Android malware making news again - G Tablet General

http://www.digitaltrends.com/mobile/malware-infected-apps-threatening-android-devices/
I usually ignore this stuff except that it seems this particular bug comes down on apps from third party markets....not like it can actually send our stuff anywhere (no phone) but it might if you are tethered.

Related

Android Malware Now Capable of Recording Your Phone Calls !!!

A new find by the researchers at CA Security have unearthed a new kind of malware on andriod which can record infected devices conversations and uploads it to a remote server !
Andriodians beware
Source: http://community.ca.com/blogs/securityadvisor/archive/2011/08/01/a-trojan-spying-on-your-conversations.aspx
Another reason why it's important to check the permissions for an app before installing it. I'm bad about sometimes just hitting ok without looking but usually I'll go back and check afterwards just in case.
Check out Permissions Denied and Privacy Blocker in the market, they are both good apps that will prevent apps from getting permission to do stuff you don't want them to. Just be aware that the affected app may FC if it tries to do something and you have it blocked. I believe CM7 now is also able to block permissions on an app by app basis.
I usually have some sort of security installed on my phone. Regardless of checking apps before you install them, is this something I should continue to do? I flash new ROM's / ROM updates quite often, and I worry sometimes that it may be a good idea to make sure that Lookout, which is the anti-virus / anti-malware program that I use is installed before I do anything else.
I usually try to read the permissions, and some apps go out of their way to use permissions that are not necessary. I have been using Lookout Mobile Security, but I am not sure how well it works.
I think its time phone makers start inculcating permission management as in CM 7 in to there builds to help user's control these things. You could also use LBE Privacy guard, to control apps.
xHausx said:
Another reason why it's important to check the permissions for an app before installing it. I'm bad about sometimes just hitting ok without looking but usually I'll go back and check afterwards just in case.
Check out Permissions Denied and Privacy Blocker in the market, they are both good apps that will prevent apps from getting permission to do stuff you don't want them to. Just be aware that the affected app may FC if it tries to do something and you have it blocked. I believe CM7 now is also able to block permissions on an app by app basis.
Click to expand...
Click to collapse
Another nice app for this is called LBE Privacy Guard. I'm also a bit lax on checking before installing, but LBE will ask you in your notification window to confirm each perm. Allowing you to choose permit, ask each time it needs it, or deny access all together. I use it to deny access for network on games that don't need it to function and phone identification for almost all apps as most really don't need that info to work.
Which software to record calls?
Hi there,
as far as I know you cannot really record calls in Android becuase you can not intercept the phone directly. Therefore basically all phone recording software requires you to switch to speaker mode and records the call via the microphone (which may result in very bad audio quality, depending on your location).
Or is there now another (a better) way to record calls? Does an app exist, which records calls?
Kind regards,
∵ ToBe
ToBe_HH said:
as far as I know you cannot really record calls in Android becuase you can not intercept the phone directly. Therefore basically all phone recording software requires you to switch to speaker mode and records the call via the microphone (which may result in very bad audio quality, depending on your location).
Click to expand...
Click to collapse
That was my understanding of it as well.. heck for the Desire you need to be rooted, flash a specially-modified kernel, and have the correct radio ROM flashed.
ToBe_HH said:
Hi there,
as far as I know you cannot really record calls in Android becuase you can not intercept the phone directly. Therefore basically all phone recording software requires you to switch to speaker mode and records the call via the microphone (which may result in very bad audio quality, depending on your location).
Or is there now another (a better) way to record calls? Does an app exist, which records calls?
Kind regards,
∵ ToBe
Click to expand...
Click to collapse
there is one, works well with sony ericsson x10 mini pro, from android market
https://market.android.com/details?id=com.schass.recording.call&feature=search_result
I installed "LBE Security Service". (needs root) : works great
The author writes:
Protect your privacy by controlling the permission of each application to access your sensitive data.
