Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Gexin.10771

Added to the Dr.Web virus database: 2019-03-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
  • TCP(HTTP/1.1) rp-na####.ron####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(TLS/1.0) s####.cn.ron####.com:443
  • TCP 1####.92.13.27:8623
DNS requests:
  • a####.b####.qq.com
  • aexcep####.b####.qq.com
  • and####.b####.qq.com
  • nav.cn.ron####.com
  • s####.cn.ron####.com
HTTP POST requests:
  • aexcep####.b####.qq.com:8011/rqd/async
  • aexcep####.b####.qq.com:8012/rqd/async
  • and####.b####.qq.com/rqd/async
  • rp-na####.ron####.com/navipush.json
File system changes:
Creates the following files:
  • /data/data/####/COUNTLY_STORE.xml
  • /data/data/####/MultiDex.lock
  • /data/data/####/RongPush.xml
  • /data/data/####/Statistics.xml
  • /data/data/####/TodayStepDB.db-journal
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/h5.xml
  • /data/data/####/journal.tmp
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.9.0.2.so
  • /data/data/####/libufix.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mix.dex
  • /data/data/####/mobclick_agent_cached_com.qianqi.fs181011
  • /data/data/####/multidex.version.xml
  • /data/data/####/native_record_lock
  • /data/data/####/push_daemon
  • /data/data/####/security_info
  • /data/data/####/today_step_share_prefs.xml
  • /data/data/####/today_step_share_prefs.xml.bak (deleted)
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/media/####/.nomedia
  • /data/media/####/20190322.log
  • /data/media/####/Group.png
  • /data/media/####/Line.png
  • /data/media/####/Oval.png
  • /data/media/####/QRCode.css
  • /data/media/####/QRCode.html
  • /data/media/####/QRCode.js
  • /data/media/####/Register_13x.png
  • /data/media/####/Register_23x.png
  • /data/media/####/Register_33x.png
  • /data/media/####/RongLog_2_8_15.log
  • /data/media/####/about.html
  • /data/media/####/about.js
  • /data/media/####/aboutHealthCoin.html
  • /data/media/####/active_huohuo.png
  • /data/media/####/add.png
  • /data/media/####/addContact.html
  • /data/media/####/addContact.js
  • /data/media/####/addEmergencyContact.html
  • /data/media/####/addEmergencyContact.js
  • /data/media/####/addFamilyCare.html
  • /data/media/####/addFamilyCare.js
  • /data/media/####/addGroupUser.html
  • /data/media/####/addHealthData.css
  • /data/media/####/addHealthData.html
  • /data/media/####/addHealthData.js
  • /data/media/####/addMember.css
  • /data/media/####/addMember.html
  • /data/media/####/addMember.js
  • /data/media/####/addNormalContact.html
  • /data/media/####/addNormalContact.js
  • /data/media/####/add_64px.png
  • /data/media/####/add_care.png
  • /data/media/####/add_health_icon.png
  • /data/media/####/add_icon.png
  • /data/media/####/add_picture@2x.png
  • /data/media/####/adminIcon.png
  • /data/media/####/analytics.js
  • /data/media/####/app.css
  • /data/media/####/arcode_icon.png
  • /data/media/####/arttmpl.js
  • /data/media/####/badminton_icon.png
  • /data/media/####/baiduMap.js
  • /data/media/####/base_clause.html
  • /data/media/####/basketball_icon.png
  • /data/media/####/billDetail.css
  • /data/media/####/billDetail.html
  • /data/media/####/billDetail.js
  • /data/media/####/bindHuoHuo.html
  • /data/media/####/bindHuoHuo.js
  • /data/media/####/calendar.css
  • /data/media/####/calendar.html
  • /data/media/####/calendar.js
  • /data/media/####/camera_img5.png
  • /data/media/####/camera_img6.png
  • /data/media/####/camera_know.png
  • /data/media/####/camera_know_pre.png
  • /data/media/####/careMe.css
  • /data/media/####/careMe.html
  • /data/media/####/careMe.js
  • /data/media/####/careMeSet.html
  • /data/media/####/careMeSet.js
  • /data/media/####/care_each_icon.png
  • /data/media/####/certification.css
  • /data/media/####/checkUpdate.js
  • /data/media/####/circleDetaiSub.css
  • /data/media/####/circleDetaiSub.html
  • /data/media/####/circleDetaiSub.js
  • /data/media/####/circleDetail.css
  • /data/media/####/circleDetail.html
  • /data/media/####/circleDetail.js
  • /data/media/####/circlePhoto.png
  • /data/media/####/city.data-3.js
  • /data/media/####/clause.css
  • /data/media/####/clause.js
  • /data/media/####/climb_icon.png
  • /data/media/####/common.js
  • /data/media/####/communication_clause.html
  • /data/media/####/complete.png
  • /data/media/####/comsume.png
  • /data/media/####/config.js
  • /data/media/####/contacs.png
  • /data/media/####/contact.css
  • /data/media/####/contactList.css
  • /data/media/####/contactList.html
  • /data/media/####/contactList.js
  • /data/media/####/createFriendCircle.css
  • /data/media/####/createFriendCircle.html
  • /data/media/####/createFriendCircle.js
  • /data/media/####/cropper.html
  • /data/media/####/cropper.min.css
  • /data/media/####/cropper.min.js
  • /data/media/####/currency_icon.png
  • /data/media/####/custody_add01 _black.png
  • /data/media/####/custody_add01.png
  • /data/media/####/custody_add02.png
  • /data/media/####/custody_add03.png
  • /data/media/####/custody_add03_black.png
  • /data/media/####/custody_add04.png
  • /data/media/####/custody_background.png
  • /data/media/####/custody_bg.png
  • /data/media/####/custody_card01.png
  • /data/media/####/custody_card02.png
  • /data/media/####/custody_event_badminton_circular.png
  • /data/media/####/custody_event_basketball_circular.png
  • /data/media/####/custody_event_climb_circular.png
  • /data/media/####/custody_event_football_circular.png
  • /data/media/####/custody_event_lay_circular.png
  • /data/media/####/custody_event_light_circular.png
  • /data/media/####/custody_event_nosport_circular.png
  • /data/media/####/custody_event_phone_circular.png
  • /data/media/####/custody_event_put.png
  • /data/media/####/custody_event_ride.png
  • /data/media/####/custody_event_ride_circular.png
  • /data/media/####/custody_event_run_circular.png
  • /data/media/####/custody_event_skip_circular.png
  • /data/media/####/custody_event_sleep_circular.png
  • /data/media/####/custody_event_square_dance.png
  • /data/media/####/custody_event_square_dance_circular.png
  • /data/media/####/custody_event_stand_circular.png
  • /data/media/####/custody_event_static_circular.png
  • /data/media/####/custody_event_stay_circular.png
  • /data/media/####/custody_event_swim_circular.png
  • /data/media/####/custody_event_table_tennis_circular.png
  • /data/media/####/custody_event_taiji_circular.png
  • /data/media/####/custody_event_tennis_circular.png
  • /data/media/####/custody_event_walk.png
  • /data/media/####/custody_event_walk_circular.png
  • /data/media/####/custody_finish_bg.png
  • /data/media/####/custody_icon_address.png
  • /data/media/####/custody_icon_blood_pressure.png
  • /data/media/####/custody_icon_blood_pressure_sim.png
  • /data/media/####/custody_icon_blood_sugar.png
  • /data/media/####/custody_icon_blood_sugar_sim.png
  • /data/media/####/custody_icon_cal_new.png
  • /data/media/####/custody_icon_fail.png
  • /data/media/####/custody_icon_line.png
  • /data/media/####/custody_icon_lineopen.png
  • /data/media/####/custody_icon_location_map.png
  • /data/media/####/custody_icon_location_map_pre.png
  • /data/media/####/custody_icon_map.png
  • /data/media/####/custody_icon_map_big.png
  • /data/media/####/custody_icon_map_big_disabled.png
  • /data/media/####/custody_icon_map_small.png
  • /data/media/####/custody_icon_map_small_disabled.png
  • /data/media/####/custody_icon_mylocation_map.png
  • /data/media/####/custody_icon_mylocation_map_pre.png
  • /data/media/####/custody_icon_note.png
  • /data/media/####/custody_icon_noteopen.png
