La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Adware.Gexin.4237

Aggiunto al database dei virus Dr.Web: 2018-11-03

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) l####.b####.com:80
  • TCP(HTTP/1.1) c####.weiliao####.com:80
  • TCP(HTTP/1.1) thi####.q####.cn:80
  • TCP(HTTP/1.1) m1.pand####.cn:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(TLS/1.0) m1.pand####.cn:443
DNS requests:
  • c####.weiliao####.com
  • h5.pand####.cn
  • i####.pand####.cn
  • l####.b####.com
  • l####.tbs.qq.com
  • m1.pand####.cn
  • r####.wx.qq.com
  • thi####.q####.cn
  • u.pand####.cn
HTTP GET requests:
  • c####.weiliao####.com/Public/dist/js/comb-lib.js
  • c####.weiliao####.com/Public/images/copyright_weiliao.png
  • c####.weiliao####.com/Public/plugins/websocket/comb_websocket_s_w.js
  • c####.weiliao####.com/PublicMob/dist/css/Home/Mobile/index.css?v=####
  • c####.weiliao####.com/PublicMob/dist/js/Home/Mobile/index.js?v=####
  • c####.weiliao####.com/PublicMob/dist/js/modulesJs/common.js?v=####
  • c####.weiliao####.com/PublicMob/fonts/fontawesome-webfont.ttf?v=####
  • c####.weiliao####.com/mobile-index-cid-24266
  • l####.b####.com/jquery/2.1.3/jquery.min.js
  • m1.pand####.cn/Api/PlatProps/CheckAppVersion?AppType=####
  • m1.pand####.cn/Api/PlatProps/CheckAppVersion?isDiff=####&android=####&ap...
  • m1.pand####.cn/Assets/images/loading-74-74.gif
  • m1.pand####.cn/Assets/images/sevtel.png
  • m1.pand####.cn/assets/2018/04/30/34445b91613-11097_png!100x100.png
  • m1.pand####.cn/assets/2018/04/30/344a57e3093-13357_png!100x100.png
  • m1.pand####.cn/assets/2018/04/30/344f7449582-10445_png!100x100.png
  • m1.pand####.cn/assets/2018/05/25/2b1b2c01005-333809_jpg!1500x1500.jpg
  • m1.pand####.cn/assets/2018/06/09/17785741169-207933_jpg!1181x1181.jpg
  • m1.pand####.cn/assets/2018/06/09/565c7073129-165210_jpg!1181x1181.jpg
  • m1.pand####.cn/assets/2018/06/11/3371cf62134-367579_jpg!1600x1600.jpg
  • m1.pand####.cn/assets/2018/06/14/1315d5c5096-215221_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/14/14e9b2c2154-142140_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/15/2818b762328-328732_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/22/262c1bd6158-146419_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/22/2aedeb87633-216248_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/28/342ea739109-182276_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/06/30/61b4d045930-118986_jpg!674x896.jpg
  • m1.pand####.cn/assets/2018/07/04/34014673366-203384_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/07/14/2a6476c6096-373514_jpg!750x750.jpg
  • m1.pand####.cn/assets/2018/07/14/347400a9206-141520_jpg!800x800.jpg
  • m1.pand####.cn/assets/2018/07/14/34ad2862347-245984_jpg!750x1177.jpg
  • m1.pand####.cn/assets/2018/08/14/5715ae04022-35587_jpg!800x800.jpg
  • m1.pand####.cn/assets/2018/08/27/57123821718-290079_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/28/628900e8944-139555_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/29/62291bf5449-109299_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/08/30/33e34ed4478-130518_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/01/5a5b8d01922-180883_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/03/5874de58368-117046_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/04/57ef4827425-114543_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/06/592eed18056-210562_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/18a84157246-211032_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/1d1f0538775-176727_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/1d6d10b6814-151158_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/12/ee16714760-146089_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/14/4fa69649668-245612_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/15/27663322525-175840_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/137bec73744-180351_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/29051744113-140275_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/29960c89336-159524_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/501c4315248-136623_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/6191cd86355-114949_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/25/6278cd05919-194070_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/28/2ffb8fc7959-163274_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/28/3077ec02236-157248_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/28/32a88e21272-217080_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/1d610909992-132631_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/2a332f79768-255004_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/2af74082374-168568_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/09/29/325d75c5044-196936_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