Need some advice around malware/viruses on android - Android Q&A, Help & Troubleshooting

Hello,
I've been looking around for an application that tracks application installs.
Especially for malware installs.
Let me explain the situation:
I've got a smartphone with installed apks (all legal from the playstore)
After a while I am trying to find out what problems are causing some random ad popups (about dating for those who are interested) it's caused by an apk called recents.
I always delete that program. But it seems that it reinstalls itself, every now and than.
also since today I've got an shortcut on my main screen that is called coobrowser (not coolbrowser although it has the same icon image, tried to find out where it came from but I can't find an apk either)
I know some applications:
os monitor is a good one though it doesn't accomplish my needs. (I can see the connections but there it stops)
Catlog doesn't make me any wiser
I hope someone know what I'm talking about and has this kind of application in reach.
TLDR: In need of an application install tracker that monitors which applications open a port for another application install (read malware)

I have the same issue with my phone.
When I clicked app info it turned out to be called trebuchet.
What type of phone do you have?

Yes exactly that's what I get too,
Jiayu S3

That is built into their os. It is made to reinstall if it detects it is Uninstalled. It's not an app that is doing it but the OEM of the device. It is known that many of the Chinese devices do this to counter the cheap prices of the device. Your only option would be to build an aosp based rom if you can.

jerrefurtor said:
Yes exactly that's what I get too,
Jiayu S3
Click to expand...
Click to collapse
I've got the same phone and the same issue started to appear recently. First the "recents" app, now the "coobrowser". The orginal Trebuchet icon is gone. Not sure if this is a virus or feature from JiaYu. How to tacke this without crafting my own ROM as mentioned?

jediz said:
I've got the same phone and the same issue started to appear recently. First the "recents" app, now the "coobrowser". The orginal Trebuchet icon is gone. Not sure if this is a virus or feature from JiaYu. How to tacke this without crafting my own ROM as mentioned?
Click to expand...
Click to collapse
Yeah I've managed to remove recents (since this was causing random ad popups)
I've got the exact same problem. Just want to know how to track it down

I can't see any other option than installing a different ROM, because the stock one is strange regarding security. For example every reboot resets "install apk from unknown sources " to YES, which is fishy. Bye bye stock rom, I liked it at the beginning but with these issues I am forced to switch.

jediz said:
I can't see any other option than installing a different ROM, because the stock one is strange regarding security. For example every reboot resets "install apk from unknown sources " to YES, which is fishy. Bye bye stock rom, I liked it at the beginning but with these issues I am forced to switch.
Click to expand...
Click to collapse
I've just noticed they have published the official rom for android 5.1 http://www.needrom.com/download/17-09-android-5-1-for-the-jiayu-s3/

I decided to avoid the official ROM as the problems I experienced were with the previous official ROM. I went for the "rom-xtreme-rom-tf"
So far so good, but don't you try to uninstall the Google Now app from android 5, I was unable to boot doing so.

Related

[Q] What's wrong with my phone?

