Technical information
- Adware.Appsad.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) p####.xhxt####.com:80
- TCP(HTTP/1.1) log.xhxt####.com:80
- TCP(HTTP/1.1) a####.xhxt####.com:8082
- TCP(HTTP/1.1) u####.b####.com:80
- TCP(HTTP/1.1) s####.mob####.b####.com:80
- TCP(HTTP/1.1) log.xhxt####.com:8081
- a####.xhxt####.com
- log.xhxt####.com
- p####.xhxt####.com
- s####.mob####.b####.com
- u####.b####.com
- u####.b####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&pro...
- u####.b####.com/setting/mbr?p=####&hp=####&l=####&c=####&prod=####&svn=#...
- log.xhxt####.com/logcollect/app-install-history.do
- log.xhxt####.com/logcollect/get-apk-install-list.do
- log.xhxt####.com:8081/get/ad_screen
- log.xhxt####.com:8081/get/browser
- log.xhxt####.com:8081/get/policy
- s####.mob####.b####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
- <Package Folder>/app_mbj/####/classes.zip
- <Package Folder>/databases/amz_download.db-journal
- <Package Folder>/databases/fbplus.db-journal
- <Package Folder>/databases/splay.db-journal
- <Package Folder>/databases/xUtils.db-journal
- <Package Folder>/databases/x_gads.db-journal
- <Package Folder>/databases/x_gads_utils.db-journal
- <Package Folder>/databases/xant.db-journal
- <Package Folder>/files/etc-uic
- <Package Folder>/files/google.db
- <Package Folder>/files/libexec.so
- <Package Folder>/shared_prefs/<Package>_preferences.xml
- <Package Folder>/shared_prefs/AdsBusiness-data.xml
- <Package Folder>/shared_prefs/AdsBusiness-data.xml (deleted)
- <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
- <Package Folder>/shared_prefs/aps.xml
- <Package Folder>/shared_prefs/apsad.xml
- <Package Folder>/shared_prefs/apscomm.xml
- <Package Folder>/virtual/####/0.xml
- <Package Folder>/virtual/####/userlist.xml
- <SD-Card>/.Android/####/etc-uic
- <SD-Card>/.AndroidCore/####/etc-uic
- <SD-Card>/.amzuuid/etc-uic
- <SD-Card>/.androidsystem/####/gads.db
- <SD-Card>/baidu/####/journal.tmp
- <SD-Card>/baidu/.cuid
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- cat /proc/meminfo
- getprop ro.product.cpu.abi
- libexec