FBI Greendot Virus.... on a phone? - Security Discussion

Hey guys,
Ive done some searching and cant seem to find anything on it, so youre my last hope.
My friends mom had an old Droid X2 and somehow while browsing Twitter on it, downloaded this FBI Greendot virus.
Basically, what it does is completely locks out the phone with just a message that says a bunch of crap about piracy and a bunch of other "crimes" and files found on the phone.
Ive tried booting into the recovery and I think it spread far enough into the system files to corrupt even that.
Im afraid to plug it into a computer in fear of it spreading to the computer itself as well.
Has anyone at all run into this issue?
Thanks guys.
Sent from my SCH-I545 using XDA Free mobile app

android viruses maybe can't spread to a computer. I did a search and they said if you aare talking about malicious android app, then there is no risk. I would mount your android to a computer use remove the file. Another way i was thinking is scanning the storage with a computer antivirus progam(maybe the virus wont be detected). I dont think can mount the Android because it is locked, but I could be wrong.

CooCooCthulhu said:
Hey guys,
Ive done some searching and cant seem to find anything on it, so youre my last hope.
My friends mom had an old Droid X2 and somehow while browsing Twitter on it, downloaded this FBI Greendot virus.
Basically, what it does is completely locks out the phone with just a message that says a bunch of crap about piracy and a bunch of other "crimes" and files found on the phone.
Ive tried booting into the recovery and I think it spread far enough into the system files to corrupt even that.
Im afraid to plug it into a computer in fear of it spreading to the computer itself as well.
Has anyone at all run into this issue?
Thanks guys.
Sent from my SCH-I545 using XDA Free mobile app
Click to expand...
Click to collapse
What does it do when you try to boot into recovery?
You might be able to just flash a new system image from RSD mode if recovery is borked..

CooCooCthulhu said:
Hey guys,
Ive done some searching and cant seem to find anything on it, so youre my last hope.
My friends mom had an old Droid X2 and somehow while browsing Twitter on it, downloaded this FBI Greendot virus.
Basically, what it does is completely locks out the phone with just a message that says a bunch of crap about piracy and a bunch of other "crimes" and files found on the phone.
Ive tried booting into the recovery and I think it spread far enough into the system files to corrupt even that.
Im afraid to plug it into a computer in fear of it spreading to the computer itself as well.
Has anyone at all run into this issue?
Thanks guys.
Sent from my SCH-I545 using XDA Free mobile app
Click to expand...
Click to collapse
Well if the phone wasnt rooted then there is no chance to the "virus" to infect the /system partition so I think a normal factory reset in recovery or try using multitasking (long pressing home button) or download Ubuntu and run it from the disk, it shouldnt infect the PC and scan everything that You can mount

CooCooCthulhu said:
Hey guys,
Ive done some searching and cant seem to find anything on it, so youre my last hope.
My friends mom had an old Droid X2 and somehow while browsing Twitter on it, downloaded this FBI Greendot virus.
Basically, what it does is completely locks out the phone with just a message that says a bunch of crap about piracy and a bunch of other "crimes" and files found on the phone.
Ive tried booting into the recovery and I think it spread far enough into the system files to corrupt even that.
Im afraid to plug it into a computer in fear of it spreading to the computer itself as well.
Has anyone at all run into this issue?
Thanks guys.
Sent from my SCH-I545 using XDA Free mobile app
Click to expand...
Click to collapse
I just made a thread about this. http://forum.xda-developers.com/general/security/ransomware-fbi-virus-android-t2816398/post54153344
If you follow these instructions you should be able to get it going.

