La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Adware.Gexin.20519

Aggiunto al database dei virus Dr.Web: 2020-06-20

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) a####.31####.com:9090
  • TCP(HTTP/1.1) a####.ytxi####.com:9090
  • TCP(HTTP/1.1) rq####.sp####.mig.####.net:80
  • TCP(HTTP/1.1) avpp1vx####.edges####.net:80
  • TCP(HTTP/1.1) up####.sdk.jig####.cn:80
  • TCP(HTTP/1.1) a####.hdg####.com:9090
  • TCP(HTTP/1.1) t####.1####.com:80
  • TCP(HTTP/1.1) a####.1####.com:80
  • TCP(HTTP/1.1) t####.0####.com.####.net:80
  • TCP(HTTP/1.1) a####.07####.com:9090
  • TCP(TLS/1.0) instant####.google####.com:443
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) md####.google####.com:443
  • TCP(TLS/1.0) 1####.217.19.206:443
  • TCP(TLS/1.0) android####.go####.com:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) l####.tbs.qq.com:443
  • TCP(TLS/1.0) x7####.1####.com:11443
  • TCP(TLS/1.0) 1####.217.17.138:443
  • TCP(TLS/1.2) 1####.217.19.206:443
  • TCP(TLS/1.2) 1####.217.17.138:443
  • TCP(TLS/1.2) 1####.217.19.195:443
  • TCP 1####.230.236.29:7000
  • UDP s.j####.cn:19000
  • TCP 1####.25.50.82:7000
DNS requests:
  • a####.07####.com
  • a####.1####.com
  • a####.31####.com
  • a####.hdg####.com
  • a####.ytxi####.com
  • and####.b####.qq.com
  • android####.go####.com
  • api.map.b####.com
  • instant####.google####.com
  • l####.tbs.qq.com
  • lot.1####.com
  • m####.go####.com
  • md####.google####.com
  • p####.google####.com
  • s.j####.cn
  • t####.0####.com
  • t####.1####.com
  • up####.sdk.jig####.cn
  • x7####.1####.com
  • x7####.1####.com
  • x7####.891####.com
HTTP GET requests:
  • avpp1vx####.edges####.net/8917689.com.js
  • avpp1vx####.edges####.net/channelConfig.js
  • avpp1vx####.edges####.net/css/
  • avpp1vx####.edges####.net/css/0.54c0b33d.css
  • avpp1vx####.edges####.net/css/app.48381db3.css
  • avpp1vx####.edges####.net/fonts/iconfont.dff7ca3a.ttf
  • avpp1vx####.edges####.net/g/
  • avpp1vx####.edges####.net/g/js/assetsmanager.min_52b82f60.js
  • avpp1vx####.edges####.net/g/js/default.thm_39d3546b.js
  • avpp1vx####.edges####.net/g/js/dragonBones.min_6252b9c4.js
  • avpp1vx####.edges####.net/g/js/egret.min_c2fb1f2f.js
  • avpp1vx####.edges####.net/g/js/egret.web.min_d7529795.js
  • avpp1vx####.edges####.net/g/js/eui.min_493403ce.js
  • avpp1vx####.edges####.net/g/js/game.min_16249d0f.js
  • avpp1vx####.edges####.net/g/js/loading.thm_6f415527.js
  • avpp1vx####.edges####.net/g/js/main.min_f4980f13.js
  • avpp1vx####.edges####.net/g/js/promise.min_83a6a5d.js
  • avpp1vx####.edges####.net/g/js/tween.min_6c5a88f9.js
  • avpp1vx####.edges####.net/g/manifest.json?v=####
  • avpp1vx####.edges####.net/g/resource/animation/BUL/BUL_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/BUL/BUL_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/BUL/BUL_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/BW/BW_Loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/BW/BW_Loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/BW/BW_Loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/CHA/CHA_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/CHA/CHA_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/CHA/CHA_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Common/common_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Common/common_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Common/common_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Common/count_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Common/count_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Common/count_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading1_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading1_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading1_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/FB/FB_Loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/KF/KF_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/KF/KF_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/KF/KF_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading1_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading1_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading1_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/LM/LM_Loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BUL_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BUL_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BUL_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BW_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BW_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/BW_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/CHA_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/CHA_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/CHA_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FB_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FB_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FB_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FLO_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FLO_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/FLO_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GB_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GB_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GB_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GT_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GT_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GT_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GU_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GU_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/GU_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/KF_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/KF_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/KF_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LH_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LH_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LH_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LM_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LM_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/LM_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/PG_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/PG_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/PG_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/SB_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/SB_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/SB_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/TEX_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/TEX_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/TEX_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/YZ_item_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/YZ_item_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/YZ_item_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_bg_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_bg_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_bg_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_logo_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_logo_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Lobby/lobby_logo_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loadingwoman_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loadingwoman_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/PG/PG_loadingwoman_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_Loading_Txt_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_Loading_Txt_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_Loading_Txt_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/SB/SB_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle1_fix_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle1_fix_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle1_fix_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle2_fix_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle2_fix_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/Shuffle2_fix_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_Bg_Ani_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_Bg_Ani_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_Bg_Ani_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/TEX/TEX_loading_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading1_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading1_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading1_tex.png
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading_ske.json
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading_tex.json
  • avpp1vx####.edges####.net/g/resource/animation/YZ/YZ_Loading_tex.png
  • avpp1vx####.edges####.net/g/resource/assets/load.res.json
  • avpp1vx####.edges####.net/g/resource/assets/loading.json
  • avpp1vx####.edges####.net/g/resource/assets/loading.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/BUL_loading_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/BUL_loading_patten.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/CHA_loading_patten.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/CHA_loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/FLO_loading_pattern....
  • avpp1vx####.edges####.net/g/resource/assets/loading/FLO_loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/GB_loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/GH_loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/GT_loadingpage_bg.jpg
  • avpp1vx####.edges####.net/g/resource/assets/loading/KF_loading_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/KF_loading_patern.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/LH_loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/PG_loading_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/PG_loading_circle.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/PG_loading_title.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/TEX_loading_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/TEX_loading_txt.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/YZ_loadingtxt.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/YZ_main_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading/main_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/loading_coinL.png
  • avpp1vx####.edges####.net/g/resource/assets/loading_coinR.png
  • avpp1vx####.edges####.net/g/resource/assets/loading_light.png
  • avpp1vx####.edges####.net/g/resource/assets/loading_patten.png
  • avpp1vx####.edges####.net/g/resource/assets/loadingpage_bg.png
  • avpp1vx####.edges####.net/g/resource/assets/main.json
  • avpp1vx####.edges####.net/g/resource/assets/main.png
  • avpp1vx####.edges####.net/g/resource/sound/common/btn.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/chipSide.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/chipUser.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/countDown.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/pokerDeal.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/pokerOpen.mp3
  • avpp1vx####.edges####.net/g/resource/sound/common/pokerShuffle.mp3
  • avpp1vx####.edges####.net/g/resource/uiassets/BUL/BUL.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/BW/BW.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/BW/BW_loading_atlas.json
  • avpp1vx####.edges####.net/g/resource/uiassets/BW/BW_loading_atlas.png
  • avpp1vx####.edges####.net/g/resource/uiassets/CHA/CHA.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/FB/FB.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/FB/FB_load.json
  • avpp1vx####.edges####.net/g/resource/uiassets/FB/FB_load.png
  • avpp1vx####.edges####.net/g/resource/uiassets/FLO/FLO.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/GB/GB.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/GH/GH.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/GT/GT.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/KF/KF.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/LH/LH.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/LM/LM.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/LM/LM_load.json
