Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Adware.Dowgin.2309

Добавлен в вирусную базу Dr.Web: 2018-08-26

Описание добавлено:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Dowgin.14.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) c####.baidust####.com:80
  • TCP(HTTP/1.1) ws####.qq.com:80
  • TCP(HTTP/1.1) h5.7####.com:80
  • TCP(HTTP/1.1) www.7####.com:80
  • TCP(HTTP/1.1) c.g####.qq.com:80
  • TCP(HTTP/1.1) p.7k7####.cn.####.com:80
  • TCP(HTTP/1.1) gdv.a.s####.com:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) c.c####.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) v.g####.qq.com:80
  • TCP(HTTP/1.1) q.c####.com:80
  • TCP(HTTP/1.1) h.7####.com.####.com:80
  • TCP(HTTP/1.1) 7####.7####.cn:80
  • TCP(HTTP/1.1) www.51bt####.com:80
  • TCP(HTTP/1.1) d.g####.qq.com:80
  • TCP(HTTP/1.1) 3####.tc.qq.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) api.durianc####.com:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(HTTP/1.1) gs.a.s####.com:80
  • TCP(HTTP/1.1) si.ei.senb####.com:80
  • TCP(TLS/1.0) h####.b####.com.####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
DNS requests:
  • a####.u####.com
  • api.durianc####.com
  • c####.baidust####.com
  • c.c####.com
  • c.g####.qq.com
  • chan####.itc.cn
  • chan####.s####.com
  • d.g####.qq.com
  • dd.m####.com
  • h####.b####.com
  • h.7####.com
  • h.7k7####.cn
  • h5.7####.com
  • hm.b####.com
  • i5.7k7####.cn
  • imgc####.qq.com
  • mi.g####.qq.com
  • p####.ugd####.com
  • p1.7k7####.cn
  • p2.7k7####.cn
  • p3.7k7####.cn
  • p4.7k7####.cn
  • p5.7k7####.cn
  • pos.b####.com
  • pp.m####.com
  • q14.c####.com
  • qzones####.g####.cn
  • s####.e.qq.com
  • si.ei.senb####.com
  • v.g####.qq.com
  • w.c####.com
  • ws####.qq.com
  • www.51bt####.com
  • www.7####.com
  • www.7k####.cn
HTTP GET requests:
  • 3####.tc.qq.com/16891/E4DA20A4851615673022923D1ED30843.apk?fsname=####&_...
  • 7####.7####.cn/wapH5/common/library/flux/2.1.1/flux.js
  • 7####.7####.cn/wapH5/common/library/keyMirror/0.1.1/key-mirror.js
  • 7####.7####.cn/wapH5/common/library/seajs/sea.2.2.0.min.js
  • 7####.7####.cn/wapH5/common/library/seajs/seajs-config.js
  • 7####.7####.cn/wapH5/common/library/zepto/zepto.1.1.2.min.js
  • 7####.7####.cn/wapH5/common/module/css/img/b.png
  • 7####.7####.cn/wapH5/common/module/css/module.css
  • 7####.7####.cn/wapH5/common/module/css/module.css?2015####
  • 7####.7####.cn/wapH5/common/module/js/ad-close.min.js
  • 7####.7####.cn/wapH5/common/module/js/back-top.min.js
  • 7####.7####.cn/wapH5/common/module/js/com.min.js
  • 7####.7####.cn/wapH5/common/module/js/crypter.min.js
  • 7####.7####.cn/wapH5/common/module/js/if.min.js
  • 7####.7####.cn/wapH5/common/module/js/played-game/action.min.js
  • 7####.7####.cn/wapH5/common/module/js/played-game/constants.min.js
  • 7####.7####.cn/wapH5/common/module/js/played-game/dispatcher.min.js
  • 7####.7####.cn/wapH5/common/module/js/played-game/local.min.js
  • 7####.7####.cn/wapH5/common/module/js/played-game/store.min.js
  • 7####.7####.cn/wapH5/common/module/js/polyfill.min.js
  • 7####.7####.cn/wapH5/common/module/js/queue.min.js
  • 7####.7####.cn/wapH5/common/module/js/scrollLoading.min.js
  • 7####.7####.cn/wapH5/common/plug/detect.js
  • 7####.7####.cn/wapH5/index/css/index.css
  • 7####.7####.cn/wapH5/index/js/index.min.js?v180####
  • 7####.7####.cn/wapH5/list/css/hot.css
  • 7####.7####.cn/wapH5/list/js/hot.min.js
  • 7####.7####.cn/wapH5/trans/css/trans.css
  • 7####.7####.cn/wapH5/trans/js/trans.min.js?v180####
  • c####.baidust####.com/cpro/ui/cm.js
  • c.c####.com/c.php?id=####
  • c.c####.com/core.php?web_id=####&t=####
  • c.g####.qq.com/gdt_mclick.fcg?viewid=####&jtype=####&i=####&os=####&asi=...