  • /data/media/####/custody_icon_oxygen.png
  • /data/media/####/custody_icon_oxygen_sim.png
  • /data/media/####/custody_icon_pulse.png
  • /data/media/####/custody_icon_pulse_sim.png
  • /data/media/####/custody_icon_register.png
  • /data/media/####/custody_icon_step_new.png
  • /data/media/####/custody_icon_success.png
  • /data/media/####/custody_icon_temperature.png
  • /data/media/####/custody_icon_temperature_sim.png
  • /data/media/####/custody_icon_time.png
  • /data/media/####/custody_icon_title.png
  • /data/media/####/custody_icon_title_count.png
  • /data/media/####/custody_icon_title_health.png
  • /data/media/####/custody_icon_title_position.png
  • /data/media/####/custody_icon_title_sports.png
  • /data/media/####/custody_icon_weight.png
  • /data/media/####/custody_icon_weight_sim.png
  • /data/media/####/custody_icon_weit.png
  • /data/media/####/custody_img_cal.png
  • /data/media/####/custody_img_mileage.png
  • /data/media/####/custody_img_step.png
  • /data/media/####/custody_word04.png
  • /data/media/####/dance_icon.png
  • /data/media/####/dataSrc.html
  • /data/media/####/dataSrc.js
  • /data/media/####/date.js
  • /data/media/####/default_portrait_min.png
  • /data/media/####/default_portrait_msg.png
  • /data/media/####/default_portrait_no.png
  • /data/media/####/deit.png
  • /data/media/####/delet.png
  • /data/media/####/deletMember.css
  • /data/media/####/deletMember.html
  • /data/media/####/deletMember.js
  • /data/media/####/dietRecords.css
  • /data/media/####/dietRecords.html
  • /data/media/####/dietRecords.js
  • /data/media/####/distance.png
  • /data/media/####/doctorProfile.css
  • /data/media/####/doctorProfile.html
  • /data/media/####/doctorProfile.js
  • /data/media/####/doctor_default.png
  • /data/media/####/drawChart.js
  • /data/media/####/eAddress.html
  • /data/media/####/eAddress.js
  • /data/media/####/eHistory.html
  • /data/media/####/eHistory.js
  • /data/media/####/eHomePhone.html
  • /data/media/####/eHomePhone.js
  • /data/media/####/echarts.min.js
  • /data/media/####/editCircleMessage.html
  • /data/media/####/editCircleMessage.js
  • /data/media/####/editContact.html
  • /data/media/####/editContact.js
  • /data/media/####/editGroupName.html
  • /data/media/####/editMyCare.css
  • /data/media/####/editMyCare.html
  • /data/media/####/editMyCare.js
  • /data/media/####/editMyCareNote.css
  • /data/media/####/editMyCareNote.html
  • /data/media/####/editMyCareNote.js
  • /data/media/####/editNote.html
  • /data/media/####/editNote.js
  • /data/media/####/edit_nick_icon.png
  • /data/media/####/emergencyContactList.html
  • /data/media/####/emergencyContactList.js
  • /data/media/####/empty.png
  • /data/media/####/endProse.html
  • /data/media/####/endProse.js
  • /data/media/####/event.js
  • /data/media/####/fall_icon.png
  • /data/media/####/feedBack.html
  • /data/media/####/feedBack.js
  • /data/media/####/fence_clause.html
  • /data/media/####/file__0.localstorage-journal
  • /data/media/####/football_icon.png
  • /data/media/####/forgetPassword.css
  • /data/media/####/forgetPassword1.html
  • /data/media/####/forgetPassword1.js
  • /data/media/####/forgetPassword2.html
  • /data/media/####/forgetPassword2.js
  • /data/media/####/forgetPassword3.html
  • /data/media/####/forgetPassword3.js
  • /data/media/####/friendCircle.css
  • /data/media/####/friendCircle.html
  • /data/media/####/friendCircle.js
  • /data/media/####/friendCircleList.css
  • /data/media/####/friendCircleList.html
  • /data/media/####/friendCircleList.js
  • /data/media/####/friend_bg.png
  • /data/media/####/friend_icon_camera.png
  • /data/media/####/friend_icon_del.png
  • /data/media/####/friend_icon_fit.png
  • /data/media/####/friend_icon_foot.png
  • /data/media/####/friend_icon_leaf.png
