Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Waps.153

Added to the Dr.Web virus database: 2018-07-08

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Waps.5.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) cdn.43####.com.####.com:80
  • TCP(HTTP/1.1) f####.fengkon####.com:80
  • TCP(HTTP/1.1) s####.m.img####.com:80
  • TCP(HTTP/1.1) f1.img####.com:80
  • TCP(HTTP/1.1) p####.43####.com:80
  • TCP(HTTP/1.1) f03.img####.com:80
  • TCP(HTTP/1.1) cloud####.fengkon####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) sni.c####.q####.####.net:80
  • TCP(TLS/1.0) m####.439####.net:443
  • TCP c####.g####.ig####.com:5225
  • TCP sdk.o####.t####.####.com:5224
  • TCP p####.43####.com:4800
DNS requests:
  • 7j####.c####.z0.####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cdn.43####.com
  • cloud####.fengkon####.com
  • f####.fengkon####.com
  • f01.img####.com
  • f02.img####.com
  • f03.img####.com
  • f04.img####.com
  • f1.img####.com
  • m####.439####.net
  • p####.43####.com
  • p.img####.com
  • pus####.43####.com
  • s####.m.img####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sj2.img####.com
HTTP GET requests:
  • cdn.43####.com.####.com//android/box/player/v3.1/miniGame-entryConfig-ma...
  • cdn.43####.com.####.com//app/android/v4.4/gameDetail-mareacode-999998-id...
  • cdn.43####.com.####.com/app/android/v3.0/config-dailySign-mareacode-9999...
  • cdn.43####.com.####.com/app/android/v3.1/album-list-mareacode-999998-n-2...
  • cdn.43####.com.####.com/app/android/v3.1/software-cover-mareacode-999998...
  • cdn.43####.com.####.com/app/android/v3.4/config-common-mareacode-999998....
  • cdn.43####.com.####.com/app/android/v3.4/game-category-mareacode-999998-...
  • cdn.43####.com.####.com/app/android/v3.6/custom-square-mareacode-999998-...
  • cdn.43####.com.####.com/app/android/v4.2/album-info-mareacode-999998-id-...
  • cdn.43####.com.####.com/app/android/v4.2/game-list-mareacode-999998-kid-...
  • cdn.43####.com.####.com/app/android/v4.3/game-index-mareacode-999998.html
  • cdn.43####.com.####.com/app/forums/android/v2.1/chat-faces-mareacode-999...
  • cdn.43####.com.####.com/app/forums/android/v3.3/chat-faces-mareacode-999...
  • cdn.43####.com.####.com/user/sns/box/android/v1.0/headgear-feature-marea...
  • f03.img####.com/230950826~480x280
  • f03.img####.com/233338360~480x280
  • f03.img####.com/234275450~480x280
  • f03.img####.com/235575345~480x280
  • f03.img####.com/235635600~480x280
  • f03.img####.com/downloader/upload/toutao/6.28liuxingyu/piyixia.zip
  • f03.img####.com/downloader/upload/toutao/zhangcao/xiaocao3.zip
  • f03.img####.com/downloader/upload/wodeyemian/20180628/new.zip
  • f03.img####.com/ma~577_20180525162642_5b07c8c209e73.jpeg
  • f03.img####.com/ma~577_20180531171311_5b0fbca75d9f9.jpeg
  • f03.img####.com/ma~577_20180531171830_5b0fbde688fac.jpeg
  • f03.img####.com/ma~577_20180601164713_5b110811b0d39.jpeg
  • f03.img####.com/ma~577_20180608172307_5b1a4afbe860a.jpeg
  • f03.img####.com/ma~577_20180622172156_5b2cbfb478ff6.jpeg
  • f03.img####.com/sj~emoji_e10140.png
  • f03.img####.com/sj~emoji_e412.png
  • f1.img####.com/downloader/tpl/thread/template189.zip
  • f1.img####.com/downloader/upload/toutao/dongwu/maomi.zip
  • f1.img####.com/ma~100273_logo2_4c34.jpg~124x124
  • f1.img####.com/ma~103587_logo2_64d2.jpg~124x124
  • f1.img####.com/ma~104850_logo2_dfb7.jpg~124x124
  • f1.img####.com/ma~105786_logo2_1522.jpg~124x124
  • f1.img####.com/ma~106139_logo2_0d57.jpg~124x124
  • f1.img####.com/ma~109196_logo2_7ff8.jpg~124x124
  • f1.img####.com/ma~109559_logo2_ef30.jpg~124x124
  • f1.img####.com/ma~111662_logo2_045d.jpg~124x124
  • f1.img####.com/ma~112104_logo2_e22c.jpg~124x124
  • f1.img####.com/ma~115226_logo2_6122.jpg~124x124
  • f1.img####.com/ma~115355_logo2_f68b.jpg~124x124
  • f1.img####.com/ma~115431_logo2_f8c0.jpg~124x124
  • f1.img####.com/ma~115552_logo2_a6d1.jpg~124x124
  • f1.img####.com/ma~115591_logo2_271c.jpg~124x124
  • f1.img####.com/ma~115678_logo2_1636.jpg~124x124
  • f1.img####.com/ma~115956_logo2_5def.jpg~124x124
  • f1.img####.com/ma~115965_logo2_8ebc.jpg~124x124
  • f1.img####.com/ma~116147_logo2_60f7.jpg~124x124
  • f1.img####.com/ma~117094_logo2_cfd9.jpg~124x124
  • f1.img####.com/ma~117892_logo2_1d17.jpg~124x124
  • f1.img####.com/ma~118519_logo2_2a25.jpg~124x124
  • f1.img####.com/ma~120006_logo2_0e49.jpg~124x124
  • f1.img####.com/ma~120456_logo2_4639.jpg~124x124
  • f1.img####.com/ma~121520_logo2_f175.jpg~124x124
  • f1.img####.com/ma~121553_logo2_1d14.jpg~124x124
  • f1.img####.com/ma~121753_logo2_a3d2.jpg~124x124
  • f1.img####.com/ma~121809_logo2_7236.jpg~124x124
  • f1.img####.com/ma~166_20180426161733_5ae18b1da43fc.png
  • f1.img####.com/ma~166_20180426161743_5ae18b27a76a5.png
  • f1.img####.com/ma~166_20180426161802_5ae18b3ab8b28.png
  • f1.img####.com/ma~166_20180426161821_5ae18b4da812b.png
  • f1.img####.com/ma~166_20180426161836_5ae18b5c38bf7.png
  • f1.img####.com/ma~166_20180426161852_5ae18b6c02d3a.png
  • f1.img####.com/ma~167_20180618234010_5b27d25a01aca.png
  • f1.img####.com/ma~167_20180618234026_5b27d26a2c009.png
  • f1.img####.com/ma~167_20180618234036_5b27d2743b026.png
  • f1.img####.com/ma~167_20180618234046_5b27d27e57819.png
  • f1.img####.com/ma~167_20180618234059_5b27d28b5326f.png
  • f1.img####.com/ma~167_20180618234110_5b27d2961ae10.png
  • f1.img####.com/ma~167_20180618234121_5b27d2a1b5c21.png
  • f1.img####.com/ma~167_20180618234132_5b27d2ac636c9.png
  • f1.img####.com/ma~167_20180618234144_5b27d2b862718.png
  • f1.img####.com/ma~167_20180618234158_5b27d2c6211dc.png
  • f1.img####.com/ma~219_20180607114133_5b18a96d5ea1b.jpeg
  • f1.img####.com/ma~27425_logo2_e054.jpg~124x124
  • f1.img####.com/ma~27_20170706154005_595de955018bc.png
  • f1.img####.com/ma~27_20180423163623_5add9b0747fa2.png
  • f1.img####.com/ma~27_20180611100401_5b1dd8913c9ea.jpeg
  • f1.img####.com/ma~27_20180620093933_5b29b055c6466.png
  • f1.img####.com/ma~27_20180625095738_5b304c127e75c.jpeg
  • f1.img####.com/ma~27_20180706153035_5b3f1a9b6791a.jpeg
  • f1.img####.com/ma~290_20180517134245_5afd165531c4f.png
  • f1.img####.com/ma~30_20180423154301_5add8e85e9036.png
  • f1.img####.com/ma~30_20180423154529_5add8f19ae49b.png
  • f1.img####.com/ma~30_20180423154752_5add8fa884718.png
  • f1.img####.com/ma~30_20180423163038_5add99aec4cca.png
  • f1.img####.com/ma~30_20180423163148_5add99f421bdf.png
  • f1.img####.com/ma~403_logo2_16eb.jpg~124x124
  • f1.img####.com/ma~577_20180510150009_5af3edf9c93d0.jpeg
  • f1.img####.com/ma~577_20180627161504_5b33478873efe.jpeg
  • f1.img####.com/ma~577_20180629151032_5b35db6867d47.jpeg
  • f1.img####.com/ma~577_20180706164803_5b3f2cc357fbd.jpeg
  • f1.img####.com/ma~85093_logo2_45a8.jpg~124x124
  • f1.img####.com/ma~92170_logo2_a073.jpg~124x124
  • f1.img####.com/ma~97256_logo2_5e4a.jpg~124x124
  • f1.img####.com/ma~98519_logo2_b59e.jpg~124x124
  • f1.img####.com/ma~99689_logo2_b450.jpg~124x124
  • f1.img####.com/ma~g_104850_11b9.jpg
  • f1.img####.com/ma~g_104850_5dc1.jpg
  • f1.img####.com/ma~g_104850_d481.jpg
  • f1.img####.com/ma~g_104850_f8cf.jpg
  • f1.img####.com/ma~g_104850_fdbc.jpg
  • f1.img####.com/ma~wap_s2_1530338329
  • f1.img####.com/ma~wap_s2_1530585087
  • f1.img####.com/mi~cea9f3254d903ea3488d910435a9a71a.jpeg
  • f1.img####.com/sj~109088_logo_5950c7367ccd5.jpg~124x124
  • f1.img####.com/sj~117437_logo_5a543071329cd.jpg~124x124
  • f1.img####.com/sj~52002_logo_5850b3fa98202.jpg~124x124
  • f1.img####.com/sj~opensj_5b177b6e6c2a6
  • f1.img####.com/sj~opensj_5b177b6e7b79c
  • f1.img####.com/sj~opensj_5b177b6ea615d
  • f1.img####.com/sj~opensj_5b177b6ebc976
  • f1.img####.com/sj~opensj_5b177b6ed677a
  • f1.img####.com/youpai~upload/17352222018/05/24/15_mwonu8.960x540.jpg~250...
  • f1.img####.com/youpai~upload/17981452018/06/22/06_3=FoYp.960x540.jpg~250...
  • f1.img####.com/yxh~u/17617468562018/07/08/20_bQMwV9.436x286.jpg~480x480
  • p####.43####.com/cloud.php?act=####&rectime=####&appid=####&uid=####&fla...
  • p####.43####.com/cloud.php?act=####&rectime=####&flag=####&data=####
  • sni.c####.q####.####.net/config/hz-hzv3.conf
  • sni.c####.q####.####.net/tdata_YYn966
  • sni.c####.q####.####.net/tdata_eOt091
HTTP POST requests:
  • c-h####.g####.com/api.php?format=####&t=####
  • cloud####.fengkon####.com/v2/device/conf
  • cloud####.fengkon####.com/v2/device/profile
  • f####.fengkon####.com/v2/device/profile
  • s####.m.img####.com/trace/<Package>/1.0/360/
  • s####.m.img####.com/trace/<Package>/1.0/360/1100f9Ud1xsklkQz3h530ec43
  • s####.m.img####.com/trace/<Package>/1.0/Unknown/.config?version=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####
Modified file system:
Creates the following files:
  • /data/data/####/._index.css
  • /data/data/####/._index.html
  • /data/data/####/._index.js
  • /data/data/####/._js
  • /data/data/####/.jg.ic
  • /data/data/####/.policy
  • /data/data/####/0103d812b7b84d3d48bebdee493d0ed2a50efad3b456d2c....0.tmp
  • /data/data/####/01175e30c7ad5c735b2a7e81ddfec79e852bfdb79be4c9b....0.tmp
  • /data/data/####/028c4ce3203be19ca85602d053aa538a6e1ab5604f5bcd9....0.tmp
  • /data/data/####/02bfc27ffb58b9a3796a629dbcb3ab08721b757150a1c08....0.tmp
  • /data/data/####/0335b35a8fba038de5aa5461924b9d7dd98f534d6270dc2....0.tmp
  • /data/data/####/0381500f39a69c30e2998746dfe20be504baeea97d17872....0.tmp
  • /data/data/####/03fb97c6d8cecb673cdb50ac9b3fab21d9a8e6fd0ce3620....0.tmp
  • /data/data/####/04316336a8f6c70fbe185704ceb466ab23cdb19dbd3fd64....0.tmp
  • /data/data/####/045138a1e4216b74d31f49c42dece1b6f2929e0072458a0....0.tmp
  • /data/data/####/062c2aa72a311d78e0e6010cc3abccd28872c9c933b48fa....0.tmp
  • /data/data/####/06c091f2bd42e160025ec2992ef1bf8d9fdc0451a915f46....0.tmp
  • /data/data/####/0877363b249c39a56264a8124fa6f4874cfbc97b24537c8....0.tmp
  • /data/data/####/08afb90989af4e8027ada76491e4545bf53e7306d073603....0.tmp
  • /data/data/####/091cbd025fd3a3ca704a634b662de31be91ed31355e21f4....0.tmp
  • /data/data/####/0ee24ce0f361092745a16150c27923fcf0ae4d160a50f21....0.tmp
  • /data/data/####/0f4dedde2fab45afdc1c9c4e3d079e6e254fff1a1946884....0.tmp
  • /data/data/####/146204ef3eb0c241f2c105b88502f753fdec824f3db1399....0.tmp
  • /data/data/####/16f904ca9b8a363fa0fea75b2b0c2c8ceb93689f0071dd4....0.tmp
  • /data/data/####/18cc77f1e919a429825aca66794c09f42af96188a52c7e2....0.tmp
  • /data/data/####/1931448f23229a4332624dcf4e74c30ee083b0c28a49330....0.tmp
  • /data/data/####/19ff28277da7474e6401bb47ab3295e360a9edd11fd6a4d....0.tmp
  • /data/data/####/1a3618994b612504ecb54fa20cc95a97b2f0708e5c785e0....0.tmp
  • /data/data/####/1cb7fb85fd7f8a75f20efea08f54e3dcbd72e32a7eb5779....0.tmp
  • /data/data/####/1d9487825cae0ee06a7d696ed6cb0c95125cd163843aebb....0.tmp
  • /data/data/####/1f22192319b3caa4b92750a03e2b50abceb715e8467d0a0....0.tmp
  • /data/data/####/1f74ba8ae6d7c852fb29c21582ac6e4a02fce098e65d7d2....0.tmp
  • /data/data/####/22057bda3a70211d694aa5186d3d844b60058aa0dc47c9a....0.tmp
  • /data/data/####/236b7312c1db3ea3ce5508f3c820d198fd369b3c269d6d6....0.tmp
  • /data/data/####/2693fe531a9a2f02448357e208c381e062a6a20bc384ebe....0.tmp
  • /data/data/####/2827dfb5f372326aa9351ee8703c55975e076a387e94d1d....0.tmp
  • /data/data/####/286d3644ac2fef61042706aa37a71c8c13f5b273abafcbf....0.tmp
  • /data/data/####/28c56c5c447bac11fb206476faa13d4d2f8a49e4a81c85b....0.tmp
