Interesting Article on New Malware Threat. - AT&T, Rogers HTC One X, Telstra One XL

Pretty interesting article I came across here. It did not specify which app so that did not help much. But good to be on the lookout for some of these malware techniques now, and the embedded files.
http://thenextweb.com/insider/2013/02/03/android-malware-emerges-on-google-play-which-installs-a-trojan-on-your-pc-uses-your-microphone-to-record-you/
On that note does anyone have experience if any of the anti-malware apps in the Playstore work well - besides the app showing it is "working" by a quick scan.

chriscerv90 said:
Pretty interesting article I came across here. It did not specify which app so that did not help much. But good to be on the lookout for some of these malware techniques now, and the embedded files.
http://thenextweb.com/insider/2013/02/03/android-malware-emerges-on-google-play-which-installs-a-trojan-on-your-pc-uses-your-microphone-to-record-you/
On that note does anyone have experience if any of the anti-malware apps in the Playstore work well - besides the app showing it is "working" by a quick scan.
Click to expand...
Click to collapse
I saw another article on that threat, it was disguising itself as a system cleaner, I can't remember the exact name though.

timmaaa said:
I saw another article on that threat, it was disguising itself as a system cleaner, I can't remember the exact name though.
Click to expand...
Click to collapse
Interesting. The app would need Root Permissions to embed those files. So is malware only an issue with "root required" apps, or only in this specific technique of malware?

It kinda takes an idiot to install that app if you read the permissions it asked for it was ridiculous and any person with half a brain would be skeptical

a box of kittens said:
It kinda takes an idiot to install that app if you read the permissions it asked for it was ridiculous and any person with half a brain would be skeptical
Click to expand...
Click to collapse
What was the name of the app? Was it Droid Dream?
Sent from my HTC One X using xda app-developers app

Related

it appears there is no privacy

I hope I'm not reposting, but it felt so important to share this
http://www.zdnet.com/blog/apple/htc-rootkit-discovered-phoning-home-with-user-data/11792
T-mobile has confirmed that this software ships with the 4G slide:
http://support.t-mobile.com/thread/12505?tstart=0&noredirect=true
Please go complain about this on that thread or directly to t-mobile, even if you're rooted and running a custom ROM. It's something that shouldn't be foisted on the 99% of normobs out there, and if people speak out about this it can only increase the chances of t-mobile doing something about it.
Removed all that crap already. This has been going on for awhile.. power to the user
sent from my RuBiX infused MT4G Slide using xda premium
Undead posted a patch, and supossedly the App that started all of it is Zipline...Doubleshot. Something within those lines.
DoubleshotNomy :3 [CM7.1] [2.3.7]
Litesorrows said:
Undead posted a patch, and supossedly the App that started all of it is Zipline...Doubleshot. Something within those lines.
DoubleshotNomy :3 [CM7.1] [2.3.7]
Click to expand...
Click to collapse
Can you post a link to the patch?
I don't know about a patch, but i found this utility that checks if you have ciq
http://forum.xda-developers.com/showpost.php?p=17612559
I checked my phone with the detection tool and it's not on there. Anyone found it?
Don't worry. T-Mobile did not put cip our phone... Only SWM-C lol
Sent from my DoubleShot Lite
http://forum.xda-developers.com/showthread.php?t=1286840
That's the link to the security patch put together by Undeadk9. It's over in Dev.
When these issues were first released, we all handled it immediately and he made a patch to make it easier to do it.
If you haven't flashed it or are on a ROM that hasn't dealt with these issues, look into it.
The link to the androidpolice article is in Undeadk9's thread.
(yes, things like this are why the app Pulse is one of my top 'need to have' apps. Breaking news - my way, about what's important to me.)
Blue6IX said:
http://forum.xda-developers.com/showthread.php?t=1286840
That's the link to the security patch put together by Undeadk9. It's over in Dev.
When these issues were first released, we all handled it immediately and he made a patch to make it easier to do it.
If you haven't flashed it or are on a ROM that hasn't dealt with these issues, look into it.
The link to the androidpolice article is in Undeadk9's thread.
(yes, things like this are why the app Pulse is one of my top 'need to have' apps. Breaking news - my way, about what's important to me.)
Click to expand...
Click to collapse
Oh.
That patch doesn't address this issue, that was another security hole.
Doing everything to address this... Another question by my father.... How does this impact exchange email, regardless of device, platform, or carrier? Does anyone know?
kronickhigh said:
Doing everything to address this... Another question by my father.... How does this impact exchange email, regardless of device, platform, or carrier? Does anyone know?
Click to expand...
Click to collapse
The answer, unfortunately, is "that depends".
Keystrokes *are* being caught and logged, that's clear. It doesn't appear that they're being permanently stored or transmitted, but that doesn't matter. Malicious software could potentially read those keystrokes and do whatever with them.
All of the RubiX_CubeD roms will be patched up and rid of any of this doggy doo doo by this Sunday.
RubiX_CubeD NoSense v3.0 INCLUDES fix to remove all tracking garbage everyone's been hearing about.
I assume cm7 would be safe since it's built from scratch.
Sent from my Sensation using xda premium
jsyi84 said:
All of the RubiX_CubeD roms will be patched up and rid of any of this doggy doo doo by this Sunday.
RubiX_CubeD NoSense v3.0 INCLUDES fix to remove all tracking garbage everyone's been hearing about.
Click to expand...
Click to collapse
You'll need to remove the SWM-C stuff.
That's the redbend sofware managemet client, which T-Mobile includes. That software gives T-Mobile the ability to install, remove, or modify any software installed on your phone without your knowledge or permission.
EDIT: Actually, it'd be great if ROMs could be titled with [NOSWM], so we'd know. Just a thought.
The Rubix Cubed ROMs have all been "fixed" now to prevent this invasion of privacy. Since we aren't allowed to post about other forums on here all I can say is to Google RubiX CubeD ROM and you'll see your 3 options.
**mods i.e. arrrghhh**
As you can see I haven't posted any direct links or referenced any other particular forums to acquire these said roms so I am not violating what you referred to as "uncredited" work and a "d!ck" move as quoted from your PM to me this morning below .....Google is everyone's friend and it's pretty common knowledge anything can be found on there!
arrrghhh said:
Especially with a link to xxxxxx, basically telling XDA users to not visit XDA. That was a real **** move - I do not want to see you doing this again.
Click to expand...
Click to collapse
So, I'm guessing if we freeze the SWM-C stuff, we should be safe? Is there anything else that's questionable and should be frozen?
I'm no expert. I have a rooted but stock MT4GS. I downloaded an app from the marketplace that is supposed to find if you have the software on your phone.
According to the software, I don't have the "infection".
I searched the marketplace for "carrier iq" and found a few detectors. I used one from Lookout, the people that make remote lock and wipe software. I also downloaded one from Bitdefender and got the same negative answer.
TMO News had a post with a list of offending phones and ours was not on there.
My guess is that it is not on our phones.
Our phone doesn't come with carrier iq thankfully. TrevE has an app that checks and removes it.
We do however have swm-c and htc loggers. Both can be removed. I know undeads roms have both removed.
I checked for both already.
sent from my RuBiX infused MT4G Slide using xda premium

AdAway, AdFree, AdBlock Plus or what???

I don't know what to use. I've used AdFree before but replaced it with AdAway. Recently I switched from a CDMA carrier to a GSM carrier. And AdAway is telling me to alter my APN proxy. I already had to alter my APN proxy to get Data to work in the 1st place. So this is something I won't do. AdBlock Plus doesn't block ads in apps so it's not enough for me. Last time I used AdFree it was having problems. Is AdFree sorted or is there another app I haven't heard of?
zapjb said:
I don't know what to use. I've used AdFree before but replaced it with AdAway. Recently I switched from a CDMA carrier to a GSM carrier. And AdAway is telling me to alter my APN proxy. I already had to alter my APN proxy to get Data to work in the 1st place. So this is something I won't do. AdBlock Plus doesn't block ads in apps so it's not enough for me. Last time I used AdFree it was having problems. Is AdFree sorted or is there another app I haven't heard of?
Click to expand...
Click to collapse
I use this:
http://forum.xda-developers.com/showthread.php?t=1916098
It's not an app, it's a flashable zip, but it works better than any ad blocking app I've ever used and gets updated pretty regularly.
If I had a dollar for every time I said that, I'd be making money in a very weird way.
1BadWolf said:
I use this:
http://forum.xda-developers.com/showthread.php?t=1916098
It's not an app, it's a flashable zip, but it works better than any ad blocking app I've ever used and gets updated pretty regularly.
If I had a dollar for every time I said that, I'd be making money in a very weird way.
Click to expand...
Click to collapse
will it mess with adfly and others ads linking page? coz sme download linked to that stupid page..
One issue I have had with adblock is that I cannot open any links from my Gmail.. It considers aweber websites as ads..
Sent from my MB865 using Tapatalk 2
hafizkris90 said:
will it mess with adfly and others ads linking page? coz sme download linked to that stupid page..
Click to expand...
Click to collapse
I always have that installed on my phone and I never see any of that stuff so I guess it does. The only ads that I see with this installed is the ones highlighted in yellow in the Google search results, but I guess they refer to those as "Sponsored Links" instead of calling them what they are.lol
If I had a dollar for every time I said that, I'd be making money in a very weird way.
hafizkris90 said:
will it mess with adfly and others ads linking page? coz sme download linked to that stupid page..
Click to expand...
Click to collapse
Yes, looking at its hosts file, that's what this thing consists of, it is blocking adfly as well.
1BadWolf said:
I always have that installed on my phone and I never see any of that stuff so I guess it does.
Click to expand...
Click to collapse
You really should only respond when you are certain that your information is correct, not when you are *thinking* that it *might* be correct.
---
PS: I don't care about "don't bump up old threads, I'm crying like a baby girl now"-losers.
I am looking for the best available solution (currently using adaway)
I recently started using Go SMS Pro, but adaway can't block either the in-app ads nor the pop-up ads that come up after closing GO SMS
Any ideas?
anyone using one of the three aps and successfully blocked ads by GO SMS?
pathologo said:
You really should only respond when you are certain that your information is correct, not when you are *thinking* that it *might* be correct.
---
PS: I don't care about "don't bump up old threads, I'm crying like a baby girl now"-losers.
Click to expand...
Click to collapse
My response was adequate and was within the boundaries of the forum rules, unlike your post. To quote something you posted elsewhere:
2.3 Flaming / Lack of respect: XDA is about sharing and this does not involve virtual yelling (flaming) or rudeness. Flaming or posting with a lack of respect is unacceptable. Treat new members in the manner in which you would like to have been treated when you were a new member. When dealing with any member, provide them with guidance, advice and instructions when you can, showing them respect and courtesy. Never post in a demanding, argumentative, disrespectful or self-righteous manner.
Click to expand...
Click to collapse
Just like you said when quoting the rules at others, "NEVER post in a DEMANDING, ARGUMENTATIVE, DISRESPECTFUL or SELF-RIGHTEOUS manner." Good day, Sir.

Q: Does anybody know what this app is or does? (Screenshot included)