Related

Impossible to root

I think my phone is impossible to root. I can never use the format tool that came with the simpleGoldCard I have done it with HP format I can never get CID so I have come to a conclusion my phone is impossible to root
DVA4890 said:
I think my phone is impossible to root. I can never use the format tool that came with the simpleGoldCard I have done it with HP format I can never get CID so I have come to a conclusion my phone is impossible to root
Click to expand...
Click to collapse
What? Try punctuation and maybe someone can actually help you.
Yeah I'm having a hard time as well. I had already rooted an inspire before but I can't do my own
Sent from my Desire HD using XDA Premium App
I just have no idead what i am missing. i have watched buddys 1 click video and think i am doing it like he says but nope does not work. I might try the other way but it seems a little more in depth but we will see.
Four-Fifty-X said:
What? Try punctuation and maybe someone can actually help you.
Click to expand...
Click to collapse
Don't be a douche! Like this?
I used a new two gig Sandisk card and formatted it in my phone, then used the Gold Card Maker, and then used the Ace hack kit picking up on number two in the menu. This downgraded the rom and then you just forward thru setup and enable debugging again and run number three in the menu. This gives you root and s-off. Then you repeat enable debugging and go to the options menu and flash the stock radio. Once it reboots, you are ready to place your renamed rom on the root of the sd card and restart in bootloader and flash away. Don't forget to disconnect the usb cable after moving the rom to the sd card. After reboot you are home free. If you flash a custom rom, you may need to flash a new radio. The key is having a good gold card, turning off antivirus, and remembering to put the phone on charge only and enabling debugging before each step.
Sent from my Desire HD using Tapatalk
Not to be a jerk but if you can't even figure out how to root the phone using one of the easiest tools around then maybe its best you just leave it alone all together.
Sent from my HTC Desire HD using XDA App
I've rooted my father in laws inspire but now I cant root mine, Im not a total noob with Android but its not working for some reason I guess ill try to find another sd to try it with
malicenfz said:
I've rooted my father in laws inspire but now I cant root mine, Im not a total noob with Android but its not working for some reason I guess ill try to find another sd to try it with
Click to expand...
Click to collapse
You Did make a new goldcard for yours, right?
Yes, I made one for mine. Thanks for all the help guys it wasnt me being a noob it was the sd card not working, i tried a different one and it worked, thanks for all the help again guys.
Right on, sometimes the obvious questions just don't get asked.
Use hack kit tool v11 and read the effenmanual. You will root your phone.
Sent from my Desire HD using XDA App
lol nvm it still didn't work now when its checking PD98IMG.zip it almost finishes then it stops and it says "Model ID incorrect!" "Update Fail!!" "Press <POWER> to reboot"
help?
malicenfz said:
lol nvm it still didn't work now when its checking PD98IMG.zip it almost finishes then it stops and it says "Model ID incorrect!" "Update Fail!!" "Press <POWER> to reboot"
help?
Click to expand...
Click to collapse
Reading stuff like this makes me ever more genuinely glad I don't care to root my Inspire. In my case I know that if it can mess up it will mess up. But the whole process seems so convoluted and messy. Using a "Goldcard" seems like a burden to me...like you have to carry around addition weight with you wherever you go just to have a rooted phone. It all seems so super-duper messy. That's the biggest turn-off for me...like I would be trying to make something work unnaturally...like this is something that isn't designed for the device...stuff like that. By the way, I know someone will misunderstand what I meant by "weight" so I will preempt them by saying I know there is no "weight"...lol
Im just trying to use the wifi hotspot without getting charged on my already unlimited data plan, do i even need to root to do that? besides i just wanna have it rooted but it keeps failing. ive done it like 4 times.
malicenfz said:
Im just trying to use the wifi hotspot without getting charged on my already unlimited data plan, do i even need to root to do that? besides i just wanna have it rooted but it keeps failing. ive done it like 4 times.
Click to expand...
Click to collapse
From what I've read in the past, AT&T detects tethering on rooted phones and will charge the specific account for the cost of the feature.
MartyLK said:
Reading stuff like this makes me ever more genuinely glad I don't care to root my Inspire. In my case I know that if it can mess up it will mess up. But the whole process seems so convoluted and messy. Using a "Goldcard" seems like a burden to me...like you have to carry around addition weight with you wherever you go just to have a rooted phone. It all seems so super-duper messy. That's the biggest turn-off for me...like I would be trying to make something work unnaturally...like this is something that isn't designed for the device...stuff like that. By the way, I know someone will misunderstand what I meant by "weight" so I will preempt them by saying I know there is no "weight"...lol
Click to expand...
Click to collapse
BTW the goldcard is not needed once you're done rooting. I haven't had a goldcard in my phone for months - it's the oiriginal 8GB that I keep it in my desk drawer should I ever need it again. Using a regular 32GB card now.
Rooting's not that hard but there is a small hurdle at first, but the rewards make it worthwhile. Some people prefer stock, some people like to tweak until the cows come home.
Does anyone know what I'm doing wrong for it to say model ID incorrect?
malicenfz said:
Im just trying to use the wifi hotspot without getting charged on my already unlimited data plan, do i even need to root to do that? besides i just wanna have it rooted but it keeps failing. ive done it like 4 times.
Click to expand...
Click to collapse
You can set up an apn that allows hotspot without a tethering plan.
Sent from the computer I carry in my pocket.
Tethering is usually free on rooted phones.
I'm pretty sure that AT&T doesn't do deep packet inspection on their traffic yet, so you should be able to easily get away with tethering as long as you don't have significantly higher data usage than usual.