- Block malicious operation from Mal-wares and Trojans.
- Block unwanted network traffic if you don’t have a unlimited data plan.
- Find out which application is trying to steal your privacy by checking the security log.
But apps like Angry Birds steal nearly everything from your (Position, Contacts ,SMS and so on) so i think there should be a general rule in the market which forbids things like Call recording(really man who needs this ^^) , and personal data stuff only the Position for apps who really needs this. And i mean nearly every free apps sells your data and this is not so cool i think you dont know nothing what happends to this data and I think there is alot to do on every mobile OS ( for every os is an angrybirds convert ^^), I knew at s60 (Symbian) there were a lot of antivirus kits to download(kaspersky, Bitdefender etc) maybe they will now see the market of android for antivirus softworks
dstyl said:
But apps like Angry Birds steal nearly everything from your (Position, Contacts ,SMS and so on) so i think there should be a general rule in the market which forbids things like Call recording(really man who needs this ^^) , and personal data stuff only the Position for apps who really needs this. And i mean nearly every free apps sells your data and this is not so cool i think you dont know nothing what happends to this data and I think there is alot to do on every mobile OS ( for every os is an angrybirds convert ^^), I knew at s60 (Symbian) there were a lot of antivirus kits to download(kaspersky, Bitdefender etc) maybe they will now see the market of android for antivirus softworks
Click to expand...
Click to collapse
just checked and angrybirds has no permission to access anything you mentioned, it only has full network access for ads (cm7 permission revoked) and read network state, thats all.
Droid Wall
I think just by using droidwall you can already squish a lot of malicious intentions an app has.
Its allows you to set a whitelist (or blacklist) of apps that you would allow to block packets from being sent.
What's great about it is:
1. it doesnt drain your battery, because it doesnt run as a service, but modifies your device's iptables
2. one of its features is logging your network activity so you could see which apps are actually sending or downloading data... this is helpful if you got a doctored copy of your favorite game or app. In case that app was modified to spy-on-you you can still block it
wow, then I think that I'll delete my entire mobile memory and apps and then start installing apps over again but I have to read the permissions very well this time.
Google should do something serious about that!
Thanks.
@FadeFX
Sry my fault Only the iOS version of angry birds steals psw ,contacts etc.
http://online.wsj.com/article/SB10001424052748704694004576020083703574602.html?mod=what_they_know
there are the most apps who are watching u so if you are unshure take a look
For Android and iOS users knows anybody sm about apps who steals your data on WP7 ?
______________________________
LG e900 MFG Unlocked Mango Beta 2 <------------ Nokia 6630
Pretty much all apps need some kind or the other kind of permission .. so the wise thing is to look up these permissions while installing app or use any one of the other apps to do that for you ..
Pretty much all apps need some kind or the other kind of permission .. so the wise thing is to look up these permissions while installing app or use any one of the other apps to do that for you ..
__________________
Phone: Htc Desire HD (ACE)
Rom: HONEY3D 1.1
Radio:12.48.60.23p_26.08.04.07_m3
Kernel :Kquicksall
Recovery: 4 EXT CWM 3.0.2.8
OC : No frills
Yes ,but if you use an iOS device there came no permission screen ,so you have to lock it up in the Appcontract what this app does in background , so it seems like the only way to get malware on an Android/WP7 seems to dont read the Permissions and only click ok ( imean if you install a FartMaschine or sth. and it needs your Position data to work there must be something bad in the background
I mean for kids who uses there phone or ipod or whatever this is a really big responsibilty and u cant except from an 10 or 14 year old kid to take care about that i think these data stealing apps should be forbidden ,if you read the article you see that from 101 tested apps 56 send user data to different networks. Both the Android and iPhone versions of Pandora, a popular music app, sent age, gender, location and phone identifiers to various ad networks so i think there have to be a cut by the law. For me it was a new world to because i had an s60v2 device from 2004 till the last month so i had to learn to take care what my phone knews about me.
_____________________________________________
LG e900 MFG Unlocked Mango Beta 2<----------Nokia 6630
I never look at the application permissions, but this made me rethink after installing some applications...

Perpetually Active Software - WeChat

WeChat is a fun and useful program that everyone I know uses... and I guess nobody cares about this issue but me, but its a serious issue
Wechat can never be prevented from launching on start up, even from Super User... no matter what, it just pops right back onto the list of start up applications immediately after its disabled
you can end the running process, end the cached process, use several task managers to prevent it from running or starting at boot.. but nothing ever works
and as soon as you get a message from someone, your phone message light starts blinking and a wechat icon appears in the taskbar.. even when there was no sign of the program even active at all
and i've found even worse violations from other chinese programs like tudou, youku, sohu, etc.. their programs will actually not start at boot, but suddenly appear with messages and news feeds in your information bar, and will even start downlaoding media to your phone without your permission
any idea how I can sever wechats malicious control & permissions violations and stop it from booting, and also prevent messages when the app hasnt been launched?
i've literally tried everything
thanks
-
chinarabbit said:
WeChat is a fun and useful program that everyone I know uses... and I guess nobody cares about this issue but me, but its a serious issue
Wechat can never be prevented from launching on start up, even from Super User... no matter what, it just pops right back onto the list of start up applications immediately after its disabled
you can end the running process, end the cached process, use several task managers to prevent it from running or starting at boot.. but nothing ever works
and as soon as you get a message from someone, your phone message light starts blinking and a wechat icon appears in the taskbar.. even when there was no sign of the program even active at all
and i've found even worse violations from other chinese programs like tudou, youku, sohu, etc.. their programs will actually not start at boot, but suddenly appear with messages and news feeds in your information bar, and will even start downlaoding media to your phone without your permission
any idea how I can sever wechats malicious control & permissions violations and stop it from booting, and also prevent messages when the app hasnt been launched?
i've literally tried everything
thanks
-
Click to expand...
Click to collapse
Don't use whatever "wechat" is?
diestarbucks said:
Don't use whatever "wechat" is?
Click to expand...
Click to collapse
if only...
everything is blocked in China, no facebook, no twits, no anything
wechat is the one tool i can connect with all the people I know.. and literally every single person in China uses it..
a lot of my overseas friends in Europe, Australia, New Zealand, and North America also use it too, because they know or have known people in China
so.. I'll keep using it anyway, since its the main use for my phone anyway.. but I'd like to break free from its grasp a bit
I feel its a Government spy program, but private manufacturers in China are equally as deliberately intrusive & invasive programmers, so who knows
its from Tencent, the company which gained infamy for its unremovable Tencent QQ toolbar virus for windows
i hate the company, but need the program, unfortunately

My first app...

It's called HereIam, it's the one with a globe and a big arrow pointing at it. Not allowed links yet...
It automatically sends a message if you are at a prefefined location. (handy if you're a cyclist), and a few other location type things.
I made it as a way of learning how to make apps.
Extra things I didnt expect to learn...
I'm rubbish at making pretty screens.
How different your app looks/behaves on different phones in real life. (I found that I had to buy a crappy phone just to test on)
Some things are a lot easier than you'd expect. (eg Mapping).
Some things are a lot harder than you'd expect. (eg sending an email from your app).
https://play.google.com/store/apps/details?id=co.uk.happyapper.HereIamFree
Tried it, it's amazing, having few force close issues at times though, but that's probably an user error. Good effort. Posted the link for you

Wifi Direct sharing from google

Most phones today have wifi direct. However, very few of these can actually use it to share files the way samsungs can. Of course, there are many 3rd party apps that can do it, and some quite well, but the thing they all have in common is that the app must be installed on both devices. (Unless using a web address on a browser on the receiving device, which is not so user friendly as apps like superbeam, or the samsung wifi direct share.)
Wouldn't it be great if all android devices came with a preinstalled app to do send large files back and forth, eith share options in all apps, like bluetooth share, only for wifi direct? Because lets face it, while blutooth is certainly useful, it's just too slow for anything more than a few picture or a short video.
So why not make a feature request in code.google.com, asking for a wifi direct share app to to be preinstalled in all devices, (in new android versions, that is, just to add another app to the gapps we already have,) or even just to be able to install from play store, just like google camera, the only difference being that all devices will be able to receive the file the way all phones can receive an incoming bluetooth file..
If this isea interests you, Post here, and if I see that thete is enough interest to actually make this worthwhile, I will post a new topic there and we can try getting as many people as possible to vote for it there, and maybe we might get our wish and the next version of android will include this! I can't believe it would be very difficult for google to implement.
So, does anyone else think this is a good idea? If you do then tell me and lets see if we can actually get built in wifi direct sharing on android!

Times up! Filling BBB report

Long story short -
I own the SM-G925P and I'm very displeased with it after receiving yet another update today that included more bloat ware to the device. I was upset with the last major update as well because it included applications like 'App Spotlight'
App Spotlight allows Sprint to collect money and to push notifications to your device to highlight recommended applications. I don't agree with this practice at all. I found it very annoying back in the Android 2.0 days and was happy when Android effectively killed that in Android 4. I myself as others didn't pay a high premium for a device to be and ad space for Sprint.
The device has native voice mail notification turn off (WMI Support) which forces you to have to use their voice mail application on the device that looks like a 10 year designed it, let alone again, there is premium features and ad space in the application. These are set to on by default and you can turn this off by visiting the application and turning off the Premium feature or by paying something like $2 a month. If you disable the application you lose voice mail notifications all together.
Yes i'm very aware that you can disable some of the applications, I'm also very aware of using Knox IT policy to disable any application I want with out root, but it comes down to I shouldn't have to do this for a device you pay top dollar for.
Right now I'm using Package Disable Pro, I have 202 Packages disabled on my device currently. Not all of it is Sprint no alot of it is Samsung truthfully. Tonight after the update I still have 202 packages disabled and now I have to add an additional 10 or so, or see if they can be uninstalled or deleted from the application manager first.
Do i have a few issues with the device with 202 applications disabled eh yes really only two issues that concern me. One my dialer codes don't work. To lazy to locate the package that has them working, two my google wallet if I use NFC closes. Other than that no I don't and my phone is running better then ever with 0 to very little lag something that Samsung promised and advertised with these devices., but not to our surprise failed to deliverer the first set of issue was the major memory leak form lollipop, honestly this phone sucked the first time out of the box after the first day of use.
Any way long story short I filed a BBB report against them, they are not accredited so I doubt they will care, but I'm looking to have my plans canceled return the devices for a refund reminding on them.
Hows every one else's day going haha?
If you didn't want all that bloatware on your device (which has been the case since...like forever with Touchwiz), why didn't you just get a Nexus?
I doubt anything will happen with the BBB because there really is no false advertising or any misleading issues with your purchase. Now if you had gotten a few lemons and kept getting them replaced to fix an issue...maybe there would be something.
I'm not specifically talking about touchwiz bloat ware. I accepted the fact that touch wiz has its own and Samsung includes its own app store's etc.
What I'm talking about is Sprint's bloat ware, how the device brands it self after activation based on (Virgin mobile/Sprint/Boost etc) when you first power on the device you don't have a ton of applications pre-installed. After activation the device brands it self to either of these carriers based on who you activated it with. Like two voice mail icons / apps (com.sprint.voicemail: yellow icon takes you to voice mail, com.coremobility.app.vnotes: blue icon used for actual notifications and visual voice mail filled with ads unlike other carriers)
Spotlight - again used to push highlighted apps to my device; added during an update was not originally on the device when purchased.
I should have made notes of each additional bloat that was added to the device with each upgrade but I failed to do that, but noted the most annoying one sense I randomly was getting notifications in my notification center. (Mind you I don't have any third party applications installed on my device it is 100% out of box with what ever applications disabled or can be uninstalled).
The point of what I was making on this, is you spend 5-700$ dollars on a device for them to make it an ad supported. I would have been more understanding of ads or pushing bloat to the device with each upgrade if the device was free. They are getting paid to push notifications to your device for featured games/applications etc. I do not agree with this business tactic at all and no where does it state they may do this.
The device was advertised and pushed by sales teams as the fastest device on the market at the time with a lag free experience. I specifically remember the commercial about this. The problem with that is you released a device with a bugged OS knowingly from the beginning ( Android 5.0 memory leak ) many devices that received 5.0 had major issues and lots of people were wanting to downgrade back to 4.X because of it. It wasn't until the 3rd update that it was improved but not resolved. I don't know its current status as I stopped following the issues. The device is no where as fast / lag free as they claim if anything I have had more lag issues with this device then a device on kitkat.
Now what you don't know is that I work with cell phones on a day to day basis, I have my hands on many different devices at a time. Comparing this device to many other devices against other carriers and Sprints specifically is one of the worst between its stupid IOTA services and other things. Comparing this device to the Verizon edge with older software and the Verizon firmware feels more improved then Sprints.
