Phone infected with malware - Android Q&A, Help & Troubleshooting

a friend of mine has an Xperia Z3 imitation. his phone has app like netalpha, key chain and others with funny names installed. thing is, they are installed as system apps. cant uninstall them. the phone does not connect to a pc. it simply charges when plugged. tried resetting it but the apps are not erased. rooting using Kingoroot failed and phone is unusable.
Adds pop up all over the [lace and when it has mobile data or wifi turned on, it downloads and installs apps silently though i have noted that one app "com.google.keyguard" asks for install permision. any ideas???
kindly assist.

My uncle had the same infections symptoms except he got GNote3 and all i did was to use CM Security apps to remove all those nasty malware. Hope it helps.

Root the device using the following method and then remove all those apps using super su
[WARNING : I AM NOT RESPONSIBLE IF ANYTHING HAPPENS TO YOUR DEVICE. DO IT AT YOUR OWN RISK]
1. Download the file XperiaRoot_ALP.zip to your smartphone or computer from this link
https://yadi.sk/d/
and extract the zip file.
2. Open the folder you extracted, called XperiaRoot, and you will see an ALP folder that contains the following .apk files: Busybox, Recovery, Root, and SuperSU. A folder named XperiaRoot will be generated. If you unzipped the archive on your computer, you'll have to transfer the extracted files somewhere on your smartphone.
3. Go to your smartphone's Settings > Security menu and check the the option to install applications from Unknown sources.
4. Install the Root.apk file. Open the app and tap on the ‘Root’ button, then wait for it to root your device.
5. Install the Busybox.apk and Recovery.apk files in the same way.
6. Open the installed Recovery app and tap ‘Install Recovery’.
7. Boot into Recovery mode! First, power off your device. Then, press the Power on button, and when the LED light starts flashing, press the volume up or down buttons a couple of times. If that doesn't work, reboot, activate USB Debugging on your phone, and use Minimal ADB or ADB from the Android SDK to reboot the handset into recovery mode by typing "adb reboot recovery" inside the terminal.
8. Once you are into recovery mode, select Install and choose the SuperSU.zip file from the ALP folder.
9. Reboot your phone after flashing. You will see SuperSU app in App drawer, and the next step is to check for root access by using any Root Checker app from the Play Store.
All the best
Regards milkyway3

fazreen said:
My uncle had the same infections symptoms except he got GNote3 and all i did was to use CM Security apps to remove all those nasty malware. Hope it helps.
Click to expand...
Click to collapse
OK, Will try that. thanks

the link for the apps download is dead.

kvthedon said:
the link for the apps download is dead.
Click to expand...
Click to collapse
Take this new link
https://yadi.sk/d/zwepmEXIpWhoM
Regards milkyway3

if you are using original sony xperia z3, use pc companion and repair software. else, maybe phone is already rooted(if you have x-bo z3) with supersu just dial *#1234#. i have one too.

milkyway3 said:
Take this new link
https://yadi.sk/d/zwepmEXIpWhoM
Regards milkyway3
Click to expand...
Click to collapse
i got an error which read " Error: Invalid OTA package, missing scatter Installation aborted" when installing SuperSU.zip

kvthedon said:
a friend of mine has an Xperia Z3 imitation. his phone has app like netalpha, key chain and others with funny names installed. thing is, they are installed as system apps. cant uninstall them. the phone does not connect to a pc. it simply charges when plugged. tried resetting it but the apps are not erased. rooting using Kingoroot failed and phone is unusable.
Adds pop up all over the [lace and when it has mobile data or wifi turned on, it downloads and installs apps silently though i have noted that one app "com.google.keyguard" asks for install permision. any ideas???
kindly assist.
Click to expand...
Click to collapse
keychain is ok,but that 'netalpha' is a problem.
can u disable them?

BatDroid said:
keychain is ok,but that 'netalpha' is a problem.
can u disable them?
Click to expand...
Click to collapse
Yes i did disable them, here is the list of the apps i disabled:
Android SystemWebview
AppManage (X2)
Avatar
BeautySnap
EmailService
Google Play Store (because it auto runs and downloads apps)
GuardService
Homescreen tips
Keychain
Kiwi
LocationServices
netalpha(x3)
org.rain.ball.update
org.snow.down.update
PhoneService
SettingService
SystemLocker
Wolf
Most of app in the list above have version numbers "1.0" or something like that, which is diff from the 4.xx on authentic apps in the phone.

