The OTA That Shouldn't Be! - Verizon LG G3

So, I recently re-flashed the most awesome Jasmine 8.0 to my Verizon LG G3. I have used the hidden menu to disable the OTA downloads (unchecked the box). However, my phone continues to download system updates.
How is this possible?
One thing I have noticed, is that even if you take the update, it (OTA) appears to do nothing. After a period of a day, the phone has apparently downloaded an additional update, and yet the OTA setting hasn't been modified. Not sure why this continues to happen. However, it is quite annoying. Is there a way to stop this ridiculous process and can the notifications? More importantly, why is my phone attempting to download an OTA when it has been explicitly told not to do such a thing?

ciphertext said:
So, I recently re-flashed the most awesome Jasmine 8.0 to my Verizon LG G3. I have used the hidden menu to disable the OTA downloads (unchecked the box). However, my phone continues to download system updates.
How is this possible?
One thing I have noticed, is that even if you take the update, it (OTA) appears to do nothing. After a period of a day, the phone has apparently downloaded an additional update, and yet the OTA setting hasn't been modified. Not sure why this continues to happen. However, it is quite annoying. Is there a way to stop this ridiculous process and can the notifications? More importantly, why is my phone attempting to download an OTA when it has been explicitly told not to do such a thing?
Click to expand...
Click to collapse
Have you carefully followed every step from here? http://forum.xda-developers.com/showpost.php?p=56404192&postcount=662
If so, I can't imagine why you would still be receiving any kind of notification, unless the OTA were cached somewhere after being downloaded. But even then I wouldn't think it would prompt you as the all itself would already be frozen. Follow every step from that post and that should fix your issue.

Titanium Backup ... FAIL
ohlin5 said:
Have you carefully followed every step from here? http://forum.xda-developers.com/showpost.php?p=56404192&postcount=662
If so, I can't imagine why you would still be receiving any kind of notification, unless the OTA were cached somewhere after being downloaded. But even then I wouldn't think it would prompt you as the all itself would already be frozen. Follow every step from that post and that should fix your issue.
Click to expand...
Click to collapse
Thank you for responding to my plea.
However, when I attempted to perform the Titanium "freeze" process found in that link you supplied me, I was unable to locate any of the items listed in that link. Just so that I could verify that the search filter was working correctly (and not a user error) I searched for a known application name. I was able to find the known application I used. However, i was unable to find and of the other search keys (e.g. SDM, protection, etc...).
Curious wouldn't you say?

ciphertext said:
Thank you for responding to my plea.
However, when I attempted to perform the Titanium "freeze" process found in that link you supplied me, I was unable to locate any of the items listed in that link. Just so that I could verify that the search filter was working correctly (and not a user error) I searched for a known application name. I was able to find the known application I used. However, i was unable to find and of the other search keys (e.g. SDM, protection, etc...).
Curious wouldn't you say?
Click to expand...
Click to collapse
Try using an app called "chefs freezer" from the play store. Its basic and minimalistic, but it does its job well for this kind of application. Rather than searching, try just looking through the list. At the very least, there should be an app titled "System Updates" - make certain that's frozen. I just did this same exact thing on a similar situation phone a few days back, so at the very least that app should be there. Freeze all the ones you find, if you don't find some of them you might still be ok by freezing everything you do find.

ciphertext said:
Thank you for responding to my plea.
However, when I attempted to perform the Titanium "freeze" process found in that link you supplied me, I was unable to locate any of the items listed in that link. Just so that I could verify that the search filter was working correctly (and not a user error) I searched for a known application name. I was able to find the known application I used. However, i was unable to find and of the other search keys (e.g. SDM, protection, etc...).
Curious wouldn't you say?
Click to expand...
Click to collapse
Make sure in TiBu you have selected in the filter to show System apps. They will show up red in the list.
What you are looking for is "Software Update xxxxxx" where xxxxx is a version number. Mine, on Jasmine 9.0, is 5.1.1-1525410464a1b.
Freeze that and the OTA notifs should go away.
It worked for me on Jasmine 8.0. And I went and froze it again on Jasmine 9.0 as I don't want any NEW OTA notifs.

