Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Waps.283

Added to the Dr.Web virus database: 2018-09-06

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Waps.5.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) pc####.i####.com:80
  • TCP(HTTP/1.1) img2new####.b0.a####.com:80
  • TCP(HTTP/1.1) qiniu-s####.cdn.d####.com:80
  • TCP(HTTP/1.1) c####.wuzh####.com:80
  • TCP(HTTP/1.1) 58.2####.198.131:888
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) i####.com:80
  • TCP(HTTP/1.1) www.remo####.com:80
  • TCP(HTTP/1.1) 2####.187.227.11:808
  • TCP(HTTP/1.1) pos.b####.com:80
  • TCP(HTTP/1.1) www.pc####.com.cn:80
  • TCP(HTTP/1.1) go.oncl####.com:80
  • TCP(HTTP/1.1) js.3con####.com:80
  • TCP(HTTP/1.1) s####.x####.com.cn:80
  • TCP(HTTP/1.1) a####.521caol####.com:80
  • TCP(HTTP/1.1) d0.x####.com.cn:80
  • TCP(HTTP/1.1) ec####.b####.com:80
  • TCP(HTTP/1.1) zf####.v.qin####.com:80
  • TCP(HTTP/1.1) i####.e####.cn:80
  • TCP(HTTP/1.1) www.hit####.org:80
  • TCP(HTTP/1.1) ad.huoli####.cn:80
  • TCP(HTTP/1.1) v####.funs####.com:80
  • TCP(HTTP/1.1) mg####.pcon####.com.cn:80
  • TCP(HTTP/1.1) c####.360.cn:80
  • TCP(HTTP/1.1) s-41####.got####.com:80
  • TCP(HTTP/1.1) m.ta####.com:80
  • TCP(HTTP/1.1) www.ta####.com:80
  • TCP(HTTP/1.1) w####.fun.tv:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) members####.com:80
  • TCP(HTTP/1.1) z####.com:80
  • TCP(HTTP/1.1) c.appj####.com:80
  • TCP(HTTP/1.1) up####.v.qin####.com:80
  • TCP(HTTP/1.1) js.e####.cn:80
  • TCP(HTTP/1.1) www.2####.com:80
  • TCP(HTTP/1.1) z####.net:80
  • TCP(HTTP/1.1) c####.z####.net:80
  • TCP(HTTP/1.1) ne####.x####.com.cn:80
  • TCP(HTTP/1.1) zhi####.b####.edu.cn:80
  • TCP(HTTP/1.1) www.pcon####.com.cn:80
  • TCP(HTTP/1.1) dup.baidust####.com:80
  • TCP(HTTP/1.1) ucstati####.b0.a####.com:80
  • TCP(HTTP/1.1) c####.baidust####.com:80
  • TCP(HTTP/1.1) www.c####.com.####.com:80
  • TCP(HTTP/1.1) c####.pc####.com.cn:80
  • TCP(HTTP/1.1) coba####.com:80
  • TCP(HTTP/1.1) www.soush####.com:80
  • TCP(HTTP/1.1) ivy.pcon####.com.cn:80
  • TCP(HTTP/1.1) gm.mm####.com:80
  • TCP(HTTP/1.1) www.traf####.com:80
  • TCP(HTTP/1.1) s####.new####.com:80
  • TCP(HTTP/1.1) imgsnew####.b0.a####.com:80
  • TCP(HTTP/1.1) tc.c####.com:80
  • TCP(HTTP/1.1) 2####.187.226.25:80
  • TCP(HTTP/1.1) www.bili####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) w####.pcon####.com.cn:80
  • TCP(HTTP/1.1) s####.funs####.net:80
  • TCP(HTTP/1.1) p####.pc####.com.cn:80
  • TCP(HTTP/1.1) v####.l####.com:80
  • TCP(HTTP/1.1) www.on####.com:80
  • TCP(HTTP/1.1) www.ax####.com:80
  • TCP(HTTP/1.1) 1####.40.20.155:80
  • TCP(HTTP/1.1) www.new####.com:80
  • TCP(HTTP/1.1) g.cn.miao####.com:80
  • TCP(HTTP/1.1) ip.zhito####.com:88
  • TCP(HTTP/1.1) i####.pcon####.fas####.com:80
  • TCP(HTTP/1.1) i####.ph.126.net:80
  • TCP(HTTP/1.1) hao.2####.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) c.c####.com:80
  • TCP(HTTP/1.1) www.9####.com:80
  • TCP(HTTP/1.1) c####.jq####.com:80
  • TCP(HTTP/1.1) ip.zhito####.com:807
  • TCP(HTTP/1.1) bbs.c####.com.####.com:80
  • TCP(HTTP/1.1) js.u####.51.####.com:80
  • TCP(HTTP/1.1) w####.c####.com:80
  • TCP(HTTP/1.1) ztp####.v.bs####.cn:80
  • TCP(HTTP/1.1) www.linko####.com:80
  • TCP(HTTP/1.1) www.h####.net:80
  • TCP(HTTP/1.1) www.yzao####.com:80
  • TCP(TLS/1.0) www.hit####.org:443
  • TCP(TLS/1.0) z.c####.com:443
  • TCP(TLS/1.0) pc####.i####.com:443
  • TCP(TLS/1.0) gm.mm####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) m.ta####.com:443
  • TCP(TLS/1.0) www.pc####.com.cn:443
  • TCP(TLS/1.0) ti####.b####.com:443
  • TCP(TLS/1.0) img.haley####.net.####.com:443
  • TCP(TLS/1.0) c####.l####.com:5656
  • TCP(TLS/1.0) mg####.pcon####.com.cn:443
  • TCP(TLS/1.0) api.u####.cn:443
  • TCP(TLS/1.0) c.c####.com:443
  • TCP(TLS/1.0) pp.c####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) c####.h####.com:5656
DNS requests:
  • a####.521caol####.com
  • ad.huoli####.cn
  • adm.t####.com
  • api.u####.cn
  • bbs.c####.com
  • c####.360.cn
  • c####.baidust####.com
  • c####.h####.com
  • c####.h####.com
  • c####.jq####.com
  • c####.l####.com
  • c####.l####.com
  • c####.mm####.com
  • c####.pc####.com.cn
  • c####.pc####.com.cn
  • c####.wuzh####.com
  • c####.z####.net
  • c.appj####.com
  • c.c####.com
  • coba####.com
  • d0.x####.com.cn
  • dup.baidust####.com
  • ec####.b####.com
  • g.cn.miao####.com
  • go.oncl####.com
  • h####.c####.com
  • h5.m.ta####.com
  • hao.2####.com
  • hm.b####.com
  • i####.51.la
  • i####.com
  • i####.e####.cn
  • i####.new####.com
  • i####.new####.com
  • i####.new####.com
  • i####.pcon####.com.cn
  • i####.ph.126.net
  • i####.x####.com.cn
  • i####.xca####.com
  • img.haley####.net
  • img.new####.com
  • img.pcon####.com.cn
  • int.d####.s####.####.cn
  • ip.zhito####.com
  • ivy.pcon####.com.cn
  • js.3con####.com
  • js.e####.cn
  • js.u####.51.la
  • js.x####.com.cn
  • l####.tbs.qq.com
  • m.ta####.com
  • members####.com
  • mg####.pcon####.com.cn
  • ne####.x####.com.cn
  • p####.pc####.com.cn
  • pc####.i####.com
  • pos.b####.com
  • pp.c####.com
  • s####.funs####.net
  • s####.new####.com
  • s####.x####.com.cn
  • s11.c####.com
  • s13.c####.com
  • s19.c####.com
  • s20.c####.com
  • s23.c####.com
  • s4.c####.com
  • s95.c####.com
  • st####.funs####.com
  • tc.c####.com
  • ti####.b####.com
  • u####.b####.com.####.cn
