La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Adware.Gexin.1491

Aggiunto al database dei virus Dr.Web: 2018-08-17

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) a####.exc.mob.com:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(TLS/1.0) them####.wh####.com:443
DNS requests:
  • a####.exc.mob.com
  • l####.tbs.qq.com
  • mt####.go####.com
  • them####.wh####.com
HTTP POST requests:
  • a####.exc.mob.com/errconf
  • l####.tbs.qq.com/ajax?c=####&k=####
Modified file system:
Creates the following files:
  • /data/data/####/.duid
  • /data/data/####/.jg.ic
  • /data/data/####/.lock
  • /data/data/####/.vpl_lock
  • /data/data/####/MultiDex.lock
  • /data/data/####/ThrowalbeLog.db-journal
  • /data/data/####/core_info
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/debug.conf
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/index
  • /data/data/####/libjiagu-1730835396.so
  • /data/data/####/mob_commons_1
  • /data/data/####/mob_sdk_exception_1
  • /data/data/####/multidex.version.xml
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/whrjwh.xml
  • /data/media/####/.artc_lock
  • /data/media/####/.di
  • /data/media/####/.dic_lock
  • /data/media/####/.duid
  • /data/media/####/.globalLock
  • /data/media/####/.im_lock
  • /data/media/####/.lecd
  • /data/media/####/.lesd_lock
  • /data/media/####/.mn_-1464060969
  • /data/media/####/.nomedia
  • /data/media/####/.pkg_lock
  • /data/media/####/.pkgs_lock
  • /data/media/####/.rc_lock
  • /data/media/####/.slw
  • /data/media/####/.ss_lock
  • /data/media/####/AniUpBoardCompSkin.exml
  • /data/media/####/ConfirmCompSkin.exml
  • /data/media/####/MainCompSkin.exml
  • /data/media/####/PetGridsListScrollerCompSkin.exml
  • /data/media/####/SubjectSkin.exml
  • /data/media/####/VerifyCompSkin.exml
  • /data/media/####/VersionInfo.json
  • /data/media/####/aniBoard.png
  • /data/media/####/aniBoard2.png
  • /data/media/####/aniBtn.png
  • /data/media/####/animal0.mp3
  • /data/media/####/animal0_0_0.png
  • /data/media/####/animal0_0_1.png
  • /data/media/####/animal0_0_2.png
  • /data/media/####/animal0_0_3.png
  • /data/media/####/animal1.mp3
  • /data/media/####/animal2.mp3
  • /data/media/####/animal3.mp3
  • /data/media/####/animal4.mp3
  • /data/media/####/animals_ske.json
  • /data/media/####/animals_tex.json
  • /data/media/####/animals_tex.png
  • /data/media/####/arrow.png
  • /data/media/####/back.png
  • /data/media/####/banner_c9713a1.png
  • /data/media/####/barBgBg.png
  • /data/media/####/bathBoard.png
  • /data/media/####/bathBtn.png
  • /data/media/####/bathGrid.png
  • /data/media/####/bbCloud.png
  • /data/media/####/bcAni.png
  • /data/media/####/bg.jpg
  • /data/media/####/bg0.png
  • /data/media/####/bg0112.png
  • /data/media/####/bg0_0_0.png
  • /data/media/####/bg0_0_1.png
  • /data/media/####/bg0_1_0.png
  • /data/media/####/bg0_1_0_0_0.png
  • /data/media/####/bg0_1_0_1_0.png
  • /data/media/####/bg0_1_0_1_1.png
  • /data/media/####/bg0_1_0_2_0.png
  • /data/media/####/bg0_1_0_2_1.png
  • /data/media/####/bg0_1_1.png
  • /data/media/####/bg0_1_2.png
  • /data/media/####/bg0_2_0.png
  • /data/media/####/bg0_3_0.png
  • /data/media/####/bg0_3_1.png
  • /data/media/####/bg_5a2f5212.png
  • /data/media/####/bgm.mp3
  • /data/media/####/bgm_51bcd9c7.mp3
  • /data/media/####/blast.mp3
  • /data/media/####/blast0_2_0.png
