Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Adware.Gexin.2130

Добавлен в вирусную базу Dr.Web: 2018-09-04

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Adware.Gexin.2.origin
Осуществляет доступ к приватному интерфейсу телефонии (ITelephony).
Сетевая активность:
Подключается к:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) ti####.c####.l####.####.com:80
  • TCP(HTTP/1.1) f####.fengkon####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) api.9####.com:80
  • TCP(HTTP/1.1) t####.c####.q####.####.com:80
  • TCP(HTTP/1.1) pili-ip####.qini####.com:80
  • TCP(HTTP/1.1) nav.cn.ron####.com:80
  • TCP(HTTP/1.1) idu####.qini####.com:80
  • TCP(HTTP/1.1) et2-na6####.wagbr####.ali####.####.com:80
  • TCP(HTTP/1.1) cloud####.fengkon####.com:80
  • TCP(HTTP/1.1) loc.map.b####.com:80
  • TCP(HTTP/1.1) sdkopt####.chinane####.com.####.com:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) s####.9####.com:80
  • TCP(TLS/1.0) api.map.b####.com:443
  • TCP(TLS/1.0) idu####.qini####.com:443
  • TCP(TLS/1.0) s####.cn.ron####.com:443
  • TCP 1####.131.1.72:8601
  • TCP c####.g####.ig####.com:5226
  • TCP sdk.o####.t####.####.com:5224
Запросы DNS:
  • 7j####.c####.z0.####.com
  • api.9####.com
  • api.map.b####.com
  • c####.g####.ig####.com
  • c-h####.g####.com
  • cloud####.fengkon####.com
  • f####.fengkon####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • i####.img.9####.com
  • img.img.9####.com
  • loc.map.b####.com
  • log.u####.com
  • nav.cn.ron####.com
  • pili-ip####.qini####.com
  • s####.9####.com
  • s####.cn.ron####.com
  • s####.u####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sdkopt####.chinane####.com
  • st####.6####.com
  • up####.6####.com
Запросы HTTP GET:
  • api.9####.com/channel/main/ad?reqtime=####&shuMeiDeviceId=####&imei=####...
  • api.9####.com/channel/main/channelIndex?reqtime=####&shuMeiDeviceId=####...
  • api.9####.com/channel/main/channelTag?reqtime=####&shuMeiDeviceId=####&t...
  • api.9####.com/channel/main/city?reqtime=####&shuMeiDeviceId=####&imei=##...
  • api.9####.com/channel/main/openFollow?reqtime=####&shuMeiDeviceId=####&i...
  • api.9####.com/common/appVersion?reqtime=####&shuMeiDeviceId=####&imei=##...
  • api.9####.com/common/resourceversion
  • api.9####.com/game/common/newGameList?reqtime=####&shuMeiDeviceId=####&i...
  • api.9####.com/game/dropegg/eggImage
  • api.9####.com/index.php/common/getgiftlist?reqtime=####&shuMeiDeviceId=#...
  • api.9####.com/index.php/common/getresource
  • api.9####.com/ucenter/my/sysBadge?reqtime=####&shuMeiDeviceId=####&imei=...
  • api.9####.com/v2/common/appConf?reqtime=####&shuMeiDeviceId=####&imei=##...
  • api.9####.com/v2/main?reqtime=####&shuMeiDeviceId=####&imei=####&os=####...
  • et2-na6####.wagbr####.ali####.####.com/bar/get/52c4f8d956240b441501443a/...
  • idu####.qini####.com/resource/mobile/image/car/car100052.png
  • idu####.qini####.com/resource/mobile/image/car/car100053.png
  • idu####.qini####.com/resource/mobile/image/car/car100054.png
  • idu####.qini####.com/resource/mobile/image/car/car100055.png
  • idu####.qini####.com/resource/mobile/image/car/car100059.png
  • idu####.qini####.com/resource/mobile/image/car/car100060.png
  • idu####.qini####.com/resource/mobile/image/car/car100061.png
  • idu####.qini####.com/resource/mobile/image/car/car2000001.png
  • idu####.qini####.com/resource/mobile/image/car/car2000002.png
  • idu####.qini####.com/resource/mobile/image/car/car2000003.png
  • idu####.qini####.com/resource/mobile/image/car/car2000004.png
  • idu####.qini####.com/resource/mobile/image/car/car2000005.png
  • idu####.qini####.com/resource/mobile/image/car/car2000006.png
  • idu####.qini####.com/resource/mobile/image/car/car2000007.png
  • idu####.qini####.com/resource/mobile/image/car/car2000008.png
  • idu####.qini####.com/resource/mobile/image/car/car2000009.png
  • idu####.qini####.com/resource/mobile/image/car/car2000010.png
  • idu####.qini####.com/resource/mobile/image/car/car2000011.png
  • idu####.qini####.com/resource/mobile/image/car/car2000012.png
  • idu####.qini####.com/resource/mobile/image/car/car2000013.png
  • idu####.qini####.com/resource/mobile/image/car/car2000014.png
  • idu####.qini####.com/resource/mobile/image/car/car2000052.png
  • idu####.qini####.com/resource/mobile/image/car/car2000058.png
  • idu####.qini####.com/resource/mobile/image/car/car2000074.png
  • idu####.qini####.com/resource/mobile/image/car/car2000075.png
  • idu####.qini####.com/resource/mobile/image/car/car2000077.png
  • idu####.qini####.com/resource/mobile/image/car/car2000078.png
  • idu####.qini####.com/resource/mobile/image/car/car2000080.png
  • idu####.qini####.com/resource/mobile/image/car/car2000081.png
  • idu####.qini####.com/resource/mobile/image/car/car2000090.png
  • idu####.qini####.com/resource/mobile/image/car/car2000096.png
  • idu####.qini####.com/resource/mobile/image/car/car2000097.png
  • idu####.qini####.com/resource/mobile/image/car/car2000098.png
  • idu####.qini####.com/resource/mobile/image/car/car2000099.png
  • idu####.qini####.com/resource/mobile/image/car/car2000123.png
  • idu####.qini####.com/resource/mobile/image/car/car2000135.png
  • idu####.qini####.com/resource/mobile/image/car/car2000164.png
  • idu####.qini####.com/resource/mobile/image/car/car5000000.png
  • idu####.qini####.com/resource/mobile/image/car/car5000001.png
  • idu####.qini####.com/resource/mobile/image/car/car5000002.png
  • idu####.qini####.com/resource/mobile/image/car/car5000003.png
  • idu####.qini####.com/resource/mobile/image/car/car5000004.png
  • idu####.qini####.com/resource/mobile/image/car/car5000005.png
  • idu####.qini####.com/resource/mobile/image/car/car5000006.png
  • idu####.qini####.com/resource/mobile/image/car/car5000007.png
  • idu####.qini####.com/resource/mobile/image/car/car5000008.png
  • idu####.qini####.com/resource/mobile/image/car/car5000009.png
  • idu####.qini####.com/resource/mobile/image/car/car5000010.png
  • idu####.qini####.com/resource/mobile/image/car/car5000011.png
  • idu####.qini####.com/resource/mobile/image/car/car5000012.png
  • idu####.qini####.com/resource/mobile/image/car/car5000027.png
  • idu####.qini####.com/resource/mobile/image/car/car5000028.png
  • idu####.qini####.com/resource/mobile/image/car/car5000029.png
  • idu####.qini####.com/resource/mobile/image/car/car5000030.png
  • idu####.qini####.com/resource/mobile/image/car/car5000031.png
  • idu####.qini####.com/resource/mobile/image/car/car5000032.png
  • idu####.qini####.com/resource/mobile/image/car/car5000033.png
  • idu####.qini####.com/resource/mobile/image/car/car5000034.png
  • idu####.qini####.com/resource/mobile/image/car/car5000035.png
  • idu####.qini####.com/resource/mobile/image/car/car5000036.png
  • idu####.qini####.com/resource/mobile/image/car/car5000037.png
  • idu####.qini####.com/resource/mobile/image/car/car5000038.png
  • idu####.qini####.com/resource/mobile/image/car/car5000039.png
  • idu####.qini####.com/resource/mobile/image/car/car5000040.png
  • idu####.qini####.com/resource/mobile/image/car/car5000041.png
  • idu####.qini####.com/resource/mobile/image/car/car5000042.png
  • idu####.qini####.com/resource/mobile/image/car/car5000043.png
  • idu####.qini####.com/resource/mobile/image/car/car5000044.png
  • idu####.qini####.com/resource/mobile/image/car/car5000045.png
  • idu####.qini####.com/resource/mobile/image/car/car5000046.png
  • idu####.qini####.com/resource/mobile/image/car/car5000047.png
  • idu####.qini####.com/resource/mobile/image/car/car5000048.png
  • idu####.qini####.com/resource/mobile/image/car/car5000049.png
  • idu####.qini####.com/resource/mobile/image/car/car5000050.png
  • idu####.qini####.com/resource/mobile/image/car/car5000051.png
  • idu####.qini####.com/resource/mobile/image/car/car5000052.png
  • idu####.qini####.com/resource/mobile/image/car/car5000053.png
  • idu####.qini####.com/resource/mobile/image/car/car5000054.png
  • idu####.qini####.com/resource/mobile/image/car/car5000055.png
  • idu####.qini####.com/resource/mobile/image/car/car5000056.png
  • idu####.qini####.com/resource/mobile/image/car/car5000057.png
  • idu####.qini####.com/resource/mobile/image/game/egg5-0.png
  • idu####.qini####.com/resource/mobile/image/game/egg5-1.png
  • idu####.qini####.com/resource/mobile/image/game/egg5-2.png
  • idu####.qini####.com/upload/focus/2018/03/08/15205123762033572x0561u0ig....
  • idu####.qini####.com/upload/focus/2018/07/16/1531712853115156t9aoiaihqb....
  • idu####.qini####.com/upload/focus/2018/08/20/1534748922150919uh4d50o0o7....
  • idu####.qini####.com/upload/roomimg/2017/11/25/34959948183050y60hwdm16i_...
  • idu####.qini####.com/upload/roomimg/2017/11/30/35129756173447590dotj6t4_...
  • idu####.qini####.com/upload/roomimg/2018/01/10/34277105151554yhi2hahn09_...
  • idu####.qini####.com/upload/roomimg/2018/04/19/19990138225316hg3x1tth06_...
  • idu####.qini####.com/upload/roomimg/2018/04/19/34390112160208u6cb0f00w2_...
  • idu####.qini####.com/upload/roomimg/2018/05/05/314847052300461w0t8nlhsg_...
  • idu####.qini####.com/upload/roomimg/2018/05/20/36760889234239v4w4i9citu_...
  • idu####.qini####.com/upload/roomimg/2018/05/22/26162369213850t3jcvcpync_...
  • pili-ip####.qini####.com/v1/query/play?stream=####&clientIP=####&video_f...
  • s####.9####.com/api/ard_activate.php?reqtime=####&imei=####&os=####&idfa...
  • sdkopt####.chinane####.com.####.com/
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift1.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100002.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100004.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100005.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100010.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100012.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100013.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100014.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100021.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100022.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100023.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100024.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100025.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100029.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100030.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100031.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100032.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100034.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100035.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100036.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100037.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100039.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100040.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100042.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100044.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100045.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100051.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100056.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift100057.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift1024.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000037.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000041.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000084.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000085.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000086.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000088.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000089.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000100.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000102.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000109.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000117.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000118.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000122.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000125.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000134.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000150.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000163.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000170.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000203.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000204.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000205.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000207.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000213.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000214.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000217.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000218.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000220.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000224.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000228.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000229.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000230.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000231.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000233.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000234.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000235.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000236.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000249.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000255.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000256.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000257.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000258.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000259.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000261.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000264.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000270.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000277.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000290.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000297.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000299.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000308.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000309.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000310.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000312.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000317.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000318.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000319.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000320.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000321.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000322.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000330.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000332.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000333.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000355.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000356.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000357.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000358.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000359.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000361.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000366.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000367.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000371.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000374.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000375.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000377.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000385.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000386.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000393.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000394.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000396.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000400.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000406.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000411.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000416.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000419.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000420.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000421.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000422.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000423.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000424.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000427.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000428.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000431.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000432.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000433.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000434.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000435.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000436.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000437.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000438.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000439.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000440.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000441.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000442.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000443.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000444.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000445.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000446.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift2000447.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift7.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift8.png
  • t####.c####.q####.####.com/resource/mobile/image/chat/mgift85.png
  • t####.c####.q####.####.com/tdata_Soq141
  • t####.c####.q####.####.com/tdata_vxj811
  • t####.c####.q####.####.com/upload/focus/2015/10/14/1444819906561e33d5ca7...
  • t####.c####.q####.####.com/upload/focus/2016/09/22/147452849857e385007c6...
  • t####.c####.q####.####.com/upload/focus/2016/09/26/147488255057e8ec2dd59...
  • t####.c####.q####.####.com/upload/focus/2016/09/27/147495548557ea08f8911...
  • ti####.c####.l####.####.com/config/hz-hzv3.conf
Запросы HTTP POST:
  • api.9####.com/channel/mobileartist/openappad
  • c-h####.g####.com/api.php?format=####&t=####
  • cloud####.fengkon####.com/v2/device/conf
  • f####.fengkon####.com/v2/device/profile
  • loc.map.b####.com/sdk.php
  • nav.cn.ron####.com/navipush.json
  • sdk.o####.p####.####.com/api.php?format=####&t=####
Изменения в файловой системе:
Создает следующие файлы:
  • /data/data/####/.jg.ic
  • /data/data/####/1004
  • /data/data/####/1536016949884.log
  • /data/data/####/COUNTLY_STORE.xml
  • /data/data/####/DEFAULT_BADGE_URLS.xml
  • /data/data/####/GAMEVERSION.xml
  • /data/data/####/IS_FIRST_USED.xml
  • /data/data/####/RongPush.xml
  • /data/data/####/Statistics.xml
  • /data/data/####/advertiseMentInfo.xml
  • /data/data/####/authStatus_com.ninexiu.sixninexiu;remote.xml
  • /data/data/####/bugly_db_-journal
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cloudms.conf.xml
  • /data/data/####/com.ninexiu.sixninexiu_preferences.xml
  • /data/data/####/com.shumei.xml
  • /data/data/####/config.xml
  • /data/data/####/crashrecord.xml
  • /data/data/####/firll.dat
  • /data/data/####/gdaemon_20161017
  • /data/data/####/getui_sp.xml
  • /data/data/####/gift_version.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/journal.tmp
  • /data/data/####/libcuid.so
  • /data/data/####/libjiagu.so
  • /data/data/####/mobclick_agent_cached_com.ninexiu.sixninexiu144
  • /data/data/####/multidex.version.xml
  • /data/data/####/n_info.xml
  • /data/data/####/nineshow.db
  • /data/data/####/nineshow.db-journal
  • /data/data/####/pili_qos_index.json
  • /data/data/####/pili_qos_log.0
  • /data/data/####/push.pid
  • /data/data/####/push_daemon
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/qos.xml
  • /data/data/####/run.pid
  • /data/data/####/seq.xml
  • /data/data/####/tdata_Soq141
