Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Adware.Gexin.11461

Added to the Dr.Web virus database: 2019-04-02

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Gexin.2.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) m.c####.com:80
  • TCP(HTTP/1.1) img.zwka####.com:80
  • TCP(HTTP/1.1) res.ika####.cn:80
  • TCP(HTTP/1.1) reso####.msg.xi####.net:80
  • TCP(HTTP/1.1) dn####.iw####.com:80
  • TCP(HTTP/1.1) c.appj####.com:80
  • TCP(HTTP/1.1) api.shu####.cn:80
  • TCP(HTTP/1.1) d####.c####.l####.####.com:80
  • TCP(HTTP/1.1) zwscimg####.c####.com.####.com:80
  • TCP(HTTP/1.1) a.appj####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) z####.c####.com:80
  • TCP(HTTP/1.1) z####.ika####.cn:80
  • TCP(TLS/1.0) 2####.58.212.174:443
  • TCP(TLS/1.0) wap.cm####.com:443
  • TCP(TLS/1.0) regi####.xm####.xi####.com:443
  • TCP 4####.62.94.2:443
  • TCP 47.74.1####.158:5222
DNS requests:
  • a####.u####.com
  • a.appj####.com
  • api.shu####.cn
  • c.appj####.com
  • dai.shu####.cn
  • dn####.iw####.com
  • images####.c####.com
  • img.zwka####.com
  • m.c####.com
  • regi####.xm####.xi####.com
  • res.ika####.cn
  • reso####.msg.xi####.net
  • sdk.o####.p####.####.com
  • wap.cm####.com
  • z####.c####.com
  • z####.ika####.cn
  • zwscimg####.c####.com
HTTP GET requests:
  • d####.c####.l####.####.com/211/images/103035.jpg
  • d####.c####.l####.####.com/211/images/103049.jpg
  • d####.c####.l####.####.com/211/images/104251.jpg
  • d####.c####.l####.####.com/211/images/135768.jpg
  • d####.c####.l####.####.com/211/images/203347.jpg
  • d####.c####.l####.####.com/211/images/236353.jpg
  • d####.c####.l####.####.com/211/images/240756.jpg
  • d####.c####.l####.####.com/211/images/245675.jpg
  • d####.c####.l####.####.com/211/images/245836.jpg
  • d####.c####.l####.####.com/211/images/245877.jpg
  • d####.c####.l####.####.com/211/images/245907.jpg
  • d####.c####.l####.####.com/211/images/245966.jpg
  • d####.c####.l####.####.com/211/images/245988.jpg
  • d####.c####.l####.####.com/211/images/246142.jpg
  • d####.c####.l####.####.com/211/images/306538.jpg
  • d####.c####.l####.####.com/211/images/320891.jpg
  • d####.c####.l####.####.com/211/images/320925.jpg
  • d####.c####.l####.####.com/211/images/328202.jpg
  • d####.c####.l####.####.com/211/images/329019.jpg
  • d####.c####.l####.####.com/211/images/329366.jpg
  • d####.c####.l####.####.com/211/images/335806.jpg
  • d####.c####.l####.####.com/211/images/354018.jpg
  • d####.c####.l####.####.com/211/images/356794.jpg
  • d####.c####.l####.####.com/211/images/50003054.jpg
  • d####.c####.l####.####.com/211/images/50004895.jpg
  • d####.c####.l####.####.com/211/images/50006710.jpg
  • d####.c####.l####.####.com/211/images/50006748.jpg
  • d####.c####.l####.####.com/211/images/50013314.jpg
  • d####.c####.l####.####.com/211/images/50018150.jpg
  • d####.c####.l####.####.com/211/images/60002271.jpg
  • d####.c####.l####.####.com/211/images/60348907.jpg
  • d####.c####.l####.####.com/211/images/60349685.jpg
  • d####.c####.l####.####.com/211/images/60349695.jpg
  • d####.c####.l####.####.com/211/images/60352469.jpg
  • d####.c####.l####.####.com/211/images/60360651.jpg
  • d####.c####.l####.####.com/211/images/60366365.jpg
  • d####.c####.l####.####.com/211/images/60371094.jpg
  • d####.c####.l####.####.com/211/images/60428751.jpg
  • d####.c####.l####.####.com/211/images/60430388.jpg
  • d####.c####.l####.####.com/211/images/60442727.jpg
