Android adware? - General Questions and Answers

So I see a ton of cool looking free games in the play store, and am interested in mass downloading a bunch of them. However I know nothing comes without a price, and dont want to run the risk of infecting my cellphone with whatever crap is out there. If you uninstall an app that manages to spam your notification bar or place shortcuts on your homescreen, are you effectively clean? Does uninstalling the offending app basically rid you of its presence? Or is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing? Also, whats the risk with apps accessing things like email and your phone number? Do I have to worry about some freeware game sending spam to my gmail inbox? Or sending emails on my behalf? Or worse yet, getting my cellphone number and texting me or others? Are any of these things even possibilities, at least from apps on the play store with high ratings?

RunNgun42 said:
So I see a ton of cool looking free games in the play store, and am interested in mass downloading a bunch of them. However I know nothing comes without a price, and dont want to run the risk of infecting my cellphone with whatever crap is out there. If you uninstall an app that manages to spam your notification bar or place shortcuts on your homescreen, are you effectively clean? Does uninstalling the offending app basically rid you of its presence? Or is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing? Also, whats the risk with apps accessing things like email and your phone number? Do I have to worry about some freeware game sending spam to my gmail inbox? Or sending emails on my behalf? Or worse yet, getting my cellphone number and texting me or others? Are any of these things even possibilities, at least from apps on the play store with high ratings?
Click to expand...
Click to collapse
Before uninstall I recommend clearing any app data and force stop through settings. After uninstalling you can use Clean Master and/or SD Maid to clean up and remnant files and folders. As for privacy, you can use XPrivacy to restrict app access to anything and everything.
https://www.youtube.com/watch?v=qu6FHo4X5ts
If you are still worried, you can run android emulators on your PC in an enclosed virtual machine before install on your device.

RunNgun42 said:
SoOr is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing?
Click to expand...
Click to collapse
I use clean master from ks apps. Nothing can clean leftovers better than you.
You download something, app uninstall does the download disappear? Neither commonly used references like flash.
You are tge best judge when it comes to cleaning.
Privacy tools tries to disconnect wifi 3g etc which again you can do manually. Run your apps in flight mode.
Use firewall to control to fro traffic.
Pressing THANKS easier than typing.
Sent from s5360 GB DDMD1 rooted stock.

Related

[Q] Remove / Disable Marketplace App

Does anyone know how to remove or disable the marketplace app completely from reg hack?
apg5031 said:
Does anyone know how to remove or disable the marketplace app completely from reg hack?
Click to expand...
Click to collapse
just one question.
why????
We are trying to use this for business. We do not need anyone to go to marketplace and download apps. Or is there a way to control downloading apps?
Parental controls on a Live ID can prevent the purchase of apps, but I don't know of any way to prevent people from installing free apps. Also, even if you could block app installs on the phone (by blocking the Marketplace), it's still possible to install apps from the PC by using the Zune software.
What is the concern around apps? Smartphones without them are far less useful, and the security model on WP7 is good enough that you don't have to worry that an app will steal sensitive business data or something from elsewhere on the phone.
no, it is impossible... also your application has to be downloaded from marketplace (not good idea to load as dev), and the phone access it for checking updates to apps and everything else...
I can see some concerns: Facebook, FIM, Youtube, etc. If the phone is being used for business, the company may be concerned with employees goofing off through such apps.
Is there any current limit in the registry that we could utilize? A max number of installed apps?
To bad we couldn't create a build that doesn't have the marketplace app in it.

Official: Some Apps contain now Malware

Hey there,
I was surfing through the android market days ago and found some interesting news, non pleasant ones i may say.
I took the applications Granny Smith and Big Great War Game to give it a go, installed them, and failed to check the onscreen advice, so install was successfull.
The applications were working properly, tested it, but i noticed my notification bar had an extra app going, ads mostly, regarding other available purchases. Yes i know some apps do this on a regular basics but this isn't the case. As one of the apps referred above asks for SU privileges, (both are games), and when i tried to uninstall them, i get always "Uninstallation not Successfull". Also, it appears two install apps for each one, example: Granny (240kb) and Granny (14mb). Either way you simply cannot uninstall them.
I then tried the root explorer to hunt these b*astards down manually, after a quick search, i did managed to delete every trace. But though it was done properly, the damn icon still appears on my apps list, and with various uninstall tools available, simply gives you error after error.
Down side is, so far you may think this is harmless, after all its publicity and there are a ton of apps doing the same. Right?
Well, not quite. You see, the apps run with the system constantly, with 3G or WIFI or not, not appearing on any task killer, and thus completely draining your battery in 1hr tops.
I would like to know if anyone encountered any issue relevant or similar to this case, as is critical to at least inform the customer the malware capabilities of such apps.
If needed or for experiment use, you can ask me for the apk files, i saved copies of it.
Cheers.

