • /data/data/####/mall-my-fenxiaoManage.js
  • /data/data/####/mall-my-goodsCollection.css
  • /data/data/####/mall-my-goodsCollection.html
  • /data/data/####/mall-my-goodsCollection.js
  • /data/data/####/mall-my-inviteDetails.css
  • /data/data/####/mall-my-inviteDetails.html
  • /data/data/####/mall-my-inviteDetails.js
  • /data/data/####/mall-my-kaquan.css
  • /data/data/####/mall-my-kaquan.html
  • /data/data/####/mall-my-keywordList.css
  • /data/data/####/mall-my-keywordList.html
  • /data/data/####/mall-my-keywordList.js
  • /data/data/####/mall-my-order-search.html
  • /data/data/####/mall-my-order-search.js
  • /data/data/####/mall-my-order-searchResult.html
  • /data/data/####/mall-my-order-searchResult.js
  • /data/data/####/mall-my-order.css
  • /data/data/####/mall-my-order.html
  • /data/data/####/mall-my-order.js
  • /data/data/####/mall-my-orderDetails.html
  • /data/data/####/mall-my-orderDetails.js
  • /data/data/####/mall-my-orderEvaluate.html
  • /data/data/####/mall-my-orderEvaluate.js
  • /data/data/####/mall-my-orderEvaluateSuccessed.html
  • /data/data/####/mall-my-orderEvaluateSuccessed.js
  • /data/data/####/mall-my-pinOrder-search.html
  • /data/data/####/mall-my-pinOrder-search.js
  • /data/data/####/mall-my-pinOrder-searchResult.html
  • /data/data/####/mall-my-pinOrder-searchResult.js
  • /data/data/####/mall-my-pinOrder.css
  • /data/data/####/mall-my-pinOrder.html
  • /data/data/####/mall-my-pinOrder.js
  • /data/data/####/mall-my-pintuanDetails.css
  • /data/data/####/mall-my-pintuanDetails.html
  • /data/data/####/mall-my-pintuanDetails.js
  • /data/data/####/mall-my-shoppingcar.css
  • /data/data/####/mall-my-shoppingcar.html
  • /data/data/####/mall-my-shoppingcar.js
  • /data/data/####/mall-my-shouhouApplySuccessful.css
  • /data/data/####/mall-my-spreadEwm.css
  • /data/data/####/mall-my-spreadOrder.css
  • /data/data/####/mall-my-spreadOrder.html
  • /data/data/####/mall-my-spreadOrder.js
  • /data/data/####/mall-my-storeCollection.css
  • /data/data/####/mall-my-storeCollection.html
  • /data/data/####/mall-my-storeCollection.js
  • /data/data/####/mall-my-tuiguang.css
  • /data/data/####/mall-my-tuiguang.html
  • /data/data/####/mall-my-tuiguang.js
  • /data/data/####/mall-my-tuikuan.css
  • /data/data/####/mall-my-tuikuanApply.css
  • /data/data/####/mall-my-tuikuanApply.html
  • /data/data/####/mall-my-tuikuanApply.js
  • /data/data/####/mall-my-tuikuanApplySuccessful.html
  • /data/data/####/mall-my-tuikuanApplySuccessful.js
  • /data/data/####/mall-my-tuikuanDetails.css
  • /data/data/####/mall-my-tuikuanDetails.html
  • /data/data/####/mall-my-tuikuanDetails.js
  • /data/data/####/mall-my-tuikuanList.html
  • /data/data/####/mall-my-tuikuanList.js
  • /data/data/####/mall-my-visitHistory.css
  • /data/data/####/mall-my-visitHistory.html
  • /data/data/####/mall-my-visitHistory.js
  • /data/data/####/mall-my-wallet-details.css
  • /data/data/####/mall-my-wallet-details.html
  • /data/data/####/mall-my-wallet-details.js
  • /data/data/####/mall-my-wallet-recharge.css
  • /data/data/####/mall-my-wallet-recharge.html
  • /data/data/####/mall-my-wallet-spread.css
  • /data/data/####/mall-my-wallet-spreadPrize.html
  • /data/data/####/mall-my-wallet-spreadPrize.js
  • /data/data/####/mall-my-wallet-withdraw.html
  • /data/data/####/mall-my-wallet-withdrawDetails.css
  • /data/data/####/mall-my-wallet-withdrawDetails.html
  • /data/data/####/mall-my-wallet-withdrawDetails.js
  • /data/data/####/mall-my-wallet.css
  • /data/data/####/mall-my-wallet.html
  • /data/data/####/mall-my-wallet.js
  • /data/data/####/mall-myCenter-bg.jpg
  • /data/data/####/mall-myCenter.css
  • /data/data/####/mall-news.png
  • /data/data/####/mall-order-operate.js
  • /data/data/####/mall-pintuan-successful.html
  • /data/data/####/mall-pintuan-successful.js
  • /data/data/####/mall-pintuanGoods-details.css
  • /data/data/####/mall-pintuanGoods-details.html
  • /data/data/####/mall-pintuaning-list.html
  • /data/data/####/mall-pintuaning-list.js
  • /data/data/####/mall-singleBuy-successful.html