  • /data/media/####/blast0_2_1.png
  • /data/media/####/blast0_2_2.png
  • /data/media/####/blast0_2_3.png
  • /data/media/####/blast0_2_4.png
  • /data/media/####/blast0_2_5.png
  • /data/media/####/bmFont.fnt
  • /data/media/####/bmFont.png
  • /data/media/####/book.png
  • /data/media/####/book1.png
  • /data/media/####/bottom0_2_0.png
  • /data/media/####/bottom_6989a2fa.png
  • /data/media/####/box.png
  • /data/media/####/btn0.png
  • /data/media/####/btn1.png
  • /data/media/####/btn2.png
  • /data/media/####/btn3.png
  • /data/media/####/bubble.png
  • /data/media/####/burst.mp3
  • /data/media/####/button.mp3
  • /data/media/####/button_41c43e93.mp3
  • /data/media/####/buyEnter_43c628e0.mp3
  • /data/media/####/cBtn_a.png
  • /data/media/####/cBtn_b.png
  • /data/media/####/cancel.png
  • /data/media/####/cancel2.png
  • /data/media/####/car_ske.json
  • /data/media/####/car_tex.json
  • /data/media/####/car_tex.png
  • /data/media/####/chuanglian.png
  • /data/media/####/chuangliangan.png
  • /data/media/####/close.png
  • /data/media/####/closeBgUi.png
  • /data/media/####/closeFgUi.png
  • /data/media/####/cloth0.png
  • /data/media/####/cloth1.png
  • /data/media/####/cloth2.png
  • /data/media/####/cloth3.png
  • /data/media/####/cloth4.png
  • /data/media/####/clothBg.png
  • /data/media/####/clothBoard.png
  • /data/media/####/clothBtn.png
  • /data/media/####/clothGrid.png
  • /data/media/####/complete0_0_0.mp3
  • /data/media/####/confirm.png
  • /data/media/####/continue.png
  • /data/media/####/count.fnt
  • /data/media/####/count.png
  • /data/media/####/crownUi.png
  • /data/media/####/cup0.png
  • /data/media/####/dancing.mp3
  • /data/media/####/ddbb.png
  • /data/media/####/default.res.json
  • /data/media/####/default.thm.json
  • /data/media/####/description.json
  • /data/media/####/desk0_1_0_1_0.png
  • /data/media/####/dingdongCar_ske.json
  • /data/media/####/dingdongCar_tex.json
  • /data/media/####/dingdongCar_tex.png
  • /data/media/####/dingdongWord0.mp3
  • /data/media/####/dingdongWord1.mp3
  • /data/media/####/dingdong_ske.json
  • /data/media/####/dingdong_ske_2f0411f1.json
  • /data/media/####/dingdong_tex.json
  • /data/media/####/dingdong_tex.png
  • /data/media/####/dingdong_tex_3a260d16.png
  • /data/media/####/dingdong_tex_4914634d.json
  • /data/media/####/documentBg.png
  • /data/media/####/door.png
  • /data/media/####/door1.png
  • /data/media/####/door2.png
  • /data/media/####/door3.png
  • /data/media/####/doorOpen.json
  • /data/media/####/doorOpen.png
  • /data/media/####/dragonBones.js
  • /data/media/####/dragonBones.min.js
  • /data/media/####/dragon_ske.json
  • /data/media/####/dragon_tex.json
  • /data/media/####/dragon_tex.png
  • /data/media/####/dress0_1.png
  • /data/media/####/dress0_2.png
  • /data/media/####/dress1_1.png
  • /data/media/####/dress1_2.png
  • /data/media/####/dress2_1.png
  • /data/media/####/dress2_2.png
  • /data/media/####/dress3_1.png
  • /data/media/####/dress3_2.png
  • /data/media/####/dress4_1.png
  • /data/media/####/dress4_2.png
  • /data/media/####/dress5_1.png
  • /data/media/####/dress5_2.png
  • /data/media/####/eatBoard.png
  • /data/media/####/eatBtn.png
  • /data/media/####/eatGrid.png
  • /data/media/####/effect1.mp3
  • /data/media/####/effectStar.png
  • /data/media/####/egret.js
