In need of a security app - Security Discussion

Recently I've been finding random tweets have been sent by a rogue app, but I don't know which one. Neither avast or malwarebytes find anything. What app should I download that would be able to tell me what app is sending tweets?
Sent from my SGH-T999 using xda app-developers app

Try this:
https://play.google.com/store/apps/details?id=com.virustotal
Upload the ones that aren't already uploaded to VirusTotal, rescan the ones that are. If you know how to manually backup apps you can also upload the .apk files to Virustotal. If all that comes up clean, then you could also try sending in a suspicious app to an Anti-Virus provider directly (I'd try Malwarebytes first).
Worst case, you might want to consider a reinstall of everything.

This is troubling.
A report saying 96% of apps have vulnerabilities.

there are a lot of good Android anti-virus apps out there. av-test(dot)org tests a bunch of vendors every quarter or so. check them out for more detailed reviews.
Kaspersky
ESET
Sophos
Avast
Armor for Android
all consistently test well. Disclaimed i work for Armor for Android, so of course i believe they are among the best. However, Armor for Android does not offer a free version so if you need free try one of the others.
in response to loner.
"This is troubling.
A report saying 96% of apps have vulnerabilities."
that report is pretty liberal with what it considers a vulnerability. There is a lot of bad stuff out there, but saying 96% of all apps have "vulnerabilities" is a bit irresponsible of that report.

Not trying to rain on anyones parade, but, these are some serious accusations.
http://www.androidauthority.com/armor-for-android-342192/

Related

[Q] Android app security

While I'm waiting for my GS2 (my first Android device) to be shipped I have been doing a little research into the apps and general security and was shocked to find that many apps actually leak private information and data back to ad servers. This scares me a little. I don't want my location, and other personal data being sent to places I haven't authorised.
Is there any way of being able to stop or block this or any way of identifying which apps do this? How can one know if a publisher of an app can be trusted?
I try to keep my PC locked down from this sort of thing and want to do so with my phone. I just want to be able to make an informed decision with Android.
There is a app called Permissions Denied that can do that.
When you download an app from the market, it tells you what permissions theapp has to have. Most of th time, the permissions aren't for what you think. Internet connection is usually cause it has ads. Also, see what the apps are rated, and read the comments to see if the app is trustworthy.
[sig]I'm close to root, im patiently waiting on those puzzles[sig]
First thing I downloaded when I bought my EVO was Lookout mobile. Very good AntiVirus app with free features that Sprint is trying to sell with their own junk. Try it out.
Thanks for the comments guys. The thing is how do you really know that the app is not maliciously harvesting your data?
Take the Lookout Mobile app triagetoday mentioned above. Now, I'm only using this app as an example and am not saying that there is anything wrong with the app as I've not used it. But it makes a good example.
The app wants permissions for everything. Most user comments are positive, there are a few that say that they cannot uninstall it which is worrying but generally the comments are favourable. But how can I be sure that this app wasn't written to harvest data on the pretence that it's protecting your phone? In fact there is even one comment suggesting just that. I can't see anywhere where I can look at the source code so is it a case of blind faith and hope the publisher is not malicious?
After reading many reports about huge increase in malware on Android and data leakage it's a real concern on how to protect your data.

Does android devices need an antivirus?

