[Q] Possible for malware to spoof notification? - Android Q&A, Help & Troubleshooting

Hi:
Just got a notification on my Galaxy 10.1 tab: "Sign-in error for [email protected] - Touch to sign into your account".
Is it possible that this is malware spoofing the system? Any way for me to find out? I've run Avira and it says the tab's clean, and I also checked the running services, but I don't see anything out of the ordinary.
I'm wary because a few days ago I got a notification that my tablet had a virus *eyeroll* and when I tapped it it went to a 'download antivirus here' page which of course I didn't click on...
Thanks.

It must be an app with notification ads...try to recall which apps you installed recently and uninstall it...you problem should be solved...
Sent from my GT-S5830 using xda premium

Do you use Swiftkey, by any chance? I got the exact same thing happen this morning and I think that's what it was. I closed the notification anyway without entering my details and found that I had to go through a setup process with Swiftkey because it had just been updated. Not had the notification since.

AppBrain Ad Detector should find the malicious app

Related

addon detector

Hello All
Still kinda new with the Android OS, I have recently experienced some strange icons on my home page, anyway, it seems that a lot of spam (I'm just guessing) comes with DLd stuff.
So I DLd a app called addon detector and I'm not exactly sure how to use it so does anyone know how to use this app? I ran the scan function but I still got a unwanted icon so theres evidently more to this then just running a scan
Anyway, all help is greatly appreciated!! Thanks
https://play.google.com/store/apps/...SwxLDMsImNvbS5kZW5wZXIuYWRkb25zZGV0ZWN0b3IiXQ
n2bowling said:
Hello All
Still kinda new with the Android OS, I have recently experienced some strange icons on my home page, anyway, it seems that a lot of spam (I'm just guessing) comes with DLd stuff.
So I DLd a app called addon detector and I'm not exactly sure how to use it so does anyone know how to use this app? I ran the scan function but I still got a unwanted icon so theres evidently more to this then just running a scan
Anyway, all help is greatly appreciated!! Thanks
https://play.google.com/store/apps/...SwxLDMsImNvbS5kZW5wZXIuYWRkb25zZGV0ZWN0b3IiXQ
Click to expand...
Click to collapse
Download Airpush from the market. Run it. It will tell you what app is the problem and you can choose to uninstal it
Sent from my SAMSUNG-SGH-I717 using xda premium
After you run a scan select the "Addons" button. In the filter box above select "Push Notifications". This will tell you the apps pushing notifications to your notification bar. You will need to uninstall the causing app.
The other filters will meen very little to most.
Now strange icons on your home page is something totally different. Tell us about these icons.
Install an app called Airblocker. It will block all airpush ads without having to uninstall anything.

Screen turns on by itself...

Hi,
I've noticed in the past couple of days that my screen turns on by itself for about 3 or 4 seconds.
Phone information in picture attached.
On the weekend I did an OTA update via Kies, on Wednesday I flashed This Kernel (SpeedMod S3) via Odin.
Anyone got any advice?
Thanks for your help
this usually happens when u have a certain app or a live wallpaper that does advertise on your phone ... try removing some apps that are for free but ad-supported or remove some live wallpapers and it should go away
Yeah thanks "striving-to-survive", I had noticed some notification adverts since the OTA update. I haven't added any apps. Unless its an app I updated. "AirPush Detector" used to tell me what was sending those notifications, however that detects nothing when I scan. Can anyone recommend something that does a similar job that might tell me where the notifications are coming from? I don't fancy just deleting a bunch of apps on the off chance they are the offender.
I do not think it is kernel related.
Download adfree and run it.
Also here in xda search for the app called
"Anti spy mobile free"
Sent from my GT-I9300 using xda premium
I wasn't sure if it was kernel related, just wanted to give as much info as possible about what I had done recently with my phone.
I have Ad Free, but just realised I hadn't hit the "download and install hosts" button since my OTA update.
I got Anti Spy Mobile Free, after scanning that said I have no spywares, 4 suspicious apps: Contapps, Phone Backup (HChina), ooVoo & MyBackup Pro. None of which I think would be responsible.
Hopefully Ad Free will sort it out.
Thanks for your help
Same issue for me with stock fw and kernel. I have a battery brain since two days and I can see my screen on time up to 4 hours per day without using my phone.
Lowyo said:
I wasn't sure if it was kernel related, just wanted to give as much info as possible about what I had done recently with my phone.
I have Ad Free, but just realised I hadn't hit the "download and install hosts" button since my OTA update.
I got Anti Spy Mobile Free, after scanning that said I have no spywares, 4 suspicious apps: Contapps, Phone Backup (HChina), ooVoo & MyBackup Pro. None of which I think would be responsible.
Hopefully Ad Free will sort it out.
Thanks for your help
Click to expand...
Click to collapse
Update your hosts then and keep an eye on it. Check for hosts daily
Sent from my GT-I9300 using xda premium
I have similar issue. My phone also turns screen on by itself, but it looks like it stays on until I turn it off. This have happened about 4 times during week or two...
I have tried AirPush detector. Didn't find anything.
Anti Spy Mobile found 0 Spywares and 2 Warnings. Light Flow Lite and TrustGo Security. I have had Light Flow Lite for a long time, so I doubt it can't be it. TrustGo is quite new, but I think it's trusted app. Could it be the reason..?
AdFree is working and I don't see ads.
What should I try next?

[Q] Air Push Notification issue

Hi guys,
I'm new to SGS3, not new in Android world though.
I'm having air push notifications (in Chinese language) pushed to my new SGS3 device.
I already tried several Air Push detecting applications (AdAway, Addons Detector, AirPush Detector, Avast) but all of them finds nothing.
I had similar problem before on my old HTC and AirPush Detector would show me the guilty app.
All I did since I bought the phone is flashing the latest UK 4.1.1 Unbranded stock ROM through Odin, factory reset, and rooted it using CF-Auto-Root.
Any ideas what could possibly cause this?
Thanks in advance.
Well, in case anyone else have this problem, here is the solution...
Next time you get air push notification long tap on it in notification dropdown until you get "App info" popup, click on it and you will know the guilty app.
Mine was some game, that none of air push detectors detected it for some reason.
Sent from my GT-I9300 using xda premium

[Q] Still Getting Ads Pushed to Notification Even After deleting Airpush Apps?

I am still getting ads pushed to my notification bar even after I deleted all the apps which are using Airpush. How is this possible?
I've tried several Airpush detector apps including 'Airpush Finder' (which found that 2 GoSMS themes had Airpush, so I deleted them). Now there is 0 apps detected using Airpush...however I am still getting ads in my notification bar. The latest one was something like, "40% OFF SALE FOR 100th...Redefine your phone with this 3D Launcher..."
I suspect its coming from the new version of Go Launcher EX which I recently updated, but I have no way to verify it since nothing is being detected. Could it also be some bit of code left on my phone from the previous airpush apps which I deleted? I don't know where its coming from. Please help.
Zoracay said:
I am still getting ads pushed to my notification bar even after I deleted all the apps which are using Airpush. How is this possible?
I've tried several Airpush detector apps including 'Airpush Finder' (which found that 2 GoSMS themes had Airpush, so I deleted them). Now there is 0 apps detected using Airpush...however I am still getting ads in my notification bar. The latest one was something like, "40% OFF SALE FOR 100th...Redefine your phone with this 3D Launcher..."
I suspect its coming from the new version of Go Launcher EX which I recently updated, but I have no way to verify it since nothing is being detected. Could it also be some bit of code left on my phone from the previous airpush apps which I deleted? I don't know where its coming from. Please help.
Click to expand...
Click to collapse
When an add is displayed in your notification bar, press and hold it.. then it will show the 'App info' option.. click on that and then you will come to know which app is pushing these ads..
Bro firstly sorry if i mistake noemal ads with airpush ads i really dont know d diff btwn dem but if ur rooted then try using host file to block ads
Gooe mother of adblocking and the first link of xda will guide u further....hope im of help to u
Pm me if need any help
Sent from my Cynus T2 using xda app-developers app
Thanks for these 2 quick replies, heres some more info: I am not rooted and I am using Gingerbread 2.3.6
I tried long-pressing the ad as amith007 suggested, but nothing happened.