  • /data/media/####/egret.min.js
  • /data/media/####/egret.web.js
  • /data/media/####/egret.web.min.js
  • /data/media/####/egret_icon.png
  • /data/media/####/endBox.png
  • /data/media/####/endBox2.png
  • /data/media/####/endBox3.png
  • /data/media/####/endBubble.png
  • /data/media/####/endBubble2.png
  • /data/media/####/endBurst.mp3
  • /data/media/####/endStar1.json
  • /data/media/####/endStar1.png
  • /data/media/####/endStar2.json
  • /data/media/####/endStar2.png
  • /data/media/####/endStars.png
  • /data/media/####/endStars2.png
  • /data/media/####/erWeiMa.png
  • /data/media/####/error.png
  • /data/media/####/eui.js
  • /data/media/####/eui.min.js
  • /data/media/####/experimental.js
  • /data/media/####/experimental.min.js
  • /data/media/####/f0110.png
  • /data/media/####/f0111.png
  • /data/media/####/f0112.png
  • /data/media/####/f0113.png
  • /data/media/####/favicon.ico
  • /data/media/####/fish0.mp3
  • /data/media/####/fish0_0_0.png
  • /data/media/####/fish0_0_1.png
  • /data/media/####/fish0_0_2.png
  • /data/media/####/fish0_0_3.png
  • /data/media/####/fish0_0_4.png
  • /data/media/####/fish0_0_5.png
  • /data/media/####/fish0_0_6.png
  • /data/media/####/fish0_0_7.png
  • /data/media/####/fish1.mp3
  • /data/media/####/fish2.mp3
  • /data/media/####/fish3.mp3
  • /data/media/####/fish4.mp3
  • /data/media/####/fish5.mp3
  • /data/media/####/fish6.mp3
  • /data/media/####/fish7.mp3
  • /data/media/####/fishs0_0_0.png
  • /data/media/####/fishs0_0_1.png
  • /data/media/####/fishs0_0_2.png
  • /data/media/####/fishs0_0_3.png
  • /data/media/####/flower.png
  • /data/media/####/flower2.png
  • /data/media/####/fontLoading.fnt
  • /data/media/####/fontLoading.png
  • /data/media/####/fontLoading_5e199f55.fnt
  • /data/media/####/fontLoading_e9ea92c.png
  • /data/media/####/fontsRed.fnt
  • /data/media/####/fontsRed.png
  • /data/media/####/fontsRed_30dd8c73.fnt
  • /data/media/####/fontsRed_50c178dd.png
  • /data/media/####/food0.png
  • /data/media/####/food1.png
  • /data/media/####/food2.png
  • /data/media/####/food3.png
  • /data/media/####/food3_1.png
  • /data/media/####/food4.png
  • /data/media/####/food4_1.png
  • /data/media/####/foodBoard.png
  • /data/media/####/foodBtn.png
  • /data/media/####/foodGrid.png
  • /data/media/####/game.js
  • /data/media/####/game.min.js
  • /data/media/####/game0_1_1_obj0125.png
  • /data/media/####/giftBox_ske.json
  • /data/media/####/giftBox_tex.json
  • /data/media/####/giftBox_tex.png
  • /data/media/####/glass0_1_0_1_0.png
  • /data/media/####/glass0_1_0_1_1.png
  • /data/media/####/glass0_1_0_1_2.png
  • /data/media/####/glass0_1_0_1_3.png
  • /data/media/####/glass0_1_0_1_4.png
  • /data/media/####/gold.mp3
  • /data/media/####/gold.png
  • /data/media/####/goldCoin.png
  • /data/media/####/goldIcon.png
  • /data/media/####/goldStar.json
  • /data/media/####/goldStar.png
  • /data/media/####/grass0_0_0.png
  • /data/media/####/grass0_0_1.png
  • /data/media/####/guizi.png
  • /data/media/####/hand.png
  • /data/media/####/handClic.png
  • /data/media/####/handFlip.png
  • /data/media/####/head.png
  • /data/media/####/heartUi.png
  • /data/media/####/home.png
  • /data/media/####/homeBg.png
  • /data/media/####/homeBtn.png
  • /data/media/####/horse.png
  • /data/media/####/house0_1_1.png
  • /data/media/####/house0_1_2.png
  • /data/media/####/house0_1_3.png
  • /data/media/####/house0_1_4.png
  • /data/media/####/house0_1_5.png
  • /data/media/####/house0_1_6.png
  • /data/media/####/house0_1_7.png
  • /data/media/####/house0_1_8.png
  • /data/media/####/house0_1_9.png
  • /data/media/####/house0_2_1.png
  • /data/media/####/house0_2_2.png
  • /data/media/####/house0_2_3.png
  • /data/media/####/house0_2_4.png
  • /data/media/####/house0_2_5.png
  • /data/media/####/house0_2_6.png
  • /data/media/####/house0_2_7.png
  • /data/media/####/house0_2_8.png
  • /data/media/####/house0_2_9.png
  • /data/media/####/icon0_1_0_1_0.png
  • /data/media/####/icon0_1_0_1_1.png
  • /data/media/####/icon0_1_0_1_2.png
  • /data/media/####/icon0_1_0_1_3.png
  • /data/media/####/index.html
  • /data/media/####/jifen.png
  • /data/media/####/kongtoubaozha1.plist
  • /data/media/####/light.png
  • /data/media/####/lightPoi.png
  • /data/media/####/load-0sheet_1f45d9e8.png
  • /data/media/####/load-0sheet_2569ece0.json
  • /data/media/####/load-1sheet_59677dd6.json
  • /data/media/####/load-1sheet_6fa83026.png
  • /data/media/####/load-2sheet_3ce45201.png
  • /data/media/####/load-2sheet_49c0a9bd.json
  • /data/media/####/load-3sheet_645c5adb.json
  • /data/media/####/load-3sheet_e3625a4.png
  • /data/media/####/load-4sheet_6ec2ee56.png
  • /data/media/####/load-4sheet_c88d984.json
  • /data/media/####/load-5sheet_40ab593a.json
  • /data/media/####/load-5sheet_976d433.png
  • /data/media/####/load-6sheet_1b33c66e.png
  • /data/media/####/load-6sheet_765f9f07.json
  • /data/media/####/load-7sheet_1f96414f.json
  • /data/media/####/load-7sheet_342bad0b.png
  • /data/media/####/loadingBackGround.png
  • /data/media/####/loadingBar_Bg.png
  • /data/media/####/loadingBar_Fg.png
  • /data/media/####/loadingBg.png
  • /data/media/####/loadingObj1.png
  • /data/media/####/loadingObj2.png
  • /data/media/####/loadingObj3.png
  • /data/media/####/loadingObj4.png
  • /data/media/####/loadingStar.png
  • /data/media/####/loadingball.png
  • /data/media/####/loadingbg.png
  • /data/media/####/loadingyun1.png
  • /data/media/####/loadingyun2.png
  • /data/media/####/loadingyun3.png
  • /data/media/####/loadingyun4.png
  • /data/media/####/logo_ske.json
  • /data/media/####/logo_tex.json
  • /data/media/####/logo_tex.png
  • /data/media/####/lookDown.mp3
  • /data/media/####/magic.mp3
  • /data/media/####/main.min.js
  • /data/media/####/main2.min.js
  • /data/media/####/mainLight.png
  • /data/media/####/mainScene_ske.json
  • /data/media/####/mainScene_tex.json
  • /data/media/####/mainScene_tex.png
  • /data/media/####/mainTit.png
  • /data/media/####/manifest.json
  • /data/media/####/monkeyCar_ske.json
  • /data/media/####/monkeyCar_tex.json
  • /data/media/####/monkeyCar_tex.png
  • /data/media/####/moreGameBg.png
  • /data/media/####/moreGameBtn.png
  • /data/media/####/moreGameCloseBtn.png
  • /data/media/####/net0_1_0.png
  • /data/media/####/number0_2_0.png
  • /data/media/####/number0_2_1.png
  • /data/media/####/number0_2_2.png
  • /data/media/####/number0_2_3.png
  • /data/media/####/number0_2_4.png
  • /data/media/####/number0_2_5.png
  • /data/media/####/number0_2_6.png
  • /data/media/####/number0_2_7.png
  • /data/media/####/number0_2_8.png
  • /data/media/####/obj0.png
  • /data/media/####/obj0111.png
  • /data/media/####/obj0113.png