  • /data/media/####/friend_icon_light.png
  • /data/media/####/friend_icon_love.png
  • /data/media/####/friend_icon_man.png
  • /data/media/####/friend_icon_no1.png
  • /data/media/####/friend_icon_no1_bg.png
  • /data/media/####/friend_icon_no2.png
  • /data/media/####/friend_icon_no3.png
  • /data/media/####/friend_icon_people.png
  • /data/media/####/friend_icon_weman.png
  • /data/media/####/get_health_coin.png
  • /data/media/####/group-default.png
  • /data/media/####/groupIndex.html
  • /data/media/####/groupIndex.js
  • /data/media/####/groupInfo.html
  • /data/media/####/groupInfo.js
  • /data/media/####/groupMessage.css
  • /data/media/####/groupMessage.html
  • /data/media/####/groupMessage.js
  • /data/media/####/havePlanBg.png
  • /data/media/####/headJsInit.js
  • /data/media/####/headerbg0.png
  • /data/media/####/headerbg1.png
  • /data/media/####/healthChart.css
  • /data/media/####/healthChart.html
  • /data/media/####/healthChart.js
  • /data/media/####/healthCoin.html
  • /data/media/####/healthCoinChange.css
  • /data/media/####/healthCoinChange.html
  • /data/media/####/healthCoinChange.js
  • /data/media/####/healthCoinList.css
  • /data/media/####/healthCoinList.html
  • /data/media/####/healthCoinList.js
  • /data/media/####/healthCurrency-picture.png
  • /data/media/####/healthDataUtils.js
  • /data/media/####/healthDetail.css
  • /data/media/####/healthDetail.html
  • /data/media/####/healthDetail.js
  • /data/media/####/healthManage.css
  • /data/media/####/healthManage.html
  • /data/media/####/healthManage.js
  • /data/media/####/healthNative.js
  • /data/media/####/healthProperty.js
  • /data/media/####/healthRecords.css
  • /data/media/####/healthRecords.html
  • /data/media/####/healthRecords.js
  • /data/media/####/healthReward.css
  • /data/media/####/healthReward.html
  • /data/media/####/healthReward.js
  • /data/media/####/healthTools.js
  • /data/media/####/health_coin.png
  • /data/media/####/health_currency_icon.png
  • /data/media/####/health_report_background.png
  • /data/media/####/helpRegister.css
  • /data/media/####/historyLuckyStar.css
  • /data/media/####/historyLuckyStar.html
  • /data/media/####/historyLuckyStarList.html
  • /data/media/####/historyLuckyStarList.js
  • /data/media/####/huohuo.css
  • /data/media/####/huohuo.js
  • /data/media/####/huohuo_code@3x.png
  • /data/media/####/icon_add.png
  • /data/media/####/icon_camera.png
  • /data/media/####/icon_diet.png
  • /data/media/####/icon_insurance_1.png
  • /data/media/####/icon_insurance_2.png
  • /data/media/####/icon_insurance_3.png
  • /data/media/####/icon_insurance_new_1.png
  • /data/media/####/icon_insurance_new_2.png
  • /data/media/####/icon_insurance_new_3.png
  • /data/media/####/icon_no_network.png
  • /data/media/####/icon_reduce.png
  • /data/media/####/icon_selected.png
  • /data/media/####/icon_serve_base_1.png
  • /data/media/####/icon_serve_base_2.png
  • /data/media/####/icon_serve_base_3.png
  • /data/media/####/icon_serve_boult.png
  • /data/media/####/icon_serve_communicate_1.png
  • /data/media/####/icon_serve_communicate_2.png
  • /data/media/####/icon_serve_fence_1.png
  • /data/media/####/icon_serve_fence_2.png
  • /data/media/####/icon_serve_tumble_1.png
  • /data/media/####/icon_serve_tumble_2.png
  • /data/media/####/icon_serve_tumble_3.png
  • /data/media/####/icon_server_normal.png
  • /data/media/####/icon_unselected.png
  • /data/media/####/iconfont.css
  • /data/media/####/iconfont.ttf
  • /data/media/####/icons-extra.css
  • /data/media/####/identification_img_photo copy@3x.png
  • /data/media/####/identification_img_photo@3x.png
  • /data/media/####/identification_img_process4@3x.png
  • /data/media/####/img0.png
  • /data/media/####/img1.png
  • /data/media/####/img2.png
  • /data/media/####/imgLoad.css