1df915b5994-191289_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1f33ea57956-127155_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/03/1f928ff3061-265100_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/262602c9237-102782_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/5938bc47285-226848_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/05/5abfe936231-131478_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/282a8622908-107628_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/288a3e06127-145888_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/10/288efec9379-106344_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/15f1dc36934-176141_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/174a84d9447-156758_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1e29b8e6001-283360_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1edbd794089-162030_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/15/1fad5666541-171888_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/16/c12b3a5743-165130_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/57147283964-92240_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/57e1c3f9196-104311_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/58513237529-182692_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/58b2b119447-238972_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/592c01c5341-82139_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/59758ff7768-285152_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/5a212bc1594-118462_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/61f8f787140-141259_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/23/62c06e14770-168174_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/25/d2b1388362-242666_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/13a72104914-102764_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/13f81991765-157005_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/14504da7434-118339_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/29/620e94b3164-124487_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/1cd403b3372-8575_png!100x100.png
  • m1.pand####.cn/assets/2018/10/31/34302387639-39225_jpg!640x640.jpg
  • m1.pand####.cn/assets/2018/10/31/60b86e54371-289239_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/642b7ea5734-152055_jpg!700x717.jpg
  • m1.pand####.cn/assets/2018/10/31/642b7fa5187-173198_jpg!700x690.jpg
  • m1.pand####.cn/assets/2018/10/31/642b8585984-154575_jpg!700x696.jpg
  • m1.pand####.cn/assets/2018/10/31/642b9529327-123407_jpg!700x867.jpg
  • m1.pand####.cn/assets/2018/10/31/642b9907324-99069_jpg!700x915.jpg
  • m1.pand####.cn/assets/2018/10/31/642b9ee2612-127647_jpg!700x856.jpg
  • m1.pand####.cn/assets/2018/10/31/642bad87288-138167_jpg!700x823.jpg
  • m1.pand####.cn/assets/2018/10/31/642bb559576-118106_jpg!700x939.jpg
  • m1.pand####.cn/assets/2018/10/31/642bc305209-214263_jpg!700x1563.jpg
  • m1.pand####.cn/assets/2018/10/31/642bccc5969-207027_jpg!700x1416.jpg
  • m1.pand####.cn/assets/2018/10/31/64592a14871-281087_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/64a40234519-289230_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/6500bd72414-272329_jpg!1000x1000.jpg
  • m1.pand####.cn/assets/2018/10/31/699cafe3271-266959_jpg!640x320.jpg
  • m1.pand####.cn/assets/2018/10/31/6e496546531-8575_png!100x100.png
  • m1.pand####.cn/assets/2018/11/01/5ad66b32483-322016_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5ae5dd54029-339823_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5aef7654207-97310_jpg!750x360.jpg
  • m1.pand####.cn/assets/2018/11/01/5b044962288-333528_jpg!1500x720.jpg
  • m1.pand####.cn/assets/2018/11/01/5b1d5f32974-96877_jpg!750x360.jpg
  • m1.pand####.cn/assets/2018/11/01/5fe4b227674-41336_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff16a05899-41464_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff3da04814-39560_jpg!200x200.jpg
  • m1.pand####.cn/assets/2018/11/01/5ff66d33667-42265_jpg!200x200.jpg
  • m1.pand####.cn/assets/images/loading-74-74.gif
  • m1.pand####.cn/im/chat/kefu?v=####
  • m1.pand####.cn/product/productDetail?id=####
  • s####.tc.qq.com/open/js/jweixin-1.0.0.js
  • thi####.q####.cn/mmopen/vi_32/DYAIOgq83eqY9sn3yubGrluAxJUS04iawYLz6UAPju...
  • thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTJC67FoVFa6YGjSXRokQnDjcxTDXbZ6yE...
  • thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTJEnnkaAuJjjAnqp4hSTGFhh4hjY40rtM...
  • thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTKPpghjAbE8Q35leTfzBh1d76VR3m0RTu...
  • thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTL9iceZQJadiacEdByTWtWP7arn3ksqwY...
  • thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTLntUOHAP6feDqqiaUPYVv4TIsw72KrsR...
  • thi####.q####.cn/mmopen/vi_32/Y0O72lenMulYNUkW124aAX4CX77F7XbjGwWNI6hZCm...
