Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(TLS/1.0) we####.jumore####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- 7j####.c####.z0.####.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- c-h####.g####.com
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- we####.jumore####.com
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/tdata_Rnl693
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_siA393
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/H537C8863.xml
- /data/data/####/H537C8863_storages.xml
- /data/data/####/b898ca508797
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/clientid_igexin.xml
- /data/data/####/com.secneo.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/mobclick_agent_cached_cn.com.jumore.information.app123
- /data/data/####/pdr.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/secData.dex
- /data/data/####/secData.dve
- /data/data/####/secData.jar
- /data/data/####/tdata_Rnl693
- /data/data/####/tdata_Rnl693.jar
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_siA393
- /data/data/####/tdata_siA393.jar
- /data/data/####/umeng_general_config.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/app.css
- /data/media/####/app.db
- /data/media/####/app.js
- /data/media/####/app_evaluate.js
- /data/media/####/article_child.html
- /data/media/####/article_child.js
- /data/media/####/article_detail.css
- /data/media/####/article_detail.html
- /data/media/####/article_detail.js
- /data/media/####/article_main.html
- /data/media/####/article_main.js
- /data/media/####/band_one.png
- /data/media/####/band_two.png
- /data/media/####/center_main.css
- /data/media/####/center_main.html
- /data/media/####/center_main.js
- /data/media/####/checkPass.png
- /data/media/####/checkUnpass.png
- /data/media/####/checking.png
- /data/media/####/cn.com.jumore.information.app.bin
- /data/media/####/cn.com.jumore.information.app.db
- /data/media/####/collect_child.html
- /data/media/####/collect_child.js
- /data/media/####/collect_icon.png
- /data/media/####/collect_main.html
- /data/media/####/collect_main.js
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/common.js
- /data/media/####/company_auth.css
- /data/media/####/company_auth.html
- /data/media/####/consult_order.css
- /data/media/####/consult_order.html
- /data/media/####/consult_order.js
- /data/media/####/consult_order_detail.css
- /data/media/####/consult_order_detail.html
- /data/media/####/consult_order_detail.js
- /data/media/####/consultation_form.html
- /data/media/####/consultation_form.js
- /data/media/####/consultation_form_success.css
- /data/media/####/consultation_form_success.html
- /data/media/####/consultation_form_success.js
- /data/media/####/copy.png
- /data/media/####/datetime-utils.js
- /data/media/####/default_load_bg.png
- /data/media/####/default_load_img.png
- /data/media/####/default_user_icon.png
- /data/media/####/example.png
- /data/media/####/exclusive_main.html
- /data/media/####/exclusive_main.js
- /data/media/####/expert_detail.css
- /data/media/####/expert_detail.html
- /data/media/####/expert_detail.js
- /data/media/####/expert_detail_self.html
- /data/media/####/feedback.css
- /data/media/####/feedback.html
- /data/media/####/feedback.js
- /data/media/####/file__0.localstorage-journal
- /data/media/####/follow.css
- /data/media/####/follow.html
- /data/media/####/follow.js
- /data/media/####/forget.html
- /data/media/####/forget.js
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/guide.html
- /data/media/####/guide_01.jpg
- /data/media/####/guide_02.jpg
- /data/media/####/guide_03.jpg
- /data/media/####/home_logo.png
- /data/media/####/home_main.html
- /data/media/####/home_main.js
- /data/media/####/hot.png
- /data/media/####/iconfont.ttf
- /data/media/####/image-new.js
- /data/media/####/img_one.png
- /data/media/####/industry_main.css
- /data/media/####/industry_main.html
- /data/media/####/industry_main.js
- /data/media/####/info_main.html
- /data/media/####/info_main.js
- /data/media/####/information-detail.css
- /data/media/####/information-img.png
- /data/media/####/information-supply.css
- /data/media/####/information_detail.html
- /data/media/####/information_detail.js
- /data/media/####/iscroll.js
- /data/media/####/iscrollAssist.js
- /data/media/####/jquery.min.js
- /data/media/####/login.css
- /data/media/####/login.html
- /data/media/####/login.js
- /data/media/####/login_logo.png
- /data/media/####/loginedUsertImg.png
- /data/media/####/logo.png
- /data/media/####/main.css
- /data/media/####/main.html
- /data/media/####/main.js
- /data/media/####/manifest.json
- /data/media/####/md5.js
- /data/media/####/message.css
- /data/media/####/message.html
- /data/media/####/message.js
- /data/media/####/modify_info.css
- /data/media/####/modify_info.html
- /data/media/####/modify_info.js
- /data/media/####/modify_introduce.css
- /data/media/####/modify_introduce.html
- /data/media/####/modify_introduce.js
- /data/media/####/modify_pwd.css
- /data/media/####/modify_pwd.html
- /data/media/####/modify_pwd.js
- /data/media/####/more_menu.html
- /data/media/####/more_menu.js
- /data/media/####/mui.css
- /data/media/####/mui.lazyload.img.js
- /data/media/####/mui.lazyload.js
- /data/media/####/mui.min.css
- /data/media/####/mui.min.js
- /data/media/####/mui.previewimage.js
- /data/media/####/mui.pullToRefresh.js
- /data/media/####/mui.pullToRefresh.material.js
- /data/media/####/mui.ttf
- /data/media/####/mui.zoom.js
- /data/media/####/my_business_info.css
- /data/media/####/my_bussiness_info.html
- /data/media/####/my_bussiness_info.js
- /data/media/####/my_info.css
- /data/media/####/my_info.html
- /data/media/####/my_info.js
- /data/media/####/nav_center_selected.png
- /data/media/####/nav_center_unselected.png
- /data/media/####/nav_exclusive_selected.png
- /data/media/####/nav_exclusive_unselected.png
- /data/media/####/nav_home_selected.png
- /data/media/####/nav_home_unselected.png
- /data/media/####/nav_industry_selected.png
- /data/media/####/nav_industry_unselected.png
- /data/media/####/nav_info_selected.png
- /data/media/####/nav_info_unselected.png
- /data/media/####/news-banner.png
- /data/media/####/news_item.css
- /data/media/####/no_content_bg.png
- /data/media/####/no_content_business_info.png
- /data/media/####/photo-utils.js
- /data/media/####/previewimage.css
- /data/media/####/pull-icon.gif
- /data/media/####/pull-icon@2x.png
- /data/media/####/pull_tab.css
- /data/media/####/qq.png
- /data/media/####/qq_zone.png
- /data/media/####/regex-utils.js
- /data/media/####/reginster_new_01.css
- /data/media/####/register.css
- /data/media/####/register_01.html
- /data/media/####/register_01.js
- /data/media/####/register_02.html
- /data/media/####/register_02.js
- /data/media/####/register_03.html
- /data/media/####/register_03.js
- /data/media/####/register_bg.png
- /data/media/####/register_new_01.html
- /data/media/####/register_new_01.js
- /data/media/####/register_new_02.html
- /data/media/####/register_new_02.js
- /data/media/####/report.css
- /data/media/####/report.html
- /data/media/####/report.js
- /data/media/####/report.png
- /data/media/####/search_icon.png
- /data/media/####/search_main.css
- /data/media/####/search_main.html
- /data/media/####/search_main.js
- /data/media/####/search_main_android.html
- /data/media/####/search_main_sub.html
- /data/media/####/search_main_sub.js
- /data/media/####/security.js
- /data/media/####/setting.css
- /data/media/####/setting.html
- /data/media/####/setting.js
- /data/media/####/setting_text.css
- /data/media/####/setting_text.html
- /data/media/####/setting_text.js
- /data/media/####/share_btn.png
- /data/media/####/share_dialog.css
- /data/media/####/show-icon.png
- /data/media/####/sina_weibo.png
- /data/media/####/star-active.png
- /data/media/####/star.png
- /data/media/####/stars.png
- /data/media/####/start-1.png
- /data/media/####/start-2.png
- /data/media/####/start.html
- /data/media/####/submitCardImage.png
- /data/media/####/success-icon.png
- /data/media/####/tdata_Rnl693
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_siA393
- /data/media/####/test.log
- /data/media/####/time-pop.css
- /data/media/####/top-arrow-black.png
- /data/media/####/top-arrow-blue.png
- /data/media/####/unloginUserImg.png
- /data/media/####/update.js
- /data/media/####/update_wgt.js
- /data/media/####/vue.js
- /data/media/####/vue.min.js
- /data/media/####/web_page.html
- /data/media/####/web_page.js
- /data/media/####/weixin.png
- /data/media/####/weixin_group.png
- <Package Folder>/files/gdaemon_20161017 0 <Package>/io.dcloud.feature.apsGt.GTNormalPushService 25881 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- mount
- SecShell
- getuiext2
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-ECB-PKCS5Padding