Samsung Trojan. - Security Discussion

I had a Samsung grandmax g7202(untouched stock rom) with popup ads and automatic app downloads. A factory reset didn't help.I found out that the stock recovery had been replaced with odin and the trojan has been flashed.(probably thats why odin right?)
I rooted the phone but i couldn't figure out the package names and had to flash a new rom.Its ok now but how can something like this be done remotely? Had it been a spyware...cant imagine. Is it a venerability? it seems serious or am i missing something??

Pemba_Tamang said:
I had a Samsung grandmax g7202(untouched stock rom) with popup ads and automatic app downloads. A factory reset didn't help.I found out that the stock recovery had been replaced with odin and the trojan has been flashed.(probably thats why odin right?)
I rooted the phone but i couldn't figure out the package names and had to flash a new rom.Its ok now but how can something like this be done remotely? Had it been a spyware...cant imagine. Is it a venerability? it seems serious or am i missing something??
Click to expand...
Click to collapse
man let me see
did you install any outside apps ?
if so pls name
is someone in ur family interseted in tech(root etc.)?
maybe someone had physical access to ur phone
i recommend a nice permissions app.
maybe scan your phone with avg also
if possible do you have the apk file of the trojan(s) app ?
pls send, wanna have a look
thanks

Related

[Q] help?

okay so i rooted my captivate installed titanium backup and deleted a bunch of the bloatware but somewhere in the process i deleted a file that goes along with the market i can still use the market however when i try to download and install apps it gives me an error message and they just constantly say downloading i tried using odin and have tried factory resetting the phone and nothing is working can anyone help me fix my phone?
jedens said:
okay so i rooted my captivate installed titanium backup and deleted a bunch of the bloatware but somewhere in the process i deleted a file that goes along with the market i can still use the market however when i try to download and install apps it gives me an error message and they just constantly say downloading i tried using odin and have tried factory resetting the phone and nothing is working can anyone help me fix my phone?
Click to expand...
Click to collapse
Install the drivers from here http://forum.xda-developers.com/showthread.php?t=731989
try odin again
Mod, move to general please
Sent from my SAMSUNG-SGH-I897 using XDA App
i messed with odin for like 3 hours and it didnt do me any good so i ran a program to unroot my device and i restored the factory data and that didnt help me a bit i guess i'm just going to root it again is there any way possible that i could just reinstall the market.apk file? i downloaded one but it wont let me install it on my phone something about it my phone not being allowed to do it or are there any captivate roms that are available i dont even care if they give me all the bloatware back or is the i9000 rom usable on the captivate?
jedens said:
i messed with odin for like 3 hours and it didnt do me any good so i ran a program to unroot my device and i restored the factory data and that didnt help me a bit i guess i'm just going to root it again is there any way possible that i could just reinstall the market.apk file? i downloaded one but it wont let me install it on my phone something about it my phone not being allowed to do it or are there any captivate roms that are available i dont even care if they give me all the bloatware back or is the i9000 rom usable on the captivate?
Click to expand...
Click to collapse
Did you use the Odin one-click download to re-install the Original OS? There is no file to load - just one big 300MB Odin file.
If you can't get this done, then I doubt you will be able to put the i9000 firmware on - it requires you to use Odin and is more complicated.
jedens said:
i messed with odin for like 3 hours and it didnt do me any good so i ran a program to unroot my device and i restored the factory data and that didnt help me a bit i guess i'm just going to root it again is there any way possible that i could just reinstall the market.apk file? i downloaded one but it wont let me install it on my phone something about it my phone not being allowed to do it or are there any captivate roms that are available i dont even care if they give me all the bloatware back or is the i9000 rom usable on the captivate?
Click to expand...
Click to collapse
How did you try to install the market.apk? Am guessing it would have to be sideloaded as I doubt it's a standard market app, and of course AT&T cripples the ability to load non-market apps natively.
alphadog00 said:
Did you use the Odin one-click download to re-install the Original OS? There is no file to load - just one big 300MB Odin file.
If you can't get this done, then I doubt you will be able to put the i9000 firmware on - it requires you to use Odin and is more complicated.
Click to expand...
Click to collapse
yes i used the one click downloader and i follow all the directions it has on the thread but when i go through the process my phone doesnt show up and i've tried it may different ways and when it does show up nothing has worked it always goes to file analysis then after a few seconds it says fail
could you possibly tell me or show me a walk through of how you use it because i may be doing something wrong that the odin thread isn't telling me
plus do you use the .exe .rar or .zip? not that i think it would matter
startngate said:
How did you try to install the market.apk? Am guessing it would have to be sideloaded as I doubt it's a standard market app, and of course AT&T cripples the ability to load non-market apps natively.
Click to expand...
Click to collapse
i found a market.apk file searching online and put it on my sd card and tried to run it from there because thats what i used to do with my pure and .cab files so i figured i would give it a shot on the captivate

Baffled, newb

so i recently used superoneclick to root my phone. The program said my phone is rooted yet when my kernels etc are the same as stock. I have superuser on my phone but how do i change the kernels etc so that i can use non market apps like wireless tether?
Kernels can be changed with new ROMS. Rooting means you get superuser permission on the terminals so things can be changed.
i dont understand what you asking about non market apps? But you can use apps that required root.
Hope i helped.
mithusingh32 said:
Kernels can be changed with new ROMS. Rooting means you get superuser permission on the terminals so things can be changed.
i dont understand what you asking about non market apps? But you can use apps that required root.
Hope i helped.
Click to expand...
Click to collapse
thanks, sorry let me clarify.
I downloaded wireless tether and titanium backup to remove sprint ID. The issue is when i try to run either, they dont work. Wireless says the kernel is the issue. What else should I do to be able to use these apps?
samsung transform m920 with eclair
atros1 said:
thanks, sorry let me clarify.
I downloaded wireless tether and titanium backup to remove sprint ID. The issue is when i try to run either, they dont work. Wireless says the kernel is the issue. What else should I do to be able to use these apps?
samsung transform m920 with eclair
Click to expand...
Click to collapse
Try barnacle(it's in the market) for wifi tether and you need to download and install busybox in order to use titanium backup, and be careful what you remove because you could brick your phone...
joenathane said:
Try barnacle(it's in the market) for wifi tether and you need to download and install busybox in order to use titanium backup, and be careful what you remove because you could brick your phone...
Click to expand...
Click to collapse
Thank you for the barnacle thing, i havn't removed anything im having issues using anything that requires root access, just unrooted my phone.
Can anyone give me a step by step to rooting it? I simply want to remove sprint ID and have my phone run faster. Cant think of any apps i would really need.
Download z4root here http://forum.xda-developers.com/attachment.php?attachmentid=446145&d=1290341328 transfer it to your sdcard and use a file manager to open it(if you don't have one download astro) install and run it, choose permanent root, and let it do it's thing...
did that, still isnt working, thank you though.
it appears anytime i try to run an app it says something along the lines of not having root access, even though it is rooted
Weird. Hmmmm. I meant i dont know much about your phone. I know that when my root got effed, i just did a factory reset and re-rooted and it worked.
Sorry couldnt help
have you tried this http://www.youtube.com/watch?v=shkOp2Q2AM4 ?
mithusingh32 said:
Weird. Hmmmm. I meant i dont know much about your phone. I know that when my root got effed, i just did a factory reset and re-rooted and it worked.
Sorry couldnt help
Click to expand...
Click to collapse
thanks for trying either way
joenathane said:
have you tried this http://www.youtube.com/watch?v=shkOp2Q2AM4 ?
Click to expand...
Click to collapse
going to try this now, just didnt want to since it seems a bit more complicated and im really weak when it comes to linux
You could try installing Rom Manager from the market. If it works you will be able to flash a custom recovery, backup your device and flash a custom ROM.
Give it a go and let us know if it works.
cool so i followed the video, then it wasnt rooted, so i used z4root apparently it took two things to fully root my phone. Not sure why, some sort of sprint failsafe?
Although i forgot to set a backup to sprint features, so im a bit screwed down the road.
You prolly can find a sprint ROM somewhere. Or you could do a factory reset, not sure of that will bring back the sprint apps. Dont they have the sprint apps on the Android market?
atros1 said:
cool so i followed the video, then it wasnt rooted, so i used z4root apparently it took two things to fully root my phone. Not sure why, some sort of sprint failsafe?
Although i forgot to set a backup to sprint features, so im a bit screwed down the road.
Click to expand...
Click to collapse
That would be my video. AND no, you are NOT rooted if you flashed that tar. All that tar does, is make your phone STOCK with custom recovery, to ensure a nice clean platform to work with. You would hold down volume down, voice button, and power. let go when you see samsung, and then apply an update.zip for the kernel. i do have a video on how to root the Android 2.2.2 and it's a proper root video. Sorry for the confusion.

