La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Adware.Gexin.17825

Aggiunto al database dei virus Dr.Web: 2019-09-15

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(DNS) <Google DNS>
  • TCP(HTTP/1.1) f04.img####.com:80
  • TCP(HTTP/1.1) q####.c####.l####.####.com:80
  • TCP(HTTP/1.1) 1111033####.dns.wa####.com:80
  • TCP(HTTP/1.1) up####.sdk.jig####.cn:80
  • TCP(HTTP/1.1) s####.m.img####.com:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) cdn.43####.com:80
  • TCP(HTTP/1.1) cnhuo####.439####.net:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) who.wa####.com:80
  • TCP(HTTP/1.1) cloud####.fengkon####.com:80
  • TCP(HTTP/1.1) sdk-ope####.g####.com:80
  • TCP(HTTP/1.1) f1.img####.com:80
  • TCP(HTTP/1.1) a.img####.com:80
  • TCP(HTTP/1.1) f####.fengkon####.com:80
  • TCP(TLS/1.0) f1.img####.com:443
  • TCP(TLS/1.0) gd-s####.j####.cn:443
  • TCP(TLS/1.0) t####.j####.cn:443
  • TCP(TLS/1.0) m####.439####.net:443
  • TCP(TLS/1.0) yx####.505####.com:443
  • TCP(TLS/1.0) fs.img####.com:443
  • TCP(TLS/1.0) ali-s####.j####.cn:443
  • TCP cm-1####.ig####.com:5227
  • TCP 1####.232.25.180:7011
  • TCP sdk.o####.t####.####.com:5224
  • UDP s.j####.cn:19000
  • UDP easytom####.com:19000
  • UDP 2####.14.153.110:19000
DNS requests:
  • 111102e####.dns.wa####.com
  • 1111033####.dns.wa####.com
  • 1111033####.dns.wa####.com
  • 7j####.c####.z0.####.com
  • a.img####.com
  • ali-s####.j####.cn
  • c-h####.g####.com
  • cdn.43####.com
  • cloud####.fengkon####.com
  • cm-1####.ig####.com
  • easytom####.com
  • f####.fengkon####.com
  • f04.img####.com
  • f1.img####.com
  • fs.img####.com
  • gd-s####.j####.cn
  • huo####.4####.cn
  • l####.tbs.qq.com
  • m####.439####.net
  • m.439####.com
  • p.img####.com
  • pub-####.qin####.com
  • s####.m.img####.com
  • s.j####.cn
  • s1.img####.com
  • sdk-ope####.g####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sis.j####.io
  • sj2.img####.com
  • t####.j####.cn
  • up####.sdk.jig####.cn
  • who.wa####.com
  • yx####.505####.com
HTTP GET requests:
  • 1111033####.dns.wa####.com/result?key=####&form=####&
  • a.img####.com/1335638890/middle?155108####
  • a.img####.com/2010806156/middle?156532####
  • a.img####.com/3044733301/middle?156851####
  • cdn.43####.com//android/box/v1.0/config-gameAutoInst-mareacode-999998-br...
  • cdn.43####.com//app/android/v4.4.5/gameDetail-index-package-com.miaoju.p...
  • cdn.43####.com/android/box/game/v4.0/detail-customTab-mareacode-999998.h...
  • cdn.43####.com/android/box/general/v1.0/adverts-start-coverSize-1-mareac...
  • cdn.43####.com/android/box/v1.0/download-notice-package-com.miaoju.ppxcq...
  • cdn.43####.com/android/box/v1.1/config-tabs.html
  • cdn.43####.com/app/android/v3.0/config-dailySign-mareacode-999998.html
  • cdn.43####.com/app/android/v3.4/config-common-mareacode-999998.html
  • cdn.43####.com/app/android/v3.4/config-common.html
  • cdn.43####.com/app/android/v4.4.1/game-index-mareacode-999998.html
  • cdn.43####.com/app/forums/android/v2.1/chat-faces-mareacode-999998.html
  • cdn.43####.com/app/forums/android/v3.3/chat-faces-mareacode-999998.html
  • cdn.43####.com/user/sns/box/android/v1.0/headgear-feature-id-68-mareacod...