  • /data/data/####/2f1bb3c431b9bdd539ecfb9eb3c5703bb26125e5bea0381....0.tmp
  • /data/data/####/30feada53f80f592ae13185d08ed2a6d6201f7b281976f1....0.tmp
  • /data/data/####/31c7017e863fed6dd06799707c6cf2da438fa09cbe8fc9a....0.tmp
  • /data/data/####/323aa7580b0aaa253afe4ddc76865af96cd0f12656992b5....0.tmp
  • /data/data/####/34a4b6025a59263f356a24c1f066539c64088e66d9932c4....0.tmp
  • /data/data/####/34ae652cda994b8bcc2dc5a90315f6d1194fbf032d6f078....0.tmp
  • /data/data/####/3721ed0de15507ca47fc9802f376d2ec42260381980ed1f....0.tmp
  • /data/data/####/37b83352a2503ac5c4d3644a946a9ed0a1eaeeaf75d50c8....0.tmp
  • /data/data/####/3826de567378b3f88c340b02a06514d12301ceef2d6395d....0.tmp
  • /data/data/####/39a15eceb8899be48a5019d2796876b119616d40c0c1bbd....0.tmp
  • /data/data/####/3b83bba6b660edc3ed4602d5b58588a2472c734c9b1d6b4....0.tmp
  • /data/data/####/44e8df07c533a70964fe2b3efd4a1f4dfce0a629fab3350....0.tmp
  • /data/data/####/44fa721c10e008827ce3f503dccbe15edff66614c9fad44....0.tmp
  • /data/data/####/458984e00bf51e8b3fbf9a837dd10c9427872e558110a57....0.tmp
  • /data/data/####/4603e3c60f8123427cb3f39d609afa2228186278379b617....0.tmp
  • /data/data/####/465ed22eff17fa608b8cfa3199735cda8e2bd9194a29450....0.tmp
  • /data/data/####/4a1906ef41df9a6f1a638acf7ffd15a75d296bead0ad476....0.tmp
  • /data/data/####/4a40c2e1f05507173b558449b1951883fe978a79f35219b....0.tmp
  • /data/data/####/4bec97ae3bd36070fac4554eeb08ccb6184977c2e67f843....0.tmp
  • /data/data/####/4c5ffbd0d9e25d3ee3b8ee5ae01647d9837a1e0e60eabd5....0.tmp
  • /data/data/####/4d6d174bf88689b8cf687972e87303e82b3e40e181c1978....0.tmp
  • /data/data/####/4e509207be3024aa15d323fb8f47eb72bfdeb43b04e90af....0.tmp
  • /data/data/####/4eb40b7a4bf17574113bb19c715915459d517e23569d4b4....0.tmp
  • /data/data/####/4fc5d9a2383c7762a28f9c4d489beca61a8b28a6ac54733....0.tmp
  • /data/data/####/4fd67ead20265605ce05ad518f8d44ffe5ceabc208f4705....0.tmp
  • /data/data/####/50e7e04272fef86e234745ebe9507d2247b7ed39e7213e9....0.tmp
  • /data/data/####/50ede90026446a7092efde16158153a706dffde0cd18596....0.tmp
  • /data/data/####/54daa4540584990e6e018de836e5f89a480f1c82135c027....0.tmp
  • /data/data/####/5593ca6988005a4ddb85369c015a824e60810e2ab43e192....0.tmp
  • /data/data/####/563af24bbb00b5325454ef2c0935475bf0aef83d33f6ea0....0.tmp
  • /data/data/####/563ef7833b679227438bc0cfb691141fbfee2746316bf02....0.tmp
  • /data/data/####/579cd4c3ae7ad1d8f73bbb2b7f0313b011aaf3d1110bf3b....0.tmp
  • /data/data/####/5c9743567b004b281e11040e98f1704931ded10cb661692....0.tmp
  • /data/data/####/5dc009eb54b724270d6acbab0c37d80eb4d38cad3b2ef2c....0.tmp
  • /data/data/####/5e75503e17072c0785fe55973b26d896e691c41db18da47....0.tmp
  • /data/data/####/639fffa265eab094d5c8fe70644a5379c23cbbefe5bfc64....0.tmp
  • /data/data/####/657980096168115e6b0bbc690ad52909e284d1eb7c2a0a4....0.tmp
  • /data/data/####/6698739573fcc405690ab498e6106bebba7ccce7005ec55....0.tmp
  • /data/data/####/66e7dd311b8f3e77b11a6fdc4bf5fb063110ce3fa8e27e2....0.tmp
  • /data/data/####/67ecddccb72c8fdc17ee899f1d1c8261e20ffc8c8da47d0....0.tmp
  • /data/data/####/68b5344c531e03d9f93d316662566e0d8056aa8f80bc5bb....0.tmp
  • /data/data/####/6b5b899ea1e7f68a44510c04ed6a7ffec45c1d2886e1acf....0.tmp
  • /data/data/####/6b85f2429d240ff54f90a9872f56a61a77a4df856c84618....0.tmp
  • /data/data/####/6db7ce3eaa53b4e1e0b626b0ea5a24297d3e583df80f813....0.tmp
  • /data/data/####/6e3c770349eb076cdd9fe12d4ccafa7b520a13ae3886693....0.tmp
  • /data/data/####/6e6ae4e473c39cd29bf43e66444b4cb6569de4e0d61c715....0.tmp
  • /data/data/####/6f0adfe8b82ad5f1020828a54a40814200bef9b644c9015....0.tmp
  • /data/data/####/6fb7de4c13ae311adf50a0c7c831203b4d113878ac14bab....0.tmp
  • /data/data/####/7019f4bb02229a593c7390ffae64fd595d8e3eca9f70334....0.tmp
  • /data/data/####/71fc79837fa48ff54161dcb062449ac6eb2e4e9ebbd5dd1....0.tmp
  • /data/data/####/72c11d88697e2677a4c0812909fe18f7ecd6f256d3abddb....0.tmp
  • /data/data/####/73938b7841243429d730cf5435527ed67dcd5218c0e8045....0.tmp
  • /data/data/####/73c64da6bd2fd0d08683908f9e7bfe83d4df5eedff2cebb....0.tmp
  • /data/data/####/76445cdbaeae501179ac2af3a44e6e8475dd19607dd7440....0.tmp
  • /data/data/####/76c468e8dc669ffce31977ddf6c74532da19e4436a7b0c4....0.tmp
  • /data/data/####/7951baaef5b8171f7bf862fa3990f700b3764d1b9823b1f....0.tmp
  • /data/data/####/80fb233b7e02e816c0bdaa5ebd87e2216adb958d4ff0810....0.tmp
  • /data/data/####/83843f2830417a3bda69c618f6444446d8ade30cd4b2fca....0.tmp
  • /data/data/####/83bf5e1a9c7dcc4a9d929e385f4b3beebe08d2957cea3e6....0.tmp
  • /data/data/####/87f786bbc2a91dab49f88b4b8b4725a481c2eeeb7976c3c....0.tmp
  • /data/data/####/88c085751a501221ce94bde79ea17dc8b17c60749f2d907....0.tmp
  • /data/data/####/8976d5ad7c41f0a761cdd142ab8ddf4c07a0580900fc94f....0.tmp
  • /data/data/####/89b62b30965a0bfa29ffe066e82d275c2e6857b16eff560....0.tmp
  • /data/data/####/8b094aae4d86a0d814e103690ade4a8e2a789e86c769d55....0.tmp
  • /data/data/####/8b6414a131338fd342061af72b815648f0dcef688f34cfc....0.tmp
  • /data/data/####/8c7f5fe98a450bbfafcda18202cdf19d98c9564f8ee4259....0.tmp
  • /data/data/####/8cdc1f61e4d8cb283268fe1d87aa396e083cc0307427795....0.tmp
  • /data/data/####/8cf12af583d64c1fa48bd04b3d455333dcc0c7b96669afe....0.tmp
  • /data/data/####/9013ad25284f96d5e8d6bc76171acfe408687874f78309e....0.tmp
  • /data/data/####/921d628f4235ef1835b0342c049328b89fda6c94c2ad13d....0.tmp
  • /data/data/####/94a0cee6550f7d39103d4714434addd71866a1c51053d7a....0.tmp
  • /data/data/####/94d2049b694aa990e2dbb2666b29fc2cee5e5f36d7486ad....0.tmp
  • /data/data/####/950a194d329b2f8fc861ac656fcc6df5bb021f903d2debb....0.tmp
  • /data/data/####/95fbeb2cf9b017baa13d89779462e5b3e029df7b0bb3e25....0.tmp
  • /data/data/####/96884e9e9a3231c7e85d21a4079d96cc2d30988df098f75....0.tmp
  • /data/data/####/96c162dcf8134044be35dcc04843951011814d6c7fa77b8....0.tmp
  • /data/data/####/97d3b7163bc3d90fbed78f4f2a4e5084c714b587d0f5e75....0.tmp
  • /data/data/####/98986c7a7fd06fe64085d8b7b5851c1027c710d07b860e8....0.tmp
  • /data/data/####/9a6ecfcf58957fd975814fef9a3c5b5330e04ea1c70a847....0.tmp
  • /data/data/####/9d0c10c90c2705394f8971b9def57ccc440fd91d4edd870....0.tmp
  • /data/data/####/9e08035fa5f2096cad10c898924c0ad7bd143e17eaf8be4....0.tmp
  • /data/data/####/9e17709a59cc96cbacd3b19d830ed25f1f74865ae942143....0.tmp
  • /data/data/####/9e41109f0b9ba82832afb01e78e7f10bcd2e2050b0768af....0.tmp
  • /data/data/####/MultiDex.lock
  • /data/data/####/MyAnalytics_VERSION_INFO.xml
  • /data/data/####/MyAnalytics_device_id.xml
  • /data/data/####/MyAnalytics_general_config.xml
  • /data/data/####/MyAnalytics_send_config.xml
  • /data/data/####/UserInfo.xml
  • /data/data/####/a0a12c03d1c301088b6c3c14aae39d8b0d9705af3e498db....0.tmp
  • /data/data/####/a2f07c3c334a713879f1a27366f71e5e88fe0bab76cf79d....0.tmp
  • /data/data/####/a41fa1bcddf122229bd946d651a4a3fc75ab4a47ff615e9....0.tmp
  • /data/data/####/a72c39046c546c1e4ce3740c271ef152f436f697251a3e8....0.tmp
  • /data/data/####/a9d8d47c538116d6b753dec1370d6d9f17f0b45267d656e....0.tmp
  • /data/data/####/aa1094948e79f7b63f3d29ab56720dc0fd252afa056f7f3....0.tmp
  • /data/data/####/aae1be4e1175fdf551f4f52bb16543a102f9e1eaa990873....0.tmp
  • /data/data/####/ac68829b9e339467a140d26d89aaad9d0f09468872b0808....0.tmp
  • /data/data/####/ae41d317f94aae972e4b91dbe0892d0c288aa1cc0c29d56....0.tmp
  • /data/data/####/aebd727457fbc6dfbaaa03f1037282178eba017d04fb544....0.tmp
  • /data/data/####/aecbb72dc191414ec0c46df582723aa27bb9181cc43b5b5....0.tmp
  • /data/data/####/asset-manifest.json
  • /data/data/####/b02bf47cf5692a3f1bfa7efbe8fdad839424bc837d5a7b5....0.tmp
  • /data/data/####/b2db8fa4701b3d50ab851d25233d51c6367c311f689d70a....0.tmp
  • /data/data/####/b35b6b947c8c3e54fa234ff2c003dcd0665dc7fa1702722....0.tmp
  • /data/data/####/b4d12994a38888ded5da4db3a388f5d41df0ccce4b5c3f1....0.tmp
  • /data/data/####/b637dc13e8681556e3655b22c9660e5788fecee17f3652c....0.tmp
  • /data/data/####/b6f931b3706dfd433e2bf260fe5aef6cdc6314121ced0d7....0.tmp
  • /data/data/####/b7daf056fefc0af500e54864806fb9a035ef5ae9c2fe251....0.tmp
  • /data/data/####/b7e91aee7876c20b84503b2871c2433bd685bb1ec90205b....0.tmp
  • /data/data/####/ba3523f27b724aeed4fb6dda6c0e6fecdf5c8f651fe8363....0.tmp
  • /data/data/####/bd005fa02328ef85462a8b552822d28b8c1eef897ca25ad....0.tmp
  • /data/data/####/bfddb67c6b9cb34db7f4b4e594692b422ffcace1eec4c76....0.tmp
  • /data/data/####/c332a728732a99853f2f85c852f5310baa81256882cd6d3....0.tmp
  • /data/data/####/c38b18a9569da8561dc5a9525a50be8eef601f8ceadb17c....0.tmp
  • /data/data/####/c394bb4f5d0307145802e23af997e8c625beb0f276ad651....0.tmp
  • /data/data/####/c589a2013a70f9324b114806b3e385de42738a5668dbe27....0.tmp
  • /data/data/####/c9b0521863c5ae0fd93a3014305f4cf8ceb6765183822f6....0.tmp
  • /data/data/####/ca014f66c7ab4528e00664d1bf8685f5c8a7036e26cdb20....0.tmp
  • /data/data/####/ca60812d194f454bf5c842e705fa6ec63b402089bbcc79f....0.tmp
  • /data/data/####/cache.emoji.key.xml
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cce8ed007fd5323e5c56265046687435cbbbe1bfbc0fb7c....0.tmp
  • /data/data/####/cd690feb0cd340e911deb01ec7df5331e020ccba8434117....0.tmp
  • /data/data/####/ce178f5442b3d5260d200d9500a90d3b2638bc0ccfe7c53....0.tmp
  • /data/data/####/cea34de35a84f9d61a91041ed5f79ed83283ab34fba4e54....0.tmp
  • /data/data/####/cf3e6a6a6c470d168650c8ba4e93955ebb25247c99a4921....0.tmp
  • /data/data/####/cfd7a9b0ee8a88ca06813a0cedffb75bdd38cadd3b983dc....0.tmp
  • /data/data/####/cloudms.conf.xml
  • /data/data/####/com.m4399.gamecenter_preferences.xml
  • /data/data/####/com.m4399.gamecenter_preferences.xml (deleted)
  • /data/data/####/com.m4399.gamecenter_preferences.xml.bak
  • /data/data/####/com.shumei.xml
  • /data/data/####/comment.zip
  • /data/data/####/d06d1fd355d4318ac35599b11c75db6ea17440643681dc2....0.tmp
  • /data/data/####/d099959c88330ff3d8560bd194fa3e40465bd2cb0fab085....0.tmp
  • /data/data/####/d0c25a0888e7c8e32405b27e06fa854684a246277d822f9....0.tmp
  • /data/data/####/d0f3a979b34bfbfb1c825be4dd21e812c8ec77f5bd16a7d....0.tmp
  • /data/data/####/d2479d54bb386585f730d42b1331e72b7af3e543cb985ba....0.tmp
  • /data/data/####/d3f5ee6a9e1309348661891da30ac25d11aee9425ba0c1c....0.tmp
  • /data/data/####/d466738864fc1f60bd42cb6663ce01cd0eb691d0845e593....0.tmp
  • /data/data/####/d479633284d44a8b20d89f5e8396fb10345d6382ed06138....0.tmp
  • /data/data/####/d4fef0d500932be70c97ee3fb319612bf78366855885e92....0.tmp
  • /data/data/####/d52b2bae9d96093c179beb23d4b405a68ba3cc382af4d94....0.tmp
  • /data/data/####/d545a00bb91a68ca8aa2c3f9e9654d2c518755f5fd271db....0.tmp
  • /data/data/####/d5c2564dcbafa7151d2c42b558d7b0ba85040651bd6b741....0.tmp
  • /data/data/####/d799b475239b0c11e5438f999bfd8aa9ead4c2dade3ba56....0.tmp
  • /data/data/####/d7ca7b7c7bdf98737e43d393bc9ada92e327265c90e34de....0.tmp
  • /data/data/####/d7d4928da500b01ec4bf20bd3ae0fbe60f7cac0c26d40aa....0.tmp
  • /data/data/####/d808d60c68dccd968f67aaf2e3f8aad7dfc87081289cb3c....0.tmp
  • /data/data/####/d81e5a2cf0958c24859e3b2b35fcd1a4d1ee23f45a04876....0.tmp
  • /data/data/####/d84b7d65342a404874a6a5f910b16e6c6dabba923910252....0.tmp
  • /data/data/####/d87e26e0d48b75fbcaff43eadb308648f97593d82c864b2....0.tmp
  • /data/data/####/d8f43bbef24ab424d93533c4e9d8bbae2ab1e85630a56dc....0.tmp
  • /data/data/####/d90bb099a1950b34e7ffaf4b766d193bad91ecc28b91b7e....0.tmp
  • /data/data/####/da78da674c20b239e587d985766e4b680602b7dacb86ce0....0.tmp
  • /data/data/####/db53137ae2ba794881fd130787e6d28a9f73d86bcb3b777....0.tmp
  • /data/data/####/downloads.db-journal
  • /data/data/####/e207c9aa6049168b289d94729f6f707280929508b1496eb....0.tmp
  • /data/data/####/e382086694986f43001b36d1c718d78bacf85a7fdbe4373....0.tmp
  • /data/data/####/e63d1bdf79718ca53e72407a408b387e5e812c518f7f640....0.tmp
  • /data/data/####/e8472fc83bef3d45b3dac7b14dc625ec054e21c831031d0....0.tmp
  • /data/data/####/eaa66944cb180aff6253adf52dd369f6bf210a4c18b08d7....0.tmp
  • /data/data/####/eb593a13470341e2e40d5650d8e0fecd3aefb8a0e08eb25....0.tmp
  • /data/data/####/ecc3a95ed9662e9f64527dfbd7462f60dafac7813c8336f....0.tmp
  • /data/data/####/ece102708aec0ec246e79ec2bec6b364f8377e9ad70c7d1....0.tmp
  • /data/data/####/ee05ffde2e86d6a6e90dfb90fbfc6893a361be42f555ab6....0.tmp
  • /data/data/####/eea3deb99d681788cbb0ddfc6a92f1ce82443cb3fbd0ba2....0.tmp
  • /data/data/####/f1.img4399.comsj~emoji_e10140.png
  • /data/data/####/f1.img4399.comsj~emoji_e412.png
  • /data/data/####/f2035133704de5d3e2ee110387c13c4263269b05b8bef98....0.tmp
  • /data/data/####/f50fc16536716011d18a46efa705d689bdf3d275dbc5efa....0.tmp
  • /data/data/####/f522bca1585c62d4d7a1e32aa3d70dbd11e29ed9ceb66ab....0.tmp
  • /data/data/####/f63bee868a870c58c8529f2b2c3d7695ef4b04e19720c55....0.tmp
  • /data/data/####/f7b5dfd40ef95e9fd6bf3161b626c81db738389763fac33....0.tmp
  • /data/data/####/f884a78a48b103e074ca298752aa4ff64c60fa180628a3a....0.tmp
  • /data/data/####/f90cf24b601c4027aef9a623c15f1cc8a30d9b514396302....0.tmp
  • /data/data/####/f9a414fd41102d5574e222196ff6089cda800bed8a61b34....0.tmp
  • /data/data/####/fa72e77aa0cd790d84b941b6cce601e15c51f13e28f5bb2....0.tmp
  • /data/data/####/facb4fff1a908f3117854cded34a9a233e61b607729d1d4....0.tmp
  • /data/data/####/favicon.ico
  • /data/data/####/fc969e3a7e64e5e9f23e4c17195c941a552941581453bd4....0.tmp
  • /data/data/####/ff9de88a824355fb2cab8e9f58197fcbf056a436fd5e7d7....0.tmp
  • /data/data/####/framework.db-journal
  • /data/data/####/gamecenter.db-journal
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/index.css
  • /data/data/####/index.html
  • /data/data/####/index.js
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/journal.tmp
  • /data/data/####/libjiagu1858054988.so
  • /data/data/####/m4399AppEmoji3.0.json
  • /data/data/####/m4399BBSEmoji3.0.json
  • /data/data/####/main.917cc7aa.css
  • /data/data/####/main.b02023ee.js
  • /data/data/####/main.b487e26b.css
  • /data/data/####/main.ff76f3dd.js
  • /data/data/####/manifest.json
  • /data/data/####/mobclick_agent_cached_com.m4399.gamecenter1289
  • /data/data/####/multidex.version.xml
  • /data/data/####/placeholder.png
  • /data/data/####/plugin.meta
  • /data/data/####/pref.headup.message.chat.unread.pt
  • /data/data/####/push.jar
  • /data/data/####/push.pid
  • /data/data/####/push.zip
  • /data/data/####/push_box_sdk_version.xml
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/run.gif
  • /data/data/####/run.pid
  • /data/data/####/seq.xml
  • /data/data/####/service-worker.js
  • /data/data/####/skin_main_plugin_pref.xml
  • /data/data/####/statistics_agent_cached_com.m4399.gamecenter
  • /data/data/####/tdata_YYn966
  • /data/data/####/tdata_YYn966.jar
  • /data/data/####/tdata_eOt091
  • /data/data/####/tdata_eOt091.jar
  • /data/data/####/template.zip
  • /data/data/####/tracker.db-journal
  • /data/data/####/type1
  • /data/data/####/type2
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/webview.db-journal
  • /data/media/####/.disys
  • /data/media/####/.test.txt
  • /data/media/####/.thumbcache_idx0
  • /data/media/####/.udid
  • /data/media/####/010001.png
  • /data/media/####/010002.png
  • /data/media/####/010003.png
  • /data/media/####/010004.png
  • /data/media/####/010005.png
  • /data/media/####/010006.png
  • /data/media/####/010007.png
  • /data/media/####/010008.png
  • /data/media/####/010009.png
  • /data/media/####/010010.png
  • /data/media/####/010011.png
  • /data/media/####/010012.png
  • /data/media/####/010013.png
  • /data/media/####/010014.png
  • /data/media/####/010015.png
  • /data/media/####/010016.png
  • /data/media/####/010017.png
  • /data/media/####/010018.png
  • /data/media/####/010019.png
  • /data/media/####/010020.png
  • /data/media/####/010021.png
  • /data/media/####/010022.png
  • /data/media/####/010023.png
  • /data/media/####/010024.png
  • /data/media/####/010025.png
  • /data/media/####/010026.png
  • /data/media/####/010027.png
  • /data/media/####/010028.png
  • /data/media/####/010029.png
  • /data/media/####/010030.png
  • /data/media/####/10001.png
  • /data/media/####/10002.png
  • /data/media/####/10003.png
  • /data/media/####/10004.png
  • /data/media/####/10005.png
  • /data/media/####/10006.png
  • /data/media/####/10007.png
  • /data/media/####/10008.png
  • /data/media/####/10009.png
  • /data/media/####/10010.png
  • /data/media/####/10011.png
  • /data/media/####/10012.png
  • /data/media/####/10013.png
  • /data/media/####/10014.png
  • /data/media/####/10015.png
  • /data/media/####/10016.png
  • /data/media/####/10017.png
  • /data/media/####/10018.png
  • /data/media/####/5b3c2bdc-341c8.downlad
  • /data/media/####/aio_file.zip
  • /data/media/####/app.db
  • /data/media/####/background.json
  • /data/media/####/background.zip
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.m4399.gamecenter.bin
  • /data/media/####/com.m4399.gamecenter.db
  • /data/media/####/com.m4399.gamecenter.sdklogin
  • /data/media/####/config.json
  • /data/media/####/data.json
  • /data/media/####/img_0.png
  • /data/media/####/img_1.png
  • /data/media/####/shumei.txt
  • /data/media/####/t1v189.meta
  • /data/media/####/tdata_YYn966
  • /data/media/####/tdata_eOt091
  • /data/media/####/test.log
Miscellaneous:
Executes next shell scripts:
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 24788 300 0
  • cat /proc/self/cgroup
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 755 <Package Folder>/.jiagu/libjiagu1858054988.so
  • dmesg
  • getprop
  • grep -i virtualbox
  • ls /system/bin
  • ls /system/lib
  • ps
  • sh
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 24788 300 0
Loads the following dynamic libraries:
  • getuiext2
  • libjiagu1858054988
  • m4399
  • smsdk
Uses the following algorithms to encrypt data:
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • DES-ECB-NoPadding
Uses special library to hide executable bytecode.
Gains access to camera interface.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android