  • thi####.q####.cn/mmopen/vi_32/d2Rsric0xRnkkBAdDlmO7bgHJADjOY03MIRHEUrn8L...
  • thi####.q####.cn/mmopen/vi_32/s824qoKMYYIz0t4bP7SUkYFPtTC7jpyEYm0Cmicjic...
HTTP POST requests:
  • c####.weiliao####.com/chat-ajax_clogin.html
  • l####.tbs.qq.com/ajax?c=####&k=####
  • m1.pand####.cn/Api/Ad/IndexAd
  • m1.pand####.cn/Api/Article/HeadLine
  • m1.pand####.cn/Api/Order/LastOrderBarrage
  • m1.pand####.cn/Api/Product/AppraiseList
  • m1.pand####.cn/Api/Product/Index
  • m1.pand####.cn/Api/Product/List
  • m1.pand####.cn/Api/Product/ProductSkuList
  • m1.pand####.cn/Api/PromotionRule/PromotionActivity
  • m1.pand####.cn/Api/PromotionRule/RewardMethodList
  • m1.pand####.cn/Api/Slide/IndexBanner
  • m1.pand####.cn/api/PlatProps/PlatVendor
  • m1.pand####.cn/api/PlatProps/SetUserMenuStates
  • m1.pand####.cn/api/PlatProps/UserMenuStates
Modified file system:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/039b8d87f5cc8d88d1261e851c08d100f163d5f43f7f6fc....0.tmp
  • /data/data/####/0717f02ed9000997d72ce32d5d0cbcce117762b7ccc54d2....0.tmp
  • /data/data/####/0b0a3a1663765d53f1f5b772ce19a035692f3237d3c33be....0.tmp
  • /data/data/####/0b64ce14b17f10e210b31193214fde1f1845e616660ac5f....0.tmp
  • /data/data/####/0c0abb0bd7b3db065a1e98d06e95619407841acbe7148c2....0.tmp
  • /data/data/####/0ceff1c986f9a91d45820132d3e582de8b95dd48759c96e....0.tmp
  • /data/data/####/0e71219f59472eb1ad673d7e52014a3ba666da1909a0b8f....0.tmp
  • /data/data/####/1241399989b91df928b20f29ebad29bf2da7f153c32d5f7....0.tmp
  • /data/data/####/13c8b657e7f56640086bc69632bdcf846ad261c1a153b0f....0.tmp
  • /data/data/####/17bafc8588015ba4f030fa94fc4d31b8524683e3f9b1289....0.tmp
  • /data/data/####/2017185346998a4cad420267a00abbf8261a2f957a49aea....0.tmp
  • /data/data/####/2521ca81e820acd60aa195f9746f68a3f9278ef71ef515f....0.tmp
  • /data/data/####/260a64c1eeec0e1cf6438b6300da677f8b0b2928449eb0b....0.tmp
  • /data/data/####/280b5d214bc69032f685584e6d0aad2872fb4d55d8002c3....0.tmp
  • /data/data/####/29a397d8bee17938933261a49102c384452f40957d1d320....0.tmp
  • /data/data/####/2bc84f344867893e142c0fd7bf4bcb3a261feff0012860c....0.tmp
  • /data/data/####/33987ea50da1b723e84b10fd75e3f7b16319d083a6b9939....0.tmp
  • /data/data/####/3759f66d0fcdda9292ad54f0efd9bec05cb8928391c9a24....0.tmp
  • /data/data/####/38621109dc8351a50e47128b3aff90616525e5f17dca34d....0.tmp
  • /data/data/####/3b9f687f434782e56fa6a8cb80020cbde7bfe21ef288d2e....0.tmp
  • /data/data/####/4145d620b3f9e47758e90e4fbf89c16845a7f499935d92e....0.tmp
  • /data/data/####/4d6a95943b7371dd08a3b97f22273070389b55b5216447e....0.tmp
  • /data/data/####/4e40d49d5edc1212f0e4b0e0cd15d29cf4a7891e1a56be9....0.tmp
  • /data/data/####/557a2b062c18624720fdd01501da04750695a6342b2bb15....0.tmp
  • /data/data/####/57f282280d2dda9ff94e3ab1f91968d2e838e88811f7d9d....0.tmp
  • /data/data/####/581a29acbe503fb534261f2cc12135812ac5bf1c3f85af1....0.tmp
  • /data/data/####/583afdf63fdb8831bd9a7fcf831052574c7dc9d819d91a4....0.tmp
  • /data/data/####/5b085a69866f9a41d267d87e3ada3b1c1906ff747cf8399....0.tmp
  • /data/data/####/5b1993cadfaf07a9d709a685288c87e80a15f322525372b....0.tmp
  • /data/data/####/61de52b9fb054fe6018c932b8969736592b7cd96feb225b....0.tmp
  • /data/data/####/62041df293a5a79b813a1f5559ba03103dd53615f3c9119....0.tmp
  • /data/data/####/63873691c8e107e3284e61c687ca22a744a85b9d64d5364....0.tmp
  • /data/data/####/66e6b0086ec394a3b8acdafec981c71ed314911dcb0618b....0.tmp
  • /data/data/####/68a63322e3d1c47c88f1867b0371a8c0ed019f2c6d70704....0.tmp
  • /data/data/####/693bf7f99963dc322ad67f429fc0cf5802ddd0207d645ff....0.tmp
  • /data/data/####/6ae5e836a902b6cba1a0bb0191506ae182442aa7a3748ae....0.tmp
  • /data/data/####/6d4d36b81eb775f38b26cbf03a912bc54600e37af136294....0.tmp
  • /data/data/####/6ef632cef4d7739904089449c0bbae8b4a0e4ef417f012a....0.tmp
  • /data/data/####/6fa95f15c9ca91762e168d69d19e764eb65e634abd4c483....0.tmp
  • /data/data/####/745af2f0d5f6f3976aaf3f1f182f047cdf067ea557d8be4....0.tmp
  • /data/data/####/7a067f9805f3b564d6c680badf15f7e53fcd5b0698a771e....0.tmp
  • /data/data/####/7c1c6ed32ca2219e01eba4c868d1c9aa23d623ff275d2ca....0.tmp
  • /data/data/####/7c42a80ae32b8bdf0edc0a05fe9fd59263b92c2f7b3890f....0.tmp
  • /data/data/####/82ed6734472c5a6cb9ff2de35323aa180b7b6f53bc7f5e2....0.tmp
  • /data/data/####/865af199e9265b4919b4acd75b7a0f3395b2d1b1428057c....0.tmp
  • /data/data/####/867d3b6a60022bd2edbefaac0d8b4d78ba8f760ab8c177d....0.tmp
  • /data/data/####/894b002565bd02450e65ff5ca0bf989ffed728929f63910....0.tmp
  • /data/data/####/8b126de202b355935f975d3373448eaef7ade4f10478524....0.tmp
  • /data/data/####/8dec42eb9afb6c0a531b84e89f411aca6760c2cac9e94ce....0.tmp
  • /data/data/####/8f65f3ccebb81258f0034ce5bf4121d4f816ab8502c48ae....0.tmp
  • /data/data/####/95d6646c368005b0261f438797247463193bdaf296cabf0....0.tmp
  • /data/data/####/9bfc5e3229284e83edbeb01491dc59b5a63326943f3ebf6....0.tmp
  • /data/data/####/BMWEEXOPEN_NATIVE_SP.xml
  • /data/data/####/CookiePrefsFile.xml
  • /data/data/####/MultiDex.lock
  • /data/data/####/Updater.xml
  • /data/data/####/WXStorage
  • /data/data/####/WXStorage-journal
  • /data/data/####/a3011f18fd521123150d7e04e8ab171b477e132e2a7a640....0.tmp
  • /data/data/####/a5d9282efd831f5ca39c3ca3ac60b5d8c220c5e62f74940....0.tmp
  • /data/data/####/a714f4fd48b24849701579c089a6a0763598ede10f45571....0.tmp
  • /data/data/####/a7bff7a9e91f2d164e91b5c479e9536750a20b19a6b03c1....0.tmp
  • /data/data/####/a93705e2fa6a96f2d64abf29f41be65909d2bb7f0a64ca3....0.tmp
  • /data/data/####/ad1f142ed52b972a5e2d9fde5727e6e4b84f3b36589302b....0.tmp
  • /data/data/####/b38a1ce4ffe4062e31afc68298ecfefb982455f4b9dc59b....0.tmp
  • /data/data/####/b5d6af1a9e9294cf6a592014e776dbcf03bfd9bf806ac91....0.tmp
  • /data/data/####/bbb2fc5aa772ae3629ff457e8340fb817149194f275685d....0.tmp
  • /data/data/####/bc57703ae9f69e5af63f5b2bb599f89c09a4b453ebbab71....0.tmp
  • /data/data/####/c139f1bf2a7c616753e608043f383a194f5b67148fefe9f....0.tmp
  • /data/data/####/c14a9d7ee6dc6a8bd2d280ff81b0dc3bc4acdfdae80e3ee....0.tmp
  • /data/data/####/c2ec2f21fc740424a555d29855bc0251474e1ff5cb7c9cb....0.tmp
  • /data/data/####/c62237e570b949fbed6946d588d0c039012e95a6ac29840....0.tmp
  • /data/data/####/c62d29ce786f1b98d97f8095d851837730ea630f1ce0c96....0.tmp
  • /data/data/####/core_info
  • /data/data/####/d28cc811b2195a81160550e8a2223afb8b9613ac1049997....0.tmp