PAPalinskie said:
if you are using original sony xperia z3, use pc companion and repair software. else, maybe phone is already rooted(if you have x-bo z3) with supersu just dial *#1234#. i have one too.
Click to expand...
Click to collapse
unfortunately,it is not an original and it does not show up on the PC when connected. so PC is out. when i dial *#1234# it pops up " Unfortunately, Dialer has stopped"

kvthedon said:
unfortunately,it is not an original and it does not show up on the PC when connected. so PC is out. when i dial *#1234# it pops up " Unfortunately, Dialer has stopped"
Click to expand...
Click to collapse
it should direct you to supersu. else' try to install supersu.apk from other sources and clear its data to reset to default settings. it is x-bo right? x-bo's phone has supersu binary and it is in debug build.

Bought an dirt cheap Mi3 from a local tech forum via postage. Turned out it had a locked bootloader, not rooted and was laced with malware as system.. it was displaying ads/apps.. Fast forward.. This is how I solve my malware problem for the moment.. To temporarily CURE your device, install/sideload both Secdroid and DNS66 from fdroid/play. Firstly, turn on airplane mode, secure phone with Secdroid using its 2nd option. Lastly, start DNS66 and let it run at boot. This solved my problem and I've never seen any ad/app after. Phone's cool and data's back normal..

i had the same problem on a chinese phone, I had the "Geocode Service" trojan, anyway, I managed to disable it.
try removing the battery from the phone (if this is possible, I know the battery should be built in, but there is a connector that can be removed if you remove that black tape that covers the battery) when plugging into the PC, maybe it will enter in the correct mode

kvthedon said:
a friend of mine has an Xperia Z3 imitation. his phone has app like netalpha, key chain and others with funny names installed. thing is, they are installed as system apps. cant uninstall them. the phone does not connect to a pc. it simply charges when plugged. tried resetting it but the apps are not erased. rooting using Kingoroot failed and phone is unusable.
Adds pop up all over the [lace and when it has mobile data or wifi turned on, it downloads and installs apps silently though i have noted that one app "com.google.keyguard" asks for install permision. any ideas???
kindly assist.
Click to expand...
Click to collapse
Xperia clone ? Its a Mediatek phone.
First Factory Reset... And do not connect to internet (WIFI,Data,etc)
Try to disable Netalpha. (setting-Apps..... )
Root with Kingroot or Kingoroot PC versions ( but need Debug Mode active in phone ), install Link2Sd and freeze suspicious apps (apps with two names) and try to unisntall.
Netalpha app itself install with system permission. So cannot be unistalled even with root. I instal Busybox and change permission and attributes and rm the file.
I hope helps
Sorry for my english.....

Related

[Q] Stuck disabled app

I've got an app that is listed as 'disabled' in application manager list, but when I select it to try and re-enable the button is grayed out and says 'disable' on it as if it was never disabled to start with.
How do I un-stick this app? TIA
What app is it?
You should be able to use any app or file manager to uninstall it.
Do you have root access?
440bro said:
What app is it?
You should be able to use any app or file manager to uninstall it.
Do you have root access?
Click to expand...
Click to collapse
The basic 'email' app. I had originally disabled that and 'exchange services' way back at the beginning (root required) because I wasn't using anything but gmail and was paring down on apps as much as possible. Now I have a reason to use it, and while I was able to enable 'exchange services' again, the other one just seems stuck. After the update to ICS and then JB I never installed root, and with the OTA updates it seems this particular app has gotten into a bit of a mangled state.
tigerknight said:
The basic 'email' app. I had originally disabled that and 'exchange services' way back at the beginning (root required) because I wasn't using anything but gmail and was paring down on apps as much as possible. Now I have a reason to use it, and while I was able to enable 'exchange services' again, the other one just seems stuck. After the update to ICS and then JB I never installed root, and with the OTA updates it seems this particular app has gotten into a bit of a mangled state.
Click to expand...
Click to collapse
Well you can try installing them again. I'm going to assume you're on the latest 4.1.2 version. So here is the email apk and here is the exchange apk just in case you want to reinstall both.
Or you could gain root access and use an app to unfreeze them that way.
To root the stock 4.1.2 rom
1. Use Odin 1.85 in Admin Mode for Windows users.
2. Install TWRP 2.5 via PDA settings.
3. Reboot phone into Recovery.
4. Install SuperSU via the Zip.
5. Reboot phone and viola You're rooted!. SuperSU is there and works.
440bro said:
Well you can try installing them again. I'm going to assume you're on the latest 4.1.2 version. So here is the email apk and here is the exchange apk just in case you want to reinstall both.
Or you could gain root access and use an app to unfreeze them that way.
To root the stock 4.1.2 rom
1. Use Odin 1.85 in Admin Mode for Windows users.
2. Install TWRP 2.5 via PDA settings.
3. Reboot phone into Recovery.
4. Install SuperSU via the Zip.
5. Reboot phone and viola You're rooted!. SuperSU is there and works.
Click to expand...
Click to collapse
Grr. I downloaded the email apk and tried to run it, and it just failed with 'application not installed'. Apparently I buggered myself up good - I'll have to go the root option, any tips/tricks to keep in mind before I do that?

[Q] commercials appers in my screen at any time

Hi
I have a problem in my phone that whenever I make a phone call or send a text message a commerical appears in my screen..it's really annoying
it appears in my whole screen and I can remove it by pressing the X button on the corner
is there anything I can do? I tried to remove some apps and clear my browser's history but no luck
Have you rooted your phone?
Have you installed any apps/mods/whatever from anywhere other than the Play Store?
If yes to the last one (unless it was an XPosed Module), uninstall it, then reboot and see if the problem re-appears.
If you have uninstalled everything other than what came on the phone to begin with and you still have the problem, copy all your music/photos/etc off the phone, then use FlashTool to re-install the ROM and choose the wipe SD card option, then set the phone up again from scratch and hope for the best.
Tachikoma_kun said:
Have you rooted your phone?
Have you installed any apps/mods/whatever from anywhere other than the Play Store?
If yes to the last one (unless it was an XPosed Module), uninstall it, then reboot and see if the problem re-appears.
If you have uninstalled everything other than what came on the phone to begin with and you still have the problem, copy all your music/photos/etc off the phone, then use FlashTool to re-install the ROM and choose the wipe SD card option, then set the phone up again from scratch and hope for the best.
Click to expand...
Click to collapse
I didn't root my phone and I didn't install any apps outside the play store.. I will try the uninstall every app method and I will see
this sounds like an app you have installed, try uninstalling some recently installed apps and see if your problem goes away
GoSMS is always doing this if u are not a premium user.
Sent from my D6503 via Tapatalk Pro

Help Me Please kindle fire home screen blank

So on my kindle i had everything installed to have the play store working and i got the play store to work and i got the youtube app to work. And so what happened was i deleted the youtube app and installed the newest version and when i opened youtube it gave me the google play services error, but the play store itself still worked.
So what i did was i uninstalled all the google account manager, google services frame work, etc.
And tried to fix the youtube issue by reinstalling all of those things. I started by installing google account manager, and then i rebooted it to install the next thing. Only, when it started up i could unlock the device, but none of the apps would load. So i did a stupid thing and factory reset it, which i think got rid of the root.
I have no idea what to do. I couldn't find any thread about this.
The notificaton bar works and the navigaton buttons show up on the side. So i can get to settings, but the carousel and home screen won't load after i unlock it
here are some pics:
i can't post links because i'm a new member so type it in without spaces
http :// imgur . com / a/ uuB6f
What version of firmware do you use?
ONYXis said:
What version of firmware do you use?
Click to expand...
Click to collapse
13.3.2.6
Sorry, I missed that you did hard reset. without root I think i can do nothing.
Only way is update to 13.4.1..1 http://forum.xda-developers.com/kindle-fire-hdx/general/update-1314-4-1-1-probably-sangria-t2901813 (if you can go to settings) and lose root. Of course if your devices HDX 7.
ONYXis said:
Easiest way , i think, is install safestrap and flash stock firmware by SafeStrap (without wiping anything!)
after that gapps need to install again.
Adb working?
Click to expand...
Click to collapse
How am i going to install safestrap when i can't open any apps?
android2204 said:
How am i going to install safestrap when i can't open any apps?
Click to expand...
Click to collapse
Sorry, I missed that you did hard reset. without root I think you can do nothing.
Only way is update to 13.4.1..1 http://forum.xda-developers.com/kindle-fire-hdx/general/update-1314-4-1-1-probably-sangria-t2901813 (if you can go to settings) and lose root possibility.
What do you mean by loose root possibility?
android2204 said:
Do you mean by loose root possibility?
Click to expand...
Click to collapse
Sorry. English isn't my native language so I don't understand your question.
I wrote that if you upgrade to 13.4.1.1 you will not be able to obtain root.
How do i update?
http://www.amazon.com/gp/help/customer/display.html?nodeId=201390340
link to update file https://kindle-fire-updates.s3.amazonaws.com/update-kindle-13.4.1.1_user_411009920.bin
Yes. but how would i install it?
you wrote ""So i can get to settings, ", what difficulties after that?
Can you get into Settings - Device - System Updates?
nevermind. so i followed the instructions and put the update into the internal storage folder but when i went into system updates on my kindle the box said "check now" instead of "update" so when i tap check now it says "last update failed".
android2204 said:
kindle the box said "check now" instead of "update" so when i tap check now it says "last update failed".
Click to expand...
Click to collapse
Try to turn off wifi and reboot.
You should see that your device has found update, no more variants.
I'll try it again after school. What would I do next if I get the error again?
I have no idea. This is one variant. if tablet do not found update - this says about broken symlinks for example or something else that anyway do not fix without root.
btw check your root status:
adb shell
su
ONYXis said:
I have no idea. This is one variant. if tablet do not found update - this says about broken symlinks for example or something else that anyway do not fix without root.
btw check your root status:
adb shell
su
Click to expand...
Click to collapse
I didn't really understand any of that. What is a broken symlink? And I don't think I'm rooted because I factory reset it.
Also, how could I check root status and what would be the purpose?
Okey. You not rooted now, so do not pay attention.
Your one method to get working device is update firmware.
In way that I described.
If you do not see "update" button after pulling file - sorry. no other idea.
So basically, if this doesn't work I'm screwed?
Anyone else got any ideas?

Kingroot stuck as system apps

I rooted my phone using kingroot before and after removing al root authorization i found that kingroot has been installed as system app
also whenever i open the kingroot app it restarts my phone
how could i completely remove it
there's also the problem of the phone not able to connect to google play store (no connection, cannot login account)
my phone is NTT Docomo Sony Xperia SO-O4E
tried factory reset twice, deleting cached apps data, still doesnt work
a basic rundown on how it all happened :
-uninstall some bloatware from phone
-phone starts to restart randomly
-deleted cached apps data, no more random restart
-remove kingroot root auth and uninstall
-found out that phone cannot connect to play store, also kingroot has installed itself as system app
anonweeb said:
I rooted my phone using kingroot before and after removing al root authorization i found that kingroot has been installed as system app
also whenever i open the kingroot app it restarts my phone
how could i completely remove it
Click to expand...
Click to collapse
If your bootloader is already unlocked, the easiest way would be to restart the phone in fastboot mode, then boot (you don't need to flash it) TWRP and install SuperSU from a flashrecovery zipfile. This will remove kingroot app and running processes (mind you, there may be some dead kingroot traces left over on the filesystem - if you want to remove these too, you'll have to do so from a shell with root permissions). I haven't tried this with the Sony Xperia ZR/NTT Docomo Sony Xperia A (SO-04E), but it seems to work with most phones that are supported by TWRP. I wrote a short guide on how to do this (it's for a different device but these steps should be mostly generic if you have the necessary prerequisites in place).
Another good thing about SuperSU is that if you don't wish to keep root, it will remove itself cleanly and completely from your system (you'll find the unroot option in the apps settings). If however you would like to keep root, then SuperSU is an app that doesn't spy on you and doesn't phone home (I did a thorough check of the shell script used to install SuperSU and a rough check of the SuperSU apk using strings and wireshark only yesterday and as far as I could tell, it doesn't attempt to do anything malicious or touch files that it doesn't need to touch for its purpose, nor did it start a single internet connection by itself). The automatic NVISO analysis at https://apkscan.nviso.be/report/show/99a7841aa3eeaefa69f767602b0c454c confirms this too. Just saying this in case you decided to move away from root due to spyware concerns.
TWRP is an open source project. Their Homepage is https://twrp.me/
The TWRP image files for your device arel located here https://dl.twrp.me/dogo/
SuperSU homepage is https://www.chainfire.eu/ , the latest flashrecovery zipfile can be found here http://www.supersu.com/download
Both projects also have their own sections here on xda.
SuperSU also has it's own sections here on xda.
there's also the problem of the phone not able to connect to google play store (no connection, cannot login account)
Click to expand...
Click to collapse
Was this problem related to the rooting process in any way?
Does your internet access work otherwise?
What happens exactly when you start google play?
hi, thank you for the reply
the phone has only been rooted once with kingroot app, which i have removed (both the supposed app and the root auth), but kingroot app installed itself as system app without my permission and whenever i open the app my phone reboots
i'll try looking for ways to flash the phone
as for the play store, it always show the no connection screen even though i can browse the internet without any problem
i tried following the steps from google help page but it doesnt seem to do anything
i'm thinking that the hosts.txt file cause this so im trying to delete it, but i found no other way to delete it without rerooting my phone
i tried factory reset twice but it doesnt seem to help either
thanks before and sorry for the late reply
EDIT : i dont think i can unlock the bootloader officially so i need an exploit
anonweeb said:
EDIT : i dont think i can unlock the bootloader officially so i need an exploit
Click to expand...
Click to collapse
[/QUOTE]
In that case, you will have to root first. Once having gained root access you can unlock the bootloader. To root, you can either use the kingroot app you used before (not much to loose, since you already installed it and its spyware the first time, and you will later be able to remove it with SuperSU). Or you can try towelroot, although if your smartphone has seen firmware updates, that will propably no longer work. There may be other, more current options - search trough the Xperia ZR Section.
Once you have root, you can use adb and fastboot to boot the latest TWRP for Sony Xperia ZR, then install the latest SuperSU recovery flashable zip. Using that you can completely remove Kingroot even as a system app and afterwards remove SuperSU itself, which will cleanly uninstall itself via Settings.
Code:
as for the play store, it always show the no connection screen even though i can browse the internet without any problem
i tried following the steps from google help page but it doesnt seem to do anything
i'm thinking that the hosts.txt file cause this so im trying to delete it, but i found no other way to delete it without rerooting my phone
i tried factory reset twice but it doesnt seem to help either
I would try the above first, see if the playstore works again after you SuperSU has completely removed Kingroot (reboot), and if it doesn't take a look at the hosts file. Then uninstall SuperSU when you don't need root anymore...
I can help along with adb/fastboot commands, but you need to root your device first (and install the necessary drivers for your phone on your computer).
Good luck!

