Nasty adware removal - General Questions and Answers

Hey guys,
So I have this really annoying adware that pops up everytime I open Google Chrome and for the life of me I can't find where it's coming from.
I posted a screenshot of what it looks like. It only happens once I open a browser.
Here's what I've done and figured out :
-Everytime I uninstall Go Launcher EX it stops
-Can't be Go Launcher EX because my gf has it and doesn't get the adware
-I've removed all widgets from the screen with no luck
-I've uninstalled all free widgets with no luck
Last resort will be uninstalling all apps, but that'll be a pain so I'm trying to avoid it.
Any help on removing this would be greatly appreciated.
Thanks

Help! to Make Adware Removal
Hi there, I am having issue with my Lenovo laptop, its Windows 8 home basic. it is now running very poor and the CPU usage is increases high to 99.9%. So, when I open any of the program and PC, all get stuck. I run my anti-virus for a full scanning and detects the adware program which makes the PC slow, I guess. Otherwise antivirus can't remove it absolutely. That's why I need to know how to remove it altogether from my PC. Its so nasty that everything is messed up now. but when i search on the internet, something. i found this......virusspywaredisinstallazione.com/linee-guida-utile-per-sbarazzarsi-di-pup-optional-bestpriceninja-a-da-pc

Related

Apps launch and then quit. Pulling my hair out. *SOLVED!*

Bing, News, Amazon Kindle are a few apps which launch for one second and then quit. Even mail and people tiles do not update any longer and live tiles stop working. I have uninstalled these apps and reinstalled them where they begin to work again for a bit and then start playing up again. I have refreshed pc and still same problems. Also in Notifications tab in PC Settings, where it says Show notifications from these apps, there is nothing listed. They were listed after a refresh and no longer there.
I have all the latest updates installed and I think that is where the problem is. I bet one update is causing the problems. I feel like refreshing again and not installing any kb updates or firmware updates. Really really frustrated.
Any ideas? Solutions? Magic words?
Sounds awful. Do you have a stable WiFi connection? I have noticed that the Surface wants good connection or she gets weird. Surfing the web ok? Don't have to tap links multiple times to go anyware?
Sent from my HTC One X using xda premium
wardh said:
Sounds awful. Do you have a stable WiFi connection? I have noticed that the Surface wants good connection or she gets weird. Surfing the web ok? Don't have to tap links multiple times to go anyware?
Sent from my HTC One X using xda premium
Click to expand...
Click to collapse
WiFi is good.
Did you recently change your mSD card ?
tboy2000 said:
Bing, News, Amazon Kindle are a few apps which launch for one second and then quit. Even mail and people tiles do not update any longer and live tiles stop working. I have uninstalled these apps and reinstalled them where they begin to work again for a bit and then start playing up again. I have refreshed pc and still same problems. Also in Notifications tab in PC Settings, where it says Show notifications from these apps, there is nothing listed. They were listed after a refresh and no longer there.
I have all the latest updates installed and I think that is where the problem is. I bet one update is causing the problems. I feel like refreshing again and not installing any kb updates or firmware updates. Really really frustrated.
Any ideas? Solutions? Magic words?
Click to expand...
Click to collapse
Have you contacted Microsoft or Amazon about those apps? Maybe it's the HW and you need to exchange? Unless you want to wipe everything as a last resort use alternative apps until that's sorted or the web browser. For news I would use this aggregator called news republic instead of the default app because it's faster at loading up, playing videos, and opening up articles. I don't use Bing, people, mail, or amazon kindle. Don't think there's anything that gets you live tiles n does everything those programs do. So it seems nothing you can really do.
Their is a Microsoft fixit for windows store apps not launching, a simple search will find it. If it tells you that it found corrupted files then a complete reset is in order. Also if you have done any of the tweaks, some of them can cause instability. If you have then retroactively undo the tweaks until you find the cause.
Ok I solved the problem. A simple refresh of the pc was not enough as it does not delete your apps or databases. I there chose to remove everything and reinstall the os which DOES delete the apps and data. This solved the crashing apps and non syncing mail/dead live tiles. I guess due to some corrupt data for the apps.

