How to remove recurring virus in android 4.4.2 lava iris atom 2 - General Questions and Answers

I have a virus on my phone device mentioned at the title. I have heard about it in some websites and 1 in xda too but it didn't help. I hard resetted it alot from the power and volume buttons. It still comes. My device was rooted using king root. The virus installs many apps . I do not know the exact file names. it was like asd.htj.zcx , zgf.iok.lkj etc. I get it every time i connect to the internet. It creates shortcut to porn sites (sex club, hot videos). I do not own the device its of my mom and she will be mad if she saw it. I couldn't suspect any apps that could do it i would have removed it if i could suspect it. It gives another type of ad about juggernaut champions, uc browser(which i already had). It displays full screen ads excluding the status bar stating launcher loading. It just draws its content over other apps as i noticed it while i hold down the home button i noticed the recent apps thing. And I discovered that if i turn off wifi its gone. Until the time i turn off wifi.
I couldn't install a custom rom as my phone is not detected in spreadtrum driver update tool.
The official update from lavamobiles.com fails halfway while verification.
I have a good experience on samsung devices. But i don't know about others
Plz help!! Fast!!!

sashinm said:
I have a virus on my phone device mentioned at the title. I have heard about it in some websites and 1 in xda too but it didn't help. I hard resetted it alot from the power and volume buttons. It still comes. My device was rooted using king root. The virus installs many apps . I do not know the exact file names. it was like asd.htj.zcx , zgf.iok.lkj etc. I get it every time i connect to the internet. It creates shortcut to porn sites (sex club, hot videos). I do not own the device its of my mom and she will be mad if she saw it. I couldn't suspect any apps that could do it i would have removed it if i could suspect it. It gives another type of ad about juggernaut champions, uc browser(which i already had). It displays full screen ads excluding the status bar stating launcher loading. It just draws its content over other apps as i noticed it while i hold down the home button i noticed the recent apps thing. And I discovered that if i turn off wifi its gone. Until the time i turn off wifi.
I couldn't install a custom rom as my phone is not detected in spreadtrum driver update tool.
The official update from lavamobiles.com fails halfway while verification.
I have a good experience on samsung devices. But i don't know about others
Plz help!! Fast!!!
Click to expand...
Click to collapse
If your mom hasn't killed you yet, follow these steps.
1. Download ES File Explorer from Google Play
2. Run app and navigate to the "Apps Page"
3. Sort installed apps by Date. Making the most recently installed apps appear first
3. Using Es File Explorer, unistall the suspicious looking apps. Or navigate to data/app or system/app and delete the apps manually. You can sort the files (apks) in the system/app folder by date. That should make it easier to locate the newly installed malware.
4. After you've removed all the suspicious apps, Reboot and connect to a WiFi/Mobile Data to make sure all the malicious apps are gone (you shouldn't get the pop ups or the shortcuts anymore)
5. If everything works as intended, uninstall ES File Explorer.

Thanks
Freewander10 said:
If your mom hasn't killed you yet, follow these steps.
1. Download ES File Explorer from Google Play
2. Run app and navigate to the "Apps Page"
3. Sort installed apps by Date. Making the most recently installed apps appear first
3. Using Es File Explorer, unistall the suspicious looking apps. Or navigate to data/app or system/app and delete the apps manually. You can sort the files (apks) in the system/app folder by date. That should make it easier to locate the newly installed malware.
4. After you've removed all the suspicious apps, Reboot and connect to a WiFi/Mobile Data to make sure all the malicious apps are gone (you shouldn't get the pop ups or the shortcuts anymore)
5. If everything works as intended, uninstall ES File Explorer.
Click to expand...
Click to collapse
Thank you!
But I already did that. :good::good::good:
I was inactive to reply if i am late i checked my email and got the reply.
The method was pretty much the same.
The differences from the method are:
I used link2sd to do so
and i found that they weren't in /system/app/ but in /system/priv-app/ .
I tried uninstalling them and it said reboot device. Still they were not uninstalled.
I have just frozen them. And now it works fine.
Good news for non rooted people you can disable the apps if you have the same virus.
If you still have the virus after disabling the apps then you can use link2sd without root and view the system apps and sort them acc to date.
The name of the apps are:
Android Media Service
catstudio
netalpha
org.rain.ball.update
PhoneService
Good news the device is mine now :laugh::laugh::laugh:
I classified the virus and its impacts and removed the explicit one.
And let my mom use facebook for a while i know it sounds cruel but i had to do it.
She had a experience from hell. Then i disabled the sim and said "Now even the sim doesnt work" :cyclops::cyclops::cyclops:

sashinm said:
Thank you!
But I already did that. :good::good::good:
I was inactive to reply if i am late i checked my email and got the reply.
The method was pretty much the same.
The differences from the method are:
I used link2sd to do so
and i found that they weren't in /system/app/ but in /system/priv-app/ .
I tried uninstalling them and it said reboot device. Still they were not uninstalled.
I have just frozen them. And now it works fine.
Good news for non rooted people you can disable the apps if you have the same virus.
If you still have the virus after disabling the apps then you can use link2sd without root and view the system apps and sort them acc to date.
The name of the apps are:
Android Media Service
catstudio
netalpha
org.rain.ball.update
PhoneService
Good news the device is mine now :laugh::laugh::laugh:
I classified the virus and its impacts and removed the explicit one.
And let my mom use facebook for a while i know it sounds cruel but i had to do it.
She had a experience from hell. Then i disabled the sim and said "Now even the sim doesnt work" :cyclops::cyclops::cyclops:
Click to expand...
Click to collapse
I'm glad you got them removed.
You're cold bro
But you got a new phone so :good:

Flash the device
using ResearchDownload Spreadtrum
first, install driver spreadtrum in pc
2, firmware firmwarefile*com/lava-iris-atom-2

Freewander10 said:
I'm glad you got them removed.
You're cold bro
But you got a new phone so :good:
Click to expand...
Click to collapse
Thanks
And actually I got an old phone :silly::silly::silly:
But something is better than nothing:good::good:

danmrz said:
using ResearchDownload Spreadtrum
first, install driver spreadtrum in pc
2, firmware firmwarefile*com/lava-iris-atom-2
Click to expand...
Click to collapse
My device isnt detected in flash tool while it is detected in auto driver installer.

Related

[Q] Gfirewall and Gsearch bloatware/virus problem.. HELP!

