Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Gexin.12760

Added to the Dr.Web virus database: 2019-04-25

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) norma-e####.m####.com:80
  • TCP(HTTP/1.1) qin####.com.www.####.com:80
  • TCP(HTTP/1.1) sdk-ope####.g####.com:80
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) wq.nd####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) api.map.b####.com:80
  • TCP(HTTP/1.1) st####.t####.b####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) ser####.dc####.net.cn:443
  • TCP(TLS/1.0) and####.cli####.go####.com:443
  • TCP sdk.o####.t####.####.com:5224
  • TCP c####.g####.ig####.com:5227
DNS requests:
  • 7j####.c####.z0.####.com
  • a####.b####.qq.com
  • aexcep####.b####.qq.com
  • and####.b####.qq.com
  • and####.cli####.go####.com
  • api.map.b####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • norma-e####.m####.com
  • pub-####.qin####.com
  • s####.nd####.com
  • sdk-ope####.g####.com
  • sdk.c####.ig####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • ser####.dc####.net.cn
  • st####.t####.b####.com
  • wq.nd####.com
HTTP GET requests:
  • api.map.b####.com/?qt=####&ak=####&callback=####
  • api.map.b####.com/getscript?v=####&ak=####
  • api.map.b####.com/images/blank.gif?product=####&sub_product=####&v=####&...
  • norma-e####.m####.com/android/exchange/getpublickey.do
  • qin####.com.www.####.com/tdata_EDT369
  • st####.t####.b####.com/tb/pms/img/st.gif?ts=####&t=####&sid=####&dv=####...
  • t####.c####.q####.####.com/config/hz-hzv6.conf
  • t####.c####.q####.####.com/tdata_Jga153
  • t####.c####.q####.####.com/tdata_bca864
  • t####.c####.q####.####.com/tdata_duV457
  • t####.c####.q####.####.com/tdata_mSr887
  • wq.nd####.com/app.php?c=####&a=####&city_name=####
HTTP POST requests:
  • aexcep####.b####.qq.com:8011/rqd/async
  • aexcep####.b####.qq.com:8012/rqd/async
  • and####.b####.qq.com/rqd/async
  • c-h####.g####.com/api.php?format=####&t=####
  • norma-e####.m####.com/push/android/external/add.do
  • sdk-ope####.g####.com/api.php?format=####&t=####
  • sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
  • wq.nd####.com/app.php?c=####&a=####
  • wq.nd####.com/news/index/hotkeywrod
File system changes:
Creates the following files:
  • /data/data/####/.imei.txt
  • /data/data/####/H51752B1C.xml
  • /data/data/####/_adio.dcloud.feature.ad.a.a.xml
  • /data/data/####/ab465a88a172
  • /data/data/####/authStatus_com.nongduoshou.nds.xml
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/com.x.y.1.xml
  • /data/data/####/com.x.y.2.xml
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/f_000001
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gkt-journal
  • /data/data/####/gx_sp.xml
  • /data/data/####/index
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/libcuid.so
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-3.0.0.0.so
  • /data/data/####/libufix.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mix.dex
  • /data/data/####/native_record_lock
  • /data/data/####/pdr.xml
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushk.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/run.pid
  • /data/data/####/security_info
  • /data/data/####/start_statistics_data.xml
  • /data/data/####/stream_permission.xml
  • /data/data/####/tdata_Jga153
  • /data/data/####/tdata_Jga153.jar
  • /data/data/####/tdata_bca864
  • /data/data/####/tdata_bca864.jar
  • /data/data/####/tdata_duV457
  • /data/data/####/tdata_duV457.jar
  • /data/data/####/tdata_mSr887
  • /data/data/####/tdata_mSr887.jar
  • /data/data/####/test_app
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.imei.txt
  • /data/media/####/.nomedia