I've recently been experiencing a series of pop-ups in an Android dialogue box occasionally when I click links that I know are clean.
A lot of them are dialogue boxes that say "Congratulations, your US number has been chosen for a gift - press the OK button to continue"
and the only way out is to either press the Okay button or force stop the browser.
The browser it most recently happened with has been with Dolphin Mini browser - can't remember if it occurred through my Android's native Internet browser or not, either way it takes me to a site called Mobgifts(dot)org
I did some research and some said it was a virus, but I have Lookout installed on my device and scan it weekly and just did a scan yesterday - all was clean..
TL;DR: Internet links in browser lately have been unescapable diallogue boxes that say "Congrats you won this" and you have no other options than to either force quit or press Okay then exit
What are your takes on my issue?
Btw - phone is stock, non rooted, hasn't ever been rooted.
Ok it seems your pop up blocker is disabled
i dont know wich browser u´re using so try to find something like that in the preferences of the browser
if it doensnt work go to settings applications head to your browser open the dialog box and delete all app data (dont uninstal it!!)
If this doesnt work try another browser
What pages are you visiting when the popups are there
jiffer1991 said:
Ok it seems your pop up blocker is disabled
Click to expand...
Click to collapse
My Phone is completely stock - no rooting so no popup blocker
jiffer1991 said:
i dont know wich browser u´re using so try to find something like that in the preferences of the browser
Click to expand...
Click to collapse
I'm using Dolphin Mini browser
jiffer1991 said:
if it doensnt work go to settings applications head to your browser open the dialog box and delete all app data (dont uninstal it!!)
Click to expand...
Click to collapse
I've done that, cleaned it all out, I have Lookout installed, but as I stated, nothing is being picked up by it
jiffer1991 said:
What pages are you visiting when the popups are there
Click to expand...
Click to collapse
It's happened on various pages, some links to Imgur (image hosting site), and then this time it happened on Vimeo.
I'm getting the same on my Cappy whenever I try to come to XDA. I just loaded Serenity Rom on the phone, haven't added any apps that I didn't have when I was on Cognition (other than BLN and Avast, in an attempt to see if the phone is virused. It's not. Supposedly).
I am royally pissed about this. I've had this phone for two years, most of it on some form of Cognition, and never had a problem. I literally can't imagine how these popups have wormed their way onto my phone--and for me, at least, what browser I use doesn't matter. Sooner or later, that damned popup shows up, and there's no way out of it except to FC the browser.
Looks like I'll be stripping the OS back to stock and starting over again, unless someone can suggest a solution beyond "turn on your popup blocker", since it's never off.
NOT happy.
I seemed to have found a solution - and from what I was told on AndroidForums on a thread post - its more of an AirPush issue - meaning its an advert through an app that has been installed,
I just scanned with Lookout and Norton and nothing was out of place or infected.
I also posted to Reddit's Android Community to see what they thought. I'm awaiting their opinions.
Getting the same popup from mobgifts.org for only the last couple days. Googling it get almost nothing. It doesn't seem to have a pattern of coming from any particular website.
I did as others have said and FC'd. I even accidentally clicked on OK once and it seemed to do nothing but except close the popup box, it didn't take me to a new website, etc.
Experiencing a similar problem, but so far, it doesn't seem like anyone has come up with a solution. It could very well be an app that is using the most obnoxious ads ever, but I've used both Airpush Detector and Lookout's Ad Network Detector and both come up empty.
I know that the ad network is BlueAds.com and they keep changing the URL of the gift site. It has been mobilewinner.org, mobilevisitor.org, rewardstoday.org, mobprizes.com and now mobgifts.org.
Has been happenning on my tab as well.. Mainly on xda. My phone hasnt had any problems yet. Quite annoying i must say. Hope someone can shed some light as have gona through all the apps with no luck.
In light of the situation came an email from Lookout!
Hey everyone, I just wanted to post this here - a conversation I had with the Lookout security team about the whole situation, perhaps this might bring some ease to some of you.
Enjoy
alex.ap.pacman said:
Hey everyone, I just wanted to post this here - a conversation I had with the Lookout security team about the whole situation, perhaps this might bring some ease to some of you.
