Library
My library

+ Add to library

Profile

Adware.Dowgin.2015

Added to the Dr.Web virus database: 2018-06-24

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Dowgin.14.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • TCP(/m/empty.js.gif?site_name=M58&tag=pvstatall&referrer=&post_count=-1&_trackParams=10241%3A6%40%40111235%3A501%40%4010243%3A1%40%4010374%3A0%40%40111247%3A18784*6341*14068*6335*11551*23023*6339*25963*11498*11511*4877*25417%40%4011535%3A0%40%40111246%3A6%40%40111249%3A21*37*39*42*382*1539*2748*4089*8102*10074*14806*16990*17328*17860*18455*18458*18863*20796*21273*22954*23625*23637*30003*33890*34115*36208*36269*36423*36481*36482*36540*36548*36615*36632*36849*36854*36910*36936*36938*37322*37336*37426*37597*37613*37712*37730*37817*38039*42548*42912*43307*43498*43687*44420*44706*49501*49535*50046*50060*50111*50115*59993*60032*60036*60039*60044*60079*60115*60121*60145*60154*201933*205999*208066*208577*208719*210341*216497*217114*220998*222343*222358*222455*227152*227430*227522*229671*241916*244263*245583*246022*250000*250562*252168*253766*254974*257689*258327*259032*259033*260177*265713*266055*268143*269237*271557*274325*275641*276881*277787*301341*307876*311869*315016*326044*327301*327846*330431*331884*334136*334722*334749*334791*336566*341757*343635*345220*347027*348885%40%40111251%3A430*202*435*436*414*359*338*290*291%40%40111255%3A16*17*39*1043*696*884*433*136*654*368*668*91*95*96*607*608*97%40%40111254%3A363*177*364*144*178*358*181*142%40%40111257%3A2039*1850*900%40%40111256%3A9696%40%40111259%3A1362%40%40111265%3A1038529','infoid':'34479748926511','infotype':'','usertype':'','als':'','utm_source':'market','utm_campaign':'','spm':'u-LmZ2V4Aa1luDubj.ydlm_wzl','qz_gdt':'','br58':'','coords':'_','new_session':'1','init_refer':'','new_uv':'1','UUID':'94473cc1-1451-4359-8ff6-ffa91f465cc5','bangbangid':'','navtype':'0','sc':'600,800','sid':'166017709200515039073478651','cate':'9224,13901,9546','actiontype':'m_zhuzhan','localcate':'574,580,2626','area':'1,1142,15336','localarea':'1','pagetype':'detail','source':'6','zhiweiID':'34479748926511','ownerid':'56194114215951','shopid':'56194114215951','thirdcate':'','is_biz':'false','userid':'56194114215951','GA_pageview':'/m/bj/job/yewu/detail/','version':'G'}&rand_id=0.06762114237062633 HTTP/1.1) trac####.58.com:80
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) trac####.58.com:80
  • TCP(HTTP/1.1) n####.5####.com.cn:80
  • TCP(HTTP/1.1) b####.58.com:80
  • TCP(HTTP/1.1) wb.110.ta####.com:80
  • TCP(HTTP/1.1) s####.jom####.com:80
  • TCP(HTTP/1.1) aserver####.m.ta####.com:80
  • TCP(HTTP/1.1) c.g####.qq.com:80
  • TCP(HTTP/1.1) gdv.a.s####.com:80
  • TCP(HTTP/1.1) mf####.gam####.cn.####.com:80
  • TCP(HTTP/1.1) ada####.m.ta####.com:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(HTTP/1.1) c####.e.qq.com:80
  • TCP(HTTP/1.1) zhusho####.gam####.cn:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) zhg.ali####.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) i####.gam####.cn.####.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) pass####.58.com:80
  • TCP(HTTP/1.1) ad####.m.ta####.com:80
  • TCP(HTTP/1.1) si.hi.shpan####.cn:80
  • TCP(HTTP/1.1) zp.recom####.58.com:80