  • /data/media/####/1024x1024.png
  • /data/media/####/120x120.png
  • /data/media/####/144x144.png
  • /data/media/####/152x152.png
  • /data/media/####/167x167.png
  • /data/media/####/180x180.png
  • /data/media/####/192x192.png
  • /data/media/####/2019-04-25.log.txt
  • /data/media/####/20190425.log
  • /data/media/####/20x20.png
  • /data/media/####/256x256.png
  • /data/media/####/29x29.png
  • /data/media/####/40x40.png
  • /data/media/####/48x48.png
  • /data/media/####/58x58.png
  • /data/media/####/60x60.png
  • /data/media/####/72x72.png
  • /data/media/####/76x76.png
  • /data/media/####/80x80.png
  • /data/media/####/87x87.png
  • /data/media/####/96x96.png
  • /data/media/####/README.md
  • /data/media/####/add-bank-icon.png
  • /data/media/####/add-num.png
  • /data/media/####/add1.png
  • /data/media/####/addImg.png
  • /data/media/####/add_concern.png
  • /data/media/####/add_concern1.png
  • /data/media/####/address-active.png
  • /data/media/####/address.png
  • /data/media/####/address_icon.png
  • /data/media/####/adverse-rent.png
  • /data/media/####/advertise-icon.png
  • /data/media/####/agreement.css
  • /data/media/####/agreement.html
  • /data/media/####/agreement.js
  • /data/media/####/ajax.js
  • /data/media/####/ali_icon.png
  • /data/media/####/aliiconfont.ttf
  • /data/media/####/app.db
  • /data/media/####/apply-checkedFailed.html
  • /data/media/####/apply-checkedFailed.js
  • /data/media/####/apply-checkedSuc.html
  • /data/media/####/apply-checkedSuc.js
  • /data/media/####/apply-checking.css
  • /data/media/####/apply-checking.html
  • /data/media/####/apply-org.js
  • /data/media/####/apply-organization.css
  • /data/media/####/apply-organization.html
  • /data/media/####/apply-personal.css
  • /data/media/####/apply-personal.html
  • /data/media/####/apply-personal.js
  • /data/media/####/article-jubao.css
  • /data/media/####/article-jubao.html
  • /data/media/####/article-jubao.js
  • /data/media/####/article-news.css
  • /data/media/####/article-news.html
  • /data/media/####/article-news.js
  • /data/media/####/article_collect.png
  • /data/media/####/article_like1.png
  • /data/media/####/article_like2.png
  • /data/media/####/article_qq.png
  • /data/media/####/article_transfer.png
  • /data/media/####/article_wx.png
  • /data/media/####/article_wxfriend.png
  • /data/media/####/author1.png
  • /data/media/####/author2.png
  • /data/media/####/author_icon.png
  • /data/media/####/bank-icon.png
  • /data/media/####/beMerchant_icon.png
  • /data/media/####/bind-phone.css
  • /data/media/####/bind-phone.js
  • /data/media/####/bottom_arrow.png
  • /data/media/####/card_icon.png
  • /data/media/####/checked_failed.png
  • /data/media/####/chongzhi.png
  • /data/media/####/choose-agreement.png
  • /data/media/####/choose.png
  • /data/media/####/choose_active.png
  • /data/media/####/city.data-3.js
  • /data/media/####/classify-icon.png
  • /data/media/####/close-goods-type.png
  • /data/media/####/collect_grey.png
  • /data/media/####/collect_icon.png
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.nongduoshou.nds.bin
  • /data/media/####/com.nongduoshou.nds.db
  • /data/media/####/comment.png
  • /data/media/####/comment_icon.png
  • /data/media/####/common-fontSize.js
  • /data/media/####/common.js
  • /data/media/####/daifahuo.png
  • /data/media/####/daifukuan.png
  • /data/media/####/daipingjia.png
  • /data/media/####/daishouhuo.png
  • /data/media/####/delete-comment-icon.png
  • /data/media/####/delete_img.png
  • /data/media/####/delete_search_history.png
  • /data/media/####/dianpu.png
  • /data/media/####/dingdan.png
  • /data/media/####/distance.js
  • /data/media/####/ewm.png
  • /data/media/####/ewm_bg1.png
  • /data/media/####/ewm_bg2.png
  • /data/media/####/ewm_default.png
  • /data/media/####/fenxiao.png
  • /data/media/####/format.js
  • /data/media/####/getBank.js
  • /data/media/####/getui-plugin.js
  • /data/media/####/gkt-journal
  • /data/media/####/gktper
  • /data/media/####/goods-details-transfer.png
  • /data/media/####/goods-detrails-back.png
  • /data/media/####/gouwuche.png
  • /data/media/####/guide.css
  • /data/media/####/guide.html
  • /data/media/####/guide1.png
  • /data/media/####/guide2.png
  • /data/media/####/guide3.png
  • /data/media/####/had_concerned.png
  • /data/media/####/has_collected.png
  • /data/media/####/history_icon.png
  • /data/media/####/home-article-reply.css
  • /data/media/####/home-article-reply.html
  • /data/media/####/home-article-reply.js
  • /data/media/####/home-article-replyComment.html
  • /data/media/####/home-article-replyComment.js
  • /data/media/####/home-articleDetails.css
  • /data/media/####/home-articleDetails.html
  • /data/media/####/home-articleDetails.js
  • /data/media/####/home-articleDetails_sub.css
  • /data/media/####/home-main.css
  • /data/media/####/home-main.html
  • /data/media/####/home-main.js
  • /data/media/####/home-scanner.css
  • /data/media/####/home-search-result.css
  • /data/media/####/home-search-result.html
  • /data/media/####/home-search-result.js
  • /data/media/####/home-search.css
  • /data/media/####/home-search.html
  • /data/media/####/home-search.js
  • /data/media/####/home-selectCity.css
  • /data/media/####/home-selectCity.html
  • /data/media/####/home.png
  • /data/media/####/home_active.png
  • /data/media/####/icon_search.png
  • /data/media/####/iconfont.css
  • /data/media/####/iconfont.ttf
  • /data/media/####/icons.rar
  • /data/media/####/index-no-content.png
  • /data/media/####/index.css
  • /data/media/####/index.html
  • /data/media/####/index.js
  • /data/media/####/info-news.png
  • /data/media/####/invite-details-icon.png
  • /data/media/####/jquery.min.js
  • /data/media/####/jubao.png
  • /data/media/####/kaquan-list-bg.png
  • /data/media/####/kaquan.png
  • /data/media/####/kefu_gery.png
  • /data/media/####/keyboard-icon.png
  • /data/media/####/keyword_icon.png
  • /data/media/####/kuadi_address.png
  • /data/media/####/kuaidi_addInfo.png
  • /data/media/####/kw-and-advertise.js
  • /data/media/####/lazy.png
  • /data/media/####/lazyload.min.js
  • /data/media/####/like.png
  • /data/media/####/like_active.png
  • /data/media/####/list-common.css
  • /data/media/####/loading.gif
  • /data/media/####/location-failed.png
  • /data/media/####/location.png
  • /data/media/####/location_active.png
  • /data/media/####/login.css
  • /data/media/####/login.html
  • /data/media/####/login.js
  • /data/media/####/logo.png
  • /data/media/####/mall-advertise-buy.html
  • /data/media/####/mall-advertise-buy.js
  • /data/media/####/mall-advertise-goodsList.html
  • /data/media/####/mall-advertise-goodsList.js
  • /data/media/####/mall-advertise-paySuccessful.html
  • /data/media/####/mall-advertise-paySuccessful.js
  • /data/media/####/mall-advertise-storeList.html
  • /data/media/####/mall-advertise-storeList.js
  • /data/media/####/mall-confirmOrder.css
  • /data/media/####/mall-confirmOrder.html
  • /data/media/####/mall-confirmOrder.js
  • /data/media/####/mall-goods-details.css
  • /data/media/####/mall-goods-details.html
  • /data/media/####/mall-goods-orderCommon.css
  • /data/media/####/mall-join-pintuan.html
  • /data/media/####/mall-join-pintuan.js
  • /data/media/####/mall-keyword-buy.css
  • /data/media/####/mall-keyword-buy.html
  • /data/media/####/mall-keyword-buy.js
