Advice about malware - Android Q&A, Help & Troubleshooting

Hi Folks.
I've done something a bit silly and hoping some Android expert on here may be able to help me.
I stupidly installed an app from an external source using a link that was given me for a specific app.
I am now freaking out about malware/spyware and all the rest of it.
At this point, I must point out that there is nothing to immediately suggest the app is bad. I only installed it a few hours ago on my phone but there hasn't been anything suspicious like extra battery use, heat, unknown apps in the list of battery usage or pop ups or anything like that. It could be that it's absolutely fine (and probably is.)
What I'm more concerned about is that there may be some nefarious background process running that means I suddenly wake up and find my bank account has been drained, or I'm being blackmailed by some Russian hacker that has hold of my emails and photos etc.
TWO IMPORTANT DISCLAIMERS (before anybody states the below:
- Yes, I know it was a stupid thing to do and I don't know what came over me. But it is done now.
- I know that a full factory reset is the best way to clear all but I'm desperate to avoid that. It took me two days to setup my new S21 Ultra and hate the thought of going through all of that again!
I know that Google Play Protect helps with apps from the GP Store, but I assume this is not relevant here because it came from an external source. Is there any kind of facility where I can upload the app and it scans it? Or am I screwed?
I also know you can download Norton etc but I read that they may not be effective on things like this. FYI, I am running the January 1st Android security patch (the most recent available.)
Thanks in advance.

Scan the apk file with online Virustotal.
Meh... show us the apk in question.
I have a few side loaded apps, so what?
Playstore is no sure bet either... load what you need, disregard the rest and toss the bad ones.
A badly written app can cause headaches even after it's uninstalled. Not as common with Android as in Windows but it happens.
On a clean load I'm careful what I install ie known good apps.

blackhawk said:
Scan the apk file with online Virustotal.
Meh... show us the apk in question.
I have a few side loaded apps, so what?
Playstore is no sure bet either... load what you need, disregard the rest and toss the bad ones.
A badly written app can cause headaches even after it's uninstalled. Not as common with Android as in Windows but it happens.
On a clean load I'm careful what I install ie known good apps.
Click to expand...
Click to collapse
Thanks. I've attached the apps. Thanks for your help and advice. I've scanned them on VirusTotal and they appear to be clean..

If you are worried about this, then you need to flash the phone. Then install the app to protect your phone from the official source.

philliplavelle said:
Thanks. I've attached the apps. Thanks for your help and advice. I've scanned them on VirusTotal and they appear to be clean..
Click to expand...
Click to collapse
Did the reload go well?

Related

[Q] Can I fool the market about my system version?

I have a tablet with android 2.3.5 on it, but I notice there are lots of apps written for android 3.0 honeycomb. I'd like to play with some of them, but the market tells me the apps are not compatible with my device. And it won't let me even download them.
Is there a way I can make my tablet report to the market that it's running 3.0?
Thanks.
Dan
Even if you did that, the apps still wouldn't work. They would just say "error parsing package" before even installing. If they "happened" to install, they would just force close on start.
Theonew said:
Even if you did that, the apps still wouldn't work. They would just say "error parsing package" before even installing. If they "happened" to install, they would just force close on start.
Click to expand...
Click to collapse
I'm going to disagree with this. There are plenty of apps that don't work on certain devices according to the Market yet run perfectly fine on those devices. When it comes to apps made specifically for 3.0, you're more likely to run into problems with functionality, force closes, or screen size. Parsing errors are generally from a problem with the download or package itself, but I could be wrong.
Your options are to change the build.prop to read 3.0 (assuming that's how the Market discovers your build) or to download from another source. I don't know if Amazon does some type of device check or not, but you can try that.
If you decide to try editing your build.prop, back it up first just in case.
Sent from my Evo + MIUI using Tapatalk!
plainjane said:
Parsing errors are generally from a problem with the download or package itself, but I could be wrong.
Click to expand...
Click to collapse
Yes, this is wrong (in some cases). Parsing package errors occur based on firmware version. If you tried to install an app made for Gingerbread on Froyo, you would get this error. Since the OP wants Honeycomb specific apps to be able to run on Gingerbread, this error is highly likely to occur. Even if the an app worked, then there would be major functionality problems.
I think I follow: if the functionality the app is expecting isn't there, then there *will* be a problem. That makes sense.
However, I have managed to get my hands on a Motorola utility (MotoPrint) from a xoom image I found on the web, that *did* work. Admittedly, it was either going to work or not.
In this instance, it piqued my interest. And made me think that the app creators *may* be, um, overselling the "newness" of their apps by promoting them as "honeycomb." And I just wanna play. XD
I've already tried editing build.prop to no avail tho. So that's why I'm soliciting ideas.
Dan
Try and sideload the apps in question? But as posted some apps that require HC will not run or run correctly on GB.
:edit:
cranky_dan said:
However, I have managed to get my hands on a Motorola utility (MotoPrint) from a xoom image I found on the web, that *did* work. Admittedly, it was either going to work or not.
Click to expand...
Click to collapse
You already figured it out
Okay then. Thanks for ringing in, everybody.
> You already figured it out. <
I always wonder if there's another way that my noob eyes and brain don't know. So thanks.
Dan
Golleeee. Ah sure am smurt!! XD
Dealing with apk files can be easier than the android market.
And everything is free if you know where to look *cough*
Based on your first post, google will not allow you to buy the apps you want, correct?
That's not a fault of anything you are doing. Google doesn't want you to buy those apps apparently. That doesn't mean you can't "get" them.
BenKranged said:
Based on your first post, google will not allow you to buy the apps you want, correct?
Click to expand...
Click to collapse
All of the apps I have been viewing on Tablified are Honeycomb. Many are free. There are few nice ideas that I'd simply like to see if they work on my VeganGinger G-tab.
Google simply says the app is incompatible with my tablet, and greys out the install button.
So far, this is the most annoying thing in Android to me. Dammit, just let me try it. I know I may not get *all* the functionality. I'd just like to see if it's a tolerable thing for me. Without needing to jump thru hoops.
Dan
Welcome to fragmentation.
Heres a legal source for free apks.
http://androiddev.orkitra.com/download/apps/
On a sidenote I use a Galaxy S Captivate with 2.2 froyo.
There are some apps (games mostly that I have encountered) that will not run at all on less than android 2.3.x regardless of where you get the apk from.
So I can only assume the same is true with 2.3.x/3.x
Thanks! I appreciate it!

[Q] (Rooted) Safe apps to uninstall?

My phone is rooted and i would like to know which apps are safe to uninstall that are slowing down my phone so I can speed it up. ? I have root explore and would like a guide on how to uninstall these apps that are slowing my phone down. Thanks to anyone willing to help.
The answer is in here:
http://forum.xda-developers.com/showthread.php?t=1254140
lordmorphous said:
The answer is in here:
http://forum.xda-developers.com/showthread.php?t=1254140
Click to expand...
Click to collapse
Thank u uncle fester but there's no answers to my question in that link.
Please see this thread. I wouldn't remove the Package checker apps as noted in this thread. ( PackageChecker.apk [com.oem.packagechecker]
PackageUpdate.apk [com.oem.packageupdate])
http://forum.xda-developers.com/showthread.php?t=1245381
Try looking here
At the bottom of the OP is a link entitled List of Apps Safe to Remove From Stock ROM. Its there...look again.
Sent from my Dell Streak using xda premium
lordmorphous said:
At the bottom of the OP is a link entitled List of Apps Safe to Remove From Stock ROM. Its there...look again.
Sent from my Dell Streak using xda premium
Click to expand...
Click to collapse
Morpheus you should already know he's partially illiterate, were he not, then he would have been able to find the answer and not be spoon fed from his high chair
Chirunavvutho said:
I wouldn't remove the Package checker apps...
Click to expand...
Click to collapse
Why?
/10char
Strephon Alkhalikoi said:
Why?
/10char
Click to expand...
Click to collapse
Because, I don't think removing them did any good. Does anyone know what is their exact purpose?
Again, why?
Ok...let me rephrase. Why don't you think removing them did any good?
The apps are listed in the "safe to remove" section of the post as they do not affect the operation of the ROM. If Manii believed those apps shouldn't have been removed, he wouldn't have put them in that list. Regardless of that, if you're going to make a blanket statement that you don't believe those apps should be removed, be expected to provide a better explanation than "because" when someone asks you "why".
Manii likely would know what they are for. Ask him.
They're mainly for ota updating to my knowledge, as custom roms cant ota update they functionally dont do anything.
I've had them uninstalled for a while and i dont believe anything changed.
The only thing that shouldnt be removed that isnt a core android app is dell settings and internet provider.
TheManii said:
They're mainly for ota updating to my knowledge, as custom roms cant ota update they functionally dont do anything.
I've had them uninstalled for a while and i dont believe anything changed.
The only thing that shouldnt be removed that isnt a core android app is dell settings and internet provider.
Click to expand...
Click to collapse
Why Dell Settings? I have blindly been removing it from every rom I install.
I cant recall why exactly, i know stageui partially depends on it and something else does in android core.
dell settings and internet providor are the only things in com.dell and not com.oem for a reason
Strephon Alkhalikoi said:
Again, why?
Ok...let me rephrase. Why don't you think removing them did any good?
The apps are listed in the "safe to remove" section of the post as they do not affect the operation of the ROM. If Manii believed those apps shouldn't have been removed, he wouldn't have put them in that list. Regardless of that, if you're going to make a blanket statement that you don't believe those apps should be removed, be expected to provide a better explanation than "because" when someone asks you "why".
Manii likely would know what they are for. Ask him.
Click to expand...
Click to collapse
Please check the revised list. They are in the possibly not safe to remove zone now.
Manii provided his justification in favor of removing those two apps. I'm waiting for your justification in favor of NOT removing those two apps.
In simpler language, you still have yet to answer my question. Manii placing those apps into a gray area "Possibly Not Safe To Remove" does not render the question invalid.
Most of the list is self-explanitory just by the names:
It falls under:
Stuff you can download outright on market
Non-system apps that are not available on market
StageUI
engineering mode apps
logging apps
the 4 borderline cases
those are:
Calibrator.apk [com.oem.calibrator]
DisplayVersionInfo.apk [com.oem.mode]
PackageChecker.apk [com.oem.packagechecker]
PackageUpdate.apk [com.oem.packageupdate]
Last two are pretty obvious, they're used to ota update, removing it breaks it. Custom roms cant ota update to begin with so it's ok for them. If you're on a stock rom it depends on weither or not you consider being able to ota update important. (updating from recovery mode is something entirely different)
I really dont know what calibrator and displayversioninfo do (besides what their name obviously is), but they're not com.oem.engineeringmode.* so they could be important. But as many roms without them seem to run properly they might not be critical.
I left all 4 in since they dont really take up that much resources (rom wise and ram/cpu wise).
The last com.oem.* app that isnt com.oem.engineeringmode.* is
PreLoadNetworkSettings.apk [com.oem.prenetworksetting]
which is used to load new APNs when switching carriers/sims. If your apn is already properly loaded you COULD remove it, but if you need to auto-load new APNs for whatever reason removing that will break that function
Those 5 apks are every com.oem.* that isnt the mentioned com.oem.engineeringmode.*
Technically you can remove the majority of the apks and the system will still boot, just that every other apk has a defined function and removing it will break that functionality.
ALSO, the list is not and never will be perfect, unless someone on the rom team wants to come forward and document them clearly it's all though trial and error. The borderline cases are the only ones that need any real testing as I know for a fact that the majority of the com.oem.engineeringmode.* apks are never active as dell disabled eng mode in retail roms. You CAN manually activate functionality in them but they're more or less dorment code in the roms.
Strephon Alkhalikoi said:
Manii provided his justification in favor of removing those two apps. I'm waiting for your justification in favor of NOT removing those two apps.
In simpler language, you still have yet to answer my question. Manii placing those apps into a gray area "Possibly Not Safe To Remove" does not render the question invalid.
Click to expand...
Click to collapse
I just wouldn't remove them and wouldn't recommend someone to do it if I wasn't comfortable to do so in the first place.
Whatever floats your boat..
What would float my boat is for you to answer my question. There must be a reason behind you saying what you did or else you would not have said it at all.
What is that reason, or do you even have one?
Freeze
If you are worried about it, just use an app freezer, run it a few days with the apps you want off the phone frozen. Then if no ill effects, remove them.
That's what I did.
I was a bit more daring. I simply deleted them and called it a day. I figure that if I truly had an issue I could just run my backup. At worst, reinstall 360.