  • /data/media/####/imgLoad.js
  • /data/media/####/img_noserve.png
  • /data/media/####/img_serve_base_details.png
  • /data/media/####/img_serve_communicate_details.png
  • /data/media/####/img_serve_fence_details.png
  • /data/media/####/img_serve_insurance_details.png
  • /data/media/####/img_serve_tumble_details.png
  • /data/media/####/improveBaseInfo.html
  • /data/media/####/improveBaseInfo.js
  • /data/media/####/improveFamilyInfo.html
  • /data/media/####/improveFamilyInfo.js
  • /data/media/####/improveHealthInfo.html
  • /data/media/####/improveHealthInfo.js
  • /data/media/####/improvePersonalData.css
  • /data/media/####/index.css
  • /data/media/####/index.html
  • /data/media/####/index.js
  • /data/media/####/initActiveSport.css
  • /data/media/####/initActiveSport.html
  • /data/media/####/initActiveSport.js
  • /data/media/####/inputBaseInfo.css
  • /data/media/####/inputBaseInfo.html
  • /data/media/####/inputBaseInfo.js
  • /data/media/####/inputDevNumber.html
  • /data/media/####/inputDevNumber.js
  • /data/media/####/inputIDCardInfo.html
  • /data/media/####/inputIDCardInfo.js
  • /data/media/####/inputMedicalHistory.css
  • /data/media/####/inputMedicalHistory.html
  • /data/media/####/inputMedicalHistory.js
  • /data/media/####/inputMedicalHistory1.css
  • /data/media/####/inputMedicalHistory1.html
  • /data/media/####/inputMedicalHistory1.js
  • /data/media/####/inputNickName.css
  • /data/media/####/inputNickName.html
  • /data/media/####/inputNickName.js
  • /data/media/####/insertMyCare.css
  • /data/media/####/insertMyCare.html
  • /data/media/####/insertMyCare.js
  • /data/media/####/insertMyCareGuide.css
  • /data/media/####/insertMyCareGuide.html
  • /data/media/####/insertMyCareGuide.js
  • /data/media/####/insurance_clause.html
  • /data/media/####/insurance_rule_clause.html
  • /data/media/####/interventionPlan.css
  • /data/media/####/interventionPlan.html
  • /data/media/####/interventionPlan.js
  • /data/media/####/interventionPlanSubList.css
  • /data/media/####/interventionPlanSubList.html
  • /data/media/####/interventionPlanSubList.js
  • /data/media/####/inverted_trigonometric_icon.png
  • /data/media/####/isForeground.js
  • /data/media/####/launch.html
  • /data/media/####/lay_icon.png
  • /data/media/####/light_icon.png
  • /data/media/####/loading.gif
  • /data/media/####/location.js
  • /data/media/####/log.js
  • /data/media/####/login.css
  • /data/media/####/login.html
  • /data/media/####/login.js
  • /data/media/####/loginPassword.html
  • /data/media/####/loginPassword.js
  • /data/media/####/login_logo_hdpi.png
  • /data/media/####/logo.png
  • /data/media/####/lucky_star_picture.png
  • /data/media/####/lucky_start_inday.png
  • /data/media/####/manifest.json
  • /data/media/####/manualInputHealth.css
  • /data/media/####/manualInputHealth.html
  • /data/media/####/manualInputHealth.js
  • /data/media/####/map.html
  • /data/media/####/map.js
  • /data/media/####/mapMagnify.css
  • /data/media/####/mapMagnify.html
  • /data/media/####/mapMagnify.js
  • /data/media/####/md5.js
  • /data/media/####/message.css
  • /data/media/####/message.html
  • /data/media/####/message.js
  • /data/media/####/messageList.css
  • /data/media/####/messageList.html
  • /data/media/####/messageList.js
  • /data/media/####/message_icon.png
  • /data/media/####/message_icon_groupphoto.png
  • /data/media/####/microlog.txt
  • /data/media/####/mine.css
  • /data/media/####/mine.html
  • /data/media/####/mine.js
  • /data/media/####/modifyPassword1.html
  • /data/media/####/modifyPassword1.js
  • /data/media/####/modifyPassword2.html
  • /data/media/####/modifyPassword2.js
  • /data/media/####/module.js
  • /data/media/####/mui.css
  • /data/media/####/mui.imageViewer.js
  • /data/media/####/mui.imageviewer.css
  • /data/media/####/mui.indexedlist.css