Android adware?

So I see a ton of cool looking free games in the play store, and am interested in mass downloading a bunch of them. However I know nothing comes without a price, and dont want to run the risk of infecting my cellphone with whatever crap is out there. If you uninstall an app that manages to spam your notification bar or place shortcuts on your homescreen, are you effectively clean? Does uninstalling the offending app basically rid you of its presence? Or is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing? Also, whats the risk with apps accessing things like email and your phone number? Do I have to worry about some freeware game sending spam to my gmail inbox? Or sending emails on my behalf? Or worse yet, getting my cellphone number and texting me or others? Are any of these things even possibilities, at least from apps on the play store with high ratings?
RunNgun42 said:
So I see a ton of cool looking free games in the play store, and am interested in mass downloading a bunch of them. However I know nothing comes without a price, and dont want to run the risk of infecting my cellphone with whatever crap is out there. If you uninstall an app that manages to spam your notification bar or place shortcuts on your homescreen, are you effectively clean? Does uninstalling the offending app basically rid you of its presence? Or is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing? Also, whats the risk with apps accessing things like email and your phone number? Do I have to worry about some freeware game sending spam to my gmail inbox? Or sending emails on my behalf? Or worse yet, getting my cellphone number and texting me or others? Are any of these things even possibilities, at least from apps on the play store with high ratings?
Click to expand...
Click to collapse
Before uninstall I recommend clearing any app data and force stop through settings. After uninstalling you can use Clean Master and/or SD Maid to clean up and remnant files and folders. As for privacy, you can use XPrivacy to restrict app access to anything and everything.
https://www.youtube.com/watch?v=qu6FHo4X5ts
If you are still worried, you can run android emulators on your PC in an enclosed virtual machine before install on your device.
RunNgun42 said:
SoOr is it like a PC and it can side-load all sorts of crap and you'll never be able to fix your phone without reflashing?
Click to expand...
Click to collapse
I use clean master from ks apps. Nothing can clean leftovers better than you.
You download something, app uninstall does the download disappear? Neither commonly used references like flash.
You are tge best judge when it comes to cleaning.
Privacy tools tries to disconnect wifi 3g etc which again you can do manually. Run your apps in flight mode.
Use firewall to control to fro traffic.
Pressing THANKS easier than typing.
Sent from s5360 GB DDMD1 rooted stock.