  • /data/data/####/mall-singleBuy-successful.js
  • /data/data/####/mall-store-details.css
  • /data/data/####/mall-store-details.html
  • /data/data/####/mall-store-list.css
  • /data/data/####/mall-store-list.html
  • /data/data/####/mall-store-list.js
  • /data/data/####/mall-ucenter-icon.png
  • /data/data/####/mall.png
  • /data/data/####/mall_active.png
  • /data/data/####/mall_ajax.js
  • /data/data/####/mall_classify.css
  • /data/data/####/mall_classify.html
  • /data/data/####/mall_classify.js
  • /data/data/####/mall_classify.png
  • /data/data/####/mall_classify_active.png
  • /data/data/####/mall_classify_search.html
  • /data/data/####/mall_classify_search.js
  • /data/data/####/mall_classify_search_result.html
  • /data/data/####/mall_classify_search_result.js
  • /data/data/####/mall_common.css
  • /data/data/####/mall_goods_details.js
  • /data/data/####/mall_home.png
  • /data/data/####/mall_home_active.png
  • /data/data/####/mall_icon.png
  • /data/data/####/mall_index-searchResult.css
  • /data/data/####/mall_index.css
  • /data/data/####/mall_index.html
  • /data/data/####/mall_index.js
  • /data/data/####/mall_index_activity.html
  • /data/data/####/mall_index_activity.js
  • /data/data/####/mall_index_search.css
  • /data/data/####/mall_index_search.html
  • /data/data/####/mall_index_search.js
  • /data/data/####/mall_index_searchResult.html
  • /data/data/####/mall_index_searchResult.js
  • /data/data/####/mall_main.css
  • /data/data/####/mall_main.html
  • /data/data/####/mall_main.js
  • /data/data/####/mall_merchantEntry.css
  • /data/data/####/mall_merchantEntry_1.html
  • /data/data/####/mall_merchantEntry_2.html
  • /data/data/####/mall_merchantEntry_3.html
  • /data/data/####/mall_merchantEntry_4.html
  • /data/data/####/mall_merchantFailed.css
  • /data/data/####/mall_my.png
  • /data/data/####/mall_myCenter.html
  • /data/data/####/mall_myCenter.js
  • /data/data/####/mall_my_active.png
  • /data/data/####/mall_pintuanGoods_details.js
  • /data/data/####/mall_scan.png
  • /data/data/####/mall_scanner.html
  • /data/data/####/mall_scanner.js
  • /data/data/####/mall_shangcheng_searchGoods.html
  • /data/data/####/mall_shangcheng_searchGoods.js
  • /data/data/####/mall_store_details.js
  • /data/data/####/manifest.json
  • /data/data/####/md5.js
  • /data/data/####/merchant-applying.png
  • /data/data/####/merchantEntry1.png
  • /data/data/####/merchantEntry2.png
  • /data/data/####/merchantEntry3.png
  • /data/data/####/merchant_address.png
  • /data/data/####/mix.dex
  • /data/data/####/mobile-login.css
  • /data/data/####/mobile-login.html
  • /data/data/####/mobile-login.js
  • /data/data/####/mui.min.css
  • /data/data/####/mui.min.js
  • /data/data/####/mui.picker.min.css
  • /data/data/####/mui.picker.min.js
  • /data/data/####/mui.previewimage.js
  • /data/data/####/mui.pullToRefresh.js
  • /data/data/####/mui.pullToRefresh.material.js
  • /data/data/####/mui.showLoading.css
  • /data/data/####/mui.ttf
  • /data/data/####/mui.zoom.js
  • /data/data/####/multidex.version.xml
  • /data/data/####/my-order-details.css
  • /data/data/####/my-order-evaluate.css
  • /data/data/####/my-pintuan-successful.css
  • /data/data/####/my-pintuaning-list.css
  • /data/data/####/my.png
  • /data/data/####/my_active.png
  • /data/data/####/native_record_lock
  • /data/data/####/nds-tools.html
  • /data/data/####/ndsrz.png
  • /data/data/####/news-icon.png
  • /data/data/####/news-main.html
  • /data/data/####/news-main.js
  • /data/data/####/news.css
  • /data/data/####/news.png
  • /data/data/####/news_active.png
  • /data/data/####/news_icon_2.png
  • /data/data/####/no-address.png
  • /data/data/####/no-ask.png
  • /data/data/####/no-collect.png
  • /data/data/####/no-comment-icon.png
  • /data/data/####/no-concern.png
  • /data/data/####/no-goodsCollect-icon.png
  • /data/data/####/no-history.png
  • /data/data/####/no-internet.png
  • /data/data/####/no-kaquan.png
  • /data/data/####/no-like.png
  • /data/data/####/no-news1.png
  • /data/data/####/no-news2.png
  • /data/data/####/no-order.png
  • /data/data/####/no-pintuan.png
  • /data/data/####/no-storeCollect-icon.png
  • /data/data/####/open.png
  • /data/data/####/open_active.png
  • /data/data/####/operate.js
  • /data/data/####/order_icon.png
  • /data/data/####/order_pay.js
  • /data/data/####/page-search.png
  • /data/data/####/pay_choose_icon.png
  • /data/data/####/pdr.xml
  • /data/data/####/person.png
  • /data/data/####/phone_icon.png
  • /data/data/####/phone_login.png
  • /data/data/####/pin-failed-icon.png
  • /data/data/####/pintuan_icon.png
  • /data/data/####/pintuanzhong-icon.png
  • /data/data/####/previewImage.css
  • /data/data/####/publish-main.css
  • /data/data/####/publish-main.html
  • /data/data/####/publish-main.js
  • /data/data/####/publish-myConcern.css
  • /data/data/####/publish-myConcern.html
  • /data/data/####/publish-myConcern.js
  • /data/data/####/publish-successful.css
  • /data/data/####/publish-successful.html
  • /data/data/####/publish.png
  • /data/data/####/publish_active.png
  • /data/data/####/pull.css
  • /data/data/####/pulldown_bg.png
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/qqZone_share.png
  • /data/data/####/qq_share.png
  • /data/data/####/question-answer-comment.html
  • /data/data/####/question-answer-comment.js
  • /data/data/####/question-answer-details.css
  • /data/data/####/question-answer-details.html
  • /data/data/####/question-answer-details.js
  • /data/data/####/question-answer-replyComment.html
  • /data/data/####/question-answer-replyComment.js
  • /data/data/####/question-details.css
  • /data/data/####/question-details.html
  • /data/data/####/question-details.js
  • /data/data/####/question-img.png
  • /data/data/####/question-main.css
  • /data/data/####/question-main.html
  • /data/data/####/question-main.js
  • /data/data/####/question-news.html
  • /data/data/####/question-news.js
  • /data/data/####/question-reply.css
  • /data/data/####/question-reply.html
  • /data/data/####/question-reply.js
  • /data/data/####/question.png
  • /data/data/####/question_active.png
  • /data/data/####/readnum.png
  • /data/data/####/record.gif
  • /data/data/####/reduce-num.png
  • /data/data/####/refresh.png
  • /data/data/####/refresh_btn.png
  • /data/data/####/refresh_concern.js
  • /data/data/####/remind.png
  • /data/data/####/reply.png
  • /data/data/####/right_arrow.png
  • /data/data/####/run.pid
  • /data/data/####/s-merchantEntry1.png
  • /data/data/####/s-merchantEntry2.png
  • /data/data/####/s-merchantEntry3.png
  • /data/data/####/s-merchantEntry4.png
  • /data/data/####/scan.png
  • /data/data/####/scanner.html
  • /data/data/####/scanner.js
  • /data/data/####/security_info
  • /data/data/####/selectSity.js
  • /data/data/####/service_icon.png
  • /data/data/####/settings-aboutus.css
  • /data/data/####/settings-aboutus.html
  • /data/data/####/settings-aboutus.js
  • /data/data/####/settings-account-bindPhone.css
  • /data/data/####/settings-account-bindPhone.html
  • /data/data/####/settings-account-bindPhone.js
  • /data/data/####/settings-account-changePhone.html
  • /data/data/####/settings-account-changePhone.js
  • /data/data/####/settings-accountSafe.css
  • /data/data/####/settings-accountSafe.html
  • /data/data/####/settings-accountSafe.js
  • /data/data/####/settings-changePayPwd.css
  • /data/data/####/settings-changePayPwd.html
  • /data/data/####/settings-feedback.css
  • /data/data/####/settings-feedback.html
  • /data/data/####/settings-feedback.js
  • /data/data/####/settings-main.css
  • /data/data/####/settings-main.html
  • /data/data/####/settings-main.js
  • /data/data/####/settings-setPayPwd.css
  • /data/data/####/settings-setPayPwd.html
  • /data/data/####/settings-userName.html
  • /data/data/####/settings-userName.js
  • /data/data/####/settings-userSign.css
  • /data/data/####/settings-userSign.html
  • /data/data/####/settings-userSign.js
  • /data/data/####/settings-userinfo.css
  • /data/data/####/settings-userinfo.html
  • /data/data/####/settings-userinfo.js
  • /data/data/####/share.css
  • /data/data/####/share.js
  • /data/data/####/share_bg.png
  • /data/data/####/share_logo.png
  • /data/data/####/shoppingcar-icon.png
  • /data/data/####/shouhou-addImage.png
  • /data/data/####/shouhou-choose-active.png
  • /data/data/####/shouhou-choose.png
  • /data/data/####/shouhou.png
  • /data/data/####/shouhuoType_active.png
  • /data/data/####/spread_order.png
  • /data/data/####/spread_prize.png
  • /data/data/####/spread_question.png
  • /data/data/####/start_statistics_data.xml
  • /data/data/####/store-bg.png
  • /data/data/####/store_grey.png
  • /data/data/####/stream_permission.xml
  • /data/data/####/style.css
  • /data/data/####/successful.png
  • /data/data/####/system-news.css
  • /data/data/####/system-news.html
  • /data/data/####/system-news.png
  • /data/data/####/systems-news-bg.png
  • /data/data/####/template.html
  • /data/data/####/test_app
  • /data/data/####/tixian.png
  • /data/data/####/to-publish.png
  • /data/data/####/tool.png
  • /data/data/####/transfer.png
  • /data/data/####/tuiguang-prize.png
  • /data/data/####/tuiguang.png
  • /data/data/####/tuiguang_icon.png
  • /data/data/####/ucenter-collect.png
  • /data/data/####/ucenter-edit.png
  • /data/data/####/ucenter-like.png
  • /data/data/####/ucenter-main.css
  • /data/data/####/ucenter-main.html
  • /data/data/####/ucenter-main.js
  • /data/data/####/ucenter-myArticle.html
  • /data/data/####/ucenter-myArticle.js
  • /data/data/####/ucenter-myCollect.css
  • /data/data/####/ucenter-myCollect.html
  • /data/data/####/ucenter-myCollect.js
  • /data/data/####/ucenter-myConcern.css
  • /data/data/####/ucenter-myConcern.html
  • /data/data/####/ucenter-myConcern.js
  • /data/data/####/ucenter-myFans.html
  • /data/data/####/ucenter-myFans.js
  • /data/data/####/ucenter-myHistory.css
  • /data/data/####/ucenter-myHistory.html
  • /data/data/####/ucenter-myHistory.js
  • /data/data/####/ucenter-myLike.html
  • /data/data/####/ucenter-myLike.js
  • /data/data/####/ucenter-myPage.css
  • /data/data/####/ucenter-myPage.html
  • /data/data/####/ucenter-myPage.js
  • /data/data/####/ucenter-myQuestion.css
  • /data/data/####/ucenter-myQuestion.html
  • /data/data/####/ucenter-myQuestion.js
  • /data/data/####/ucenter-question.png
  • /data/data/####/ucenter-settings.png
  • /data/data/####/ucenter-wallet.png
  • /data/data/####/un_collected.png
  • /data/data/####/unionPay-icon.png
  • /data/data/####/update.js
  • /data/data/####/upload-img.png
  • /data/data/####/util.js
  • /data/data/####/voice-big.png
  • /data/data/####/voice-contentBg.png
  • /data/data/####/voice-grey-icon.png
  • /data/data/####/voice-icon.png
  • /data/data/####/voice1.png
  • /data/data/####/wallet_icon.png
  • /data/data/####/wb_share.png
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/wechat_icon.png
  • /data/data/####/withdraw-status-failed.png
  • /data/data/####/withdraw-status1.png
  • /data/data/####/withdraw-status2.png
  • /data/data/####/withdraw-status3.png
  • /data/data/####/withdraw-status4.png
  • /data/data/####/wx_friend_share.png
  • /data/data/####/wx_icon.png
  • /data/data/####/wx_share.png
  • /data/data/####/yellow_star.png
  • /data/data/####/yellow_star_active.png
  • /data/data/####/zepto.min.js
  • /data/data/####/ziti-address.png
  • /data/data/####/ziti-icon.png
  • /data/data/####/zuji.png
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.imei.txt
  • /data/media/####/AdEnable.dat
  • /data/media/####/app.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.nongduoshou.nds.bin
  • /data/media/####/com.nongduoshou.nds.db
  • /data/media/####/test.log
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/io.dcloud.feature.apsGt.GTNormalPushService 24945 300 0
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-3.0.0.0.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/io.dcloud.feature.apsGt.GTNormalPushService 24945 300 0
Loads the following dynamic libraries:
  • BaiduMapSDK_base_v4_3_1
  • Bugly
  • getuiext2
  • libnfix
  • libshella-3.0.0.0
  • libufix
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android