As topic =)
omnia1994 said:
As topic =)
Click to expand...
Click to collapse
I will not say no, but I haven't seen or had a real life demonstration where an Android AV software stopped or prevented anything on any device (Xoom included).
I personally don't have one loaded on any of my Android devices but I would say this. For phones / tables I prefer firewall software than AV.
Sent from my PG86100 using Tapatalk 2
I would have to say yes. I recently attended a corporate day at Symantec and one of the things they demonstrated to us was how an Android phone becomes infected. The using a laptop they were able to extract personal info and sent txt messages and make calls.
So for me having seen that I would say yes especially if you side load apps using alternative markets.
Funny thing about that...
The sandboxing of the Java processes means that there's no escalation of privilege possible.
There are no viruses on Android in the sense that arbitrary code can be run, or infect the bytecode of other apps.
However, there are malicious apps which can be spotted by their permissions.
Don't use alternative markets. Pay attention to what you install, read permissions, read about the developers. Turn off unknown sources when not installing something from a trusted source. Those are the best security practices.
The "antivirus" apps for Android add very little real security on top of this, but they do slow down your device to make you feel safer.
stiflingcobra said:
I would have to say yes. I recently attended a corporate day at Symantec and one of the things they demonstrated to us was how an Android phone becomes infected. The using a laptop they were able to extract personal info and sent txt messages and make calls.
So for me having seen that I would say yes especially if you side load apps using alternative markets.
Click to expand...
Click to collapse
Your correct about the permissions. The demo we had was an app that had had extra code added and was uploaded onto the market. The demo then showed both apps with the same icons etc but the permissions on the rogue app were nearly 3 times what the legit app required.
The game still ran when you installed it but in the background it was running other daemons giving the hacker the control. One of the big give aways was the ability to send txt messages. No game should need this.
So yes you do have to be vigilant but extra protection is always better if you don't mind having Antivirus software installed...
In my experience all that is really needed is a well configured firewall, pay attention to permission list before the app installation and to obviously avoid unofficial app markets.
The next thing to consider is what web browser you use. There are tons of options out there to choose and not all of them, actually most, don't offer modern features like anti-fishing and popup denial protection.
The best practice will always be prevention, and some android av programs do better than most.
If you are so inclined to have one, my recommendation would be for eset mobile security. I use their av on all my windows machines and haven't had a major issue at all.
Sent from my XT910-Rogers using XDA Premium.
As long as your brain works when reading the permissions (i.e. "why does a wallpaper need to send SMSs?"), then no, an AV isn't necessary.
Unfortunately, a lot of android users don't see to do this, hence hte mass media panic about android viruses.
stiflingcobra said:
Your correct about the permissions. The demo we had was an app that had had extra code added and was uploaded onto the market. The demo then showed both apps with the same icons etc but the permissions on the rogue app were nearly 3 times what the legit app required.
The game still ran when you installed it but in the background it was running other daemons giving the hacker the control. One of the big give aways was the ability to send txt messages. No game should need this.
So yes you do have to be vigilant but extra protection is always better if you don't mind having Antivirus software installed...
Click to expand...
Click to collapse
That's why I recommended a firewall over an AV software, when I comes to Android at least it makes more sense to me to protect the flow of information then to waist CPU cycles on scanning for viruses.
Sent from my PG86100 using Tapatalk 2
megabiteg said:
That's why I recommended a firewall over an AV software, when I comes to Android at least it makes more sense to me to protect the flow of information then to waist CPU cycles on scanning for viruses.
Sent from my PG86100 using Tapatalk 2
Click to expand...
Click to collapse
Good point. I recently un-installed my anti-virus (was using Avast) because it was really slowing down app installation and updating.
omnia1994 said:
As topic =)
Click to expand...
Click to collapse
Yes android devices need antivirus because when you download apps or games from unknown parties aka third parties they mostly have virus or spyware so we need a antivirus which can scan files while downloading and if they have virus or spyware it would stop them if u ask me which av i m using i would recommend Appriva could antivirus reasons its available on play store and its free doesn't use much memory fast and reliable
popularmechanics.com/technology/how-to/computer-security/you-should-put-antivirus-software-on-your-phone-14886208
Wysyłane z mojego Xoom za pomocą Tapatalk 2

Securing my phone, so many choices

I recently bought Android phone HTC ONE V and i am suprised how business work around Anroid OS + apps. I see some major problems :
1) Is there any trusted authority which inform users that application is 'safe' ? (see article : android-malware-spreads-via-website-injection-campaigns) Malware apps are even on Google Play market. I suppose that solution for this problem is to download just from e.g. TOP 10 apps from each category and just *hope* and *believe* that there is no malware contained just because these apps are soo much popular.
2) How to control permissions/app starts/firewall is there any good app for that ? I have unrooted phone. (I cant have Cyanogenmod 7/9 installed on my HTC One V because it was not ported yet) What would you recommend to me ? I see a lot of recommendations for "LBE Privacy Guard" app but then i found thread here on xda forum that this application is maybe suspicious/dangerous etc... I just want to have full control over my phone, why is that choice so difficult ?
List of apps, often recommened by 'The Internet', are these ok or not ? :
Wifi Protector
Droidwall
WhisperCore
WhisperMonitor
SSH Tunnel
Titanium Backup
ROM Manager
Tasker
Perfect App Protector Pro
This exactly describes my situation, many choices -> i expect to get the best from the Android :
The opportunity costs associated with a decision and the time and effort that go into making it are "fixed costs" that we "pay" up front, and those costs then get "amortized" over the life of the decision. The more we invest in a decision, the more satisfaction we expect to realize from our investment. If the decision provides substantial satisfaction for a long time after it is made, the costs of making it recede into insignificance. But if the decision provides pleasure for only a short time, those costs loom large. Spending four months deciding what stereo to buy is not so bad if you really enjoy that stereo for 15 years. But if you are excited by it for six months and then adapt, you may feel like a fool for having put in all that effort.
Dont you feel the same about these Android 'choices' sometimes ?
Tell Me What Kind Of Apps You Are Looking For And I'll Give you Some Recommendations
From the list of apps you have provided I can see that all of them are trusted and reliable.. so go ahead..
1. Well google aded some security in market so before they upload app they check if it is malware-free. But for more security you can download antivirus
(I RECOMMEND AVAST!)
2. For managing apps permisions im using LBE Privacy Guard is the top app for permisions and firewall managment.
Titanium Backup, Tasker-- awesome apps 100% excelent!
Have a nice day
+1 for avast! excellent at keeping viruses out, keeping data secure, doesn't slow the phone down and has an awesome anti-theft feature which if you're rooted is even better!
Did anyones avast actually find anything that is not a false positive?
Just wondering if this is really necessary...
My avast detected the one click root and androot files on my sd card as malware, which I mean they could be lol but the process of identifying them as false positives was a pain. Other than that... Avast is amazing.
Sent from my myTouch_4G_Slide using XDA
onebornoflight said:
My avast detected the one click root and androot files on my sd card as malware, which I mean they could be lol but the process of identifying them as false positives was a pain. Other than that... Avast is amazing.
Sent from my myTouch_4G_Slide using XDA
Click to expand...
Click to collapse
Yes, sometimes it does its an antivirus so... he thinks that third-party apps are suspicious, but there is nothing to worry about when it comes to root.
antivirus is no good for performance
Antivirus overrated
Antivirus is and will never be any good for performance. You have to decide what risk you are willing to take. With good common sense, you can filter out the obvious threats. Review apps permissions and (try to) install only apps you and the community trust. If you don't trust it, ask around in this forum
Also - obviously - don't visit suspicious sites, click on links in emails and never download programs you don't know.
Personally, i do not use virus protection. I do use DroidWall and LBE Privacy guard for a few apps, but more for data and performance issues.
But i also regularly whipe my phone to install new ROM's and let my (trusted) apps freshly reinstall and restore only game user data.
rilorolo said:
Antivirus is and will never be any good for performance. You have to decide what risk you are willing to take. With good common sense, you can filter out the obvious threats. Review apps permissions and (try to) install only apps you and the community trust. If you don't trust it, ask around in this forum
Also - obviously - don't visit suspicious sites, click on links in emails and never download programs you don't know.
Personally, i do not use virus protection. I do use DroidWall and LBE Privacy guard for a few apps, but more for data and performance issues.
But i also regularly whipe my phone to install new ROM's and let my (trusted) apps freshly reinstall and restore only game user data.
Click to expand...
Click to collapse
+1 here. I think that there is no need to use an Antivirus. Just have a look on the permissions when installing an app and you will be OK.

Good antivirus for rooted phones?

Hey does anyone know of a good antivirus app for a rooted zenfone 2e? I want one that is free but has as many features as possible as well. Thanks.
I used to use Avast but the best anti virus is you, the user. Know your system, know the internet. If youre rooting, you will/should eventually get very familiar with android, how it behaves, the file system, permissions, built-in apps, etc. Avoid indiscriminate app downloads, especially from places other than the play store, and never follow links that youre unsure of. My opinion is that Windows is the only OS that AV is pretty much necessary.
I second avast. An interesting feature is that it will survive a factory reset if stolen.
zshep99 said:
Hey does anyone know of a good antivirus app for a rooted zenfone 2e? I want one that is free but has as many features as possible as well. Thanks.
Click to expand...
Click to collapse
Unlike the PC, it is extremely unlikely you will "get" a virus on your android. It is you who has to install the malware to make it happen. And it is extremely easy to remove the malware. A factory reset would do it and as root user you could simply restore your nandroid backup.
tetakpatalked from Nexus 7 flo
Most antivirus apps come with a huge amount of crap no one needs. They often drain your battery and slow your smartphone down. I have also seen antivirus apps which behave more like spyware by replacing advertisements in other apps or direct you to untrustworthy websites when opening the webbrowser.
My opinion: You do not need an antivirus app on your smartphone. Make sure you install most apps via appstore. Take care with apps from 3rd party websites. (Especially if the website says you have an virus on your smartphone => scareware!)
I would never install Antivir-Apps, since they will drop your phone-performance. And what do you get for this? Nothing. Just be carefully of what you are downloading.
i thinks for android no needs one antivirus..
Kenfary72 said:
i thinks for android no needs one antivirus..
Click to expand...
Click to collapse
+ one
Envoyé de mon E5333 en utilisant Tapatalk
Kenfary72 said:
i thinks for android no needs one antivirus..
Click to expand...
Click to collapse
+ two
My opinion is that android doesn't need antivirus software when the user is careful about what he downloads.
no disregard to anyone, but are you sure you are in developers forum ?!?! this is not a google store !
do you still live in Symbian world ? even the google play itself has malwares ! or you just want to ignore it ? beside those, hangroid can be easily hacked. the only system that dose not a antivirus is winphone, and it has not need it yet ! but they will come for it very soon.
personally i will never trust ios o even open my email, and in android i have an original payed antivirus that really can respond to a virus. i have original nod32 (i do NOT like it, but i didn't get a better one in hangroid.)
visited by lenovo tab2 a8.
best regards, josef.
josef2600 said:
no disregard to anyone, but are you sure you are in developers forum ?!?! this is not a google store !
do you still live in Symbian world ? even the google play itself has malwares ! or you just want to ignore it ? beside those, hangroid can be easily hacked. the only system that dose not a antivirus is winphone, and it has not need it yet ! but they will come for it very soon.
personally i will never trust ios o even open my email, and in android i have an original payed antivirus that really can respond to a virus. i have original nod32 (i do NOT like it, but i didn't get a better one in hangroid.)
visited by lenovo tab2 a8.
best regards, josef.
Click to expand...
Click to collapse
Best antivirus is still brain.apk
Just do not instal every bulls* and you are good to go.
Most antivirus apps are snakeoil/bloatware which will not protect you from anything!
It is good to think about an anti-virus. Android malwares exist, so everyone who's telling here that AVs for Android are a no-go are jumping the gun. However, the Android system already has some security measures into place. So is it still worth it? Yes. The Play Store can't guarantee a 100% clean virus free app collection. History has shown that. "use your brain" is also not a really constructive argument, it is easy to install a sample or virus infected application. Is it that dumb to use an AV on Android? No.
My suggestion, *buy* an AV. For example I have a yearly subscription to Freedome from F-Secure (VPN service). Primarly for my laptop but you can install it on three devices (I have it on 2 laptops and my smartphone). For the smartphone, besides a VPN the app will also scan the device for malicious apps so I got all my important security features in one app. I know that Avast has something similar. I paid 50 euros for one year, which is next to nothing considering the features and piece of mind. And for all those that go on ranting on my post here, I am a security professional in Android and see malware samples from the inside (reverse engineer) all the time
I encourage you to look in those options: VPN and App scan.
tetakpatak said:
Unlike the PC, it is extremely unlikely you will "get" a virus on your android. It is you who has to install the malware to make it happen. And it is extremely easy to remove the malware. A factory reset would do it and as root user you could simply restore your nandroid backup.
tetakpatalked from Nexus 7 flo
Click to expand...
Click to collapse
Remember stagefight thingy ? One could have abused it to gain root privileges and install a binary that run at start, a raw binary, not a package.
Tell me how it is easy to uninstall it, you would first have to track it, if it's purpose wasn't to patch other binaries, and then, you're good to reflash system partition.
No system is invulnerable
Of course, it's tough to get a virus on android, but there's still common malware, adware, scareware, and raw security flaws. There is still need for security solutions, mostly for the raw flaws.
Best choice for you from my point of view
CM Security & Malwarebytes Anti-Malware
I agree with Magissia if you think over that what you are going to do.
Virustotal AND vulnerability patches

Apps for finding spyware someone installed on my phone?

I've looked at a lot of anti-spyware apps, but I can't find one that specifically says it can find stealth apps that someone installed when they got ahold of your phone. So it would look like an app that I personally wanted to have. They mostly talk about apps that were installed by a virus or link, etc.
It would be nice to be able to disable camera/mic functions too, or at least be notified when they are being accessed.
I don't mind paying to purchase the app, but most require a double digit monthly subscription, and I make next to nothing because I'm disabled so chances are even if I subscribed the money wouldn't be there to continue the subscription.
I've lurked here for many years without signing up, I love you guys! There are so many tutorials and apps that would never have known about if not for you guys. The developers here are geniuses. So thank you immensely in advance for your help!
Maybe try play store free app Bitdefender which has 5 million dl's & 4.7 rating. I have not tried it....
"Bitdefender Antivirus is one of the few actually free antivirus apps. It hasn’t changed much over the years. It offers a basic scanning feature, a simple interface, quick performance, and no configuration. This is a great one for super basic needs. All it really does is scan stuff ..." androidauthority
galaxys said:
Maybe try play store free app Bitdefender which has 5 million dl's & 4.7 rating. I have not tried it....
"Bitdefender Antivirus is one of the few actually free antivirus apps. It hasn’t changed much over the years. It offers a basic scanning feature, a simple interface, quick performance, and no configuration. This is a great one for super basic needs. All it really does is scan stuff ..." androidauthority
Click to expand...
Click to collapse
Thanks for the reply. Do anti-virus apps detect spyware though?
They can, just read some of the app playstore reviews and it's Developer app description for details....
Try ‘Malwarebytes for Android’.
If you really think there's spyware do a hard reset.
If you still aren't satisfied go full nuke and have the firmware reflashed.
No virus detection has a 100% detection rate and the worst trojans only a reflash can eradicate them.
A better question is why do you think there's spyware on the phone?
In over 6 years of using outdated OS's I've never had to do a reload because of malware.
Once found a nasty trojan preloader before it could be triggered with Malwarebytes.
I had a infected jpeg that damaged files in the download folder. Deleting the jpeg and some of the files ended it's brief rain of terror.
Be careful what apps you load, what you download*, what you click and never let others have unsupervised access to your device. React quickly to abnormal behavior to find it's cause.
Delete any file you suspect of being malware including jpegs and pngs.
Be prepare to do a hard reset at any time if you believe the device has been infected.
Always keep at least 2 complete isolated data backups for the device. Stagger syncs to them so a virus can't get embedded on both of them... hopefully.
Lol, paranoid yet?
*use only cloud based email apps like gmail
Google apps are spyware, Facebook is spyware, Whatsapp is spyware, Instagram is spyware. In principle all Social Media apps are spyware.
All apps what are designed to track your Internet browsing habits, such as frequented sites and favorite downloads, and then provide advertising companies with marketing data are spyware. All apps what can access your contacts data are spyware ...
Android, the spyware party mix...
You can try Bitdefender Free or Malwarebytes Premium. I have not used the second one before but have read a review at https://antivirusdoctor.net/ and think about using it on my smartphone.

Categories

Resources