  • /data/media/####/mall-keyword-goodsList.css
  • /data/media/####/mall-keyword-goodsList.html
  • /data/media/####/mall-keyword-goodsList.js
  • /data/media/####/mall-keyword-paySuccessful.html
  • /data/media/####/mall-keyword-paySuccessful.js
  • /data/media/####/mall-keyword-storeList.css
  • /data/media/####/mall-keyword-storeList.html
  • /data/media/####/mall-keyword-storeList.js
  • /data/media/####/mall-merchant-entry-common.js
  • /data/media/####/mall-merchantChecked.html
  • /data/media/####/mall-merchantChecked.js
  • /data/media/####/mall-merchantEntrySucceed.js
  • /data/media/####/mall-merchantEntry_1.js
  • /data/media/####/mall-merchantEntry_2.js
  • /data/media/####/mall-merchantEntry_3.js
  • /data/media/####/mall-merchantEntry_4.js
  • /data/media/####/mall-merchantFailed.html
  • /data/media/####/mall-merchantFailed.js
  • /data/media/####/mall-merchantSuccessful.html
  • /data/media/####/mall-my-addAddress.css
  • /data/media/####/mall-my-addAddress.html
  • /data/media/####/mall-my-addAddress.js
  • /data/media/####/mall-my-address.css
  • /data/media/####/mall-my-address.html
  • /data/media/####/mall-my-address.js
  • /data/media/####/mall-my-adverList.css
  • /data/media/####/mall-my-advertiseList.html
  • /data/media/####/mall-my-advertiseList.js
  • /data/media/####/mall-my-bankCardList.html
  • /data/media/####/mall-my-bankCardList.js
  • /data/media/####/mall-my-bankCradList.css
  • /data/media/####/mall-my-bindBankCard.css
  • /data/media/####/mall-my-bindBankCard.html
  • /data/media/####/mall-my-bindBankCard.js
  • /data/media/####/mall-my-ewm.html
  • /data/media/####/mall-my-ewm.js
  • /data/media/####/mall-my-fenxiao-details.css
  • /data/media/####/mall-my-fenxiao-withdraw.html
  • /data/media/####/mall-my-fenxiao-withdraw.js
  • /data/media/####/mall-my-fenxiaoManage.css
  • /data/media/####/mall-my-fenxiaoManage.html
  • /data/media/####/mall-my-fenxiaoManage.js
  • /data/media/####/mall-my-goodsCollection.css
  • /data/media/####/mall-my-goodsCollection.html
  • /data/media/####/mall-my-goodsCollection.js
  • /data/media/####/mall-my-inviteDetails.css
  • /data/media/####/mall-my-inviteDetails.html
  • /data/media/####/mall-my-inviteDetails.js
  • /data/media/####/mall-my-kaquan.css
  • /data/media/####/mall-my-kaquan.html
  • /data/media/####/mall-my-keywordList.css
  • /data/media/####/mall-my-keywordList.html
  • /data/media/####/mall-my-keywordList.js
  • /data/media/####/mall-my-order-search.html
  • /data/media/####/mall-my-order-search.js
  • /data/media/####/mall-my-order-searchResult.html
  • /data/media/####/mall-my-order-searchResult.js
  • /data/media/####/mall-my-order.css
  • /data/media/####/mall-my-order.html
  • /data/media/####/mall-my-order.js
  • /data/media/####/mall-my-orderDetails.html
  • /data/media/####/mall-my-orderDetails.js
  • /data/media/####/mall-my-orderEvaluate.html
  • /data/media/####/mall-my-orderEvaluate.js
  • /data/media/####/mall-my-orderEvaluateSuccessed.html
  • /data/media/####/mall-my-orderEvaluateSuccessed.js
  • /data/media/####/mall-my-pinOrder-search.html
  • /data/media/####/mall-my-pinOrder-search.js
  • /data/media/####/mall-my-pinOrder-searchResult.html
  • /data/media/####/mall-my-pinOrder-searchResult.js
  • /data/media/####/mall-my-pinOrder.css
  • /data/media/####/mall-my-pinOrder.html
  • /data/media/####/mall-my-pinOrder.js
  • /data/media/####/mall-my-pintuanDetails.css
  • /data/media/####/mall-my-pintuanDetails.html
  • /data/media/####/mall-my-pintuanDetails.js
  • /data/media/####/mall-my-shoppingcar.css
  • /data/media/####/mall-my-shoppingcar.html
  • /data/media/####/mall-my-shoppingcar.js