alcatel onetouch pop 4 5051x

Hello, I have an alcatel pop 4 model 5051x.
4 useless apps consume 50% of the battery and I would like to delete them (force stop does not work) and for that I need to root my phone.
The problem is that this model has the bootloader locked.
I tried a lot of methods, from kingoroot to adb but nothing happened. Yet he is recognized by adb.
I also downloaded all the drivers including qualcomm as well as android studio ...
The phone does not even have a day with these apps, help me please!
And if you have the solution, do not hesitate to explain step by step, thanks!
i succeeded !
I succeeded !!!
For those who are interested :
- install Kingroot 5.3.0 apk on your mobile (uninstall the installed app)
- run the root as many times as necessary, making sure that you have granted the administrator and accessibility rights
when the phone restarts, restart it
- as soon as the phone is rooted (be careful it's temporary but you can start again if necessary), install the flashify app
- choose "recovery image", and choose where you put your twrp http.s://drive.google.com/file/d/0B6EQd1aL0EmWX3I2WEFuVmdUcUk/view
- restart on the twrp (I took the opportunity to make a backup above all, count 10/15 minutes)
- launch the Supersu zip install (SuperSU-v2.82-201705271822) that you have taken care to place at the base of your sd card
- restart, supersu is installed
- to transfer my apps, I chose besides the app uninstall system (root)
And finally, here is your Alcatel pop 4 5051x which holds the load again and you can control without parasites
Hi. Now I need your help, since you succeeded, and apparently you're the only one on xda-developers and on the whole Internet!
As I am a complete newbie, please tell me what exactly did you mean in your last bullet ("to transfer my apps, I chose besides the app uninstall system (root)"), and how do you actually remove the 4 useless apps?
Thanks!
RaNo99 said:
Hi. Now I need your help, since you succeeded, and apparently you're the only one on xda-developers and on the whole Internet!
As I am a complete newbie, please tell me what exactly did you mean in your last bullet ("to transfer my apps, I chose besides the app uninstall system (root)"), and how do you actually remove the 4 useless apps?
Thanks!
Click to expand...
Click to collapse
"App uninstall system (root)" is an app from Google play but you can choose another one of course, just choose one "root" in order to access to app system.
Be careful of what you desinstall. To choose apps, I've looke on the battery, which apps were consuming the most and I uninstalled they after searching the net to make sure they were not needed.
I offered this phone to my son 1 month ago and he works very well included with 3D games with a long life battery !
Just wanted to confirm that this is working. I installed Flashify, downloaded the TWRP img and supersu zip to my SD card in advance to avoid any issues, and after four tries or so it finally rooted. Thanks OP!

Categories

Resources