Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Adware.Dowgin.2318

Added to the Dr.Web virus database: 2018-08-26

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Dowgin.14.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) m####.v####.i####.com:80
  • TCP(HTTP/1.1) s8.q####.com:80
  • TCP(HTTP/1.1) s.3####.cn:80
  • TCP(HTTP/1.1) m####.qy.net:80
  • TCP(HTTP/1.1) contr####.i####.com:80
  • TCP(HTTP/1.1) i####.i####.com:80
  • TCP(HTTP/1.1) si.ei.senb####.com:80
  • TCP(HTTP/1.1) c.g####.qq.com:80
  • TCP(HTTP/1.1) t7z.c####.i####.com:80
  • TCP(HTTP/1.1) pa####.i####.com:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(HTTP/1.1) se####.v####.i####.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) msg.vip.i####.com:80
  • TCP(HTTP/1.1) secu####.i####.com:80
  • TCP(HTTP/1.1) v.g####.qq.com:80
  • TCP(HTTP/1.1) c####.v####.i####.com:80
  • TCP(HTTP/1.1) 3####.tc.qq.com:80
  • TCP(HTTP/1.1) subscri####.i####.com:80
  • TCP(HTTP/1.1) b.scoreca####.com.####.net:80
  • TCP(HTTP/1.1) m####.71.am:80
  • TCP(HTTP/1.1) iqiy####.com.edg####.net:80
  • TCP(HTTP/1.1) js.pass####.qih####.com:80
  • TCP(HTTP/1.1) www.51bt####.com:80
  • TCP(HTTP/1.1) d####.v####.i####.com:80
  • TCP(HTTP/1.1) s####.i####.com:80
  • TCP(HTTP/1.1) d.g####.qq.com:80
  • TCP(HTTP/1.1) d####.b####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) pub.m.i####.com:80
  • TCP(HTTP/1.1) api.durianc####.com:80
  • TCP(HTTP/1.1) msg.i####.com:80
  • TCP(HTTP/1.1) a####.i####.com:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(HTTP/1.1) c####.m.i####.com:80
  • TCP(HTTP/1.1) i####.com.edg####.net:80
  • TCP(TLS/1.0) m####.qy.net:443
  • TCP(TLS/1.0) i####.com.edg####.net:443
  • TCP(TLS/1.0) c####.i####.com:443
  • TCP(TLS/1.0) secu####.i####.com:443
  • TCP(TLS/1.0) acti####.m.i####.com:443
  • TCP(TLS/1.0) nl####.i####.com:443
DNS requests:
  • a####.i####.com
  • a####.u####.com
  • acti####.m.i####.com
  • api.durianc####.com
  • b.scoreca####.com
  • c####.i####.com
  • c####.m.i####.com
  • c####.v####.i####.com
  • c.g####.qq.com
  • contr####.i####.com
  • d####.b####.com
  • d####.v####.i####.com
  • d.g####.qq.com
  • dd.m####.com
  • gamest####.i####.com
  • hm.b####.com
  • i####.i####.com
  • imgc####.qq.com
  • js.pass####.qih####.com
  • m####.71.am
  • m####.qy.net
  • m####.v####.i####.com
  • m.i####.com
  • m.iqiy####.com
  • mi.g####.qq.com
  • msg.i####.com
  • msg.vip.i####.com
  • nl####.i####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.ugd####.com
  • pa####.i####.com
  • pp.m####.com
  • pub.m.i####.com
  • qzones####.g####.cn
  • s####.e.qq.com
  • s####.i####.com
  • s.3####.cn
  • s8.q####.com
  • se####.v####.i####.com
  • secu####.i####.com
  • si.ei.senb####.com
  • st####.i####.com
  • subscri####.i####.com
  • t7z.c####.i####.com
  • v.g####.qq.com
  • www.51bt####.com
  • www.iqiy####.com
HTTP GET requests:
  • 3####.tc.qq.com/16891/E4DA20A4851615673022923D1ED30843.apk?fsname=####&_...
  • a####.i####.com/feed/outline?hasRecomFeed=####&feedTypes=####&circleid=#...
  • b.scoreca####.com.####.net/beacon.js
  • c####.m.i####.com/jp/tmts/1266487200/ac407df48f13267ef88c6fc60fc6c4c2/?u...
  • c####.m.i####.com/jp/tmts/1277221600/371b7336aa4cdce4dcbbfd54e63cdbf0/?u...
  • c####.v####.i####.com/jp/collection/502515002/1/?src=####&_=####&callbac...