  • TCP(HTTP/1.1) v.g####.qq.com:80
  • TCP(HTTP/1.1) c.5####.com.####.com:80
  • TCP(HTTP/1.1) d.g####.qq.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) wap.n.sh####.com:80
  • TCP(HTTP/1.1) gdtc####.58.com:80
  • TCP(HTTP/1.1) st####.58.com:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(HTTP/1.1) oth.up####.mdt.####.com:8080
  • TCP(TLS/1.0) ssl.gst####.com:443
  • TCP(TLS/1.0) ae.bdst####.com.####.com:443
  • TCP(TLS/1.0) www.go####.nl:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) www.gst####.com:443
  • TCP(TLS/1.0) sh.wagbr####.ta####.com:443
  • TCP(TLS/1.0) h####.b####.com:443
  • TCP(TLS/1.0) tag.b####.com:443
  • TCP(TLS/1.0) wap.n.sh####.com:443
  • TCP(TLS/1.0) a####.a####.m.####.com:443
  • TCP(TLS/1.0) adser####.go####.com:443
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP umengj####.m.ta####.com:443
  • TCP ope####.m.ta####.com:443
DNS requests:
  • a####.m.ta####.com
  • a####.u####.com
  • ad####.m.ta####.com
  • ada####.m.ta####.com
  • adser####.go####.com
  • ae.bdst####.com
  • ag####.m.ta####.com
  • api.s####.b####.com
  • b####.58.com
  • b####.s####.b####.com
  • bcfeed####.ta####.com
  • c####.e.qq.com
  • c.5####.com.cn
  • c.g####.qq.com
  • chan####.s####.com
  • d####.58.com
  • d.g####.qq.com
  • g####.cm.58.com
  • gdtc####.58.com
  • h####.b####.com
  • hm.b####.com
  • i####.gam####.cn
  • img.5####.com.cn
  • imgc####.qq.com
  • j####.58.com
  • j1.5####.com.cn
  • j2.5####.com.cn
  • ji####.m.58.com
  • l####.tbs.qq.com
  • m####.b####.com
  • m####.gam####.cn
  • m.5####.com
  • m.m.5####.com
  • mf####.gam####.cn
  • mi.g####.qq.com
  • msg.umengc####.com
  • n####.5####.com.cn
  • nsc####.b####.com
  • oth.up####.mdt.####.com
  • p####.g####.cn
  • p####.zhanz####.b####.com
  • pass####.58.com
  • pl####.y####.com
  • qzones####.g####.cn
  • s####.e.qq.com
  • si.hi.shpan####.cn
  • ssl.gst####.com
  • st####.58.com
  • tag.b####.com
  • trac####.58.com
  • umen####.m.ta####.com
  • umengj####.m.ta####.com
  • v.g####.qq.com
  • wb.110.ta####.com
  • www.go####.com
  • www.go####.nl
  • www.gst####.com
  • xiongz####.b####.com
  • y####.al####.com
  • zhusho####.gam####.cn
  • zp.recom####.58.com
  • zp.ser####.58.com
HTTP GET requests:
  • ad####.m.ta####.com/rest/gc2?ak=####&av=####&c=####&d=####&sv=####&t=###...
  • aserver####.m.ta####.com/jsapi
  • aserver####.m.ta####.com/unifull/css/unifull.min.css
  • b####.58.com/yewu/34269627948235x.shtml?utm_source=####&spm=####&gdt_cli...
  • b####.58.com/yewu/34479748926511x.shtml?utm_source=####&spm=####&gdt_cli...
  • c####.e.qq.com/cm.fcg?a=####&j=####&time=####
  • c.5####.com.####.com/crop/ecom/m/tcb/ideaShow/main.css
  • c.5####.com.####.com/crop/ecom/m/tcb/ideaShow/main_v20180516105424.js
  • c.5####.com.####.com/job/img/jubao.png
  • c.5####.com.####.com/job/m/common/0.1/esl_zepto.min_v20161228133534.js
  • c.5####.com.####.com/job/m/full/detail/0.1/job_common_final_v20180614173...
  • c.5####.com.####.com/job/m/full/detail/0.1/m.job.detail_v20180614173734....
  • c.5####.com.####.com/job/m/full/detail/0.1/zp_m_recommend_v2018010215465...
  • c.5####.com.####.com/job/m/resume/delivery/1.1/js/app.bundle_v2018061916...