  • cnhuo####.439####.net/daily/9820.html?f=####
  • f04.img####.com/2114533612/middle?156706####
  • f04.img####.com/2682128196/middle?156777####
  • f04.img####.com/3039124649/middle
  • f04.img####.com/downloader/upload/toutao/tianqi/xiayu5.zip
  • f04.img####.com/ma~290_20190621105322_5d0c46a282f61.png
  • f04.img####.com/sj~emoji_e030.png
  • f04.img####.com/sj~emoji_e10014.png
  • f04.img####.com/sj~emoji_e10135.png
  • f04.img####.com/sj~emoji_e10137.png
  • f04.img####.com/sj~emoji_e10139.png
  • f04.img####.com/sj~emoji_e10140.png
  • f04.img####.com/sj~emoji_e10145.png
  • f04.img####.com/sj~emoji_e10146.png
  • f04.img####.com/sj~emoji_e110.png
  • f04.img####.com/sj~emoji_e118.png
  • f04.img####.com/sj~emoji_e307.png
  • f04.img####.com/sj~emoji_e419.png
  • f04.img####.com/sj~emoji_e444.png
  • f04.img####.com/sj~emoji_e529.png
  • f1.img####.com/254408467~480x280
  • f1.img####.com/257057436~480x280
  • f1.img####.com/257057638~480x280
  • f1.img####.com/257293657~480x280
  • f1.img####.com/box~cp/1672019/09/14/16_a_Bn56.474x282.jpg
  • f1.img####.com/box~cp/1932019/07/27/16_5sCcCk.912x261.png
  • f1.img####.com/box~cp/2072019/09/13/17_K3EmS7.474x282.jpg
  • f1.img####.com/box~cp/5392019/09/12/14_d1qe8h.1080x720.jpg
  • f1.img####.com/f/forums~mtag/82066_icon_124x124?4####
  • f1.img####.com/ma~106139_logo2_ce57.jpg
  • f1.img####.com/ma~111068_logo2_254d.jpg~124x124
  • f1.img####.com/ma~114518_logo2_b400.jpg~124x124
  • f1.img####.com/ma~116161_logo2_581f.jpg
  • f1.img####.com/ma~116858_logo2_6bfb.jpg~124x124
  • f1.img####.com/ma~117074_logo2_38a2.jpg~124x124
  • f1.img####.com/ma~119514_logo2_ca65.jpg~124x124
  • f1.img####.com/ma~120256_logo2_0910.jpg~124x124
  • f1.img####.com/ma~120456_logo2_bf5c.jpg~124x124
  • f1.img####.com/ma~121809_logo2_48b3.jpg~124x124
  • f1.img####.com/ma~122220_logo2_31a9.jpg~124x124
  • f1.img####.com/ma~122302_logo2_18f1.jpg~124x124
  • f1.img####.com/ma~124699_logo2_3b3b.jpg~124x124
  • f1.img####.com/ma~125610_logo2_b638.jpg~124x124
  • f1.img####.com/ma~126869_logo2_6ab9.jpg~124x124
  • f1.img####.com/ma~131304_logo2_9ffd.jpg~124x124
  • f1.img####.com/ma~133004_logo2_c647.jpg~124x124
  • f1.img####.com/ma~133430_logo2_3a00.jpg~124x124
  • f1.img####.com/ma~134427_logo2_7654.jpg~124x124
  • f1.img####.com/ma~136214_logo2_6a04.jpg~124x124
  • f1.img####.com/ma~137864_logo2_19d8.jpg~124x124
  • f1.img####.com/ma~137924_logo2_7bf0.jpg~124x124
  • f1.img####.com/ma~138374_logo2_8450.jpg~124x124
  • f1.img####.com/ma~138727_logo2_2211.jpg~124x124
  • f1.img####.com/ma~139825_logo2_f9c6.jpg~124x124
  • f1.img####.com/ma~139997_logo2_f945.jpg~124x124
  • f1.img####.com/ma~140361_logo2_483f.jpg~124x124
  • f1.img####.com/ma~141566_logo2_2630.jpg~124x124
  • f1.img####.com/ma~141696_logo2_eddf.jpg~124x124
  • f1.img####.com/ma~142057_logo2_0bab.jpg~124x124
  • f1.img####.com/ma~142178_logo2_d2ee.jpg~124x124
  • f1.img####.com/ma~142871_logo2_74eb.jpg~124x124
  • f1.img####.com/ma~144709_logo2_11ec.jpg~124x124
  • f1.img####.com/ma~147724_logo2_27dd.jpg~124x124
  • f1.img####.com/ma~148674_logo2_5065.jpg~124x124
  • f1.img####.com/ma~167_20190528204200_5ced2c987f205.png
  • f1.img####.com/ma~167_20190529140822_5cee21d69c35b.png
  • f1.img####.com/ma~242_logo2_9c95.jpg~124x124
  • f1.img####.com/ma~27_20170706154005_595de955018bc.png
  • f1.img####.com/ma~27_20190516173745_5cdd2f6913f42.png
  • f1.img####.com/ma~27_20190516173825_5cdd2f91d1e97.png
  • f1.img####.com/ma~27_20190516173839_5cdd2f9faeab7.png
  • f1.img####.com/ma~27_20190516173902_5cdd2fb612252.png
  • f1.img####.com/ma~27_20190516173925_5cdd2fcdd8abd.png
  • f1.img####.com/ma~27_20190516173938_5cdd2fda2352f.png
  • f1.img####.com/ma~27_20190522170739_5ce5115b66ce0.png