Enjoy
Click to expand...
Click to collapse
can you cut and paste the actual text from the mail - opening up the image its too blurry to read
thanks
alex.ap.pacman said:
Hey everyone, I just wanted to post this here - a conversation I had with the Lookout security team about the whole situation, perhaps this might bring some ease to some of you.
Enjoy
Click to expand...
Click to collapse
Don't know about anybody else but I can't read the text in that image, could you provide a larger version or copy & paste the conversation?
I just started getting this on my phone. Coincidentally it had never happened prior to me putting the Pure ICS ROM on my SGS2. Here's my timeline if it helps:
• Stock ICS ROM (O2 UK)
• Sunday - Backuped up and Flashed FOXHOUND ICS ROM
• Tuesday Morning - Factory rest, wiped cache/dalvik cache and flashed Pure ICS ROM
• Tuesday Afternoon - Restored app backups via Titanium
• Tuesday Night - Started noticing mobgifts(dot)org hijacking my browser(s)
I say mobgifts(dot)org is hijacking because it happens on the stock browser, ICS Browser+ (my current fav) and dolphin. It is also not appearing as a popup but rather loading in the current browser tab.
It's hard to diagnose because I can't make it happen, but it seems to be overriding some hyperlink clicks. As others have said, it seems to happen most often when I'm on xda-developers.com but then that could be because I'm on these forums a lot right now.
I've run Addons Detector, AirPush Detector, TrustGo Antivirus & Mobile Security, Comodo Antivirus Free, Lookout etc. All have come up with nothing. So, assuming all these Android anti-virus/malware scanners aren't just a load of rubbish it only really leaves either something in the Pure ICS ROM or malware in one or more of the sites I visit?
Would really love it if that image was big enough for us to read. This scam ad thing is killing me.
AndySX said:
Don't know about anybody else but I can't read the text in that image, could you provide a larger version or copy & paste the conversation?
I just started getting this on my phone. Coincidentally it had never happened prior to me putting the Pure ICS ROM on my SGS2. Here's my timeline if it helps:
• Stock ICS ROM (O2 UK)
• Sunday - Backuped up and Flashed FOXHOUND ICS ROM
• Tuesday Morning - Factory rest, wiped cache/dalvik cache and flashed Pure ICS ROM
• Tuesday Afternoon - Restored app backups via Titanium
• Tuesday Night - Started noticing mobgifts(dot)org hijacking my browser(s)
I say mobgifts(dot)org is hijacking because it happens on the stock browser, ICS Browser+ (my current fav) and dolphin. It is also not appearing as a popup but rather loading in the current browser tab.
It's hard to diagnose because I can't make it happen, but it seems to be overriding some hyperlink clicks. As others have said, it seems to happen most often when I'm on xda-developers.com but then that could be because I'm on these forums a lot right now.
I've run Addons Detector, AirPush Detector, TrustGo Antivirus & Mobile Security, Comodo Antivirus Free, Lookout etc. All have come up with nothing. So, assuming all these Android anti-virus/malware scanners aren't just a load of rubbish it only really leaves either something in the Pure ICS ROM or malware in one or more of the sites I visit?
Click to expand...
Click to collapse
Its not just ics roms as it happens to me on my stock unrooted tab 10.1 running honeycomb 32. As you said its not a tab and it disables the back button requiring closing and opening a new tab
Not Malware or anything to worry about - marked as solved please
vsniperii said:
Its not just ics roms as it happens to me on my stock unrooted tab 10.1 running honeycomb 32. As you said its not a tab and it disables the back button requiring closing and opening a new tab
Click to expand...
Click to collapse
Like I said guys, it's strictly adware - use Lookout's Ad Network app off the Play store, I would link it but unfortunately I don't have enough posts to do that yet.
- It isn't malware or any form of trojan - its advertising, Someone brought up that it wasn't AirPush but a different company instead.
Hi Alex
I'm not sure it is adware. It seems to be just a Javascript alert dialog box. Because users don't always realise that, they assume that clicking OK is going to start a download or something. As far as I know, it should be just fine to accept the OK then hit the back button etc. It certainly gave me a fright the first time I saw it!
It looks like we're ending the golden age of mobile browsing. I remember a period on the desktop about 15 years ago when you couldn't block popups, and one malign website could completely ruin your afternoon. Hopefully we're not going to go through a similar phase with mobile computing....