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dbca87c42f8fbdfb9c08db9dd1e9f703f5139307ed108a3....0.tmp
  • /data/data/####/debug.conf
  • /data/data/####/df36c67faa7cb6a05c3616e4ba73c4c6f44e3de7db4c77d....0.tmp
  • /data/data/####/eb9b5bdfea0bd9a1398efefa3b51861f7139d1a13afac9c....0.tmp
  • /data/data/####/ed34627e2d4621602822dc98930e7aa4d292a6cc8a8afdc....0.tmp
  • /data/data/####/ed39125ac499b27d6b4262b2afc4008325f8f010e0c9eca....0.tmp
  • /data/data/####/f5a6189b63b65d0fed6f953cc1f751eee7070c96723c842....0.tmp
  • /data/data/####/f7ca666fa18b24dd55346ad8580e7d4a5ed29dd72ce5559....0.tmp
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/index
  • /data/data/####/journal
  • /data/data/####/journal.tmp
  • /data/data/####/libjiagu1390117721.so
  • /data/data/####/libweexjsb.so
  • /data/data/####/multidex.version.xml
  • /data/data/####/qihoo_jiagu_crash_report.xml
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/media/####/Share.png
  • /data/media/####/ad_sel.png
  • /data/media/####/add.png
  • /data/media/####/addAddress.js
  • /data/media/####/addressEdit.js
  • /data/media/####/agencyArea.js
  • /data/media/####/agencyAreaStat.js
  • /data/media/####/agentDistribution.js
  • /data/media/####/appSaveImageSlider.js
  • /data/media/####/applyAgent.js
  • /data/media/####/applyUpgrade.js
  • /data/media/####/arror.png
  • /data/media/####/award.js
  • /data/media/####/b1.png
  • /data/media/####/b10.png
  • /data/media/####/b11.png
  • /data/media/####/b12.png
  • /data/media/####/b2.png
  • /data/media/####/b3.png
  • /data/media/####/b4.png
  • /data/media/####/b5.png
  • /data/media/####/b6.png
  • /data/media/####/b7.png
  • /data/media/####/b8.png
  • /data/media/####/b9.png
  • /data/media/####/bankEdit.js
  • /data/media/####/blank.html
  • /data/media/####/blank.png
  • /data/media/####/bot_arrow_1.png
  • /data/media/####/bot_arrow_2.png
  • /data/media/####/bundle.zip
  • /data/media/####/buy.png
  • /data/media/####/c10_ico.png
  • /data/media/####/c11_ico.png
  • /data/media/####/c12_ico.png
  • /data/media/####/c13_ico.png
  • /data/media/####/c14_ico.png
  • /data/media/####/c15_ico.png
  • /data/media/####/c16_ico.png
  • /data/media/####/c17_ico.png
  • /data/media/####/c18_ico.png
  • /data/media/####/c19_ico.png
  • /data/media/####/c1_ico.png
  • /data/media/####/c20_ico.png
  • /data/media/####/c21_ico.png
  • /data/media/####/c22_ico.png
  • /data/media/####/c23_ico.png
  • /data/media/####/c24_ico.png
  • /data/media/####/c25_ico.png
  • /data/media/####/c26_ico.png
  • /data/media/####/c27_ico.png
  • /data/media/####/c2_ico.png
  • /data/media/####/c31_ico.png
  • /data/media/####/c32_ico.png
  • /data/media/####/c33_ico.png
  • /data/media/####/c3_ico.png
  • /data/media/####/c4_ico.png
  • /data/media/####/c5_ico.png
  • /data/media/####/c6_ico.png
  • /data/media/####/c7_ico.png
  • /data/media/####/c8_ico.png
  • /data/media/####/c9_ico.png
  • /data/media/####/card.png
  • /data/media/####/card_pic.png
  • /data/media/####/center_bg.png
  • /data/media/####/close.png
  • /data/media/####/close2.png
  • /data/media/####/code.png
  • /data/media/####/code_ico.png
  • /data/media/####/collect_off.png
  • /data/media/####/collect_on.png