  • c.5####.com.####.com/js/login/passportMobileLogin_v20171226161048.js
  • c.5####.com.####.com/js/login/passport_fingerprint2.js
  • c.5####.com.####.com/logo/m58/40_40/logo.png
  • c.5####.com.####.com/logo/m58/60_35/logo.png
  • c.5####.com.####.com/m58/img/icon58b.png
  • c.5####.com.####.com/m58/img/man1_126.png
  • c.5####.com.####.com/m58/img/man2_126.png
  • c.5####.com.####.com/m58/img/man3_126.png
  • c.5####.com.####.com/m58/img/man4_126.png
  • c.5####.com.####.com/m58/img/my_img.png
  • c.5####.com.####.com/m58/img/pointer_left.png
  • c.5####.com.####.com/m58/img/toutu.png
  • c.5####.com.####.com/m58/img/virtual_img.png
  • c.5####.com.####.com/m58/img/woman1_126.png
  • c.5####.com.####.com/m58/img/woman2_126.png
  • c.5####.com.####.com/m58/img/woman3_126.png
  • c.5####.com.####.com/m58/img/woman4_126.png
  • c.5####.com.####.com/m58/job/css/m3_v20180226154553.css
  • c.5####.com.####.com/m58/job/css/mresume_v20171228181422.css
  • c.5####.com.####.com/m58/job/img/my_logo.png
  • c.5####.com.####.com/m58/job/img/zp_head_new.png
  • c.5####.com.####.com/m58/m3/js/ppfingerprint_m.js
  • c.5####.com.####.com/m58/m3/js/ppstore-m.js
  • c.5####.com.####.com/m58/njs/conf/boot_job_v20180517144203.js
  • c.5####.com.####.com/m58/njs/lib/esl_zepto.min.js
  • c.5####.com.####.com/m58/njs/pkg/job/job_resume_post_micro.js?v=####
  • c.5####.com.####.com/olympia/img/common/58logo_icon.png
  • c.5####.com.####.com/olympia/img/job/job_detail.png
  • c.5####.com.####.com/olympia/js/conf/boot_invoke_config_v20180329140357.js
  • c.5####.com.####.com/pso/pcuc.js
  • c.5####.com.####.com/webfonts/footer/footer.ttf?v=####
  • c.5####.com.####.com/webfonts/header/header.ttf?v=####
  • c.5####.com.####.com/webfonts/job/job_detail.ttf?v=####
  • c.5####.com.####.com/zt/appdown/js/m_invoke_app.js?v=####
  • c.g####.qq.com/gdt_mclick.fcg?viewid=####&jtype=####&i=####&os=####&asi=...
  • d.g####.qq.com/fcg-bin/gdt_appdetail.fcg?ico=####&op_appid=####
  • gdtc####.58.com/adJump?target=####&qz_gdt=####
  • gdtc####.58.com/api?action=direct_tg&params={"localid":"1","cateid":"139...
  • gdtc####.58.com/bj/yewu/34269627948235x.shtml?reform=####&utm_source=###...
  • gdtc####.58.com/bj/yewu/34479748926511x.shtml?reform=####&utm_source=###...
  • gdtc####.58.com/counter?infoid=####
  • gdtc####.58.com/gdtcm?city=####&cate=####&plat=####
  • gdtc####.58.com/gdtcmres?status=####&id=####&name=####&time=####&j=####&...
  • gdtc####.58.com/history/save/34269627948235?_=####&callback=####
  • gdtc####.58.com/history/save/34479748926511?_=####&callback=####
  • gdtc####.58.com/m_createmicroresumev2/?infoids=34479748926511&itype=0&fr...
  • gdv.a.s####.com/api/2/topic/load?page_size=####&style=####&hot_size=####...
  • gdv.a.s####.com/stat/uvstat?platform=####&uuid=####&client_id=####
  • hm.b####.com/hm.gif?cc=####&cf=####&ck=####&cl=####&ds=####&vl=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.js?53c001d####
  • hm.b####.com/hm.js?5a7a7bf####
  • hm.b####.com/hm.js?a6dafb1####
  • i####.gam####.cn.####.com/2017/11/20/106-1G1201633040-L.jpg
  • i####.gam####.cn.####.com/2017/11/25/106-1G1252131550-L.jpg
  • i####.gam####.cn.####.com/2017/11/25/106-1G1252135380-L.jpg
  • i####.gam####.cn.####.com/2017/12/03/106-1G2031203280-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041452080-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041453190-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041456200-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041504240-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041515410-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P504151G60-L.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P5041523110.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P504160A60.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P504160F70.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P504160H00.jpg
  • i####.gam####.cn.####.com/2018/05/04/106-1P504160Q60.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P504111G80.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041124450.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041132280.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041210420.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041212190.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041213150.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041220300.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041222380.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041224390.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041229430.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P504122F00.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P504122J50.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041231010.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041332570.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041335300.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041343280.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P5041343580.jpg
  • i####.gam####.cn.####.com/2018/05/04/23-1P504134K40.jpg
  • i####.gam####.cn.####.com/2018/05/08/106-1P50QT3340.jpg
  • i####.gam####.cn.####.com/2018/05/09/106-1P5091434200-L.jpg
  • i####.gam####.cn.####.com/2018/05/09/106-1P5091441590-L.jpg
  • i####.gam####.cn.####.com/2018/05/09/106-1P509162P80-L.jpg
  • i####.gam####.cn.####.com/2018/05/09/106-1P5091631150-L.jpg
  • i####.gam####.cn.####.com/2018/05/10/106-1P510164Z10-L.jpg
  • i####.gam####.cn.####.com/2018/05/10/106-1P5101A4390-L.jpg
  • i####.gam####.cn.####.com/2018/05/10/106-1P5101F0110.jpg
  • i####.gam####.cn.####.com/2018/05/11/106-1P5111Q6370-L.jpg
  • i####.gam####.cn.####.com/2018/05/11/106-1P5111R2030-L.jpg
  • i####.gam####.cn.####.com/2018/05/14/106-1P5141I2400-L.jpg
  • mf####.gam####.cn.####.com/2017/12/11/106-1G2111640570.jpg
  • mf####.gam####.cn.####.com/2017/12/12/106-1G2121G6320.jpg
  • mf####.gam####.cn.####.com/2017/12/12/106-1G2121H5220.jpg
  • mf####.gam####.cn.####.com/2017/12/25/106-1G225160A40.jpg
  • mf####.gam####.cn.####.com/2017/12/27/106-1G22G503330.jpg
  • mf####.gam####.cn.####.com/2017/12/27/106-1G22G505590.jpg
  • mf####.gam####.cn.####.com/2018/01/03/106-1P1031219160.jpg
  • mf####.gam####.cn.####.com/2018/01/05/106-1P1051521460.jpg
  • mf####.gam####.cn.####.com/2018/01/05/106-1P1051523140.jpg
  • mf####.gam####.cn.####.com/2018/01/05/106-1P1051526230.jpg
  • mf####.gam####.cn.####.com/2018/01/05/106-1P1051531520.jpg
  • mf####.gam####.cn.####.com/2018/05/09/106-1P5091631230.jpg
  • mf####.gam####.cn.####.com/js/jquery.min.js
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
  • n####.5####.com.cn/net_big.png
  • n####.5####.com.cn/net_small.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/banner_close_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg03.jpg
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg07.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close03.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon....
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon_...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/gdt_logo_black...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-ad.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/sdk_bg.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tc-gdt-sdk-ope...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js/lib/require.js
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • pass####.58.com/mobile/m/init?callback=####
  • pass####.58.com/rsa/ppt_security.js
  • pass####.58.com/rsa?callback=####
  • s####.jom####.com/push.js
  • s####.jom####.com/s.gif?l=/m.58.com/bj/yewu/34269627948235x.shtml?reform...
  • s####.jom####.com/s.gif?l=/m.58.com/bj/yewu/34479748926511x.shtml?reform...
  • s####.jom####.com/static/api/css/share_style0_32.css?v=####
  • s####.jom####.com/static/api/js/base/tangram.js?v=####
  • s####.jom####.com/static/api/js/share.js?v=89860593.js?cdnversion=####
  • s####.jom####.com/static/api/js/share/api_base.js
  • s####.jom####.com/static/api/js/share/share_api.js?v=####
  • s####.jom####.com/static/api/js/trans/logger.js?v=####
  • s####.jom####.com/static/api/js/view/share_view.js?v=####
  • s####.jom####.com/static/api/js/view/view_base.js
  • s####.jom####.com/v.gif
  • s####.tc.qq.com/gdt/0/DAAe8EKABIABIAADBbLbrFDn2g6MKW.png/0?ck=####
  • s####.tc.qq.com/gdt/0/transformer_9087817697001000772_1529519378_80.jpg/...
  • st####.58.com/zhaopin?bp_time=####&sp_time=####&cz_time=####&pagetype=##...
  • trac####.58.com/m/click/empty.js.gif?site_name=####&tag=####&from=####&t...
  • trac####.58.com/m/click/empty.js.gif?site_name=M58&tag=pvsiters&from=fil...
  • trac####.58.com/m/click/empty.js.gif?site_name=M58&tag=pvsiters&from=m-p...
  • trac####.58.com/m/click/empty.js.gif?site_name=M58&tag=pvsiters&from=m_m...
  • trac####.58.com/m/empty.js.gif?site_name=####&tag=####&referrer=####&pos...
  • trac####.58.com/m/empty.js.gif?site_name=M58&tag=pvstatall&referrer=http...
  • trac####.58.com/referrer_m.js
  • v.g####.qq.com/gdt_stats.fcg?viewid=####&i=####&os=####&xp=####&gap=####
  • wap.n.sh####.com/sdk/c.js?appid=####
  • zhusho####.gam####.cn/api/qqdzz/AppVersion.xml
  • zhusho####.gam####.cn/index.php?m=####&a=####&aid=####
  • zhusho####.gam####.cn/index.php?m=####&a=####&id=####&umengchannel=####
  • zhusho####.gam####.cn/index.php?m=####&a=####&page=####&typeid=####&flag...
  • zhusho####.gam####.cn/index.php?m=####&a=####&pageSize=####&page=####&ty...
  • zp.recom####.58.com/api/abtest/?page=####&pagesize=####&platform=####&sh...
  • zp.recom####.58.com/js/58appLaunch.js
HTTP POST requests:
  • a####.u####.com/app_logs
  • ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
  • l####.tbs.qq.com/ajax?c=####&k=####
  • l####.tbs.qq.com/ajax?c=####&v=####&k=####
  • oth.up####.mdt.####.com:8080/beacon/vercheck
  • s####.e.qq.com/activate
  • s####.e.qq.com/click
  • s####.e.qq.com/msg
  • si.hi.shpan####.cn/K/k/g3e
  • si.hi.shpan####.cn/Q/M/n/xa6
  • v.g####.qq.com/gdt_stats.fcg
  • wb.110.ta####.com/api/update.do
  • zhg.ali####.com/saveWb.json
Modified file system:
Creates the following files:
  • /data/data/####/-10813310522058493755
  • /data/data/####/-10813310522058608106
  • /data/data/####/-10813310522058674423
  • /data/data/####/-10813310522058674446
  • /data/data/####/-273320033-2109024155
  • /data/data/####/.imprint
  • /data/data/####/07adc.xml
  • /data/data/####/0a231bd8575dcf72.txt
  • /data/data/####/1003943842-753711954
  • /data/data/####/13766565441768003496
  • /data/data/####/1824952415-1520548306
  • /data/data/####/1d77ea041509fe06.lock
  • /data/data/####/21c22f492aba3de8.lock
  • /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
  • /data/data/####/8ef9c457b3bbb403.lock
  • /data/data/####/930a31b34bd52c08.lock
  • /data/data/####/ACCS_BINDumeng;57047cbbe0f55a54dc00222f.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/BrowserPreference.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/SGMANAGER_DATA2.tmp
  • /data/data/####/TrineaAndroidCommon.xml
  • /data/data/####/UTCommon.xml
  • /data/data/####/WebViewSettings.xml
  • /data/data/####/__Baidu_Stat_SDK_SendRem.xml
  • /data/data/####/__local_ap_info_cache.json
  • /data/data/####/__local_last_session.json
  • /data/data/####/__local_stat_cache.json
  • /data/data/####/__send_data_1529819107510
  • /data/data/####/__send_data_1529819119212
  • /data/data/####/accs.db-journal
  • /data/data/####/agoo.pid
  • /data/data/####/ap.Lock
  • /data/data/####/beacontsa_cover.xml
  • /data/data/####/beacontsa_cover_check.lock
  • /data/data/####/bfffc514b85e4341a6cdae2d5e0d5515.temp
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/channel__local_stat_cache.json
  • /data/data/####/cn.gamedog.spherefightassist_preferences.xml
  • /data/data/####/cn.gamedog.spherefightassistz.jar
  • /data/data/####/core_info
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/debug.conf
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/eudemon
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_suid
  • /data/data/####/index
  • /data/data/####/libcuid.so
  • /data/data/####/libsgmainso-5.1.81.so.tmp
  • /data/data/####/lock.lock
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/register.xml
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/sp.lock
  • /data/data/####/spherefightassist.db-journal
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/trinea_android_common.db-journal
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/ut.db
  • /data/data/####/ut.db-journal
  • /data/data/####/uuid.xml
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/ywPrefsTools.xml
  • /data/media/####/.confd
  • /data/media/####/.confd-journal
  • /data/media/####/.cuid
  • /data/media/####/.cuid2
  • /data/media/####/.nomedia