  • /data/media/####/mall-my-shouhouApplySuccessful.css
  • /data/media/####/mall-my-spreadEwm.css
  • /data/media/####/mall-my-spreadOrder.css
  • /data/media/####/mall-my-spreadOrder.html
  • /data/media/####/mall-my-spreadOrder.js
  • /data/media/####/mall-my-storeCollection.css
  • /data/media/####/mall-my-storeCollection.html
  • /data/media/####/mall-my-storeCollection.js
  • /data/media/####/mall-my-tuiguang.css
  • /data/media/####/mall-my-tuiguang.html
  • /data/media/####/mall-my-tuiguang.js
  • /data/media/####/mall-my-tuikuan.css
  • /data/media/####/mall-my-tuikuanApply.css
  • /data/media/####/mall-my-tuikuanApply.html
  • /data/media/####/mall-my-tuikuanApply.js
  • /data/media/####/mall-my-tuikuanApplySuccessful.html
  • /data/media/####/mall-my-tuikuanApplySuccessful.js
  • /data/media/####/mall-my-tuikuanDetails.css
  • /data/media/####/mall-my-tuikuanDetails.html
  • /data/media/####/mall-my-tuikuanDetails.js
  • /data/media/####/mall-my-tuikuanList.html
  • /data/media/####/mall-my-tuikuanList.js
  • /data/media/####/mall-my-visitHistory.css
  • /data/media/####/mall-my-visitHistory.html
  • /data/media/####/mall-my-visitHistory.js
  • /data/media/####/mall-my-wallet-details.css
  • /data/media/####/mall-my-wallet-details.html
  • /data/media/####/mall-my-wallet-details.js
  • /data/media/####/mall-my-wallet-recharge.css
  • /data/media/####/mall-my-wallet-recharge.html
  • /data/media/####/mall-my-wallet-spread.css
  • /data/media/####/mall-my-wallet-spreadPrize.html
  • /data/media/####/mall-my-wallet-spreadPrize.js
  • /data/media/####/mall-my-wallet-withdraw.html
  • /data/media/####/mall-my-wallet-withdrawDetails.css
  • /data/media/####/mall-my-wallet-withdrawDetails.html
  • /data/media/####/mall-my-wallet-withdrawDetails.js
  • /data/media/####/mall-my-wallet.css
  • /data/media/####/mall-my-wallet.html
  • /data/media/####/mall-my-wallet.js
  • /data/media/####/mall-myCenter-bg.jpg
  • /data/media/####/mall-myCenter.css
  • /data/media/####/mall-news.png
  • /data/media/####/mall-order-operate.js
  • /data/media/####/mall-pintuan-successful.html
  • /data/media/####/mall-pintuan-successful.js
  • /data/media/####/mall-pintuanGoods-details.css
  • /data/media/####/mall-pintuanGoods-details.html
  • /data/media/####/mall-pintuaning-list.html
  • /data/media/####/mall-pintuaning-list.js
  • /data/media/####/mall-singleBuy-successful.html
  • /data/media/####/mall-singleBuy-successful.js
  • /data/media/####/mall-store-details.css
  • /data/media/####/mall-store-details.html
  • /data/media/####/mall-store-list.css
  • /data/media/####/mall-store-list.html
  • /data/media/####/mall-store-list.js
  • /data/media/####/mall-ucenter-icon.png
  • /data/media/####/mall.png
  • /data/media/####/mall_active.png
  • /data/media/####/mall_ajax.js
  • /data/media/####/mall_classify.css
  • /data/media/####/mall_classify.html
  • /data/media/####/mall_classify.js
  • /data/media/####/mall_classify.png
  • /data/media/####/mall_classify_active.png
  • /data/media/####/mall_classify_search.css
  • /data/media/####/mall_classify_search.html
  • /data/media/####/mall_classify_search.js
  • /data/media/####/mall_classify_search_result.html
  • /data/media/####/mall_classify_search_result.js
  • /data/media/####/mall_common.css
  • /data/media/####/mall_goods_details.js
  • /data/media/####/mall_home.png
  • /data/media/####/mall_home_active.png
  • /data/media/####/mall_icon.png
  • /data/media/####/mall_index-searchResult.css
  • /data/media/####/mall_index.css
  • /data/media/####/mall_index.html
  • /data/media/####/mall_index.js
  • /data/media/####/mall_index_activity.html
  • /data/media/####/mall_index_activity.js
  • /data/media/####/mall_index_search.css
  • /data/media/####/mall_index_search.html
  • /data/media/####/mall_index_search.js
  • /data/media/####/mall_index_searchResult.html
  • /data/media/####/mall_index_searchResult.js
  • /data/media/####/mall_main.css
  • /data/media/####/mall_main.html
  • /data/media/####/mall_main.js
  • /data/media/####/mall_merchantEntry.css
  • /data/media/####/mall_merchantEntry_1.html
  • /data/media/####/mall_merchantEntry_2.html
  • /data/media/####/mall_merchantEntry_3.html
  • /data/media/####/mall_merchantEntry_4.html
  • /data/media/####/mall_merchantFailed.css
  • /data/media/####/mall_my.png
  • /data/media/####/mall_myCenter.html
  • /data/media/####/mall_myCenter.js
  • /data/media/####/mall_my_active.png
  • /data/media/####/mall_pintuanGoods_details.js
  • /data/media/####/mall_scan.png
  • /data/media/####/mall_scanner.html
  • /data/media/####/mall_scanner.js
  • /data/media/####/mall_shangcheng_searchGoods.html
  • /data/media/####/mall_shangcheng_searchGoods.js
  • /data/media/####/mall_store_details.js
  • /data/media/####/manifest.json
  • /data/media/####/md5.js
  • /data/media/####/merchant-applying.png
  • /data/media/####/merchantEntry1.png
  • /data/media/####/merchantEntry2.png
  • /data/media/####/merchantEntry3.png
  • /data/media/####/merchant_address.png
  • /data/media/####/mobile-login.css
  • /data/media/####/mobile-login.html
  • /data/media/####/mobile-login.js
  • /data/media/####/mui.min.css
  • /data/media/####/mui.min.js
  • /data/media/####/mui.picker.min.css
  • /data/media/####/mui.picker.min.js
  • /data/media/####/mui.previewimage.js
  • /data/media/####/mui.pullToRefresh.js
  • /data/media/####/mui.pullToRefresh.material.js
  • /data/media/####/mui.showLoading.css
  • /data/media/####/mui.ttf
  • /data/media/####/mui.zoom.js
  • /data/media/####/my-order-details.css
  • /data/media/####/my-order-evaluate.css
  • /data/media/####/my-pintuan-successful.css
  • /data/media/####/my-pintuaning-list.css
  • /data/media/####/my.png
  • /data/media/####/my_active.png
  • /data/media/####/nds-tools.html
  • /data/media/####/ndsrz.png
  • /data/media/####/news-icon.png
  • /data/media/####/news-main.html
  • /data/media/####/news-main.js
  • /data/media/####/news.css
  • /data/media/####/news.png
  • /data/media/####/news_active.png
  • /data/media/####/news_icon_2.png
  • /data/media/####/no-address.png
  • /data/media/####/no-ask.png
  • /data/media/####/no-collect.png
  • /data/media/####/no-comment-icon.png
  • /data/media/####/no-concern.png
  • /data/media/####/no-goodsCollect-icon.png
  • /data/media/####/no-history.png
  • /data/media/####/no-internet.png
  • /data/media/####/no-kaquan.png
  • /data/media/####/no-like.png
  • /data/media/####/no-news1.png
  • /data/media/####/no-news2.png
  • /data/media/####/no-order.png
  • /data/media/####/no-pintuan.png
  • /data/media/####/no-storeCollect-icon.png
  • /data/media/####/open.png
  • /data/media/####/open_active.png
  • /data/media/####/operate.js
  • /data/media/####/order_icon.png
  • /data/media/####/order_pay.js
  • /data/media/####/page-search.png
  • /data/media/####/pay_choose_icon.png
  • /data/media/####/person.png
  • /data/media/####/phone_icon.png
  • /data/media/####/phone_login.png
  • /data/media/####/phonegap.js
  • /data/media/####/pin-failed-icon.png
  • /data/media/####/pintuan_icon.png
  • /data/media/####/pintuanzhong-icon.png
  • /data/media/####/previewImage.css
  • /data/media/####/publish-main.css
  • /data/media/####/publish-main.html
  • /data/media/####/publish-main.js
  • /data/media/####/publish-myConcern.css
  • /data/media/####/publish-myConcern.html
  • /data/media/####/publish-myConcern.js