Hello guys, i have a problem as reported above with 2 bloatware apps on my android phone: Gfirewall and Gsearch.
My phone model is UBTEL U8 (MTK model, china phone) and i'm running Android 4.2.2 ROOTED. I have no custom rom/firmware installed.
These 2 apps appeared magically about 2/3 months ago, and i thought they were safe beacuse of Google logo and name. Nothing happened in these months except for some phone crashes and restarts, but 2 days ago a banner ad appeared in my home screen at phone restart and/or phone unlock. I use AdAway (similar to AdBlock) to disable ALL TYPES of banner, ads and related on my phone, browser and apps. When i went to AdAway i noticed that was disabled: i enabled it again and restarted the phone.. but banner ads still showing.. so i went again in AdAway and it was disabled.. again!
I have a similar problem with 3G/H connection with Vodafone. Everytime i disable internet connection, it gets activated again in 1 minute max.. so i can't disable internet.. never!
I removed these 2 bloatware apps today and fortunatly they didn't show up again or get reinstalled.. ads and AdAway blocks are disappeared. I started a lot of antivirus controls with Avira and nothing showed up.. so i thought i was fine, BUT the internet problem persists.. i can't disable internet everytime i want. Someone of you could help me to solve this problem? I hope there is an alternative method to solve this without format/reset the phone!
I have the same problem with Gfirewall and Gsearch in my STAR N9800
Same full screen banner ad in my home screen.
In my phone there is Trend Micro Worry Free Business Security Services as antivirus, but nothing was found after a full scan.
If I find something new, I'll write here
user064 said:
I have the same problem with Gfirewall and Gsearch in my STAR N9800
Same full screen banner ad in my home screen.
In my phone there is Trend Micro Worry Free Business Security Services as antivirus, but nothing was found after a full scan.
If I find something new, I'll write here
Click to expand...
Click to collapse
Hello! I solved with hard reset.. if you want to try i suggest you to use titanium backup for your safe apps, so you'll not lose anything
MatthewTaylor92 said:
Hello! I solved with hard reset.. if you want to try i suggest you to use titanium backup for your safe apps, so you'll not lose anything
Click to expand...
Click to collapse
I am facing the same issues, I do not think a hard reset will solve the problem, these two apps are embedded in the firmware, they lie dormant for a while then kick in, after a while, about 3months after purchase.
I have tried uninstalling & they just re-install, if you phone is rooted, you can hybernate them with ''App Quarantine''
I am struggling to deal with them, as my phone is not currently rooted.
FYI: CM security now shows Gsearch as a virus.
Any solutions please??
Cheers Martin
martinzx13 said:
I am facing the same issues, I do not think a hard reset will solve the problem, these two apps are embedded in the firmware, they lie dormant for a while then kick in, after a while, about 3months after purchase.
I have tried uninstalling & they just re-install, if you phone is rooted, you can hybernate them with ''App Quarantine''
I am struggling to deal with them, as my phone is not currently rooted.
FYI: CM security now shows Gsearch as a virus.
Any solutions please??
Cheers Martin
Click to expand...
Click to collapse
remove them after rooting your phone!!! seems soo unimaginable that they are embedded in your rom :/
pushkardua said:
remove them after rooting your phone!!! seems soo unimaginable that they are embedded in your rom :/
Click to expand...
Click to collapse
Yes you are very likely to be correct, I was kinda hoping, for a solution without rooting? Any ideas? Anyone?
Cheers Martin :angel::angel:
Same problem , rooted phone and uninstalled gsearch and gfirewall but in one or two days they auto-reinstall
Play Store
There is a app in the rom called Play Store (Not Google Play Store!) and Opera Service
Remove those apps from the rom to prevent advertisements at screen unlocking.
To remove Play Store and Opera service your phone needs to be rooted (use Titanium backup fi). You can check this by using a firewall like droidwall.
If you can't root your device:
Use a firewall like mobiwol if your device is not rooted (is creates an internal vpn where it can filter your traffic).
Suspicious files found running at background