  • c.g####.qq.com/gdt_mclick.fcg?viewid=####&jtype=####&i=####&os=####&asi=...
  • c.g####.qq.com/gdt_trace_a.fcg?actionid=####&targettype=####&tagetid=###...
  • contr####.i####.com/control/content_config?business=####&is_iqiyi=####&i...
  • d####.b####.com/x.gif?he=[mag####&prot_ver=####&app_id=####&rnd=####&log...
  • d####.b####.com/x.js?si=####&dm=####
  • d####.v####.i####.com/v.mp4?_=####&callback=####
  • d.g####.qq.com/fcg-bin/gdt_appdetail.fcg?ico=####&op_appid=####
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.gif?cc=0&ck=1&cl=16-bit&ds=600x800&vl=899&ep=6659,6659&e...
  • hm.b####.com/hm.js?5df871a####
  • i####.com.edg####.net/
  • i####.com.edg####.net/a_19rrh6y4y5.html
  • i####.com.edg####.net/css/20180710/h5-album-aura.css
  • i####.com.edg####.net/css/20180710/h5-paopao-play-aura.css
  • i####.com.edg####.net/css/20180710/h5-search.css
  • i####.com.edg####.net/css/2018080717/h5-play-aura.css
  • i####.com.edg####.net/css/2018082017/h5-aura.css
  • i####.com.edg####.net/ext/common/auraIcon/iconfont.ttf
  • i####.com.edg####.net/ext/common/auraIcon20180622/iconfont.ttf
  • i####.com.edg####.net/ext/common/iconography2018053117/iconfont.ttf
  • i####.com.edg####.net/js/common/7d183edd03bc4414b315e8964fb41826.js
  • i####.com.edg####.net/js/common/ares4-h5.min.js
  • i####.com.edg####.net/js/html5/js/lib/clipboard.min.js
  • i####.com.edg####.net/js/html5/js/lib/lib.2.0.8.min.js?sea1.2.####
  • i####.com.edg####.net/js/html5/js/lib/qoe.3.0.3.min.js?v=####
  • i####.com.edg####.net/js/html5/js/lib/qoe.min.js?v=####
  • i####.com.edg####.net/js/html5/js/page/home/700366fd25!app.js
  • i####.com.edg####.net/js/html5/js/page/newAlbum/eb23a59b94!app.js
  • i####.com.edg####.net/js/html5/js/page/playLong/14b0effce6!app.js
  • i####.com.edg####.net/js/html5/js/page/playSingle/ea9a52839c!app.js
  • i####.com.edg####.net/js/html5/js/page/search/c097073de2!app.js
  • i####.com.edg####.net/search.html?source=####&vfrm=####&key=####
  • i####.com.edg####.net/v_19rqymd87g.html
  • i####.com.edg####.net/v_19rqzj1ea4.html
  • i####.com.edg####.net/v_19rr1i5o2k.html
  • i####.i####.com/irt?_iwt_t=####&_iwt_id=####&_iwt_UA=####&r=####
  • iqiy####.com.edg####.net/common/20171106/ac/1b/vip_100000_v_601_0_60.png
  • iqiy####.com.edg####.net/common/20180322/b78ffa490af04be394dc908de16f1e3...
  • iqiy####.com.edg####.net/common/20180509/70ea099b771d43189d4cf0d7ffd7a16...
  • iqiy####.com.edg####.net/common/20180509/9c64fce5ad2940d289c84c5586085b0...
  • iqiy####.com.edg####.net/common/20180510/d9bd60258fac424a8aa71068559efeb...
  • iqiy####.com.edg####.net/common/20180528/ac/1b/vip_100004_v_601_0_34.png
  • iqiy####.com.edg####.net/common/20180528/ac/1b/vip_100004_v_601_0_60.png
  • iqiy####.com.edg####.net/common/20180627/reliao_1530091658440.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/album-title-icon.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/channel-icon-20180119.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/foot.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/icon-handMore.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/imgLogo-b.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/imgLogo-s.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/iqiyi-logo.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/menu-more-icon.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/nav-linebg.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/picicon-bg-20180509.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/picicon-s-bg-20171214.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/playPage-icon-20180228.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/player-bg.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/player-default-logo.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/pp-entrance-icon.png
  • iqiy####.com.edg####.net/common/fix/h5-aura/video-pp.png
  • iqiy####.com.edg####.net/common/fix/h5-paopao/paopao-xiaopao.png
  • iqiy####.com.edg####.net/common/fix/h5-v3/am-update-icon.png
  • iqiy####.com.edg####.net/common/fix/h5-v3/guide-new.png
  • iqiy####.com.edg####.net/common/fix/h5-v3/guide-qiyitop.png
  • iqiy####.com.edg####.net/common/fix/h5-v3/horizontal-img-220-124.jpg
  • iqiy####.com.edg####.net/common/fix/h5-v3/iqiyi-logo.png
  • iqiy####.com.edg####.net/common/fix/h5-v3/player-tip-bg.jpg
  • iqiy####.com.edg####.net/common/fix/iqiyi-wechat/logo.jpg
  • iqiy####.com.edg####.net/common/fix/search/play_source-20180614.png
  • iqiy####.com.edg####.net/common/lego/20170915/35d844f8af07412e9980d56cb7...
