Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) app.z####.com.cn:80
- TCP(HTTP/1.1) phon####.x####.d####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) h####.opensp####.cn:80
- TCP(HTTP/1.1) 1####.55.144.200:80
- TCP(HTTP/1.1) 1####.78.36.36:8995
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) d####.opensp####.cn:80
- TCP c####.g####.ig####.com:5224
- TCP sdk.o####.t####.####.com:5224
- 7j####.c####.z0.####.com
- app.z####.com.cn
- c####.g####.ig####.com
- c-h####.g####.com
- d####.opensp####.cn
- h####.opensp####.cn
- phon####.x####.d####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- app.z####.com.cn/pic/201801/14/t2_(0X7X586X337)f41a5626-ced1-4343-bbed-d...
- app.z####.com.cn/pic/201810/29/33a34ba2-90ba-444e-a7e5-20751300fc02.jpg
- app.z####.com.cn/pic/201811/07/t1_(0X0X594X339)ae990bb8-7804-420c-87ea-6...
- app.z####.com.cn/pic/201811/09/c2b3d62c-f609-4636-8f0e-772529795361.jpg
- app.z####.com.cn/pic/201811/12/t1_(0X2X200X116)d4896d9d-c979-43f8-944a-a...
- app.z####.com.cn/pic/201811/13/t2_(0X0X600X338)ed768f6e-cb48-4d55-915b-4...
- app.z####.com.cn/pic/201811/13/t2_(0X2X400X227)d0fdd10b-c16b-4284-836f-7...
- app.z####.com.cn/pic/201811/14/t2_(14X21X576X337)efacd333-4a06-47d6-bfb3...
- app.z####.com.cn/pic/201811/14/t2_(18X35X600X362)52004df3-caa8-47f0-a661...
- app.z####.com.cn/pic/201811/16/t1_(20X26X500X300)b2af3ca5-862a-407e-87d6...
- app.z####.com.cn/pic/201811/16/t1_(41X36X600X355)7221a462-5ee3-4009-be57...
- app.z####.com.cn/pic/201811/21/t1_(9X10X400X233)0ea52e93-18bf-4003-836f-...
- app.z####.com.cn/pic/201811/22/t1_(1X193X395X418)1b4b1776-9674-47e7-8463...
- app.z####.com.cn/pic/201811/22/t1_(2X12X200X125)c2ccb99c-2a36-42a1-bc48-...
- app.z####.com.cn/pic/201811/26/64b873b7-987b-444d-9936-1ce4f52bff30.jpg
- app.z####.com.cn/pic/201811/26/9dc3814b-05b1-425c-b761-aebad4a35e07.jpg
- app.z####.com.cn/pic/201811/26/c5556189-03e6-4a97-8147-828d2aafe658.jpg
- app.z####.com.cn/pic/201811/26/d8ae560b-e43c-425e-b6c7-a5f79ec1c532.jpg
- app.z####.com.cn/pic/201811/26/t1_(11X9X600X345)c7a20c22-f651-4d6c-b5fd-...
- app.z####.com.cn/pic/201811/26/t1_(1X2X457X262)2836278e-7935-4363-baea-e...
- app.z####.com.cn/pic/201811/26/t1_(26X40X278X184)9ecd8c8b-4f76-409e-8f42...
- app.z####.com.cn/pic/201811/28/b8ec90b2-9d1b-4229-af00-031a69e95961.jpg
- app.z####.com.cn/pic/201811/28/t1_(0X5X336X197)7583466d-97d7-4d60-b089-c...
- app.z####.com.cn/pic/201811/28/t1_(18X0X516X284)d268265b-04a8-4cb3-8a83-...
- app.z####.com.cn/pic/201811/28/t1_(1X0X300X171)b0ec72d7-d288-462d-81b8-e...
- app.z####.com.cn/pic/201811/28/t1_(33X0X504X269)e5bcf7ca-07a9-49d7-8fbc-...
- app.z####.com.cn/template/0172e396-1763-4286-ae13-79f34e28cfb7.jpg
- app.z####.com.cn/template/163cc554-c787-4e60-9751-dad765f7fcf6.zip
- h####.opensp####.cn/launchconfig?t=####&p=ZWV6Z####
- phon####.x####.d####.com/weather/getWeatherByAreaID?areaId=####
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_vxj811
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- c-h####.g####.com/api.php?format=####&t=####
- d####.opensp####.cn/index.php/clientrequest/clientcollect/isCollect
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/-1034821270
- /data/data/####/-1118183991
- /data/data/####/-1328401133
- /data/data/####/.jg.ic
- /data/data/####/086ca1532ccab8c9aec9faa09d936f730d4a3e3b050b894....0.tmp
- /data/data/####/0ac6b35a972c083b6ba4c84c443e08a546bcc4172776407....0.tmp
- /data/data/####/0d6039610b9d51252bc4c0b46fb173f72d17e22630f7e4d....0.tmp
- /data/data/####/1100459639
- /data/data/####/11f9a87ad9be1207d7f6f16ab7c104428f5c137701b5d06....0.tmp
- /data/data/####/1389023919
- /data/data/####/13af76e3cf9f53169a3563258bf8f7650c36e8b0f3ac7db....0.tmp
- /data/data/####/1509597072
- /data/data/####/1695857311
- /data/data/####/1852455375
- /data/data/####/2126955433
- /data/data/####/28ad4c48c9702953efb58f301b098ef009cf0182eae6f61....0.tmp
- /data/data/####/28c0b4eb6546fddcf7697fd6a66ee52782153fb2db659e2....0.tmp
- /data/data/####/315999b0d0e400aa6308d2440620c4283cde0035d3a7a80....0.tmp
- /data/data/####/3201d2923b0ff2669c74fd3b1734cb610a5f1a5f50affa0....0.tmp
- /data/data/####/357dd834d1e2768492b1963abe1be94688f7ec0d1c38ff7....0.tmp
- /data/data/####/386967948
- /data/data/####/43e4a1da1212d508267066f5610f2d2675f6d47234025a2....0.tmp
