Detection of Keylogger - Android Q&A, Help & Troubleshooting

Good morning,
I have a Galaxy Tab S that is rooted. Yesterday morning I woke up to a Skype message tone hoping that my family had sent me a message. However, I noticed that messages were sent to few of my contacts with an attachment from my account. It is obvious that something fishy is going on. I am just not sure how bad it is. My tablet is the only device with my skype account.
I ran two antivirus software scans 1) Kaspersky - no issues detected and 2) AVG. AVG identified two warning
1) "Unsecure privilege mode detected. Your device is running in High Privilege mode (i.e., it has been rooted) we recommend using only genuine firmware"
2) Enabling 'USB Debuggin' is not recommended unless you use your device for software development purposes.
I just rooted my device and am not using any custom ROM. I have rooted it about close 3 years now and never had any issue. With regards to the second message, I don't ever recall enabling the 'USB debugging' and I can't even find that option to turn it off.
Can someone please let me figure it out what is going on with my situation and what are the next steps. I haven't rest my accounts as it was useless cause this is the only way to access the internet. I would first solve the virus or keylogging issues (if the case) and then fix on working resetting the accounts.
I use only my office machine (which I am using it right now) to access my bank accounts or my personal emails. The tablet is mostly for Streaming apps, games, and Skype.
Any help would be greatly appreciated. Thank you for your time and advice.

Related

activesync 3.7 problem/question!!! help!!!

why is it that activesync 3.7 will stop syncing with my pda? the last time it did it, i had to completely uninstall activesync and reinstall it. when i turn my phone on, it makes a sound to signify that new hardware has been connected, but activesynce remains dim. i don't remember having this problem with 3.6, however, i do recall the problem with 3.7. is there a way around this glitch?
have you got firewall software blocking it ? I run Active Sync 3.7 and have no problems other than not permanently allowing it access ('cos I'm paranoid) so it occasionally asks for permission...
Yes I agree with Spence, check your firewall if you run software like Zonealarm of the like.
If you still get problems with activesync, stop its process completely (alt-ctrl-delete.. processes.. wcescomm.exe) and relaunch the program. Or you could just reboot!!
Max
yeah I used to run Zone Alarm until yesterday and have had a few permission niggles with it - finally ended up uninstalling it as it doesn't work properly with Mcaffee VirusScan anyway-
on reinstalling Virus Scan I was finally able to load the Mcaffee FireWall, and have had no problems at all with Active Sync once allowing it through... it even has a "trace" facility for tracking intrusion attempts .. (very cool in a geeky way)
..also did a leak test on the firewall and it's locked down!
VirusScan also now recognises my XDA and scans that as well as a bonus !! So my recommendation is to buy Virus Scan 7 with the firewall - it's about 40 quid.........!!

Exchange bug?

Set up my works Exchange account on the S3 and suspected it was causing high battery drain.
Selected some 'sleep time' from within the application and then also selected Manual Update so I could save battery. It appears manual doesn't change anything though as my mail still comes through unless I deactivated the account completely?
Anyone else have this issue.?
Sent from my GT-I9300 using Xparent ICS Tapatalk 2
WhiteHartMart said:
Set up my works Exchange account on the S3 and suspected it was causing high battery drain.
Selected some 'sleep time' from within the application and then also selected Manual Update so I could save battery. It appears manual doesn't change anything though as my mail still comes through unless I deactivated the account completely?
Anyone else have this issue.?
Sent from my GT-I9300 using Xparent ICS Tapatalk 2
Click to expand...
Click to collapse
That wouldn't be a bug in Exchange causing the issue.
It is, most likely, because ActiveSync, which is what Exchange uses to communicate with your phone, is a server-side "push" technology. This means that your phone, most likely, has WiFi and/or your Internet services "always on" to accommodate ActiveSync. ActiveSync doesn't work like Blackberry where the client-side does all of the control/communication (pull technology). It is all done server-side, which means that the phone has to always have an Internet connection, either through WiFi or the phone Internet services, to be ready to accept incoming information from ActiveSync.
Thanks for the reply - so the option to manually retrieve mail is pointless then as it going to get pushed whether I want it or not?
Sent from my GT-I9300 using Xparent ICS Tapatalk 2
After posting my response, I decided that it could be a little bit clearer, so here goes.
Blackberry (BES specifically), IMAP, POP3, SMTP, etc, the client side, in this case the phone, is in control of all of the message synchronization. Meaning that every n number of minutes/hours/days it opens up an Internet connection and says, "Do you have anything for me? If so, send it now." That's client-side pull technology.
ActiveSync, on the other hand, the server (in this case the Exchange Client Access Server), sends out the info, via AvtiveSync, every time something new comes in to your Exchange mailbox. This happens "real-time" rather than every n number of minutes. This means that the client side, in this case the phone, must have an "always on" Internet connection, either via WiFi or the phone's Internet service, to accept these "real-time" updates. This is server-side push technology.
Server-side push technology, by its very nature, causes the client-side, in this case the phone, to consume more battery since the WiFi and Internet "radios" must always be on.
I hope that this makes more sense than my last post.
---------- Post added at 11:33 AM ---------- Previous post was at 11:28 AM ----------
WhiteHartMart said:
Thanks for the reply - so the option to manually retrieve mail is pointless then as it going to get pushed whether I want it or not?
Sent from my GT-I9300 using Xparent ICS Tapatalk 2
Click to expand...
Click to collapse
Correct. The server is the controlling "party" in the paired relationship.
WhiteHartMart said:
Set up my works Exchange account on the S3 and suspected it was causing high battery drain.
Selected some 'sleep time' from within the application and then also selected Manual Update so I could save battery. It appears manual doesn't change anything though as my mail still comes through unless I deactivated the account completely?
Anyone else have this issue.?
Sent from my GT-I9300 using Xparent ICS Tapatalk 2
Click to expand...
Click to collapse
I ran the same tests on the S3. I'm syncing 3 exchange accounts.
Email exchange service drains the battery really fast ...
Nearly half of the battery is used (battery stats) for this process only [47%].
My battery cannot last:
- on 3G networks, more than 5 hours.
- on WiFi, it goes up to 8 hours.
I used to sync the same exchange accounts on 2 other Samsung devices: Captivate Glide and Galaxy Note - both running Android 2.3.5/2.3.6
=> no issues with the sync services draining the battery.
IMHO, this is not only linked to the Activesync technology, it is also linked android release and the way email exchange service is made/configured (or runs).
There might be some tweaks or possible patch for this service...
But don't know what or where, yet ...
My 2 cents ...
The phone keeps at least one connection to Google open at all times (C2DM push) when it has a network connection.
Open and half-open connections do not really cause high battery drain since your device can (and will) go to lower power states and switch the network to fast dormancy which is a sort of periodic polling for new data.
A scientific article about the topic can be found here: Link (PDF)
The relevant part is in footnote 4 of paragraph 4.1.2
In fact, even at IDLE, a handset periodically wakes up to listen for incoming packets on the paging
channel. If a downlink packet happens to arrive between two paging occasions, it will be delayed until the next paging occasion
Click to expand...
Click to collapse
Additionally that IMAP is poll-only is not entirely correct. While IMAP itself is usually only used as PULL (client requests, receives, closes connection) many servers support the IMAP IDLE mode (client requests, receives, waits for new data, receives, waits, ...) which is a real push technology.
(Technically it differs from Google's C2DM which in fact is HTTP (Comet) long-polling and not true pushing)
I've noticed a high battery drain on Exchange too, even if the account was disabled. It's unrelated to how the phone is connected (Wifi,3G,2G) and _seems_ to get lower when no data connection is open.
It will only go away if the account is removed and seems to caused by the app waking up all the time even if not needed. Thirdparty apps and stock Android do not seem to have this issue - at least my S1 did not.
(I haven't tested on the S3 with a non-stock app yet)
Btw my Exchange server is a patched Z-Push IMAP/SMTP<->Activesync converter from their trunk with Exchange2007 capabilities.
Yes, there HAS to be a bug in the exchange app on this phone.
I got my phone a month ago, and have had no issues with battery drain and high data usage with Exchange what so ever. Until this weekend.
All of a sudden, with no change in the settings at all, my battery all of a sudden just lasted 5-6 hours. It got really warm too. Then after a day or so, I got a message that my monthly limit of data was reached. I didn´t believe this at all since I had more than 500 MB left on my limit the day before.
But when I checked the settings, I was shocked to see that this was true indeed. And it was "exchange services" that caused this. It had downloaded about 600-700 MBs over this short period, thus (of course) causing my battery to drain quickly, and I will now get a nice bill from my phone company for over use of data
As I said. No changes to the settings were done. This happened over night. And of course this has to be a bug in the app, not a server-issue. No one else in my company, as far as I have heard, had had this issue (yet), but after googling I can see that this actually is a problem for many, with different phone brands.
It seems like google has got complains about this, but there has not been released a fix, which is totally unacceptable. I now have had to turn of my mail sync to prevent the data usage to go insane, and my phone to get warm, slow and quick battery drain.
If this isn´t fixed quickly, I will uninstall Exchange services from my phone (have root), and install Touchdown instead.
Here is the problem discussed:
productforums.google.com/forum/#!topic/mobile/tCA92MdBTmc
- but with no solution.
Issue was resolved by deleting account and reinstalling it. But I had to do it twice before it worked.
I also cleand the Exchange Services App with the tool SD Maid before I reinstalled my account the second time.
My battery is back to normal, and no more crazy data usage.

[Q] Play Services cut-off my cellular abilities when there's no internet

Hi everyone - I actually don't know who else to ask but this issue has been driving me mental for the last couple of months. After days and nights of investigating and looking through various forums and articles, I think I can find (or try at least) the words to describe my problem more...technically))
So OK, first off the device is Huawei Ascend G510-0100 running KitKat under the Cyanogenmod platform but the issue was already present with the factory's 4.1 ROM. I thought rooting the phone, installing just brand-new everything and having a bloatware/clutter-free Android OS would rectify all the causes of this nightmare but no. I'm not the only one with this problem: Google-search the issue and you'll find numerous forum threads where users seek for a solution to this "software loophole" as well as one of my friends (Galaxy S2) and another one with the HTC One X+ so I rule out my phone's model, OS version or just my device being faulty from the list of potential causes.
So - every time I turn my WiFi off on purpose or when I go out of my house (where logically my phone looses home's wireless signal) - the location services and the app synchronization processes stumble, mess up, run into and furthermore cause internal system mess-ups from such "unexpected" losts of internet. After that I can't make a phone call, send SMS or run USSD codes (checking credit balance etc) but I can still receive calls and texts - basically I fail to reach my cellular services but the service can still reach me. Turning Airplane Mode on and then off or simply restarting the phone altogether temporary fixes the cellular problem until the next time the internet becomes unreachable to Play Services. I tried turning location and sync off, tried different location/sync options...I wish I could disable Play Services but then I wouldn't be able to use the Play Store - | tried messing around with probably every single option available and possible but the Play Services still failed me and.......I honestly don't know what am I missing and where to look next
Edit: (I never use the mobile data btw)
Any suggestions? Anybody? I'm hopeless at this point :crying:
Thank you all...
...
Anyone? Please...

Firewall problem: WhatsApp messages not arriving (ONLY when the phone is in sleep)

So first of: This is not phone or android version or even firewall-app specific because I've had the problem on previous phones and I know other people who also have this problem.
I'm running a firewall with a whitelist and obviously WhatsApp has Wi-Fi and mobile data allowed. It generally works. I can send and receive messages and media.
But if I put my phone away for a longer period of time (I think around 15 minutes or more) I no longer receive messages until I open WhatsApp.
So for some reason WhatsApp can't establish a connection when the phone is in sleep (or whatever it's called).
I verified this with another person who had the same problem. Turned off firewall and put the phone away for an hour or more, then sent a message and it arrived instantly. Worked for both phones.
I'm guessing that I need to give some other app internet access so WhatsApp receive messages while the phone is in sleep.
P.S: No, it's not that the notifications aren't showing up, it's not some battery saver, I did some research before and no suggested solution worked. Except for turning off the firewall (the 3-4 messages we sent for testing all worked perfectly fine), but since I came up with this idea myself, there was no thread to get some info about it and I didn't really find anything using google (though I found it hard to word the search).

How to record memory usage to troubleshoot random, non-reproducible crashes/errors

I am the mobile device manager for my company. We use Samsung Tab S4 tablets (Oreo 8.1) and Mobicontrol MDM for field workers and have been experiencing issues that we have not been able to recreate. The app in question is CAPI by Confirmit. We have been working with their devs but so far they have not been able to explain what is happening.
We have an alert set up in Mobicontrol to alert us to excessive memory usage but every time we receive the alert we have to hope to catch it in time to be able to remote tot he device to have a look but we have yet to be able to catch it in the moment, by the time we gain access the condition has subsided. Sometimes we get the RAM alert only, sometimes we get it in conjunction with an app crash, sometimes the app crashes without an alert. It may be that the memory spike is too brief to trip the alert, or it may be that they are only coincidental and not related at all. we just don't know.
I have been trying to find some sort of "flight data recorder" equivalent that can run on these devices that will be monitoring so that when the app crashes, or when a preset memory threshold has been exceeded, we can inspect the recorded data from the time previous to the event to hopefully identify the cause(s). So far I have been unable to find anything that does this, and my efforts at using Tasker, Elixir 2 with E Robot, MacroDroid, etc have been unsuccessful.
One of the major limitations we face is that the devices are in the hands of technically unsophisticated users. We lock down the devices fairly tightly using Mobicontrol application whitelists to limit what they users can do, but whatever solution we might come up with would have to be able to be communicated to and reliably executed by these non-technical users.
I thought maybe that enabling Developer Options and configuring debugging in the power menu would be an easy way to get debug logs but we don't permit Google or other accounts so email, Drive, etc are not options and I can't figure a way to save the logs to a local folder accessible by Mobicontrol so we can remote to the tablet to retrieve it. Nearby devices, Wifi Direct, or adb/USB connections don't work, either.
Any ideas? Would appreciate any thoughts or comments that might help us drive toward resolution of this problem.
Thanks!

Categories

Resources