Fingers Crossed ...
ohlin5 said:
Try using an app called "chefs freezer" from the play store. Its basic and minimalistic, but it does its job well for this kind of application. Rather than searching, try just looking through the list. At the very least, there should be an app titled "System Updates" - make certain that's frozen. I just did this same exact thing on a similar situation phone a few days back, so at the very least that app should be there. Freeze all the ones you find, if you don't find some of them you might still be ok by freezing everything you do find.
Click to expand...
Click to collapse
I downloaded "Chefs App Freezer" from the Play Store and was able to Freeze the System Update application. I'm keeping my fingers crossed. I'll know later if the situation worked based upon the notifications I receive.
Thanks!

Related

I need your help fixing the market "My Apps"

So I haven't quit looking into what actually causes the market "My Apps" issue. While I do feel it truly is the database I have a slightly more detailed theory as to why it does it. However in order to test this theory I need to take a general poll.
How many of you discovered this issue after using some sort of Root tool (ie: Rom Toolbox, Root Tools, Titanium Backup)?
How many of you have accidentally or on purpose used the Market Fix that supplement these programs?
The reason I'm asking is semi obvious I suppose. While these programs can do great good it would appear that if not done correctly they can also do bad. Last night I decided to play with it a bit more and I Linked ALL system apps and user apps to the market. After a few minutes or a reboot I would get the error again.So I went ahead and broke all links again, deleted the .dbs file and started all over again. This time only doing system apps and user apps that I knew were updatable. This lead to the market functioning much better. However I'm not finished yet. I want to figure out what apps and programs trigger this. At this point in time most User apps are okay but I have found I have linked considerably less system apps to the market. What I would like to ideally do is narrow the list down to just a few apps that shouldn't be linked.
Also if anybody would be so kind as to copy and share their database file that would help tremendously. This file needs to be completely stock having NEVER used any of these programs to edit the market links. Sharing this could potentially help all Android users having this extremely annoying issue. If you would like to keep the amount of users who this down to just me you can PM me or even send it to me over Skype or some other messenger with a file share tool. Thank you all in advance.
For those of you currently having the issue I have posted a fix here: http://rootzwiki.com...market-my-apps/
What issue?
DirkGently said:
What issue?
Click to expand...
Click to collapse
With the "My Apps" being a blank page and not containing any of the apps from the account.
Sent from my super awesome Kindle Fire running CM7 with Tapatalk

Did Swype Installer do this?

I installed Swype on my TP yesterday and everything seemed fine, but today I keep getting the message that [bunch of asian characters] has stopped. I had no idea what it possibly could be since I don;t know what it says so I thought it might be Swype and went into Input on Settings to turn Swype off. Now, under KEYBOARD AND INPUT METHODS the first thing says Default and under it is a bunch of Asian characters. Under that is all the input methods. The interesting thing is there are two selections that are checked yet grayed out so I can't deselect them which are Japenese IME and the last one is those Asian characters. What is going on and how do I get rid of them?
OK. I went through all my Apps in Settings and at the very end is one named with Asian characters. Under the name it says version 4.0.3-eng.erik.20120221.223654. It doesn't give me the option to uninstall it, but I have disabled it. I don't download a lot of apps, and I certainly don't download shady looking apps, so where did it come from and how do I get rid of it??????
It could be something else pushed on you - some apps with the Networks and Internet permissions push random apps to your phone without you knowing it (or explicitly allowing it). My girlfriend has a music app that does it to her sometimes, and it's annoying, but not malicious (at least, not that I've seen).
I tried deleting it through Titanium but it didn't work so I decided to try installing the Nightly version of CM9 and that got rid of it completely. Still, weird!
loomism2 said:
I tried deleting it through Titanium but it didn't work so I decided to try installing the Nightly version of CM9 and that got rid of it completely. Still, weird!
Click to expand...
Click to collapse
check if the application is considered a system app
ve6ay said:
It could be something else pushed on you - some apps with the Networks and Internet permissions push random apps to your phone without you knowing it (or explicitly allowing it). My girlfriend has a music app that does it to her sometimes, and it's annoying, but not malicious (at least, not that I've seen).
Click to expand...
Click to collapse
installing applications on your phone/tablet without your "permission" is the definition of malicious.
IIRC there has been some sort of Asian language keyboard in CM9/ICS for a while. I remember disabling it a while ago, not sure why its included in an English version of the OS.
Well, when I installed the Nightly build all Japanese-related input choices disappeared, so maybe they aren't included in CM9 anymore? Whatever the reason, I am happy it is solved.
Varemenos said:
check if the application is considered a system app
Click to expand...
Click to collapse
It was considered a system app to Titanium, and to the phone as well, I guess. Titanium said it would do some special thing and the phone would reboot twice and it would be gone. Well, when it was finished doing its thing the app was still there. I think I tried using Titanium to remove the stock Music app that came with the phone and it didn't work right then, either. I can't remember how I got rid of that, but I eventually did.