  • f1.img####.com/ma~539_20190905173235_5d70d6337ce06.gif
  • f1.img####.com/ma~712_20190610103621_5cfdc2255875d.png
  • f1.img####.com/ma~97293_logo2_0708.jpg~124x124
  • f1.img####.com/mi~79075d9c4aca7bbc3aac8187bb3dec9e.jpeg
  • f1.img####.com/openapi/aliapi-index.html
  • f1.img####.com/sj~emoji_e10134.png
  • f1.img####.com/sj~opensj_5d12d71e740c6
  • f1.img####.com/sj~opensj_5d12d71ead083
  • f1.img####.com/sj~opensj_5d12d71f10943
  • f1.img####.com/sj~opensj_5d12d71f6e0a2
  • f1.img####.com/sj~opensj_5d12d71ff225b
  • f1.img####.com/v/5.1.1.24/4399Game_5.1.1.24.upgrade.2de4.apk
  • f1.img####.com/yxh~u/13356388902019/09/15/11_nghHxE.960x704.jpg
  • f1.img####.com/yxh~u/20108061562019/09/15/11_oj9onQ.720x828.jpg~480x480
  • f1.img####.com/yxh~u/23817671832019/09/14/12_phVDSc.246x254.gif
  • f1.img####.com/yxh~u/30447333012019/09/15/11_r0ouNo.480x848.jpg
  • q####.c####.l####.####.com/config/hz-hzv6.conf
  • q####.c####.l####.####.com/tdata_EDT369
  • q####.c####.l####.####.com/tdata_Gni835
  • q####.c####.l####.####.com/tdata_YYn966
  • q####.c####.l####.####.com/tdata_tYM194
  • q####.c####.l####.####.com/tdata_wSS777
  • s####.m.img####.com/trace/v2/keynote
  • sdk.o####.p####.####.com/api/addr.htm
  • who.wa####.com/?key=####&form=####
HTTP HEAD requests:
  • f1.img####.com/v/5.1.1.24/4399Game_5.1.1.24.upgrade.2de4.apk
HTTP POST requests:
  • c-h####.g####.com/api.php?format=####&t=####
  • cloud####.fengkon####.com/v2/device/conf
  • cloud####.fengkon####.com/v2/device/profile
  • f####.fengkon####.com/v2/device/profile
  • l####.tbs.qq.com/ajax?c=####&k=####
  • s####.m.img####.com/trace/<Package>/1.0/360/1100gkxPWwjHPGO8YPiBKa746
  • s####.m.img####.com/trace/<Package>/1.0/Unknown/.config?version=####
  • sdk-ope####.g####.com/api.php?format=####&t=####
  • sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
  • up####.sdk.jig####.cn/v1/push/sdk/postlist
File system changes:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/.policy
  • /data/data/####/031c2bb28c203f0ee0c6ff5d0896c66a2d0519594134ec1....0.tmp
  • /data/data/####/04926b2bb9e5811ec3e8a2621e5ddd2a8011fbbf3960b3a....0.tmp
  • /data/data/####/04d2908dde3a8bb8bd0627f16c6a139c8da5985901fee5a....0.tmp
  • /data/data/####/05061dbe67cbd720e0509d6d33b82ef8313b51fdf39c7a7....0.tmp
  • /data/data/####/05c7adebc4e982e5b73a8d1c0a79cd2c137a40055a342ef....0.tmp
  • /data/data/####/05e6cc0ef9a70d678e3fdb4c869e7af12340b63f9ab996c....0.tmp
  • /data/data/####/0607979d1198031aed8a93facc21b17cfcbfd79b01d2a6e....0.tmp
  • /data/data/####/0a7b793185ddd5d26382d4e18e6eec225f99d5b9f923f68....0.tmp
  • /data/data/####/0aa2cc1b0853dc8798a114dee20b58418e91097894c1bea....0.tmp
  • /data/data/####/0cbe07e43c733de2da3240ac8092cd107d551c86f3a755c....0.tmp
  • /data/data/####/1.f8dafd6b.chunk.js
  • /data/data/####/1.f8dafd6b.chunk.js.map
  • /data/data/####/10b116febf4d5d840ee22fa83bfeefc6bfdf7ece955a3d0....0.tmp
  • /data/data/####/10c320af3bb02dcb4273cd5e81cbf65ad76e59b4a3fef27....0.tmp
  • /data/data/####/121d6f0101443250abbb80880237d017b45f0d940bc48ac....0.tmp
  • /data/data/####/12c5b0732e83e740974b61cbb0dd5dab83d0b2c48603303....0.tmp
  • /data/data/####/14d310e684c7e8ffabcc9eb381a14d9f6bf162a7d4d5437....0.tmp
  • /data/data/####/193931ad476a18998c5ff76121ce1d8ea4943e33ce99e53....0.tmp
  • /data/data/####/197409a77d535cc55c7e515e2a7663151401f62404485dc....0.tmp
  • /data/data/####/1b04255b42ac30a8b62bcd1b5b688767da3e4a95f0b6868....0.tmp
  • /data/data/####/1b16e39969b8a1500e06b89b32d318d25a9a5f25dcef311....0.tmp
  • /data/data/####/1ca04b4932dc855ad0837a1f20f509e3eddc1d791a3f0d4....0.tmp
  • /data/data/####/1d12c4b25a970d39b46e1425bd6e0aef43a576c3913a327....0.tmp
  • /data/data/####/1e0c611ff2e7ce86bf90bf65f6d8e23a891a69abd54e0f8....0.tmp
  • /data/data/####/1f3df72fdc196339b5092e467f18ad470d2c56c14e541f6....0.tmp
  • /data/data/####/2088a0d868bc
  • /data/data/####/2223f3e6762b56451dc950c40ef23684bc87f96662ea85f....0.tmp
  • /data/data/####/24245908d2b3713acb2a9084392fe7a65c8cd02b30201a9....0.tmp
  • /data/data/####/2a31b10fbc1095a97f4943c7960db12b22aca982bf48cd3....0.tmp
  • /data/data/####/2a5b375a-623c-4ef0-b67d-62a0238a5da6
  • /data/data/####/2ad15e2c2eabd2a8694c26457c415d7115d3f84a630af78....0.tmp
  • /data/data/####/2aea91d4b9cc9b170c3bfcf55171a677b48d8de0969bd82....0.tmp
  • /data/data/####/2b4c60e682d3d1f05b85ebf5b8e9c34d7f2641985cfaddd....0.tmp
  • /data/data/####/2d5fd7d1947c9ff53d7fec197b7355e513447fdc5fea38f....0.tmp
  • /data/data/####/2e6b3ede5201ae83ea407ffb9fd9ec6a67c88b0fabb257c....0.tmp
  • /data/data/####/2ef8a8a76355fe762c4040717755fb95b63118917c63c37....0.tmp
  • /data/data/####/2f70f978bcd9931f3811e34371fdeb7b80fb2cbc1325122....0.tmp
  • /data/data/####/30df08fdac759f85e1d2662a42a335e27ef7ee345c5a2c1....0.tmp
  • /data/data/####/31cfe31d0a2c748886cf2a6a8c4fa4181be59a24904b820....0.tmp
  • /data/data/####/31d53607d711c119e6e8486f4bbb987c.0.tmp
  • /data/data/####/36ca0899e5747e2d106388493b45f1f5362c0aa3c4df659....0.tmp
  • /data/data/####/36ca0899e5747e2d106388493b45f1f5362c0aa3c4df659...6871.0
  • /data/data/####/3a7595499cecc2b45099035df76f511b3e74c47a0447a2c....0.tmp
  • /data/data/####/3d538f5036a5d46b09c755b4e5d42f51751d8cd62bf67d0....0.tmp
  • /data/data/####/3fde0c055b07fe6c6a4946c28948bea513413e0707f9000....0.tmp
  • /data/data/####/40780e461a70602e3ff3f94bd1aacf08d975865a0bbfca1....0.tmp
  • /data/data/####/42729b1196fe9bab3b8707d35337c4361393fb87f5a5f32....0.tmp
  • /data/data/####/440d1d716c1cd4226074ff18e4fcb8c548fe46854dc9594....0.tmp
  • /data/data/####/44c4bdbc8aa473d6d469e6d787bb477f0b5c9746b8dc05a....0.tmp
  • /data/data/####/46c399beba9c91900c1ae5a8ac7eebaccaf3449c3635daa....0.tmp
  • /data/data/####/4b2b4071f5ff3ff809b483aea277316974a9a04c0bbde80....0.tmp
  • /data/data/####/4b3bb430701e7f72ab756d7e8eb6b167e88bd898c8d8c5a....0.tmp
  • /data/data/####/4d996c5c-1bc4-4fb0-bc5b-6b04aaf08653
  • /data/data/####/504a9f63b69bd5f3fa16955d1114c7d084cec9350100995....0.tmp
  • /data/data/####/50f6b66843b6753efa06d9316156591aa5af4dee9678bb5....0.tmp
  • /data/data/####/51aa8b607d7cff450dd5b23a87d32a496d966a6234bbd0d....0.tmp
  • /data/data/####/52d653da86d66704b08c82a42205e6f0b88684b13844edc....0.tmp
  • /data/data/####/536d69e49c1733cf153c88e64e2659b7e68b9acb10edc8e....0.tmp
  • /data/data/####/54e8b8bc67c0366d4554462e403c4f3c17cf33492dd0e32....0.tmp
  • /data/data/####/561c397b182eef4ea6bfc5e5dd3d06764f7c7d66fe29a13....0.tmp
  • /data/data/####/568e0a1c-3eb7-456a-a5d9-f42e1b1dd806
  • /data/data/####/59dbc299927b0f480286c25e4ec5799f4093dfa403ebbe8....0.tmp
  • /data/data/####/5a56b5025a03212c66a1892c84324bad63883fd29ba489a....0.tmp
  • /data/data/####/5a7f1b33968aef42bbf1d5463612e164e821209005979af....0.tmp
  • /data/data/####/5ae1635d4549f5e59457c55e1ef21698.0.tmp
  • /data/data/####/5bbbdfe96fd14fd1745f6070fcd42037632b9add3059a82....0.tmp
  • /data/data/####/5c868628acddaa9114adbb3fc135f46a2b6696fc008ad92....0.tmp
  • /data/data/####/5d318e9fe984a786850b25bafb8a7137dfdc8042bbeb00c....0.tmp
  • /data/data/####/5e226957947348612a7f84a6a374e43a.0.tmp
  • /data/data/####/60d01c932743e5510f2c561f9c44092c.0.tmp
  • /data/data/####/60daf3e4e1e0506f55d1f75d7f8d1be6a3b0070acd25851....0.tmp
  • /data/data/####/61ab53c88af5786353d376440ce0d3ea.0.tmp
  • /data/data/####/62a3f2b5e2500b7e5ef016ac5b5826d78ed00b431f54523....0.tmp
  • /data/data/####/632c92a528051bbd0b94df128d34e90948cf69600211ec9....0.tmp
  • /data/data/####/6473681b07a61b933a87ced1cf9a09910e11ee72116be00....0.tmp