Infected with malware?

Hi.
My girlfriend has a Samsung Galaxy S II that has been acting a bit weird recently. Battery life has become extremely short, and she discovered hundreds of files all with names beginning with "tracker-c6446d57267343". Most mysterious of all is that something is somehow using the GPS even though it has been deactivated in the settings.
I'm suspecting her phone is infected with malware, and I'm planning to do a full wipe next time we meet. She's downloading AVG from Google Play right now to run a scan, but I'm going to do a full wipe anyway just to be sure and because she wants to have a clean start anyway.
I'm mostly curious if anyone has encountered this before. Is it malware? If so, how harmful is it? Keylogger, possibly?
Thanks.
CNMOH said:
Hi.
My girlfriend has a Samsung Galaxy S II that has been acting a bit weird recently. Battery life has become extremely short, and she discovered hundreds of files all with names beginning with "tracker-c6446d57267343". Most mysterious of all is that something is somehow using the GPS even though it has been deactivated in the settings.
I'm suspecting her phone is infected with malware, and I'm planning to do a full wipe next time we meet. She's downloading AVG from Google Play right now to run a scan, but I'm going to do a full wipe anyway just to be sure and because she wants to have a clean start anyway.
I'm mostly curious if anyone has encountered this before. Is it malware? If so, how harmful is it? Keylogger, possibly?
Thanks.
Click to expand...
Click to collapse
wow, first post for ya huh? good for you.
dont waste your time with AVG. just wipe the phone. and tell her not to install a bunch of stupid apps.
BluePoint Antivirus is my personal fave
Sent from my Samsung Galaxy SII
CM9 Stable/Siyah 4.1
topiratiko said:
BluePoint Antivirus is my personal fave
Sent from my Samsung Galaxy SII
CM9 Stable/Siyah 4.1
Click to expand...
Click to collapse
Lmao. anti virus on android. you guys are funny!
U know its pointless right?
MotoMudder77 said:
Lmao. anti virus on android. you guys are funny!
U know its pointless right?
Click to expand...
Click to collapse
Exactly. It is. Odds are someone installed an app on yer girlfriends phone to be able to track her, tape pictures with the camera remotely, steal her credit card info, use the mic to record what's going on , etc. All of this can be achieved with ONE app and allows the person who installed it to remotely access the device. Also the app hides itself from detection in the app drawer and in the app manager . The legal reasons to install it are for if u lose your phone. But if someone got a hold of her phone they could easily have put this on and set it up within minutes. In other words. Someone can hear and see everything she's been doing.
Sent from my SGH-I777 using Tapatalk 2
Phalanx7621 said:
Exactly. It is. Odds are someone installed an app on yer girlfriends phone to be able to track her, tape pictures with the camera remotely, steal her credit card info, use the mic to record what's going on , etc. All of this can be achieved with ONE app and allows the person who installed it to remotely access the device. Also the app hides itself from detection in the app drawer and in the app manager . The legal reasons to install it are for if u lose your phone. But if someone got a hold of her phone they could easily have put this on and set it up within minutes. In other words. Someone can hear and see everything she's been doing.
Sent from my SGH-I777 using Tapatalk 2
Click to expand...
Click to collapse
I'm finding it highly unlikely that any of her friends would do something like that, not to mention that none of them have the technical know-how (yes, I know it's not hard, but none of her friends are even technologically adept to pull something like this off) to do it. If such malware has been installed on her phone, it most likely came bundled with some app she downloaded. She doesn't get all her app downloads from Google Play.
MotoMudder77 said:
Lmao. anti virus on android. you guys are funny!
U know its pointless right?
Click to expand...
Click to collapse
I like the way it looks on my status bar.
Sent from my Samsung Galaxy SII
CM9 Stable/Siyah 4.1
CNMOH said:
I'm finding it highly unlikely that any of her friends would do something like that, not to mention that none of them have the technical know-how (yes, I know it's not hard, but none of her friends are even technologically adept to pull something like this off) to do it. If such malware has been installed on her phone, it most likely came bundled with some app she downloaded. She doesn't get all her app downloads from Google Play.
Click to expand...
Click to collapse
There is no such thing as malware on android. everything you install tells you what it has access to.
The only thing like malware, would be an application that records stuff and sends it out, which would be listed when she installed the app, Tho im sure most rarely pay attention to that screen other than hitting install.
There are no viruses, no malware, or anything "hidden" that can attack stuff without your permission.
Wipe the phone. Dont install pirated apps or stupid pointless apps.
MotoMudder77 said:
There is no such thing as malware on android. everything you install tells you what it has access to.
The only thing like malware, would be an application that records stuff and sends it out, which would be listed when she installed the app, Tho im sure most rarely pay attention to that screen other than hitting install.
There are no viruses, no malware, or anything "hidden" that can attack stuff without your permission.
Wipe the phone. Dont install pirated apps or stupid pointless apps.
Click to expand...
Click to collapse
Malware can definitely affect android. Sure there are safeguards built in to reduce the chances of it happening, but they rely on the user to enforce them. I can almost guarantee that a majority of android users don't look at what permissions an app is asking for prior to installation. I know for a fact that out of the 5 android users in my house I am the only one that checks permissions before I install anything. In addition, even if one is checking the permissions, a malicious app can easily disguise itself as an everyday app that requires the permissions the Malware needs but would be overlooked because the host app has a valid reason for needing those permissions.
A dialer, email, sms, social networking app will all ask for access to your contacts. And it's necessary for that app to do its job. Well if that same app has unlimited access to your network then it can now take your contacts and upload them.
Now a virus is another thing all together. While it's possible on a rooted phone with rw permissions in the system directory, it's unlikely since most apps exist in a "sandbox" so to speak. It wouldn't be that difficult for a root explorer app to gain access to your /system directory and wreak havoc and then target your sdcard and wipe out your data. But not before uploading whatever it wants (a lot of explorers require network permissions for cloud service, etc). But then I guess that would be classified as malware and not a virus
And lets not leave out all the apps that use social networks to login..
But the last two Lines of your post say it all. Stay away from pirated apps and watch what 3rd party apps you're trusting these permissions with.

so tired of this! My j7 android 6 gets full device storage everyday for months

Hey, my device internal storage got like free 1-2gb space, sometimes it accidently (no special time) tells me that i got full storage and i can't even recieve any messege. free space is like 16kb. If i leave it like this it will be fixed alone after sometime like 10 minutes for example. I couldn't find any reason why is this happening. I attached my system info and screen shots for my most strange apps. i also uploaded this short video to youtube to show you guys the problem (ignore clean master in the video because i deleted it, when i got that app installed i think the problem happens more!)
https://youtu.be/gng5N4XV4E4
Please help i am so busy in collage's exams for months i don't have time to factory reset or to try new roms and if i don't find why this happens it will happen after i do factory reset.
Please help
You will find no help here with lucky patcher installed. This app is banned and any that, use it are tossed to the wolves so to speak.
What is most likely happening is the caches from other apps are eating up your space until they get cleared. With this low budget device I would keep apps and files to a bare minimum.
zelendel said:
You will find no help here with lucky patcher installed. This app is banned and any that, use it are tossed to the wolves so to speak.
What is most likely happening is the caches from other apps are eating up your space until they get cleared. With this low budget device I would keep apps and files to a bare minimum.
Click to expand...
Click to collapse
Thanks sir, i didn't know that xda bans lucky patcher i just deleted it now, i Don't use it anymore i used it long time ago for some games i tried then deleted (am in middle east and paypal is banned so i can't pay online so used it few times. got no other sollution)
is there any way to know which app is causing this? i don't think an app can creates +1gb cache in a minute except if it wants to do that (like a virus) so do you have any idea for me sir?
karedo said:
Thanks sir, i didn't know that xda bans lucky patcher i just deleted it now, i Don't use it anymore i used it long time ago for some games i tried then deleted (am in middle east and paypal is banned so i can't pay online so used it few times. got no other sollution)
is there any way to know which app is causing this? i don't think an app can creates +1gb cache in a minute except if it wants to do that (like a virus) so do you have any idea for me sir?
Click to expand...
Click to collapse
Any app that bypasses paying for an app is banned here. Developers don't take to thieves very well. Good. That app can give you all kinds of junk that messes up devices.
You could enable adb on the device and run a logcat. This will take some time to catch the issue.
Or you could do a factory reset and see if it still does it. This way you will know if it is a system app.
karedo said:
Hey, my device internal storage got like free 1-2gb space, sometimes it accidently (no special time) tells me that i got full storage and i can't even recieve any messege. free space is like 16kb. If i leave it like this it will be fixed alone after sometime like 10 minutes for example. I couldn't find any reason why is this happening. I attached my system info and screen shots for my most strange apps. i also uploaded this short video to youtube to show you guys the problem (ignore clean master in the video because i deleted it, when i got that app installed i think the problem happens more!)
https://youtu.be/gng5N4XV4E4
Please help i am so busy in collage's exams for months i don't have time to factory reset or to try new roms and if i don't find why this happens it will happen after i do factory reset.
Click to expand...
Click to collapse
My 2 cents here, if it helps.
1. Since you have root access, try and and use a good (system) app uninstaller and completely uninstall any apps you do not use. (my guess is you already did that?)
2. Reboot (must step after finishing uninstalling for better follow-up, clean-up process)
3. Try and use SD Maid. On first use, grant it superuser access, go to options and customize folders, give permissions to clean system folders and apps. You might be surprised to see as much as half a GB available for cleaning/ deletion. https://play.google.com/store/apps/details?id=eu.thedarken.sdm&hl=en
Let me know how it went, if you haven't already tried the posted suggestion.

Does anyone recognize this as spyware?

I have a good friend who believes her husband, they are separated and divorcing, has some kind of spyware on her phone. A lot of her claims as far as strange things happening with her phone, seem kind of impossible but her ex was involved in some high level activities in the Military. For one, she says she can factory reset her phone and all the strange things pop back on her phone. The first thing I looked at was what apps on her android were using the most data. I will include a picture of it but I personally have never seen anything like it. Many of the apps that are shown are "restricted".
Now, the app store for example. She claims she never installs new apps or really even looks around on the app store however the data use on it is insane. She also has NO work stuff on here and has no idea what osulogin is. Does anyone have a clue??
osu login is a preinstalled system app.
blackhawk said:
osu login is a preinstalled system app.
Click to expand...
Click to collapse
Thank you for letting me know that. Did you notice or see anything strange on there? Like why is the appstore data so high and all the app restricted? She said he ex was like scary good on cell phones.
sphereplay said:
Thank you for letting me know that. Did you notice or see anything strange on there? Like why is the appstore data so high and all the app restricted? She said he ex was like scary good on cell phones.
Click to expand...
Click to collapse
Have the phone reflashed to its original stock rom. Change Google account password.
Turn off wifi. Get off social media. Never leave anyone use your phone out of your sight... if at all.
I doubt the ex would risk his security clearance and job like this. The DOD has a vast array of spyware tools... I've seen some in use.
You upload and scan any app you want to with online Virustotal.
blackhawk said:
Have the phone reflashed to its original stock rom. Change Google account password.
Turn off wifi. Get off social media. Never leave anyone use your phone out of your sight... if at all.
I doubt the ex would risk his security clearance and job like this. The DOD has a vast array of spyware tools... I've seen some in use.
You upload and scan any app you want to with online Virustotal.
Click to expand...
Click to collapse
Gotcha. I will pass that on. Thank you very much again.

Categories

Resources