  • /data/media/####/obj0114.png
  • /data/media/####/obj0119.png
  • /data/media/####/obj0121.png
  • /data/media/####/obj0122.png
  • /data/media/####/obj0124_0.png
  • /data/media/####/obj0126.png
  • /data/media/####/obj0127.png
  • /data/media/####/obj0128.png
  • /data/media/####/obj0129.png
  • /data/media/####/obj0130.png
  • /data/media/####/obj0131.png
  • /data/media/####/obj0132.png
  • /data/media/####/obj0133.png
  • /data/media/####/obj0134.png
  • /data/media/####/obj1.png
  • /data/media/####/obj2.png
  • /data/media/####/obj3.png
  • /data/media/####/obj4.png
  • /data/media/####/othTit.png
  • /data/media/####/outBtn.png
  • /data/media/####/p3.gif
  • /data/media/####/panelBg.png
  • /data/media/####/paopao0_0_0.png
  • /data/media/####/paopao0_0_1.png
  • /data/media/####/parents.png
  • /data/media/####/particle.js
  • /data/media/####/particle.min.js
  • /data/media/####/passScene1.png
  • /data/media/####/passScene2.png
  • /data/media/####/passScene3.png
  • /data/media/####/passScene4.png
  • /data/media/####/passScene5.png
  • /data/media/####/pay-0sheet_162c02e5.png
  • /data/media/####/pay-0sheet_35c50a8d.json
  • /data/media/####/pay-1sheet_5c77dadd.json
  • /data/media/####/pay-1sheet_6d333aa3.png
  • /data/media/####/petBg.png
  • /data/media/####/pet_ske.json
  • /data/media/####/pet_ske_528beccd.json
  • /data/media/####/pet_tex.json
  • /data/media/####/pet_tex.png
  • /data/media/####/pet_tex_23b83d10.png
  • /data/media/####/pet_tex_6d5c0ec6.json
  • /data/media/####/plant.png
  • /data/media/####/preload-0sheet_2cb6dd4b.json
  • /data/media/####/preload-0sheet_ea5995e.png
  • /data/media/####/preload-1sheet_6d91fc9e.json
  • /data/media/####/preload-1sheet_c5d3ca0.png
  • /data/media/####/preload-2sheet_209c54c1.png
  • /data/media/####/preload-2sheet_b7d95cf.json
  • /data/media/####/presentation.png
  • /data/media/####/promise.js
  • /data/media/####/promise.min.js
  • /data/media/####/qipao0_0_0.png
  • /data/media/####/qipao0_0_1.png
  • /data/media/####/qqbBaseAni.png
  • /data/media/####/qqbBoardAni.png
  • /data/media/####/qqbShadow.png
  • /data/media/####/quit.png
  • /data/media/####/recordBg.png
  • /data/media/####/recordLi0.png
  • /data/media/####/recordLi1.png
  • /data/media/####/recordUi.png
  • /data/media/####/res.js
  • /data/media/####/res.min.js
  • /data/media/####/rewardSnd.mp3
  • /data/media/####/right.png
  • /data/media/####/rightStar.png
  • /data/media/####/scene0_1_0_0_ske.json
  • /data/media/####/scene0_1_0_0_tex.json
  • /data/media/####/scene0_1_0_0_tex.png
  • /data/media/####/sect0.png
  • /data/media/####/sect0Now.png
  • /data/media/####/sect1.png
  • /data/media/####/sect1Now.png
  • /data/media/####/sect2.png
  • /data/media/####/sect2Now.png
  • /data/media/####/sect3.png
  • /data/media/####/sect3Now.png
  • /data/media/####/sect4.png
  • /data/media/####/select.png
  • /data/media/####/shuihu1.png
  • /data/media/####/shuihu2.png
  • /data/media/####/signIn.png
  • /data/media/####/silk.png
  • /data/media/####/skip.png
  • /data/media/####/slip.mp3
  • /data/media/####/sound0_0.mp3
  • /data/media/####/sound0_1.mp3
  • /data/media/####/sound0_10.mp3
  • /data/media/####/sound0_11.mp3
  • /data/media/####/sound0_12.mp3
  • /data/media/####/sound0_13.mp3
  • /data/media/####/sound0_14.mp3
  • /data/media/####/sound0_2.mp3