  • /data/media/####/mui.indexedlist.js
  • /data/media/####/mui.js
  • /data/media/####/mui.picker.all.css
  • /data/media/####/mui.picker.all.js
  • /data/media/####/mui.previewimage.js
  • /data/media/####/mui.ttf
  • /data/media/####/mui.zoom.js
  • /data/media/####/muiTools.js
  • /data/media/####/myCareCase.css
  • /data/media/####/myCareCase.html
  • /data/media/####/myCareCase.js
  • /data/media/####/myCareList.css
  • /data/media/####/myCareList.html
  • /data/media/####/myCareList.js
  • /data/media/####/myCareMap.css
  • /data/media/####/myCareMap.html
  • /data/media/####/myCareMap.js
  • /data/media/####/myCareReport.html
  • /data/media/####/myCareState.css
  • /data/media/####/myCareState.html
  • /data/media/####/myCareState.js
  • /data/media/####/myHuoHuo.css
  • /data/media/####/myHuoHuo.html
  • /data/media/####/myHuoHuo.js
  • /data/media/####/myPackageDetail.html
  • /data/media/####/myPackageDetail.js
  • /data/media/####/myPackageList.html
  • /data/media/####/myPackageList.js
  • /data/media/####/myStorage.js
  • /data/media/####/mySubList.html
  • /data/media/####/mySubList.js
  • /data/media/####/myTaget.css
  • /data/media/####/myTarget.html
  • /data/media/####/myTarget.js
  • /data/media/####/noNetConnect.html
  • /data/media/####/noNetConnect.js
  • /data/media/####/noPlanBg.png
  • /data/media/####/no_data.png
  • /data/media/####/no_link.png
  • /data/media/####/no_plan.png
  • /data/media/####/nodata_img.png
  • /data/media/####/nodata_img03.png
  • /data/media/####/nodata_img07.png
  • /data/media/####/normalContactList.html
  • /data/media/####/normalContactList.js
  • /data/media/####/normalRecordPicker.css
  • /data/media/####/normalRecordPicker.html
  • /data/media/####/normalRecordPicker.js
  • /data/media/####/normalSet.html
  • /data/media/####/normalSet.js
  • /data/media/####/nosport_icon.png
  • /data/media/####/otherActiveInfoList.html
  • /data/media/####/otherActiveInfoList.js
  • /data/media/####/packageInfo.html
  • /data/media/####/packageInfo.js
  • /data/media/####/packageIntro.html
  • /data/media/####/packageIntro.js
  • /data/media/####/payInfo.html
  • /data/media/####/payInfo.js
  • /data/media/####/phoneContacts.html
  • /data/media/####/phoneContacts.js
  • /data/media/####/phone_icon.png
  • /data/media/####/photo_icon.png
  • /data/media/####/pinyin.js
  • /data/media/####/planDetails.css
  • /data/media/####/planDetails.html
  • /data/media/####/planDetails.js
  • /data/media/####/plan_finshed.png
  • /data/media/####/plan_going.png
  • /data/media/####/plan_no_start.png
  • /data/media/####/plusInit.js
  • /data/media/####/previewImage.css
  • /data/media/####/printTools.js
  • /data/media/####/privacyPolicy.html
  • /data/media/####/privacyRights.html
  • /data/media/####/privacyRights.js
  • /data/media/####/private-default.png
  • /data/media/####/pullrefresh_sub.css
  • /data/media/####/pullrefresh_sub.html
  • /data/media/####/pullrefresh_sub.js
  • /data/media/####/qrcode.js
  • /data/media/####/rCloudIM.js
  • /data/media/####/radio_normal3x.png
  • /data/media/####/radio_pitch3x.png
  • /data/media/####/records.data-1.js
  • /data/media/####/reduceDietImg.css
  • /data/media/####/reduceDietImg.html
  • /data/media/####/reduceDietImg.js
  • /data/media/####/register.css
  • /data/media/####/register1.html
  • /data/media/####/register1.js
  • /data/media/####/register2.html
  • /data/media/####/register2.js
  • /data/media/####/register3.html
  • /data/media/####/register3.js
  • /data/media/####/registerSuccess.html
  • /data/media/####/registerSuccess.js
  • /data/media/####/requestFamilyCareList.html
  • /data/media/####/requestFamilyCareList.js
  • /data/media/####/ride_icon.png
  • /data/media/####/run_icon.png
  • /data/media/####/selectAccount.html