  • d####.c####.l####.####.com/211/images/60450236.jpg
  • d####.c####.l####.####.com/211/images/60451802.jpg
  • d####.c####.l####.####.com/211/images/60451898.jpg
  • d####.c####.l####.####.com/211/images/60458034.jpg
  • d####.c####.l####.####.com/211/images/60458469.jpg
  • d####.c####.l####.####.com/211/images/60459412.jpg
  • d####.c####.l####.####.com/211/images/60459944.jpg
  • d####.c####.l####.####.com/211/images/60465968.jpg
  • d####.c####.l####.####.com/211/images/60528122.jpg
  • d####.c####.l####.####.com/211/images/60528123.jpg
  • d####.c####.l####.####.com/211/images/60528124.jpg
  • d####.c####.l####.####.com/211/images/60534788.jpg
  • d####.c####.l####.####.com/211/images/60552296.jpg
  • d####.c####.l####.####.com/211/images/60568500.jpg
  • d####.c####.l####.####.com/211/images/60596772.jpg
  • d####.c####.l####.####.com/211/images/60596787.jpg
  • d####.c####.l####.####.com/211/images/60597218.jpg
  • d####.c####.l####.####.com/211/images/60636892.jpg
  • d####.c####.l####.####.com/211/images/60636898.jpg
  • d####.c####.l####.####.com/211/images/60642472.jpg
  • d####.c####.l####.####.com/211/images/60642473.jpg
  • d####.c####.l####.####.com/211/images/60647694.jpg
  • d####.c####.l####.####.com/211/images/60659214.jpg
  • d####.c####.l####.####.com/211/images/60694674.jpg
  • d####.c####.l####.####.com/211/images/60721566.jpg
  • d####.c####.l####.####.com/211/images/60750295.jpg
  • d####.c####.l####.####.com/211/images/60798529.jpg
  • d####.c####.l####.####.com/211/images/60798535.jpg
  • d####.c####.l####.####.com/211/images/60798537.jpg
  • d####.c####.l####.####.com/211/images/60798539.jpg
  • d####.c####.l####.####.com/211/images/60798540.jpg
  • d####.c####.l####.####.com/211/images/60809432.jpg
  • d####.c####.l####.####.com/211/images/60884139.jpg
  • d####.c####.l####.####.com/211/images/60884142.jpg
  • d####.c####.l####.####.com/211/images/80000522.jpg
  • d####.c####.l####.####.com/211/images/80000552.jpg
  • d####.c####.l####.####.com/211/images/80000747.jpg
  • d####.c####.l####.####.com/211/images/80001410.jpg
  • d####.c####.l####.####.com/211/images/802000593.jpg
  • d####.c####.l####.####.com/211/images/802001017.jpg
  • d####.c####.l####.####.com/211/images/802100003.jpg
  • d####.c####.l####.####.com/211/images/802600004.jpg
  • d####.c####.l####.####.com/211/images/802900049.jpg
  • d####.c####.l####.####.com/211/images/802900235.jpg
  • d####.c####.l####.####.com/211/images/803200590.jpg
  • d####.c####.l####.####.com/211/images/803200625.jpg
  • d####.c####.l####.####.com/211/images/803200897.jpg
  • d####.c####.l####.####.com/211/images/803201598.jpg
  • d####.c####.l####.####.com/211/images/803201838.jpg
  • d####.c####.l####.####.com/211/images/803201933.jpg
  • d####.c####.l####.####.com/211/images/803202070.jpg
  • d####.c####.l####.####.com/211/images/803202363.jpg
  • d####.c####.l####.####.com/211/images/803202420.jpg
  • d####.c####.l####.####.com/211/images/803202465.jpg
  • d####.c####.l####.####.com/211/images/803202699.jpg
  • d####.c####.l####.####.com/211/images/803202701.jpg
  • d####.c####.l####.####.com/211/images/803500017.jpg
  • d####.c####.l####.####.com/211/images/804500004.jpg
  • d####.c####.l####.####.com/211/images/804500008.jpg
  • d####.c####.l####.####.com/211/images/804500021.jpg
  • d####.c####.l####.####.com/211/images/804500040.jpg
  • d####.c####.l####.####.com/211/images/804500050.jpg
  • d####.c####.l####.####.com/211/images/804500053.jpg
  • d####.c####.l####.####.com/211/images/804500067.jpg
  • d####.c####.l####.####.com/211/images/804500081.jpg
  • d####.c####.l####.####.com/211/images/804500088.jpg
  • d####.c####.l####.####.com/211/images/804500096.jpg
  • d####.c####.l####.####.com/211/images/804500168.jpg
  • d####.c####.l####.####.com/211/images/804500180.jpg
  • d####.c####.l####.####.com/211/images/804500187.jpg
  • d####.c####.l####.####.com/211/images/804500245.jpg
  • d####.c####.l####.####.com/211/images/804500316.jpg
  • d####.c####.l####.####.com/211/images/804500367.jpg
  • d####.c####.l####.####.com/211/images/804500435.jpg
  • d####.c####.l####.####.com/211/images/804500443.jpg
  • d####.c####.l####.####.com/211/images/804500760.jpg
  • d####.c####.l####.####.com/211/images/804501230.jpg
  • d####.c####.l####.####.com/211/images/804501542.jpg
  • d####.c####.l####.####.com/211/images/804501627.jpg
  • d####.c####.l####.####.com/211/images/804501944.jpg
  • d####.c####.l####.####.com/211/images/805000203.jpg
  • d####.c####.l####.####.com/211/images/805000472.jpg
  • d####.c####.l####.####.com/211/images/805100216.jpg
  • d####.c####.l####.####.com/211/images/805600062.jpg
  • d####.c####.l####.####.com/211/images/805600086.jpg
  • d####.c####.l####.####.com/211/images/805600107.jpg
  • d####.c####.l####.####.com/211/images/805600115.jpg
  • d####.c####.l####.####.com/211/images/805600129.jpg
  • d####.c####.l####.####.com/211/images/805600219.jpg
  • d####.c####.l####.####.com/211/images/805900007.jpg
  • d####.c####.l####.####.com/211/images/805900053.jpg
  • d####.c####.l####.####.com/211/images/805900122.jpg
  • d####.c####.l####.####.com/211/images/805900171.jpg
  • d####.c####.l####.####.com/211/images/806300002.jpg
  • d####.c####.l####.####.com/211/images/806400074.jpg
  • d####.c####.l####.####.com/211/images/807000018.jpg
  • d####.c####.l####.####.com/211/images/807000102.jpg
  • d####.c####.l####.####.com/211/images/807000118.jpg
  • d####.c####.l####.####.com/211/images/807000120.jpg
  • d####.c####.l####.####.com/211/images/807000142.jpg
  • d####.c####.l####.####.com/211/images/807000162.jpg
  • d####.c####.l####.####.com/211/images/808200875.jpg
  • d####.c####.l####.####.com/211/images/808500052.jpg
  • d####.c####.l####.####.com/211/images/808500172.jpg
  • d####.c####.l####.####.com/211/images/808500505.jpg
  • d####.c####.l####.####.com/211/images/808500533.jpg
  • d####.c####.l####.####.com/211/images/808500830.jpg
  • d####.c####.l####.####.com/211/images/808800085.jpg
  • d####.c####.l####.####.com/211/images/808800165.jpg
  • d####.c####.l####.####.com/211/images/808800222.jpg
  • d####.c####.l####.####.com/211/images/809301181.jpg
  • d####.c####.l####.####.com/211/images/809301202.jpg
  • d####.c####.l####.####.com/211/images/809301388.jpg
  • d####.c####.l####.####.com/211/images/809301477.jpg
  • d####.c####.l####.####.com/211/images/809900047.jpg
  • d####.c####.l####.####.com/211/images/810300016.jpg
  • d####.c####.l####.####.com/211/images/810300026.jpg
  • d####.c####.l####.####.com/211/images/810300030.jpg
  • d####.c####.l####.####.com/211/images/810300044.jpg
  • d####.c####.l####.####.com/211/images/810300057.jpg
  • d####.c####.l####.####.com/211/images/810300087.jpg
  • d####.c####.l####.####.com/211/images/810300089.jpg
  • d####.c####.l####.####.com/211/images/810300092.jpg
  • d####.c####.l####.####.com/211/images/810300099.jpg
  • d####.c####.l####.####.com/211/images/810300131.jpg
  • d####.c####.l####.####.com/211/images/810300136.jpg
  • d####.c####.l####.####.com/211/images/810300267.jpg
  • d####.c####.l####.####.com/211/images/810300521.jpg
  • d####.c####.l####.####.com/211/images/810300685.jpg
  • d####.c####.l####.####.com/211/images/810301797.jpg
  • d####.c####.l####.####.com/211/images/810302507.jpg
  • d####.c####.l####.####.com/211/images/810900183.jpg
  • d####.c####.l####.####.com/211/images/810900184.jpg
  • d####.c####.l####.####.com/211/images/811200309.jpg
  • d####.c####.l####.####.com/211/images/811200459.jpg
  • d####.c####.l####.####.com/211/images/811400098.jpg
  • d####.c####.l####.####.com/211/images/811400105.jpg
  • d####.c####.l####.####.com/211/images/812100012.jpg
  • d####.c####.l####.####.com/211/images/812300041.jpg
  • d####.c####.l####.####.com/211/images/812300108.jpg
  • d####.c####.l####.####.com/211/images/813300069.jpg
  • d####.c####.l####.####.com/211/images/813300079.jpg
  • d####.c####.l####.####.com/211/images/813600006.jpg
  • d####.c####.l####.####.com/211/images/813600007.jpg
  • d####.c####.l####.####.com/211/images/813600035.jpg
  • d####.c####.l####.####.com/211/images/813800013.jpg
  • d####.c####.l####.####.com/211/images/813800024.jpg
  • d####.c####.l####.####.com/211/images/814000004.jpg
  • d####.c####.l####.####.com/211/images/814800001.jpg
  • d####.c####.l####.####.com/211/images/814800002.jpg
  • d####.c####.l####.####.com/211/images/814800003.jpg
  • d####.c####.l####.####.com/211/images/814800006.jpg
  • d####.c####.l####.####.com/211/images/814800007.jpg
  • d####.c####.l####.####.com/211/images/814800011.jpg
  • d####.c####.l####.####.com/211/images/814800012.jpg
  • d####.c####.l####.####.com/211/images/814800013.jpg
  • d####.c####.l####.####.com/211/images/814800014.jpg
  • d####.c####.l####.####.com/211/images/814800015.jpg
  • d####.c####.l####.####.com/211/images/814800016.jpg
  • d####.c####.l####.####.com/211/images/814800017.jpg
  • d####.c####.l####.####.com/211/images/815102332.jpg
  • d####.c####.l####.####.com/211/images/815102346.jpg
  • d####.c####.l####.####.com/211/images/815200103.jpg
  • d####.c####.l####.####.com/211/images/816100016.jpg
  • d####.c####.l####.####.com/211/images/816400067.jpg
  • d####.c####.l####.####.com/211/images/817000010.jpg
  • d####.c####.l####.####.com/211/images/817000026.jpg
  • d####.c####.l####.####.com/211/images/817400312.jpg
  • d####.c####.l####.####.com/211/images/817400371.jpg
  • d####.c####.l####.####.com/211/images/817400551.jpg
  • d####.c####.l####.####.com/211/images/817400572.jpg
  • d####.c####.l####.####.com/211/images/817400593.jpg
  • d####.c####.l####.####.com/211/images/817400608.jpg
  • d####.c####.l####.####.com/211/images/817400620.jpg
  • d####.c####.l####.####.com/211/images/817400671.jpg
  • d####.c####.l####.####.com/211/images/817400744.jpg
  • d####.c####.l####.####.com/211/images/817400835.jpg
  • d####.c####.l####.####.com/211/images/817400851.jpg
  • d####.c####.l####.####.com/211/images/817400855.jpg
  • d####.c####.l####.####.com/211/images/817400859.jpg
  • d####.c####.l####.####.com/211/images/817400883.jpg
  • d####.c####.l####.####.com/211/images/817400893.jpg
  • d####.c####.l####.####.com/211/images/817400901.jpg
  • d####.c####.l####.####.com/211/images/817400918.jpg
  • d####.c####.l####.####.com/211/images/817400924.jpg
  • d####.c####.l####.####.com/211/images/817401058.jpg
  • d####.c####.l####.####.com/211/images/817401059.jpg
  • d####.c####.l####.####.com/211/images/817401101.jpg
  • d####.c####.l####.####.com/211/images/818000167.jpg
  • d####.c####.l####.####.com/211/images/820800045.jpg
  • d####.c####.l####.####.com/cx/endimgs/70bff44c6b6f49f39eedabacd3fb454b.jpg
  • d####.c####.l####.####.com/cx/endimgs/bcdae6af8e8e45a69768eeb3c2a38d3c.jpg
  • dn####.iw####.com/get?host=####
  • img.zwka####.com/images/icons/7392_100.png
  • m.c####.com/default.aspx
  • res.ika####.cn/cebianlan/qiandao.png
  • reso####.msg.xi####.net/gslb/?ver=####&type=####&conpt=####&uuid=####&li...
  • z####.c####.com/book/bookDetail?bookid=####&cnid=####&cnsubid=####&umeng...
  • z####.c####.com/book/bookDetail?cnid=####&channelId=####&uid=####&imsi=#...
  • z####.c####.com/bookmall/index?cnid=####&cnsubid=####&umeng=####&version...
  • z####.c####.com/bookmall/rankingForSearch?cnid=####&channelId=####&uid=#...
  • z####.c####.com/bookmall/search?cnid=####&uid=####&imsi=####&imei=####&c...
  • z####.c####.com/interface/getExitRemind?cnid=####&uid=####&imsi=####&ime...
  • z####.c####.com/interface/getExtendInfo?id=####&cnid=####&uid=####&imsi=...
  • z####.c####.com/interface/getRegistGift550?cnid=####&uid=####&imsi=####&...
  • z####.c####.com/interface/getSidebar?sidebarVersion=####&cnid=####&uid=#...
  • z####.c####.com/interface/getUserInfo?cnid=####&uid=####&imsi=####&imei=...
  • z####.c####.com/interface/register?pckName=####&cnid=####&uid=####&imsi=...
  • z####.c####.com/static/css/module1/module1.css?f8e4fbc####
  • z####.c####.com/static/css/style-before-4.1.css?85b44b3####
  • z####.c####.com/static/css/style.css?e733386####
  • z####.c####.com/static/images/c3a9a4-bg.png
  • z####.c####.com/static/images/catalog1.png
  • z####.c####.com/static/images/close-24.png
  • z####.c####.com/static/images/default-cover.png
  • z####.c####.com/static/images/o.png
  • z####.c####.com/static/images/open_vip.png
  • z####.c####.com/static/images/point.png
  • z####.c####.com/static/images/pop-loading.png
  • z####.c####.com/static/images/send_bg.png
  • z####.c####.com/static/images/status-wrap.png
  • z####.c####.com/static/images/title-bg.jpg
  • z####.c####.com/static/images/up.jpg
  • z####.c####.com/static/images/v585/freshen.png
  • z####.c####.com/static/images/vip-icon2.png
  • z####.c####.com/static/images/vip-icon3.png
  • z####.c####.com/static/images/vip480_1.png
  • z####.c####.com/static/images/vip480_2.png
  • z####.c####.com/static/images/vip480_3.png
  • z####.c####.com/static/images/vipCon1.png
  • z####.c####.com/static/images/vipCon2.png
  • z####.c####.com/static/images/vip_tb.png
  • z####.c####.com/static/images/vip_wx.png
  • z####.c####.com/static/images/vip_zfb.png
  • z####.c####.com/static/images/vp1.png
  • z####.c####.com/static/images/vp3.png
  • z####.c####.com/static/images/z1.png
  • z####.c####.com/static/js/base/base.js?da2f969####
  • z####.c####.com/static/js/base/myself.js?1fb44c7####
  • z####.c####.com/static/js/base/touch.js?326d964####
  • z####.c####.com/static/js/base/zepto.min.js?50a4556####
  • z####.c####.com/static/js/module/bookmall/search.js?144aeea####
  • z####.c####.com/static/js/module/bookmall/top_quality.js?d41d8cd####
  • z####.c####.com/static/js/module/common/client.js?5d3baee####
  • z####.c####.com/static/js/module/common/common.js?
  • z####.c####.com/static/js/module/common/common.js?c5459a7####
  • z####.c####.com/static/js/module/user/user.js?cc8c37b####
  • z####.c####.com/static/js/plugin/autopage.js?84420ba####
  • z####.c####.com/static/js/plugin/echo.min.js?4accae4####
  • z####.c####.com/static/js/plugin/fastclick.js?cb8140a####
  • z####.c####.com/static/js/plugin/jquery-1.12.4.min.js?4f25252####
  • z####.c####.com/static/js/plugin/swiper-3.3.1.jquery.min.js?5bbd6ca####
  • z####.c####.com/usersign/signclendar?cnid=####&uid=####&imsi=####&imei=#...
  • z####.c####.com/vip/index?cnid=####&channelId=####&uid=####&imsi=####&im...
  • z####.ika####.cn/log.js?cnid=####&channelId=####&uid=####&imsi=####&imei...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/11/1509020540_20421463...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/11/1510210995_18901077...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/11/1516540772_15486854...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/11/1518050337_82329790...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/12/1728050600_18870534...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/12/1729310977_12713105...
  • zwscimg####.c####.com.####.com/jpBannerImage/2017/12/1730280040_16491766...
  • zwscimg####.c####.com.####.com/jpBannerImage/2018/01/1108340972_21202623...
  • zwscimg####.c####.com.####.com/jpBannerImage/2018/07/1605100368_15733227...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/03/0959430529_35980869...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/03/1012400929_19671625...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/03/1437490159_30411707...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/03/1454030258_19279454...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/03/1557080622_12730149...
  • zwscimg####.c####.com.####.com/jpBannerImage/2019/04/1154350013_18565005...
  • zwscimg####.c####.com.####.com/shareImage/2018/07/1148290739_206926655_春...
  • zwscimg####.c####.com.####.com/shareImage/2018/12/1020220846_137050598_余...
HTTP POST requests:
  • a####.u####.com/app_logs
  • a.appj####.com/jiagu/check/upgrade
  • api.shu####.cn/report?v=####&c=####&e=####
  • c.appj####.com/ad/splash/stats.html
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • z####.c####.com/interface/getAdInfo?position=####&cnid=####&cnsubid=####...
  • z####.c####.com/pay/getWxAndZfbRepayMoney?cnid=####&channelId=####&uid=#...
  • z####.ika####.cn/logs.html?cnid=####&uid=####&imsi=####&imei=####&cnsubi...
File system changes:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/1095230965
  • /data/data/####/17kAppPrefs.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/XMPushServiceConfig.xml
  • /data/data/####/ad_show_time.xml
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/ch_readerv3.db-journal
  • /data/data/####/com.chineseall.singlebook;pushservice
  • /data/data/####/com.chineseall.singlebook_dna.xml
  • /data/data/####/com.chineseall.singlebook_prefs.xml
  • /data/data/####/common.db-journal
  • /data/data/####/config.db-journal
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/du.lock
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/f_00003e
  • /data/data/####/f_00003f
  • /data/data/####/f_000040
  • /data/data/####/f_000041
  • /data/data/####/f_000042
  • /data/data/####/f_000043
  • /data/data/####/f_000044
  • /data/data/####/f_000045
  • /data/data/####/f_000046
  • /data/data/####/f_000047
  • /data/data/####/f_000048
  • /data/data/####/f_000049
  • /data/data/####/f_00004a
  • /data/data/####/f_00004b
  • /data/data/####/f_00004c
  • /data/data/####/f_00004d
  • /data/data/####/f_00004e
  • /data/data/####/f_00004f
  • /data/data/####/f_000050
  • /data/data/####/f_000051
  • /data/data/####/f_000052
  • /data/data/####/f_000053
  • /data/data/####/f_000054
  • /data/data/####/f_000055
  • /data/data/####/f_000056
  • /data/data/####/f_000057
  • /data/data/####/f_000058
  • /data/data/####/f_000059
  • /data/data/####/f_00005a
  • /data/data/####/f_00005b
  • /data/data/####/f_00005c
  • /data/data/####/f_00005d
  • /data/data/####/f_00005e
  • /data/data/####/f_00005f
  • /data/data/####/f_000060
  • /data/data/####/f_000061
  • /data/data/####/f_000062
  • /data/data/####/f_000063
  • /data/data/####/f_000064
  • /data/data/####/f_000065
  • /data/data/####/f_000066
  • /data/data/####/f_000067
  • /data/data/####/f_000068
  • /data/data/####/f_000069
  • /data/data/####/f_00006a
  • /data/data/####/f_00006b
  • /data/data/####/f_00006c
  • /data/data/####/f_00006d
  • /data/data/####/f_00006e
  • /data/data/####/f_00006f
  • /data/data/####/f_000070
  • /data/data/####/f_000071
  • /data/data/####/f_000072
  • /data/data/####/f_000073
  • /data/data/####/f_000074
  • /data/data/####/f_000075
  • /data/data/####/f_000076
  • /data/data/####/f_000077
  • /data/data/####/f_000078
  • /data/data/####/f_000079
  • /data/data/####/f_00007a
  • /data/data/####/f_00007b
  • /data/data/####/f_00007c
  • /data/data/####/f_00007d
  • /data/data/####/f_00007e
  • /data/data/####/f_00007f
  • /data/data/####/f_000080
  • /data/data/####/f_000081
  • /data/data/####/f_000082
  • /data/data/####/f_000083
  • /data/data/####/f_000084
  • /data/data/####/f_000085
  • /data/data/####/f_000086
  • /data/data/####/f_000087
  • /data/data/####/f_000088
  • /data/data/####/f_000089
  • /data/data/####/f_00008a
  • /data/data/####/f_00008b
  • /data/data/####/f_00008c
  • /data/data/####/f_00008d
  • /data/data/####/f_00008e
  • /data/data/####/f_00008f
  • /data/data/####/f_000090
  • /data/data/####/f_000091
  • /data/data/####/f_000092
  • /data/data/####/f_000093
  • /data/data/####/f_000094
  • /data/data/####/f_000095
  • /data/data/####/f_000096
  • /data/data/####/f_000097
  • /data/data/####/f_000098
  • /data/data/####/f_000099
  • /data/data/####/f_00009a
  • /data/data/####/f_00009b
  • /data/data/####/f_00009c
  • /data/data/####/f_00009d
  • /data/data/####/f_00009e
  • /data/data/####/f_00009f
  • /data/data/####/f_0000a0
  • /data/data/####/f_0000a1
  • /data/data/####/f_0000a2
  • /data/data/####/f_0000a3
  • /data/data/####/f_0000a4
  • /data/data/####/f_0000a5
  • /data/data/####/f_0000a6
  • /data/data/####/f_0000a7
  • /data/data/####/f_0000a8
  • /data/data/####/f_0000a9
  • /data/data/####/f_0000aa
  • /data/data/####/f_0000ab
  • /data/data/####/f_0000ac
  • /data/data/####/f_0000ad
  • /data/data/####/f_0000ae
  • /data/data/####/f_0000af
  • /data/data/####/f_0000b0
  • /data/data/####/f_0000b1
  • /data/data/####/f_0000b2
  • /data/data/####/getui_sp.xml
  • /data/data/####/index
  • /data/data/####/init_c1.pid
  • /data/data/####/init_er.pid
  • /data/data/####/jg_app_update_settings_random.xml
  • /data/data/####/libgetuiext2.so
  • /data/data/####/libjiagu.so
  • /data/data/####/mipush.xml
  • /data/data/####/mipush.xml.bak (deleted)
  • /data/data/####/mipush_account.xml
  • /data/data/####/mipush_extra.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/media/####/._android.dat
  • /data/media/####/._driver.dat
  • /data/media/####/._system.dat
  • /data/media/####/.nomedia
  • /data/media/####/.zb
  • /data/media/####/1a32hvk53fdq0doogvfiqjszm.tmp
  • /data/media/####/23106po3d16v5f9n9f9iqamb4.tmp
  • /data/media/####/2i97cb8xjsyr2eesc0wzoi0dv.tmp
  • /data/media/####/2riel81lweb7g4s4jwiczyaer.tmp
  • /data/media/####/312ivu33k4wmi2fijmvk1a2tf.tmp
  • /data/media/####/3221076
  • /data/media/####/3221076.tmp
  • /data/media/####/328187.jpg
  • /data/media/####/3bbkfsk76uximmvc9wlff5zcp.tmp
  • /data/media/####/419gdcdnvvu3ptunswpseu2n6.tmp
  • /data/media/####/4b3hp1tzyaey93j19qydrqvxw.tmp
  • /data/media/####/50013396.jpg
  • /data/media/####/58fzyev9v9ens6zc96l1hj8f3.tmp
  • /data/media/####/66g31x0y6c0o7s09ho8z1gasd.tmp
  • /data/media/####/75jbybor0mpri2g6fyquije2k.tmp
  • /data/media/####/7fckwycndvnf4bhm1axu2zg8v.tmp
  • /data/media/####/80000439.jpg
  • /data/media/####/80000484.jpg
  • /data/media/####/80002102.jpg
  • /data/media/####/80002307.jpg
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/_android.dat
  • /data/media/####/_driver.dat
  • /data/media/####/_system.dat
  • /data/media/####/app_read_onclick_status
  • /data/media/####/dir.ski
  • /data/media/####/qu1d2fhu5nh0bl8l2g5d8q4e.tmp
  • /data/media/####/sidebar_frame_module_item_data
Miscellaneous:
Executes the following shell scripts:
  • chmod 755 <Package Folder>/.jiagu/libjiagu.so
  • date
  • df
  • id
  • ls /dev/socket
  • mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
  • ps
  • service call iphonesubinfo 1
  • sh -c cat
  • sh -c cat /proc/meminfo
  • sh -c cat /proc/sys/kernel/osrelease
  • sh -c cat /proc/sys/kernel/random/boot_id
  • sh -c cat /proc/sys/kernel/random/uuid
  • sh -c cat /proc/uptime
  • sh -c cat /sys/block/mmcblk0/device/cid
  • sh -c cat /sys/class/net/eth0/address
  • sh -c cat /sys/class/net/eth1/address
  • sh -c cat /sys/class/net/eth2/address
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/._android.dat
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/._driver.dat
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/._system.dat
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/.aio.dat
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
  • sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/aio.dat
  • sh -c cd /proc/;cat cpuinfo
  • sh -c cd /proc/net/ && cat arp
  • sh -c cd /proc/self/;cat status
  • sh -c cd /sys/class/net/eth0/ && cat address
  • sh -c cd /sys/class/net/wlan0/ && cat address
  • sh -c echo ODQ3RERGN0Y2NThDMzQ4ODJFNjRCODk3MjFDOTNFM0FGREFDNkI6RUUzQzM2OjM5QTgzQg== > <SD-Card>/../../../../../..<SD-Card>/._driver.dat
  • sh -c echo ODQ3RERGN0Y2NThDMzQ4ODJFNjRCODk3MjFDOTNFM0FGREFDNkI6RUUzQzM2OjM5QTgzQg== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_driver.dat
  • sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
  • sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
  • sh -c echo QzFGQjRGMjBFRjY1RTJFREFBQ0I4NzQwNUYzQ0M2RjI0NDA4OUM6NkJEN0RDOkY2QTRGRg== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
  • sh -c echo QzFGQjRGMjBFRjY1RTJFREFBQ0I4NzQwNUYzQ0M2RjI0NDA4OUM6NkJEN0RDOkY2QTRGRg== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
Loads the following dynamic libraries:
  • du
  • getuiext2
  • libjiagu
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • RSA
  • RSA-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • RSA-None-PKCS1Padding
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android