  • /data/media/####/publish-successful.css
  • /data/media/####/publish-successful.html
  • /data/media/####/publish.png
  • /data/media/####/publish_active.png
  • /data/media/####/pull.css
  • /data/media/####/pulldown_bg.png
  • /data/media/####/qqZone_share.png
  • /data/media/####/qq_share.png
  • /data/media/####/question-answer-comment.html
  • /data/media/####/question-answer-comment.js
  • /data/media/####/question-answer-details.css
  • /data/media/####/question-answer-details.html
  • /data/media/####/question-answer-details.js
  • /data/media/####/question-answer-replyComment.html
  • /data/media/####/question-answer-replyComment.js
  • /data/media/####/question-details.css
  • /data/media/####/question-details.html
  • /data/media/####/question-details.js
  • /data/media/####/question-img.png
  • /data/media/####/question-main.css
  • /data/media/####/question-main.html
  • /data/media/####/question-main.js
  • /data/media/####/question-news.html
  • /data/media/####/question-news.js
  • /data/media/####/question-reply.css
  • /data/media/####/question-reply.html
  • /data/media/####/question-reply.js
  • /data/media/####/question.png
  • /data/media/####/question_active.png
  • /data/media/####/readnum.png
  • /data/media/####/record.gif
  • /data/media/####/reduce-num.png
  • /data/media/####/refresh.png
  • /data/media/####/refresh_btn.png
  • /data/media/####/refresh_concern.js
  • /data/media/####/remind.png
  • /data/media/####/reply.png
  • /data/media/####/right_arrow.png
  • /data/media/####/s-merchantEntry1.png
  • /data/media/####/s-merchantEntry2.png
  • /data/media/####/s-merchantEntry3.png
  • /data/media/####/s-merchantEntry4.png
  • /data/media/####/scan.png
  • /data/media/####/scanner.html
  • /data/media/####/scanner.js
  • /data/media/####/selectSity.js
  • /data/media/####/service_icon.png
  • /data/media/####/settings-aboutus.css
  • /data/media/####/settings-aboutus.html
  • /data/media/####/settings-aboutus.js
  • /data/media/####/settings-account-bindPhone.css
  • /data/media/####/settings-account-bindPhone.html
  • /data/media/####/settings-account-bindPhone.js
  • /data/media/####/settings-account-changePhone.html
  • /data/media/####/settings-account-changePhone.js
  • /data/media/####/settings-accountSafe.css
  • /data/media/####/settings-accountSafe.html
  • /data/media/####/settings-accountSafe.js
  • /data/media/####/settings-changePayPwd.css
  • /data/media/####/settings-changePayPwd.html
  • /data/media/####/settings-feedback.css
  • /data/media/####/settings-feedback.html
  • /data/media/####/settings-feedback.js
  • /data/media/####/settings-main.css
  • /data/media/####/settings-main.html
  • /data/media/####/settings-main.js
  • /data/media/####/settings-setPayPwd.css
  • /data/media/####/settings-setPayPwd.html
  • /data/media/####/settings-userName.html
  • /data/media/####/settings-userName.js
  • /data/media/####/settings-userSign.css
  • /data/media/####/settings-userSign.html
  • /data/media/####/settings-userSign.js
  • /data/media/####/settings-userinfo.css
  • /data/media/####/settings-userinfo.html
  • /data/media/####/settings-userinfo.js
  • /data/media/####/share.css
  • /data/media/####/share.js
  • /data/media/####/share_bg.png
  • /data/media/####/share_logo.png
  • /data/media/####/shoppingcar-icon.png
  • /data/media/####/shouhou-addImage.png
  • /data/media/####/shouhou-choose-active.png
  • /data/media/####/shouhou-choose.png
  • /data/media/####/shouhou.png
  • /data/media/####/shouhuoType_active.png
  • /data/media/####/spread_order.png
  • /data/media/####/spread_prize.png
  • /data/media/####/spread_question.png
  • /data/media/####/store-bg.png