  • c.g####.qq.com/gdt_trace_a.fcg?actionid=####&targettype=####&tagetid=###...
  • d.g####.qq.com/fcg-bin/gdt_appdetail.fcg?ico=####&op_appid=####
  • gdv.a.s####.com/api/2/config/get/cyqHvdkcp?callback=####
  • gdv.a.s####.com/api/2/topic/load?client_id=####&topic_url=####&topic_tit...
  • gdv.a.s####.com/api/2/user/info?client_id=####&_=####&callback=####
  • gdv.a.s####.com/debug/cookie?callback=####
  • gdv.a.s####.com/debug/cookie?setCook####&callback=####&Sun Aug####
  • gdv.a.s####.com/upload/mobile/wap-js/changyan_mobile.js?client_id=####&c...
  • gdv.a.s####.com/upload/version-v3.js?1535274####
  • gs.a.s####.com/upload/mobile/v1/wap-css/wap-changyan2.css?version=####
  • gs.a.s####.com/upload/mobile/v1/wap-css/wap-scs/wap-default.css?version=...
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face01.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face02.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face03.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face04.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face05.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face06.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face07.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face08.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face09.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face10.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face11.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face12.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face13.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face14.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face15.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face16.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face17.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face18.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face19.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face20.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face21.png
  • gs.a.s####.com/upload/mobile/v1/wap-imgs/face/face22.png
  • gs.a.s####.com/upload/mobile/v1/wap-js/src/init-build.js?undef####
  • gs.a.s####.com/upload/mobile/v1/wap-js/src/widget/colorful-eggs/colorful...
  • gs.a.s####.com/v3/v20180824934/src/adapter.min.js
  • h.7####.com.####.com/
  • h.7####.com.####.com/games/23530
  • h.7####.com.####.com/games/23533
  • h.7####.com.####.com/games/23538
  • h.7####.com.####.com/hot
  • h5.7####.com/
  • h5.7####.com/api/guess?uid=####&page=####&callback=####
  • h5.7####.com/api/iscps?client=####&uid=####&callback=####
  • h5.7####.com/api/rank?type=####&page=####&callback=####
  • h5.7####.com/api/specialinfo?id=####&callback=####
  • h5.7####.com/dateall.json
  • h5.7####.com/static/css/app.89f5eaa6.css
  • h5.7####.com/static/fonts/iconfont.6f71b584.ttf
  • h5.7####.com/static/img/foot1.571d26f1.png
  • h5.7####.com/static/img/foot2.c6e569ba.png
  • h5.7####.com/static/img/foot3.8a093827.png
  • h5.7####.com/static/img/foot4.2dc68368.png
  • h5.7####.com/static/img/head1.7286cf9e.png
  • h5.7####.com/static/img/head2.91e114ed.png
  • h5.7####.com/static/img/head3.a9019359.png
  • h5.7####.com/static/img/logo.39615b8b.png
  • h5.7####.com/static/img/new-foot-bg.25dc5261.jpg
  • h5.7####.com/static/img/new-guess-bg.d4f7e3fc.jpg
  • h5.7####.com/static/img/qrcode.0d2d2178.jpg
  • h5.7####.com/static/img/userbg.795d7e71.png
  • h5.7####.com/static/js/28.32a0da4e.js
  • h5.7####.com/static/js/29.39f71f24.js
  • h5.7####.com/static/js/app.62df7ee9.js
  • h5.7####.com/static/js/manifest.f72bb937.js
  • h5.7####.com/static/js/vendor.803333f9.js
  • hm.b####.com/h.js?a72a91b####
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/banner.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/banner_close_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg03.jpg
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/bannerbg07.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close02.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/close03.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon....