  • /data/data/####/680abf1dae1d10880cc0c42d8aefb0dc9cd37e12882ec17....0.tmp
  • /data/data/####/683c173691cf1e156ef0a08fa188ad9a656e18c00b6d882....0.tmp
  • /data/data/####/68ac562089cc00482798154d30daa53c9707f3ec84e9dbe....0.tmp
  • /data/data/####/68bf9eb4bcd16f3f60e6b2eae5f519ec68be5fe92aa0fcc....0.tmp
  • /data/data/####/6968dea9fb6c88650018759459c2c0d7.0.tmp
  • /data/data/####/6991c0bcf5b8c733c82d6454d56d89b89287de958e4a5ca....0.tmp
  • /data/data/####/6cdcb39d504d94317ebd4f2230ac4e765905e7aecf32a4d....0.tmp
  • /data/data/####/6da6841fba30771d6fb8daf55ce43665ec3870c9518b685....0.tmp
  • /data/data/####/6e2bb6f83a31c3a6a445fbdd253b0b99c4b9fb0d7f08d40....0.tmp
  • /data/data/####/741cbe018b05dfa35eee7a65bd6c2521.0.tmp
  • /data/data/####/74a1948dcfe824fc88632f201c7b40e168bb1e134343b79....0.tmp
  • /data/data/####/75163d129ad820869f810768668b8ecca6cd90a34c1f707....0.tmp
  • /data/data/####/75327a941629573fc58d30f0d64d0a7f5a60e7b756c80f1....0.tmp
  • /data/data/####/7836e571ee536f2bf266408a56b2ed8bddb25adca832a9d....0.tmp
  • /data/data/####/7874c29e2aa0c272edbcbd3e92019c931a2a13a4c0af0af....0.tmp
  • /data/data/####/79c2aff37a2f008b13cda2caa3b9c38529eed32b2b7667d....0.tmp
  • /data/data/####/7a52e61344a681104a8cc9fc38737da2d1b2d71bf423c2a....0.tmp
  • /data/data/####/7a78f542edcdca2209eb14b8595333a36687100513af6de....0.tmp
  • /data/data/####/7a891f0a07c5409026426d494b2acf879808ac26cfb112e....0.tmp
  • /data/data/####/7aa6d53f896e5df823c00f8543840d9f47ec55403bcff93....0.tmp
  • /data/data/####/7ae4088a-39d8-449c-82ac-a7e3d71a1e75
  • /data/data/####/7b5c2b9a1849c524469f885ff2932d912b1b746e0cb2658....0.tmp
  • /data/data/####/7d59214389f51b25db5b6369e08c489a54b938f43593101....0.tmp
  • /data/data/####/7fbb7bbef9079be5b4f11386bd12980f89f01cb6535cdca....0.tmp
  • /data/data/####/7ffae432d8114c936894cf9113428ef32e44c3433d6d1fb....0.tmp
  • /data/data/####/811fcaf8019422648045096df092939b69d43927864a2a7....0.tmp
  • /data/data/####/83c73c84a72fdad8e888e8d1d40ed8f639676c84afd05f2....0.tmp
  • /data/data/####/87c192722efbbfd9bf023d9735214cc84738787a3a032d6....0.tmp
  • /data/data/####/890b1229dc7569e860d950ec0299d6a485eae30359917ce....0.tmp
  • /data/data/####/898a0a8603c79679455df41a801e0cf246a22dd4c1e6409....0.tmp
  • /data/data/####/899f56ba940c43f94dd5efac67310781b0262aec9006022....0.tmp
  • /data/data/####/89b62b30965a0bfa29ffe066e82d275c2e6857b16eff560....0.tmp
  • /data/data/####/89c8dddc25a146b32be6598e43711e3dd17328fc78ba1ce....0.tmp
  • /data/data/####/8d2d411fab6ce590391fdbec602c2d04738199be5d7143d....0.tmp
  • /data/data/####/8d90759aa997e3330ec9324e0bf73aefae01acd028f5cd9....0.tmp
  • /data/data/####/8fce84c9dece64c6632b90177da94465.0.tmp
  • /data/data/####/8fe1cba0513218962237438aab0b313bbcb416637f62a37....0.tmp
  • /data/data/####/9197df09fee36e97b8e7fe46b1c11c1d65ab2efcf414db7....0.tmp
  • /data/data/####/92605ff8a350c3e0bc241632876dae4d0f3dec7d5fbfae6....0.tmp
  • /data/data/####/9289475895d0c7f9f33e93da10adc6ee19d5a5e6b058417....0.tmp
  • /data/data/####/9403d6f7b31bb3922c4d91c12b49f3c01874efa3fdbce75....0.tmp
  • /data/data/####/94c785ec-5b21-4658-b199-e5627a7e7e11
  • /data/data/####/95cfb78c58aa8b5015839ecd198d0d4a8881e943f013656....0.tmp
  • /data/data/####/9746f677004161df596d888251b8dbd6a6741fd8edad903....0.tmp
  • /data/data/####/9a94cd2254863f6ef0e26e20bdc2063a5491488ea8268c9....0.tmp
  • /data/data/####/9d9a382e9e63491ca20cfd6c17ae960337b9852056853b4....0.tmp
  • /data/data/####/JPushSA_Config.xml
  • /data/data/####/MultiDex.lock
  • /data/data/####/MyAnalytics_VERSION_INFO.xml
  • /data/data/####/MyAnalytics_device_id.xml
  • /data/data/####/MyAnalytics_general_config.xml
  • /data/data/####/MyAnalytics_send_config.xml