Weird issue with Settings / Applications Manager

I have tried most of the JB Roms for the Galaxy S3, trying to see what would bother me less in every rom as a missing or not working feature.
I am facing the same problem with almost all roms (but not with all).
As soon as I bring back my applications and data through Titanium backup (never restoring the system files of course) then when I go to Settings/Applications Manager and try to scroll through the installed applications it always freezes and I get the message "Unfortunately, Settings has Stopped" and I get back to home screen.
As I said I did not had the problem only with a couple of roms (not remembering which ones though) but having it most of those I flashed.
All the roms have always been flashed on totally blank mediums since I have always used full wipes (tried to reflash a couple of them on top just to see if this would fix the problem but it did not)
Note that all applications do scroll normally and very fast in other programs also listing the installed applications, either through Titanium Backup or even in the drawer where all apps literally fly when scrolling.
Any help or advice would be greatly.
Does it work ok before you restore apps from Titanium Backup? If it does, try just restoring the apps one at a time and testing after each one. I suspect there's a duff application in there that's been restored, and that's causing the problem
Alternatively just reinstall the apps from the Play Store rather than using TB.
Thank you anthropolyte, man you are fast.
Thought of many things related to JB (because up until v4.0.4 I did not have this issue with - almost - the same applications installed) but I did not think for a moment that a specific application could be the issue. I will re-flash the rom later today and try it your way.
I will report back in case someone faces the same issue.
You're welcome - good luck!
Dear jsfero, did you manage to solve that problem? I'm just facing the same. Firstly I thought it was due to blackm* app but after uninstall it nothing changed. Then I thought it may have to do with apps in drawer showing the same name. Then I kept one and uninstalled the other. Nothing changed. I'm just a bit bored with this situation. My only difference is that I occurred to me also with ICS, not only with JB or CM10.
Could you provide me with some light about this issue?
Many thanks in advance.
Zentenario said:
Dear jsfero, did you manage to solve that problem? I'm just facing the same. Firstly I thought it was due to blackm* app but after uninstall it nothing changed. Then I thought it may have to do with apps in drawer showing the same name. Then I kept one and uninstalled the other. Nothing changed. I'm just a bit bored with this situation. My only difference is that I occurred to me also with ICS, not only with JB or CM10.
Could you provide me with some light about this issue?
Many thanks in advance.
Click to expand...
Click to collapse
Unfortunately, after having tried almost everything from re-flashing to re-downloading all my apps, I could not manage to find out the source of this problem.
It is only just by accident that I found out that a couple of ROMs are not causing any problem and the phone works perfectly well. The one I do remember and I do use now as my main daily usage ROM is the one from Sotmax.
Now, I don't know if this problem is the outcome of a 'bad' combination or bad coexistence of certain programs from kernel or Rom, all I know is that my exact same Titanium back with over 300 apps is the same one I tried on all the Roms so I doubt that the problem is coming the applications side. It was always as if the amount of applications / data was too high for the Roms to handle and crashed the application. And all the sudden one day, I simply realized that with Sotmax's Rom and same applications installed via Titanium did not cause any problem or malfunction.
I even changed kernels, from stock to Siyah and now Perseus, the problem seems to be gone for good with this Rom. I am sure that I must have found a one or two other Roms which did not cause the problem either, unfortunately I did not like them that much to keep them and remember which one they were.
HTH
I had the same problem as well unfortunately, also couldn't access App info/app size
Had to uninstall some apps, then reinstalled them again
But I can't install broken Sword without getting the problem again
Sent from my GT-I9300 using xda premium
Yes, I can confirm that Broken Sword game causes App Info to crash. Another one that I found is from Samsung Apps called "Catch The Monkey". Troubleshooting this was time consuming as I had to uninstall each app in the sequence (refering to appbrain.com which has the sequence of apps I installed from Google Play) and keep testing whether App Info crashes or not.

Battery life (wakelock), Amplify, SD Maid, Auto Call Recorder, Chrome, APUS Launcher

Hi,
This is my first time specifically posting a question as a Q&A style thread so I hope I'm doing this right.
I have been using the Redmi Note 2 for about a month now. Overall, it's been a great phone (especially considering the price). However, I've been experiencing a couple of issues and I am hoping that some of you may be able to help.
I have rooted the phone but have not installed a ROM/kernel.
I have been using Wakelock Detector to track my battery life. Of most significance is com.baidu.map.location (NetworkLocation). I have attached the two screenshots showing the frequency of how often it wakes up my device. I tried to greenify it but it wouldn't allow me - it says "Sorry, "NetworkLocation" is ingreenifiable". Does anyone have any idea for me?
I have also been trying to use Amplify as another means to try and improve battery life. As mentioned, my phone is rooted, and the app prompted me to install the Xposed app which I did. However, after installing the app, it wants me to install the framework but it does not allow me to. I have attached the screenshot of this too.
Nova Launcher - Sometimes when I open the app drawer, the resolution of the app launcher appears funny. To fix it, I normally just press back and go back into the app drawer and it goes back to normal. I have attached a screenshot of what this roughly looks like. This is not a big deal but can be a little annoying. Has anyone experienced this?
SD Maid - I used to use this app on my old Galaxy S3 i9305 to clear out storage space taken up by unnecessary stuff. This app no longer works on this phone. I have attached a screenshot of the issue that I am having.
I have downloaded Auto Call Recorder from the app store with the intention of having it automatically record my phone conversations. It does not work but I am unable to figure out why. I have checked the settings and I cannot identify any obvious setting that is incorrectly configured.
Flynx - I have been trying to use Flynx as it appears to be an incredibly useful app, but it seems something is not working correctly. In the screenshot that I have attached, where it says "Tap on the bubble to open it!" I am assuming there is a bubble that is supposed to appear for me to tap, but it does not appear.
APUS Launcher/Clean Master - finally and maybe most worryingly, I sometimes get 2 or 3 apps "pushed" to my device prompting me to install it. I can only remember 2 at the moment; APUS Launcher and Clean Master. Fortunately, I am asked to give the app permission for installation but it worries me because it has occurred a few times and I did not download it at all. I do not have a screenshot of this at the moment, but I will do it next time it occurs.
I have been told that my provider (Vaya in Australia) sends out a SMS for "automatic update" purposes. I only spotted this because I have noticed that I was charged for 2 separate international SMS on 2 occasions when I did not send them (to a UK number, +44 7786209730). I am not sure whether this one is a phone problem or something else.
I appreciate any of your assistance in advance and I am sorry if I have not provided enough information. I am also not sure as to which issues may simply be app problems as opposed to a problem with MIUI software or Xiaomi.
Hope I will be able to get some assistance!
SD Maid - I used to use this app on my old Galaxy S3 i9305 to clear out storage space taken up by unnecessary stuff. This app no longer works on this phone. I have attached a screenshot of the issue that I am having.
Click to expand...
Click to collapse
Does the crash happen when the dialog opens, or when you click the orange entry?
Try giving your sdcard a name, possibly doing it from a desktop computer.
Hi, the crash happens when I click on "Overview" then click on "To start press [refresh icon]" and then you just press there - what normally happens is it will give a overall summary of the phone.
However, I have just tried it again. When that error message comes up, instead of tapping on the listed entry (as is instructed), I press "Done" and it is able to give me a summary!
So for some reason it appears as though it doesn't work (at least from the error message), and I just press done and it still works.
Thanks for your reply nevertheless! Would not have figured that out had you not replied hahaha.
If you just press "done", SD Maid won't have access to your external sdcard.
Did you try installing the Xiaomi EU rom, since it's supposed to be cleaned from chinese apps (Like the baidu one).
Hi all,
Sorry it seems like I never came back to expand what I have done to try and fix these problems.
I ended up changing to Hermes ROM here http://www.smiui.net/redminote2_hermes.php
Most of the issues above are now solved, but there are some that are still present such as #2 and #5. So Amplify still doesn't work, but I think this is a hardware limitation and Auto Call Recorder still doesn't work. As for why Auto Call Recorder doesn't work, I don't know why, but I am not greatly bothered by it so I have not attempted to do anything to resolve that problem.

The strange case of recurring malware

Ok first let me tell you guys that i have never seen this problem before and all of a sudden TODAY I saw it in two unrelated phones, one huawey ascend 530 something , and the other one a no brand chinese dual sim note 3 or note 4 knockoff , bot phones where stock , and users dont even know what rooting is, let alone custom roms.
The problem was popups , lots of them , some with pr0n ads, others with "security software" ads, some more for games, this popups started as soon as the phone booted, no need to enter a browser or app at all, then it started downloading some more apps with weird names (weird as apparently random garbage names), and some other apps for coupons, games, launchers etc, tons of crap, every time one finished downloading it was asking for which method to use for installation :google verification or something else I think "package installer" that i don't remember now, but that I know both are legit apps from android to install stuff, of course I said no every time but it just kept asking so I figured I will factory reset this because I have no time but he is a friend so I need to help him, but have not much time so I thought that was the best thing to do.
WRONG, after factory reset (from settings menu) popups where still there, so I just figured I would do it from recovery screen, and I did, ... surprise, popups still there and also the downloading notifications of more unknown apps, as I said before some of them had names like games or security software, other were just random gibberish, sometimes an app with chinesse name crashed (force stop) , when I saw that the first time I immediately knew it was some chinesse malware crap, ok I guessed maybe the sdcard had something sticky on it , hidden partition or something, so I removed it, and reset again, ... problem persists, oh and let me tell you, this problem showed up immediately after boot, I didn't even have the chance to register a google account, so crap was not coming from a google sync data or or synced apps or browsers or something , well then I had the idea of turning off the wifi and see if they stop, some of the popups opened browser pages and other popups just opened by themselves as if it was from an already installed app.
results: the damn thing turned wifi ON by itself to keep downloading their ****y apps, so I just deleted the saved wifi networks, and the damn thing started using the mobile data to keep doing its stuff (it even turned data on).
There was only one 2 things left to do, either try to root the phone and dive in the apps to try and remove any suspicious ones, or reflash with stock.
Well I had to leave by that time and told my friend i would like to help him, but it would have to be some other time, coz I know how hard it is to try and find a rom for an unknown chinese manufacturer even if I find one, trying to figure out the links in chinesse pages I doubt it would be an exact match (had done that before, so I know its difficult and takes many hours of your time) it had JB on it.
Then I arrived to work and a coworker asked if I could help him , it was a Huawei ascend G527-U081. exact same symptoms and behavior, ok so again I did factory resets blah blah erase sdcard etc etc, same results malware persisted, but in this case, it took me less than 5 mins to find the stock rom at huawey support page, downloaded it, did update via sdcard, and VOILA FIXED.
So someone who knows more about how could this infection happen can take some time and try to explain me?
My uneducated guess is that some side-loaded app or downloaded app from the webpages ads or something like that got ROOT access to the phone internally or even rooted the phone with their own root renamed app, and somehow put themselves in the system partition or the place where the factory apps are installed from, i guess that's why only a full flash fixed it.
Could that be it?
I hope no one here gets that crap, I have never had any malware in any of my phones and I am even surprised and wonder what people can possible do to get infected that bad, lol, I don't think I could even on purpose, but then again, having an adaway app takes most of the dangerous ads away so no risk clicking them by mistake.
Hi,
By any chance did you save the apks that were the cause of this as I would like to decompile and test them under a VM maybe we could take them offline or attempt to get a warning out there.
BioT3rm said:
Hi,
By any chance did you save the apks that were the cause of this as I would like to decompile and test them under a VM maybe we could take them offline or attempt to get a warning out there.
Click to expand...
Click to collapse
I didnt find out wich apps were the cause of this, it was to many apps trying to install themselves and one popup after another from different apps.
the chinese phone still has all the crap, i wouldnt know what to give you from it
arana1 said:
I didnt find out wich apps were the cause of this, it was to many apps trying to install themselves and one popup after another from different apps.
the chinese phone still has all the crap, i wouldnt know what to give you from it
Click to expand...
Click to collapse
I thought as much but this is the second time I've seen someone post something similar, brand new install on the phone or factory reset and mileage downloading apps, I do believe this could be a new malware out of China.
This is a common thing with Chinese devices. They mostly contain malware. This is why China based devices are not big with most of the world.
If is built into their os. You can't really remove it.
arana1 said:
I didnt find out wich apps were the cause of this, it was to many apps trying to install themselves and one popup after another from different apps.
the chinese phone still has all the crap, i wouldnt know what to give you from it
Click to expand...
Click to collapse
To my knowledge it's the one app "pornclub" that installs all those junk applications. This app somehow access the root on non-rooted phones and reinstall automatically even if you hard reset the phone. Removing this app after rooting may be helpful. This malware also appeared in ASUS Nexus tablet and other phones. So it is not linked to some specific make. People who download apps from third party sources should be careful and get them only from sites which display hash info for play store apps. Besides avoid downloading junk porn apps.
I also have a similar malaware on my note5. I did a factory reset and when I checked my chrome I had no ads but when I reconnected to my Internet I instantly started downloading galaxy apps and when I checked my chrome again I had a ad by mgid again.
---------- Post added at 04:04 PM ---------- Previous post was at 03:38 PM ----------
I scanned my phone and it said s health was a threat
Did anyone find a fix to this? Does a FW update help?
rhri3 said:
Did anyone find a fix to this? Does a FW update help?
Click to expand...
Click to collapse
I fixed the huawey "updating " to the same rom version it already had, ie full flash,
i read that there are some utilities and av cleaner in google play sstore that get rid of this, search for pornhub cleaner
arana1 said:
I fixed the huawey "updating " to the same rom version it already had, ie full flash,
i read that there are some utilities and av cleaner in google play sstore that get rid of this, search for pornhub cleaner
Click to expand...
Click to collapse
thanks for the reply. I'll try flashing the existing ROM again and see if I get rid of it. There's also some info on that on https://blog.avast.com/2013/10/23/no-pleasure-from-this-adult-app-only-pain/
edit: It worked! I flashed the same ROM on the phone again and now the phone responds fast again.
Which AV/anti malware app would you recommend to avoid this incident in the future - and I don't want thousands of other apps that come along with it (battery saver etc.)?
rhri3 said:
thanks for the reply. I'll try flashing the existing ROM again and see if I get rid of it. There's also some info on that on https://blog.avast.com/2013/10/23/no-pleasure-from-this-adult-app-only-pain/
edit: It worked! I flashed the same ROM on the phone again and now the phone responds fast again.
Which AV/anti malware app would you recommend to avoid this incident in the future - and I don't want thousands of other apps that come along with it (battery saver etc.)?
Click to expand...
Click to collapse
Actually I use NONE, the problem was not on my phones, I just dont install anything that doesnt come from trusted sources , be it development forums like this , or play store, or other well known pages, what I do USe is an adblocker, most of this malware comes from popups that suggest you install something else, well with adaway i get rid of most of that and have never had malware on any of my phones
hi i am having a same problems which u've mentioned above. ive tried factory reset ,erasing sd card, reboot and all but it doesnot remove totally from my phone.can anyone tell me how to fix this problem and get rid of this malicious app and virus.
I have same problem, i tried malwarebytes and the following was found backdoor.triada.js, trojan.rootnik.ab, trojan.agent.gc, trojan.sivu.rn, trojan.sinu.c, and bct_service app. I click delete and reboot my phone still not remove.
I've had this problem for a few months, but it was mostly controllable. I was too lazy to fix it, but I have a bit of knowledge about it now.
I got this when I tried installing a hack mod for a dead game. As far as I can remember, the "bad apps" were netalpha, catstudio(these two can only be disabled), com.google.keyguard, and com.android.gesture.builder (there were more, but I can't remember them). Some of the apps that get downloaded are Lazada, Zalora, Battery saver, Apus, Heathstone, 2048, and Township. I also factory reset my phone a few times, and the apps either lessen or increase...
My phone is also Huawei, so I'll just try updating the rom.
Thanks for the info ^^
kitaro11 said:
hi i am having a same problems which u've mentioned above. ive tried factory reset ,erasing sd card, reboot and all but it doesnot remove totally from my phone.can anyone tell me how to fix this problem and get rid of this malicious app and virus.
Click to expand...
Click to collapse
The only way that solved this problem was to reinstall the ROM trought recovery.
reboot phone to remove malware trojan
Hi I been racking my brain trying to fix my phone with similar issues. On Monday 5/11/17 after doing a update the viruses took over the phone , I have are Trojan Triada and Slocker Back door Ransomware and another viruses I cant remember , I did the same steps you mentioned and nothing. So my last 2 options are the same.. Is it hard to flash a LGG3 att version , or will rooting the phone and manually remove them... i AM SO GLAD I FOUND YOUR POST :angel: Thanks.
edpinal72 said:
Hi I been racking my brain trying to fix my phone with similar issues. On Monday 5/11/17 after doing a update the viruses took over the phone , I have are Trojan Triada and Slocker Back door Ransomware and another viruses I cant remember , I did the same steps you mentioned and nothing. So my last 2 options are the same.. Is it hard to flash a LGG3 att version , or will rooting the phone and manually remove them... i AM SO GLAD I FOUND YOUR POST :angel: Thanks.
Click to expand...
Click to collapse
I had this problem and the only way to solve it was to reflash the Rom.
Also experiencing on a Mintt phone
I live in a developing country and had few options when I needed a new phone. I have a Mintt phone which I cannot seem to root. The internet here is terrible so I don't have many apps but have had recurring self installing malware that renders the phone unusable until factory reset at which point the whole process starts again.
It seems to be attached to the inbuilt browser which I can't remove. It starts with a circle on the screen which can't be removed and if touched opens a warning message that WhatsApp has a virus. I don't have WhatsApp. Then chrome tries to install. I don't use chrome. Then the messages become so frequent nothing can be done but factory reset. Any help would be much appreciated!
Samsung GT-N8013
Stock ROM full flash help?
I was wondering if I could get a walkthrough on how to find and do a full flash Stock ROM for my android tablet, similar to what you describe here.
I have had this tablet for years, but years ago, I think I got some malware, and anything I've tried over the years seems to be unable to get rid of it. I've followed many times the clearing cache from pwr/volumn up boot menu, and factory resets from same menu, yet everytime it starts up for the first time, it loads and updates several apps, then when it fully starts to home page, there is always a "lucky try" app.
I can't remove this app, and there are extra settings apps too, and the official google apps don't update properly. All in all it's very fishy, and I would like to try what you are talking about, with a full flash reset, but I have no idea how. I'm at the point where if I totally brick the thing, I'm ok with that. It is pretty much useless and has been for years anyway.
The only way to solve this problem is to flash a stock or a custom Rom.

Random app(s) missing after restart

Hello,
I'm writing because I've seen this issue since a longer time on my phone.
When I restart sometimes some random app is missing. Thing is when I restart again the app is back in the list and works fine.
I think some time ago I found others having similar issues somewhere hidden in other links on Google but I can't find them anymore for the same of this thread x_x
Normally people seem to have trouble with (all) apps on sd card disappearing after reboot. I don't use that feature; I install everything on internal memory and it is always some other app (random). And the app returns working normally after restart.
Note: the missing app I see missing normally through the system itself, as the app is not listed under apps. So nova launcher and others also do not display it.
Anyone seen this too?
I noticed that titanium backup restores the missing app fine and then the app works without a restart. Also I checked the directory /data/app and also found the apk of the missing app.
How does android get the available apps on boot and how would it forget some of them? And how to fix...?
I'm on android 4.4 (slimkat) on Samsung Galaxy Note 3 with leankernel.
Thanks!
I'm on android 4.4 (slimkat) on Samsung Galaxy Note 3 with leankernel
Hi , did you tried to flash stock firmware with odin or SmartSwitch and see if the apps are missing again ?
Sorry, I was absent and did not receive a message for this thread.
Thank you for your reply!
Well, it is hard to see. I'm happy with this rom so I'm having a difficult time using other roms. I cannot recall having this on another rom I used before for a few months (bobcat rom, based on Kitkat Samsung stock).
It might be worth reinstalling the current rom for testing. Seeing everything up though takes its time though.
I was kinda hoping someone had that experience and pointed to something like some xposed module which I love. It is not easy to test because I mostly do not know/notice there is an app missing. Just sometimes my quick settings times with the apps show "error". Then I know something is wrong. So easily weeks pass by until I find this again...

Categories

Resources