  • avpp1vx####.edges####.net/g/resource/uiassets/LM/LM_load.png
  • avpp1vx####.edges####.net/g/resource/uiassets/PG/PG.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/SB/SB.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/SB/SB_loading_atlas.json
  • avpp1vx####.edges####.net/g/resource/uiassets/SB/SB_loading_atlas.png
  • avpp1vx####.edges####.net/g/resource/uiassets/TEX/TEX.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/YZ/YZ.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/common/PG_popUpOpen.json
  • avpp1vx####.edges####.net/g/resource/uiassets/common/PG_popUpOpen.png
  • avpp1vx####.edges####.net/g/resource/uiassets/common/common.res.json
  • avpp1vx####.edges####.net/g/resource/uiassets/common/icons.json
  • avpp1vx####.edges####.net/g/resource/uiassets/common/icons.png
  • avpp1vx####.edges####.net/image/10/ico
  • avpp1vx####.edges####.net/image/2/1570334011639.png
  • avpp1vx####.edges####.net/image/2/1570334021175.png
  • avpp1vx####.edges####.net/image/2/1570334026759.png
  • avpp1vx####.edges####.net/image/2/1570353629814.png
  • avpp1vx####.edges####.net/images/activity/mobile_banner.png
  • avpp1vx####.edges####.net/images/winPopup_bg.png
  • avpp1vx####.edges####.net/images/winPopup_btn.png
  • avpp1vx####.edges####.net/js/0.f2d84476.js
  • avpp1vx####.edges####.net/js/app.eaf1f534.js
  • avpp1vx####.edges####.net/js/chunk-vendors.e94ac32d.js
  • avpp1vx####.edges####.net/langConfig.js
  • avpp1vx####.edges####.net/lotteryLangConfig.js
  • avpp1vx####.edges####.net/m/app
  • avpp1vx####.edges####.net/myConfig.js
  • avpp1vx####.edges####.net/playRuleConfigWap.js
  • avpp1vx####.edges####.net/playRuleConfigWeb.js
  • avpp1vx####.edges####.net/resultCodeLangConfig.js
  • avpp1vx####.edges####.net/thriveGame.css
  • avpp1vx####.edges####.net/validationConfig.js
  • avpp1vx####.edges####.net/zlcai-favicon.ico
  • t####.0####.com.####.net/tl01.html
  • t####.1####.com/tl01.html
HTTP POST requests:
  • a####.07####.com:9090/?appName=####&os=####&version=####
  • a####.1####.com/FanLottery6HC/openApi?tio=####
  • a####.1####.com/FanPlatform/appConfig/detail?tio=####
  • a####.1####.com/FanPlatform/checkUser/status?tio=####
  • a####.1####.com/FanPlatform/imageApi?tio=####
  • a####.1####.com/FanPlatform/network/check?tio=####
  • a####.1####.com/FanPlatform/platformApi?tio=####
  • a####.1####.com/FanPlatform/winBroadcast/findShowRow?tio=####
  • a####.1####.com/FanPlatform/winBroadcast/listWinBroadcast?tio=####
  • a####.31####.com:9090/?appName=####&os=####&version=####
  • a####.hdg####.com:9090/?appName=####&os=####&version=####
  • a####.ytxi####.com:9090/?appName=####&os=####&version=####
  • rq####.sp####.mig.####.net/rqd/async?aid=####
  • up####.sdk.jig####.cn/v1/push/sdk/postlist
File system changes:
Creates the following files:
  • /data/data/####/.cl
  • /data/data/####/.jg.ic
  • /data/data/####/01d2f16b6c130e0b_0
  • /data/data/####/022b7080d25a239a_0
  • /data/data/####/02b602118bc244c3_0
  • /data/data/####/02ee1072b455cafa_0
  • /data/data/####/0488626b1fc1fb88_0
  • /data/data/####/049d16e2f9996dac_0
  • /data/data/####/0615b117200b382b_0
  • /data/data/####/086d20b4c89b7f8b_0
  • /data/data/####/09375d43a6177d7b_0
  • /data/data/####/0a60fd1b13508a18_0
  • /data/data/####/0d9c8dca90c638bc_0
  • /data/data/####/0de8a3da09f1b99b_0
  • /data/data/####/0f3261957dfc908d_0
  • /data/data/####/1002
  • /data/data/####/1004
  • /data/data/####/108d2aa618148412_0
  • /data/data/####/109166e63c6f80d5_0
  • /data/data/####/10e47f208af9d634_0
  • /data/data/####/115a1e2f8efe617a_0
  • /data/data/####/14d8633cde5f9037_0
  • /data/data/####/14db64be2bf094d1_0
  • /data/data/####/15a5a1704827c1b4_0
  • /data/data/####/174fb3cc13bfadfa_0
  • /data/data/####/180aedf13682d6a5_0
  • /data/data/####/1885cf1425cdd0dd_0