  • /data/data/####/a36905744de23ead49cf6c839c87dbddb8b6dbde36566ae....0.tmp
  • /data/data/####/a39c4f44404336d808659c271f5e50b04545451c4ce1146....0.tmp
  • /data/data/####/aa9c484959aa759e4c6eb827411af8d05b048bee60d7d44....0.tmp
  • /data/data/####/ab8c8cc52b5b113fd057dc2f0b42afdb032aec8b3138d64....0.tmp
  • /data/data/####/ac5fd845e9d99b9fcb6d1b8771615aa1ea4ec686990dd02....0.tmp
  • /data/data/####/af9b3f372308beb0e365bf642610ddb1ae8676166662650....0.tmp
  • /data/data/####/afb2dab118ddddfea9e89864e89d13c539513355a79f61c....0.tmp
  • /data/data/####/appPackageNames_v2
  • /data/data/####/asset-manifest.json
  • /data/data/####/b016be622a9e5314aafded50e15562ecb863c8c2919018f....0.tmp
  • /data/data/####/b1b77f8a473f46ae75680e1816e954afb659adcb5dcb1a4....0.tmp
  • /data/data/####/b2f5d62b18ed28254ee91e926336dfb48d9598388da0a3c....0.tmp
  • /data/data/####/b6946d68cdcd8cc3e7fbd7b33ebe895c90539862dbd0b34....0.tmp
  • /data/data/####/b7408ef4df8bc9a96845a00c0ba5d24145ad8d8652b1839....0.tmp
  • /data/data/####/bc8f3dca361668a758266dca4e7942acae5d67cb9015999....0.tmp
  • /data/data/####/bc8f3dca361668a758266dca4e7942acae5d67cb9015999...68bd.0
  • /data/data/####/bdfaad66fcec97a9ff4256995e74cd5b4dfa24ff600559d....0.tmp
  • /data/data/####/c04174c58195e4eb810fd3f63de7a1aa40ee516c4de5204....0.tmp
  • /data/data/####/c0b6ff5910eefdbe44b66e2b203b4311feaa16058c7593f....0.tmp
  • /data/data/####/c0deefef-70aa-4ef1-9475-de3213c300ba
  • /data/data/####/c4490a4f053a4f47dce787f3bd03a9e886fe72a7c5e6eef....0.tmp
  • /data/data/####/c465ec92212e7653ccdbba5784ab1a797bad06fe046f4d8....0.tmp
  • /data/data/####/c47868757c118150a76d47d3afd342e6.0.tmp
  • /data/data/####/c7595596b978e48f7cd0fae9bda858fda9694adee59ebb0....0.tmp
  • /data/data/####/c97ae93fa42fbd1d4a99e4a811a70f789e19a24adc2adc8....0.tmp
  • /data/data/####/ca6c589dd9065d8357751f3e6fb43f96c67275785b8d44d....0.tmp
  • /data/data/####/cache.emoji.key.xml
  • /data/data/####/cba743b1c7bbe232e521a4e933d7da8e18d0b88cfc6de45....0.tmp
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cc901a6e56742cdf0c67fb39db257e6307ad097ec0d604b....0.tmp
  • /data/data/####/cf1fa7fde7985ffc72bfa3d4988c245607d45c9b58c03f3....0.tmp
  • /data/data/####/cloudms.conf.xml
  • /data/data/####/cn.jpush.android.user.profile.xml
  • /data/data/####/cn.jpush.preferences.v2.rid.xml
  • /data/data/####/cn.jpush.preferences.v2.xml
  • /data/data/####/com.m4399.gamecenter_preferences.xml
  • /data/data/####/com.shumei.xml
  • /data/data/####/core_info
  • /data/data/####/d205b648e0178d7d8f28db9abbf3ce5bf7d06c54b2e8c20....0.tmp
  • /data/data/####/d4ba5f431b77a9e125dd2968706e5dc618727a487a3538f....0.tmp
  • /data/data/####/d58308af2c59ca0ff726f77e07fb7c0d3ef7ecb056bdb72....0.tmp
  • /data/data/####/d5d6a1f22126af59a876d256b0880de1cc3da4d2e17855b....0.tmp
  • /data/data/####/d963f9e1c256e84f1798253b4f206c021541be9cdc3fcea....0.tmp
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dd0b84ce9a0a40a9b3274402dbabfad3788f16308089052....0.tmp
  • /data/data/####/deb97a11bb847cdaa67131788099a8d96f0d8e8de2dce95....0.tmp
  • /data/data/####/download_upload
  • /data/data/####/downloads.db-journal
  • /data/data/####/e011dd86edcfee9d385a5268dee2c0c3e062faf356313e1....0.tmp
  • /data/data/####/e0be2cd09540f22dcd7fa3c9cef4913cbbfcbc934020d18....0.tmp
  • /data/data/####/e31b4afbd8c472ea3070cf74b6e19df1.0.tmp
  • /data/data/####/e45a7efa416b08904727555b7268b80255fcf546c5c2957....0.tmp
  • /data/data/####/e587aa83d8bac46cd15e674158155de258696701035ac13....0.tmp
  • /data/data/####/e6c4fdeeed76ad1987c8f5c35874501d458ac67f85d59d6....0.tmp
  • /data/data/####/e82e278739715a32424f1c4fd903fb5c40fbf9af3cfc812....0.tmp
  • /data/data/####/ef2ff3fc66c533939a7713bcecd577edf6cf4080dac79c3....0.tmp