  • iqiy####.com.edg####.net/common/lego/20170915/3e2d8d029f104eea9261ef9dca...
  • iqiy####.com.edg####.net/common/lego/20170915/5909cbd78fd44f6fa3d9b78dc9...
  • iqiy####.com.edg####.net/common/lego/20170915/7df91c03d5db4113848f7ca1b9...
  • iqiy####.com.edg####.net/common/lego/20170915/bc4532a1bfd64f3c929b6f9200...
  • iqiy####.com.edg####.net/common/lego/20170921/3ba9004a0a1e43939cf4631a5f...
  • iqiy####.com.edg####.net/common/lego/20180201/34b505af4dad4528a87cb15e2e...
  • iqiy####.com.edg####.net/common/lego/20180713/c8b8cad6fc964071b09ea6a33f...
  • iqiy####.com.edg####.net/common/lego/20180719/2f7f7934d11b427b9e86da8b92...
  • iqiy####.com.edg####.net/common/lego/20180817/2461a180b7cf4f759cd7bc3250...
  • iqiy####.com.edg####.net/common/lego/20180821/c7976ce4a2234133b69d9cd5ae...
  • iqiy####.com.edg####.net/common/lego/20180823/7fc50d3ed98a489b8021b42a3b...
  • iqiy####.com.edg####.net/common/lego/20180824/5adff6021622409490306f3295...
  • iqiy####.com.edg####.net/common/lego/20180824/711f410e951a41f6ada68c46dc...
  • iqiy####.com.edg####.net/common/lego/20180825/ad9b526d3b99432fac68adef52...
  • iqiy####.com.edg####.net/common/lego/20180826/13a0806cdbfe4946a7709a9a0c...
  • iqiy####.com.edg####.net/common/lego/20180826/60ad52debd374b3aa6c63ea4e4...
  • iqiy####.com.edg####.net/common/lego/20180826/c7ed1830b8244a408ca5ef0287...
  • iqiy####.com.edg####.net/common/lego/20180826/df1442860f634eb99ce5ee07b4...
  • iqiy####.com.edg####.net/image/20140609/4d/9b/d4/v_106576504_m_601_180_2...
  • iqiy####.com.edg####.net/image/20150811/8c/1a/v_50120712_m_601_m3_180_23...
  • iqiy####.com.edg####.net/image/20150908/08/31/v_109458034_m_601_284_160....
  • iqiy####.com.edg####.net/image/20160104/f2/4c/a_50009273_m_601_m4_180_23...
  • iqiy####.com.edg####.net/image/20160310/44/fa/v_110140482_m_601_284_160....
  • iqiy####.com.edg####.net/image/20160909/25/e1/v_110949636_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20170227/e4/e9/v_111876551_m_601_284_160....
  • iqiy####.com.edg####.net/image/20170301/25/08/v_111890265_m_601_284_160....
  • iqiy####.com.edg####.net/image/20170809/49/9d/v_113067276_m_601_284_160....
  • iqiy####.com.edg####.net/image/20170831/0d/55/a_100059659_m_601_m1_180_2...
  • iqiy####.com.edg####.net/image/20170917/f9/5f/v_110283365_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20171110/e6/7f/v_113910754_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180102/26/5f/v_114472247_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180108/aa/17/v_114535399_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180303/79/0f/v_115072637_m_601_160_90.jpg
  • iqiy####.com.edg####.net/image/20180314/55/22/v_115198663_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180326/21/40/v_115345236_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180510/79/2c/v_115691920_m_601_m3_284_1...
  • iqiy####.com.edg####.net/image/20180529/cc/07/v_116379246_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180626/74/8a/a_100156211_m_601_m2_128_1...
  • iqiy####.com.edg####.net/image/20180712/74/8a/a_100156211_m_601_m3_180_2...