  • /data/media/####/store_grey.png
  • /data/media/####/style.css
  • /data/media/####/successful.png
  • /data/media/####/system-news.css
  • /data/media/####/system-news.html
  • /data/media/####/system-news.png
  • /data/media/####/systems-news-bg.png
  • /data/media/####/tdata_Jga153
  • /data/media/####/tdata_bca864
  • /data/media/####/tdata_duV457
  • /data/media/####/tdata_mSr887
  • /data/media/####/template.html
  • /data/media/####/test.log
  • /data/media/####/tixian.png
  • /data/media/####/to-publish.png
  • /data/media/####/tool.png
  • /data/media/####/transfer.png
  • /data/media/####/tuiguang-prize.png
  • /data/media/####/tuiguang.png
  • /data/media/####/tuiguang_icon.png
  • /data/media/####/ucenter-collect.png
  • /data/media/####/ucenter-edit.png
  • /data/media/####/ucenter-like.png
  • /data/media/####/ucenter-main.css
  • /data/media/####/ucenter-main.html
  • /data/media/####/ucenter-main.js
  • /data/media/####/ucenter-myArticle.html
  • /data/media/####/ucenter-myArticle.js
  • /data/media/####/ucenter-myCollect.css
  • /data/media/####/ucenter-myCollect.html
  • /data/media/####/ucenter-myCollect.js
  • /data/media/####/ucenter-myConcern.css
  • /data/media/####/ucenter-myConcern.html
  • /data/media/####/ucenter-myConcern.js
  • /data/media/####/ucenter-myFans.html
  • /data/media/####/ucenter-myFans.js
  • /data/media/####/ucenter-myHistory.css
  • /data/media/####/ucenter-myHistory.html
  • /data/media/####/ucenter-myHistory.js
  • /data/media/####/ucenter-myLike.html
  • /data/media/####/ucenter-myLike.js
  • /data/media/####/ucenter-myPage.css
  • /data/media/####/ucenter-myPage.html
  • /data/media/####/ucenter-myPage.js
  • /data/media/####/ucenter-myQuestion.css
  • /data/media/####/ucenter-myQuestion.html
  • /data/media/####/ucenter-myQuestion.js
  • /data/media/####/ucenter-question.png
  • /data/media/####/ucenter-settings.png
  • /data/media/####/ucenter-wallet.png
  • /data/media/####/un_collected.png
  • /data/media/####/unionPay-icon.png
  • /data/media/####/update.js
  • /data/media/####/upload-img.png
  • /data/media/####/util.js
  • /data/media/####/voice-big.png
  • /data/media/####/voice-contentBg.png
  • /data/media/####/voice-grey-icon.png
  • /data/media/####/voice-icon.png
  • /data/media/####/voice1.png
  • /data/media/####/wallet_icon.png
  • /data/media/####/wb_share.png
  • /data/media/####/wechat_icon.png
  • /data/media/####/withdraw-status-failed.png
  • /data/media/####/withdraw-status1.png
  • /data/media/####/withdraw-status2.png
  • /data/media/####/withdraw-status3.png
  • /data/media/####/withdraw-status4.png
  • /data/media/####/wx_friend_share.png
  • /data/media/####/wx_icon.png
  • /data/media/####/wx_share.png
  • /data/media/####/yellow_star.png
  • /data/media/####/yellow_star_active.png
  • /data/media/####/zepto.min.js
  • /data/media/####/ziti-address.png
  • /data/media/####/ziti-icon.png
  • /data/media/####/zuji.png
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.getui.plugins.DemoPushService 24945 300 0
  • cat /sys/class/net/wlan0/address
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-3.0.0.0.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • mount
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.getui.plugins.DemoPushService 24945 300 0
Loads the following dynamic libraries:
  • BaiduMapSDK_base_v5_2_1
  • Bugly
  • getuiext3
  • libnfix
  • libshella-3.0.0.0
  • libufix
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CFB-NoPadding
  • AES-ECB-PKCS5Padding
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
  • AES-ECB-PKCS5Padding
  • AES-GCM-NoPadding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android