- /data/data/####/4f300a83fd517b9421141f9143a345f8ce02fc84646ab08....0.tmp
- /data/data/####/5cd8c14c333542ce5b335e5e8a0885f6139a66a6e7184b7....0.tmp
- /data/data/####/648dc372ddc03bbd691d271d5e617a2a89d0cad0d23d3c2....0.tmp
- /data/data/####/65ac77d957a672391d8be6f9f321846664972d33fb189d5....0.tmp
- /data/data/####/6ab1e9ef55b57fb311645b05b5baa635a4c805ef6c4379e....0.tmp
- /data/data/####/74fa483533819225fce25f646aa3fcda61ae21fefbca747....0.tmp
- /data/data/####/75ea314156df6de2542f6bd8fce3ad6b67077fc0f3e3b4a....0.tmp
- /data/data/####/79108a14b84bc0084c59ed1cd1aedab2b8f428f1579250a....0.tmp
- /data/data/####/848a966e37ea477da9f34fcd873accb0f0de2cd8a13ed17....0.tmp
- /data/data/####/860ca66759b6ead30c9e55e7a9956793b7b16e7c9298381....0.tmp
- /data/data/####/87f83f33d78088024e31144bfb72f3aeceb6e4697efe679....0.tmp
- /data/data/####/9226a3c3662bbf8bedd479eb063b6c18a30926ad169e829....0.tmp
- /data/data/####/979760830
- /data/data/####/FZLTXHK-GBK_YS.ttf
- /data/data/####/a06db90ddc1fcb0a52161550ac8403be6920b534ad655db....0.tmp
- /data/data/####/a0b89a47e1801b80c92c08884a60468d53c09041abec994....0.tmp
- /data/data/####/a1e95ed5c9846d946b65adef007805cfb76666117372796....0.tmp
- /data/data/####/a91ac52e03391545072461c85cf31e4e2f6e27855d768a8....0.tmp
- /data/data/####/aa635174810315bc06c293d4d9a91b6a177b7018f767020....0.tmp
- /data/data/####/articleJson.js
- /data/data/####/articlejson.js
- /data/data/####/attId_128_newsId_92596_articleJson.js
- /data/data/####/b047a7b103932fbbe1e65be70c001c279d6960b5205a4e1....0.tmp
- /data/data/####/b8338817155485ce9ef6592034d7df90127e19d2edeb4b9....0.tmp
- /data/data/####/bg_addfollow.png
- /data/data/####/bg_delfollow.png
- /data/data/####/btn-addAttention.png
- /data/data/####/btn-hadAttention.png
- /data/data/####/c5deda15a1653078cdc62871a493ac82e1fd81af1c9eadc....0.tmp
- /data/data/####/columnId.xml
- /data/data/####/com.iflytek.id.xml
- /data/data/####/com.iflytek.msc.xml
- /data/data/####/content_template.html
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/db_founder26002
- /data/data/####/db_founder26002-journal
- /data/data/####/defaultImg.png
- /data/data/####/e403572c0cdb09cd88916535ee13e1cf9859fc58ab6c218....0.tmp
- /data/data/####/e7306dde584ed6f597525c7abb1bb45a2b36fc03a7cb680....0.tmp
- /data/data/####/ender.js
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/fd001cb21bdfa130ec1f83422e04828f83db70b0576c414....0.tmp
- /data/data/####/ff645f657766e4a9afac69b09efd54570c92a4471b4d947....0.tmp
- /data/data/####/fileMapping.js
- /data/data/####/font.css
- /data/data/####/font.css.bak
- /data/data/####/fontSytleMsg.xml
- /data/data/####/fonty.css.bak
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/helpMsg.xml
- /data/data/####/icon-relative.png
- /data/data/####/icon-southReporter.png
- /data/data/####/ifly_launch_lib.xml
- /data/data/####/iflytek_state_com.petroleumnews.breeze.xml
- /data/data/####/index
- /data/data/####/index.jsp
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/journal.tmp
- /data/data/####/jquery-1.6.4.min.js
- /data/data/####/jquery.lazyload.min.js
- /data/data/####/left.png
- /data/data/####/libjiagu.so
- /data/data/####/mobclick_agent_cached_com.petroleumnews.breeze
- /data/data/####/mobclick_agent_header_com.petroleumnews.breeze.xml
- /data/data/####/mobclick_agent_state_com.petroleumnews.breeze.xml
- /data/data/####/multidex.version.xml
- /data/data/####/playBtn.png
- /data/data/####/portrait.jpg
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/reader.db-journal
- /data/data/####/reader.png
- /data/data/####/right.png
- /data/data/####/run.pid
- /data/data/####/save_device_send_time.xml
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_vxj811
- /data/data/####/tdata_vxj811.jar
- /data/data/####/video.png
- /data/data/####/weatherSp.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.petroleumnews.breeze.bin
- /data/media/####/com.petroleumnews.breeze.db
- /data/media/####/iflyworkdir_test
- /data/media/####/localTemplate.zip
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_vxj811
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.MyGetuiService 25482 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- RSSupportIO
- getuiext2
- libjiagu
- librsjni
- msc
- AES-CBC-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding