La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Adware.Gexin.356

Aggiunto al database dei virus Dr.Web: 2018-07-19

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) t####.me####.com:80
  • TCP(HTTP/1.1) sh####.360t####.com:80
  • TCP(HTTP/1.1) up####.sdk.jig####.cn:80
  • TCP(HTTP/1.1) qos.l####.360.cn:80
  • TCP(HTTP/1.1) p3.q####.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) m3.s.3####.cn:80
  • TCP(HTTP/1.1) api.k.36####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) s####.s.360.cn:80
  • TCP(HTTP/1.1) p1.q####.com:80
  • TCP(HTTP/1.1) u.api.l####.####.cn:80
  • TCP(HTTP/1.1) ab####.m.s.####.cn:80
  • TCP(HTTP/1.1) amdc####.m.ta####.com:80
  • TCP(HTTP/1.1) sni.c####.q####.####.net:80
  • TCP(HTTP/1.1) sdk.l####.360.cn:80
  • TCP(HTTP/1.1) p.s.3####.cn:80
  • TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
  • TCP(HTTP/1.1) p4.q####.com:80
  • TCP(HTTP/1.1) s####.l####.360.####.com:80
  • TCP(HTTP/1.1) k####.36####.com:80
  • TCP(HTTP/1.1) res.qhup####.com:80
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP(TLS/1.0) t####.me####.com:443
  • TCP(TLS/1.0) app.k.36####.com:443
  • TCP(TLS/1.0) mdm.ope####.360.cn:443
  • TCP(TLS/1.0) 2####.107.1.97:443
  • TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
  • TCP(TLS/1.0) s####.tf.360.cn:443
  • TCP(TLS/1.0) sdkc####.e.360.cn:443
  • TCP(TLS/1.0) cc.p####.dc.####.cn:443
  • TCP(TLS/1.0) api####.me####.com:443
  • TCP(TLS/1.0) s####.j####.cn:443
  • TCP c####.g####.ig####.com:5225
  • TCP sdk.o####.t####.####.com:5224
  • TCP 1####.121.49.70:7007
  • TCP 1####.163.230.182:80
  • TCP umengj####.m.ta####.com:80
  • UDP s.j####.cn:19000
  • TCP ope####.m.ta####.com:443
DNS requests:
  • 7j####.c####.z0.####.com
  • a####.man.aliy####.com
  • ab####.m.s.####.cn
  • ag####.m.ta####.com
  • amdc####.m.ta####.com
  • api####.me####.com
  • api.k.36####.com
  • app.k.36####.com
  • app.v.k.####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cc.p####.dc.####.cn
  • k####.36####.com
  • m3.s.3####.cn
  • mdm.ope####.360.cn
  • msg.umengc####.com
  • mt####.go####.com
  • p.s.3####.cn
  • p0.q####.com
  • p1.q####.com
  • p1.q####.com
  • p10.qhi####.com
  • p15.q####.com
  • p2.q####.com
  • p3.q####.com
  • p4.q####.com
  • p5.q####.com
  • p6.q####.com
  • p7.q####.com
  • p8.q####.com
  • p9.q####.com
  • plb####.u####.com
  • pub-####.qin####.com
  • qos.l####.360.cn
  • res.qhup####.com
  • s####.j####.cn
  • s####.l####.360.cn
  • s####.s.360.cn
  • s####.tf.360.cn
  • s.j####.cn
  • sdk.c####.ig####.com
  • sdk.l####.360.cn
  • sdk.l####.360.cn
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sdkc####.e.360.cn
  • sh####.360t####.com
  • sh####.me####.com
  • t####.me####.com
  • u####.u####.com
  • u.api.l####.####.cn
  • umen####.m.ta####.com
  • umengj####.m.ta####.com
  • up####.sdk.jig####.cn
HTTP GET requests:
  • ab####.m.s.####.cn/abtest/cloud.so?appkey=####&dt=####&os=####&ov=####&m...
  • k####.36####.com//k2/appconfig/getjar?appid=####&m=####&m2=####&ch=####&...
  • k####.36####.com/hotrizon2/appConfig?os=####&use_gear=####&time=####&sys...
  • k####.36####.com/hotrizon2/authorlist?pageSize=####&appid=####&curQid=##...
  • k####.36####.com/hotrizon2/channelnew?m2=####&appid=####&m=####&ch=####&...
  • k####.36####.com/hotrizon2/detail?os=####&requestNum=####&sys=####&appid...
  • k####.36####.com/hotrizon2/list?svc=####&kw=####&os=####&ckw=####&sys=##...
  • k####.36####.com/hotrizon2/list?svc=####&os=####&sys=####&direction=####...
  • k####.36####.com/hotrizon2/myfollower?appid=####&maxOffset=####&m=####&m...
  • k####.36####.com/hotrizon2/play?id=####&m2=####&strategy=####&appid=####...
  • k####.36####.com/hotrizon2/play?os=####&userclick=####&sys=####&appid=##...
  • k####.36####.com/hotrizon2/relate?os=####&sys=####&columns=####&appid=##...
  • k####.36####.com/hotrizon2/topic/detail?id=####&appid=####&cdn_url=####&...
  • k####.36####.com/k2/api/privacy/config?appid=####&m=####&m2=####&ch=####...
  • k####.36####.com/k2/appconfig/getAbRole?os=####&time=####&sys=####&m2=##...
  • k####.36####.com/k2/appconfig/getNewinfo?appid=####&m=####&m2=####&ch=##...
  • k####.36####.com/k2/appconfig/getRedpackPop?appid=####&m=####&m2=####&ch...
  • k####.36####.com/k2/appconfig/getplugin?appid=####&m=####&m2=####&ch=###...
  • k####.36####.com/k2/appconfig/getpopup?appid=####&m=####&m2=####&ch=####...
  • k####.36####.com/k2/hotrizon2/aconfig?appid=####&m=####&m2=####&ch=####&...
  • k####.36####.com/k2/hotrizon2/gettime?os=####&sys=####&m2=####&appid=###...
  • p1.q####.com/dr/_100_70/t012fa7c5b9faadaf76.jpg
  • p1.q####.com/dr/_100_70/t01326589796ae8d615.png
  • p1.q####.com/dr/_100_70/t0149f69c04efab9975.jpg
  • p1.q####.com/dr/_100_70/t014c511eabec5d2cf7.jpg
  • p1.q####.com/dr/_100_70/t016012c525ec7ca449.jpg
  • p1.q####.com/dr/_100_70/t016b84558bc06685e9.jpg
  • p1.q####.com/dr/_100_70/t016e93b5963ca5885b.png
  • p1.q####.com/dr/_100_70/t016f90fb89c1d7be15.jpg
  • p1.q####.com/dr/_100_70/t017177f2f146c15315.jpg
  • p1.q####.com/dr/_100_70/t017b94e48cf09597f3.jpg
  • p1.q####.com/dr/_100_70/t01baabadead5d72453.jpg
  • p1.q####.com/dr/_100_70/t01c697f85f876adeb8.jpg
  • p1.q####.com/dr/_280_50/t013cd050825de14fb3.webp
  • p1.q####.com/dr/_280_50/t01d634b47e5ecbda98.webp
  • p1.q####.com/dr/_280_50/t01f2fd5f55ec79ebc5.webp
  • p1.q####.com/dr/_280_50/t01fa605889803548cf.webp
  • p1.q####.com/t01153c265593f3258e.jpg
  • p1.q####.com/t01462cf7b991326f0c.png
  • p1.q####.com/t0147eeb331a280d627.jpg
  • p1.q####.com/t0178bccfe750f110a1.jpg
  • p1.q####.com/t0189d354d45e711896.png
  • p1.q####.com/t018a091efca6865662.jpg
  • p1.q####.com/t019394dd4b2d1e1505.jpg
  • p1.q####.com/t019f6478307ad0eea6.jpg
  • p1.q####.com/t01c284e24d09f6b14d.jpg
  • p1.q####.com/t01f24c635cf1cf4cbf.jpg
  • p1.q####.com/video/568_320_70/t0105af1c6cf833fdf2.webp
  • p1.q####.com/video/568_320_70/t0106eebd17676d36f9.webp
  • p1.q####.com/video/568_320_70/t0116f9491f61ca0c6c.webp
  • p1.q####.com/video/568_320_70/t0117ba6a78bb54c958.webp
  • p1.q####.com/video/568_320_70/t011998b9a0d3a2775b.webp
  • p1.q####.com/video/568_320_70/t0131e369d4822d5246.webp
  • p1.q####.com/video/568_320_70/t0132a709e90d5a248f.webp
  • p1.q####.com/video/568_320_70/t01390301edeeb9c0f0.webp
  • p1.q####.com/video/568_320_70/t013cada9fa58786fd7.webp
  • p1.q####.com/video/568_320_70/t01455f6d2497c6678b.webp
  • p1.q####.com/video/568_320_70/t014750c5587a77c620.webp
  • p1.q####.com/video/568_320_70/t01480608d44eb94513.webp
  • p1.q####.com/video/568_320_70/t014b25d8ff68ac5e80.webp
  • p1.q####.com/video/568_320_70/t014ba49b04106cbb40.webp
  • p1.q####.com/video/568_320_70/t01568e33572661bf20.webp
  • p1.q####.com/video/568_320_70/t0169ce45f777cc43a4.webp
  • p1.q####.com/video/568_320_70/t016adcb68d21d02996.webp
  • p1.q####.com/video/568_320_70/t016d8165dbb6edeb8c.webp
  • p1.q####.com/video/568_320_70/t0178d32a57b7940a18.webp
  • p1.q####.com/video/568_320_70/t01790a675daafb0371.webp
  • p1.q####.com/video/568_320_70/t0180a650eda707e07f.webp
  • p1.q####.com/video/568_320_70/t01844c425129839941.webp
  • p1.q####.com/video/568_320_70/t0199e80fba7e005b39.webp
  • p1.q####.com/video/568_320_70/t01a00a54e9cfa56124.webp
  • p1.q####.com/video/568_320_70/t01b270d0df290b4adf.webp
  • p1.q####.com/video/568_320_70/t01b432e75e64f5529c.webp
  • p1.q####.com/video/568_320_70/t01b523e1ba77043667.webp
  • p1.q####.com/video/568_320_70/t01baaadb701e72bc52.webp
  • p1.q####.com/video/568_320_70/t01bc857a16f198035c.webp
  • p1.q####.com/video/568_320_70/t01c18bd309e1f82898.webp
  • p1.q####.com/video/568_320_70/t01cb805c4f6a5b9de8.webp
  • p1.q####.com/video/568_320_70/t01cfb53d81b15f1ace.webp
  • p1.q####.com/video/568_320_70/t01d197316cc6a81a34.webp
  • p1.q####.com/video/568_320_70/t01d1a28186ca7dd351.webp
  • p1.q####.com/video/568_320_70/t01d1f534c82faee036.webp
  • p1.q####.com/video/568_320_70/t01e243a4d3a248e846.webp
  • p1.q####.com/video/568_320_70/t01f2fd5f55ec79ebc5.webp
  • p1.q####.com/video/568_320_70/t01fe22737b3757b478.webp
  • p3.q####.com/dr/_100_70/t010d44a5c30eace11d.png
  • p3.q####.com/dr/_100_70/t013973222a49091817.jpg
  • p3.q####.com/dr/_100_70/t013e5fb5fcbb00e16a.jpg
  • p3.q####.com/dr/_100_70/t01450b5370bc7038ac.jpg
  • p3.q####.com/dr/_100_70/t01617466b815f87167.jpg
  • p3.q####.com/dr/_100_70/t016e4122f7af851377.jpg
  • p3.q####.com/dr/_100_70/t01877e70e4c2cbbf8b.jpg
  • p3.q####.com/dr/_100_70/t01a8517ea618dfd515.jpg
  • p3.q####.com/dr/_100_70/t01b8f6653ac702884a.jpg
  • p3.q####.com/dr/_100_70/t01f7dfa9a24befb325.png
  • p3.q####.com/t013db82533aa9e5a9a.jpg
  • p3.q####.com/t01895341e0317eb44d.png
  • p3.q####.com/t018b8da39d8f222ada.png
  • p3.q####.com/t01ae70f3f6372b712d.jpg
  • p3.q####.com/t01e69681fa8d4220ab.jpg
  • p3.q####.com/t01f9458c7931fe73bc.jpg
  • p3.q####.com/video/568_320_70/t010638111045459001.webp
  • p3.q####.com/video/568_320_70/t01517172a0386d3742.webp
  • p3.q####.com/video/568_320_70/t01c79e2c32bc66f65d.webp
  • p4.q####.com/dr/_100_70/t011ec559cd96d84bcf.jpg
  • p4.q####.com/dr/_100_70/t014966ace5f392d429.jpg
  • p4.q####.com/dr/_100_70/t016bd4a569c6fb59a7.jpg
  • p4.q####.com/dr/_100_70/t0181468424c7f200a7.jpg
  • p4.q####.com/dr/_100_70/t01b121fd2c9c01cea6.jpg
  • p4.q####.com/t01143607e913214ebe.png
  • p4.q####.com/t01c1ff533a19145140.jpg
  • p4.q####.com/video/568_320_70/t01023d6976cc30809e.webp
  • p4.q####.com/video/568_320_70/t0103ed7c4643ef294e.webp
  • p4.q####.com/video/568_320_70/t0105fedd225d0ad18f.webp
  • p4.q####.com/video/568_320_70/t010750e79e08bc38d5.webp
  • p4.q####.com/video/568_320_70/t0111b898d906c43c04.webp
  • p4.q####.com/video/568_320_70/t01218e01d1dd9af35c.webp
  • p4.q####.com/video/568_320_70/t012d9a7a66f9dcd322.webp
  • p4.q####.com/video/568_320_70/t0136a920430fe447bd.webp
  • p4.q####.com/video/568_320_70/t013cd050825de14fb3.webp
  • p4.q####.com/video/568_320_70/t01563f3ed4a98fb463.webp
  • p4.q####.com/video/568_320_70/t015caa57cdcdea69b2.webp
  • p4.q####.com/video/568_320_70/t01688dac84a0b02336.webp
  • p4.q####.com/video/568_320_70/t01972dee8eabeb3fc5.webp
  • p4.q####.com/video/568_320_70/t01a1153c3253f475e5.webp
  • p4.q####.com/video/568_320_70/t01a5ee219df2702834.webp
  • p4.q####.com/video/568_320_70/t01ab05566136d134b6.webp
  • p4.q####.com/video/568_320_70/t01b3ff7c94e312ed84.webp
  • p4.q####.com/video/568_320_70/t01b7c99f613629535c.webp
  • p4.q####.com/video/568_320_70/t01bc7c1a472ed24f5c.webp
  • p4.q####.com/video/568_320_70/t01c2bc188c1a41483f.webp
  • p4.q####.com/video/568_320_70/t01cbeba12d6e6d98b5.webp
  • p4.q####.com/video/568_320_70/t01d634b47e5ecbda98.webp
  • p4.q####.com/video/568_320_70/t01d634fb78c1d8a705.webp
  • p4.q####.com/video/568_320_70/t01e4f92888d4f9da30.webp
  • p4.q####.com/video/568_320_70/t01f18e71f3693f7ae6.webp
  • p4.q####.com/video/568_320_70/t01f78edbb5eac2c679.webp
  • p4.q####.com/video/568_320_70/t01fa605889803548cf.webp
  • qos.l####.360.cn/vc.gif?&bid=####&pid=####&ver=####&c_ver=####&os=####&m...
  • res.qhup####.com/360reader/disp.gif?uid=411b8e6b4e089d595f860e0777223956...
  • s####.l####.360.####.com/Object.getFile/livecloudsdk/YW5kcm9pZF9wbHVnaW5...
  • s####.l####.360.####.com/Object.getFile/livecloudsdk/cGx1Z2luX3lmX3AycF8...
  • s####.s.360.cn/ak/6766aa2750c19aad2fa1b32f36ed4aee.html?m2=####
  • s####.s.360.cn/su/index.php?k=####&av=####&slv=####&sv=####&be=####&cv=#...
  • sdk.l####.360.cn/codec?os=####&tm=####&model=####&r=####&package=####&pi...
  • sdk.l####.360.cn/rtc?os=####&tm=####&model=####&r=####&package=####&pid=...
  • sdk.l####.360.cn/sdkconf/videoplace?sign=####&u=####&version=####&sdk_ve...
  • sdk.l####.360.cn/xinxiliu_tv_android_10228.conf?os=####&tm=####&r=####&p...
  • sh####.360t####.com/171122/c867c6e2f627a813302a3a0d0d891203/FZLTHK.TTF
  • sni.c####.q####.####.net/config/hz-hzv3.conf
  • sni.c####.q####.####.net/tdata_jVg168
  • sni.c####.q####.####.net/tdata_pSF696
  • t####.c####.q####.####.com/tdata_EDT356
  • u.api.l####.####.cn/comment/hot?client_id=####&url=####&page_key=####&fr...
  • u.api.l####.####.cn/comment/lists?client_id=####&url=####&type=####&star...
HTTP POST requests:
  • amdc####.m.ta####.com/amdc/mobileDispatch?appkey=####&deviceId=####&plat...
  • api.k.36####.com/k2/api/lockscreen/config?os=####&time=####&sys=####&m2=...
  • c-h####.g####.com/api.php?format=####&t=####
  • k####.36####.com/hotrizon2/report2?os=####&time=####&sys=####&m2=####&ap...
  • k####.36####.com/k2/appconfig/getjarlist?appid=####&curEnv=####&m=####&m...
  • k####.36####.com/k2/hotrizon2/getSInfo?os=####&sys=####&psw2=Li####&ssid...
  • m3.s.3####.cn/api/v1/newid
  • p.s.3####.cn/pstat/plog.php
  • p.s.3####.cn/update/update.php?p=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
  • t####.me####.com/adsdk?pver=####&skey=AB####
  • u.api.l####.####.cn/comment/lists
  • up####.sdk.jig####.cn/v1/push/sdk/postlist
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/2033145970-602345128
  • /data/data/####/5204fe4a-dad6-4f78-b0fb-f81d080188b6
  • /data/data/####/6ea2d07d-728a-4242-8a4e-089391b47455
  • /data/data/####/7ec46584-19c5-4d25-9c36-00046b8e6d88
  • /data/data/####/8c87839ccb4b
  • /data/data/####/ACCS_BINDumeng;5a56c9198f4a9d0c2f0001a8.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alliance.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/MENU_CACHE.xml
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/PendantConfig.xml
  • /data/data/####/QHA_JSON_PERSISTER_42998cf32d552343bc8e460416382dca
  • /data/data/####/QHDeviceFile
  • /data/data/####/QHDeviceID.lock
  • /data/data/####/QH_DeviceSDK.xml
  • /data/data/####/QH_SDK_M2.xml
  • /data/data/####/QH_SDK_UserData42998cf32d552343bc8e460416382dca.xml
  • /data/data/####/QH_SDK_UserData6766aa2750c19aad2fa1b32f36ed4aee.xml
  • /data/data/####/QH_SDK_sessionID42998cf32d552343bc8e460416382dca.xml
  • /data/data/####/TAB_CACHE.xml
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/Y29tLmxpZ2h0c2t5LnZpZGVv.tick.lock
  • /data/data/####/a177c961-3329-4389-81b9-f98701a7f78b
  • /data/data/####/a20400f2-76f1-4889-bf8c-b07f283c2768
  • /data/data/####/a2ac51b6-8a2f-4e51-b784-b356fd3fa357
  • /data/data/####/ab_test_config.xml
  • /data/data/####/ab_test_config.xml.bak
  • /data/data/####/abtest_base_sp_filename42998cf32d552343bc8e4604...ca.xml
  • /data/data/####/accs.db-journal
  • /data/data/####/ad_config_file.xml
  • /data/data/####/agoo.pid
  • /data/data/####/android_player_20180719_125039_000.log_0
  • /data/data/####/appPackageNames_v2
  • /data/data/####/app_globel_config_file.xml
  • /data/data/####/auth_guide_config_sdk.xml
  • /data/data/####/banner.db-journal
  • /data/data/####/cache.ttf
  • /data/data/####/channel_webview.db-journal
  • /data/data/####/cloud_config_file.xml
  • /data/data/####/cloud_push_config_file.xml
  • /data/data/####/cloud_switch_cache
  • /data/data/####/cn.jpush.android.user.profile.xml
  • /data/data/####/cn.jpush.preferences.v2.rid.xml
  • /data/data/####/cn.jpush.preferences.v2.xml
  • /data/data/####/com.qihoo.livecloud.settings.GPWebrtcSettings.pref.xml
  • /data/data/####/core_update
  • /data/data/####/core_update_locker
  • /data/data/####/critical_service_config.xml
  • /data/data/####/daemon_webview.db-journal
  • /data/data/####/dbfocus-journal
  • /data/data/####/device_collector
  • /data/data/####/device_collector_locker
  • /data/data/####/download-journal
  • /data/data/####/dso_deps
  • /data/data/####/dso_lock
  • /data/data/####/dso_manifest
  • /data/data/####/dso_state
  • /data/data/####/eb2053dc-f907-413d-8597-6b8ae024741a
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/finalcore.jar
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/hotrizon_sharepref.xml
  • /data/data/####/http_cookie.xml
  • /data/data/####/httpdns_config_cache.xml
  • /data/data/####/i==1.2.0&&1.2.28_1532004604457_envelope.log
  • /data/data/####/info.xml
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/jpush_device_info.xml
  • /data/data/####/jpush_local_notification.db
  • /data/data/####/jpush_local_notification.db-journal
  • /data/data/####/jpush_local_notification.db-wal
  • /data/data/####/jpush_stat_cache.json
  • /data/data/####/jpush_stat_cache_history.json
  • /data/data/####/jpush_statistics.db
  • /data/data/####/jpush_statistics.db-journal
  • /data/data/####/jpush_statistics.db-shm (deleted)
  • /data/data/####/jpush_statistics.db-wal
  • /data/data/####/jpushservice_webview.db-journal
  • /data/data/####/libdvrender.so.tmp
  • /data/data/####/libjiagu-71411075.so
  • /data/data/####/libjplayer.so.tmp
  • /data/data/####/liblocalserver.so.tmp
  • /data/data/####/libmyssl.so.1.1.tmp
  • /data/data/####/libtranscore.so.tmp
  • /data/data/####/libviewer.so.tmp
  • /data/data/####/libyfnet_360.so.tmp
  • /data/data/####/light_sky_avast.xml
  • /data/data/####/localserver_2.0.3.18042602.zip
  • /data/data/####/locker
  • /data/data/####/log_reupload_task
  • /data/data/####/log_reupload_task_locker
  • /data/data/####/message.db-journal
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/msg_queue
  • /data/data/####/msplugin_ksp.xml
  • /data/data/####/multidex.version.xml
  • /data/data/####/p.l
  • /data/data/####/player_20180719_125039_000.log_0
  • /data/data/####/player_record_2.0.3.18051401.zip
  • /data/data/####/privacy_config_file.xml
  • /data/data/####/profile_task
  • /data/data/####/profile_task_locker
  • /data/data/####/profile_torch_platform
  • /data/data/####/push.db-journal
  • /data/data/####/push.pid
  • /data/data/####/push_share.xml
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/qhvc_plugin.xml
  • /data/data/####/qhvc_plugin.xml.bak
  • /data/data/####/qpush_msg.xml
  • /data/data/####/run.pid
  • /data/data/####/safe_user_info_file.xml
  • /data/data/####/screen_conf.xml
  • /data/data/####/session_base_sp_filename42998cf32d552343bc8e460...ca.xml
  • /data/data/####/session_base_sp_filenameandroidID.xml
  • /data/data/####/share_data.xml
  • /data/data/####/shortcut_badger_sharepref.xml
  • /data/data/####/sp.livecloud.database.xml
  • /data/data/####/sp_file_recommend_upload.xml
  • /data/data/####/tab_request_name.xml
  • /data/data/####/tdata_jVg168
  • /data/data/####/tdata_jVg168.jar
  • /data/data/####/tdata_pSF696
  • /data/data/####/tdata_pSF696.jar
  • /data/data/####/tools_2.0.3.18051401.zip
  • /data/data/####/torch_sdk_config.xml
  • /data/data/####/trans_20180719_125039_000.log_0
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/umeng_message_state.xml
  • /data/data/####/uninstall_apk
  • /data/data/####/uninstall_apk_locker
  • /data/data/####/universalPopup.xml
  • /data/data/####/videolist.db-journal
  • /data/data/####/waitingDown
  • /data/data/####/waitingDown_locker
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/yf_p2p_201804191558.zip
  • /data/media/####/-ON90yxCRhrFxZwjF2yKneeGjzw.1224539678.tmp
  • /data/media/####/-Xn3qeh86J5z4uv0xW10mHU8rCg.-1993405230.tmp
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.deviceId
  • /data/media/####/.iddata
  • /data/media/####/.nomedia
  • /data/media/####/.push_deviceid
  • /data/media/####/.sfp
  • /data/media/####/.testf
  • /data/media/####/.umm.dat
  • /data/media/####/087373469f0c47b8b15390853b5fcf27
  • /data/media/####/1Ok9itRz2euz1vfbYZJMUVE4I2U.255625716.tmp
  • /data/media/####/1lyguS3YHNq8IhR6N-ofGmazqe8.-658757456.tmp
  • /data/media/####/2XSmBmvf4ZDTyEtfbNBUYyzBQUg.-1992589725.tmp
  • /data/media/####/3On0fTsebiRW4NXKueeyJdyTKZw.865166475.tmp
  • /data/media/####/42998cf32d552343bc8e460416382dca
  • /data/media/####/48cf916e5d8344f9ba15fb8cf2f63bfb
  • /data/media/####/5UR91GU6P5kJZI0r34fctFGM9hw.-1473775885.tmp
  • /data/media/####/65ummpGUBsIa4sd_y3WOosmLq5k.-1997378862.tmp
  • /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee
  • /data/media/####/6VzzC07JSEQODUKPvcU_1em1xjk.901569830.tmp
  • /data/media/####/6ZKBs5YBEYwT_44D5Ig797LP4l0.-1078302813.tmp
  • /data/media/####/6uKuvbjAPMP766Id6j52X6PhPg0.1687116154.tmp
  • /data/media/####/7X82E9lDEAwIOxu3pMnxs8BprFY.-1760195739.tmp
  • /data/media/####/7eh
  • /data/media/####/7eh (deleted)
  • /data/media/####/82m9X_dT8zLY-1Tm74cwbwxKzeY.574277171.tmp
  • /data/media/####/8XuJaHPyumjhSQwbXCAg57uFzps.-2006720346.tmp
  • /data/media/####/9CX
  • /data/media/####/9CX (deleted)
  • /data/media/####/9rxP1CRHUAjkte1CQZPQX-anZQQ.9267623.tmp
  • /data/media/####/A8T-zV5rkp7GDZqhO3WTVnSX1j0.454283815.tmp
  • /data/media/####/A_qyxeNYKyUYpMicvDMXE5O0VJo.-1626205977.tmp
  • /data/media/####/Alvin2.xml
  • /data/media/####/AvVevOYCmrf-trWcum33Sh62saI.-2112907484.tmp
  • /data/media/####/B2v
  • /data/media/####/B2v (deleted)
  • /data/media/####/B3ErNLN_x1erb7dDPqo_t5SOKIA.402391217.tmp
  • /data/media/####/ContextData.xml
  • /data/media/####/Eeur8WLRMS1dCE3AxP8RUQn7EjM.762725475.tmp
  • /data/media/####/FDmR_5NfHNV6jF5QtiSqGeaMbkM.-826421118.tmp
  • /data/media/####/FJzYo6v5bcSbie7rv-mf4Gg9avk.-622003570.tmp
  • /data/media/####/FjQNhLhS4Rt_T-kViETsHxrtCoM.-523208661.tmp
  • /data/media/####/GVWQR7lu4-Fe3in3bmVlJbZt5sY.818682599.tmp
  • /data/media/####/G_dquEycJf7Y2-ie1T2rVVhIcVs.-961030966.tmp
  • /data/media/####/Gi237f0nHbG7g4WiRB3nDuAgYcE.-1430976504.tmp
  • /data/media/####/H2UszZQCp-Q2yHK3To419Y72OKk.1583022629.tmp
  • /data/media/####/H_KahYJn0oLL3DeQ-W2rtRXQYsk.167123226.tmp
  • /data/media/####/HbkGN8WWFwC2VlT4T_E7B5oOJJ8.-234593711.tmp
  • /data/media/####/HfRofvR3BJT1ZIwtO9JuY--7TaI.309823725.tmp
  • /data/media/####/JFgYHGgr_Z0a57pxbFP0qQ5UaWo.1416252327.tmp
  • /data/media/####/JYamYJgOeRQdBwME6q3cz-B03d8.-25623988.tmp
  • /data/media/####/JaeS8_Mmc3s3vdtMJA_5D80KgbQ.-766358558.tmp
  • /data/media/####/KqGMUVfFEHGRdok73l2DBm4VhWA.393548225.tmp
  • /data/media/####/L2LGfCH7SBiGPiW5tuuLgfHeXiQ.2085299585.tmp
  • /data/media/####/LClUXArwIWvPr10uaahGtjOb13Y.-1110252550.tmp
  • /data/media/####/LXQ
  • /data/media/####/LXQ (deleted)
  • /data/media/####/LkUUKhlO3HiCsc_52aFRiCGiXkI.-1311000149.tmp
  • /data/media/####/Lpvcyn31d83DOfKdVQEwWcqtItY.-275280669.tmp
  • /data/media/####/MAZY5aEci3sxXHBBkXofXV6SYrU.1560413837.tmp
  • /data/media/####/MVTavA2fx9SgZemMzAj7rN58SYY.1584867369.tmp
  • /data/media/####/MdzkIMMnw-Pqb_s9BIRWUNs4v1g.-740010561.tmp
  • /data/media/####/MgMySUuczp5rOoAQQirp-LLvPlI.1666837826.tmp
  • /data/media/####/MixYQ_mnchBm9ZMy13rDCKVS6h8.479388759.tmp
  • /data/media/####/MtGi6s6barfMGDextXuiJyvmpg0.-1576022796.tmp
  • /data/media/####/NA_q3HSf8OmtPnscmd7lUsxYHY4.137656875.tmp
  • /data/media/####/NhinU5eNjAEdIbkfs-2qVA6dlag.-1111684813.tmp
  • /data/media/####/O5Q5kIU7-0JTlquzdMXicXaPML8.553505374.tmp
  • /data/media/####/OBsFdNaPqU7Efx_jWRsSbOorSBk.1302332943.tmp
  • /data/media/####/OVoaoFqZq0GwTTYV9vImPJs0TLc.2134086279.tmp
  • /data/media/####/Oqp-WKCkhPA2Ah5EwcXn_0rsJIk.297324592.tmp
  • /data/media/####/Pvr1OhOXX0G_Hlpa5qu-fujdlrg.1279099754.tmp
  • /data/media/####/QA1VCzu-2WK33yAFlrSOxhJBtfc.10767883.tmp
  • /data/media/####/QE8_QVQkExUu9qszNowDZnzZVtY.-880960551.tmp
  • /data/media/####/QHiQFm80p8FYYjoAoIYkQB0OP5A.-1287076576.tmp
  • /data/media/####/QjGFQphNT7rPODIud0PoSj-AVcE.-664366902.tmp
  • /data/media/####/Qt6RAt3fQzVpYav-E6MTKs3Jwo8.-1844208673.tmp
  • /data/media/####/SLYekV_xKZ6pyuMxVh-GNE_BlzI.1003825359.tmp
  • /data/media/####/SSYsvc1dH3kwNpW5WgxKEBEapAI.-183816437.tmp
  • /data/media/####/T-_PaRsTM5mniKRtfrE3JbvT6yI.156293130.tmp
  • /data/media/####/T1VSyrH4R_rSOvV12SWta4xSmUE.-1032775798.tmp
  • /data/media/####/TZhPjEY8Xr5whtY-IIy3tLzAIyc.876394882.tmp
  • /data/media/####/U8EtPDEMv9K4aAVB26h9VpKtsd4.1994860383.tmp
  • /data/media/####/UCP1DQbbj44zP6r7mEV3lHloq8o.1476332398.tmp
  • /data/media/####/Uz0b4GYvKvpDrIlEntlSs1iOgE0.1360351781.tmp
  • /data/media/####/VVE6oN4OggNpl7Klr6BcacCg87k.-535977371.tmp
  • /data/media/####/WQXPSreC8N7seWxzTri4zv8FWkg.-2059494266.tmp
  • /data/media/####/WYyIhksfybSdr2grMzvle2mm4Y8.-2019636861.tmp
  • /data/media/####/WnNTGFE3I_z6L9MXoMwSRQKKRbw.2128318414.tmp
  • /data/media/####/XKBAFTsI1oX2tlDzhYuvCaTZ2bI.1175615835.tmp
  • /data/media/####/Xd6
  • /data/media/####/Xd6 (deleted)
  • /data/media/####/XkXaMREavbb9ZZyba_FdEPHjMv8.2080375957.tmp
  • /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv
  • /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv (deleted)
  • /data/media/####/ZVk3dN9t-CLxQvvMJU3dPhRdxCE.1778816898.tmp
  • /data/media/####/ZxUq0N9-Rbllz9oEVZRnANJEV8E.157413632.tmp
  • /data/media/####/_Q3-bcW5YW1vQ3GxJY79vudilaY.-1921289974.tmp
  • /data/media/####/__VERSION__
  • /data/media/####/_bb8Kr7DPnlnm-9yfOjAsfa0-bo.1547580659.tmp
  • /data/media/####/_yyYk1sPFj2njmB4OczoZzruL-0.-740122655.tmp
  • /data/media/####/app.db
  • /data/media/####/avast_done
  • /data/media/####/b05ce39c1fe9e72dc1df70989e7e6d14
  • /data/media/####/b4FioJsTDGR590UnvNGxpdFLnqI.-2120765805.tmp
  • /data/media/####/b7f6edbd688d4945a8cf887e89b5f110
  • /data/media/####/bOLOb23yGFBElW1lMHuxtcwiNh4.-442290397.tmp
  • /data/media/####/bTHepyjO3w2N5fDSx_nkKdCNI1M.-2003020736.tmp
  • /data/media/####/bhaR7_4zzPCLAhTQP8WcVCZF6Xo.1078187187.tmp
  • /data/media/####/c4dab50e92cf43f9a615e1ba6e953ce3
  • /data/media/####/cHHBXyRLqJdPTuPku3bx0hbZ4FE.531747864.tmp
  • /data/media/####/chletZC5hHBH_uUuw0wALrDanBk.-1759670705.tmp
  • /data/media/####/cjfoyemieg26Tnxf_3as8SBLa2o.-966702781.tmp
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.lightsky.video.bin
  • /data/media/####/com.lightsky.video.db
  • /data/media/####/data.lock
  • /data/media/####/deviceToken
  • /data/media/####/dxIZFeNU9f7xXMaUcvqjavwefzY.-2144473442.tmp
  • /data/media/####/e-zEG_As-Civbmh9XBgTMmXekRk.-900722799.tmp
  • /data/media/####/eysKqYJalJ-qMY3zLe_9miu8o-8.2084254256.tmp
  • /data/media/####/fqlPeLiuNJonxopSv9tb3zauOAw.112398074.tmp
  • /data/media/####/gpWYEYvmxIISZvIaz54alkFhPSk.1418827418.tmp
  • /data/media/####/gx8zQ0Do5CJRwABnVzti6L7P4hM.-931367237.tmp
  • /data/media/####/hRfoR0jJ0OYeIpeJ5JQ032lGzrs.1246305111.tmp
  • /data/media/####/iAfdr91kvrB1-iDUQKlRbNz5gcc.-1869962669.tmp
  • /data/media/####/ioFM-vKN3S5REaA5SeWqfsepIKc.350878076.tmp
  • /data/media/####/jGRMiJw_rlOvHfduc1hlwU89WpU.1136038629.tmp
  • /data/media/####/jcSAOr9jGZwkhQZMXMgqUBAFH0c.2070546745.tmp
  • /data/media/####/jfsw2eTILH9JzsyMfQqcUWhuCfs.-1521147499.tmp
  • /data/media/####/jiC2mvilCA_mEvRdqvOwl7mxaF0.-378426464.tmp
  • /data/media/####/kjZSdrKU6ClZwZ49zTf9tid1BHc.-1643166435.tmp
  • /data/media/####/ltemZdzsKmsJKUo5H8BlFPz47Dg.-1509613058.tmp
  • /data/media/####/mYJJcwmedpnMfdK1-VNksoUobaA.752971174.tmp
  • /data/media/####/n52K2QnaQ1v1BWCy3ETbUFJhA8Y.1749140497.tmp
  • /data/media/####/nISAIdo8iCZAXWQ4UMk6KOmoksc.260148803.tmp
  • /data/media/####/nr3pZrxeQzyZqH6_g4e9UFuZIcs.105924059.tmp
  • /data/media/####/oOqVRHO25rYaxG_o17TGnjseNEE.-1324000048.tmp
  • /data/media/####/oqNuiNDFd_ZpRGaGjVx2IaTTlMY.1811088454.tmp
  • /data/media/####/pdNd8OSxkMupvAp6GFxT6jbzODE.-1950852164.tmp
  • /data/media/####/qEgcO952HF85PI9EgZuAJQZcEr8.805838821.tmp
  • /data/media/####/report.lock
  • /data/media/####/rzSKaME3RVbIgPACsPv4BoEm_tk.-1330205276.tmp
  • /data/media/####/s8SBT9vNq7ahA-YHaNUnA3bhGmU.-232739348.tmp
  • /data/media/####/tdata_jVg168
  • /data/media/####/tdata_pSF696
  • /data/media/####/test.log
  • /data/media/####/ucYRmgGWASTmwYPMKZRJLcMC5XM.797875754.tmp
  • /data/media/####/un99YXwHDEyWhdqnF8uVheVEOi0.1423463732.tmp
  • /data/media/####/uninstall_apk_list
  • /data/media/####/vfeXr784-MF3pH2zRFWYMXwM97w.-1797314913.tmp
  • /data/media/####/xUm-uHLZseen7-xzU1dB1QKFots.-833190481.tmp
  • /data/media/####/xqVUO2lnZR_IdlDejpgr0aSTcEs.-1946288387.tmp
  • /data/media/####/xvzsfq2qWKsW2cJU5zE4NPDzD_E.1775129977.tmp
  • /data/media/####/yiDEbnuRI0nmWDX1xnqwPzJ32k0.-1565737354.tmp
  • /data/media/####/zGR8_ESPt7W_J-FoZN1eXYeN7nw.-983754598.tmp
  • /data/media/####/zQfjjtNOMTYnS42j1l1o3Y0aYUQ.125591529.tmp
Miscellaneous:
Executes next shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/xbin/which su
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:5a56c9198f4a9d0c2f0001a8","utdid":"W1CI+qvMIP8DAGdzx1HA0QkL","sdkVersion":"221"} -I agoodm.m.taobao.com -O 80 -T -Z
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.qihoo.qpush.sdk.GeTuiPushService 24825 300 0
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 755 <Package Folder>/.jiagu/libjiagu-71411075.so
  • ls /
  • ls /sys/class/thermal
  • mount
  • sh
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.qihoo.qpush.sdk.GeTuiPushService 24825 300 0
Loads the following dynamic libraries:
  • GPBreakpad
  • getuiext2
  • jcore120
  • libdvrender
  • libimagepipeline
  • libjiagu-71411075
  • libjplayer
  • liblocalserver
  • libtranscore
  • libviewer
  • libyfnet_360
  • tnet-3.1
Uses the following algorithms to encrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-NoPadding
  • DES
Uses elevated priveleges.
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Gains access to information about accounts (Google, Facebook, etc.) registered on the device.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android