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/download_icon_...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/gdt_logo_black...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-ad.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-close.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/inter_close_lo...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/popup_ad_car_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/score.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/sdk_bg.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tc-gdt-sdk-ope...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/i...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js/lib/require.js
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • p.7k7####.cn.####.com/cms/cms10/20180306/141704_6363.jpg
  • p.7k7####.cn.####.com/html5app/201408/1913/10-140Q913055B25_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201412/0513/19-14120513541T95_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201412/2313/18-141223134446418_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201412/2616/8-141226163440131_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201501/2011/19-150120114135946_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201501/2113/18-15012113545CB_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201501/2211/19-150122115215c9_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201501/2412/19-150124121430335_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201504/2415/19-150424150416342_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201507/2411/8-150H411310O03_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201507/2814/19-150HQ44PY34_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201507/3115/31-150I1152Q3425_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201508/2115/28-150R1151524V2_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201603/3116/31-16033116233M42_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201607/0116/31-160F1163934R7_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201706/1918/28-1F6191P02V45_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201710/2014/28-1G02014230c55_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201711/1309/28-1G113092039145_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201711/2409/28-1G1240956461Q_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/0110/28-1G201102GbG_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/0210/28-1G20210393OL_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1119/3-1G211191641457_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1119/3-1G211192000320_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1210/28-1G212105053449_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1310/28-1G21310325Q24_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1614/28-1G2161456412O_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1810/28-1G21Q04403309_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1818/3-1G21QRS25c_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/1915/28-1G219152HD25_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/2609/28-1G2260Z33N19_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/2610/28-1G22610491UK_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/2817/28-1G22QH93I50_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201712/2819/3-1G22Q94T4C1_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/0217/28-1P1021I44X37_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/0219/3-1P102191001Q0_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/0319/3-1P1031Z241614_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/0409/28-1P104095A9311_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/0817/28-1P10QH624912_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/1010/3-1P11010224W94_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/1018/28-1P1101P204930_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/1515/28-1P11515342QR_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/2311/28-1P123114321253_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201801/2314/28-1P123145940556_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201802/0711/28-1P20G151343A_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/0514/3-1P305145935334_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/0615/3-1P30615430D19_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/0615/3-1P306154400357_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/0615/3-1P306154623452_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/1211/3-1P312113423517_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/1211/3-1P31211415B06_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/1211/3-1P312114ADP_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201803/1211/3-1P31211522X93_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201804/0915/3-1P409154T9315_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201804/0916/3-1P409160SD33_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201807/0317/28-1PF31H1244A_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/0415/3-1PP41514154E_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2416/28-1PR4163R2K0.jpg
  • p.7k7####.cn.####.com/html5app/201808/2416/28-1PR4163R2K0_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2417/28-1PR41F12B59_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2417/28-1PR41G00E64_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2417/28-1PR41G553222_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51J64L49_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51JS3531_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51K44LS_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51KG1A3_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51KZb59.jpg
  • p.7k7####.cn.####.com/html5app/201808/2517/28-1PR51KZb59_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2518/28-1PR51P1114F_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2611/28-1PR6112133J1_96-96.jpg
  • p.7k7####.cn.####.com/html5app/201808/2611/28-1PR6112R2294_96-96.jpg
  • p.7k7####.cn.####.com/wapH5/common/module/js/array-contain.min.js
  • p.7k7####.cn.####.com/wapH5/common/module/js/array-unique.min.js
  • p.7k7####.cn.####.com/wapH5/common/module/js/focus.min.js
  • p.7k7####.cn.####.com/wapH5/common/module/js/played-game/get-recommend-d...