  • ucst####.c####.com
  • v####.fun.tv
  • v####.fun.tv
  • v####.l####.com
  • v1.c####.com
  • w####.c####.com
  • w####.fun.tv
  • w####.pc####.com.cn
  • w####.pc####.com.cn
  • w####.pcon####.com.cn
  • www.2####.com
  • www.9####.com
  • www.ax####.com
  • www.bili####.com
  • www.c####.com
  • www.ell####.com
  • www.google-####.com
  • www.h####.net
  • www.ha####.com
  • www.hit####.org
  • www.linko####.com
  • www.new####.com
  • www.on####.com
  • www.pc####.com.cn
  • www.pc####.com.cn
  • www.pcon####.com.cn
  • www.remo####.com
  • www.soush####.com
  • www.ta####.com
  • www.traf####.com
  • www.yzao####.com
  • z####.com
  • z####.net
  • z11.c####.com
  • z13.c####.com
  • z4.c####.com
  • z6.c####.com
  • z7.c####.com
  • z8.c####.com
  • zhi####.b####.edu.cn
HTTP GET requests:
  • 2####.187.226.25/babynew.html?h####
  • 2####.187.226.25/bb.html
  • 2####.187.226.25/hui.html
  • 2####.187.226.25/yuncpc.html
  • a####.521caol####.com/
  • ad.huoli####.cn/hlh.html?pc_c####
  • ad.huoli####.cn/pc.html?h####
  • bbs.c####.com.####.com/banner3.html?d=####
  • bbs.c####.com.####.com/css/other.css
  • bbs.c####.com.####.com/d/post/18804879.html
  • bbs.c####.com.####.com/images/user_sig_split.gif
  • bbs.c####.com.####.com/jscripts/doc.js
  • bbs.c####.com.####.com/style/images/bg_header.jpg
  • bbs.c####.com.####.com/style/images/icon.gif
  • bbs.c####.com.####.com/style/images/icon_num.gif
  • bbs.c####.com.####.com/style/images/search.gif
  • bbs.c####.com.####.com/style/images/top1.jpg
  • bbs.c####.com.####.com/style/images/top2.jpg
  • bbs.c####.com.####.com/style/images/use_tool.gif
  • bbs.c####.com.####.com/style/newPost.css?v=####
  • bbs.c####.com.####.com/style/style_board.css
  • bbs.c####.com.####.com/style/style_post3.css
  • c####.baidust####.com/cpro/ui/c.js
  • c####.jq####.com/jquery-1.4.4.min.js
  • c####.pc####.com.cn/count.php?__uuid=####&autox=####&channel=####&screen...
  • c####.pc####.com.cn/count.php?autox=1&channel=1411&screen=600*800&refer=...
  • c####.wuzh####.com/location.php
  • c####.z####.net/v.js?SrKRGVq93kdVoA3wd6tClXDN75RRsNXbzFjq6lecE+I=####
  • c.c####.com/core.php?web_id=####&t=####
  • c.c####.com/stat.php?id=####
  • c.c####.com/stat.php?id=####&web_id=####
  • c.c####.com/stat.php?id=####&web_id=####&show=####
  • c.c####.com/z_stat.php?id=####
  • c.c####.com/z_stat.php?id=####&web_id=####
  • coba####.com/afu.php?zoneid=####
  • d0.x####.com.cn/pvlog/ad_count.php
  • d0.x####.com.cn/pvlog/ad_count.php?t=####
  • dup.baidust####.com/js/os.js
  • ec####.b####.com/se.jpg?type=####&id=####&pos=####&status=####&async=###...
  • g.cn.miao####.com/x/k=2006848&p=6tQ4p&dx=0&rt=2&ns=__IP__&ni=__IESID__&v...
  • gm.mm####.com/9.gif?abc=####&rnd=####
  • go.oncl####.com/afu.php?zoneid=####
  • hao.2####.com/?65####
  • hao.2####.com/index.css
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.js?05a09dd####
  • hm.b####.com/hm.js?1b2a81d####
  • hm.b####.com/hm.js?5f68d35####
  • i####.com/irt?_iwt_UA=####&jsonp=####
  • i####.com/irt?_iwt_UA=####&ref=####&jsonp=####
  • i####.e####.cn/a/2018-09-01/153576419232538115.jpg
  • i####.e####.cn/a/2018-09-01/153576419764630263.jpg
  • i####.e####.cn/a/2018-09-01/153576420124799689.jpg
  • i####.e####.cn/a/2018-09-01/153576420620712427.jpg
  • i####.e####.cn/a/2018-09-01/153576421152473823.jpg
  • i####.e####.cn/iclk/?s=####&a=####
  • i####.e####.cn/iclk/?s=MTk0M####&a=####
  • i####.e####.cn/iclk/?s=MjQ4N####&a=####
  • i####.e####.cn/iclk/?s=NjMxN####&a=####
  • i####.e####.cn/iclk/?s=Nzc0O####&a=####
  • i####.e####.cn/iclk/?s=NzgzM####&a=####
  • i####.e####.cn/iclk/?s=ODEwM####&a=####
  • i####.e####.cn/iclk/?s=ODMyO####&a=####
  • i####.e####.cn/iclk/?s=ODU4O####&a=####
  • i####.e####.cn/iclk/?s=OTY1M####&a=####
  • i####.e####.cn/images/close.gif
  • i####.e####.cn/images/imgcopy.png
  • i####.pcon####.fas####.com/blank.gif
  • i####.ph.126.net/hU7TAnjpYOGrGRUPU-syww==/2848526764412496446.png
  • img2new####.b0.a####.com/auto/201711/css/index_red.css
  • img2new####.b0.a####.com/auto/201711/image/icon.png
  • img2new####.b0.a####.com/auto/201711/image/loading.png
  • img2new####.b0.a####.com/auto/201711/image/loading_614_307.png
  • img2new####.b0.a####.com/auto/201711/image/loading_70_70.png
  • img2new####.b0.a####.com/auto/201711/js/public.js
  • img2new####.b0.a####.com/image/auto/160630/lazyload200.jpg
  • img2new####.b0.a####.com/image/auto/160630/lazyload340.jpg
  • img2new####.b0.a####.com/images/ad/ad.png
  • img2new####.b0.a####.com/js/index_sign_data_cache.js
  • img2new####.b0.a####.com/js/iwt/iwt-min.js
  • img2new####.b0.a####.com/js/jquery-1.7.2.min.js
  • img2new####.b0.a####.com/js/widgets/adapter-mini.js
  • img2new####.b0.a####.com/top/css/index_red.css
  • img2new####.b0.a####.com/top/image/ewm_top.png
  • img2new####.b0.a####.com/top/image/icon.png
  • img2new####.b0.a####.com/top/js/public.js
  • imgsnew####.b0.a####.com/top/image/logo.png
  • ip.zhito####.com:807/hui.html?z####
  • ip.zhito####.com:88/pcip.html?z####
  • ivy.pcon####.com.cn/adpuba/show?id=####&media=####&channel=####&trace=####
  • ivy.pcon####.com.cn/show?id=####&media=####&channel=####&
  • js.3con####.com/2013/usercenter/images/icolist.jpg
  • js.3con####.com/2013/usercenter/images/icolku.jpg
  • js.3con####.com/2013/usercenter/images/sharels.jpg
  • js.3con####.com/2014/channel/images/0901pic.png
  • js.3con####.com/2014/channel/images/articleMain.png
  • js.3con####.com/2014/channel/images/jcz.png
  • js.3con####.com/2014/channel/images/rePoint.png
  • js.3con####.com/2014/index/x.png
  • js.3con####.com/2015/channel/images/QR2.png
  • js.3con####.com/footer/images/g-footer-jubao.png
  • js.3con####.com/footer/images/g-footer-logo.png
  • js.3con####.com/header/images/navbar.png
  • js.3con####.com/iresearch/iwt-min.js
  • js.3con####.com/min/temp/v1/dpl-jquery.slide.js
  • js.3con####.com/min/temp/v1/lib-jquery1.10.2.js
  • js.3con####.com/min2/temp/v2/plugin-locate,plugin-locate_auto.js
  • js.3con####.com/pcauto/2017/price/css/photos2.css
  • js.3con####.com/zt/gz20170412/price/jbian.png
  • js.e####.cn/js/yp.js
  • js.e####.cn/page/?s=####
  • js.u####.51.####.com/16355087.js
  • js.u####.51.####.com/19560175.js
  • m.ta####.com/?sprefer=####
  • members####.com/getimg.php?id=####
  • mg####.pcon####.com.cn/auto.airui.test15./
  • ne####.x####.com.cn/images/np_ps_bj.jpg
  • ne####.x####.com.cn/images/r_map.gif
  • ne####.x####.com.cn/images/rl_bj.gif
  • ne####.x####.com.cn/js/Jump.js?v=####
  • ne####.x####.com.cn/jsinclude/jquery.js
  • ne####.x####.com.cn/photo/sdb5188_1/1488581.htm
  • p####.pc####.com.cn/cars/image/1154951-1-sg3544-o1-c16740.html?ad=####
  • p####.pc####.com.cn/dealer/interface/price/getLowestModelPrice4All.jsp?c...