  • /data/data/####/tdata_Soq141.jar
  • /data/data/####/tdata_vxj811
  • /data/data/####/tdata_vxj811.jar
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_socialize.xml
  • /data/media/####/-1161353980.tmp
  • /data/media/####/-1219572383.tmp
  • /data/media/####/-1269310339.tmp
  • /data/media/####/-1270833433.tmp
  • /data/media/####/-1299649494.tmp
  • /data/media/####/-1367987308.tmp
  • /data/media/####/-136954511.tmp
  • /data/media/####/-1442914985.tmp
  • /data/media/####/-1463471137.tmp
  • /data/media/####/-1638019758.tmp
  • /data/media/####/-1893969225.tmp
  • /data/media/####/-1921500338.tmp
  • /data/media/####/-247773393.tmp
  • /data/media/####/-392494885.tmp
  • /data/media/####/-430580745.tmp
  • /data/media/####/-454003776.tmp
  • /data/media/####/-641647760.tmp
  • /data/media/####/-680290209.tmp
  • /data/media/####/-777007137.tmp
  • /data/media/####/-851456064.tmp
  • /data/media/####/-893633411.tmp
  • /data/media/####/-92456483.tmp
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.nomedia
  • /data/media/####/.thumbcache_idx0
  • /data/media/####/1061475068.tmp
  • /data/media/####/1489319579.tmp
  • /data/media/####/1493369456.tmp
  • /data/media/####/1504589617.tmp
  • /data/media/####/170754232.tmp
  • /data/media/####/1834107256.tmp
  • /data/media/####/1845981707.tmp
  • /data/media/####/202051919.tmp
  • /data/media/####/2026235321.tmp
  • /data/media/####/207768575.tmp
  • /data/media/####/208094841.tmp
  • /data/media/####/46684643.tmp
  • /data/media/####/715946858.tmp
  • /data/media/####/735696289.tmp
  • /data/media/####/962191471.tmp
  • /data/media/####/988802894.tmp
  • /data/media/####/RongLog_2_8_17.log
  • /data/media/####/advertiseMent.jpg
  • /data/media/####/app.db
  • /data/media/####/car100052
  • /data/media/####/car100053
  • /data/media/####/car100054
  • /data/media/####/car100055
  • /data/media/####/car100059
  • /data/media/####/car100060
  • /data/media/####/car100061
  • /data/media/####/car2000001
  • /data/media/####/car2000002
  • /data/media/####/car2000003
  • /data/media/####/car2000004
  • /data/media/####/car2000005
  • /data/media/####/car2000006
  • /data/media/####/car2000007
  • /data/media/####/car2000008
  • /data/media/####/car2000009
  • /data/media/####/car2000010
  • /data/media/####/car2000011
  • /data/media/####/car2000012
  • /data/media/####/car2000013
  • /data/media/####/car2000014
  • /data/media/####/car2000052
  • /data/media/####/car2000058
  • /data/media/####/car2000074
  • /data/media/####/car2000075
  • /data/media/####/car2000077
  • /data/media/####/car2000078
  • /data/media/####/car2000080
  • /data/media/####/car2000081
  • /data/media/####/car2000090
  • /data/media/####/car2000096
  • /data/media/####/car2000097
  • /data/media/####/car2000098
  • /data/media/####/car2000099
  • /data/media/####/car2000123
  • /data/media/####/car2000135
  • /data/media/####/car2000164
  • /data/media/####/car5000000
  • /data/media/####/car5000001
  • /data/media/####/car5000002
  • /data/media/####/car5000003
  • /data/media/####/car5000004
  • /data/media/####/car5000005
  • /data/media/####/car5000006
  • /data/media/####/car5000007
  • /data/media/####/car5000008
  • /data/media/####/car5000009
  • /data/media/####/car5000010
  • /data/media/####/car5000011
  • /data/media/####/car5000012
  • /data/media/####/car5000027
  • /data/media/####/car5000028
  • /data/media/####/car5000029
  • /data/media/####/car5000030
  • /data/media/####/car5000031
  • /data/media/####/car5000032
  • /data/media/####/car5000033
  • /data/media/####/car5000034
  • /data/media/####/car5000035
  • /data/media/####/car5000036
  • /data/media/####/car5000037
  • /data/media/####/car5000038
  • /data/media/####/car5000039
  • /data/media/####/car5000040
  • /data/media/####/car5000041
  • /data/media/####/car5000042
  • /data/media/####/car5000043
  • /data/media/####/car5000044
  • /data/media/####/car5000045
  • /data/media/####/car5000046
  • /data/media/####/car5000047
  • /data/media/####/car5000048
  • /data/media/####/car5000049
  • /data/media/####/car5000050
  • /data/media/####/car5000051
  • /data/media/####/car5000052
  • /data/media/####/car5000053
  • /data/media/####/car5000054
  • /data/media/####/car5000055
  • /data/media/####/car5000056
  • /data/media/####/car5000057
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.ninexiu.sixninexiu.db
  • /data/media/####/egg5-0
  • /data/media/####/egg5-1
  • /data/media/####/egg5-2
  • /data/media/####/info.xml
  • /data/media/####/mgift1
  • /data/media/####/mgift100002
  • /data/media/####/mgift100004
  • /data/media/####/mgift100005
  • /data/media/####/mgift100010
  • /data/media/####/mgift100012
  • /data/media/####/mgift100013
  • /data/media/####/mgift100014
  • /data/media/####/mgift100021
  • /data/media/####/mgift100022
  • /data/media/####/mgift100023
  • /data/media/####/mgift100024
  • /data/media/####/mgift100025
  • /data/media/####/mgift100029
  • /data/media/####/mgift100030
  • /data/media/####/mgift100031
  • /data/media/####/mgift100032
  • /data/media/####/mgift100034
  • /data/media/####/mgift100035
  • /data/media/####/mgift100036
  • /data/media/####/mgift100037
  • /data/media/####/mgift100039
  • /data/media/####/mgift100040
  • /data/media/####/mgift100042
  • /data/media/####/mgift100044
  • /data/media/####/mgift100045
  • /data/media/####/mgift100051
  • /data/media/####/mgift100056
  • /data/media/####/mgift100057
  • /data/media/####/mgift1024
  • /data/media/####/mgift2000037
  • /data/media/####/mgift2000041
  • /data/media/####/mgift2000084
  • /data/media/####/mgift2000085
  • /data/media/####/mgift2000086
  • /data/media/####/mgift2000088
  • /data/media/####/mgift2000089
  • /data/media/####/mgift2000100
  • /data/media/####/mgift2000102
  • /data/media/####/mgift2000109
  • /data/media/####/mgift2000117
  • /data/media/####/mgift2000118
  • /data/media/####/mgift2000122
  • /data/media/####/mgift2000125
  • /data/media/####/mgift2000134
  • /data/media/####/mgift2000150
  • /data/media/####/mgift2000163
  • /data/media/####/mgift2000170
  • /data/media/####/mgift2000203
  • /data/media/####/mgift2000204
  • /data/media/####/mgift2000205
  • /data/media/####/mgift2000207
  • /data/media/####/mgift2000213
  • /data/media/####/mgift2000214
  • /data/media/####/mgift2000217
  • /data/media/####/mgift2000218
  • /data/media/####/mgift2000220
  • /data/media/####/mgift2000224
  • /data/media/####/mgift2000228
  • /data/media/####/mgift2000229
  • /data/media/####/mgift2000230
  • /data/media/####/mgift2000231
  • /data/media/####/mgift2000233
  • /data/media/####/mgift2000234
  • /data/media/####/mgift2000235
  • /data/media/####/mgift2000236
  • /data/media/####/mgift2000249
  • /data/media/####/mgift2000255
  • /data/media/####/mgift2000256
  • /data/media/####/mgift2000257
  • /data/media/####/mgift2000258
  • /data/media/####/mgift2000259
  • /data/media/####/mgift2000261
  • /data/media/####/mgift2000264
  • /data/media/####/mgift2000270
  • /data/media/####/mgift2000277
  • /data/media/####/mgift2000290
  • /data/media/####/mgift2000297
  • /data/media/####/mgift2000299
  • /data/media/####/mgift2000308
  • /data/media/####/mgift2000309
  • /data/media/####/mgift2000310
  • /data/media/####/mgift2000312
  • /data/media/####/mgift2000317
  • /data/media/####/mgift2000318
  • /data/media/####/mgift2000319
  • /data/media/####/mgift2000320
  • /data/media/####/mgift2000321
  • /data/media/####/mgift2000322
  • /data/media/####/mgift2000330
  • /data/media/####/mgift2000332
  • /data/media/####/mgift2000333
  • /data/media/####/mgift2000355
  • /data/media/####/mgift2000356
  • /data/media/####/mgift2000357
  • /data/media/####/mgift2000358
  • /data/media/####/mgift2000359
  • /data/media/####/mgift2000361
  • /data/media/####/mgift2000366
  • /data/media/####/mgift2000367
  • /data/media/####/mgift2000371
  • /data/media/####/mgift2000374
  • /data/media/####/mgift2000375
  • /data/media/####/mgift2000377
  • /data/media/####/mgift2000385
  • /data/media/####/mgift2000386
  • /data/media/####/mgift2000393
  • /data/media/####/mgift2000394
  • /data/media/####/mgift2000396
  • /data/media/####/mgift2000400
  • /data/media/####/mgift2000406
  • /data/media/####/mgift2000411
  • /data/media/####/mgift2000416
  • /data/media/####/mgift2000419
  • /data/media/####/mgift2000420
  • /data/media/####/mgift2000421
  • /data/media/####/mgift2000422
  • /data/media/####/mgift2000423
  • /data/media/####/mgift2000424
  • /data/media/####/mgift2000427
  • /data/media/####/mgift2000428
  • /data/media/####/mgift2000431
  • /data/media/####/mgift2000432
  • /data/media/####/mgift2000433
  • /data/media/####/mgift2000434
  • /data/media/####/mgift2000435
  • /data/media/####/mgift2000436
  • /data/media/####/mgift2000437
  • /data/media/####/mgift2000438
  • /data/media/####/mgift2000439
  • /data/media/####/mgift2000440
  • /data/media/####/mgift2000441
  • /data/media/####/mgift2000442
  • /data/media/####/mgift2000443
  • /data/media/####/mgift2000444
  • /data/media/####/mgift2000445
  • /data/media/####/mgift2000446
  • /data/media/####/mgift2000447
  • /data/media/####/mgift7
  • /data/media/####/mgift8
  • /data/media/####/mgift85
  • /data/media/####/shumei.txt
  • /data/media/####/tdata_Soq141
  • /data/media/####/tdata_vxj811
  • /data/media/####/test.0
  • /data/media/####/test.log
  • /data/media/####/yoh.dat
  • /data/media/####/yol.dat
  • /data/media/####/yom.dat
Другие:
Запускает следующие shell-скрипты:
  • /system/bin/chmod 777 <Package Folder>/app_lib/x86/push_daemon
  • <Package Folder>/app_lib/x86/push_daemon <Package> io.rong.push.PushService /storage/emulated/0/.rongLock
  • <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 25287 300 0
  • chmod 700 <Package Folder>/files/gdaemon_20161017
  • chmod 755 <Package Folder>/.jiagu/libjiagu.so
  • sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 25287 300 0
Загружает динамические библиотеки:
  • Bugly
  • RongIMLib
  • encrypt
  • getuiext2
  • libjiagu
  • locSDK7
  • push
  • smsdk
Использует следующие алгоритмы для шифрования данных:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
Использует следующие алгоритмы для расшифровки данных:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • DES-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Использует специальную библиотеку для скрытия исполняемого байткода.
Осуществляет доступ к информации о геолокации.
Осуществляет доступ к информации о сети.
Осуществляет доступ к информации о телефоне (номер, imei и тд.).
Осуществляет доступ к информации об установленных приложениях.
Добавляет задания в системный планировщик.
Отрисовывает собственные окна поверх других приложений.

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке