[Q] alot http requests from my phone - Android Q&A, Help & Troubleshooting

Hey everybody, i hope you can help me.
I've a Samsung Galaxy S3 GT-I9300 rootet and since 2 weeks with CM11 M7. I use the Tool Reverse Thetering from this thread Link while at work to have some kind of internet on my phone.
The tool shows all kinds of up and downloads. After flashing my Phone with CM11 M7 i used the tool again and noticed that after 2 minutes in standby my Phone starts to do a lot of http connections. (See 2nd image). I know that the phone updates all the messaging and mail apps but with stock rom ist wasn't that often. In normal conditions the requests look like this in standby:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
But after around 2 Minutes the Phone starts to request some http adresses all the time and it doesn't stop. This looks like this for example:
(Sorry for the big image)
Unfortunately i don't know if the phone does this only when using Reverse Thetering or also when i'm online with wifi or gsm. I can only see and chek it with reverse thetering.
I've bought Kaspersky Internetsecurity and tryed other apps from avg or avira to check my phone for a virus or similar bot non of them found something (i used each app on its on with only on app installed at the time)
I'm not an expert but it looks like my phone could be infested by some kind of botnet or similar but i'm not sure. Has anyone a idea what this could be and how i could stop it or get rid of the whatever i have?
Thanks a lot for your help.

Related

Possible hacked phone sending sms's, help needed

Hi iv checked my orange uk bill online and seen that a number keeps dialing out but it never connects then after or before it calls out it sends a text ti the same number then charges me 0.08p no its not a lot but this is happening every 5-10 minutes
Iv attached a picture for you to look at and see that its been going on since before christmas.
Iv got unlimited text messages with my orange uk bundle, and the texts i do send to my friends do not charge me. Little lost in what to do or what program may be causing this little problem.
Help is need here.
Take a look its happening a lot.
Going to try a fresh rom.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Try installing a virus scanning app from the market to see if it finds the culprit. Otherwise backup important apps/data, wipe and flash a fresh ROM. Not 100% sure if flashing a new ROM removes the virus but its worth a shot.
Sent from my GT-I9100 using XDA App
What rom are you running?
Was running a miui port on my xperia arc, ill install a virus scanner, likely avast and see what comes up, the number/numbers are not in my phone book as well. So it's not a number i know of.
Sent from my Arc to your eyes.
punkmonkey1984 said:
Was running a miui port on my xperia arc, ill install a virus scanner, likely avast and see what comes up, the number/numbers are not in my phone book as well. So it's not a number i know of.
Sent from my Arc to your eyes.
Click to expand...
Click to collapse
I would use a different rom as well and see if it stops.

[SOLVED] Play Store New Feature?

Hi guys...I'm from the GT-I9100G forum......I'm running the latest cm9 on my phone...
Ok, back to my topic...When updating apps, it only downloads for a few percent as shown in Play Store...
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
But in my notifications drawer, it fills up very fast and the update is completed in a short while...faster then expected...but my apps still get updated magically!
It has been like this for many times...tried searching butI don't know what to search for...lol...so anyone else aware about this? My hypothesis is that Play Store only downloads the necessary files to 'patch' the existing apks...Is this possible?
Yes, you are right, actually. The Play Store now only downloads new content for each app, instead of downloading the entire app over again. Makes sense, especially for larger apps, like Death Rally, which is a 50MB initial download. VERY useful update for people who spend a lot of time on their mobile networks (not everybody has 4G or 4G LTE service available, or phones with those capabilities).
I noticed this behavior on my phone, and coincidentally read it online the next day on a random news post.
Wow...great feature......still remember the title of the news?kinda interested...
Ryuinferno said:
Wow...great feature......still remember the title of the news?kinda interested...
Click to expand...
Click to collapse
It is called delta updates. here is an article from androidandme about it.
Http://androidandme.com/2012/08/app...pdates-now-enabled-to-save-you-time-and-data/
Sent from my Samsung Galaxy Tab via Xparent Cyan Tapatalk 2

Infected with malware via chrome

Hey guys.
When I was exploring the Internet via chrome my phone has been infected. The new tab opened by itself, phone started to vibrate and page said that my phone is infected and that I should download Antivirus (but this page was similar to other pages with slogans "YOU WON 100K$ CLICK HERE etc.) so I ignored it. Now after every call (only then) Clean Master is saying that I already installed "Games " so I can delete apk file. Sometimes I press YES or sometimes I press No and sometimes it appear on desktop as game (last time it was yahoo logo) sometimes it doesn't. Clean Master Says That is malware with ".bf" extension. I tried every AV, even Avast didn't find anything. I tried also looking for this file by my self but no results (CM Antivirus also find nothing) . (gonna add name of virus for better tagging)
NAME OF VIRUS:
Android .Troj.tb_downloader.bf
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I think that is ads... Btw to be safe you can always format your phone, be sure backup your data and contacts.. If you are rooted use adblocking software.. If not use browser which supports adblocking features..there are many in playstore
Sent from my GT-I9300 using Tapatalk
Ghostery is a great adblock browser

Strange DNS requests from wileyfox swift 2 phone

Hello everyone, I got a wileyfox swift 2 phone a couple of months ago and once the android 8 update came out, I updated my phone. Now, recently I installed a pi hole server on my home network and noticed that there is some strange dns queries being made by my phone. I have attached a picture of the requests. Can someone tell me if this is normal of there is some malware or virus affecting my phone. Also, I have tried a factory reset on the phone since I first thought it was a virus/malware but the requests still continue. Any help would be appreciated, thank you.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
xyphos10 said:
Hello everyone, I got a wileyfox swift 2 phone a couple of months ago and once the android 8 update came out, I updated my phone. Now, recently I installed a pi hole server on my home network and noticed that there is some strange dns queries being made by my phone. I have attached a picture of the requests. Can someone tell me if this is normal of there is some malware or virus affecting my phone. Also, I have tried a factory reset on the phone since I first thought it was a virus/malware but the requests still continue. Any help would be appreciated, thank you.
Click to expand...
Click to collapse
many of those look like AD networks, legit ones though.

Note 5 possibly bricked/droidcam

{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I have an old Note 5 lying around with a cracked screen. Not worth using except as a backup, not worth selling. I had a great idea: use it as a webcam!
I downloaded droidcam, used it a few times, forgot all about it. Until yesterday.
I turned on the phone and the screen was as in the attachment. I used Android Control to mirror the screen to my PC (effortlessly) and make sure the phone was actually working. I figured that the last time I used the phone, I had actually left the phone connected to droidcam for a long time (forgot about it) and it may have done something to the display driver or some such. No biggie, I'll just reflash, maybe it'll solve the problem, maybe not.
After some struggle, got the phone into download mode and used Odin to attempt to flash 3 different firmwares, all for my SM-920 XSG (UAE firmware). The first time it made it all the way to the end when it failed to write. The other two fail early on. I even attempted to flash a PIT, which worked and then everything failed after just as fast as before the PIT flashing.
So, anyone have any idea what's wrong with the phone's screen? It was working before and literally had been left alone on a table undisturbed. Also, it would be nice to unbrick the phone, so that I can donate it (as a working phone sans screen) or at least try to sell it online to someone who would fix the screen (or a local shop).
You don't tell me nevermind

Categories

Resources