  • /data/media/####/sound0_3.mp3
  • /data/media/####/sound0_4.mp3
  • /data/media/####/sound0_5.mp3
  • /data/media/####/sound0_6.mp3
  • /data/media/####/sound0_7.mp3
  • /data/media/####/sound0_8.mp3
  • /data/media/####/sound0_9.mp3
  • /data/media/####/sound1_0.mp3
  • /data/media/####/sound1_1.mp3
  • /data/media/####/sound1_1_1_baozha_191163b4.mp3
  • /data/media/####/sound1_2.mp3
  • /data/media/####/sound1_3.mp3
  • /data/media/####/sound1_4.mp3
  • /data/media/####/sound1_5.mp3
  • /data/media/####/sound1_6.mp3
  • /data/media/####/sound1_7.mp3
  • /data/media/####/sound1_8.mp3
  • /data/media/####/sound2_0.mp3
  • /data/media/####/sound2_1.mp3
  • /data/media/####/sound_background_gift.mp3
  • /data/media/####/sound_endBox.mp3
  • /data/media/####/sound_endGold.mp3
  • /data/media/####/spider0_2_0.png
  • /data/media/####/spider0_2_1.png
  • /data/media/####/star.png
  • /data/media/####/start.png
  • /data/media/####/startButton.png
  • /data/media/####/startWord2_4ebe45ee.mp3
  • /data/media/####/startWord3_53bc7c5e.mp3
  • /data/media/####/startWord_3e261e2.mp3
  • /data/media/####/subject.png
  • /data/media/####/subject1.mp3
  • /data/media/####/subject10.mp3
  • /data/media/####/subject10_1.png
  • /data/media/####/subject10_2.png
  • /data/media/####/subject10_3.png
  • /data/media/####/subject1_1.png
  • /data/media/####/subject1_2.png
  • /data/media/####/subject1_3.png
  • /data/media/####/subject2.mp3
  • /data/media/####/subject2_1.png
  • /data/media/####/subject2_2.png
  • /data/media/####/subject2_3.png
  • /data/media/####/subject3.mp3
  • /data/media/####/subject3_1.png
  • /data/media/####/subject3_2.png
  • /data/media/####/subject3_3.png
  • /data/media/####/subject4.mp3
  • /data/media/####/subject4_1.png
  • /data/media/####/subject4_2.png
  • /data/media/####/subject4_3.png
  • /data/media/####/subject5.mp3
  • /data/media/####/subject5_1.png
  • /data/media/####/subject5_2.png
  • /data/media/####/subject5_3.png
  • /data/media/####/subject6.mp3
  • /data/media/####/subject6_1.png
  • /data/media/####/subject6_2.png
  • /data/media/####/subject6_3.png
  • /data/media/####/subject7.mp3
  • /data/media/####/subject7_1.png
  • /data/media/####/subject7_2.png
  • /data/media/####/subject7_3.png
  • /data/media/####/subject8.mp3
  • /data/media/####/subject8_1.png
  • /data/media/####/subject8_2.png
  • /data/media/####/subject8_3.png
  • /data/media/####/subject9.mp3
  • /data/media/####/subject9_1.png
  • /data/media/####/subject9_2.png
  • /data/media/####/subject9_3.png
  • /data/media/####/subjectRight.mp3
  • /data/media/####/subjectStart.mp3
  • /data/media/####/subjectWrong.mp3
  • /data/media/####/sunwukong_ske.json
  • /data/media/####/sunwukong_ske_117a660f.json
  • /data/media/####/sunwukong_tex.json
  • /data/media/####/sunwukong_tex.png
  • /data/media/####/sunwukong_tex_1cc646d4.json
  • /data/media/####/sunwukong_tex_5826493c.png
  • /data/media/####/taijie0_2_0.png
  • /data/media/####/taijie0_2_1.png
  • /data/media/####/taijie0_2_2.png
  • /data/media/####/taijie0_2_3.png
  • /data/media/####/tbslog.txt
  • /data/media/####/tips.png
  • /data/media/####/titStar.png
  • /data/media/####/title0_1_1.png
  • /data/media/####/title0_1_2.png
  • /data/media/####/title0_1_3.png
  • /data/media/####/title0_1_4.png
  • /data/media/####/title0_1_5.png
  • /data/media/####/title0_1_6.png
  • /data/media/####/title0_1_7.png
  • /data/media/####/title0_1_8.png
  • /data/media/####/title0_1_9.png
  • /data/media/####/title0_2_1.png
  • /data/media/####/title0_2_2.png
  • /data/media/####/title0_2_3.png
  • /data/media/####/title0_2_4.png
  • /data/media/####/title0_2_5.png
  • /data/media/####/title0_2_6.png
  • /data/media/####/title0_2_7.png
  • /data/media/####/title0_2_8.png
  • /data/media/####/title0_2_9.png
  • /data/media/####/top0.png
  • /data/media/####/top0_2_0.png
  • /data/media/####/top0_2_1.png
  • /data/media/####/top_3de4a86b.png
  • /data/media/####/touchToUp.mp3
  • /data/media/####/tray0_1_0_1_0.png
  • /data/media/####/tween.js
  • /data/media/####/tween.min.js
  • /data/media/####/water0_1_0_1_0.png
  • /data/media/####/water0_1_0_1_1.png
  • /data/media/####/water0_1_0_1_2.png
  • /data/media/####/word0_0_0.mp3
  • /data/media/####/word0_0_0_6d9e2071.mp3
  • /data/media/####/word0_0_1.mp3
  • /data/media/####/word0_0_10.mp3
  • /data/media/####/word0_0_11.mp3
  • /data/media/####/word0_0_12.mp3
  • /data/media/####/word0_0_13.mp3
  • /data/media/####/word0_0_14.mp3
  • /data/media/####/word0_0_15.mp3
  • /data/media/####/word0_0_16.mp3
  • /data/media/####/word0_0_17.mp3
  • /data/media/####/word0_0_18.mp3
  • /data/media/####/word0_0_19.mp3
  • /data/media/####/word0_0_1_6d522e2c.mp3
  • /data/media/####/word0_0_2.mp3
  • /data/media/####/word0_0_20.mp3
  • /data/media/####/word0_0_21.mp3
  • /data/media/####/word0_0_2_36668334.mp3
  • /data/media/####/word0_0_3.mp3
  • /data/media/####/word0_0_3_692baf68.mp3
  • /data/media/####/word0_0_4.mp3
  • /data/media/####/word0_0_4_3edc9bf0.mp3
  • /data/media/####/word0_0_5.mp3
  • /data/media/####/word0_0_6.mp3
  • /data/media/####/word0_0_7.mp3
  • /data/media/####/word0_0_8.mp3
  • /data/media/####/word0_0_9.mp3
  • /data/media/####/word0_1_0_0.mp3
  • /data/media/####/word0_1_0_1.mp3
  • /data/media/####/word0_1_0_10.mp3
  • /data/media/####/word0_1_0_11.mp3
  • /data/media/####/word0_1_0_12.mp3
  • /data/media/####/word0_1_0_13.mp3
  • /data/media/####/word0_1_0_1d42039d.mp3
  • /data/media/####/word0_1_0_2.mp3
  • /data/media/####/word0_1_0_3.mp3
  • /data/media/####/word0_1_0_4.mp3
  • /data/media/####/word0_1_0_5.mp3
  • /data/media/####/word0_1_0_6.mp3
  • /data/media/####/word0_1_0_7.mp3
  • /data/media/####/word0_1_0_8.mp3
  • /data/media/####/word0_1_0_9.mp3
  • /data/media/####/word0_2_0_5e3239f3.mp3
  • /data/media/####/word0_3_0_401992ba.mp3
  • /data/media/####/word0_4_0_566b1d40.mp3
  • /data/media/####/word6.mp3
  • /data/media/####/xiguan.png
  • /data/media/####/zhangyu0_0_0.png
  • /data/media/####/zhangyu0_0_1.png
  • /data/media/####/zhangyu0_0_2.png
  • /data/media/####/zhubajie_ske_1ec867a7.json
  • /data/media/####/zhubajie_tex_232b912c.json
  • /data/media/####/zhubajie_tex_29ab1cee.png
Miscellaneous:
Executes next shell scripts:
  • cat /sys/class/net/wlan0/address
  • chmod 755 <Package Folder>/.jiagu/libjiagu-1730835396.so
  • getprop ro.product.cpu.abi
Loads the following dynamic libraries:
  • libjiagu-1730835396
Uses the following algorithms to encrypt data:
  • AES-ECB-PKCS7Padding
  • RSA-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES-ECB-NoPadding
Uses special library to hide executable bytecode.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android