Tronsmart TS7 (aka Glacier TS7) installs random apps without permission

I have a (4GB) Tronsmart TS7 (some times known as a Alps Glacier TS7). It's a Chinese MTK6589 based phone running Android 4.2 purchased from geekbuying.
For the most part the device is stock, there are next to no pre-installed apps apart from the usual, and the only additional apps I have installed are: Playstation, Steam, ColorNote, Shuttle+, Root Explorer DI Radio, Chrome & Gmail
The problem I have is that there are apps appearing on the device that I am not installing. So far it has been the same set of apps that appear:
Mobo Market
UC Browser
TrustGo Security
DU Battery Saver
337 Game Master
GameCenter
(there may be more)
These apps don't start appearing right after a factory reset, but start to arrive 1-2weeks later. They also seem to be packaged similarly; when I say packaged I mean opening them seems to prompt with the same menu & style (accept licence etc) before it gets to the main app. Also, after you open the app from the app drawer it then creates an icon on the desktop. Maybe opening it actually does the installing?
The apps themselves seem to be legit.
I have factory reset the device (twice), and changed my Google password but they are still appearing. They don't show up in my Play store history so they must be coming from elsewhere.
My main concern is that if it is downloading things without my permission, what might it be uploading ? Not to mention wasting my 3g data etc.
So I have a few questions:
Should I be (really) worried?
Is there a way to monitor this? eg connect to a wifi hotspot and packet capture the network traffic? or maybe use a process monitor (the ones I've tried so far haven't shown anything) to see if there is some sort of script in the background?
Can it be stopped?
Thanks in advance, I would be interested to know if anyone else has/had this problem?
I have the same problem.
I haven't tried flashing some other ROM yet, but I guess that is the only way to get it to stop installing those things.
Have you actually found any other roms to install?
For anybody's information:
You may have noticed how you always end up with a 'Tronsmart.mp4' video file appearing in your gallery app. This is damn annoying since it appears twice, once on the internal and once on the external SD card. There is an '\system\app\CopyTest.apk' file which creates both of these. Should be safe to delete it and thus prevent the file(s) appearing
I have actually decompiled this apk. It works as a service that runs when MEDIA_UNMOUNTED or MEDIA_MOUNTED is invoked, and does absolutely nothing else.
I have the same problem, those random apps installing and the video always in my gallery. I have managed to stop tge apps by using a firewall and allowing only my apps that i want to use the internet. I havent found a solution though to fix the problem. Probably tronsmart is spamming its customers...
mariosm1cy said:
I have managed to stop tge apps by using a firewall and allowing only my apps that i want to use the internet.
Click to expand...
Click to collapse
What Firewall did you use? I might be able to use something like that to pinpoint the app that's causing this.
Sory for the late reply. I am usin "android firewall" free from google play store.
USB debugging disabled stopped it on mine
edit: not that easy, wasn't enough. made some cleanup by disabing/removing some system apps. seems to work so far although there are still some strange events like superuser crashing and right after that system downloader.apk reappearing. haven't seen any other junk coming back
these are the apk's i removed:
systemupdateassistant
systemdownloader
omacp
mtkbt
midtest
galaxy4
fusedlocation
engineermode
engineermodesim
cds_info
basicdreams.

[Q] Gfirewall and Gsearch bloatware/virus problem.. HELP!

Hello guys, i have a problem as reported above with 2 bloatware apps on my android phone: Gfirewall and Gsearch.
My phone model is UBTEL U8 (MTK model, china phone) and i'm running Android 4.2.2 ROOTED. I have no custom rom/firmware installed.
These 2 apps appeared magically about 2/3 months ago, and i thought they were safe beacuse of Google logo and name. Nothing happened in these months except for some phone crashes and restarts, but 2 days ago a banner ad appeared in my home screen at phone restart and/or phone unlock. I use AdAway (similar to AdBlock) to disable ALL TYPES of banner, ads and related on my phone, browser and apps. When i went to AdAway i noticed that was disabled: i enabled it again and restarted the phone.. but banner ads still showing.. so i went again in AdAway and it was disabled.. again!
I have a similar problem with 3G/H connection with Vodafone. Everytime i disable internet connection, it gets activated again in 1 minute max.. so i can't disable internet.. never!
I removed these 2 bloatware apps today and fortunatly they didn't show up again or get reinstalled.. ads and AdAway blocks are disappeared. I started a lot of antivirus controls with Avira and nothing showed up.. so i thought i was fine, BUT the internet problem persists.. i can't disable internet everytime i want. Someone of you could help me to solve this problem? I hope there is an alternative method to solve this without format/reset the phone!
I have the same problem with Gfirewall and Gsearch in my STAR N9800
Same full screen banner ad in my home screen.
In my phone there is Trend Micro Worry Free Business Security Services as antivirus, but nothing was found after a full scan.
If I find something new, I'll write here
user064 said:
I have the same problem with Gfirewall and Gsearch in my STAR N9800
Same full screen banner ad in my home screen.
In my phone there is Trend Micro Worry Free Business Security Services as antivirus, but nothing was found after a full scan.
If I find something new, I'll write here
Click to expand...
Click to collapse
Hello! I solved with hard reset.. if you want to try i suggest you to use titanium backup for your safe apps, so you'll not lose anything
MatthewTaylor92 said:
Hello! I solved with hard reset.. if you want to try i suggest you to use titanium backup for your safe apps, so you'll not lose anything
Click to expand...
Click to collapse
I am facing the same issues, I do not think a hard reset will solve the problem, these two apps are embedded in the firmware, they lie dormant for a while then kick in, after a while, about 3months after purchase.
I have tried uninstalling & they just re-install, if you phone is rooted, you can hybernate them with ''App Quarantine''
I am struggling to deal with them, as my phone is not currently rooted.
FYI: CM security now shows Gsearch as a virus.
Any solutions please??
Cheers Martin
martinzx13 said:
I am facing the same issues, I do not think a hard reset will solve the problem, these two apps are embedded in the firmware, they lie dormant for a while then kick in, after a while, about 3months after purchase.
I have tried uninstalling & they just re-install, if you phone is rooted, you can hybernate them with ''App Quarantine''
I am struggling to deal with them, as my phone is not currently rooted.
FYI: CM security now shows Gsearch as a virus.
Any solutions please??
Cheers Martin
Click to expand...
Click to collapse
remove them after rooting your phone!!! seems soo unimaginable that they are embedded in your rom :/
pushkardua said:
remove them after rooting your phone!!! seems soo unimaginable that they are embedded in your rom :/
Click to expand...
Click to collapse
Yes you are very likely to be correct, I was kinda hoping, for a solution without rooting? Any ideas? Anyone?
Cheers Martin :angel::angel:
Same problem , rooted phone and uninstalled gsearch and gfirewall but in one or two days they auto-reinstall
Play Store
There is a app in the rom called Play Store (Not Google Play Store!) and Opera Service
Remove those apps from the rom to prevent advertisements at screen unlocking.
To remove Play Store and Opera service your phone needs to be rooted (use Titanium backup fi). You can check this by using a firewall like droidwall.
If you can't root your device:
Use a firewall like mobiwol if your device is not rooted (is creates an internal vpn where it can filter your traffic).
Suspicious files found running at background
I have the same problem with the two files reinstalling by itself after I delete them. I have a Chinese made smartphone Tronsmart PS7 running Android 4.2.2 rooted. After digging deeper into the files running at the background, I noticed there are files that have complete access to all the privilege rights in my phone other than android system, they are android.cube, AdupsFotaReboot, RebootAndWriteSys and Common Data Service. I have tried to force these files to stop and it seems the problem is solved, Anyone has any ideas what these 4 files are for?
I don't think to do any hard reset, if these are hard coded in ROM, this is not a stable solution
IMHO there are only two exit ways:
1) do a virus submission request
I've done this request 1 minute ago.
2) flash the device with another ROM (4.2.2 is getting older, anyway...)
You can see the manifests of Gsearch and Gfirewall, are identical:
Not so good news...
Hi all,
in my case, I found a solution. Once MTKDroidTools used to get root on the phone (root only, nothing else), I pressed the button "Delete China" and the application has removed the files from the "files_for_delete.txt" list. After this, the problems are over !!!
Another way to do this with the phone already rooted, you do it manually, and you can follow the steps of:
http://forum.xda-developers.com/showpost.php?p=44455669
or
http://electricheatingcosts.com/removing-chinese-smartphone-spyware/
Best regards.
No more Gsearch and Gfirewall
I had the same problem with my Chinese new teca n9900 and I found the same apps on my phone that you mentioned. I force stopped android.cube, AdupsFotaReboot, Common Data Service, and RebootandWriteSys in app manager in the setting and now Gfirewall and Gsearch stopped automatically installing. I can't seem to enable them back to restart even after I reboot the phone except for "android.cube" that app will restart after I reboot the phone which may be the app causing them to reinstall. I'm not sure what exactly these apps do but my phone seems to work perfectly without them running. Thank you.
Pete636 said:
I had the same problem with my Chinese new teca n9900 and I found the same apps on my phone that you mentioned. I force stopped android.cube, AdupsFotaReboot, Common Data Service, and RebootandWriteSys in app manager in the setting and now Gfirewall and Gsearch stopped automatically installing. I can't seem to enable them back to restart even after I reboot the phone except for "android.cube" that app will restart after I reboot the phone which may be the app causing them to reinstall. I'm not sure what exactly these apps do but my phone seems to work perfectly without them running. Thank you.
Click to expand...
Click to collapse
It seems like now i don't have Gfirewall anymore but Gsearch got reinstalled and i've got an add displayed again so this solution doesn't really work
uninstall gsearch en gfirewall.
I had the same troubles with my phone (elephone P8). First I stopped the software, then I uninstalled it. So far so good.. Did'nt get popupsuntill now..
Succes..
Arthur
Netherlands
MatthewTaylor92 said:
Hello guys, i have a problem as reported above with 2 bloatware apps on my android phone: Gfirewall and Gsearch.
My phone model is UBTEL U8 (MTK model, china phone) and i'm running Android 4.2.2 ROOTED. I have no custom rom/firmware installed.
These 2 apps appeared magically about 2/3 months ago, and i thought they were safe beacuse of Google logo and name. Nothing happened in these months except for some phone crashes and restarts, but 2 days ago a banner ad appeared in my home screen at phone restart and/or phone unlock. I use AdAway (similar to AdBlock) to disable ALL TYPES of banner, ads and related on my phone, browser and apps. When i went to AdAway i noticed that was disabled: i enabled it again and restarted the phone.. but banner ads still showing.. so i went again in AdAway and it was disabled.. again!
I have a similar problem with 3G/H connection with Vodafone. Everytime i disable internet connection, it gets activated again in 1 minute max.. so i can't disable internet.. never!
I removed these 2 bloatware apps today and fortunatly they didn't show up again or get reinstalled.. ads and AdAway blocks are disappeared. I started a lot of antivirus controls with Avira and nothing showed up.. so i thought i was fine, BUT the internet problem persists.. i can't disable internet everytime i want. Someone of you could help me to solve this problem? I hope there is an alternative method to solve this without format/reset the phone!
Click to expand...
Click to collapse
UPDATE:
I'm triyng "Disconnect Mobile" to limit the amount of data probably stolen by these two applications, and after the last unistall of Gsearch and Gfirewall, they do not auto-reinstall!
Disconnect Mobile is a privacy app inspired by our award-winning browser software. The app actively blocks the biggest mobile trackers when you use an app or browse the web using 3G, 4G, LTE, or Wi-Fi. Optional packs include ad filtering and malware protection. Does NOT require root.
Features:
- Blocks the biggest mobile trackers from tracking and collecting your info
- Blocks ads from more than 2500 ad tracking services
- Blocks thousands of websites suspected of malware, spyware, phishing scams and more
Click to expand...
Click to collapse
Like all ad-blocker apps, you can't find this on Play Store, you can find it on 1mobile, for example.
(I cannot post links)
Please let me know if this hint works on your phones
Hi all, my rooted phone is Ulefone U9592 and I found this information :
http://androidforums.com/android-applications/864435-gfirewall.html
TEXT : " My phone is rooted, i set every apk need confirm install, and wait the apk download and confirm install, i used root explorer try to search which directory is. In my phone, i found "/data/user/0/com. cube. android" have the gfirewall apk, i delete that directory, also check whose apk create this directory. The apk is Cube_CJIA01.apk in /system/app, i delete this apk. It fixed. (I think you find the name may not same Cube_CJIA01.apk)"
Well, I revised this information and the folder are : "/data/user/0/com. cube.activity" or "/data/data/com. cube.activity" and in the folder "files" I found :
"_com.gsz.own.pack.apk" and "_com.zgs.gg.pack.apk" (GSearch and GFirewall), I deleted this APK's and I think the problem is solved ..... NOT REALLY!!
If you check the folder "shared_prefs" you find various XML with the information shared at ALISOFT (Chinesse company) and specifically "ApkLoader.xml" with the URL where are downloaded GSearch and GFirewall. Only you need to delete in the XML the parts what you not are interested .... well, if you reboot the phone, the infected XML are restored. The best option is delete the file Cube_CJIA01.apk (do Backup) and reboot the phone. The mentioned folder disappears and the phone works well. Enjoy !!!
Best regards.
Hi jorfen,
I want to follow your instructions, but I need to root my phone before.
Pelase can you give me some hint (or link) to find the right software?
I don't want to install another chinese spyware (like probably VROOT), to remove GFirewall and GSearch
---------- Post added at 09:28 AM ---------- Previous post was at 08:54 AM ----------
may be I have already found the right answer to my question: Framaroot
Compatibility list:
http://www.tfq.me/rooting-almost-any-android-smartphone-without-computer/
App:
http://forum.xda-developers.com/apps/framaroot/root-framaroot-one-click-apk-to-root-t2130276
jorfen said:
If you check the folder "shared_prefs" you find various XML with the information shared at ALISOFT (Chinesse company) and specifically "ApkLoader.xml" with the URL where are downloaded GSearch and GFirewall. Only you need to delete in the XML the parts what you not are interested.
Click to expand...
Click to collapse
I found two files "ApkLoader.xml" and "ApkLoad.xml" with similar info inside, and in both of them I modified the string starting with
<string name="json">blah blah blah...</string> to <string name="json"></string>
jorfen said:
well, if you reboot the phone, the infected XML are restored. The best option is delete the file Cube_CJIA01.apk (do Backup) and reboot the phone. The mentioned folder disappears and the phone works well. Enjoy !!!
Click to expand...
Click to collapse
in my phone I found some files with different names:
_com.gsz.own.pack.apk
_com.zgs.gg.pack.apk
core.apk
gad.apk
uac.apk
uac.dex
jorfen, Cube_CJIA01.apk was in "/data/user/0/com.cube.activity/files" (or similar) in your phone?
Thanks in advance,
Federico
Hi Federico,
I think you already have rooted the phone. Well, I used for this MTKDroidTools, found in this forum (and modified for only install 'su" and "SuperUser.apk"). No problem, only is needed root for System access.
The app Cube_CJIA01.apk is in the folder "/System/app/" (the normal folder for System App's ). The folder "/data/user/0/" is a soft-link (use ln in linux) to the folder "/data/data/"). You locate in this folders the same information, and this is a default folder for working or write files, used in the APK's. Every reboot of phone regenerate information in this folder.
Best regards.
Good news from my virus submission request at Trend Micro:
The two samples are confirmed as malware.
They will be detected as AndroidOS_FakeGSearch.A
Click to expand...
Click to collapse
From now, all products coming from Trend Micro will handle this malware the right way

how do i get rid of a pop up ad?

This pop up ad appears many times a day.
Can't figure where its coming from and how to get rid of it.
Any help would be appreciated.
Download Malwearbytes and run a scan. Looks like adware.
Malwarebytes found nothing ugg
What happens if you go to your pull down from top notifications? I'd think it will show the running process. Hold your finger on it and should go to the 'notifications' setting for the app.
Start deleting questionable apps you downloaded recently.
I had an update recently installed on my Samsung s8. When I tried to play my music, my phone said I had to download Samsung Music Player, since then I've had ads popping up every 5 minutes. Every ad has the System UI logo and an app that I downloaded to monitor app usage confirmed it also. When I go into advanced setting or admin settings the buttons are blocked. Some say to delete any unusual apps, but how can I tell which apps or stock apps I really need?
Which music player did you install?
I agree with the Malwarebytes, you might also want to check out your skin theme. Some have sneaky ways of rolling out ads to your phone.

Categories

Resources