Technical information
- Adware.Gexin.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) z.c####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) tq.18t####.com:80
- TCP(HTTP/1.1) hm.b####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) c.c####.com:80
- TCP(HTTP/1.1) gm.mm####.com:80
- TCP(HTTP/1.1) w####.18t####.com.####.com:80
- TCP(HTTP/1.1) api.appj####.com:80
- UDP s.j####.cn:19000
- UDP s.j####.cn:80
- a####.u####.com
- api.18t####.com
- api.appj####.com
- api.bbs.18t####.com
- c####.mm####.com
- c.c####.com
- cfg.ads####.com
- cfg.ads####.mobi
- cfg.ads####.net
- cfg.ads####.org
- h####.c####.com
- hm.b####.com
- im.j####.cn
- qn.18t####.com
- s.j####.cn
- s11.c####.com
- tq.18t####.com
- www.18t####.com
- c.c####.com/core.php?web_id=####&t=####
- c.c####.com/stat.php?id=####&web_id=####
- gm.mm####.com/9.gif?abc=####&rnd=####
- hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
- hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
- hm.b####.com/hm.js?ca01a95####
- t####.c####.q####.####.com/uploads/20150617/1434505972104453.jpg
- t####.c####.q####.####.com/uploads/20150626/1435286022301916.jpg
- t####.c####.q####.####.com/uploads/20150812/1439361355755465.jpg
- t####.c####.q####.####.com/uploads/20151204/1449198740541516.jpg
- tq.18t####.com/?c=####&a=####&dk=####&ak=####
- tq.18t####.com/Forum/11899?dk=####&ak=####
- tq.18t####.com/Post/287626?bf=####&count=####&order=####&comment=####&dk...
- tq.18t####.com/Topic/287626?dk=####&ak=####
- tq.18t####.com/TopicList/11899?type=####&filter=####&order=####&page=###...
- tq.18t####.com/index.php?c=####&a=####&ids=####&dk=####&ak=####
- tq.18t####.com/roomapi/TalkRoom?platform=####&bundle=####
- w####.18t####.com.####.com/?bf=####&count=####&order=####&comment=####&d...
- w####.18t####.com.####.com/?dk=####&ak=####
- w####.18t####.com.####.com/?platform=####&bundle=####
- w####.18t####.com.####.com/?type=####&filter=####&order=####&page=####&p...
- z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
- a####.u####.com/app_logs
- api.appj####.com/appjiagu
- /data/data/####/AdsMogo_CacheData.txt
- /data/data/####/ForumInfoTopic287626.txt
- /data/data/####/ForumListHead11899.txt
- /data/data/####/JPushSA_Config.xml
- /data/data/####/Q8tFVImbNuvsmBwWwdqsPE6jsRQsSPkQ.xml
- /data/data/####/cn.jpush.serverconfig.xml
- /data/data/####/com.touch18.glxbwysw.app_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/forum_infolist_page0_data11899_0.txt
- /data/data/####/glxbwy_BannerData.txt
- /data/data/####/index
- /data/data/####/jiagu.lock
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/libjiagu.so
- /data/data/####/mobclick_agent_header_com.touch18.glxbwysw.app.xml
- /data/data/####/mobclick_agent_state_com.touch18.glxbwysw.app.xml
- /data/data/####/openudid_prefs.xml
- /data/data/####/rep.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.nomedia
- /data/media/####/.push_deviceid
- /data/media/####/549ol04b5pkgxqt9wgjo8zvx8
- /data/media/####/5bej5dhlo2xayw5ymll3bdiy1
- /data/media/####/69a57n9x08c26wgzly150l6uj
- /data/media/####/s5fpphxopedsr4brffdfxcgv
- jiagu
- jpush164
- libjiagu