  • /data/data/####/f01164fc0ba43f0a69bf6d911cd1f2132d13bcb96e04f52....0.tmp
  • /data/data/####/f1.img4399.comsj~emoji_e030.png
  • /data/data/####/f1.img4399.comsj~emoji_e10014.png
  • /data/data/####/f1.img4399.comsj~emoji_e10134.png
  • /data/data/####/f1.img4399.comsj~emoji_e10135.png
  • /data/data/####/f1.img4399.comsj~emoji_e10137.png
  • /data/data/####/f1.img4399.comsj~emoji_e10139.png
  • /data/data/####/f1.img4399.comsj~emoji_e10140.png
  • /data/data/####/f1.img4399.comsj~emoji_e10145.png
  • /data/data/####/f1.img4399.comsj~emoji_e10146.png
  • /data/data/####/f1.img4399.comsj~emoji_e110.png
  • /data/data/####/f1.img4399.comsj~emoji_e118.png
  • /data/data/####/f1.img4399.comsj~emoji_e307.png
  • /data/data/####/f1.img4399.comsj~emoji_e419.png
  • /data/data/####/f1.img4399.comsj~emoji_e444.png
  • /data/data/####/f1.img4399.comsj~emoji_e529.png
  • /data/data/####/f3754052239e2ffb0919980673dfc77e3ae3c35f9ffcce9....0.tmp
  • /data/data/####/f4d309d62fd9750c446e039bb8f7c33fb715f66a2dc4f69....0.tmp
  • /data/data/####/f55223b2c9e22592ef5b2c3ac230c4d112c54a7f874b478....0.tmp
  • /data/data/####/f5c6a1c8744d879e9cd218492c9f437413c3a592d67bfa0....0.tmp
  • /data/data/####/f7d78c184d703e5998d45ba5747e7affd9edfe88fedc21d....0.tmp
  • /data/data/####/f825bb28be219181ce0643af332538b20a92bcdf7938e28....0.tmp
  • /data/data/####/favicon.ico
  • /data/data/####/ff3396797dd199173e97f81d7ae2c73b411149fc478f01a....0.tmp
  • /data/data/####/ff739a9d348890fcffb2c4644dacf8be828aac97a6b3324....0.tmp
  • /data/data/####/framework.db-journal
  • /data/data/####/gamecenter183.db-journal
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gkt-journal
  • /data/data/####/gx_sp.xml
  • /data/data/####/index
  • /data/data/####/index.html
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/journal.tmp
  • /data/data/####/jpush_device_info.xml
  • /data/data/####/jpush_stat_cache.json
  • /data/data/####/jpush_stat_cache_history.json
  • /data/data/####/jpush_statistics.db
  • /data/data/####/jpush_statistics.db-journal
  • /data/data/####/jpush_statistics.db-shm (deleted)
  • /data/data/####/jpush_statistics.db-wal
  • /data/data/####/libjiagu1858054988.so
  • /data/data/####/loading1.png
  • /data/data/####/loading2.png
  • /data/data/####/loading3.png
  • /data/data/####/loading_content0.png
  • /data/data/####/loading_content1.png
  • /data/data/####/loading_content2.png
  • /data/data/####/loading_content3.png
  • /data/data/####/loading_content5.png
  • /data/data/####/m4399AppEmoji3.0.json
  • /data/data/####/m4399BBSEmoji3.0.json
  • /data/data/####/main.0b469cc8.css
  • /data/data/####/main.36264d64.js
  • /data/data/####/main.4ee0e002.js
  • /data/data/####/main.5b0bb7c5.css
  • /data/data/####/main.5e560635.css
  • /data/data/####/main.5f61bb60.js
  • /data/data/####/main.8068e237.chunk.css
  • /data/data/####/main.8068e237.chunk.css.map
  • /data/data/####/main.8a6d7afc.css
  • /data/data/####/main.acda91e5.chunk.js
  • /data/data/####/main.acda91e5.chunk.js.map
  • /data/data/####/main.f96fee95.js
  • /data/data/####/manifest.json
  • /data/data/####/mobclick_agent_cached_com.m4399.gamecenter1352
  • /data/data/####/multidex.version.xml
  • /data/data/####/placeholder.png
  • /data/data/####/plugin.meta
  • /data/data/####/precache-manifest.8772885af9f55e8b657d57621596f2d0.js
  • /data/data/####/pref.activity.visit.history.pt
  • /data/data/####/pref.app.covers.new.1.pt
  • /data/data/####/pref.headup.message.chat.unread.pt
  • /data/data/####/pref.paperdb.key.resume.tasks.pt
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushk.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/run.pid
  • /data/data/####/runtime~main.54148531.js
  • /data/data/####/runtime~main.54148531.js.map