[Q] delate downloaded Software update

hi
I downloaded a software update accidently on my rooted 8013 now it keeps reminding me about installing the update
how to remove the notification forever I can remove it by pressing the home button but as soon as I Connectto a Wifi it reminds me again.
To don't want an update if it will remove the root until Jellybean is out (is there a leakedJellybean for 8013UEALGB?)
I rooted using the1st Method in this thread:
http://forum.xda-developers.com/showthread.php?t=1831152
and by mistake I installed the update (same as the one I am getting now ) and it ruined every thin took ME SOM time to fiX it and now I have 2 binary counts for some reason, I think this happened after I Flashed a kernal its not that important but how do I remove the binary count and is there a
Stock UEALGB Firmware? I searched around I couldn't find
If I well understand use Triangleaway from here http://forum.xda-developers.com/showthr ... ?t=1494114 ).
hokuto34 said:
If I well understand use Triangleaway from here http://forum.xda-developers.com/showthr ... ?t=1494114 ).
Click to expand...
Click to collapse
thanks but apparently using that program has the risk of bricking My device I don't wanna risk it Over something not important
but Whats Important is the Software update notification that I wanna remove
You have the same chance of bricking your device by using ODIN to flash your tab...
ultramag69 said:
You have the same chance of bricking your device by using ODIN to flash your tab...
Click to expand...
Click to collapse
Yes i know that....but its about the level of importance the only thing i want so badly is to remove the software update notification
Where is the update downloaded before installing??
why didn't anyone answer his question? i want to remove firmware update from my tablet, 400mb is a lot of dats to loose iIm glad It was not More!
dont worry triangleway works like charm, other way is root it manually search for it delete and disable automatic updates in settings
samir_a said:
dont worry triangleway works like charm, other way is root it manually search for it delete and disable automatic updates in settings
Click to expand...
Click to collapse
I don't know Where to search for It (a filename would be great) also how do you disable the update notfication so it dosn't download the update again? what is the process called in the app task manager so i can disable, i wish there was a option so that you are never notfied again.
also there is no option to disable auto updates in settings (on ics anyway)

device status

Hi,
my device status is modified, but ive used the traingle application to make the binary count like stock, but you cannot remove the battery on a tablet which is what ive seen people say to do...so what do I do to fix this?
asustf700t said:
Hi,
my device status is modified, but ive used the traingle application to make the binary count like stock, but you cannot remove the battery on a tablet which is what ive seen people say to do...so what do I do to fix this?
Click to expand...
Click to collapse
Did you remove root by deleting superuser?
mertin said:
Did you remove root by deleting superuser?
Click to expand...
Click to collapse
I genuinely don't understand what that means...
Triangle-away only resets the flash counter on our device... It will still say modified as samsung get the tabs to do a scan of the root directory to see if it can find any "abnormal" binaries meaning the tab is rooted... It will show "Custom" in the about settings everytime... The ONLY way, so far, is to reset flash counter, remove Super User access and essentially go back to stock...
It's Samsung's little way of finding out if you have flashed a custom rom/recovery using ODIN as triangle-away cheats their system...
You will need to reset EVERYTHING back to stock if you have a valid warranty claim....
ultramag69 said:
Triangle-away only resets the flash counter on our device... It will still say modified as samsung get the tabs to do a scan of the root directory to see if it can find any "abnormal" binaries meaning the tab is rooted... It will show "Custom" in the about settings everytime... The ONLY way, so far, is to reset flash counter, remove Super User access and essentially go back to stock...
It's Samsung's little way of finding out if you have flashed a custom rom/recovery using ODIN as triangle-away cheats their system...
You will need to reset EVERYTHING back to stock if you have a valid warranty claim....
Click to expand...
Click to collapse
thank you

[Q] i dunno what went wrong

Hey guys. me again................sadly. here's what happened. i placed a few custom roms on my sd card and tried to flash them unto my infuse 4G using the three finger salute with the factory wipe/cache wipe method. my phone is rooted(thanks a bunch to u guys) and i started getting E: signature verification failed or failed to verify the whole file with all of them. even my original update zip and recovery (3e). seemed just to not work. i rebooted and now i cant retrieve my backups,my wifi refuses to connect and continuous pop ups of whats not workin on my phone anymore are rampant....especially google play. even superuser even tho the app is there it shows errors as well. please tell me what to do to fix the problem......i really want to experience ics and jelly bean and im stuck wit gingerbread and it seems like i missed a step or a download somewhere. also recently my phones memory is being chewed up. jus like that i have 26,32 even 40 apps running. mind u i did not activate them......please help
Skorpyo1983 said:
Hey guys. me again................sadly. here's what happened. i placed a few custom roms on my sd card and tried to flash them unto my infuse 4G using the three finger salute with the factory wipe/cache wipe method. my phone is rooted(thanks a bunch to u guys) and i started getting E: signature verification failed or failed to verify the whole file with all of them. even my original update zip and recovery (3e). seemed just to not work. i rebooted and now i cant retrieve my backups,my wifi refuses to connect and continuous pop ups of whats not workin on my phone anymore are rampant....especially google play. even superuser even tho the app is there it shows errors as well. please tell me what to do to fix the problem......i really want to experience ics and jelly bean and im stuck wit gingerbread and it seems like i missed a step or a download somewhere. also recently my phones memory is being chewed up. jus like that i have 26,32 even 40 apps running. mind u i did not activate them......please help
Click to expand...
Click to collapse
sooo please tell me what going on right now, what is the state of your device, you are able to get into recovery correct? its not the stock recovery which is recovery 3e. it turns on but allot of the apps are not working. so since the signature verification failed, you are going to go to (this is assuming you have CWM NOT STOCK RECOVERY) install zip from sdcard then toggle signature verification, and try to reflash the rom you wanted and since the google play store isent working on your device you need to flash the gapps. it needs to be the version of android the rom you want to flash. (gingerbread roms dont need it but ICS and JB need it) just google gapps and look for the android version of what the rom is.
Trozzul said:
sooo please tell me what going on right now, what is the state of your device, you are able to get into recovery correct? its not the stock recovery which is recovery 3e. it turns on but allot of the apps are not working. so since the signature verification failed, you are going to go to (this is assuming you have CWM NOT STOCK RECOVERY) install zip from sdcard then toggle signature verification, and try to reflash the rom you wanted and since the google play store isent working on your device you need to flash the gapps. it needs to be the version of android the rom you want to flash. (gingerbread roms dont need it but ICS and JB need it) just google gapps and look for the android version of what the rom is.
Click to expand...
Click to collapse
list of whats goin on:
wi-fi fails to connect.
update zip shows same message as other roms (signature verification failed)
google services is gone
recovery-clockwork-2.5.1.5-infuse .zip doesnt work
neaither do (DlevRom++Infuse Edition+1.2.zip,INFINITIUM-v1.1.1.zip,)
vcremoveboot-CWM.zip fails
i cant get into recovery,but how do u toggle signature verification? ive tried reflashing all the roms and the same thing happens.....
Skorpyo1983 said:
list of whats goin on:
wi-fi fails to connect.
update zip shows same message as other roms (signature verification failed)
google services is gone
recovery-clockwork-2.5.1.5-infuse .zip doesnt work
neaither do (DlevRom++Infuse Edition+1.2.zip,INFINITIUM-v1.1.1.zip,)
vcremoveboot-CWM.zip fails
i cant get into recovery,but how do u toggle signature verification? ive tried reflashing all the roms and the same thing happens.....
Click to expand...
Click to collapse
Ah, this is a samsung phone, i thought it was htc,so are you able to get into download mode? if you dont know how to get into download mode, look it up for your phone specificly
Trozzul said:
Ah, this is a samsung phone, i thought it was htc,so are you able to get into download mode? if you dont know how to get into download mode, look it up for your phone specificly
Click to expand...
Click to collapse
i do kno how. but my pc is currently down for repairs and this pc on work is protected. so most programs dont even open, like odin. i recently asked on this site about alternative ways of flashing and i was told about Odin mobile......but sadly my this craziness happened so i havent gotten the chance to do anything
Skorpyo1983 said:
i do kno how. but my pc is currently down for repairs and this pc on work is protected. so most programs dont even open, like odin. i recently asked on this site about alternative ways of flashing and i was told about Odin mobile......but sadly my this craziness happened so i havent gotten the chance to do anything
Click to expand...
Click to collapse
Well for now Odin is the only way to fix your device if your able to boot into it
good luck!
ahhh how frustrating. hope you were able to get it fixed!
Skorpyo1983 said:
list of whats goin on:
wi-fi fails to connect.
update zip shows same message as other roms (signature verification failed)
google services is gone
recovery-clockwork-2.5.1.5-infuse .zip doesnt work
neaither do (DlevRom++Infuse Edition+1.2.zip,INFINITIUM-v1.1.1.zip,)
vcremoveboot-CWM.zip fails
i cant get into recovery,but how do u toggle signature verification? ive tried reflashing all the roms and the same thing happens.....
Click to expand...
Click to collapse
Do you have ClockworkMod recovery installed or the stock 3e recovery?
Sent from my iPhone using Tapatalk
ProtheusIRC said:
Do you have ClockworkMod recovery installed or the stock 3e recovery?
Sent from my iPhone using Tapatalk
Click to expand...
Click to collapse
he is unable to get into recovery, when he gets his computer back, he will be able to know if he can get into download mode, please read before posting something that has already been sloved.
Trozzul said:
he is unable to get into recovery, when he gets his computer back, he will be able to know if he can get into download mode, please read before posting something that has already been sloved.
Click to expand...
Click to collapse
Before being a ****, make sure you know what I'm asking. I did not ask him could he get into recovery, I asked which recovery he had installed. Is there a block button for assholes like you?
Sent from my iPhone using Tapatalk
ProtheusIRC said:
Before being a ****, make sure you know what I'm asking. I did not ask him could he get into recovery, I asked which recovery he had installed. Is there a block button for assholes like you?
Sent from my iPhone using Tapatalk
Click to expand...
Click to collapse
if you read again, he says he does not know which recovery he has. i was not being a "****" i was only informing you :/
Trozzul said:
if you read again, he says he does not know which recovery he has. i was not being a "****" i was only informing you :/
Click to expand...
Click to collapse
That's the second time you've insinuated I didn't read the thread. I can read perfectly well, thank you. At one point he let on he didn't know which recovery he had installed and then he let on he may have CMW. Unless you have something to actually contribute to this thread or a valid question, I'd appreciate it if we just don't communicate with each other. It's a waste of space, which drives up server costs and i don't much like you.
Sent from my iPhone using Tapatalk
ProtheusIRC said:
That's the second time you've insinuated I didn't read the thread. I can read perfectly well, thank you. At one point he let on he didn't know which recovery he had installed and then he let on he may have CMW. Unless you have something to actually contribute to this thread or a valid question, I'd appreciate it if we just don't communicate with each other. It's a waste of space, which drives up server costs and i don't much like you.
Sent from my iPhone using Tapatalk
Click to expand...
Click to collapse
Look, im not Barking at you because you trembled onto someone im helping, i was just telling you and YOU yourself are being the "****". i am not insulting* you in anyway i was only telling you of the situation. i thought at first maybe we can help this guy together. now if your Going to have a fit, take it out on admins or mods, we should not be fighting on this persons thread.
okaaaaaaaaaay that was a bit weird. ok lets see how clear i can be. i roioted my phone using odin. superuser is there(but i cant tell if it works cause my wifi is not connecting whatsoever). basic phone functions(camera,music player,calling work fine) when i do the three finger salute i see 3e recovery. updates and roms are on my sd card but the verification halts any progress. its like the files are incomplete somehow i guess(just a guess). google framework shows an error pop up all the time...............should i reroot the phone,try to get cwm again or try another rom jus in case. any advice right now would be greatly appreciated. i recommend u guys to my friends and u helped me so much in the past. i jus wanna be back in the game makin all my android friends jealous and see what this baby can really do
Skorpyo1983 said:
okaaaaaaaaaay that was a bit weird. ok lets see how clear i can be. i roioted my phone using odin. superuser is there(but i cant tell if it works cause my wifi is not connecting whatsoever). basic phone functions(camera,music player,calling work fine) when i do the three finger salute i see 3e recovery. updates and roms are on my sd card but the verification halts any progress. its like the files are incomplete somehow i guess(just a guess). google framework shows an error pop up all the time...............should i reroot the phone,try to get cwm again or try another rom jus in case. any advice right now would be greatly appreciated. i recommend u guys to my friends and u helped me so much in the past. i jus wanna be back in the game makin all my android friends jealous and see what this baby can really do
Click to expand...
Click to collapse
Well we can try rerooting use the old method you used for now,
i'll try.....hope this work pc lets me load odin. i'll give u guys a heads up
Skorpyo1983 said:
i'll try.....hope this work pc lets me load odin. i'll give u guys a heads up
Click to expand...
Click to collapse
welp! odin and kies dont install on this pc. needs admin permissions.
Skorpyo1983 said:
welp! odin and kies dont install on this pc. needs admin permissions.
Click to expand...
Click to collapse
did you right click and hit run admin?
Trozzul said:
did you right click and hit run admin?
Click to expand...
Click to collapse
yes i did. all it asks for is admin name and password. thats usually reserved for the guys in the IT dept
Skorpyo1983 said:
yes i did. all it asks for is admin name and password. thats usually reserved for the guys in the IT dept
Click to expand...
Click to collapse
well your going to have to wait untill you have computer you have admin rights for.

Categories

Resources