  • /data/media/####/commission.js
  • /data/media/####/cumulativeInventory.js
  • /data/media/####/evaluationList.js
  • /data/media/####/evaluationSubmission.js
  • /data/media/####/exchange.js
  • /data/media/####/face.jpg
  • /data/media/####/face.png
  • /data/media/####/face1.jpg
  • /data/media/####/face1.png
  • /data/media/####/face2.png
  • /data/media/####/fhadd.png
  • /data/media/####/font_1469606063_76593.ttf
  • /data/media/####/font_1469606522_9417143.woff
  • /data/media/####/font_zn5b3jswpofuhaor.ttf
  • /data/media/####/forget.js
  • /data/media/####/fx_ico1.png
  • /data/media/####/fx_ico2.png
  • /data/media/####/fx_ico3.png
  • /data/media/####/gamesList.js
  • /data/media/####/home_ico.png
  • /data/media/####/icon_close.png
  • /data/media/####/iconfont-eros.ttf
  • /data/media/####/iconfont.ttf
  • /data/media/####/index.js
  • /data/media/####/index_banner_bg.png
  • /data/media/####/integral.js
  • /data/media/####/join.js
  • /data/media/####/joininfo.js
  • /data/media/####/kefu.js
  • /data/media/####/kefu.png
  • /data/media/####/kejian.png
  • /data/media/####/list-card.png
  • /data/media/####/lmtt_ico.png
  • /data/media/####/loading-50-50.gif
  • /data/media/####/loading-74-74.gif
  • /data/media/####/login.js
  • /data/media/####/logo.png
  • /data/media/####/md5.json
  • /data/media/####/messageDetail.js
  • /data/media/####/messages.js
  • /data/media/####/modifyPwd.js
  • /data/media/####/msg_agent.png
  • /data/media/####/msg_distribution.png
  • /data/media/####/msg_finance.png
  • /data/media/####/msg_ico.png
  • /data/media/####/msg_order.png
  • /data/media/####/msg_other.png
  • /data/media/####/msg_system.png
  • /data/media/####/myCollect.js
  • /data/media/####/myFans.js
  • /data/media/####/myTeam.js
  • /data/media/####/n1_ico.png
  • /data/media/####/n2_ico.png
  • /data/media/####/n3_ico.png
  • /data/media/####/n4_ico.png
  • /data/media/####/n5_ico.png
  • /data/media/####/nav1.png
  • /data/media/####/nav2.png
  • /data/media/####/nav3.png
  • /data/media/####/nav4.png
  • /data/media/####/nav5.png
  • /data/media/####/nearbyStores.js
  • /data/media/####/none_ico.png
  • /data/media/####/off_check.png
  • /data/media/####/off_radio.png
  • /data/media/####/onlinekefu.png
  • /data/media/####/orderDetail.js
  • /data/media/####/orderList.js
  • /data/media/####/orderLogistics.js
  • /data/media/####/orderPay.js
  • /data/media/####/orderPut.js
  • /data/media/####/parentchildComment.js
  • /data/media/####/parentchildLive.js
  • /data/media/####/parentchildTV.js
  • /data/media/####/parentchildTVList.js
  • /data/media/####/paySuccess.js
  • /data/media/####/pcode_ico.png
  • /data/media/####/photo_ico.png
  • /data/media/####/pl_ico.png
  • /data/media/####/pl_ico1.png
  • /data/media/####/post_ico.png
  • /data/media/####/post_icoy.png
  • /data/media/####/price.png
  • /data/media/####/pro.png
  • /data/media/####/pro1.png
  • /data/media/####/pro2.png
  • /data/media/####/proDetail.js
  • /data/media/####/proList.js
  • /data/media/####/pro_1.png
  • /data/media/####/pro_2.png
  • /data/media/####/product1.png
  • /data/media/####/psd.png
  • /data/media/####/purchase.js
  • /data/media/####/purchaseApplications.js
  • /data/media/####/purchaseMoney.js
  • /data/media/####/q1.png
  • /data/media/####/q2.png
  • /data/media/####/q3.png
  • /data/media/####/q4.png
  • /data/media/####/qou.png
  • /data/media/####/qq_ico.png
  • /data/media/####/quan.png
  • /data/media/####/rebate.js
  • /data/media/####/rebatePerformance.js
  • /data/media/####/rebateStat.js
  • /data/media/####/rebateTable.js
  • /data/media/####/recharge.js
  • /data/media/####/recommendFriends.js
  • /data/media/####/register.js
  • /data/media/####/remittanceCertificate.js
  • /data/media/####/resetpwd.js
  • /data/media/####/saixuan.png
  • /data/media/####/salesSend.js
  • /data/media/####/saveImageSlider.js
  • /data/media/####/search.png
  • /data/media/####/search_ico.png
  • /data/media/####/sel_check.png
  • /data/media/####/sel_radio.png
  • /data/media/####/sendBackProduct.js
  • /data/media/####/sendGoods.js
  • /data/media/####/set_face.png
  • /data/media/####/setting.js
  • /data/media/####/sfz1.png
  • /data/media/####/sfz2.png
  • /data/media/####/share.js
  • /data/media/####/share_wx_circle.png
  • /data/media/####/share_wx_friend.png
  • /data/media/####/ship1.js
  • /data/media/####/ship2.js
  • /data/media/####/ship3.js
  • /data/media/####/shipOrder.js
  • /data/media/####/shipmentMoney.js
  • /data/media/####/shop.png
  • /data/media/####/shop_ico.png
  • /data/media/####/signIn.js
  • /data/media/####/star-off.png
  • /data/media/####/star-on.png
  • /data/media/####/star.png
  • /data/media/####/statistics.js
  • /data/media/####/stock.js
  • /data/media/####/stockRecord.js
  • /data/media/####/storeDetail.js
  • /data/media/####/storeManage.js
  • /data/media/####/subordinate.js
  • /data/media/####/suc_pic.png
  • /data/media/####/t_bg.png
  • /data/media/####/tabPage.js
  • /data/media/####/tbslog.txt
  • /data/media/####/teamOrder.js
  • /data/media/####/tel.png
  • /data/media/####/tj_banner.png
  • /data/media/####/top_arrow_1.png
  • /data/media/####/top_arrow_2.png
  • /data/media/####/tvDetail.js
  • /data/media/####/tv_ico.png
  • /data/media/####/tz1.png
  • /data/media/####/tz2.png
  • /data/media/####/up.jpg
  • /data/media/####/upgrade.js
  • /data/media/####/userBill.js
  • /data/media/####/userinfo.js
  • /data/media/####/vip_ico.png
  • /data/media/####/warehouseStock.js
  • /data/media/####/webView.js
  • /data/media/####/weix_ico.png
  • /data/media/####/withdraw.js
  • /data/media/####/withdrawList.js
  • /data/media/####/wx_ico.png
  • /data/media/####/xz_ico.png
  • /data/media/####/xzlogo.png
  • /data/media/####/yuer_ico.png
  • /data/media/####/zan.png
  • /data/media/####/zan1.png
  • /data/media/####/zt_ico1.png
  • /data/media/####/zt_ico2.png
  • /data/media/####/zy_img.png
Miscellaneous:
Executes next shell scripts:
  • /data/app-lib/<Package>-1/libweexjsb.so 50 0
  • getprop ro.product.cpu.abi
Loads the following dynamic libraries:
  • Patcher
  • libjiagu1390117721
  • weexjsc
Uses the following algorithms to encrypt data:
  • RSA-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Gains access to telephone information (number, IMEI, etc.).
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android