Infected with malware via chrome - Android Q&A, Help & Troubleshooting

Hey guys.
When I was exploring the Internet via chrome my phone has been infected. The new tab opened by itself, phone started to vibrate and page said that my phone is infected and that I should download Antivirus (but this page was similar to other pages with slogans "YOU WON 100K$ CLICK HERE etc.) so I ignored it. Now after every call (only then) Clean Master is saying that I already installed "Games " so I can delete apk file. Sometimes I press YES or sometimes I press No and sometimes it appear on desktop as game (last time it was yahoo logo) sometimes it doesn't. Clean Master Says That is malware with ".bf" extension. I tried every AV, even Avast didn't find anything. I tried also looking for this file by my self but no results (CM Antivirus also find nothing) . (gonna add name of virus for better tagging)
NAME OF VIRUS:
Android .Troj.tb_downloader.bf
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}

I think that is ads... Btw to be safe you can always format your phone, be sure backup your data and contacts.. If you are rooted use adblocking software.. If not use browser which supports adblocking features..there are many in playstore
Sent from my GT-I9300 using Tapatalk

Ghostery is a great adblock browser

Related

Rogue apps?

In my settings under manage applications, I have 2 apps (wolfram alpha and blood brothers) that seem to have a slight... problem.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
According to link2sd and launching blood brothers from a homescreen shortcut, those 2 apps are not installed. Yet, when I sideload blood brothers (not officially compatible with my phone but works nevertheless) it gives me the prompt saying this app will replace another app and all data will be saved. Then I hit install and it says "application not installed"
So I decided to open up settings and uninstall them from there, but it FCs every time I tap on either one of them.
Then, I went into /data/app, deleted both apks, went into /data/sdext2/data and deleted the data files for both of them. I also went into /data/data to delete all data. I also think there were apks in /data/sdext2 which I deleted. Anyhow, from screenie you can see both apps have 0.00 bytes of storage taken up, which I assume means I've cleared everything.
But they're still there, I want to use the apps and its annoying me to have those show up in settings.
So I went into TiBackup. They didn't show up. Like stated before, link2sd said nothing.
The Play Store says wolfram alpha is uninstalled, but here's the weird thing. I refunded the app (because it is not worth $3!) And it has this weird residue left over. Couldn't care less about it right now, but gimme blood brothers!
Any ideas as to what could have caused this?
Sent from my MB508 using xda premium
What is the equivalent cp usb for d405n? I only see Diag Settings and Data Settings!

Doubts about OneNotes

Hello,
I have some questions about the default app OneNotes. Every time that I open the app, it tries to sync. I dont know why it is automatic... And i would like to know if is possible to delete the app or change this configuration.
One more thing, when I open the app, at the first screen, i have 2 "notes". Why SkyDrive created a note ?
I cant delete anything..
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
The app works flawlessly at least to me, and I am using it a lot. Combined with the web app, it is just perfect!
Now, about deleting stuff, u have to wait for sync to be finished, and then just a long press and then delete!
Dear friend,
OneNote is a cloud program synced with your SkyDrive account so that you wont never miss a note or a change. This is why everytime you open on your mobile or on your computer, the program keeps syncing.
You cant remove it because its part of the system, its part of office suite. Just dont use it, you dont have to open it for nothing else. You cant configure it either because of it purposes.
Like a said, as the program keeps it data on skydrive, you will automatically have one there and one in your phone, so the one on your skydrive you can change it wherever you are and on your phone is your local one that you can modifiy and sync it.
This program is too easy to use like all cloud system that Office has, i dunno why so much trouble with this. Just dont use it if you are having so difficult. Try Evernote so.
Thank you all, guys.
You guys gave me excellents explanations. I will think about it..
Att,
Arthur

[Q] alot http requests from my phone

Hey everybody, i hope you can help me.
I've a Samsung Galaxy S3 GT-I9300 rootet and since 2 weeks with CM11 M7. I use the Tool Reverse Thetering from this thread Link while at work to have some kind of internet on my phone.
The tool shows all kinds of up and downloads. After flashing my Phone with CM11 M7 i used the tool again and noticed that after 2 minutes in standby my Phone starts to do a lot of http connections. (See 2nd image). I know that the phone updates all the messaging and mail apps but with stock rom ist wasn't that often. In normal conditions the requests look like this in standby:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
But after around 2 Minutes the Phone starts to request some http adresses all the time and it doesn't stop. This looks like this for example:
(Sorry for the big image)
Unfortunately i don't know if the phone does this only when using Reverse Thetering or also when i'm online with wifi or gsm. I can only see and chek it with reverse thetering.
I've bought Kaspersky Internetsecurity and tryed other apps from avg or avira to check my phone for a virus or similar bot non of them found something (i used each app on its on with only on app installed at the time)
I'm not an expert but it looks like my phone could be infested by some kind of botnet or similar but i'm not sure. Has anyone a idea what this could be and how i could stop it or get rid of the whatever i have?
Thanks a lot for your help.

Google Drive Backup - No Backup Found

I had problem with accidentally updating my Oreo 8.1 SGS9+ to Pie while being modded with Swift Installer. It failed. So I had to flash stock Oreo rom with Odin to get it working. I did a factory reset to get it running because it couldn't optimize apps.
On clean Oreo I tried to restore my old progress by logging to my main Gmail. As it always worked on all my devices in the past. But FML now everything refuses to work.
When I tried to log at the welcome screen and restore data from the old device (same model same system) NOT create new it shows something like this
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
which is not true, look at my drive -
I'm looking everywhere for a solution as I can't get past welcome screen and i won't create new (exactly same) device because I don't believe at all that Google won't overwrite the data I NEED.
Google support is also on top of **** - https://support.google.com/drive/answer/6305834?co=GENIE.Platform%3DAndroid&oco=1 by manage they understand DELETE.
What should I do. I even flashed lineageOS 15 as i thought its Samsung fault as its also based on oreo 8.1
Please help.
I have skipped the welcome screen to add account and see what will be restored. NOTHING no call logs, SMS, calendar, and of course no apps. Play store sees only 10 random apps when I can easily" count on my fingers" to 50

Very annoying and dangerous options disguised as "feature" (Bixby and dex)

Hi
Im the same guy who made this post a few months-
Now, Im trying to get rid some bloatware that aƱsp could be used in malicious way like _
Dex. An attacker could do whatever on the users laptop and the guy wont even notice. Settings is showing as dual app even tho ive never touched dual apps.. i guess this happens once you open dex for the first time
So, any simpl.istic way to compltetely get rid of DEX and Bixby Routines?
The elephant on the room here is that google assumes any random google account logged in that tablet. OWNs the tablet.
Ofc this could be done by having good google security passwords on the google account. Enforce tat!
Or ask us if we reeaaaalllly wanna execute those random rutines someone just sent to is throw wifi
https://imgur.com/a/AMnRWg8
Use a Package Disabler or adb edit to kill them.
I disable both.
blackhawk said:
Use a Package Disabler or adb edit to kill them.
I disable both.
Click to expand...
Click to collapse
I need to completely get rid of those normie features. Tell me which files I have to delete do it doesn't work at all.
This is what's on my N10+/Pie variant.
You might want to keep Bixby Vision though if you have it. Used for reading barcodes etc.
Not sure if it's dependent on any other Bixby apps.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}

Categories

Resources