  • p.7k7####.cn.####.com/wapH5/common/module/js/played-game/tpl/swipe.min.js
  • p.7k7####.cn.####.com/wapH5/common/module/js/played-game/tpl/template.mi...
  • p.7k7####.cn.####.com/wapH5/common/module/js/played-game/view.min.js
  • p.7k7####.cn.####.com/wapH5/common/plug/swipe.js
  • q.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
  • s####.tc.qq.com/gdt/0/DAAHU5BAKAAPAAAjBbSHTKAgBsMSJi.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/transformer_14189501191749432915_1534267516_114.jp...
  • s####.tc.qq.com/gdt/0/transformer_7965249044853711888_1534930358_114.jpg...
  • s####.tc.qq.com/ma_icon/0/icon_42256978_1535006097/256
  • v.g####.qq.com/gdt_stats.fcg?viewid=####&i=####&os=####&xp=####&gap=####
  • ws####.qq.com/w.cgi?releaseversion=####&commandid=####&serverip=####&app...
  • www.7####.com/
  • www.7####.com/img/0043e961dce3288db5337181c780f2ce.jpg
  • www.7####.com/img/010f71ee2971ed86c06abef6bc20f680.jpg
  • www.7####.com/img/07f2d84fc2f12ced43b81d016642663a.jpg
  • www.7####.com/img/099c3ce4786c5234f5ff4569e628ebd9.gif
  • www.7####.com/img/09ec1024223ca9bcd173f577af717103.jpg
  • www.7####.com/img/0b4dddd6c046d0a56287045d588a7767.png
  • www.7####.com/img/0bfcad083a1791a7213cf070de68f6dd.jpg
  • www.7####.com/img/0edbf087784d8481b8451d929c285230.jpg
  • www.7####.com/img/14401734db027af021e66094c06c9edd.jpg
  • www.7####.com/img/14b8809697fed9b2281871ba6bb843ad.jpg
  • www.7####.com/img/14ef04c24bc64207e85f85df02afb6b0.png
  • www.7####.com/img/150aed498964a5963cf3ab9694dcad49.jpg
  • www.7####.com/img/1634c9b1f71a607249c897d6e055222c.jpg
  • www.7####.com/img/18c558edf5f29a631a5dbda0336d4324.jpg
  • www.7####.com/img/1948f6cadf088417a6ff43b36e59c28d.png
  • www.7####.com/img/19d801598e67b36600842b5c01dd24ec.jpg
  • www.7####.com/img/1ec86b8da2e007fbc487f492ee62a7bf.jpg
  • www.7####.com/img/1f6d5d12e56fe22e184b7bbfb4411802.jpg
  • www.7####.com/img/208b6bea28aaaf124f23413cb2464fa0.jpg
  • www.7####.com/img/214c8fb1dc37bd3519cb8881fbffdd11.png
  • www.7####.com/img/22d6a621c8734d92d9c6bb9b4d9adba6.jpg
  • www.7####.com/img/290194a9712908dd26df72c3dcf719c7.jpg
  • www.7####.com/img/292e3bfb08e96a33a2fb22372c926fea.gif
  • www.7####.com/img/29bcb07cd6ba79fb05fe93bd536c40ca.jpg
  • www.7####.com/img/2a044fb0430b3ea2bc0652056211e969.jpg
  • www.7####.com/img/2a2aabef8f023f1feb4eae67d03bd5e7.jpg
  • www.7####.com/img/2b1e8701054f25bcf0c0407a5c5698e2.jpg
  • www.7####.com/img/327f8f60e8b05fbb53b02175f631e5e3.jpg
  • www.7####.com/img/33e0f92012e3dde73b937dbaf1b75a8e.png
  • www.7####.com/img/360d95cf31beb54b940dcb9aac296950.jpg
  • www.7####.com/img/3747b8e551d88fee17fb220d5f9db7ff.png
  • www.7####.com/img/39ac006fb2be3da63757d22bef94df9e.png
  • www.7####.com/img/3c1b90be4c5290e24e0f06781e293240.gif
  • www.7####.com/img/3e6ccd520a3cb4c3a4451a8d43b4458c.jpg
  • www.7####.com/img/40dc67e4d02d39d67868f0b388e455e2.jpg
  • www.7####.com/img/418736c4d6987878e2972f67e204eeb9.jpg
  • www.7####.com/img/448452c95a71a01985fcd7d39f761e99.jpg
  • www.7####.com/img/44f75dfd2958c1aa49f34f65c12e5c42.png
  • www.7####.com/img/4a9e29eb47d4c3de45631b73e2c7a29f.jpg
  • www.7####.com/img/4e44a9c5475df04b8770a96abc9e2e59.png
  • www.7####.com/img/4ebe0ed2c7ece4c480a1b81286cfb5a7.jpg
  • www.7####.com/img/4ee156186e79325146e1e7ced1005712.jpg
  • www.7####.com/img/50756abb2ff938bc203f38864451ce82.png
  • www.7####.com/img/51ef2c57581ff9ad8a8ca63c92748c17.jpg
  • www.7####.com/img/530fab4c96c0acf951f830ce680d8d7c.jpg
  • www.7####.com/img/549ef5a6c7524bdb18a022d3898a5ebc.gif
  • www.7####.com/img/5596917d3ca50a74e095521d4ade3039.png
  • www.7####.com/img/561bbb34445f171a353bee0450eb9968.jpg
  • www.7####.com/img/56eecd8a34d08f346f8b4b5feecd2c62.gif
  • www.7####.com/img/574a4593e96b23c6c60a8cff95f03939.gif
  • www.7####.com/img/58aedbb4496bb0890dd774f44059002f.jpg
  • www.7####.com/img/58bfdf52fb2fda38858f871b22f9c213.jpg
  • www.7####.com/img/59f257d8c7bd804374e084081d115377.jpg
  • www.7####.com/img/5aeaed74c73bf8548018d8b30e3417ba.jpg
  • www.7####.com/img/5d471769368bb419d8f9b519eec609ab.png
  • www.7####.com/img/5dc7bf38359a3b2a188ac40761bfb5fc.jpg
  • www.7####.com/img/5dd48b9ad3b855f2198161abb013e9ca.jpg
  • www.7####.com/img/5f0de8acfce27547a3cc80b793fe0f57.gif
  • www.7####.com/img/60b760920a1aa2b87188103a7746c619.jpg
  • www.7####.com/img/63f976035f91471b735ec8825a92b18f.jpg
  • www.7####.com/img/68f12b9bb6548a94a3bd8f1f0c09e044.jpg
  • www.7####.com/img/692f0570cb0b58bf9ecdb8ff08f5b04b.jpg
  • www.7####.com/img/69d7ece5519c7477793259dacf1333ab.jpg
  • www.7####.com/img/6b0697e06f28816140b5fbd405d540f0.jpg
  • www.7####.com/img/6b0ede011f48c3d03b40daea32d54049.gif
  • www.7####.com/img/6b7dc82cf4aa159d82aaaff3c125bc0e.jpg
  • www.7####.com/img/6e1cf1ce390bfe50ab693a1f8213ef3b.jpg
  • www.7####.com/img/6f3bc9a41516f4cd9028a7c3ae83137f.jpg
  • www.7####.com/img/6fa11548c37f6d2a81eac15a05efe446.gif
  • www.7####.com/img/73fd42e69b515751e8895af36f82c102.gif
  • www.7####.com/img/786f4d9c95a97fff92cfd4f44ec6df43.jpg
  • www.7####.com/img/79bea99f78843524770e321b70b20bbc.gif
  • www.7####.com/img/7b4a6a4c6751ba4ad3d9a3d22f6f265d.jpg
  • www.7####.com/img/7d46ad60f2d2958656f5421fed0c50ce.png
  • www.7####.com/img/7e0cd2c7fd2752187bcd48b1cdebc21a.gif
  • www.7####.com/img/7f6e34cd07eab52b0d96e3e7dc04774e.jpg
  • www.7####.com/img/80b848dd0f71a60e51c31f7fff3f219d.jpg
  • www.7####.com/img/82b90b1a8031f725814acc34f3dd2f98.jpg
  • www.7####.com/img/82e0c674e668c9883c19c01b83ffa888.jpg
  • www.7####.com/img/837b98b11f8e6ea4ac1c048d89bdd17d.png
  • www.7####.com/img/84596e077d776f07132eb1adf57e2996.jpg
  • www.7####.com/img/86c9cbd4d27c65d9dfab2ee87ce6f114.jpg
  • www.7####.com/img/8949b9e910ad03cbb60fd4708e273c62.gif
  • www.7####.com/img/8958ddddcc2cbc91fd5c50bd6b1bca61.gif
  • www.7####.com/img/8ff9e8bfbe03aca8e4978aefa1e66431.jpg
  • www.7####.com/img/90a83b61d80ffc0e3d704c3bcd44db0f.jpg
  • www.7####.com/img/91383d93ae311e14f0ea14c7a9b538e0.jpg
  • www.7####.com/img/9273f79bba924be7dfb441354702de44.jpg
  • www.7####.com/img/9310fe5f39be0997c18175938bf4a4de.jpg
  • www.7####.com/img/95062357c246b582991200e8c234a1a9.gif
  • www.7####.com/img/96ba648fb0a4fe70268333a3ab042098.png
  • www.7####.com/img/999e52d1f5594d05fc83a55a1912d0c0.jpg
  • www.7####.com/img/9ba2d3fc8edcea3cd480b3770c707cb1.png
  • www.7####.com/img/9fee95b3a79e3f8dbb15169768e4cefc.jpg
  • www.7####.com/img/a1f1a783369fb27f1dc2d25ebb819aab.png
  • www.7####.com/img/a30e87a154ffe1ebd32643ed17bdfc11.jpg
  • www.7####.com/img/a61ca152ad0cdccc39b5f48302576875.jpg
  • www.7####.com/img/a7a871e54ea2d44ccdaed333598cf023.jpg
  • www.7####.com/img/aa031860ec739a3c4a73733c009556c7.jpg
  • www.7####.com/img/ab5ff3701ad2107d892ccab7ce31a28a.jpg
  • www.7####.com/img/ae0e2cc6c6ae8c6e873e57431e7d70ce.jpg
  • www.7####.com/img/ae1a1772110e75b8af9c8857a8843db0.png
  • www.7####.com/img/aeb9e7494a49ba0d6c82ae86be1bfe66.jpg
  • www.7####.com/img/b0bb1eeb1dc8ee6904a09895df4b1224.png
  • www.7####.com/img/b40ac503b306dc3e87b3dbbe0c0aa668.gif
  • www.7####.com/img/b4827f23158b7b148b9acdd9a1b51402.jpg
  • www.7####.com/img/b8636c7c4ed6fe26de63b7f5b3fa14a6.jpg
  • www.7####.com/img/bacf33e52d9d18b74b47fe1c2cb087a4.png
  • www.7####.com/img/bb3067c9879378fb212de82677745154.jpg
  • www.7####.com/img/c1366d281952999370f8f734c92cbcb1.jpg
  • www.7####.com/img/c6402e4e4efad8b6cf45a9f33f0b9b36.png
  • www.7####.com/img/c8f0bbe071a1c114136055a4560bad6a.jpg
  • www.7####.com/img/c9ab942083c5e05dbf0fdde94a3e8594.jpg
  • www.7####.com/img/ccd37b22a9274833aa67657667ddc3e8.gif
  • www.7####.com/img/cd1143e3c765546f1d885386ce94a201.gif
  • www.7####.com/img/d22fc8f67e764a00274c0d7573785e64.gif
  • www.7####.com/img/d42f77e335bb17d16c886b0cdf39c9e9.jpg
  • www.7####.com/img/d4e9eaedf3eed2e7883c3ff5f5dc7fbb.jpg
  • www.7####.com/img/d6d60d7c7e7c9b86d9da7e9b4c78a31a.jpg
  • www.7####.com/img/d93cea4b11c29459780c597fcede9ae0.jpg
  • www.7####.com/img/daf8afec9602a4061c08a22073319fab.png
  • www.7####.com/img/dcf9b9bdf7bde7d82fb8738e308c2ef4.png
  • www.7####.com/img/def689fae118441f184f96a31c93f5e8.gif
  • www.7####.com/img/df38f010222dde24d23afeb23da69157.jpg
  • www.7####.com/img/e0ebb1231edcd96d35843579a8a4dd24.png
  • www.7####.com/img/e1974c9f778ddb26b6dcd65c7af3f8b7.jpg
  • www.7####.com/img/e2babe438045bad1af14fd051867a5f1.gif
  • www.7####.com/img/e48dae84d65c6709fd9b792bbfdc8251.jpg
  • www.7####.com/img/e9a574d3d32a5bac178ccb3e91106fb8.png
  • www.7####.com/img/eb6f5d442a0a9d174ae4f9e5d254c37c.jpg
  • www.7####.com/img/f05b21e7f7bf8b0668c337f2271fe9bc.jpg
  • www.7####.com/img/f3835f77c0b8f187fb7c6bcfb828b7f5.gif
  • www.7####.com/img/f8d7aff77a455892caeffbe0a18db2d9.jpg
  • www.7####.com/img/f9fd0ebd1379e948df9fa0251f3d0cc7.jpg
  • www.7####.com/img/fa8ad79d84c63038896fb041ca7f2410.jpg
  • www.7####.com/img/fbdb2793f5857ccd9580efebeb67fe46.jpg
  • www.7####.com/img/fd1300c63755c49234a36489adb240f9.png
  • www.7####.com/img/fdc473c423128cd4aedb663879bc93d6.jpg
  • www.7####.com/img/fe1d1b7572c9207acdeeaa8817e77723.jpg
  • www.7####.com/img/ff795dec90502996bc7626ebe17450b7.jpg
HTTP POST requests:
  • a####.u####.com/app_logs
  • api.durianc####.com/video/v1/config.jsp
  • api.durianc####.com/video/v1/info.jsp
  • s####.e.qq.com/activate
  • s####.e.qq.com/click
  • s####.e.qq.com/msg
  • si.ei.senb####.com/CY/c31ak
  • si.ei.senb####.com/w/X/ddc3l
  • v.g####.qq.com/gdt_stats.fcg
  • www.51bt####.com/apps/client/GetAppData8.php
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
  • /data/data/####/65e0775c716622ec8f14b7ac8cd050db.temp
  • /data/data/####/Alvin2.xml
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/WebViewSettings.xml
  • /data/data/####/_i1030546545.xml
  • /data/data/####/_w1030546545.xml
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/com.uinixeea.jar
  • /data/data/####/com.yujinwe.az.jar
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/f_00003e
  • /data/data/####/f_00003f
  • /data/data/####/f_000040
  • /data/data/####/f_000041
  • /data/data/####/f_000042
  • /data/data/####/f_000043
  • /data/data/####/f_000044
  • /data/data/####/f_000045
  • /data/data/####/f_000046
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_suid
  • /data/data/####/index
  • /data/data/####/mscom.xhxm.media.e.xml
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/z7ddc31a7.xml
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/com.ss.android.ugc.live.apk_0
  • /data/media/####/e7a9e238f80771c4104c02205d35639a
  • /data/media/####/xhxm
Miscellaneous:
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • DES
  • RSA-ECB-PKCS1Padding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке