[Q] Android Trojan(s)? - Android Q&A, Help & Troubleshooting

Ok, I've never seen this or had this issue before. So I am not sure what is causing it.
I installed my usual apps after flashing Mr. X's stock+root-CIQ Tmo T989 rom.
First app I usually download and run before anything is Adfree. Then Astro file manager to restore APKs. But I realized that this method left me with some older versions of the apps and they wouldn't have their market links. Yes, I could run Titanium Backup to fix them..
Anyways, suddenly I get a star icon on my notification bar. I look at it and it sends me to a website claiming I won a tablet and to chose.
This is one of the links, don't visit it, I just posted it for reference;
Code:
http://com-user.mobi/galaxy/usa/go.php?t202kw=usipad31&uid=REMOVED
So I decided to wipe and flash again and go through the same process to see if perhaps catch who's the culprit..
It happens again this time with a plus icon..
The star icon has happened twice on different occasions, only in the last week, and after installing a recent update to Adfree.
These are the apps I have installed;
Adfree
Astro
3G Watchdog
AT&T Smart Wi-Fi
Barcode Scanner
Beautiful Widgets
Bloat Freezer Free
GasBuddy
Google Voice
Quick Boot
QuickPic
RealCalc
Root Explorer
ScanLive
ShopSavvy
Speed Test
Tapatalk
Ubuntu Regular TTF
Zillow
Has this happen to anyone? Any idea what's causing this or how to catch / prevent it?
I've had one app actually hijack my my stock browser and change the search engine to some smartsearch type site, like it does to normal windows browsers.. lol
Thanks,
-CC

I've had one
I've had the same one, (it's some kind of advertising). I tracked it to some gosms theme. My suggestion:
1. Wipe (with backup of all the apps)
2. Restore ONE App
3. Reboot. (since the ad appeared everytime i rebooted my phone)
4. Repeat 2 & 3 until you see the ad
5. Uninstall latest restored app or complain to developer.
Hope i helped

AirPush Detector
Ad Detector
AirPush should find the culprit.

Related

[Q] Safe to remove apps?

Has anyone compiled a list of the safe-to-remove apps for the AT&T GSII along with corresponding .apk filenames, yet? I've already removed a number of them via Root Explorer, using the list of removed apps from Cognition's rom, but there's a couple that still remain and I'm wondering if they're ok to remove or not. A full list would be best, though I'm mainly wondering about:
Kies Air
Featured Apps
Social Hub
AT&T Hot Spots (doesn't show in app list, but still shows as a running app for me)
Don't know...I saw that AT&T Hot Spots wasn't actually in the drawer but it shows up as a running app too. I don't plan on removing Kies Air or the Social Hub (for the moment) but I'd like to remove "Featured Apps" but when I go into Titanium Backup it'll ask me if I'm sure I want to do this since it's part of the framework so I've backed off of it for now...I'd like to know about these 4 apps and if they're safe to remove as well.
I used root explorer and did it manually. I lost count how many I ripped out.
Sent from my SAMSUNG-SGH-I777 using XDA App
joeybear23 said:
I would like to keep a running list of AT&T-delivered apps from the stock ROM that are safe to freeze/uninstall without causing any loss of essential functionality.
Amazon Kindle
AP Mobile
AT&T Code Scanner
AT&T Family Map
AT&T Hotspots (if you do not use it)
AT&T Navigator
Buddies Now
City ID
Digital Clock
Dual Clock
Featured Apps
Live TV
Media Hub (not AT&T Bloatware, rather Samsung-delivered)
Mini Diary
Mini Paper
QIK Lite (if you do not use stock video chat)
Yahoo Finance
YP
If you have any apps that you have removed and run problem free for at least 48 hours, please let me know and I will update the list.
Click to expand...
Click to collapse
From this thread.
Honestly I'd recommend installing Titanium Backup and doing a backup before you remove ANY apps. You simply never know if you might need them down the road for something. Sure 99% of the AT&T crap is crap, but there's no reason not to back them up first.
Also, if you're worried about it, buy the PRO version (of TB) and simply freeze ones you don't want to use. This isn't deleting them, it simply disables them.
Kadin said:
Honestly I'd recommend installing Titanium Backup and doing a backup before you remove ANY apps. You simply never know if you might need them down the road for something. Sure 99% of the AT&T crap is crap, but there's no reason not to back them up first.
Also, if you're worried about it, buy the PRO version (of TB) and simply freeze ones you don't want to use. This isn't deleting them, it simply disables them.
Click to expand...
Click to collapse
I have the PRO version. I know about freezing but I was being lazy and I know there are much more adventurous people than me who've gone ahead and ripped things out. I didn't want to do the freeze app, okay seems safe to remove, repeat per next app deal. Like I said, I'm lazy...
Some of these At&t apps i cant find under root explorer, for example featured apps. what would be the file name for featured apps?
re: bloat/system apps
Smoghog said:
Has anyone compiled a list of the safe-to-remove apps for the AT&T GSII along with corresponding .apk filenames, yet? I've already removed a number of them via Root Explorer, using the list of removed apps from Cognition's rom, but there's a couple that still remain and I'm wondering if they're ok to remove or not. A full list would be best, though I'm mainly wondering about:
Kies Air
Featured Apps
Social Hub
AT&T Hot Spots (doesn't show in app list, but still shows as a running app for me)
Click to expand...
Click to collapse
If you want to uninstall even more bloatware you need to get the app called
"SystemAppRemover" from the market. (everything will show up with this).
It makes it very easy to uninstall most any system apps.
The app has other functions too.
It's also best to flash a Nandroid backup of your rom before uninstalling
bloatware/system apps.
(use CWM Manager or CWM Recovery and NOT rom manager for backing up).
Good luck!

List of freezable apps (updated 11/18 7:00 pm EST, many apps added)

For as long as I've been a member here, I don't think I've ever started two threads in one day in a Dev section that I was so unsure belonged in the dev section... so Mods, please forgive if this is in the wrong place.
I thought it would be helpful to get a running list of apps that can be frozen with Titanium that won't cause any FC's or other problems. I'm a bit extreme with this, I think, compared to most... I tend to freeze (or remove) a LOT of stuff.... but so far I haven't caused any problems. Here is my list:
Amazon Kindle
Backup Assistant
Blockbuster
Books
Car Panel
com.htc.footprints.widget3d
Connected Media
Facebook
Facebook Chat Widget
Facebook for HTC Sense
Fb Chat
Flickr
Footprints
Friend Stream (there are two of these with different versions on my Rez)
Friend Stream Widget
Gmail
Home screen tips
Mobile Hotspot
Mobile IM
Mobile Instant Messaging
Music
Music Enhancer
Music Widget
News
News Widget
NFL Mobile
Peep
Polaris
Slacker
Stock Widget
Stocks (There are two of these as well)
Talk
Task Manager
Task Widget
Tasks
Tethering Guard (WTF IS THIS????? A way for them to keep us from free tethering??)
Tips for Home
Trends Widget
Twitter Widget
Usage Monitor
Vcast Media Manager
Vcast Music
Vcast Videos
VZ Navigator
Watch
Watch Widget
So far, so good. And I've little doubt that much more can be removed... on my Dinc, I always ran a Sense ROM, but I'd run them REALLY lean. I will be experimenting more with what can be removed and will update the list as I do...
EDIT: Froze quite a few more apps, still no FC's or other issues, here are the additional ones...
App Sharing
Archive Viewing
Data Dashboard (this is a widget)
Data Roaming (this is a widget)
Field Trial
Hot Pursuit
HTC Report Agent
Jetcet Print
Jetcet Print Resources
Let's Golf 2
My Verizon Mobile
NewBayService
Power Dashboard (this is a widget)
Profile Widget (this is a widget)
Ringtone Trimmer
Ringtone Widget (this is a widget)
Screen Brightness (this is a widget)
Screen Timeout (this is a widget)
Tell HTC
Good looking out! Looks like i can freeze a couple more!
Thanks for testing all of that and posting the list.
Sent from my Droid Incredible HD using Tapatalk
Do these apps re-install after a reboot like others are reporting with temp root or does "freezing" have better results than deleting?
Freezing them sticks after reboots. It is almost as good as removing them.
But OP, you really went to town on the freezing.
Thanks for testing these! Appreciated.
con247 said:
But OP, you really went to town on the freezing.
Click to expand...
Click to collapse
hahah I said in the first post, I freeze a LOT of stuff. You can freeze as few or as many of those apps as you need, I just wanted to guinea pig it and see what would crash, so far no issues.
As mentioned above, freezing DOES stick after a reboot. However, unlike freezing on a fully rooted device, freezing here doesn't remove the apps' market links, and doesnt remove them from the apps list in settings. It DOES remove them from the app drawer and keep them from running, which is what matters
I just tried to freeze apps with "Bloat Freezer Free" and most of the apps came back after a reboot. Is everyone else using Titanium? Does it "freeze" apps differently?
Thanks!
I've only ever used Titanium to freeze apps but you need the pro version. WELL worth the money, this app has proven very useful.
Added almost 20 more apps...
I need to have temp root going to make this happen, right?
I'm on a Mac. Loving the rezound so far even without root .
Sent from my ADR6425LVW using XDA App
yep must have temp root and using Titanium or something equivalent
I'm moving this to the App section since it is more related to that section.
Thanks for this list, but have you tried removing any, if possible?
Bluetooth busted?
Trying to troubleshoot it but I froze most of the apps from your first list but noticed this afternoon I could not get my Bluetooth to turn on. Could be a coincidence but any chance freezing one of those apps could cause that?
trying to get mine to temp root it self would cause BT to quit working
reboot would fix it most of the time
I don't think any of the apps I listed would cause BT to stop working. I did try to remove an app once and it crashed Titanium. I figure without S-OFF that's not going to be happening any time soon, since we can't get the /system/ folder mounted in R/W.
Thanks for this. I loaded my own task manager and I couldn't believe all the junk that autostarts on boot. This cut down on that signficantly!
Now I just can't wait for a debloated ROM to come out.
Superguy said:
Thanks for this. I loaded my own task manager and I couldn't believe all the junk that autostarts on boot. This cut down on that signficantly!
Now I just can't wait for a debloated ROM to come out.
Click to expand...
Click to collapse
Which task manager did you load?
bigdwg71 said:
I just tried to freeze apps with "Bloat Freezer Free" and most of the apps came back after a reboot. Is everyone else using Titanium? Does it "freeze" apps differently?
Thanks!
Click to expand...
Click to collapse
You can use App Quarantine:
https://market.android.com/details?id=com.ramdroid.appquarantine
Free and does the same thing -- I've used it on my Rezound (I have Titanium Backup as well, but this has a lighter footprint and our temp root is finicky).

My Quarantined / frozen apps

I downloaded an app called App quarantine from the market and put the following apps in the don't run bin , but before doing that I downloaded Go Launcher / Go Contacts / Go Sms Pro and did a ehh, conversion from the stock samsung apps to Go Stuff. Has anyone else done this or anything similar?
Apk's no longer running on boot
(See screen shots, i'm lazy today.)
jb0nd38372 said:
I downloaded an app called App quarantine from the market and put the following apps in the don't run bin , but before doing that I downloaded Go Launcher / Go Contacts / Go Sms Pro and did a ehh, conversion from the stock samsung apps to Go Stuff. Has anyone else done this or anything similar?
Apk's no longer running on boot
(See screen shots, i'm lazy today.)
Click to expand...
Click to collapse
There are a number of apps that do the same type of thing, Titanium Backup will 'freeze' apps as well as a whole host of additional features.
Then of course, another option is to just rename the apps from *.apk to *.bpk and rebooting.
My personal preference is a third option called Autostarts which is similar to MSconfig in Windows but for Android. The reason being is, it gives you the ability to keep an app from ever running unless you actually tap the app to run it but still allows you to keep the app installed in the event you want to use it. Google Maps comes to mind, I want it installed, I dont want it running in the background.
I dont recommend removing any of the bloatware if you plan on staying on stock but, some of it for US Note users was able to be uninstalled without root via either Settings->Applications->Manage Applications->All Applications, then tap an app and see if uninstall was lit up, if so, sweet. Or, alternatively you could go thru the Market->(Menu Key)->My Apps but not all apps show up in this list. As a side note, I actually manually did a search for many of the apps on the phone and manually updated them because they were not showing up in the market 'My Apps' list.
One other side note, most of the Samsung apps are actually pretty decent, I usually dont touch them. Its the ATT software and the apps ATT took bribe money from third parties that bothers me (Yellow Pages for example).
Oh, and a little known feature of Go Launcher is the ability to hide apps.
Tap the App drawer icon to get to the list of apps on your phone, tap the menu button, tap hide apps. For those of us that havent bothered to root, this at least gives you the ability to not have to look at apps you dont want to see in the app drawer.
Wow thank you for all the info. As far as staying stock, I like making my devices unique to me, I did keep all spen related apps, but killed pretty much everything else. I doubt my phone will ever see an official release of anything, Xda all the way
littlewierdo said:
There are a number of apps that do the same type of thing, Titanium Backup will 'freeze' apps as well as a whole host of additional features.
Then of course, another option is to just rename the apps from *.apk to *.bpk and rebooting.
My personal preference is a third option called Autostarts which is similar to MSconfig in Windows but for Android. The reason being is, it gives you the ability to keep an app from ever running unless you actually tap the app to run it but still allows you to keep the app installed in the event you want to use it. Google Maps comes to mind, I want it installed, I dont want it running in the background.
I dont recommend removing any of the bloatware if you plan on staying on stock but, some of it for US Note users was able to be uninstalled without root via either Settings->Applications->Manage Applications->All Applications, then tap an app and see if uninstall was lit up, if so, sweet. Or, alternatively you could go thru the Market->(Menu Key)->My Apps but not all apps show up in this list. As a side note, I actually manually did a search for many of the apps on the phone and manually updated them because they were not showing up in the market 'My Apps' list.
One other side note, most of the Samsung apps are actually pretty decent, I usually dont touch them. Its the ATT software and the apps ATT took bribe money from third parties that bothers me (Yellow Pages for example).
Oh, and a little known feature of Go Launcher is the ability to hide apps.
Tap the App drawer icon to get to the list of apps on your phone, tap the menu button, tap hide apps. For those of us that havent bothered to root, this at least gives you the ability to not have to look at apps you dont want to see in the app drawer.
Click to expand...
Click to collapse
Just to add I guess a 'fourth' option, I like to use the app 'root toolbox' available on the market with both free and pro versions. Under the advanced menu you can remove any system apps you like but the nice thing is anything you remove is automatically backed up to the root toolbox folder on the internal sd. The backup is done automatically so you dont have to worry about removing something and forgetting to backup first and also gives you the option to restore any system apps you removed simply and easily. Ill be honest the restore feature has saved my bacon many times lol and is also a great way to experiment which apps are safe and unsafe to remove.

[Q] Help Leadboltads virus on Galaxy S4

Hi All
Since a day I have a sort of leadbolt virus that opens my browser and shows the website like below:
ad.leadboltads.net with Top Apps/Offers of the Day
This happens when I download something from the playstore or when I delete apps.
It Makes crazy and I have tried some things alrdy so fix it without any succes.
- Downloaded and installed virusscannen, no succes
- Downloaded and installed ad detector, found a app with leadbolt, deleted it but didn't solve the problem
Hopefully someone can help me too fix this annoying problem
Me too!!!
This is so annoying! My browser keeps opening to the leadbolts site with a bunch of apps on it....Please someone help!
+1. From where come this shlt ?
Shaundiesel said:
Me too!!!
This is so annoying! My browser keeps opening to the leadbolts site with a bunch of apps on it....Please someone help!
Click to expand...
Click to collapse
I'm also having the problem and have not found a solution yet.
The only difference for me is I have adaway installed so the webpage never gets to display. Just opens the browser.
I've tried different ad detector apps from google play, but nothing is fixed this problem. Almost ready to reflash the rom and start from scratch.
UPDATE: I fixed the problem.
When the browser hijacking occurred, it happened after installing or updating a program from any source. Google Play, Amazon or a standalone APK. That meant the virus had control over my installer.
Using Lookout's Ad Detector, I identified some potential culprits (Go Launcher EX being at the top of the list) and uninstalled them. That didn't work.
What actually fixed the problem was resetting the defaults for all the apps. Settings > More > Application Manager. Hit the menu key and choose Reset app preferences.
You don't loose any data. You just get prompted for choosing a default app when you run certain applications. I choose to use Lookout's installer instead of the default android installer when I got prompted to install updates.
Haven't had the issue since. Hope this helps.
markmi300 said:
What actually fixed the problem was resetting the defaults for all the apps. Settings > More > Application Manager. Hit the menu key and choose Reset app preferences.
You don't loose any data. You just get prompted for choosing a default app when you run certain applications. I choose to use Lookout's installer instead of the default android installer when I got prompted to install updates.
Haven't had the issue since.
Click to expand...
Click to collapse
Hi everybody. (First sorry for my english but I speak french)
This is a solution but it workn't very good.
After the downloading and installation from a update or a program, AndroƮd ask me if I want to finish the task with the default browser or Chrome ? So I can't see this f*cking page more but I must always put my choice between the 2 browsers.
I thank you for your solutions....
+1 to lookout fixing. Had the same problem, ripped it right out.
Sent from carbon note 2 on XDA premium app
shbaldw said:
+1 to lookout fixing. Had the same problem, ripped it right out.
Sent from carbon note 2 on XDA premium app
Click to expand...
Click to collapse
Glad I was able to help.
See the solution at
http://forum.xda-developers.com/showthread.php?t=2525965
#@!%&#! 'ad.leadboltads.net' Malware
shbaldw said:
+1 to lookout fixing. Had the same problem, ripped it right out.
Click to expand...
Click to collapse
Lookout Security & Antivirus found mine in ChargeBar Free Edition,
ChargeBar came embedded in the NottachTrix 2.3.0 ROM.
I installed it (NottachTrix) and it (ChargeBar) didn't update for 3 months, then, BANG.
I've deleted ChargeBar's update, moved it from system apps to apps, deleted it, and the browser pop open 'ad.leadboltads.net' still persists.
Lookout Security & Antivirus can not find the new location of the malware, they do not have a forum.
By the very definition and behaviour, this is malware, and, ChargeBar (Asgard Casino Apps) is involved in the distribution of malware.
Asgard Casino Apps distributes 34 apps that behave this way.
They are using Google to distribute this malware, abet, that app is benign in its origin, its a pipeline, or conduit for malware.
Sneaky F##kers aren`t they.........
#1) I would like to get this crap off my phone.
#2) I need to bring this to Google's attention, and have the developer and apps banned from the Play store.
Sooo, starting with #1,,,how do I get this crap off my phone!
NOTE:
I will be linking to this post in the NottachTrix post, I'm asking the developers to to move ChargeBar from the ROM zip.
My MBAM forum post: https://forums.malwarebytes.org/index.php?showtopic=138306#entry764184

Browser opening ad website after updating apps

Sometimes when an app finishes updating my browser (Via Browser) opens and loads a page that is advertising apps. First it was Appsquare, now it's some other website I forgot to remember. I have NO idea what the cause is and I didn't install any strange apps to my knowledge. I never installed any APK that I downloaded outside the Play Store and both Malwarebytes Antimalware and Eset found nothing. This doesn't always happen when I update an app so there's no set pattern. Smetimes it doesn't happen after updating one or more apps and sometimes it does and that is why I can't really figure out which app is causing it, if it is an app at all because there are no ads displaying in either app I use because I paid to get rid of it. Yes, I did some research and it seems to be an issue mainly affecting Samsung users and one site in particular did some research and found out it was a shady ad network behind it: Clickity. My symptoms do match but I have an LG device, not a Samsung device and I use a different browser. I have used a few of Cheetah Mobile's apps in the past but I'm sure I deleted all traces of it on my phone, at least the things I could find. And I haven't used a single app from those devs anymore since I did a factory reset on my phone and updated to Android 8 so there shouldn't be a trace left. I need help fixing this because I have no idea where to look.
EDIT: It turned out to be my clock widget app "Digital Clock Widget Xperia" made by Lazar Dimitrov that was causing those ads to pop up, despite paying to remove ads.

Categories

Resources