Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) reso####.msg.xi####.net:80
- TCP(HTTP/1.1) a####.m.ta####.com:80
- TCP(HTTP/1.1) s####.j####.cn:80
- TCP(HTTP/1.1) api.xiao####.co.####.net:80
- TCP(HTTP/1.1) slide####.api.xiao####.co:80
- TCP(TLS/1.0) api.face####.com:443
- TCP(TLS/1.0) 1####.217.17.78:443
- TCP(TLS/1.0) redi####.network####.com:443
- TCP(TLS/1.0) dc1.network####.com:443
- TCP(TLS/1.0) d####.fl####.com:443
- TCP(TLS/1.0) s####.ml####.cc:443
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP 1####.121.49.66:7003
- UDP s.j####.cn:19000
- TCP 47.74.1####.158:5222
- TCP 4####.62.94.2:5222
- UDP s.j####.cn:80
- UDP easytom####.com:19000
- a####.m.ta####.com
- a####.u####.com
- d####.fl####.com
- dc1.network####.com
- easytom####.com
- g####.face####.com
- redi####.network####.com
- regi####.xm####.xi####.com
- reso####.msg.xi####.net
- s####.j####.cn
- s####.ml####.cc
- s.api.xiao####.co
- s.j####.cn
- slide####.api.xiao####.co
- reso####.msg.xi####.net/gslb/?ver=####&type=####&connpt=####&uuid=####&l...
- a####.m.ta####.com/rest/gc?dd=####&nsgs=####&ak=####&av=####&c=####&v=##...
- a####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=####&...
- api.xiao####.co.####.net/api/rest/s/ss
- s####.j####.cn/v2/report
- slide####.api.xiao####.co/api/rest/d/dd
- slide####.api.xiao####.co/api/rest/d/dg
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_ZS66DXVZ...NW_234
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsMain
- /data/data/####/.jg.ic
- /data/data/####/.yflurrydatasenderblock.0714ff03-c4f2-4875-98b7...984330
- /data/data/####/.yflurrydatasenderblock.7371ca1f-9e2d-4abc-9d09...14f2e2
- /data/data/####/.yflurrydatasenderblock.8cbced92-76b2-4672-a917...7fcd0d
- /data/data/####/.yflurrydatasenderblock.905e3ce4-480a-41c1-91a0...28d838
- /data/data/####/.yflurrydatasenderblock.cc43183a-2972-4f20-9556...d2d9b6
- /data/data/####/.yflurrydatasenderblock.dafe7e98-db58-479e-a85a...ede5b3
- /data/data/####/.yflurrydatasenderblock.e078b5d5-3bec-4cab-b069...37d2ac
- /data/data/####/.yflurryreport.-476542aa0177b2eb
- /data/data/####/Alvin2.xml
- /data/data/####/AppEventsLogger.persistedevents
- /data/data/####/ContextData.xml
- /data/data/####/FLURRY_SHARED_PREFERENCES.xml
- /data/data/####/JPushSA_Config.xml
- /data/data/####/PrefsFile
- /data/data/####/StackRec.xml
- /data/data/####/UTCommon.xml
- /data/data/####/UTMCConf-1180439896.xml
- /data/data/####/UTMCConf1829330759.xml
- /data/data/####/UTMCLog-1180439896.xml
- /data/data/####/UTMCLog1829330759.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cn.jpush.serverconfig.xml
- /data/data/####/com.facebook.internal.preferences.APP_SETTINGS.xml
- /data/data/####/com.facebook.sdk.appEventPreferences.xml
- /data/data/####/com.facebook.sdk.attributionTracking.xml
- /data/data/####/com.google.android.gms.analytics.prefs.xml
- /data/data/####/com.google.android.gms.appid-no-backup
- /data/data/####/com.google.android.gms.appid.xml
- /data/data/####/com.networkbench.agent.impl.v2_com.quvideo.slideplus.xml
- /data/data/####/com.quvideo.slideplus;pushservice
- /data/data/####/com.quvideo.slideplus_preferences.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/gaClientId
- /data/data/####/global.db
- /data/data/####/global.db-journal
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/grv720f4X6gPz_user.db
- /data/data/####/grv720f4X6gPz_user.db-journal
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/libjiagu.so
- /data/data/####/mipush.xml
- /data/data/####/mipush_account.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/persistent_data.xml
- /data/data/####/pref_registered_pkg_names.xml
- /data/data/####/rep.db-journal
- /data/data/####/serverurl.ini
- /data/data/####/statistics_config.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/media/####/.nomedia
- /data/media/####/.push_deviceid
- /data/media/####/0x00000003.ttf
- /data/media/####/0x00000004.ttf
- /data/media/####/0x00000005.ttf
- /data/media/####/0x0000001A.ttf
- /data/media/####/Alvin2.xml
- /data/media/####/CPUConfig.ini
- /data/media/####/ContextData.xml
- /data/media/####/hw_codec_cap.xml
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/lostPic.jpg
- /data/media/####/serverurl.ini
- /data/media/####/serverurl.p1
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- ArcSoftSpotlight
- cesliveeditor
- cesmediabase
- cesplatform
- cesplatformutils
- cesrenderengine
- dtdetector
- ffmpeg
- jpush181
- libjiagu
- postprocess
- x264
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- desede-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- desede-CBC-PKCS5Padding