I have the same problem with the two files reinstalling by itself after I delete them. I have a Chinese made smartphone Tronsmart PS7 running Android 4.2.2 rooted. After digging deeper into the files running at the background, I noticed there are files that have complete access to all the privilege rights in my phone other than android system, they are android.cube, AdupsFotaReboot, RebootAndWriteSys and Common Data Service. I have tried to force these files to stop and it seems the problem is solved, Anyone has any ideas what these 4 files are for?
I don't think to do any hard reset, if these are hard coded in ROM, this is not a stable solution
IMHO there are only two exit ways:
1) do a virus submission request
I've done this request 1 minute ago.
2) flash the device with another ROM (4.2.2 is getting older, anyway...)
You can see the manifests of Gsearch and Gfirewall, are identical:
Not so good news...
Hi all,
in my case, I found a solution. Once MTKDroidTools used to get root on the phone (root only, nothing else), I pressed the button "Delete China" and the application has removed the files from the "files_for_delete.txt" list. After this, the problems are over !!!
Another way to do this with the phone already rooted, you do it manually, and you can follow the steps of:
http://forum.xda-developers.com/showpost.php?p=44455669
or
http://electricheatingcosts.com/removing-chinese-smartphone-spyware/
Best regards.
No more Gsearch and Gfirewall
I had the same problem with my Chinese new teca n9900 and I found the same apps on my phone that you mentioned. I force stopped android.cube, AdupsFotaReboot, Common Data Service, and RebootandWriteSys in app manager in the setting and now Gfirewall and Gsearch stopped automatically installing. I can't seem to enable them back to restart even after I reboot the phone except for "android.cube" that app will restart after I reboot the phone which may be the app causing them to reinstall. I'm not sure what exactly these apps do but my phone seems to work perfectly without them running. Thank you.
Pete636 said:
I had the same problem with my Chinese new teca n9900 and I found the same apps on my phone that you mentioned. I force stopped android.cube, AdupsFotaReboot, Common Data Service, and RebootandWriteSys in app manager in the setting and now Gfirewall and Gsearch stopped automatically installing. I can't seem to enable them back to restart even after I reboot the phone except for "android.cube" that app will restart after I reboot the phone which may be the app causing them to reinstall. I'm not sure what exactly these apps do but my phone seems to work perfectly without them running. Thank you.
Click to expand...
Click to collapse
It seems like now i don't have Gfirewall anymore but Gsearch got reinstalled and i've got an add displayed again so this solution doesn't really work
uninstall gsearch en gfirewall.
I had the same troubles with my phone (elephone P8). First I stopped the software, then I uninstalled it. So far so good.. Did'nt get popupsuntill now..
Succes..
Arthur
Netherlands
MatthewTaylor92 said:
Hello guys, i have a problem as reported above with 2 bloatware apps on my android phone: Gfirewall and Gsearch.
My phone model is UBTEL U8 (MTK model, china phone) and i'm running Android 4.2.2 ROOTED. I have no custom rom/firmware installed.
These 2 apps appeared magically about 2/3 months ago, and i thought they were safe beacuse of Google logo and name. Nothing happened in these months except for some phone crashes and restarts, but 2 days ago a banner ad appeared in my home screen at phone restart and/or phone unlock. I use AdAway (similar to AdBlock) to disable ALL TYPES of banner, ads and related on my phone, browser and apps. When i went to AdAway i noticed that was disabled: i enabled it again and restarted the phone.. but banner ads still showing.. so i went again in AdAway and it was disabled.. again!
I have a similar problem with 3G/H connection with Vodafone. Everytime i disable internet connection, it gets activated again in 1 minute max.. so i can't disable internet.. never!
I removed these 2 bloatware apps today and fortunatly they didn't show up again or get reinstalled.. ads and AdAway blocks are disappeared. I started a lot of antivirus controls with Avira and nothing showed up.. so i thought i was fine, BUT the internet problem persists.. i can't disable internet everytime i want. Someone of you could help me to solve this problem? I hope there is an alternative method to solve this without format/reset the phone!
Click to expand...
Click to collapse
UPDATE:
I'm triyng "Disconnect Mobile" to limit the amount of data probably stolen by these two applications, and after the last unistall of Gsearch and Gfirewall, they do not auto-reinstall!
Disconnect Mobile is a privacy app inspired by our award-winning browser software. The app actively blocks the biggest mobile trackers when you use an app or browse the web using 3G, 4G, LTE, or Wi-Fi. Optional packs include ad filtering and malware protection. Does NOT require root.
Features:
- Blocks the biggest mobile trackers from tracking and collecting your info
- Blocks ads from more than 2500 ad tracking services
- Blocks thousands of websites suspected of malware, spyware, phishing scams and more
Click to expand...
Click to collapse
Like all ad-blocker apps, you can't find this on Play Store, you can find it on 1mobile, for example.
(I cannot post links)
Please let me know if this hint works on your phones
Hi all, my rooted phone is Ulefone U9592 and I found this information :
http://androidforums.com/android-applications/864435-gfirewall.html
TEXT : " My phone is rooted, i set every apk need confirm install, and wait the apk download and confirm install, i used root explorer try to search which directory is. In my phone, i found "/data/user/0/com. cube. android" have the gfirewall apk, i delete that directory, also check whose apk create this directory. The apk is Cube_CJIA01.apk in /system/app, i delete this apk. It fixed. (I think you find the name may not same Cube_CJIA01.apk)"
Well, I revised this information and the folder are : "/data/user/0/com. cube.activity" or "/data/data/com. cube.activity" and in the folder "files" I found :
"_com.gsz.own.pack.apk" and "_com.zgs.gg.pack.apk" (GSearch and GFirewall), I deleted this APK's and I think the problem is solved ..... NOT REALLY!!
If you check the folder "shared_prefs" you find various XML with the information shared at ALISOFT (Chinesse company) and specifically "ApkLoader.xml" with the URL where are downloaded GSearch and GFirewall. Only you need to delete in the XML the parts what you not are interested .... well, if you reboot the phone, the infected XML are restored. The best option is delete the file Cube_CJIA01.apk (do Backup) and reboot the phone. The mentioned folder disappears and the phone works well. Enjoy !!!
Best regards.
Hi jorfen,
I want to follow your instructions, but I need to root my phone before.
Pelase can you give me some hint (or link) to find the right software?
I don't want to install another chinese spyware (like probably VROOT), to remove GFirewall and GSearch
---------- Post added at 09:28 AM ---------- Previous post was at 08:54 AM ----------
may be I have already found the right answer to my question: Framaroot
Compatibility list:
http://www.tfq.me/rooting-almost-any-android-smartphone-without-computer/
App:
http://forum.xda-developers.com/apps/framaroot/root-framaroot-one-click-apk-to-root-t2130276
jorfen said:
If you check the folder "shared_prefs" you find various XML with the information shared at ALISOFT (Chinesse company) and specifically "ApkLoader.xml" with the URL where are downloaded GSearch and GFirewall. Only you need to delete in the XML the parts what you not are interested.
Click to expand...
Click to collapse
I found two files "ApkLoader.xml" and "ApkLoad.xml" with similar info inside, and in both of them I modified the string starting with
<string name="json">blah blah blah...</string> to <string name="json"></string>
jorfen said:
well, if you reboot the phone, the infected XML are restored. The best option is delete the file Cube_CJIA01.apk (do Backup) and reboot the phone. The mentioned folder disappears and the phone works well. Enjoy !!!
Click to expand...
Click to collapse
in my phone I found some files with different names:
_com.gsz.own.pack.apk
_com.zgs.gg.pack.apk
core.apk
gad.apk
uac.apk
uac.dex
jorfen, Cube_CJIA01.apk was in "/data/user/0/com.cube.activity/files" (or similar) in your phone?
Thanks in advance,
Federico
Hi Federico,
I think you already have rooted the phone. Well, I used for this MTKDroidTools, found in this forum (and modified for only install 'su" and "SuperUser.apk"). No problem, only is needed root for System access.
The app Cube_CJIA01.apk is in the folder "/System/app/" (the normal folder for System App's ). The folder "/data/user/0/" is a soft-link (use ln in linux) to the folder "/data/data/"). You locate in this folders the same information, and this is a default folder for working or write files, used in the APK's. Every reboot of phone regenerate information in this folder.
Best regards.
Good news from my virus submission request at Trend Micro:
The two samples are confirmed as malware.
They will be detected as AndroidOS_FakeGSearch.A
Click to expand...
Click to collapse
From now, all products coming from Trend Micro will handle this malware the right way

Adware/Virus on Android

Hello
im facing an ad-ware issues on my htc desire 610
out of no where my phone's screen dims and an add appear (while im on my home screen and all the apps are closed)
You can see the adds in the attachment
please tell me how to locate and remove it
You could try running Malwarebytes, I've normally had quite good results with it.
It's one of the apps you're using. Go through the permissions your apps have
genius911 said:
Hello
im facing an ad-ware issues on my htc desire 610
out of no where my phone's screen dims and an add appear (while im on my home screen and all the apps are closed)
You can see the adds in the attachment
please tell me how to locate and remove it
Click to expand...
Click to collapse
i also have this problem... i guess "Clean Master" is doing it in my Z3 Compact.
I have solved this issue on canvas a116 and core duos (gt i8262)
firstly, to check the severity of the virus do this : go to settings>security>device administrators
try to remove all apps under device administrators. If u are unable to remove them implies the virus is now embedded to ur fone's firmware.
solution : 1. backup ur contacts and media only, (do not backup apps and app data)
2. now u need to do a factory reset either from recovery menu or using adb (factory reset from 'settings' wont work)
3. if u again see any app under device administrators then the only solution is to reflash ur firmware
About the virus: This virus come packed in several apps on playstore in april 2015, those apps were immediately removed from playstore. however before its removal from playstore the virus had infected around 5000 smartphones. some websites refer to it as ghosthost virus. Still some non playstore apps carry this virus with them. once you install such apps, the virus will first root ur fone, and then grant itself superuser permissions without u even knowing it. Then it will install itself into system folder so dat it appears to be a system app. Whenever u r connected to internet it will download adware and install them in system folder. Its a very powerful virus, it also hides itself by running a script. Once it is in system folder u wont be able to delete it because it imitates the file names of the system files.
There's a huge list of infected apps hosted by Google playstore. So I think it's not easy to keep our devices secure from virus infection.
AVG can be as correct the problem
Hi guys! i have a serious adware problem on my elephone p7000 and i hope you can help me out.
So it's been a few days and i haven't been able to uninstall this mofo.
Here's what the adware is doing:
-Used to open ads on homescreen. it did that disguising itself as a dancing matrioska doll (which you could move around). since i installed CM security it stopped showing this kinds of ads.
-It opens pop up windows with du batery saver or other related apps (from appstore and from non-official stores). Mostly when i browse the internet.
-it places vertical ad banners (like the normal ones on almost every app on the store) on some apps, it seems to be random, cause it doesn't always happen on the same app, but it's always placed on the lower side of the phone.
-it installs push notifications with ads
-i believe it shows app ads on google play store (i haven't installed any app in quite a while so it could be google implementing this).
i have tried a lot of apps:
-Avg
-Avira
-Avast
-Malwarebytes
-CM manager (found a stagefright vulnerability and fixed it)
-Stagefright detector (with vulnerable result)
-addons detector
-airpush detector
-trustgo ad detector
-adware
-ad clean & antivirus security
and not even has been able to remove this damn malware, they don't even spot it!
i've also tried looking for all the apps on the phone,searching for apps with all the permissions and here's the list ( i don't know if these are the problem or not):
-Aging test
-agoldFactory test
-Bluetooth
.Bluetooth Share
-Bluetoooth LE
-Common data service
-e_Compass
-Elephone launcher (apparently it's the same as X launcher mysterious)
-LocationEM2
-MTK THERMAL MANAGER
- at least 3 different phone apps, 2 with 4.4 icons and 1 with android 5.0 icon. all have access to everything (is it normal to have 3 apps with the same name but different icons? )
- settings storage
-trusted face
-ygps
i have also cleared the cache of the phone, because i've read on several places that it helps (settings -> storage -> clear cache data) but with no positive result.
i have also tried looking for admin permissions but the only things in there are CM security and android manager (which i suppose is NOT an app but part of the OS).
I have tried looking for hidden files while checking my phone on my pc but there wasn't any nor did i find any weird app NOT installed by me.
i don't know if you have any other advice on what to do, or if you can help me reduce this list of apps so i can find the culprit app.
i'm afraid this is the ghost virus everyone's talking about, it appeared out of nowhere.
i haven't browsed that much. and when i do i always go to trusted sources. apart from the netflix app which i downloaded a few days ago i haven't downloaded anything in like 1 or 2 months and didn't have this problem until a few days ago. Right after my girlfriend's phone (same model as mine) got the same problem.
We both had the "install from untrusted sources" option on because i was testing an app i am making, but i doubt that's the problem since we only activated it whenever i tried to install the app on the phone (like twice in a week).
she has sent me pictures or files through mail, whatsapp or telegram only and it's the only link between our phones, besides being under the same wifi connection, of course.
thanks in advance for the help!
This is a known issue with these types of devices. They have these ads built into the system apks.
Hi !
Thanks for that solutions !
I have a question : where could I find malwarebytes for android ?
Best regard.
Adware and infected htc desire 526 g plus
Guys I am in a pickle! :silly:
I want to wipe my HTC desire 526 plus clean of malware that is causing it to download unwanted apps without consent. The malware seems capable of modifying the inherent permissions and bypassing all security features.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
It can gain permission to automatically start wifi, gain pemission to install 'Unknown Apps' and sends location and data with impunity. The ads are everywhere.:crying:
I have tried stock backup but it still reinstalls all the malware and the same cycle begins again. What I want is a freash stock rom/nand backup for this menace. Surprisingly I still cant find one link on the world wide web. Please Help me find it.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
alokmey3 said:
Guys I am in a pickle! :silly:
I want to wipe my HTC desire 526 plus clean of malware that is causing it to download unwanted apps without consent. The malware seems capable of modifying the inherent permissions and bypassing all security features.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
It can gain permission to automatically start wifi, gain pemission to install 'Unknown Apps' and sends location and data with impunity. The ads are everywhere.:crying:
I have tried stock backup but it still reinstalls all the malware and the same cycle begins again. What I want is a freash stock rom/nand backup for this menace. Surprisingly I still cant find one link on the world wide web. Please Help me find it.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
Click to expand...
Click to collapse
Kingo root is the reason you are in this jam as it is. I don't think HTC ever released anything for this device so your best bet is to contact HTC.
ENERGYSER400 MTK 6572 virus help android 4.4.2
Bonjour, hy
For me it's exactly the same on my phone.... i have the snowfoxer folder with a lot of malicious apk on it and i don't know how to delete or erase the virus .... without wifi and google play ..... how i can flash the firmwire please
!
philjps said:
Bonjour, hy
For me it's exactly the same on my phone.... i have the snowfoxer folder with a lot of malicious apk on it and i don't know how to delete or erase the virus .... without wifi and google play ..... how i can flash the firmwire please
!
Click to expand...
Click to collapse
Find the forum that supports your device
model/carrier and post there. You'll likely find your answers there. If not someone will help you.
HTC desire 526G+ bricked
zelendel said:
Kingo root is the reason you are in this jam as it is. I don't think HTC ever released anything for this device so your best bet is to contact HTC.
Click to expand...
Click to collapse
I have deleted my priv-app folder and now I am stuck in boot loop, or just the HTC logo.
cant boot into recovery or bootloader (I tried). Tell me if you know something

[Q] iRoot(Vroot) detected as an Android.Spy Virus?

Hello everyone! I am not new here,I have an old account "JBmorris", however i dont use it anymore.
Anyway, does anyone know iRoot(formerly Vroot)? If so. I'm going to need your help.
I am a person who almost often scans files before running them. So yesterday, I was download iRoot, and I scanned it, and it was detected as A virus called "Android:Agent-GYN [PUP]" (avast) and "Android/Spy.Agent.Y.Gen" (Avira).
It was scanned on virustotal.
I am afraid of hackers spying me.. can you clarify me? thanks.
JBmorris289 said:
Hello everyone! I am not new here,I have an old account "JBmorris", however i dont use it anymore.
Anyway, does anyone know iRoot(formerly Vroot)? If so. I'm going to need your help.
I am a person who almost often scans files before running them. So yesterday, I was download iRoot, and I scanned it, and it was detected as A virus called "Android:Agent-GYN [PUP]" (avast) and "Android/Spy.Agent.Y.Gen" (Avira).
It was scanned on virustotal.
I am afraid of hackers spying me.. can you clarify me? thanks.
Click to expand...
Click to collapse
As far as i know its safe to use iROOT (formerly VRoot) I used it before my my computer is free of viruses. Many root "exploits" are detected as viruses or PUP. Just disconnet your internet, disable AV for rooting, delete iROOT once done OR add iROOT to your AV's exceptions. BUT you should change the contained superuser app for SuperSU once rooted.
But what about the Android Spy Agent detections?
JBmorris289 said:
But what about the Android Spy Agent detections?
Click to expand...
Click to collapse
As I said, once the phone is rooted install SuperSU. SuperSU will prompt you to uninstall the crappy chinese superuser app and you're done
LS.xD said:
As I said, once the phone is rooted install SuperSU. SuperSU will prompt you to uninstall the crappy chinese superuser app and you're done
Click to expand...
Click to collapse
Ah...okay. Thanks!
I used iRoot/VRoot but my phone got infected with something. After using the root application (which does work) it installed several more apps and I'm getting popups in my browsers and whatsapp. So far I haven't been able to remove it.
Any luck removing this? I tried using iRoot on my Galaxy S5 G900W8 and root failed, but I got a bunch of apps installed. The dam thing is in chinese and I can't read anything..... grr! This thing is sketchy... I'd say IF you're going to try it, do it NOT connected to internet (disable data/wifi) MAYBE then you wont get all these ****ty apps.....
but for me it has not worked thus far...
Happened to me yesterday. It was so painful! This junk installed 2 stubborn trojans in system/priv-app. Impossible to remove even with factory reset. It gains admin privileges, starts downloading crap from the net, fills the display with porn pics etc. Kingroot saved the day in the end! Managed to root my phone and clean the mess. It was a whole day battle.
BTW, credit to Stubborn Trojan Killer as well! It showed me the location, but wasn't able to clean because the phone wasn't really rooted.
Also, Total Commander was the only file manager capable of opening that dir without root.
P.S. First trojan was named "shell" and had version 1.0. The original shell app is higher version. That's how you know which is the good and which is the bad one. The other trojan was names something like xy_1_some digits. You should stop that "shell" crap immediately and disable it. It will be hard, but possible to do. Otherwise you wouldn't be able to do anything.

Are Google TRYING to break rooted phones?

The other night I went to the Google Playstore to find an app' I wanted to try.
I found it but the phone was acting weird.
I did some checking and in Security/admin privileges I found something I'd never seen before.
It was called "Android Digital Management".
I searched around with my file explorer and found nothing.
Hmm?
I then removed the Playstore updates and disabled Play store and it's account manager ...... I always do to save power.
I went back and checked on ADM and it was gone.
My SD Maid app' was complaining about only a partial root as well as some of my other root apps' not working correctly.
Thank God for TWRP recovery.
I had a two week old backup that I installed from recovery and everything is great now.
Has anyone else ran into this?
I am rooted aswell, and when checking the area u stated, i dont have a Android Digital Management, but its called Android Device Manager, same initials, that is checked and Greenify, quick reboot and Wheres my droid are unchecked. What app is your device administrator after what you did??
I believe they are (just my opinion).
It really seems that the once touted "open source" OS is going the way of IOS for "security" reasons. I know this is a supposed to be for my protection but it is a serious curtailing of our ability to do as we please with our device.
Google took the first major step down the slippery slope of a locked OS when THEY decided we don't need an external sd card.
I know they're locking up security exploits but it really seems that soon what we loved about Android will be gone and it willl just be another OIS or Windows phone....
urirx98 said:
I am rooted aswell, and when checking the area u stated, i dont have a Android Digital Management, but its called Android Device Manager, same initials, that is checked and Greenify, quick reboot and Wheres my droid are unchecked. What app is your device administrator after what you did??
Click to expand...
Click to collapse
Ah,that sounds like it.
My bad.
I was so pissed after it happened,I guess I screwed up the name......you got the idea though.
If you uninstall the updates to the Google Play apps',that thing goes away.
I notice when I go to the Playstore that they like to update my app' resulting in phone restarts.
This time the last restart presented a PlayStore screen in a format I hadn't seen before.
That"s when everything went downhill.
Some games are, remember mine rooted note 3 can't even detect the game marvel future fight

How I got malware on my OP6 and how I got rid of it (at least I think so)

So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch (I already have one different working app for that now). Someone suggested a very shady link to download an apk but since I'm desperate and dumb I just downloaded and installed it. However, after installation there was only a "done" button but "open" button was greyed out, there was no new app on app drawer and there was no new app in application list in settings. I started getting worried that I had just installed some bitcoin mining software or another kind of malware.
I got even more worried because if I tapped on the apk again it was asking me if I wanted to UPDATE the app instead of if I wanted to install it so it was already installed and it had permissions to access gps, phone history, and read, modify and delete USB storage.
After a while during the day, my phone started doing random noises from the speakers like audio from ads but without opening any app, then later it started opening random chit on google chrome and that is not even my default browser (my default is samsung browser), it opened those very intrusive ads that tell you you have a virus and you cannot go back you have to close the whole tab or app it also opened some ads with sexual content a few times.
I always thought all free anti-virus app on the play store were completely useless and just bloating apps but I started installing a bunch, most didn't detect absolutely anything after the option "scan all apps" I tried kaspersky, avast, AVG, Norton, etc. then I installed this (it's called "hi security" so not known brand and I thought it was going to be the worse but after opening it was powered by "McAfee" so at least McAfee is known):
https://play.google.com/store/apps/details?id=com.ehawk.antivirus.applock.wifi
And it actually detected some malware after scanning all apps, there was an app with completely blank name on device administrators that I never gave permission to become device administrator as far as I remember, so I unchecked that app from admin and then the antivirus app was able to uninstall it.
After the virus cleaner uninstalled the app I haven't had any more issues with audios or ads opening on chrome. Do you think I'm safe now or could I still have some spyware?
I posted some screenshots showing everything.
I doubt that anyone wants the apk but if a developer wants it for reverse engineering or whatever reason I can post it the the name "MALWARE_do_NOT_install.apk" or something like that
If you are afraid of malware then flashing stock room is the best bet to get rid of it
vwite said:
So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch.
Click to expand...
Click to collapse
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
surface13 said:
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Click to expand...
Click to collapse
good app, that's the one I've been using for a while It has a few issues but overall good
Manivannan9444 said:
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
Click to expand...
Click to collapse
I'm not rooted at the moment, phone has been doing everything I want except HBM but I don't think I'll root just because of that because I also use samsung pay plugin for my gear s3 and don't want to risk it
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
herecomesmaggi said:
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
Click to expand...
Click to collapse
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
vwite said:
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
Click to expand...
Click to collapse
I mentioned Avira nd AVG as antivirus. Malwarebytes is best bro for malware infection. I m using it since 2009 for pc. Every time it does the job.
Also for ur round corner.. I suggest u search for "round R" a app found on xda in 2011 or 12, since then It does it job beautifully.
Regards

Categories

Resources