  • iqiy####.com.edg####.net/image/20180712/74/8a/a_100156211_m_601_m3_260_3...
  • iqiy####.com.edg####.net/image/20180712/74/8a/a_100156211_m_601_m3_284_1...
  • iqiy####.com.edg####.net/image/20180712/da/7f/a_100156199_m_601_m3_284_1...
  • iqiy####.com.edg####.net/image/20180724/5f/38/v_117605799_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180726/30/18/v_117646728_m_601_160_90.jpg
  • iqiy####.com.edg####.net/image/20180726/30/18/v_117646728_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180726/63/ff/v_117641601_m_601_180_236....
  • iqiy####.com.edg####.net/image/20180801/92/fd/v_117785769_m_601_m3_284_1...
  • iqiy####.com.edg####.net/image/20180801/94/16/v_117793024_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180801/eb/0c/v_117793112_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180806/3d/60/v_117905750_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180806/5f/72/v_117905827_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180806/83/7e/v_117905590_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180812/12/66/v_118054939_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180812/61/aa/v_118054905_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180812/75/4b/v_118054877_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180821/42/29/v_118299726_m_601_284_160....
  • iqiy####.com.edg####.net/image/20180821/90/e4/v_118299642_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180821/94/27/v_118299773_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180821/94/27/v_118299773_m_601_m1_480_2...
  • iqiy####.com.edg####.net/image/20180821/ee/5b/v_118299696_m_601_m1_284_1...
  • iqiy####.com.edg####.net/image/20180824/bf/39/v_118395356_m_601_160_90.jpg
  • iqiy####.com.edg####.net/image/20180825/42/26/v_118407734_m_601_480_270....
  • iqiy####.com.edg####.net/image/20180825/e1/95/v_118418465_m_601_160_90.jpg
  • iqiy####.com.edg####.net/u1/image/20180813/f4/b5/uv_3083466364_m_601_160...
  • iqiy####.com.edg####.net/u2/image/20180702/9e/c9/uv_3081131355_m_601_160...
  • iqiy####.com.edg####.net/u2/image/20180716/ca/87/uv_3081854753_m_601_160...
  • iqiy####.com.edg####.net/u3/image/20180723/0f/00/huv_626935578_m_601_160...
  • iqiy####.com.edg####.net/u3/image/20180801/d8/3d/uv_20024820801_m_601_48...
  • iqiy####.com.edg####.net/u3/image/20180821/c7/35/uv_3083970146_m_601_160...
  • iqiy####.com.edg####.net/u5/image/20180806/d7/e4/uv_20025426839_m_601_48...
  • iqiy####.com.edg####.net/u5/image/20180822/0a/2c/uv_3084013468_m_601_160...
  • iqiy####.com.edg####.net/u8/image/20180806/d9/d4/uv_20025425682_m_601_48...
  • iqiy####.com.edg####.net/u8/image/20180813/61/ce/uv_3083443597_m_601_160...
  • iqiy####.com.edg####.net/u8/image/20180820/78/f7/uv_628590420_m_601_160_...
  • iqiy####.com.edg####.net/u8/image/20180825/0e/f4/uv_3084196285_m_601_160...
  • js.pass####.qih####.com/11.0.1.js?3c7bafe####
  • m####.71.am/v5/alt/act?bstp=####&p1=####&p2=####&u=####&pu=####&rn=####&...
  • m####.qy.net/b?t=####&bstp=####&pf=####&p=####&p1=####&u=####&pu=####&bl...
  • m####.qy.net/b?t=####&pf=####&p=####&p1=####&u=####&pu=####&jsuid=####&c...
  • m####.qy.net/cp2.gif?p=####&rd=####&rc=####&t=####&e=####&y=####&u=####&...
  • m####.qy.net/cp2.gif?p=####&t=####&lc=####&e=####&y=####&u=####&av=####&...
  • m####.qy.net/cp2.gif?p=####&t=####&lc=http####&e=####&y=####&u=####&av=#...
  • m####.qy.net/cp2.gif?p=####&t=####&oi=####&ri=####&di=####&e=####&y=####...
  • m####.qy.net/cp2.gif?p=####&t=####&rc=####&rd=####&ai=####&e=####&y=####...
  • m####.qy.net/jpb.gif?rdm=####&qtcurl=####&rfr=####&flshuid=####&lrfr=###...
  • m####.qy.net/tmpstats.gif?type=####&des=####&mse=####&p2p=####&p=####
  • m####.qy.net/vodpb.gif?rec=####&mse=####&url=####&fetch=####&rtc=####&ws...