  • /data/data/####/18bf875b7c35b601_0
  • /data/data/####/18f12b68b5485d47_0
  • /data/data/####/19b3a4976bd46453_0
  • /data/data/####/1a4142612bd84ea7_0
  • /data/data/####/1baa0128b44d8e55_0
  • /data/data/####/1c98036ddb41644c_0
  • /data/data/####/1cf590287cd77ffd_0
  • /data/data/####/1e8347a4d995e37a_0
  • /data/data/####/1e842599343f855c_0
  • /data/data/####/203941436f8176c0_0
  • /data/data/####/203941436f8176c0_1
  • /data/data/####/21f393ce979146b1_0
  • /data/data/####/2466b0dc1f9e2b96_0
  • /data/data/####/250ab18366f658f8_0
  • /data/data/####/2542cd46a0f926cf_0
  • /data/data/####/2542cd46a0f926cf_0 (deleted)
  • /data/data/####/259bf32af37d13d0_0
  • /data/data/####/27cbfca89161bb6b_0
  • /data/data/####/2810b9c82a10ba47_0
  • /data/data/####/286f6e2decea1d01_0
  • /data/data/####/2a03101abc2ac6a0_0
  • /data/data/####/2ac43f93806df93f_0
  • /data/data/####/2b9ced4de8a4827e_0
  • /data/data/####/2bca6654780423b9_0
  • /data/data/####/2e55c1c2a5f0662f_0
  • /data/data/####/2eef7cde69f89a44_0
  • /data/data/####/3169968190adf182_0
  • /data/data/####/36f2ea705de76edf_0
  • /data/data/####/3770271422428ad2_0
  • /data/data/####/3773a457dfe2eb15_0
  • /data/data/####/38a69759e93ef698_0
  • /data/data/####/396cbbe9266555da_0
  • /data/data/####/39dfca4548525993_0
  • /data/data/####/3d45ed46edb2eb77_0
  • /data/data/####/3d742c3223af22b8_0
  • /data/data/####/3de92b31f83a8bf2_0
  • /data/data/####/3e511077163050e9_0
  • /data/data/####/3ea6a01c55900208_0
  • /data/data/####/4475df37cd8c001a_0
  • /data/data/####/45877739925709e2_0
  • /data/data/####/466677382faf33f5_0
  • /data/data/####/466677382faf33f5_0 (deleted)
  • /data/data/####/46f83e3e0e50cb0a_0
  • /data/data/####/46fa06ee49c33935_0
  • /data/data/####/4cd043eadf0cd24e_0
  • /data/data/####/4db160c7168c5e78_0
  • /data/data/####/519828b6e588417d_0
  • /data/data/####/5505a6159ccbf247_0
  • /data/data/####/57b5a8af45fec05e_0
  • /data/data/####/593ced177a308304_0
  • /data/data/####/5a96e8688b0cc3d6_0
  • /data/data/####/5c817b18b05f8c50_0
  • /data/data/####/5c817b18b05f8c50_1
  • /data/data/####/6128ea7cb1c02ff5_0
  • /data/data/####/6128ea7cb1c02ff5_1
  • /data/data/####/62c54ed1a2409c18_0
  • /data/data/####/63b672b8caf7bc3c_0
  • /data/data/####/641b1c2eabf22cb3_0
  • /data/data/####/66efbb765bdf6893_0
  • /data/data/####/691789037e0aec78_0
  • /data/data/####/6ceff85284a5591b_0
  • /data/data/####/6d36ee13a48aa073_0
  • /data/data/####/6df4ac22c992148a_0
  • /data/data/####/73bf0f328dbec0f0_0
  • /data/data/####/74b27017531482d7_0
  • /data/data/####/74b27017531482d7_1
  • /data/data/####/756cc3db9156ad75_0
  • /data/data/####/774115a291fb78ca_0
  • /data/data/####/794eae4a9a250fa9_0
  • /data/data/####/7ba2661a1823e5a6_0
  • /data/data/####/7cf34c8b23e56d01_0
  • /data/data/####/7e6143e1d63ad129_0
  • /data/data/####/80653340f40ce7d0_0
  • /data/data/####/82010ccd91fb656e_0
  • /data/data/####/8257f42043b429c0_0
  • /data/data/####/826391089ce24489_0
  • /data/data/####/88f61b98be557c6d_0
  • /data/data/####/899e6042c0485653_0
  • /data/data/####/8a8e7c7586fca5db_0
  • /data/data/####/8bb9a8aee69fc28d_0
  • /data/data/####/8c376274b728aea9_0
  • /data/data/####/8c376274b728aea9_1
  • /data/data/####/8c91c4eedb86ccaf_0
  • /data/data/####/8e7be50f239c1679_0
  • /data/data/####/8eaa65645537b642_0
  • /data/data/####/90d57e80427264d2_0
  • /data/data/####/930b19784911e750_0
  • /data/data/####/936a0aad25cf434b_0
  • /data/data/####/95a2dcf9eb8d5ab8_0
  • /data/data/####/96e85cc4fe7049e2_0
  • /data/data/####/9851a75e2b77e2dd_0
  • /data/data/####/994e3435633d0539_0
  • /data/data/####/994e3435633d0539_1
  • /data/data/####/99ee47f68b0013a1_0
  • /data/data/####/9e7ff37335f786c4_0
  • /data/data/####/9ebb983b50b8ffbe_0
  • /data/data/####/9f5e4ab471a76898_0
  • /data/data/####/9f5e4ab471a76898_1
  • /data/data/####/9fd29b070d75308c_0
  • /data/data/####/Cookies-journal
  • /data/data/####/JPushSA_Config.xml
  • /data/data/####/JPushSA_Config.xml.bak
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a03b891a91e83169_0
  • /data/data/####/a0f5dcd293d408ae_0
  • /data/data/####/a4127684960d8cd7_0
  • /data/data/####/a4c1f41df79da884_0
  • /data/data/####/a5d518253533e29f_0
  • /data/data/####/a8435ec766015634_0
  • /data/data/####/a8f1df94ba3215cc_0
  • /data/data/####/ab39ee76fe90514b_0
  • /data/data/####/ad_auth.xml
  • /data/data/####/authStatus_com.zhizheng.huanbao.xml
  • /data/data/####/b140027cfb4d3364_0
  • /data/data/####/b39905db226f1821_0
  • /data/data/####/b4ee1674289238cb_0
  • /data/data/####/b5899c2b6e41a215_0
  • /data/data/####/b67a91e244dfc836_0
  • /data/data/####/b8097a5224c7367a_0
  • /data/data/####/bugly_db_-journal
  • /data/data/####/c0d5f51eb89e6c71_0
  • /data/data/####/c1d82df7075c3952_0
  • /data/data/####/c1d82df7075c3952_1
  • /data/data/####/c3d0860ce142f08e_0
  • /data/data/####/c3d55a6a614939f5_0
  • /data/data/####/c516dc45cbd8c079_0
  • /data/data/####/c5296c29d2304e1d_0
  • /data/data/####/c6cc530a3ff57570_0
  • /data/data/####/c6ef79c726abf00a_0
  • /data/data/####/c71758766d9b1154_0
  • /data/data/####/c7e52ccc631650f0_0
  • /data/data/####/c8ad883c0b380530_0
  • /data/data/####/ccb33daa66df4b71_0
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.dex;classes3.dex
  • /data/data/####/cn.jpush.android.user.profile.xml
  • /data/data/####/cn.jpush.preferences.v2.rid.xml
  • /data/data/####/cn.jpush.preferences.v2.xml
  • /data/data/####/cn.jpush.preferences.v2.xml.bak
  • /data/data/####/com.zhizheng.huanbao.BETA_VALUES.xml
  • /data/data/####/com.zhizheng.huanbao_preferences.xml
  • /data/data/####/core_info
  • /data/data/####/crashrecord.xml
  • /data/data/####/d1c9113a30200190_0
  • /data/data/####/d29184dd2dff50e7_0
  • /data/data/####/d5aa55f6f0884267_0
  • /data/data/####/d6811417ebb1a87f_0
  • /data/data/####/d7ae71918dfa8070_0
  • /data/data/####/d9c42902a91cbfa8_0
  • /data/data/####/da7a48617d1a8aa9_0
  • /data/data/####/daccef50c6ea8050_0
  • /data/data/####/de57fb4d071f9ee6_0
  • /data/data/####/debug.conf
  • /data/data/####/dfa37fbe86ad4120_0
  • /data/data/####/download_upload
  • /data/data/####/e5635a6823fc5559_0
  • /data/data/####/e5dfed92c175b005_0
  • /data/data/####/e5dfed92c175b005_1
  • /data/data/####/e84444b4c6bd913b_0
  • /data/data/####/ebfddfb486e53572_0
  • /data/data/####/ebfddfb486e53572_1
  • /data/data/####/ec1a484ea93ec68b_0
  • /data/data/####/ee6117d3ed845b3e_0
  • /data/data/####/eec36118755a206f_0
  • /data/data/####/eec36118755a206f_1
  • /data/data/####/f0cd094f1aed4cc8_0
  • /data/data/####/f20970b3480204bf_0
  • /data/data/####/f20970b3480204bf_1
  • /data/data/####/f214acc65d8c179f_0
  • /data/data/####/f3f03fb4d3d96869_0
  • /data/data/####/f3f03fb4d3d96869_1
  • /data/data/####/f3fb73a7aa01b1f6_0
  • /data/data/####/f52ecb1770c3fb7c_0
  • /data/data/####/fb00f1d47f657e81_0
  • /data/data/####/fb8807549df27086_0
  • /data/data/####/fbc12055eb05fd80_0
  • /data/data/####/fd5ca0055112b459_0
  • /data/data/####/fdc61f971e08427e_0
  • /data/data/####/fdfc3fb8303dad94_0
  • /data/data/####/fec3f7bbedad7933_0
  • /data/data/####/fee5227f9cfbd110_0
  • /data/data/####/http_x7a58r.8917689.com_0.localstorage-journal
  • /data/data/####/index
  • /data/data/####/jpush_stat_cache.json
  • /data/data/####/libcuid.so
  • /data/data/####/libjiagu.so
  • /data/data/####/local_crash_lock
  • /data/data/####/local_crash_lock (deleted)
  • /data/data/####/mac.xml
  • /data/data/####/metrics_guid
  • /data/data/####/native_record_lock (deleted)
  • /data/data/####/proc_auxv
  • /data/data/####/security_info
  • /data/data/####/sharePreName.xml
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_config.xml.bak
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbs_pv_config
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • getprop
  • getprop ro.product.cpu.abi
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-ECB-NoPadding
  • AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android