  • /data/media/####/.timestamp
  • /data/media/####/332ba674bb954fb29f274227ced9b610
  • /data/media/####/6c709c11d2d46a7b
  • /data/media/####/Alvin2.xml
  • /data/media/####/ApplicationCache.db-journal
  • /data/media/####/ContextData.xml
  • /data/media/####/dd7893586a493dc3
  • /data/media/####/deviceToken
  • /data/media/####/edaf155096bd41bcb13ab4d8fb34063d
  • /data/media/####/hid.dat
  • /data/media/####/http___img1_gamedog_cn_2017_11_20_106_1G1201633040_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2017_11_25_106_1G1252131550_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2017_11_25_106_1G1252135380_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2017_12_03_106_1G2031203280_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041452080_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041453190_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041456200_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041504240_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041515410_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P504151G60_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P5041523110_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P504160A60_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P504160F70_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P504160H00_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_106_1P504160Q60_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P504111G80_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041124450_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041132280_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041210420_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041212190_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041213150_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041220300_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041222380_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041224390_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041229430_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P504122F00_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P504122J50_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041231010_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041332570_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041335300_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041343280_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P5041343580_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_04_23_1P504134K40_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_08_106_1P50QT3340_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_09_106_1P5091434200_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_09_106_1P5091441590_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_09_106_1P509162P80_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_09_106_1P5091631150_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_10_106_1P510164Z10_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_10_106_1P5101A4390_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_10_106_1P5101F0110_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_11_106_1P5111Q6370_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_11_106_1P5111R2030_L_jpg
  • /data/media/####/http___img1_gamedog_cn_2018_05_14_106_1P5141I2400_L_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_11_106_1G2111640570_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_12_106_1G2121G6320_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_12_106_1G2121H5220_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_25_106_1G225160A40_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_27_106_1G22G503330_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2017_12_27_106_1G22G505590_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2018_01_03_106_1P1031219160_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2018_01_05_106_1P1051521460_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2018_01_05_106_1P1051523140_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2018_01_05_106_1P1051526230_jpg
  • /data/media/####/http___mimg1_gamedog_cn_2018_01_05_106_1P1051531520_jpg
  • /data/media/####/http_jianli.m.58.com_0.localstorage-journal
  • /data/media/####/http_m.58.com_0.localstorage-journal
Miscellaneous:
Executes next shell scripts:
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:57047cbbe0f55a54dc00222f","utdid":"Wy8v2ue2uQEDAGdzx1Eh3cTs","sdkVersion":"220"} -I agoodm.m.taobao.com -O 80 -T -Z
  • chmod 500 <Package Folder>/files/DaemonServer
  • getprop ro.product.cpu.abi
  • sh
Loads the following dynamic libraries:
  • crash_analysis
  • sgmainso-5.1
  • tnet-3.1
  • ut_c_api
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • DES
  • DESede-ECB-PKCS5Padding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
  • RSA-ECB-PKCS1Padding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about APN settings.
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android