[Q] update.appfansworld.com in Chrome browser

I am getting an annoying spam/popup whatever in my Chrome browser. It's very deceiving and I've tried restarting Chrome, the phone, clearing cache but it still pops up all the time. It's from "update.appfansworld.com" and gives me an initial message about memory being low or something. Attached is a screenshot. Anyone know how I can get rid of this?
If this is an app.
Go to settings > application manager
Find the system ui upgrade app and uninstall it.
Is it a popup? If so try an ad blocker. Or figure out what site's giving you this junk.
If your user agent string is reporting as android (in Chrome it is) they can tailor ads to look like "updates".
If you get the "memory slowed" message hit cancel or the back button.
Sent from my Verizon NC5 Galaxy S4 w/ GEL and Xposed
Fixed this problem on my phone by going into the App Info for the Chrome App and Deleting All Data. Just had to resign into Google, and it has not come back so far.
Update.... Went one week with no pop up. Got one again from app fans world. Com again last night. Not the UI one though. This one said my browser crashed, which it hadn't. Spent several hours trying to get it to repeat, but it never did, nor did it today. Just as a final check, I ran Malwarebytes, and found only one instance of malware on my phone, but not thinking it was actually malware. It was the root uninstaller file for Smart Ram Booster Pro. I uninstalled the app anyway as I don't really use it. Will give an update on this in a week or so. Looking online, this is becoming a widespread issue.
jakel1.jf said:
Update.... Went one week with no pop up. Got one again from app fans world. Com again last night. Not the UI one though. This one said my browser crashed, which it hadn't. Spent several hours trying to get it to repeat, but it never did, nor did it today. Just as a final check, I ran Malwarebytes, and found only one instance of malware on my phone, but not thinking it was actually malware. It was the root uninstaller file for Smart Ram Booster Pro. I uninstalled the app anyway as I don't really use it. Will give an update on this in a week or so. Looking online, this is becoming a widespread issue.
Click to expand...
Click to collapse
Yeah I tried deleting data in the chrome browser but that didn't prevent it from coming back. I'll look forward to a solution if you find one.
After clearing the data under app info it stopped for a week for me. It was popping up every other page almost before that. Now, it popped up again just once, and I did a couple weeks worth of browsing in a couple hours after it did, just to see if I could get the pop up again to inspect it better, but it just won't come up again. I don't know if it is gone, or will pop up again sometime later. Weird.
I have been following a guy on the Verizon forum dealing with this. He was going to run his phone in safe mode, and try activating one 3rd party app at a time, using Terminal to see if he could find an app that was causing this. That didn't work though as while in safe mode with no 3rd party apps activated, it still happened. He is now going to reset his phone, reinstalling apps one at a time to see if he can find an app causing it. This will take more than a week though, as he will take time to test chrome for awhile after each app is installed. One thing to note is that the app.fansworld.com site was only created 12.18.14. It could be any app you installed slightly before to any time after that date, or even any update installed then. I am almost thinking it is something to do with Chrome, as I don't install anything except from the Playstore, and only a thing or two that I can remember during that time frame. I am going to both uninstalled all chrome updates, and try a different browser, to see if it still happens. If it does, I am going to factory reset my phone, and see if I can fix it.
jakel1.jf said:
I have been following a guy on the Verizon forum dealing with this. He was going to run his phone in safe mode, and try activating one 3rd party app at a time, using Terminal to see if he could find an app that was causing this. That didn't work though as while in safe mode with no 3rd party apps activated, it still happened. He is now going to reset his phone, reinstalling apps one at a time to see if he can find an app causing it. This will take more than a week though, as he will take time to test chrome for awhile after each app is installed. One thing to note is that the app.fansworld.com site was only created 12.18.14. It could be any app you installed slightly before to any time after that date, or even any update installed then. I am almost thinking it is something to do with Chrome, as I don't install anything except from the Playstore, and only a thing or two that I can remember during that time frame. I am going to both uninstalled all chrome updates, and try a different browser, to see if it still happens. If it does, I am going to factory reset my phone, and see if I can fix it.
Click to expand...
Click to collapse
I assumed it was a chrome thing since that's where it always pops up for me. I guess I could try another browser...
I did click on the page (clicking cancel or update does the same thing) as I figured I will be reseting my phone anyway. No matter how many times I click on it, all it does is redirect me to the Dolphin Browser page on the playstore. This makes me really suspicious because the developers of Dolphin Browser wouldn't ruin their extremely good reputation by doing this. I think the redirect is a cover for something else. Maybe a keystroke logger, or something just as malicious. Rolling back Chrome didn't get rid of the page that pops up. No popping up with new browser so far, went with Maxthon, but it is early. Really starting to think a complete wipe and reset is necessary. After all, the pop up is only what we are seeing, what else might be going on we can't.
Quick question... Have you downloaded any (.flv or.m2v specifically) video files during the time frame? Read a recent article about hackers using them to exploit vulnerabilities. Right now it is suggested not to download those 2 file types at all.
Factory reset my phone, which was a small hassle, but it has fixed it, and the other small bugs and slow downs that appeared at the same time. Back up your files... Pics and such you want to keep, and reset. Your phone should automatically re-install all your apps, although you will have to redo some of your settings. After you save your files to wherever you want, I saved them to my pc, just go to settings.. Then back up and restore.... And select factory reset or reset phone, however it is listed. Your phone will then be like brand new, and you will only have to re-set up a few things as most things will reinstall by themselves with their previous settings. Like I said, a small hassle, but it fixes the problem, and you again know your phone and data is secure.
It started doing it again today. Reset didn't work. Talked to the guy on verizon forum, and he is going through all files to locate it's origin. Will just have to wait until he is done. FYI--It started happening in other browsers too.

Nexus 5X weird behavior (malware?), possibly caused by FB Messenger or Pixel Launcher

Some very weird things started happening on my phone earlier today. It's a Nexus 5X, running 8.0 Oreo, with the October security patch. I'm not rooted and I'm careful about what I install. The phone is fairly new, from this summer.
I will begin with describing what I did in the hours before this started. I can think of two things that possibly could have started it:
1) Two of my Facebook contacts sent malicious links to me an hour before. It looked like Youtube videos but was not. I did NOT open any of these links, knowing directly they were harmful (not sure if you can be affected by just receiving them, not clicking on them?). I received them in the Messenger Lite application (an official app from Facebook with scaled-down functionality).
2) A few hours before the Facebook links, I sideloaded an APK containing the new Pixel Launcher. I got the APK from Android Police/APK Mirror.
Can't attach links, but Google for: Hands-on with the updated Pixel Launcher, including the new Pixel 2 features [APK Download]
The APK was working fine and nothing seemed odd with it (I used the launcher for a few hours). As long as Android Police know what they uploaded, this shouldn't be the cause for my problems. I bet on Facebook Messenger instead. (People that click such malware links typically get their Facebook accounts hacked, however my account seems fine and my account didn't spam others with the same link. I did not change password or did anything else to "recover" my account yet).
So what happened after this on my phone?
Here is the first thing I noticed. I open Play Store to install updates. It turns out I have one update pending, it's called BankID. This is a major Swedish app used by nearly every smartphone user in the country, and it's for signing into government websites, bank websites, insurance company websites, and much more. When I click update in Play Store two things happen almost instantly:
1) Six pictures are downloaded from Messenger Lite to my phone. That makes no sense, how could clicking a button in Google Play trigger something to happen in Messenger Lite? In fact I tried it three times, with the same behavior every time. (Well, actually opening the Messenger Lite photo album, there are only photos there I already downloaded, so nothing new seems to be added there - but the photos were probably re-downloaded I believe).
2) The BankID update downloads to 100 % (the downloading takes a little longer than expected), then it halts and does nothing, i.e. it's not installing. No error message, it just stops there. I can choose to abort and try again, which I do three times or more, with exactly the same behavior.
Also, I now notice Play Protect hasn't run for two days, but when I try to run it, it seems to be down. After ~30 seconds of scanning it says "App verification temporarily down". "App verification temporarily down" could very well be connected with the halted update I just described? It still says it hasn't run for two days after this.
When I experiment, I notice other things that are very weird indeed.
1) Notifications in Gmail, Snapchat and possibly other apps aren't coming through. By opening the apps, I can sync manually.
2) When I move a file to a new folder using the Downloads app (Files app, stock one) I get a error message saying the move operation failed. This also triggered the photo notifications from Messenger Lite (same behavior as described above, with six photos). However, after a while the moved pictures are indeed in the right folder, even though the error message saying otherwise.
3) After some time I remove "app data" for the Google Play app. When I open it after that, there are now three app updates pending (e.g. Google Wifi also). But the same behavior occurs, when I try to download one or all of them, I get the Messenger photo notifications and the updates halt at 100 % without installing. So the BankID app - which could be targeted by attackers for obvious reasons - could just be a coincidence. It could have happened with any app I suppose, this was the only one pending right then. But still, why couldn't Play Store detect other pending app updates until I refreshed it the way I did? Was Play Store blocked from connecting to Google (or forced to connect to some other server, perhaps?).
What did I do after all of this?
I uninstalled three apps:
-Facebook Lite
-Facebook Messenger Lite
-Pixel Launcher APK
However the uninstall process was very odd. A process called "Package Installer" had a notification saying "Uninstalling Lite" and "Uninstalling Messenger Lite". It didn't seem to be working, it was stuck after some time. I restarted my phone and the apps seem to be gone now, at least they aren't listed in Settings --> Apps. So the uninstall process was successful I suppose, even though it didn't seem to work.
After I restarted my phone I also noticed:
-When I install Messenger Lite from Play Store now, it's easy to uninstall it the way it should be - in mere seconds.
-When I open Play Store, updates are now installing fine. Play Protect is also scanning fine now.
Everything looks back to normal now. But I'm not trusting my device. I'm gonna factory reset it. Before I do, I wonder:
-Can I feel safe the wipe would erase whatever malware I might have had on the phone?
-Is there something I could do to let us know what caused this? Upload a log here somehow?
The only piece of advice I have received as of now is: "Try restarting in safe mode, installing some AV software, and generally looking for suspicious processes." I haven't done that yet, would it still be a good thing to do? Must I install AV software before rebooting into safe mode, or could I install it directly from safe mode? (App suggestions, AV software?).
Usually I'm very careful and security-minded. I haven't had something like this happen before. So I'm very intrigued and mad about this. I'm gonna change my Google account and Facebook account passwords later on I think (I already have 2-factor authentication enabled).
One last thing: When I install Pixel Launcher on my non-rooted phone, it's not running as a system app if my understanding is correct. (At least it shouldn't be). But none the less, when I wanted to uninstall it I had to go into Settings --> Apps and tap "Show system apps" to find it in the list. Is that normal? Perhaps it doesn't mean anything, I just want to know.
Thanks for your advice in advance. Anything else to add? What should I do know? All you might have to say is appreciated.
Come on now guys, someone must be able to help?
If I factory reset the device, will it be clean? I didn't mess with custom ROMs, root, the bootloader or something else. (I suppose the bootloader is locked).

Question Unknown background app running during system updates

I updated my Pixel 6 to Android 13. I was aware that you can use the phone while it's updating in the background. So, in the process, I customized some settings. However, when I tried to go back by showing all running background apps (swiping up), the System Update Settings app was gone and a "Google Confidential" app was running in the background. Tried tapping it but nothing showed up. So, I went through the settings > system update again, and found out that it was still "updating and installing". When I tried to tap the "Google confidential app" while the System update tab was now present in my recent apps navigation (swipe up), it just redirected me to the System update tab "installing updates".
Any chances that the update can get corrupted? Are there ways to verify integrity of files/updates?
UPDATE: Installed Android 13 and June update successfully. Phone asked me to restart per update. It would say if something's wrong with update, wouldn't it? Also, is the Google Confidential background app normal (it looked like a gear icon with a G and a red "confidential" word on top of it)? It showed up only during the system updates. I can't seem to find any reference/mention of it online.
Thank you in advance.
raygncio said:
I updated my Pixel 6 to Android 13. I was aware that you can use the phone while it's updating in the background. So, in the process, I customized some settings. However, when I tried to go back by showing all running background apps (swiping up), the System Update Settings app was gone and a "Google Confidential" app was running in the background. Tried tapping it but nothing showed up. So, I went through the settings > system update again, and found out that it was still "updating and installing".
Any chances that the update can get corrupted? Are there ways to verify integrity of files/updates?
UPDATE: Installed Android 13 and June update successfully. Phone asked me to restart per update. It would say if something's wrong with update, wouldn't it? Also, is the Google Confidential background app normal (it looked like a gear icon with a G and a red "confidential" word on top of it)? It showed up only during the system updates. I can't seem to find any reference/mention of it online.
Thank you in advance.
Click to expand...
Click to collapse
I can't say for sure, but that doesn't sound right. Perhaps it really is a Google app, but usually they cover up their spyware by packaging it into innocent looking apps with cute colors. I can't find anything online either.
ethical_haquer said:
I can't say for sure, but that doesn't sound right. Perhaps it really is a Google app, but usually they cover up their spyware by packaging it into innocent looking apps with cute colors. I can't find anything online either.
Click to expand...
Click to collapse
I'll try to screenshot it when a system update comes up. Actually, when I tapped it while the System update tab was present in my recent apps navigation (swipe up), it just redirected me to the System update tab "installing updates".
Edit: I actually found it again after I restored my contacts. See photos below
raygncio said:
I'll try to screenshot it when a system update comes up. Actually, when I tapped it while the System update tab was present in my recent apps navigation (swipe up), it just redirected me to the System update tab "installing updates".
Edit: I actually found it again after I restored my contacts. See photos below
Click to expand...
Click to collapse
I don't think that's authentic. Just by looking at the font used on "Confidential". But than again, it could be what Google really looks like. Not quite as innocent looking as these :
It's unlikely that the update itself got corrupted, as your Pixel 6 successfully installed Android 13 and the June update. If there were any issues with the update, your phone would typically notify you or display an error message.
As for the "Google Confidential" app appearing during the system update process, it's not a standard feature or app that I'm familiar with. It's possible that it was a temporary placeholder or a bug in the user interface during the update process. Since you can't find any references or mentions of it online, it may have been a unique occurrence on your device.
To verify the integrity of files and updates on your Pixel 6, you can perform a few checks:
Reboot your device: After the update is complete, restart your phone to ensure all the new system files are properly loaded.
Check for system update status: Go to Settings > System > System update and confirm that there are no pending updates or error messages. If everything looks normal, it indicates that the update was successful.
Test system functionality: After the update, use your device as you normally would and pay attention to any unusual behavior. If you encounter any significant issues or errors, it's recommended to contact Google support or visit an authorized service center for assistance.
Overall, since your update was successful and you haven't experienced any noticeable problems apart from the "Google Confidential" app during the update process, it's unlikely that there is a major issue. However, if you continue to encounter unusual behavior or have concerns, it's best to reach out to Google support or the appropriate channels for further assistance specific to your Pixel device.
Hmm the google confidential thing looks a bit off.
I would try to find the full package name and install path to atleast get an idea of what it is or if it's legit?
De-Bloater | F-Droid - Free and Open Source Android App Repository
Use the power of Magisk to de-bloat system applications systemless-ly
f-droid.org
debloater should find it and show some info atleast.
This application looks suspicious. Check its behaviour and what permissions it requires. Install some anti-virus app and run a scan of your entire phone.

Categories

Resources