マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Adware.Gexin.17378

Added to the Dr.Web virus database: 2019-08-21

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) p####.xxt.cn:80
  • TCP(HTTP/1.1) m.x####.cn:80
  • TCP(HTTP/1.1) 1####.29.29.29:80
  • TCP(HTTP/1.1) 2####.205.239.188:80
  • UDP(NTP) 2.and####.p####.####.org:123
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) p####.xxt.cn:443
  • TCP(TLS/1.0) 1####.114.54.3:443
  • TCP(TLS/1.0) 1####.15.61.197:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) instant####.google####.com:443
  • TCP(TLS/1.0) safebro####.google####.com:443
  • TCP(TLS/1.0) 2####.58.208.110:443
  • TCP(TLS/1.0) m.x####.cn:443
  • TCP(TLS/1.0) 1####.15.61.202:443
  • TCP(TLS/1.0) ser####.xxt.cn:443
  • TCP(TLS/1.2) p####.google####.com:443
DNS requests:
  • 2.and####.p####.####.org
  • api.map.b####.com
  • instant####.google####.com
  • l####.tbs.qq.com
  • m.x####.cn
  • p####.google####.com
  • p####.xxt.cn
  • safebro####.google####.com
  • ser####.xxt.cn
  • st####.xxt.cn
HTTP GET requests:
  • m.x####.cn/android/image/home_article.png
  • m.x####.cn/android/image/home_blog.png
  • m.x####.cn/android/image/home_course_big_logo.png
  • m.x####.cn/android/image/home_course_hbjxt.png
  • m.x####.cn/android/image/home_english.png
  • m.x####.cn/android/image/home_famous_book.png
  • m.x####.cn/android/image/home_language.png
  • m.x####.cn/android/image/home_poetry.png
  • m.x####.cn/android/image/home_ttl.png
  • m.x####.cn/android/image/home_ttl_big_logo.png
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0626/6adedc987f5b150fa69e6...
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0626/a0043629fe9f242b721bb...
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0628/ee7c8eecb01de99fd675f...
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0704/3b6d06a42da3be0b96fda...
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0706/8bf6fc850b84d6d4ec95c...
  • p####.xxt.cn/upload/2017/xxt_new/index_notice/0728/eed17a1253639b0ba4f5a...
  • p####.xxt.cn/upload/2019/xxt_new/index_notice/0817/15e4bc5e80a2897268739...
HTTP POST requests:
  • l####.tbs.qq.com/ajax?c=####&k=####
  • l####.tbs.qq.com/ajax?c=####&v=####&k=####
File system changes:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/000925d071b0f3e8.0
  • /data/data/####/004a122e2dc1c6de.0
  • /data/data/####/008175b628019b45.0
  • /data/data/####/00fb7971538fec86.0
  • /data/data/####/032ebd8eac406f76.0
  • /data/data/####/0335bd06b39bc174.0
  • /data/data/####/04514214b4e2aaed.0
  • /data/data/####/0515f8a1a485f37a.0
  • /data/data/####/0593dc52a6060857.0
  • /data/data/####/061a4a66170487cd.0
  • /data/data/####/068b9b51479e06ec.0
  • /data/data/####/069a4e0420b26fa2.0
  • /data/data/####/06c6897c77f6122668a84c78877071bf.0.tmp
  • /data/data/####/06c6897c77f6122668a84c78877071bf.1.tmp
  • /data/data/####/07077b316ba0bfb7.0
  • /data/data/####/0824e182d52c33d4.0
  • /data/data/####/085b1a9ee1309fbf.0
  • /data/data/####/0861d02229bd7bc7.0
  • /data/data/####/08a97223f0f4b2ea.0
  • /data/data/####/08b17c5f600ef9b4.0
  • /data/data/####/08b5a68f73525025.0
  • /data/data/####/0ac921064193057a.0
  • /data/data/####/0b636bc6534d3da6.0
  • /data/data/####/0cc9a862f9d1f3a8.0
  • /data/data/####/0eeaa5cf69b6a84e.0
  • /data/data/####/0f193d72f71a5340.0
  • /data/data/####/0f7b611340d5de11.0
  • /data/data/####/0fdf89bdd15d5f14.0
  • /data/data/####/1002
  • /data/data/####/1004
  • /data/data/####/100da44495bd60b4.0
  • /data/data/####/102a18145eda47c7.0
  • /data/data/####/105f179954d531f4.0
  • /data/data/####/107bbf278b7d890b.0
  • /data/data/####/111001b52f9418f8.0
  • /data/data/####/123bf358826c1e6c.0
  • /data/data/####/133c562d0872c4d4.0
  • /data/data/####/135d285adc32376b.0
  • /data/data/####/13924dd8115b231d.0
  • /data/data/####/13df41cb588edf8d.0
  • /data/data/####/13fb4e50756c039a.0
  • /data/data/####/147b3236bc395935.0
  • /data/data/####/14cad06d8ab538ae.0
  • /data/data/####/14cc8873b1cca5e4.0
  • /data/data/####/15ec6784c7974499.0
  • /data/data/####/16f932520442cb14.0
  • /data/data/####/17b842ffc817f26e.0
  • /data/data/####/18d1a011e5298021.0
  • /data/data/####/1d082a31bd791102.0
  • /data/data/####/1dd4c041f997e879.0
  • /data/data/####/1f3343c57903f1ee.0
  • /data/data/####/1ffe26b12ef07759.0
  • /data/data/####/206ae1356cfe8247.0
  • /data/data/####/209a1388b5351b6e.0
  • /data/data/####/20cc4c167fda058a.0
  • /data/data/####/215505b3002d7874.0
  • /data/data/####/21d551b5136dadc9.0
  • /data/data/####/228ec0bc907ae71a.0
  • /data/data/####/2306efc6746018f2.0
  • /data/data/####/236e8d322c3b927a.0
  • /data/data/####/237ba81665f9571f.0
  • /data/data/####/23904fd23966e743.0
  • /data/data/####/24add838fede7f96.0
  • /data/data/####/262054938b9d6448.0
  • /data/data/####/26e445554ec441e8.0
  • /data/data/####/2723fdd4986b0fd0.0
  • /data/data/####/27598eb55d4d8775.0
  • /data/data/####/280379982eb050cb.0
  • /data/data/####/28510a276b224f2c.0
  • /data/data/####/28ab9110b35c4be8.0
  • /data/data/####/2a2f71ce4cdc46d8.0
  • /data/data/####/2a58512ea9fd4246.0
  • /data/data/####/2af6ce3aa6fe4deb.0
  • /data/data/####/2b66c28a3b4e90b46da0e1a0e1800e40.0.tmp
  • /data/data/####/2b66c28a3b4e90b46da0e1a0e1800e40.1.tmp
  • /data/data/####/2b75f72d8e0933bc.0
  • /data/data/####/2ba2343e338faddb.0
  • /data/data/####/2c4dbcac0a39af26.0
  • /data/data/####/2c4e83ce5ce2cfc5.0
  • /data/data/####/2c92ae9987dac713.0
  • /data/data/####/2dca4e1b25374fd5.0
  • /data/data/####/2e5fc84f0bd26316.0
  • /data/data/####/2eec41fb36b7b1c6.0
  • /data/data/####/2f738406a9afcf85.0
  • /data/data/####/2fd6d2d16945ac7f.0
  • /data/data/####/3040d9c81a3b3122.0
  • /data/data/####/30a22cdad3fd0aea.0
  • /data/data/####/3221ff391d7e9bcb.0
  • /data/data/####/331636ad269d012b.0
  • /data/data/####/336dfc29b3ca7daa.0
  • /data/data/####/357262b272fe418f.0
  • /data/data/####/35ff48cee2e76a79.0
  • /data/data/####/37dfbfb5df3737c9.0
  • /data/data/####/37e371b86e522d77.0
  • /data/data/####/3802fc23eb5b663d.0
  • /data/data/####/381adb519acd3250.0
  • /data/data/####/38a97948c1cd95fd1a07c7a6244e4e36.0.tmp
  • /data/data/####/38a97948c1cd95fd1a07c7a6244e4e36.1.tmp
  • /data/data/####/39601344fa40fd96.0
  • /data/data/####/39c1973862bb44c9.0
  • /data/data/####/39f4e0d85b3e31de.0
  • /data/data/####/39f54d25c083959a.0
  • /data/data/####/3a66ddf0d844566c.0
  • /data/data/####/3aa34e629d494a0e.0
  • /data/data/####/3ae49afb15c51ea4.0
  • /data/data/####/3d94ca48911a36d8.0
  • /data/data/####/3da95c1adc1f206d.0
  • /data/data/####/3dd3c78189195232.0
  • /data/data/####/3e948afac7ecaf9a.0
  • /data/data/####/3f1ff23d61c258bb.0
  • /data/data/####/3f3f4b23ef99233b.0
  • /data/data/####/40a2a5891d5e0537.0
  • /data/data/####/41a69d0ce03b80f2.0
  • /data/data/####/43c83418c4518a45.0
  • /data/data/####/440547a3f40e6940.0
  • /data/data/####/443ad5cc2ab073d6.0
  • /data/data/####/4513ea38aae9e9cb.0
  • /data/data/####/456a0ee7724906c9.0
  • /data/data/####/46131e4be56e27a5.0
  • /data/data/####/46ac2eb0bdc64332.0
  • /data/data/####/46c3048b06cb76fc52907dc9c77274a7.0.tmp
  • /data/data/####/46c3048b06cb76fc52907dc9c77274a7.1.tmp
  • /data/data/####/478628dde9ecb735.0
  • /data/data/####/48ddcbbc794da03a.0
  • /data/data/####/4b4ff73257bd3a22.0
  • /data/data/####/4b98147673796205.0
  • /data/data/####/4d5ed67662503313.0
  • /data/data/####/4f67ae144a7a1bf1.0
  • /data/data/####/4f8cf7534a8eab61.0
  • /data/data/####/4fc80782dad45e8f.0
  • /data/data/####/50bf2efcb30b6c0c.0
  • /data/data/####/50fabf612e50a5e6.0
  • /data/data/####/50fd9dfbd836150e.0
  • /data/data/####/52e0e4d4f01dca95.0
  • /data/data/####/537d71a09883182b.0
  • /data/data/####/5399f2ca04960dc6.0
  • /data/data/####/53abdf659a48f4f5.0
  • /data/data/####/541f8f59c732010b.0
  • /data/data/####/555977432228c9f0.0
  • /data/data/####/556f322a2ff10c3af33b82525fa9809e.0.tmp
  • /data/data/####/556f322a2ff10c3af33b82525fa9809e.1.tmp
  • /data/data/####/562284af331aa026.0
  • /data/data/####/579c6a254de65a6d.0
  • /data/data/####/57d83ed0a65d12ec.0
  • /data/data/####/58ddcbbb8dece9a0.0
  • /data/data/####/59b48106ff3cd474.0
  • /data/data/####/5aa6348a90b7644e.0
  • /data/data/####/5b580811da054f4e.0
  • /data/data/####/5b58ceb3ba73386d.0
  • /data/data/####/5b605fabb7ef7c4e.0
  • /data/data/####/5b675df72ade835f.0
  • /data/data/####/5b9a083013443bc1bc18d2d509ba72d7.0.tmp
  • /data/data/####/5b9a083013443bc1bc18d2d509ba72d7.1.tmp
  • /data/data/####/5c3a020891dce1d2.0
  • /data/data/####/5c9d67afa1d0d48f.0
  • /data/data/####/5d1de829759fbdf5.0
  • /data/data/####/5f0574fd77d060c5.0
  • /data/data/####/5f196731968105ef.0
  • /data/data/####/5ffb63a0050f7cd8d570a820a03389c1.0.tmp
  • /data/data/####/5ffb63a0050f7cd8d570a820a03389c1.1.tmp
  • /data/data/####/60c8647582aaf04a.0
  • /data/data/####/61bf9f37ed45c1cb.0
  • /data/data/####/62b16a0d0c560853.0
  • /data/data/####/6349b4f0634f990460c18c5f24b18f45.0.tmp
  • /data/data/####/6349b4f0634f990460c18c5f24b18f45.1.tmp
  • /data/data/####/63b41eac77adf1e07c3159341901f966.0.tmp
  • /data/data/####/63b41eac77adf1e07c3159341901f966.1.tmp
  • /data/data/####/63c8ce7526f66e8a.0
  • /data/data/####/6419ccbe4a61cd9c.0
  • /data/data/####/64789b82b68dd82b.0
  • /data/data/####/649d14b5f75d1e0d.0
  • /data/data/####/650b1bddbdf295cb.0
  • /data/data/####/654a53783b8e57918777ea23c06bce6b.0.tmp
  • /data/data/####/654a53783b8e57918777ea23c06bce6b.1.tmp
  • /data/data/####/6619e809f40490b9_0
  • /data/data/####/6619e809f40490b9_s
  • /data/data/####/668864d4a455f3f2.0
  • /data/data/####/67e76e9481f4187c.0
  • /data/data/####/67f443b405b8068c.0
  • /data/data/####/685f107f2c64a22f.0
  • /data/data/####/69b82929523c676a.0
  • /data/data/####/6a186dc9373413b3.0
  • /data/data/####/6b6c4345a1a1f7ad.0
  • /data/data/####/6bc97307f8949322.0
  • /data/data/####/6bf1cd40a301dcc8.0
  • /data/data/####/6e81fc96e78772f1.0
  • /data/data/####/70ad6d72c77970b3.0
  • /data/data/####/719e42b5f3d77653.0
  • /data/data/####/72f580ec2988a6aa.0
  • /data/data/####/72f6deb36edf26bd.0
  • /data/data/####/73be4a77ee1ac8e3.0
  • /data/data/####/74ae75ba741fcbe3.0
  • /data/data/####/75ad679bafb96b67.0
  • /data/data/####/75bf1d0250855dde.0
  • /data/data/####/75c070fafbf034ad.0
  • /data/data/####/77c97560f11e71c2.0
  • /data/data/####/79a3be557d39bd04.0
  • /data/data/####/79b58bcd50e0dfc7.0
  • /data/data/####/79d1f49630def68b.0
  • /data/data/####/7b21b368e75411a8.0
  • /data/data/####/7c8bb8eb6f807c1e.0
  • /data/data/####/7e2b19c1404cc1ef.0
  • /data/data/####/7e5ea0c7ac575179.0
  • /data/data/####/7eb274a7dc0bb3f7.0
  • /data/data/####/7eeb19a8ef26488a.0
  • /data/data/####/7faee1c1c32766fb.0
  • /data/data/####/806e30e1fc03eb40.0
  • /data/data/####/809107babfd668b7.0
  • /data/data/####/81f2e6409804b2fd.0
  • /data/data/####/82aed141f1018720.0
  • /data/data/####/831210316e2ad8d3.0
  • /data/data/####/831d78505808b03c.0
  • /data/data/####/84bf3295dec69d46.0
  • /data/data/####/8544b98862062d3d.0
  • /data/data/####/858adcb771553773.0
  • /data/data/####/85da5cbbad1f7c95.0
  • /data/data/####/880ddb14c2bf0dad.0
  • /data/data/####/88bda3bbe19886c0.0
  • /data/data/####/89e08cf95551f4ce.0
  • /data/data/####/8a515b324e10eaad.0
  • /data/data/####/8a9a329acc23371aad008ade965acd5c.0.tmp
  • /data/data/####/8a9a329acc23371aad008ade965acd5c.1.tmp
  • /data/data/####/8b4a81cba132f673.0
  • /data/data/####/8bcd19fbb3128bd3.0
  • /data/data/####/8c24c14d2d139e9f.0
  • /data/data/####/8c3118884cf4fc52.0
  • /data/data/####/8c7eb502886d6556.0
  • /data/data/####/8cfcf0e61d71ac6f3315642c55b9674f.0.tmp
  • /data/data/####/8cfcf0e61d71ac6f3315642c55b9674f.1.tmp
  • /data/data/####/8dc64e12157fb1dc.0
  • /data/data/####/901f8c8049666bb4.0
  • /data/data/####/908b7e0a16ca9d54f133e8b918be11e7.0.tmp
  • /data/data/####/908b7e0a16ca9d54f133e8b918be11e7.1.tmp
  • /data/data/####/918fc9ad37e6788c.0
  • /data/data/####/91cc9a283db9d3a9.0
  • /data/data/####/93e06e1e470f5ddf.0
  • /data/data/####/94540895e04cb5ba.0
  • /data/data/####/94b57dd0ff4d17f9.0
  • /data/data/####/94f1bccf1e399fad.0
  • /data/data/####/96134564ce54ecf4.0
  • /data/data/####/9725b33a4bc17e0b.0
  • /data/data/####/9777368fcfb2d511.0
  • /data/data/####/9ab3e1d06db49478.0
  • /data/data/####/9ab574f03bd84c9421875afd7250cb6e.0.tmp
  • /data/data/####/9ab574f03bd84c9421875afd7250cb6e.1.tmp
  • /data/data/####/9abd108400d1c5d8.0
  • /data/data/####/9b2e592ccee3a274.0
  • /data/data/####/9d5d6746a1191d57.0
  • /data/data/####/9d630c47ddf11686.0
  • /data/data/####/9e07c02b0d722947.0
  • /data/data/####/9f1fdeff7d9c5fed.0
  • /data/data/####/CookiePersistence.xml
  • /data/data/####/Cookies-journal
  • /data/data/####/EnContactInfo.db
  • /data/data/####/EnContactInfo.db-journal
  • /data/data/####/EnContactInfo.db-journal (deleted)
  • /data/data/####/EnXxtLogin.db
  • /data/data/####/EnXxtLogin.db-journal
  • /data/data/####/EnXxtLogin.db-journal (deleted)
  • /data/data/####/EnXxtLogin.db-shm (deleted)
  • /data/data/####/EnXxtLogin.db-wal
  • /data/data/####/EnXxtLogin.db-wal (deleted)
  • /data/data/####/EnXxtUserInfo.db
  • /data/data/####/EnXxtUserInfo.db-journal
  • /data/data/####/EnXxtUserInfo.db-shm (deleted)
  • /data/data/####/EnXxtUserInfo.db-wal
  • /data/data/####/EnZxjxMsgExecuteDate.db
  • /data/data/####/EnZxjxMsgExecuteDate.db-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a01a2af9bc233f17.0
  • /data/data/####/a09c7c801f1ba27b.0
  • /data/data/####/a0e4618854561c2b.0
  • /data/data/####/a0f85ac041112f9703e151589a860505.0.tmp
  • /data/data/####/a0f85ac041112f9703e151589a860505.1.tmp
  • /data/data/####/a1321f193dac645c.0
  • /data/data/####/a1403cb6efaff11824a25afb14bf69cb.0.tmp
  • /data/data/####/a1403cb6efaff11824a25afb14bf69cb.1.tmp
  • /data/data/####/a1785d1c0d25234f_0
  • /data/data/####/a1785d1c0d25234f_s
  • /data/data/####/a183f5ccbf6bc09d.0
  • /data/data/####/a1a74ffe66904549.0
  • /data/data/####/a20e6163a088fb16.0
  • /data/data/####/a2b5713a8a267400.0
  • /data/data/####/a383f0cbc072e51e.0
  • /data/data/####/a3a4283f3da471d4.0
  • /data/data/####/a4ac90be7b5b0a9f.0
  • /data/data/####/a6668ee39d722e6b9fc32a2fc8e0c365.0.tmp
  • /data/data/####/a6668ee39d722e6b9fc32a2fc8e0c365.1.tmp
  • /data/data/####/a6dad4693ca95385.0
  • /data/data/####/a6e6edba7ac8774a.0
  • /data/data/####/a6e83e00dd47ee41.0
  • /data/data/####/a7cdaaa007d8b71c.0
  • /data/data/####/a7f58ed72470b988.0
  • /data/data/####/a856a99d4b26e1e3.0
  • /data/data/####/a9736e2a9d85e859.0
  • /data/data/####/a9934703e8f3686a.0
  • /data/data/####/aa65bcf4292373c6.0
  • /data/data/####/abbe9a8bc5d917be.0
  • /data/data/####/ac2be1b21b0bd3e4.0
  • /data/data/####/ac2d82b1dda4a320_0
  • /data/data/####/access_20190821163544_0000.log.tmp
  • /data/data/####/access_20190821163545_0000.log.tmp
  • /data/data/####/ad3c8a5a3de30917.0
  • /data/data/####/ad_auth.xml
  • /data/data/####/adaf7608953c3837.0
  • /data/data/####/adf97492a9669131aa84f5e7152aaba2.0.tmp
  • /data/data/####/adf97492a9669131aa84f5e7152aaba2.1.tmp
  • /data/data/####/af661a030a72508a.0
  • /data/data/####/af7b3fd5176ebe37.0
  • /data/data/####/application_shared_prefs.xml
  • /data/data/####/application_shared_prefs.xml.bak
  • /data/data/####/authStatus_cn.jxt.android.xml
  • /data/data/####/b151713a520e50c1.0
  • /data/data/####/b1fd7ca1cb09156a.0
  • /data/data/####/b330c7a42c634fe0.0
  • /data/data/####/b37976fb4b24e7f4.0
  • /data/data/####/b4834a490d25caac.0
  • /data/data/####/b4a41510e7b8c9ff.0
  • /data/data/####/b675466b95f16810.0
  • /data/data/####/b760aabb810fdfa3.0
  • /data/data/####/b81519d9ef56810c.0
  • /data/data/####/b90c832a1eca9b8f.0
  • /data/data/####/ba67926ecb8e4dee.0
  • /data/data/####/bb0fffe86028b1c3.0
  • /data/data/####/bbdfe0e45b603efa565070f3bda417df.0.tmp
  • /data/data/####/bbdfe0e45b603efa565070f3bda417df.1.tmp
  • /data/data/####/bf52180023d658a7.0
  • /data/data/####/bf75e3ad587c90d7.0
  • /data/data/####/bfc05db1c86649e9.0
  • /data/data/####/bugly_db_-journal
  • /data/data/####/c0c26b0695544a94.0
  • /data/data/####/c0f80291638b144d.0
  • /data/data/####/c14ccec162133f7f.0
  • /data/data/####/c22cbd42aa319c43.0
  • /data/data/####/c36637dbaa87550c.0
  • /data/data/####/c40b6e50c06ab8d7.0
  • /data/data/####/c4e1f16537072e90.0
  • /data/data/####/c59a05e846176bf7.0
  • /data/data/####/c756483ec999a970.0
  • /data/data/####/c7afc20acaef7804.0
  • /data/data/####/c7ba3be4d83dbb34.0
  • /data/data/####/c88f0d5ce90a543a.0
  • /data/data/####/c8de0f64945d9ff8.0
  • /data/data/####/c934348586356130.0
  • /data/data/####/cb27ba4738eaa544.0
  • /data/data/####/cbbd7fdc86ecbf88.0
  • /data/data/####/cc528cf79f7c2741.0
  • /data/data/####/cceda3f2e1e1dacc.0
  • /data/data/####/ccf0f655bbeda8e5.0
  • /data/data/####/cd1a0efa89967bca.0
  • /data/data/####/cd4c8f6c21697e5f.0
  • /data/data/####/cd770fd60895d303.0
  • /data/data/####/cd9fad172c7cb886.0
  • /data/data/####/cf8690834dc0beb6.0
  • /data/data/####/circle.db
  • /data/data/####/circle.db-journal
  • /data/data/####/click_20190821163546_0000.log.tmp
  • /data/data/####/cloud.db
  • /data/data/####/cloud.db-journal
  • /data/data/####/cn.jxt.android_preferences.xml
  • /data/data/####/common_20190821163618_0000.log.tmp
  • /data/data/####/core_info
  • /data/data/####/d0244afe22aa41df.0
  • /data/data/####/d0cc9e26821a5105.0
  • /data/data/####/d0f8c8e2ffa64393.0
  • /data/data/####/d1cf9c204bca441b.0
  • /data/data/####/d2143d094ba78b0f.0
  • /data/data/####/d37de3da91cd43f5.0
  • /data/data/####/d47265a7c4f33a30.0
  • /data/data/####/d5179f8052ec50ab.0
  • /data/data/####/d5b4438116fd7b8a.0
  • /data/data/####/d5e01693bde467a8.0
  • /data/data/####/d61c1d982b005fea.0
  • /data/data/####/d7f0e2b8b2b752cb.0
  • /data/data/####/d89913caaa8ccdc6.0
  • /data/data/####/d8f35a3f6a67a05c.0
  • /data/data/####/d9342579205b30ff.0
  • /data/data/####/d956d3402386931e.0
  • /data/data/####/da584bd16c011a52.0
  • /data/data/####/daa7c5545886eb3e.0
  • /data/data/####/dbab36ba424ce952.0
  • /data/data/####/dc1ec6919a16307d.0
  • /data/data/####/dda424267a085b33.0
  • /data/data/####/de8f61d9da643d5a.0
  • /data/data/####/debug.conf
  • /data/data/####/dec90cedafd0f422.0
  • /data/data/####/def18fc736364211.0
  • /data/data/####/device_20190821163545_0000.log.tmp
  • /data/data/####/dff8cf98180158aa.0
  • /data/data/####/download_upload
  • /data/data/####/e0a715fe6645df95.0
  • /data/data/####/e0c3fb82ccce7485.0
  • /data/data/####/e1beba62f15165b6.0
  • /data/data/####/e1ef4ebfeeffd42d.0
  • /data/data/####/e230703799338c57.0
  • /data/data/####/e41f66f45eb94101.0
  • /data/data/####/e61b369191a08853.0
  • /data/data/####/e65af406b582c332.0
  • /data/data/####/e73338d1e6f8e5d0.0
  • /data/data/####/e7798fec73ab4230.0
  • /data/data/####/e809fc1c6b10a573.0
  • /data/data/####/e86fc216c10e0d3c.0
  • /data/data/####/e924a4a2eb2a58b4.0
  • /data/data/####/e92cae3f60c1b22d.0
  • /data/data/####/e9335afb5fa2f25e.0
  • /data/data/####/e9e9ee05a7ff9d4e.0
  • /data/data/####/ea2302ed8c9a0952.0
  • /data/data/####/eadb0325be74719c393af220dcbba76d.0.tmp
  • /data/data/####/eadb0325be74719c393af220dcbba76d.1.tmp
  • /data/data/####/eadfb90225e4cd2ada084b5804ad92d5.0.tmp
  • /data/data/####/eadfb90225e4cd2ada084b5804ad92d5.1.tmp
  • /data/data/####/ebfefd14d052031f.0
  • /data/data/####/ec8ffb2f2d2306bd.0
  • /data/data/####/f09b38b854e48893.0
  • /data/data/####/f0e4d9b10351741d628c6f466d463a6f.0.tmp
  • /data/data/####/f0e4d9b10351741d628c6f466d463a6f.1.tmp
  • /data/data/####/f29e794ba24d8fbd.0
  • /data/data/####/f2bc1c069acc009b.0
  • /data/data/####/f341f3d26c156bba.0
  • /data/data/####/f390da2492a1fee6.0
  • /data/data/####/f6642a6ab47e59ff.0
  • /data/data/####/f69d75deb8a9a5a0.0
  • /data/data/####/f6c12e74f7745580.0
  • /data/data/####/f79a500f01af476cbaa11ebcce51f91a.0.tmp
  • /data/data/####/f79a500f01af476cbaa11ebcce51f91a.1.tmp
  • /data/data/####/f7cb10a1c3b189c5.0
  • /data/data/####/f896adfa7cae41a8.0
  • /data/data/####/f8c346b1110c5b93.0
  • /data/data/####/f95155d93cb3ade8.0
  • /data/data/####/f962f84ba654d42b.0
  • /data/data/####/f9f3fe7187b52d52.0
  • /data/data/####/fa0d8458e0c49f9e.0
  • /data/data/####/fbc7937bc904aae0.0
  • /data/data/####/fbc906ab474d8414.0
  • /data/data/####/fd06b2fdb4d83bfd.0
  • /data/data/####/fd1300297e12a819.0
  • /data/data/####/fe3e82d342810cf3.0
  • /data/data/####/ff3484af23e652d8.0
  • /data/data/####/ff7a1f93309d0696.0
  • /data/data/####/hnxxtContacts.db
  • /data/data/####/hnxxtContacts.db-journal
  • /data/data/####/hnxxtMessage.db
  • /data/data/####/hnxxtMessage.db-journal
  • /data/data/####/hnxxtMsgExecuteDate.db
  • /data/data/####/hnxxtMsgExecuteDate.db-journal
  • /data/data/####/hnxxtRecommendSMS.db
