Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5227
- 7j####.c####.z0.####.com
- a.appj####.com
- c####.g####.ig####.com
- c-h####.g####.com
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sn.bool####.cn
- t####.c####.q####.####.com/tdata_SzD730
- t####.c####.q####.####.com/tdata_ZCi456
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a.appj####.com/ad-service/ad/mark
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/H55B702CC.xml
- /data/data/####/clientid_igexin.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/gdaemon_20161017
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/libjiagu.so
- /data/data/####/pdr.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tdata_SzD730
- /data/data/####/tdata_SzD730.jar
- /data/data/####/tdata_ZCi456
- /data/data/####/tdata_ZCi456.jar
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/60.gif
- /data/media/####/aboutme.html
- /data/media/####/app.css
- /data/media/####/app.db
- /data/media/####/arrow.png
- /data/media/####/bg-fgps.png
- /data/media/####/bg_mc_0113_1.png
- /data/media/####/bg_mc_0113_2.png
- /data/media/####/bg_mc_0113_3.png
- /data/media/####/bg_mc_0113_4.png
- /data/media/####/binaryajax.js
- /data/media/####/buy-car-con.html
- /data/media/####/buy-car.html
- /data/media/####/buy-house-cont.html
- /data/media/####/buy-house.html
- /data/media/####/buy.html
- /data/media/####/buy.png
- /data/media/####/canvasResize.js
- /data/media/####/car-rent-fabu.html
- /data/media/####/car-rent-info.html
- /data/media/####/car-rent-myinfo.html
- /data/media/####/car-rent.html
- /data/media/####/change-head.html
- /data/media/####/change-info-2.html
- /data/media/####/change-info-3.html
- /data/media/####/change-info.html
- /data/media/####/change-more.html
- /data/media/####/change-pw.html
- /data/media/####/change.html
- /data/media/####/chat-sub.html
- /data/media/####/chat.html
- /data/media/####/cityLayout.css
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/common.js
- /data/media/####/dk-hk.png
- /data/media/####/dk-no.png
- /data/media/####/dk-sq.png
- /data/media/####/exchange-fabu.html
- /data/media/####/exchange-info.html
- /data/media/####/exchange-myinfo.html
- /data/media/####/exchange-resu.html
- /data/media/####/exchange.html
- /data/media/####/exif.js
- /data/media/####/feedback-page.css
- /data/media/####/feedback.css
- /data/media/####/fg-pw-1.html
- /data/media/####/fg-pw-2.html
- /data/media/####/fg-pw-3.html
- /data/media/####/file__0.localstorage-journal
- /data/media/####/font-awesome.min.css
- /data/media/####/fontawesome-webfont.ttf
- /data/media/####/gf-ban.png
- /data/media/####/gf-bg.png
- /data/media/####/ggl.png
- /data/media/####/gift.html
- /data/media/####/guanggao.html
- /data/media/####/iconfont-index.ttf
- /data/media/####/iconfont-tianjia.png
- /data/media/####/iconfont.css
- /data/media/####/iconfont.ttf
- /data/media/####/iconfont3.css
- /data/media/####/iconfont3.ttf
- /data/media/####/iconfontIndex.css
- /data/media/####/iconfontdp.ttf
- /data/media/####/iconfontinfo.css
- /data/media/####/iconfontinfo.ttf
- /data/media/####/iconfontpo.ttf
- /data/media/####/iconfontpoto.css
- /data/media/####/icons-extra.css
- /data/media/####/in-fh.png
- /data/media/####/in-jf.png
- /data/media/####/in-md.png
- /data/media/####/in-sy.png
- /data/media/####/in-zx.png
- /data/media/####/index.html
- /data/media/####/info-base.png
- /data/media/####/info-sf.png
- /data/media/####/info-xg.png
- /data/media/####/io.dcloud.H512AB145.db
- /data/media/####/ip5.png
- /data/media/####/ip6.png
- /data/media/####/izz.png
- /data/media/####/jquery-1.8.3.min.js
- /data/media/####/list-1.html
- /data/media/####/list-buy.png
- /data/media/####/list-fh.html
- /data/media/####/list-kd.png
- /data/media/####/list-sell.png
- /data/media/####/list-yq.png
- /data/media/####/list-zx.html
- /data/media/####/log-1.png
- /data/media/####/login.html
- /data/media/####/login.png
- /data/media/####/logo.png
- /data/media/####/lv1.png
- /data/media/####/lv2.png
- /data/media/####/lv3.png
- /data/media/####/manifest.json
- /data/media/####/meeting-cont.html
- /data/media/####/mui-icons-extra.ttf
- /data/media/####/mui.dtpicker.css
- /data/media/####/mui.dtpicker.js
- /data/media/####/mui.min.css
- /data/media/####/mui.min.js
- /data/media/####/mui.picker.min.css
- /data/media/####/mui.picker.min.js
- /data/media/####/mui.previewimage.js
- /data/media/####/mui.ttf
- /data/media/####/mui.zoom.js
- /data/media/####/my-buy.png
- /data/media/####/my-dk.png
- /data/media/####/my-hk.png
- /data/media/####/my-info.png
- /data/media/####/my-jf-item-car.html
- /data/media/####/my-jf-item-house.html
- /data/media/####/my-jf-item.html
- /data/media/####/my-jf-kj.html
- /data/media/####/my-jf-shejiao.html
- /data/media/####/my-jf-sj-con.html
- /data/media/####/my-jf-sj.html
- /data/media/####/my-jf.html
- /data/media/####/my-sell.html
- /data/media/####/my-sj.png
- /data/media/####/my-zh.png
- /data/media/####/my-zj.png
- /data/media/####/my-zl.html
- /data/media/####/my-zl.png
- /data/media/####/myjs.js
- /data/media/####/news.html
- /data/media/####/pay.png
- /data/media/####/public.js
- /data/media/####/queryAllAreas.js
- /data/media/####/queryAllProvinces.js
- /data/media/####/queryCities.js
- /data/media/####/reg.html
- /data/media/####/sell-car-place.html
- /data/media/####/sell-car.html
- /data/media/####/sell-house.html
- /data/media/####/sell.html
- /data/media/####/sell.png
- /data/media/####/shop-info.html
- /data/media/####/shop.html
- /data/media/####/spend-1-1.html
- /data/media/####/spend-1-2.html
- /data/media/####/spend-1-3.html
- /data/media/####/spend-1-4.html
- /data/media/####/spend-1.html
- /data/media/####/spend-2.html
- /data/media/####/tdata_SzD730
- /data/media/####/tdata_ZCi456
- /data/media/####/test.log
- /data/media/####/up-poto.html
- /data/media/####/up-vip-img.html
- /data/media/####/up-vip.html
- /data/media/####/upcard.html
- /data/media/####/utitls.js
- /data/media/####/vip-bgem.html
- /data/media/####/vip-black.html
- /data/media/####/vip-gem.html
- /data/media/####/vip-super.html
- /data/media/####/vip-up.html
- /data/media/####/vip-white.html
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24452 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- mount
- getuiext2
- libjiagu
- RSA-NONE-OAEPWithSHA1AndMGF1Padding