  • pc####.i####.com/irt?_iwt_UA=####&ref=####&jsonp=####
  • pos.b####.com/accm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/bfp/snippetcacher.php?dpv=####&di=####
  • pos.b####.com/cckm?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/cckm?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/cckm?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/cczm?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/cczm?di=3903980&dri=0&dis=7&dai=0&ps=9x8&enu=encoding&dcb=...
  • pos.b####.com/cczm?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/cczm?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/dcpm?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/dcpm?di=3903980&dri=0&dis=7&dai=0&ps=9x8&enu=encoding&dcb=...
  • pos.b####.com/dcpm?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/dcpm?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/fcam?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/fcam?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/fcam?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/gcfm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/gckm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/hcem?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/kcwm?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/kcwm?di=3903980&dri=0&dis=7&dai=0&ps=9x8&enu=encoding&dcb=...
  • pos.b####.com/kcwm?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/kcwm?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/rctm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/sctm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/tcjm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/uccm?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pos.b####.com/ychm?conwid=1&conhei=1&rtbid=3012795&rdid=13109487&dc=2&di...
  • pos.b####.com/ychm?di=3903980&dri=0&dis=7&dai=0&ps=9x8&enu=encoding&dcb=...
  • pos.b####.com/ychm?di=5560346&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • pos.b####.com/ychm?di=5848908&dri=0&dis=7&dai=0&ps=8x8&enu=encoding&dcb=...
  • qiniu-s####.cdn.d####.com/2011newcar/images/wb_btn1.jpg
  • qiniu-s####.cdn.d####.com/cms/iwt/iwt-min.js
  • s####.funs####.net/ecom-ad/ifar_all/?oc=####
  • s####.funs####.net/ecom-ad/ifar_duration/?rprotocol=####&fck=####&mick=#...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=153621240966164&mi...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=15362124148196e&mi...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=1536212420c5d94&mi...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=153621242621f38&mi...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=15362124407bd06&mi...
  • s####.funs####.net/ecom-ad/ifar_load/?rprotocol=1&fck=153621244825b6f&mi...
  • s####.new####.com/?ina_from=####
  • s####.x####.com.cn/flow/flow.php?t=####
  • s-41####.got####.com/
  • s-41####.got####.com/css/metro2.css
  • t####.c####.q####.####.com/b116/s5188/m_20130614093234533104.jpg
  • t####.c####.q####.####.com/b116/s5188/s_20130614093232630140.jpg
  • t####.c####.q####.####.com/b116/s5188/s_20130614093233106163.jpg
  • t####.c####.q####.####.com/b116/s5188/s_20130614093234533104.jpg
  • t####.c####.q####.####.com/b116/s5188/s_20130614093236194715.jpg
  • t####.c####.q####.####.com/b116/s5188/s_20130614093237519397.jpg
  • tc.c####.com/adscache/caches/104.js?n=####
  • tc.c####.com/adscache/caches/105.js?n=####
  • tc.c####.com/adscache/caches/106.js?n=####
  • tc.c####.com/adscache/caches/196.js?n=####
  • tc.c####.com/adscache/caches/205.js?n=####
  • tc.c####.com/adscache/caches/215.js?n=####
  • tc.c####.com/adscache/caches/216.js?n=####
  • tc.c####.com/adscache/caches/239.js?n=####
  • tc.c####.com/adscache/caches/344.js?n=####
  • tc.c####.com/adscache/caches/436.js?n=####
  • tc.c####.com/adscache/caches/492.js?n=####
  • tc.c####.com/adscache/caches/510.js?n=####
  • tc.c####.com/adscache/caches/72.js?n=####
  • tc.c####.com/iframeads/adsdispatch.php?pid=####
  • tc.c####.com/js/tcjs.php
  • ucstati####.b0.a####.com/cmbbs/main.js
  • up####.v.qin####.com/main/new/js/v8/core-min.js
  • up####.v.qin####.com/main/new/js/v8/html/statIwt_www_new-min.js?v=####
  • v####.funs####.com/vasd/pa/index?zzt=####&sid=####&ref=####&mick=####&cv...