  • /data/media/####/selectAccount.js
  • /data/media/####/selectCare.css
  • /data/media/####/selectCare.html
  • /data/media/####/selectCare.js
  • /data/media/####/selectContacts.css
  • /data/media/####/selectContacts.html
  • /data/media/####/selectContacts.js
  • /data/media/####/selectDataSource.css
  • /data/media/####/selectDataSource.html
  • /data/media/####/selectDataSource.js
  • /data/media/####/selectGroup.html
  • /data/media/####/selectGroup.js
  • /data/media/####/selectIDPhoto1.html
  • /data/media/####/selectIDPhoto1.js
  • /data/media/####/selectWithPhone.css
  • /data/media/####/selectWithPhone.html
  • /data/media/####/selectWithPhone.js
  • /data/media/####/send.png
  • /data/media/####/sendVerification.html
  • /data/media/####/sendVerification.js
  • /data/media/####/serve_icon.png
  • /data/media/####/serve_icon_bought.png
  • /data/media/####/serve_icon_failure.png
  • /data/media/####/serve_img_base.png
  • /data/media/####/serve_img_base_details.png
  • /data/media/####/serve_img_communicate.png
  • /data/media/####/serve_img_communicate_details.png
  • /data/media/####/serve_img_fence.png
  • /data/media/####/serve_img_fence_details.png
  • /data/media/####/serve_img_insurance.png
  • /data/media/####/serve_img_insurance_details.png
  • /data/media/####/serve_img_tumble.png
  • /data/media/####/serve_img_tumble_details.png
  • /data/media/####/servicesPackageList.css
  • /data/media/####/servicesPackageList.html
  • /data/media/####/servicesPackageList.js
  • /data/media/####/setPassword.html
  • /data/media/####/setPassword.js
  • /data/media/####/setting.html
  • /data/media/####/setting.js
  • /data/media/####/settings.css
  • /data/media/####/sigh.png
  • /data/media/####/sit_icon.png
  • /data/media/####/skip_icon.png
  • /data/media/####/sleepActiveSport.html
  • /data/media/####/sleepActiveSport.js
  • /data/media/####/sleep_icon.png
  • /data/media/####/sportMagnify.css
  • /data/media/####/sportMagnify.html
  • /data/media/####/sportMagnify.js
  • /data/media/####/sportProperty2.js
  • /data/media/####/stand_icon.png
  • /data/media/####/static_icon.png
  • /data/media/####/step.html
  • /data/media/####/step.js
  • /data/media/####/step.png
  • /data/media/####/stepCount.js
  • /data/media/####/storage.js
  • /data/media/####/subList.html
  • /data/media/####/subList.js
  • /data/media/####/swim_icon.png
  • /data/media/####/swiper.min.css
  • /data/media/####/swiper.min.js
  • /data/media/####/table_tennis_icon.png
  • /data/media/####/taiji_icon.png
  • /data/media/####/tennis_icon.png
  • /data/media/####/testLog.js
  • /data/media/####/timetools.js
  • /data/media/####/tools.js
  • /data/media/####/translate.png
  • /data/media/####/tumble_clause.html
  • /data/media/####/unbind-bg.png
  • /data/media/####/unwear_icon.png
  • /data/media/####/userDataDetail.css
  • /data/media/####/userDataDetail.html
  • /data/media/####/userDataDetail.js
  • /data/media/####/utilityPolicy.html
  • /data/media/####/utils.js
  • /data/media/####/vue.min.js
  • /data/media/####/waitingResult.html
  • /data/media/####/waitingResult.js
  • /data/media/####/walk_icon.png
  • /data/media/####/welcome.css
  • /data/media/####/welcome.html
  • /data/media/####/welcome.js
  • /data/media/####/what_health_coin.png
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/chmod 777 <Package Folder>/app_lib/x86/push_daemon
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/app_lib/x86/push_daemon <Package> io.rong.push.PushService /storage/emulated/0/.rongLock
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
Loads the following dynamic libraries:
  • Bugly
  • RongIMLib
  • libnfix
  • libshella-2.9.0.2
  • libufix
  • nfix
  • push
  • ufix
Uses the following algorithms to encrypt data:
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android