[Q] Help Leadboltads virus on Galaxy S4

Hi All
Since a day I have a sort of leadbolt virus that opens my browser and shows the website like below:
ad.leadboltads.net with Top Apps/Offers of the Day
This happens when I download something from the playstore or when I delete apps.
It Makes crazy and I have tried some things alrdy so fix it without any succes.
- Downloaded and installed virusscannen, no succes
- Downloaded and installed ad detector, found a app with leadbolt, deleted it but didn't solve the problem
Hopefully someone can help me too fix this annoying problem
Me too!!!
This is so annoying! My browser keeps opening to the leadbolts site with a bunch of apps on it....Please someone help!
+1. From where come this shlt ?
Shaundiesel said:
Me too!!!
This is so annoying! My browser keeps opening to the leadbolts site with a bunch of apps on it....Please someone help!
Click to expand...
Click to collapse
I'm also having the problem and have not found a solution yet.
The only difference for me is I have adaway installed so the webpage never gets to display. Just opens the browser.
I've tried different ad detector apps from google play, but nothing is fixed this problem. Almost ready to reflash the rom and start from scratch.
UPDATE: I fixed the problem.
When the browser hijacking occurred, it happened after installing or updating a program from any source. Google Play, Amazon or a standalone APK. That meant the virus had control over my installer.
Using Lookout's Ad Detector, I identified some potential culprits (Go Launcher EX being at the top of the list) and uninstalled them. That didn't work.
What actually fixed the problem was resetting the defaults for all the apps. Settings > More > Application Manager. Hit the menu key and choose Reset app preferences.
You don't loose any data. You just get prompted for choosing a default app when you run certain applications. I choose to use Lookout's installer instead of the default android installer when I got prompted to install updates.
Haven't had the issue since. Hope this helps.
markmi300 said:
What actually fixed the problem was resetting the defaults for all the apps. Settings > More > Application Manager. Hit the menu key and choose Reset app preferences.
You don't loose any data. You just get prompted for choosing a default app when you run certain applications. I choose to use Lookout's installer instead of the default android installer when I got prompted to install updates.
Haven't had the issue since.
Click to expand...
Click to collapse
Hi everybody. (First sorry for my english but I speak french)
This is a solution but it workn't very good.
After the downloading and installation from a update or a program, Androîd ask me if I want to finish the task with the default browser or Chrome ? So I can't see this f*cking page more but I must always put my choice between the 2 browsers.
I thank you for your solutions....
+1 to lookout fixing. Had the same problem, ripped it right out.
Sent from carbon note 2 on XDA premium app
shbaldw said:
+1 to lookout fixing. Had the same problem, ripped it right out.
Sent from carbon note 2 on XDA premium app
Click to expand...
Click to collapse
Glad I was able to help.
See the solution at
http://forum.xda-developers.com/showthread.php?t=2525965
#@!%&#! 'ad.leadboltads.net' Malware
shbaldw said:
+1 to lookout fixing. Had the same problem, ripped it right out.
Click to expand...
Click to collapse
Lookout Security & Antivirus found mine in ChargeBar Free Edition,
ChargeBar came embedded in the NottachTrix 2.3.0 ROM.
I installed it (NottachTrix) and it (ChargeBar) didn't update for 3 months, then, BANG.
I've deleted ChargeBar's update, moved it from system apps to apps, deleted it, and the browser pop open 'ad.leadboltads.net' still persists.
Lookout Security & Antivirus can not find the new location of the malware, they do not have a forum.
By the very definition and behaviour, this is malware, and, ChargeBar (Asgard Casino Apps) is involved in the distribution of malware.
Asgard Casino Apps distributes 34 apps that behave this way.
They are using Google to distribute this malware, abet, that app is benign in its origin, its a pipeline, or conduit for malware.
Sneaky F##kers aren`t they.........
#1) I would like to get this crap off my phone.
#2) I need to bring this to Google's attention, and have the developer and apps banned from the Play store.
Sooo, starting with #1,,,how do I get this crap off my phone!
NOTE:
I will be linking to this post in the NottachTrix post, I'm asking the developers to to move ChargeBar from the ROM zip.
My MBAM forum post: https://forums.malwarebytes.org/index.php?showtopic=138306#entry764184

Categories

Resources