[Q] All services on Wp 7.5 just stopped working.

This started happening last night. Can't figure out how to fix it, and I really don't want to have to hard-reset my phone :crying:
Here's whats happened so far...
1. Metrotube wouldn't launch (insta-crashed) even after a reboot... so i uninstalled the app.
2. When i attempted to re-install metrotube, it went into the queue, but is stuck on "pending"
3. Attempting to cancel or retry the download = nothing happens
4. Feeds in the People hub refuse to update. Instantly fails with an error.
5. messenger refuses to sign in.
6. "Me" tile is stuck on "3 new items" even though Ive already read everything in there.
7. Attempting to install any other app from the marketplace = error message.
8. Rebooting the phone multiple times has done nothing to help the problems above.
What happened, and how do I fix it? Since when does WP7 randomly just fubar itself?
Still having this issue guys. Any help?
Try pulling the battery if you can for 60 seconds and then try. Otherwise, given what your phone is doing, all I can think of is a hard reset as it sounds messed up.
P.S. If you have a recent backup try using Zune to restore to that.
Device? ROM? Version?
Sent from my HD7 using Board Express
pvt_nemesis said:
Device? ROM? Version?
Sent from my HD7 using Board Express
Click to expand...
Click to collapse
Nokia Lumia 900, OS version 7.10.8779.8
Finally went ahead and hard-reset the phone. Everything is working again...going to take ages to get my handset set back up the way I like it again.
What happened and how do I keep it from happening again!?
Tell us everything you did in the past 3 weeks, and we can say what happened after that.
mcosmin222 said:
Tell us everything you did in the past 3 weeks, and we can say what happened after that.
Click to expand...
Click to collapse
Can you narrow that down slightly? I'll gladly list everything I can, but "everything" is a bit broad.
Does the list I gave in the first post give you any clues? Seems weird that the entire OS would just screw up like that, when it was working fine just minutes before hand...
It sounds to me like a potential hardware failure, either in the NAND Flash itself or in the SD card storage (for phones which use that instead of soldered-in storage). That's just a first guess, though.
As for things to tell us about, were you messing with any high-privilege apps? Either apps that use privilege elevation hacks, like WP7 Root Tools or things like Windowbreak for Samsung, or apps which you marked as "Trusted' in Root Tools?
Leapo said:
Can you narrow that down slightly? I'll gladly list everything I can, but "everything" is a bit broad.
Does the list I gave in the first post give you any clues? Seems weird that the entire OS would just screw up like that, when it was working fine just minutes before hand...
Click to expand...
Click to collapse
Well not quite everything. We don't need to know whom you're texting or stuff like that. Nice info would be if you tried rooting, sideloading some unknown app, attempting to charge without your battery, stuff like those...or if you tried some high privileges stuff, like the guy above me asked.
GoodDayToDie said:
As for things to tell us about, were you messing with any high-privilege apps? Either apps that use privilege elevation hacks, like WP7 Root Tools or things like Windowbreak for Samsung, or apps which you marked as "Trusted' in Root Tools?
Click to expand...
Click to collapse
mcosmin222 said:
Nice info would be if you tried rooting, sideloading some unknown app, attempting to charge without your battery, stuff like those...or if you tried some high privileges stuff, like the guy above me asked.
Click to expand...
Click to collapse
Like I said earlier, this is a Lumia 900. This phone can't be rooted by any known method, and mine wasn't even developer unlocked.
No high-privileges, no root tools, nothing. Totally stock and unmodified with only marketplace apps. It just decided to screw up one day and the only way to fix it was a hard reset...
Also can't charge a Lumia 900 without the battery, because it's sealed inside.