  • /data/data/####/seq.xml
  • /data/data/####/service-worker.js
  • /data/data/####/skin_main_plugin_pref.xml
  • /data/data/####/statistics_agent_cached_com.m4399.gamecenter
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbs_pv_config
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/tdata_Gni835
  • /data/data/####/tdata_Gni835.jar
  • /data/data/####/tdata_YYn966
  • /data/data/####/tdata_YYn966.jar
  • /data/data/####/tdata_tYM194
  • /data/data/####/tdata_tYM194.jar
  • /data/data/####/tdata_wSS777
  • /data/data/####/tdata_wSS777.jar
  • /data/data/####/template.zip
  • /data/data/####/tracker.db-journal
  • /data/data/####/type1
  • /data/data/####/type2
  • /data/data/####/type3
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/media/####/.disys
  • /data/media/####/.nomedia
  • /data/media/####/.push_deviceid
  • /data/media/####/.test.txt
  • /data/media/####/.thumbcache_idx0
  • /data/media/####/.udid
  • /data/media/####/.z49ids
  • /data/media/####/4399GameCenter.1365.meta
  • /data/media/####/5d312603-4d1ae.download
  • /data/media/####/5d4d2804-8025b.download
  • /data/media/####/5d54c526-1451c6a.download
  • /data/media/####/5d67890e-3a364.download
  • /data/media/####/aio_file.zip
  • /data/media/####/app.db
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.m4399.gamecenter.bin
  • /data/media/####/com.m4399.gamecenter.db
  • /data/media/####/config.json
  • /data/media/####/gkt-journal
  • /data/media/####/gktper
  • /data/media/####/plugin_init.log
  • /data/media/####/shumei.txt
  • /data/media/####/t1v670.meta
  • /data/media/####/t2v706.meta
  • /data/media/####/t3v176.meta
  • /data/media/####/tdata_Gni835
  • /data/media/####/tdata_YYn966
  • /data/media/####/tdata_tYM194
  • /data/media/####/tdata_wSS777
  • /data/media/####/test.log
  • /data/media/####/xueyu4 (1).png
  • /data/media/####/xueyu4 (10).png
  • /data/media/####/xueyu4 (11).png
  • /data/media/####/xueyu4 (12).png
  • /data/media/####/xueyu4 (13).png
  • /data/media/####/xueyu4 (14).png
  • /data/media/####/xueyu4 (15).png
  • /data/media/####/xueyu4 (16).png
  • /data/media/####/xueyu4 (17).png
  • /data/media/####/xueyu4 (18).png
  • /data/media/####/xueyu4 (19).png
  • /data/media/####/xueyu4 (2).png
  • /data/media/####/xueyu4 (20).png
  • /data/media/####/xueyu4 (21).png
  • /data/media/####/xueyu4 (22).png
  • /data/media/####/xueyu4 (23).png
  • /data/media/####/xueyu4 (24).png
  • /data/media/####/xueyu4 (25).png
  • /data/media/####/xueyu4 (26).png
  • /data/media/####/xueyu4 (27).png
  • /data/media/####/xueyu4 (28).png
  • /data/media/####/xueyu4 (29).png
  • /data/media/####/xueyu4 (3).png
  • /data/media/####/xueyu4 (30).png
  • /data/media/####/xueyu4 (31).png
  • /data/media/####/xueyu4 (4).png
  • /data/media/####/xueyu4 (5).png
  • /data/media/####/xueyu4 (6).png
  • /data/media/####/xueyu4 (7).png
  • /data/media/####/xueyu4 (8).png
  • /data/media/####/xueyu4 (9).png
Miscellaneous:
Executes the following shell scripts:
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 24788 300 0
  • cat /proc/self/cgroup
  • cat /sys/class/net/wlan0/address
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • dmesg
  • getprop ro.product.cpu.abi
  • grep -i blueStacks
  • grep -i virtualbox
  • logcat -c
  • ls /system/bin
  • ls /system/lib
  • mount
  • ps
  • sh
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 24788 300 0
Loads the following dynamic libraries:
  • getuiext2
  • jcore123
  • libjiagu1858054988
  • m4399
  • smsdk
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CFB-NoPadding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-ECB-NoPadding
  • AES-ECB-PKCS5Padding
  • DES-ECB-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android