(Potential) Malware found on Elephone S3 right out of box?

Hi guys
I recently purchased a Elephone S3 from Everbuying.com. I heard people talking about how notorious these Chinese phones are having malware installed on them, so I decided to give the malware check a go and use about 10+ popular Malware detection apps (Avast, Kaspersky, Avira, Trojan Killer, you name it) currently available on Play Store.
Out of all those, excluding warnings that doesn't really matter in this regards (Malware specific), the below two apps gave me those respective warning results.
I have done some research, but i don't think I found any relevant info in this regards. So, for all the guru out there, the question is obvious, should I be worried about these "non-deletable" apps (if not rooted)? If they ARE malicious, can I be worried free by turning off ALL permissions for the apps and in some case, disable the app (I can disable the Beauty Center, not ELE Launcher).
Thanks to you all for any input!
Malwarebytes Anti-Malware
App - Beauty Center
Message - Android/PUP.Riskware.Cooee.a
App - ELE Launcher
Message - Android/PUP.Riskware.Cooee.H
Stubborn Trojan Killer
App - Beauty Center
Message - General Trojan
App - ELE Launcher
Message - General Trojan
bagachin said:
Hi guys
I recently purchased a Elephone S3 from Everbuying.com. I heard people talking about how notorious these Chinese phones are having malware installed on them, so I decided to give the malware check a go and use about 10+ popular Malware detection apps (Avast, Kaspersky, Avira, Trojan Killer, you name it) currently available on Play Store.
Out of all those, excluding warnings that doesn't really matter in this regards (Malware specific), the below two apps gave me those respective warning results.
I have done some research, but i don't think I found any relevant info in this regards. So, for all the guru out there, the question is obvious, should I be worried about these "non-deletable" apps (if not rooted)? If they ARE malicious, can I be worried free by turning off ALL permissions for the apps and in some case, disable the app (I can disable the Beauty Center, not ELE Launcher).
Thanks to you all for any input!
Malwarebytes Anti-Malware
App - Beauty Center
Message - Android/PUP.Riskware.Cooee.a
App - ELE Launcher
Message - Android/PUP.Riskware.Cooee.H
Stubborn Trojan Killer
App - Beauty Center
Message - General Trojan
App - ELE Launcher
Message - General Trojan
Click to expand...
Click to collapse
go ahead and disable Beauty Center, as far as ELE Launcher, that seems legit. But if you don't like it, just replace it with something like Nova Launcher.
mattzeller said:
go ahead and disable Beauty Center, as far as ELE Launcher, that seems legit. But if you don't like it, just replace it with something like Nova Launcher.
Click to expand...
Click to collapse
Hi mattzeller, thanks heaps for the info! This might not be a good question, but just for my information, generally speaking, is there a way to distinguish between a real harmful malware (actively stealing personal info) and an app that has more access and integration to the phone's OS than others by looking at the information provided? In other words, is there any obvious give away sign?
Thanks again for the help!
bagachin said:
Hi mattzeller, thanks heaps for the info! This might not be a good question, but just for my information, generally speaking, is there a way to distinguish between a real harmful malware (actively stealing personal info) and an app that has more access and integration to the phone's OS than others by looking at the information provided? In other words, is there any obvious give away sign?
Thanks again for the help!
Click to expand...
Click to collapse
Well look at reviews of the app, see if it is installing other apps without your consent, or constantly nagging you to download other apps. Generally 99.99% of apps on Google play are safe. Occasionally some crapware gets on there, but if you take a look at its rating and reviews (not just the highlights) you should be good.
Sent from my SCH-R220
bagachin said:
Hi mattzeller, thanks heaps for the info! This might not be a good question, but just for my information, generally speaking, is there a way to distinguish between a real harmful malware (actively stealing personal info) and an app that has more access and integration to the phone's OS than others by looking at the information provided? In other words, is there any obvious give away sign?
Thanks again for the help!
Click to expand...
Click to collapse
Always check the apps permissions. I absolutely refuse to install an app that has permissions that it shouldn't be using. However, if the app you're about to download needs permissions related to the app features, that's OK with me.
I see so many Play Store apps that are just total spyware in my book. Flashlight apps are a good example of this. There is zero reasons a flashlight app needs to read my contacts or a data connection. Just be mindful of reviews and permissions and you'll be OK.
KernelCorn said:
Always check the apps permissions. I absolutely refuse to install an app that has permissions that it shouldn't be using. However, if the app you're about to download needs permissions related to the app features, that's OK with me.
I see so many Play Store apps that are just total spyware in my book. Flashlight apps are a good example of this. There is zero reasons a flashlight app needs to read my contacts or a data connection. Just be mindful of reviews and permissions and you'll be OK.
Click to expand...
Click to collapse
I don't worry about apps with excessive permissions, I just revoke the permissions I don't like.
Sent from my SCH-R220
mattzeller said:
I don't worry about apps with excessive permissions, I just revoke the permissions I don't like.
Click to expand...
Click to collapse
That's the best way to do it.
I do the same thing, but I see lots of people posting here that aren't too tech savvy. For them be mindful of what you download.
mattzeller said:
Well look at reviews of the app, see if it is installing other apps without your consent, or constantly nagging you to download other apps. Generally 99.99% of apps on Google play are safe. Occasionally some crapware gets on there, but if you take a look at its rating and reviews (not just the highlights) you should be good.
Sent from my SCH-R220
Click to expand...
Click to collapse
Thanks for the advice. Yes, I am aware that common source/cause of malwares are side load apps and rooted device. So I am always fairly cautious about any apps i installed via non-play store source. However, these two caught apk are installed right out of box. That kinda annoys me. I don't jump on the bandwagon and say Chinese phones are infested with malwares and I believe a lot of the time people just over exaggerate and blow some minority out of proportion.
However, the truth is, this is the first Chinese phone I got and it came with two identified malwares. To be fair, it might not be particularly malicious, but it's enough to make me have second thought about my purchase....
KernelCorn said:
Always check the apps permissions. I absolutely refuse to install an app that has permissions that it shouldn't be using. However, if the app you're about to download needs permissions related to the app features, that's OK with me.
I see so many Play Store apps that are just total spyware in my book. Flashlight apps are a good example of this. There is zero reasons a flashlight app needs to read my contacts or a data connection. Just be mindful of reviews and permissions and you'll be OK.
Click to expand...
Click to collapse
Thanks for the comment! Yes, I am quite careful about the app I get to choose to install, but I have little control over these apps that come pre-installed on these chinese phone and got detected as "malwares"
mattzeller said:
I don't worry about apps with excessive permissions, I just revoke the permissions I don't like.
Sent from my SCH-R220
Click to expand...
Click to collapse
Yap, what I did for those two apps I mentioned are turning off all permissions access to them, disable app for the one I can and turn off background data access. Hopefully it will freeze them for good and stop them from playing naughty.
Just a question though, say I do all those above (e.g. switching off permission, force stopped etc), technically speaking, can a malware still be "active and do what they "meant" to do"? I meant after all, they are meant to do something "out of control" right?
bagachin said:
Yap, what I did for those two apps I mentioned are turning off all permissions access to them, disable app for the one I can and turn off background data access. Hopefully it will freeze them for good and stop them from playing naughty.
Just a question though, say I do all those above (e.g. switching off permission, force stopped etc), technically speaking, can a malware still be "active and do what they "meant" to do"? I meant after all, they are meant to do something "out of control" right?
Click to expand...
Click to collapse
No, if you revoke the permission to view your contacts, it is the system that is blocking the apps ability to view your contacts.
Though I think you are being a little paranoid.
Everyone freaks out out all the permissions apps require, when the app actually never uses most of the permissions it asks for, at least not in the way you think. You wouldn't think the launcher needs permissions to access your contacts, but it does. How else is it going to allow you to make a call, or display an incoming all, or missed call/text badges.
I mean take a look at the litany of permissions Nova Launcher and TeslaUnread require, yet we all know the app is not malware. As long as you install from legitimate sources, you will be fine. Like I said in my first post, disable the Beauty app, the other is the Launcher. If you don't like it, install a different one.
Sent from my SCH-R220
Who would you rather have snoop in on your calls? China, or USA.. Because it is one or the other.. me personally, I will take the country in which I do not reside...
mattzeller said:
No, if you revoke the permission to view your contacts, it is the system that is blocking the apps ability to view your contacts.
Though I think you are being a little paranoid.
Everyone freaks out out all the permissions apps require, when the app actually never uses most of the permissions it asks for, at least not in the way you think. You wouldn't think the launcher needs permissions to access your contacts, but it does. How else is it going to allow you to make a call, or display an incoming all, or missed call/text badges.
I mean take a look at the litany of permissions Nova Launcher and TeslaUnread require, yet we all know the app is not malware. As long as you install from legitimate sources, you will be fine. Like I said in my first post, disable the Beauty app, the other is the Launcher. If you don't like it, install a different one.
Sent from my SCH-R220
Click to expand...
Click to collapse
Unfortunately the way things are with the permissive Android system, we have to be a little paranoid. The built in system apps like launchers and permissions can't be disabled easily unless the user is technical enough to know about rooting using apps like xposed/xprivacy.

[Q] Ovoid infecting upgrade in a trans of data

I have been increasingly disturbed by the distracting number of ads I am getting. I even get video adds that open with full volume!
There seems to be no way to ID apps that are pushing adds behind the scenes. But I wonder, even in today's add craze world, if I'm dealing with some kind of bug or malware that cannot be stopped. I mean how could a developer, legally, push endless numbers of intrusive adds anonymously, in a way that makes them unable to be ID'd and stopped?
I'm getting an S9 soon and want to avoid infecting so I'm not going to transfer files from the S8. I will reinstall amm my apps from the Play Store. But what about app data? Can I copy data files to an ext drive then copy them onto the S9, after I've reinstalled the app? Of course, apps with a backup option wouldn't be a problem.
Hi, looks like some apps might be pushing the ads. Best option would be to locate the app pushing the ads. Unfortunately, you will have to manually uninstall and check. However, you can take backup of your apps and data with titanium backup beforehand.
mikeacox said:
I have been increasingly disturbed by the distracting number of ads I am getting. I even get video adds that open with full volume!
There seems to be no way to ID apps that are pushing adds behind the scenes. But I wonder, even in today's add craze world, if I'm dealing with some kind of bug or malware that cannot be stopped. I mean how could a developer, legally, push endless numbers of intrusive adds anonymously, in a way that makes them unable to be ID'd and stopped?
I'm getting an S9 soon and want to avoid infecting so I'm not going to transfer files from the S8. I will reinstall amm my apps from the Play Store. But what about app data? Can I copy data files to an ext drive then copy them onto the S9, after I've reinstalled the app? Of course, apps with a backup option wouldn't be a problem.
Click to expand...
Click to collapse
You will have to use either google or samsung back up option to get your app data back. The data is stored on a part of the device you have no access to without root.
Get an ad blocker of a VPN. IF you use youtube then you can get an ad free version without root. I personally have not seen an ad in years.
papa.sid said:
Best option would be to locate the app pushing the ads. Unfortunately, you will have to manually uninstall and check.
Click to expand...
Click to collapse
Yes, it appears that is what is what's happening and that there is no way to ID the source. It seems, to me, that there ought to be a law against such an action. It's clearly deceptive and dishonest.
However, you can take backup of your apps and data with titanium backup beforehand.
Click to expand...
Click to collapse
I think that app required rooting, which I am not comfortable doing.

Rooted Android Security Measures. What are they?

I've never rooted an Android. One of the warnings I see over and over is that rooted devices are more vulnerable to malware. I don't see any solutions for this though.
What extra measures will I need to take to keep my Android safe?
I use Norton 360 on my PC and Androids. Will this be of any help?
Are there any apps I can install to help with this issue?
Are there any system settings I should use for this particular problem?
Thank you
With stock or rooted the biggest threat is the user themselves. Most either install or download the malware themselves. A fully updated stock Android isn't invulnerable; there's no saving dumb bunnies...
Side loaded apps are high risk; at the least scan with online Virustotal and consider the results before installing. Keep email in the cloud and be careful if you choose to download anything.
All downloads stay in the download folder until vetted. Jpeg's and png's are suspect; open them there first before moving them and watch for strange behavior in that folder. Check the download folder daily for anything you didn't download, if found do not open, delete.
Keep thrash social media apps off the phone, all of them. They are targets and vectors for malware of all types.
Use a good firewall and police what apps are doing. Revoke internet access to all apps that don't need it. Know what apps have run at start permissions; do they need it? Updates and upgrades can cause more lost time then malware trying to find work arounds. Lock auto updates down, and download them only if needed. Updates and firmware upgrades can and do break things...
Most importantly cover your six and be prepared.
Critical data can not be lost, protect it!
Redundantly backup all critical data to at least 2 hdds that are physically and electronically isolated from each other and the PC. Be ready to do a full reload if needed.
If malware is found or suspected, isolate the phone and if it can't be completely deleted in an hour or two, nuke that load. Be ready to change passwords and secure accounts.
Never trust antivirus apps to detect malware or save you, mostly they just waste resources on an Android.
Thank you!
I'm already doing a lot of those things, especially social media apps.
One of the reasons I want to root my phone is that I can't uninstall, force stop, disable or take away permissions for some apps, like Facebook, Facebook App installer, FB app manager Google, ad nauseum. The same goes for the millions of preinstalled Samsung bloatware apps. They dont stay disabled and routinely restore permissions. Im sick of having to routinely check them all. I'll never buy another Saamsung again.
You're welcome. Welcome to XDA
I run 2 stock N10+'s, one on Pie, the other on 10.
I use package disabler to kill bloatware and services I don't want to run at bootup. You can also use a adb editing app to disable apks. Don't go too nuts; be wary of disabling any Samsung system apps. Most of these apps just sit unless needed. Dependencies... actions have consequences; understand what the app does and what other apps, services or UI functions are dependent on it!
Google play Services can be disabled when not needed; disable find my device as System Administrator first.
On Pie Karma Firewall is fully functional but not on Android 10 and up, although it will still block access. It uses virtually no battery.
Once you sort it out (learning curve ahead) stock Samsung's especially older ones like the N10+ are easy to run. They are the most customizable stock Android on the planet with an excellent UI. The current load on this one will be 2 yo this June; still fast, stable and fulfilling its mission. Security is simply not an issue.
blackhawk said:
You're welcome. Welcome to XDA
I run 2 stock N10+'s, one on Pie, the other on 10.
I use package disabler to kill bloatware and services I don't want to run at bootup. You can also use a adb editing app to disable apks. Don't go too nuts; be wary of disabling any Samsung system apps. Most of these apps just sit unless needed. Dependencies... actions have consequences; understand what the app does and what other apps, services or UI functions are dependent on it!
Google play Services can be disabled when not needed; disable find my device as System Administrator first.
On Pie Karma Firewall is fully functional but not on Android 10 and up, although it will still block access. It uses virtually no battery.
Once you sort it out (learning curve ahead) stock Samsung's especially older ones like the N10+ are easy to run. They are the most customizable stock Android on the planet with an excellent UI. The current load on this one will be 2 yo this June; still fast, stable and fulfilling its mission. Security is simply not an issue.
Click to expand...
Click to collapse
The more annoying Samsung apps I was referring to are the Bixby apps, AR doodle, Smarter things... those kind of apps. If they didn't re-enable themselves restore permissions, I wouldn't mind them so much. But they DO.
I won't be using that phone much longer anyway. I'm going back to Motorola.
I always buy factory or globally unlocked phones. That helps some. But Motorola recently started forcing FB. I can uninstall it, however I have to review updates to make sure it doesn't end up on my phone again. But then I review all updates before installing them anyway..
I always look up the system apps before making any changes. Like Google Easter Egg. Everything I could find says it's unnecessary.
All those mentioned apps can be safely disabled.
Bixby Vision is used for barcode scanning though.
Try the free Galaxy store icon packs, themes and the Good Lock family of apps including One Handed Operation plus.
Chose theme>icon pack>whatever wallpaper you want. The native high contrast theme looks good.
Play with it...
blackhawk said:
All those mentioned apps can be safely disabled.
Bixby Vision is used for barcode scanning though.
Try the free Galaxy store icon packs, themes and the Good Lock family of apps including One Handed Operation plus.
Chose theme>icon pack>whatever wallpaper you want. The native high contrast theme looks good.
Play with it...
Click to expand...
Click to collapse
I actually already ordered a new Moto. It will be here tomorrow. Well, it's after 1am, so I guess it'll be here later today.
I've disabled multiple Samsung apps, restricted data and battery, taken away permissions, not just in app settings, but in permissions setting, special access permissions... And all the other weird ways I keep finding out about that you wouldn't think would be a place to remove permissions. When my phone starts to slow down, or the battery isn't lasting very long, sure enough, Samsung has gone behind my back and reset my preferences again. I never had issues like this any of the Motorola phones I've had.

Categories

Resources