  • /data/data/####/hnxxtRecommendSMS.db-journal
  • /data/data/####/homework.db
  • /data/data/####/homework.db-journal
  • /data/data/####/index
  • /data/data/####/journal
  • /data/data/####/journal.tmp
  • /data/data/####/jxhdZxjxMessage.db
  • /data/data/####/jxhdZxjxMessage.db-journal
  • /data/data/####/jxtMsgExecuteDate.db
  • /data/data/####/jxtMsgExecuteDate.db-journal
  • /data/data/####/jxtMsgFile.db
  • /data/data/####/jxtMsgFile.db-journal
  • /data/data/####/jxtMsgGroupDB.db
  • /data/data/####/jxtMsgGroupDB.db-journal
  • /data/data/####/jxtPermissionUnit.db
  • /data/data/####/jxtPermissionUnit.db-journal
  • /data/data/####/libcuid.so
  • /data/data/####/local_crash_lock
  • /data/data/####/local_crash_lock (deleted)
  • /data/data/####/log_config_table.db
  • /data/data/####/log_config_table.db-journal
  • /data/data/####/log_config_table.db-shm (deleted)
  • /data/data/####/log_config_table.db-wal (deleted)
  • /data/data/####/login_sp_file.xml
  • /data/data/####/mac.xml
  • /data/data/####/metrics_guid
  • /data/data/####/native_record_lock
  • /data/data/####/network_20190821163545_0000.log.tmp
  • /data/data/####/news.db
  • /data/data/####/news.db-journal
  • /data/data/####/notice.db
  • /data/data/####/notice.db-journal
  • /data/data/####/notice.db-shm (deleted)
  • /data/data/####/notice.db-wal
  • /data/data/####/notice.db-wal (deleted)
  • /data/data/####/operator.db
  • /data/data/####/operator.db-journal
  • /data/data/####/proc_auxv
  • /data/data/####/push_sp_file.xml
  • /data/data/####/run_20190821163545_0000.log.tmp
  • /data/data/####/security_info
  • /data/data/####/service_sp_file.xml
  • /data/data/####/service_sp_file.xml.bak
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_config.xml.bak
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbs_pv_config
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/the-real-index
  • /data/data/####/vodChannel.db
  • /data/data/####/vodChannel.db-journal
  • /data/data/####/vodChannel.db-journal (deleted)
  • /data/data/####/vodChannel.db-shm (deleted)
  • /data/data/####/vodChannel.db-wal
  • /data/data/####/webCacheDbV1.db
  • /data/data/####/webCacheDbV1.db-journal
  • /data/data/####/xxtArrangedContacts.db
  • /data/data/####/xxtArrangedContacts.db-journal
  • /data/data/####/xxtGradeInfo.db
  • /data/data/####/xxtGradeInfo.db-journal
  • /data/data/####/xxtGradeInfo.db-shm (deleted)
  • /data/data/####/xxtGradeInfo.db-wal
  • /data/data/####/xxtModule.db
  • /data/data/####/xxtModule.db-journal
  • /data/data/####/xxtModule.db-journal (deleted)
  • /data/data/####/xxtMsgFile.db
  • /data/data/####/xxtMsgFile.db-journal
  • /data/data/####/zxjxContacts.db
  • /data/data/####/zxjxContacts.db-journal
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • getprop
  • getprop ro.product.cpu.abi
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
  • DESede-ECB-PKCS5Padding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android