http://imgur.com/gallery/0NFAS
Thank you in advance!
-R
It looks like it might be this App Ops
Or something very similar.
LunaEros said:
It looks like it might be this App Ops
Or something very similar.
Click to expand...
Click to collapse
First off: Thanks for your reply!
Though I think you might been misled: Yes, this is App Ops, but I meant the program at the top of the list WITHIN App Ops (the one with the android-bot-icon)
Thank you anyways though!
The screenshot at the top? Where all those "Allowed" settings are?
My first thought when I saw that was that it looked like a Superuser settings menu.
Couldn't tell you which one if it is though.
No problem on trying to help.
I know from experience it's damn near impossible to get help on this board sometimes.
In one of my other posts on why that is someone replied with the implication that most of really knowledgeable people here
are apparently prejudiced against new users to Android.
I guess people like me (Windows users for 20+ yrs) are invading their clubhouse and they don't like it.
LunaEros said:
The screenshot at the top? Where all those "Allowed" settings are?
My first thought when I saw that was that it looked like a Superuser settings menu.
Couldn't tell you which one if it is though.
No problem on trying to help.
I know from experience it's damn near impossible to get help on this board sometimes.
In one of my other posts on why that is someone replied with the implication that most of really knowledgeable people here
are apparently prejudiced against new users to Android.
I guess people like me (Windows users for 20+ yrs) are invading their clubhouse and they don't like it.
Click to expand...
Click to collapse
Yeah, really seems that way, really hard to a response here... anyway, that app seemingly doesn't even have name (compare facebook messenger and the one above it) and thanks for your reply - have a great day
Ok. I think I know what you're talking about now.
You mean the app with the Android robot with the white box on him.
It looks like some sort or task starter like tasker.
I found this.
Try that for a starting point for finding out what it is. The robot is identical except for the X over it.
LunaEros said:
Ok. I think I know what you're talking about now.
You mean the app with the Android robot with the white box on him.
It looks like some sort or task starter like tasker.
I found this.
Try that for a starting point for finding out what it is. The robot is identical except for the X over it.
Click to expand...
Click to collapse
Oh cool, will try that, thanks! Have a nice day!
No problem.

Question about spam

Since two days ago i'm getting spam only from this site. When i surf xda chrome takes me to the following link www.itt-edu.us popping up a message that says my phone has been infected by a virus and if i select the pop up it takes me to the play store. Can someone confirm i am not the only one? It is really annoying! Please can anyone help me?
How about factory reset ? Do factory reset before your information and data go to some one..!
hugoglezp said:
Since two days ago i'm getting spam only from this site. When i surf xda chrome takes me to the following link www.itt-edu.us popping up a message that says my phone has been infected by a virus and if i select the pop up it takes me to the play store. Can someone confirm i am not the only one? It is really annoying! Please can anyone help me?
Click to expand...
Click to collapse
im pretty sure there is a thread where you can report intrusive ads. i saw someone else post this same thing a day or 2 ago.
tazaga said:
How about factory reset ? Do factory reset before your information and data go to some one..!
Click to expand...
Click to collapse
I've already done factory reset several times and the problem still persists. Thank you anyway
tazaga said:
How about factory reset ? Do factory reset before your information and data go to some one..!
Click to expand...
Click to collapse
bweN diorD said:
im pretty sure there is a thread where you can report intrusive ads. i saw someone else post this same thing a day or 2 ago.
Click to expand...
Click to collapse
Sorry but i've made a research before posting and i cant find something similar not only on xda but on the whole web.
hugoglezp said:
Sorry but i've made a research before posting and i cant find something similar not only on xda but on the whole web.
Click to expand...
Click to collapse
i typed "report intrusive ads on xda" into google, and bam, first result.
http://forum.xda-developers.com/showthread.php?t=1696660
bweN diorD said:
i typed "report intrusive ads on xda" into google, and bam, first result.
http://forum.xda-developers.com/showthread.php?t=1696660
Click to expand...
Click to collapse
I had already found it myself but I refer i cant find the same as my problem specifically in concrete www.itt-edu.us
I also started getting this yesterday. I can't offer any solution (scan with avast app doesn't find anything), but at least you know you're not the only one.
For the moment i solved it by installing app webguard from the playstore. But anyways i would like to know the reason why it happens.
Hey I have the exact same problem, where are you from? This might be a local thing affecting user from certain regions.
LazyLucretia said:
Hey I have the exact same problem, where are you from? This might be a local thing affecting user from certain regions.
Click to expand...
Click to collapse
From Spain.
hugoglezp said:
From Spain.
Click to expand...
Click to collapse
This is strange, I'm from Turkey and when I searched for "itt-edu.us" on google, I couldn't find anything but this post and another post from a Turkish site. They also claimed that problem only existed in XDA.
LazyLucretia said:
Hey I have the exact same problem, where are you from? This might be a local thing affecting user from certain regions.
Click to expand...
Click to collapse
LazyLucretia said:
This is strange, I'm from Turkey and when I searched for "itt-edu.us" on google, I couldn't find anything but this post and another post from a Turkish site. They also claimed that problem only existed in XDA.
Click to expand...
Click to collapse
I know is very strange i have made factory reset and clean chrome from the phone and pc and the problem still persists. I have also reported becouse if i press the link it takes me to an app called 360 light from google play.
hugoglezp said:
I know is very strange i have made factory reset and clean chrome from the phone and pc and the problem still persists. I have also reported becouse if i press the link it takes me to an app called 360 light from google play.
Click to expand...
Click to collapse
Yeah it also redirects me to the same app from Play Store. Is there any way to report this issue to XDA?
LazyLucretia said:
Yeah it also redirects me to the same app from Play Store. Is there any way to report this issue to XDA?
Click to expand...
Click to collapse
I have reported it in this topic http://forum.xda-developers.com/general/xda-assist/intrusive-add-spam-xda-t3280784
I don't know what else we can do. Also i have reported too to google play
I love this site, and want to support them. However, all the huge ads, and popup ads make it impossible to make it a pleasurable browse. Nevermind the amount of mobile data it consumes. As much as I hate doing this, I'll be using an adblocker now.
Rakcoon said:
I love this site, and want to support them. However, all the huge ads, and popup ads make it impossible to make it a pleasurable browse. Nevermind the amount of mobile data it consumes. As much as I hate doing this, I'll be using an adblocker now.
Click to expand...
Click to collapse
In my case, using an adblocker has no effect on itt-edu.us ads.

Can you filter out GMS based Apps from PetalSearch results?

Hey guys!
Got my hands on the P40 Pro last Tuesday - the hardware is undoubtedly gorgeous and I've managed to get 99% of my Apps working...
I read you can use PetalSearch from the AppGallery to source Apps from multiple different sources. However, there's been a few times when I've been overjoyed to find an APK, but left dissapointed once downloaded, as they've been GMS based. Insight Timer is one example...
Anyway to filter these out to make finding my top App APKs easier? (HMS)
TechPeck said:
Hey guys!
Got my hands on the P40 Pro last Tuesday - the hardware is undoubtedly gorgeous and I've managed to get 99% of my Apps working...
I read you can use PetalSearch from the AppGallery to source Apps from multiple different sources. However, there's been a few times when I've been overjoyed to find an APK, but left dissapointed once downloaded, as they've been GMS based. Insight Timer is one example...
Anyway to filter these out to make finding my top App APKs easier? (HMS)
Click to expand...
Click to collapse
Well Huawei have a 4 layer security so when you install from Petal search it does scan and check that the app is secure, How are you getting on with the phone?
EatSleepTechRepeat said:
Well Huawei have a 4 layer security so when you install from Petal search it does scan and check that the app is secure, How are you getting on with the phone?
Click to expand...
Click to collapse
It's not so much the security, I'll find an APK via PetalSearch, download it, and it's a GMS based App so still doesn't work... There's gotta be a way to filter out what will and wont work, right?
TechPeck said:
Hey guys!
Got my hands on the P40 Pro last Tuesday - the hardware is undoubtedly gorgeous and I've managed to get 99% of my Apps working...
I read you can use PetalSearch from the AppGallery to source Apps from multiple different sources. However, there's been a few times when I've been overjoyed to find an APK, but left dissapointed once downloaded, as they've been GMS based. Insight Timer is one example...
Anyway to filter these out to make finding my top App APKs easier? (HMS)
Click to expand...
Click to collapse
App gallery has meditation apps in it or petal search will no doubt have many others to pick from that are not GMS. For me it's all about understanding that HMS has alternatives to GMS based applications. I haven't really found anything I can do on the phone. Is there anything else you've had difficulty with?
ChrisHtube said:
App gallery has meditation apps in it or petal search will no doubt have many others to pick from that are not GMS. For me it's all about understanding that HMS has alternatives to GMS based applications. I haven't really found anything I can do on the phone. Is there anything else you've had difficulty with?
Click to expand...
Click to collapse
To be fair, I was pretty impressed with what went across via PhoneClone the first time! The meditation apps available from AppGallery are pretty naff at the moment, HOWEVER I've just used PhoneClone for a second time to bring Calm across... Can confirm it DOES work - It's more popular than Insight Timer, so maybe I'll stop being a little app hipster and get with the times
TechPeck said:
To be fair, I was pretty impressed with what went across via PhoneClone the first time! The meditation apps available from AppGallery are pretty naff at the moment, HOWEVER I've just used PhoneClone for a second time to bring Calm across... Can confirm it DOES work - It's more popular than Insight Timer, so maybe I'll stop being a little app hipster and get with the times
Click to expand...
Click to collapse
I think phone clone is the saving grace for Huawei, it does near enough all the leg work!
I am trying to get used to petal search now. I've found it really good so far. I haven't had any experience of apps not working via it yet?
TechPeck said:
To be fair, I was pretty impressed with what went across via PhoneClone the first time! The meditation apps available from AppGallery are pretty naff at the moment, HOWEVER I've just used PhoneClone for a second time to bring Calm across... Can confirm it DOES work - It's more popular than Insight Timer, so maybe I'll stop being a little app hipster and get with the times
Click to expand...
Click to collapse
haha, i have heard of Calm before, apparently its good if your in to that sort of thing. Im glad you've found a work around for this app. How are you finding the phone?
petal search is probably the best thing to use for all apps, everything you need should be on there with no issues.
dw9075n said:
I am trying to get used to petal search now. I've found it really good so far. I haven't had any experience of apps not working via it yet?
Click to expand...
Click to collapse
not quite sure what you are asking but if its whether its realisable, its been spot on for me :good:
From my use you cant filter them out however it does say before clicking an app that it may not work which suggests it may be GMS based.
I've been using it for a few days now and i feel that it is pretty good. Most things i have not have any issues with, You might get a message saying that you cannot use it without google services. Then it still works any way.
---------- Post added at 08:10 AM ---------- Previous post was at 08:09 AM ----------
EatSleepTechRepeat said:
not quite sure what you are asking but if its whether its realisable, its been spot on for me :good:
Click to expand...
Click to collapse
Now having used it for a few days, I really like it and it is working well.
TechPeck said:
It's not so much the security, I'll find an APK via PetalSearch, download it, and it's a GMS based App so still doesn't work... There's gotta be a way to filter out what will and wont work, right?
Click to expand...
Click to collapse
I agree this is my concern shall we say I use Power Director App for work quite a lot and got excited to say the least when I saw it was available on Petal Search but once downloaded the app itself does not load and reboots to the home screen, no bigger for now as I am WFH but will eventually need.
dw9075n said:
I am trying to get used to petal search now. I've found it really good so far. I haven't had any experience of apps not working via it yet?
Click to expand...
Click to collapse
it does give you a heads up if the app is not compatible
EatSleepTechRepeat said:
Well Huawei have a 4 layer security so when you install from Petal search it does scan and check that the app is secure, How are you getting on with the phone?[/QUOT
Do you know what the 4 layers are? I know one checks to authenticate the original app developer.
Click to expand...
Click to collapse
JaiHamilton88 said:
petal search is probably the best thing to use for all apps, everything you need should be on there with no issues.
Click to expand...
Click to collapse
id agree with this , it saves needing to have apk pure etc
Has everyone seen the PL football app has lunched on app gallery. Sorry different topic but had to share haha
ChrisHtube said:
Has everyone seen the PL football app has lunched on app gallery. Sorry different topic but had to share haha
Click to expand...
Click to collapse
What's strange is I actually searched for it on Petal, then thought why not double check AG.... was surprised to see it! Hopefully Huawei has more app releases up their sleeves!
ChrisHtube said:
Has everyone seen the PL football app has lunched on app gallery. Sorry different topic but had to share haha
Click to expand...
Click to collapse
yeah saw that which is class and just in time
---------- Post added at 09:18 AM ---------- Previous post was at 09:17 AM ----------
ChrisHtube said:
Has everyone seen the PL football app has lunched on app gallery. Sorry different topic but had to share haha
Click to expand...
Click to collapse
tinder is on there too for anyone interested lol
EatSleepTechRepeat said:
it does give you a heads up if the app is not compatible
Click to expand...
Click to collapse
Thanks for this didn't know it did that.

Categories

Resources