[Q] AAHK gave my computer a virus...is my phone safe to use?

I used AAVH from xda forums to root my Inspire 4g. The computer I opened the .zip or whatever it was on got a trojan virus immediately. I cleaned my computer throughly after I realized, but already finished rooting my phone and flashing a rom onto it (jellytime).
Recently, I've been thinking: could my phone now have a virus on it now? Is there anyway to check? Looking at other posts, antivirus like Avast seems to be looked down upon by most users, and unless there's something I'm not aware of, you can't just "completely format" a rooted phone like a computer and do a clean wipe.
I love the rom I'm using, and I think that was clean. I just get paranoid thoughts about whether some virus on my phone I don't know about is sending logging my passwords or some private information about me...
Thoughts? It'd be a shame not to use this phone just because of paranoia
If you downloaded the aahk from aatn1's website, that's all it is, paranoia, nothing else.
Disclaimer: I'm still half asleep so I might have read your post wrong.
Sent from a dream.
inspiremeplz said:
I used AAVH from xda forums to root my Inspire 4g. The computer I opened the .zip or whatever it was on got a trojan virus immediately. I cleaned my computer throughly after I realized, but already finished rooting my phone and flashing a rom onto it (jellytime).
Recently, I've been thinking: could my phone now have a virus on it now? Is there anyway to check? Looking at other posts, antivirus like Avast seems to be looked down upon by most users, and unless there's something I'm not aware of, you can't just "completely format" a rooted phone like a computer and do a clean wipe.
I love the rom I'm using, and I think that was clean. I just get paranoid thoughts about whether some virus on my phone I don't know about is sending logging my passwords or some private information about me...
Thoughts? It'd be a shame not to use this phone just because of paranoia
Click to expand...
Click to collapse
Zergrush exploit is always detected as a trojan...in fact is an exploit, but it is safe to use. That is why instructions for the Hack Kit state that antivirus and all other protection softwares must be disabled.
Relax, you have no trojan and your device is safe.

[Q] Is That Possible (About an android phone)

Hello. I'm a little paranoid here. Please help me.
I was trying to update my Samsung Galaxy mini (s5570) with kies. Electricity went off while "downloading" image was on the screen. I panicked and remove phone's battery and make it off. (I don't know why)
Since then I have black screen. I can't get into recovery mode etc. But when I plug in the phone, pc sees it. Kies fails repairing it.
Phone has a 7digit screen lock and avast anti theft installed. If I gave it somebody to repair, can he repair and read the smses inside it? The data on the phone is not important to lose, but I don't want somebody read my sms. Is it possible?
anaczugo said:
Hello. I'm a little paranoid here. Please help me.
I was trying to update my Samsung Galaxy mini (s5570) with kies. Electricity went off while "downloading" image was on the screen. I panicked and remove phone's battery and make it off. (I don't know why)
Since then I have black screen. I can't get into recovery mode etc. But when I plug in the phone, pc sees it. Kies fails repairing it.
Phone has a 7digit screen lock and avast anti theft installed. If I gave it somebody to repair, can he repair and read the smses inside it? The data on the phone is not important to lose, but I don't want somebody read my sms. Is it possible?
Click to expand...
Click to collapse
Is it possible? Maybe but no repair shop would do it. Can you get into download mode? You most likely corrupted the software and it may need to be jtaged
zelendel said:
Is it possible? Maybe but no repair shop would do it. Can you get into download mode? You most likely corrupted the software and it may need to be jtaged
Click to expand...
Click to collapse
thank you for your answer.
So, it is possible to read the texts in a probably bricked, password protected and anti theft app installed phone, if I get it right?
anaczugo said:
thank you for your answer.
So, it is possible to read the texts in a probably bricked, password protected and anti theft app installed phone, if I get it right?
Click to expand...
Click to collapse
Anti theft apps really dont work if someone knows what they are doing. If the computer can see it then it is possible to pull the info from the phone. It will not be easy but it can be done. Passwords have no use unless the phone is on.
zelendel said:
Anti theft apps really dont work if someone knows what they are doing. If the computer can see it then it is possible to pull the info from the phone. It will not be easy but it can be done. Passwords have no use unless the phone is on.
Click to expand...
Click to collapse
Is it possible to wipe it myself? I searched web but I couldn't menage to find something. I can't get the phone recovery or downloading mode. is it still possible to delete the things in?
anaczugo said:
Is it possible to wipe it myself? I searched web but I couldn't menage to find something. I can't get the phone recovery or downloading mode. is it still possible to delete the things in?
Click to expand...
Click to collapse
The only way to wipe it is to flash new software to it. Think of it like a PC hard drive. As long as it has not been over written then the info can be recovered but if it get over written then it is gone. To be honest you have little to no worry as to do what you are afraid of would take way too much time for a repair shop to even deal with.
zelendel said:
The only way to wipe it is to flash new software to it. Think of it like a PC hard drive. As long as it has not been over written then the info can be recovered but if it get over written then it is gone. To be honest you have little to no worry as to do what you are afraid of would take way too much time for a repair shop to even deal with.
Click to expand...
Click to collapse
My gf's father said that he'll repair, and is coming here to take the phone tomorrow. I don't know if he'll try but I'm still worried
anaczugo said:
My gf's father said that he'll repair, and is coming here to take the phone tomorrow. I don't know if he'll try but I'm still worried
Click to expand...
Click to collapse
Unless he is an Android/Linux hardcore developer you have nothing to worry about. Even Then it would take him a week or more to do it.
No, it won't be possible. The only way to fix it would be to get a stock image on the device through either Jtag or odin. Once that is done, it will be clean slate and without you signing into your Google account, their will be no indication that the phone was ever yours...
zelendel said:
Unless he is an Android/Linux hardcore developer you have nothing to worry about. Even Then it would take him a week or more to do it.
Click to expand...
Click to collapse
Oh, okay. Thanks again for your answer.
anaczugo said:
Oh, okay. Thanks again for your answer.
Click to expand...
Click to collapse
No problem. Only know as I had to do it for one of my devices and it took me a month to get it to where I could mount it on a linux box and then pull what I needed from the system partition.
Question answered thread closed

What's this

Can some one tell me what's this ? Sometimes happens when I unlock my phone
Sent from my Nexus 5 using XDA Free mobile app
this is creepy.
Virus / Malware? Have you noticed any odd charges on your phone bill?
Kill it with factory images. Be careful what you download next time...
RoyJ said:
Virus / Malware? Have you noticed any odd charges on your phone bill?
Kill it with factory images. Be careful what you download next time...
Click to expand...
Click to collapse
Its a new phone
Sent from my Nexus 5 using XDA Free mobile app
Well you're the one who came here asking for help.
I'm 99.999% positive that's not a feature enabled on the phone to brighten your day, but I could be wrong about that.
What does a new phone have to do with it? Nothing, that's what. If you take it out of the box and download an app that installs malware on your phone, then guess what? You have malware now. Viruses/malware/spyware/WHATEVER doesn't really care how old your phone is.
Download and install a virus scanner or flash factory images and start over. Next time be smart about what you download on your phone. Older phones aren't susceptible to viruses any more or less then new phones... -_-
It's not malware or virus or anything of that sort AFAIK... It's a carrier message which pops up when Data is enabled/disabled.. I've seen this kind of behavior in another thread.
However, it could also be an app which is causing this though as said in earlier posts.
Remove the sim card or put the phone in airplane mode and use it for a day. If the messages don't pop up then there's a good possibility that it's a carrier message!
Maybe your phone's alive!I guess it wants to talk with you!
Just kidding,I guess its something related to your carrier.
Wow that is super creepy. I don't know. I'm super paranoid as is Haha. I'd probably do with @RoyJ had described.. However I never encountered this.
Seeing a stupid comment on Google Play about an app you love and marking it as "spam". You've done it too.
Here you go: http://forum.xda-developers.com/google-nexus-5/help/quick-question-smiley-appearing-screen-t2779035
It's most probably a carrier message as I said earlier. There's no solution to it as it's being sent by your carrier. Changing the runtime to ART was a temporary solution which the OP of that thread found!
Download Air Push Detector and run it...

Categories

Resources