I will have to write more latter, if you were local to me it would be easier for me to point out the issues in person, and if you have similar OCD like mine it will eat at you like it has me.
File a complaint to the BBB and that will get you nothing and nowhere. You can actually disable most of the apps, google play news/games/books/ect.
You put your finger on and app, hold your finger on it and drag it up to the disable option or uninstall on apps you don't want.
amoamare said:
I'm not specifically talking about touchwiz bloat ware. I accepted the fact that touch wiz has its own and Samsung includes its own app store's etc.
What I'm talking about is Sprint's bloat ware, how the device brands it self after activation based on (Virgin mobile/Sprint/Boost etc) when you first power on the device you don't have a ton of applications pre-installed. After activation the device brands it self to either of these carriers based on who you activated it with. Like two voice mail icons / apps (com.sprint.voicemail: yellow icon takes you to voice mail, com.coremobility.app.vnotes: blue icon used for actual notifications and visual voice mail filled with ads unlike other carriers)
Spotlight - again used to push highlighted apps to my device; added during an update was not originally on the device when purchased.
I should have made notes of each additional bloat that was added to the device with each upgrade but I failed to do that, but noted the most annoying one sense I randomly was getting notifications in my notification center. (Mind you I don't have any third party applications installed on my device it is 100% out of box with what ever applications disabled or can be uninstalled).
The point of what I was making on this, is you spend 5-700$ dollars on a device for them to make it an ad supported. I would have been more understanding of ads or pushing bloat to the device with each upgrade if the device was free. They are getting paid to push notifications to your device for featured games/applications etc. I do not agree with this business tactic at all and no where does it state they may do this.
The device was advertised and pushed by sales teams as the fastest device on the market at the time with a lag free experience. I specifically remember the commercial about this. The problem with that is you released a device with a bugged OS knowingly from the beginning ( Android 5.0 memory leak ) many devices that received 5.0 had major issues and lots of people were wanting to downgrade back to 4.X because of it. It wasn't until the 3rd update that it was improved but not resolved. I don't know its current status as I stopped following the issues. The device is no where as fast / lag free as they claim if anything I have had more lag issues with this device then a device on kitkat.
Now what you don't know is that I work with cell phones on a day to day basis, I have my hands on many different devices at a time. Comparing this device to many other devices against other carriers and Sprints specifically is one of the worst between its stupid IOTA services and other things. Comparing this device to the Verizon edge with older software and the Verizon firmware feels more improved then Sprints.
I will have to write more latter, if you were local to me it would be easier for me to point out the issues in person, and if you have similar OCD like mine it will eat at you like it has me.
Click to expand...
Click to collapse
This is nothing new for Sprint either...nor Verizon for that matter. When you activate either of those (and my guess is the other 2 major carriers as well) it connects to the network, downloads necessary as well as licensed apps and drivers. There are a lot more Sprint specific apps that they don't install. Go to Apps and Sprint in Play and see what they could have put on. As mentioned, most of the apps are able to be disabled. With root they can be removed. This has been the case for several iterations of Samsung US phones. My GF's Note 4 did this, I think the S5 and Note 3 did as well. I fail to see how Sprint putting extra programs on your phone is a case for the BBB. But good luck with your case. Again sounds like you should stick to Nexus devices going forward.
This same phone is used on the CDMA network in India so it is more convenient to install carrier specific files upon activation.
I could care less about what comes on a phone being that it's 100% customizable. Hell, be happy it's not as much of a headache as iPhone. If it's not for you then don't buy it. That's what the demos are for in the store. I usually buy a phone, play around with the stock for a few hours, root and customize to my standard. After these last 2 updates, I'm very pleased with the phone
Try this
We all dislike some bloatware, but all carriers include it.
A better option that people can follow along with, is change.org where anyone can start actual community petitions against companies.
I would sign your petition. I'm sure many people will.
BBB is simply not the place for this type of opinion, as Sprint would probably call it just that.
If you disabled over 200 apps, i can bet a large amount of those are system apps that are needed by one thing or another. If you're going to disable things that you aren't sure of, dont complain about nfc not working. The system comes with about 290 total apps, and over 150 of those are required for everything on the device to function properly. And sprint isn't making much money off you paying for the phone. They have to buy them from Samsung, for more than what you even lease the phone for. But its the only way they can cover their asses money wise if they aren't locking people into contracts and giving away a 600 dollar phone for 200 bucks. Do your research before you start ranting and complaining to BBB that literally got off the phone with you and tossed out your complaint

Categories

Resources