  • m####.v####.i####.com/jp/mixin/albums/227148001/songs?_=####&callback=####
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
  • msg.i####.com/b?t=####&bstp=####&pf=####&p=####&p1=####&u=####&pu=####&b...
  • msg.i####.com/jpb.gif?rdm=890670351&qtcurl=http://m.iqiyi.com/search.htm...
  • msg.vip.i####.com/qya.gif?qy_n=####&qy_cid=####&qy_fcode=####&qy_platfor...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/banner_close_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg03.jpg
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg07.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close03.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon....
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon_...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/gdt_logo_black...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-ad.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-close.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/inter_close_lo...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/popup_ad_car_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/score.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/sdk_bg.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tc-gdt-sdk-ope...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/i...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js/lib/require.js
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • pa####.i####.com/apis/e/paopao/list.action?authcookie=####&m_device_id=#...
  • pa####.i####.com/apis/e/starwall/basic_wall.action?wallId=####&qypid=###...
  • pub.m.i####.com/jp/h5/search/fragment/22508438309/?_=####&callback=####
  • s####.i####.com/apis/app/infoList.action?agent_type=####&app_ids=####&_=...
  • s####.tc.qq.com/gdt/0/DAAHU5BAKAAPAAAqBbbTM3CfI0Avn2.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAOTgCABIABIAAFBaf7_rCIofucTF.png/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAT9y4ABIABIAADBa6-tqDJ25h2cF.png/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAfs2xABIABIAAEBbctDnCUt-4Fxl.png/0?ck=####
  • s####.tc.qq.com/gdt/0/transformer_14189501191749432915_1534267516_114.jp...
  • s####.tc.qq.com/gdt/0/transformer_7965249044853711888_1534930358_114.jpg...
  • s####.tc.qq.com/ma_icon/0/icon_42256978_1535006097/256
  • s.3####.cn/so/zz.gif?url=http://m.iqiyi.com/search.html?source=####&vfrm...
  • s8.q####.com/static/ab77b6ea7f3fbf79.js
  • se####.v####.i####.com/m?if=####&key=####
  • se####.v####.i####.com/o?channel_name=####&if=####&pageNum=####&pageSize...
  • secu####.i####.com/api/getNewAdInfo?pageName=####&appNum=####&key=####&v...
  • secu####.i####.com/jp/h5/albums/227148001?callback=####
  • secu####.i####.com/jp/h5/count/play/227148001?_=####&callback=####
  • secu####.i####.com/jp/h5/play/fragment/1277221600/?albumId=####&_=####&c...
  • secu####.i####.com/jp/h5/recommend/videos/?area=####&size=####&type=####...
  • secu####.i####.com/jp/h5/recommend/videos/?page=####&size=####&area=####...
  • subscri####.i####.com/dingyue/api/isSubscribed.action?agent_type=####&su...
  • t7z.c####.i####.com/show2?e=####&h=####&a=####&u=####&p=####&s=####&_=##...
  • t7z.c####.i####.com/show2?e=AF48R####&h=####&a=####&u=####&p=####&s=####...
  • t7z.c####.i####.com/track2?w=####&dts=####&nr=####&c=####&f=####&g=####&...
  • v.g####.qq.com/gdt_stats.fcg?viewid=####&i=####&os=####&xp=####&gap=####
HTTP POST requests:
  • a####.u####.com/app_logs
  • api.durianc####.com/video/v1/config.jsp
  • api.durianc####.com/video/v1/info.jsp
  • s####.e.qq.com/activate
  • s####.e.qq.com/click
  • s####.e.qq.com/msg
  • si.ei.senb####.com/Tw/yr/c9dbk
  • si.ei.senb####.com/qs/55c9l
  • v.g####.qq.com/gdt_stats.fcg
  • www.51bt####.com/apps/client/GetAppData8.php
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/4ead3051adab16aa5f527f7033d51b99.temp
  • /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
  • /data/data/####/Alvin2.xml
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/WebViewSettings.xml
  • /data/data/####/_i59620850.xml
  • /data/data/####/_w59620850.xml
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/com.uinixeea.jar
  • /data/data/####/com.yujinwe.az.jar
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_suid
  • /data/data/####/index
  • /data/data/####/mscom.xhxm.media.e.xml
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/zb55c9db5.xml
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/com.ss.android.ugc.live.apk_0
  • /data/media/####/e7a9e238f80771c4104c02205d35639a
  • /data/media/####/xhxm
Miscellaneous:
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
  • RSA-ECB-PKCS1Padding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android