  • v####.l####.com//images/close.png
  • v####.l####.com/a/2017-12-03/15122627291008.jpg
  • v####.l####.com/a/2018-05-22/15269693462682.jpg
  • v####.l####.com/a/2018-07-29/15328636049836.gif
  • v####.l####.com/a/2018-08-24/15350908815365.gif
  • v####.l####.com/a/2018-08-24/15350911044414.gif
  • v####.l####.com/a/2018-08-27/15353407856027.gif
  • v####.l####.com/a/2018-08-27/15353408148351.gif
  • v####.l####.com/a/2018-08-31/15356448966473.gif
  • v####.l####.com/a/2018-08-31/15356449452498.gif
  • v####.l####.com/c.php?s=####&p=####&srccpv=####
  • v####.l####.com/c.php?s=Jnpvb####&p=####&srccpv=####
  • v####.l####.com/images/b-1.png
  • v####.l####.com/s.php?id=####
  • v####.l####.com/v.php?id=####&p=####&l=d3d3L####
  • w####.c####.com/abc/xyz/point/index_single.php
  • w####.fun.tv/vplay/g-309487.v-887787
  • w####.fun.tv/vplay/g-316099.v-976517
  • w####.fun.tv/vplay/g-319991.v-1059709
  • w####.pcon####.com.cn/ipJson.jsp?defaultCity=####&sts=####&callback=####
  • www.2####.com/Hao250Js
  • www.9####.com/
  • www.ax####.com/adtu/1.gif
  • www.ax####.com/adtu/2.gif
  • www.ax####.com/adtu/4.gif
  • www.ax####.com/c.php?s=Jnpvb####&p=####&srccpv=####
  • www.ax####.com/v.php?siteid=####&id=####&p=####&l=d3d3L####
  • www.ax####.com/vs.php?id=####
  • www.bili####.com/gg/sjgg-v.html
  • www.bili####.com/gg/sjgg_files/131648729694.jpg
  • www.bili####.com/gg/sjgg_files/13242612645.jpg
  • www.bili####.com/gg/sjgg_files/gq24man_middle.png
  • www.bili####.com/gg/sjgg_files/saved_resource
  • www.bili####.com/gg/sjgg_files/saved_resource(1)
  • www.c####.com.####.com/js/iwt-min.js
  • www.h####.net/up/2977/512/4-youku-logo.png
  • www.hit####.org/js/adsbyhit4hit.js
  • www.linko####.com/b/img/ban3.jpg
  • www.new####.com/?ina_from=####
  • www.on####.com/ax/?uid=####&ad=####
  • www.pc####.com.cn/3g/wap2013/intf/1305/intf1727.js
  • www.pc####.com.cn/airui/246/2469962.html
  • www.pc####.com.cn/airui/x.html
  • www.pc####.com.cn/autox/x2.html
  • www.pc####.com.cn/blank.gif
  • www.pcon####.com.cn/_hux_/auto/price/detail.js
  • www.remo####.com/z.html
  • www.soush####.com/?fromuid=####
  • www.soush####.com/static/image/mobile/images/arrow_top.png
  • www.soush####.com/static/image/mobile/images/collapsed_yes.png
  • www.soush####.com/static/image/mobile/images/icon.png
  • www.soush####.com/static/image/mobile/images/logo.png
  • www.soush####.com/static/image/mobile/images/nav_b_line.png
  • www.soush####.com/static/image/mobile/images/pic_bg.jpg
  • www.soush####.com/static/image/mobile/images/titlebg.png
  • www.soush####.com/static/image/mobile/style.css
  • www.soush####.com/static/js/mobile/common.js?Y####
  • www.soush####.com/static/js/mobile/jquery-1.8.3.min.js?Y####
  • www.ta####.com/
  • www.traf####.com/getban2.php?mem=####&k=####&loc=####&nks=####
  • www.traf####.com/trafficg.js
  • www.traf####.com/trafficg2.js
  • www.yzao####.com//images/close.png
  • www.yzao####.com/a/2017-05-22/14954352635201.gif
  • www.yzao####.com/a/2018-06-18/15293032028789.gif
  • www.yzao####.com/a/2018-06-18/15293032161187.gif
  • www.yzao####.com/c.php?s=####&p=####&srccpv=####
  • www.yzao####.com/c.php?s=Jnpvb####&p=####&srccpv=####
  • www.yzao####.com/images/b-1.png
  • www.yzao####.com/stats.php?adsid=####&planid=####&uid=####&siteid=####&p...
  • www.yzao####.com/v.php?siteid=####&id=####&p=####&l=d3d3L####
  • www.yzao####.com/yezi.php?id=####
  • z####.com/ax/?uid=####&ad=####
  • z####.com/ax?uid=####&ad=####
  • z####.net/
  • z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
  • z.c####.com/stat.htm?id=1261172571&r=http://ip.zhitoudsp.com:807/hui.htm...
  • z.c####.com/stat.htm?id=1272176858&r=http://221.229.204.23:88/pcip.html?...
  • z.c####.com/stat.htm?id=4762020&r=http://222.187.226.25/pc.html?h####&lg...
  • zf####.v.qin####.com/market/ext/udc/c99331047.html?zzt=####
  • zf####.v.qin####.com/unet/static/udc.js?zzt=####
  • zhi####.b####.edu.cn/attachment/forum/201606/29/161530m3sby6sayistscs3.p...
  • ztp####.v.bs####.cn/images/piclib/201405/15/simple/1/1400136878771h28hf3...
  • ztp####.v.bs####.cn/images/piclib/201405/19/simple/1/14004629206301dsoro...
  • ztp####.v.bs####.cn/images/piclib/201405/19/simple/1/1400463296008mh94a8...
  • ztp####.v.bs####.cn/images/piclib/201405/19/simple/1/1400463712619roikyw...
  • ztp####.v.bs####.cn/images/piclib/201405/28/simple/1/1401259042171kdfy8u...
  • ztp####.v.bs####.cn/images/upload/upc/tx/auto5/1310/09/c7/27176838_13812...
  • ztp####.v.bs####.cn/images/upload/upc/tx/kidsphotolib_bbs/1410/13/c0/395...
  • ztp####.v.bs####.cn/images/upload/upc/tx/kidsphotolib_bbs/1508/15/c1/112...
  • ztp####.v.bs####.cn/images/upload/upc/tx/kidsphotolib_bbs/1508/18/c0/113...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1508/30/c1/11942461_144...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1508/30/c1/11948393_144...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1508/31/c1/11958634_144...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1508/31/c1/11960588_144...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1508/31/c6/11988122_144...
  • ztp####.v.bs####.cn/images/upload/upc/tx/pc_best/1509/01/c1/12010752_144...
HTTP POST requests:
  • c####.360.cn/stra_packet
  • c.appj####.com/ad/splash/stats.html
  • l####.tbs.qq.com/ajax?c=####&k=####
Modified file system:
Creates the following files:
  • /data/data/####/.jg.ic
  • /data/data/####/.jgrpa.xml
  • /data/data/####/.log.lock
  • /data/data/####/.log.rpa
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/WebpageIcons.db-journal
  • /data/data/####/ad_show_time.xml
  • /data/data/####/com.e4a.runtime.android.mainActivity.xml
  • /data/data/####/core_info
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/debug.conf
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/f_00003e
  • /data/data/####/f_00003f
  • /data/data/####/f_000040
  • /data/data/####/f_000041
  • /data/data/####/f_000042
  • /data/data/####/http_newcar.xcar.com.cn_0.localstorage-journal
  • /data/data/####/http_vas.fun.tv_0.localstorage-journal
  • /data/data/####/http_www.news18a.com_0.localstorage-journal
  • /data/data/####/index
  • /data/data/####/jg_app_update_settings_random.xml
  • /data/data/####/jg_so_upgrade_setting.xml
  • /data/data/####/libjiagu1851228152.so
  • /data/data/####/qihoo_jiagu_crash_report.xml
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal (deleted)
  • /data/media/####/tbslog.txt
Miscellaneous:
Executes next shell scripts:
  • chmod 755 <Package Folder>/.jiagu/libjiagu1851228152.so
  • getprop ro.product.cpu.abi
Loads the following dynamic libraries:
  • libjiagu1851228152
Uses the following algorithms to encrypt data:
  • RSA
  • RSA-ECB-NoPadding
Uses special library to hide executable bytecode.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android