Game Guardian unsafe? - Security Discussion

I have downloaded Game guardian on its official website after downloading the file I have installed it.. Root Permission pops-up then I grant it but suddenly another one pops-up saying a silent auto installation is blocked and it has the Game Guardian icon still and it ask Root Permission but it isn't named GameGuardian it has random text names and It occurs during between 40% to 60% of installation i cancelled the root permission and it ask me to retry the installation twice but I cancelled it but still after all the Game Guardian works normally even I didn't install the extended files that request to download..I am pretty sure it was also from GameGuardian but idk what it is.. I tried using Cheat Engine apk too and I use it I try to select process and I found out Game Guardian is named Catch_.Me_.If_.You_.Can Wich made me think GameGuardian might be doin a dirty job running in the background I googled Catch Me If You Can and I see a movie about it and it's a movie about fraud and I guess Game Guardian is referring to that movie..Means they might doing fraud/odd things on your device. I tried going to Game Guardian forum but they close the signup or registration and I guess they are avoiding people to ask about it..Game Guardian use to be good but now it's quite suspecious and some antivirus detected it as Trojan. :/

Game Guardian requires root for 2 parts, the first being the app itself, the second (random letters) is the debugging module. The random letters help it to stay hidden from whatever app you're using it to modify.

CATCH_.IF_.YOU_.CAN_ IS A TRACKER
I downloaded and installed GG as well. However somehow I didn't catch that second installation. The one with a random character string as a name. My phone was infected and my data plan emptied.
I would have never noticed, but I went to SU to change permissions on another app and saw the CMIYC thing as having been granted full access permissions... After a failed attempt at a Google search using only the words, I tried agian with the u der scores and periods. That's when I find the description for CMIYC. It's a TRACKER/spyware often used by parents and or jealous spouses to spy on people. It will allow the spying party to access calls,texts,contacts, GPS location, web data, AND EVEN CAMERA AND MIC functions. I had to perform a factory reset to be rid of that junk.
I hope people see this article and therefore know better than o download that spy app.......
I figured I was at fault, because I downloaded GG from a third party site that hosts pirated apps etc. I therefore hadn't given it a second this ght untill coming across this post...

Thread closed.
Discussion of warez is strictly prohibited on XDA.

Related

Mobage app permissions?

Not sure if any of you ever heard of ngmoco's Plus+ game social network on iPhone, well they were bought out by a japanese company who owns "Mobage", a mobile game network in Japan.. Now they're releasing games on Android, but every single one of their apps has every permission in the book, & they give no explanation for any of them.
Now I'd normally stay away, but they have one game I loved on iOS, Pocket Frogs, here's a link; http://0.mk/72868 check out the permissions tabs.
Is it safe? Is there any way to block all permissions in an app or disable them??
Thanks.
TL;DR, remove app permissions?
I clicked on it and the permissions they have in there now seem normal actually. Except for this one:
Allows an application to read all of the contact (address) data stored on your device. Malicious applications can use this to send your data to other people.
It looks like they might have removed quite a bit of the permission requests because in the reviews people were saying it requests "super user access" and stuff like that but when I read the permissions, that one isn't listed anymore.
Yeah, that's the one that bothered me the most, but hardly any of those are required for the app to run, it's just unnecessary & annoying for a game to have that many permissions
Is there any way to remove its permission to read contact data?
That app also requested SU access on my phone. I denied it and then immediately removed the app. There is no reason that game should require SU access.
There is a handy linux tool to list permissions that an APK uses via commandline called scanperms. I use it to check out what an app uses before installing.
URL is hxxp://tinyurl.com/cvo6dqw

Official: Some Apps contain now Malware

Hey there,
I was surfing through the android market days ago and found some interesting news, non pleasant ones i may say.
I took the applications Granny Smith and Big Great War Game to give it a go, installed them, and failed to check the onscreen advice, so install was successfull.
The applications were working properly, tested it, but i noticed my notification bar had an extra app going, ads mostly, regarding other available purchases. Yes i know some apps do this on a regular basics but this isn't the case. As one of the apps referred above asks for SU privileges, (both are games), and when i tried to uninstall them, i get always "Uninstallation not Successfull". Also, it appears two install apps for each one, example: Granny (240kb) and Granny (14mb). Either way you simply cannot uninstall them.
I then tried the root explorer to hunt these b*astards down manually, after a quick search, i did managed to delete every trace. But though it was done properly, the damn icon still appears on my apps list, and with various uninstall tools available, simply gives you error after error.
Down side is, so far you may think this is harmless, after all its publicity and there are a ton of apps doing the same. Right?
Well, not quite. You see, the apps run with the system constantly, with 3G or WIFI or not, not appearing on any task killer, and thus completely draining your battery in 1hr tops.
I would like to know if anyone encountered any issue relevant or similar to this case, as is critical to at least inform the customer the malware capabilities of such apps.
If needed or for experiment use, you can ask me for the apk files, i saved copies of it.
Cheers.

[Q] How can I test an .apk to see if it's "safe" to install?

Hi,
Sometimes an app (.apk) is either simply not available through Google's store, or it might say "not compatible with your device", etc. There can be various reasons why a person might download a .apk from somewhere other than a "trusted" source.
If this was a file for my PC I could test it in a "sandbox", and I could scan it with both Microsoft Security Essentials and Malware Bytes Antimalware.
On my Android phone(s) I'm not aware of something like the "sandbox" option, and I don't really want to run an "antivirus" program on my phone. Is there an easy way to scan .apk files on the PC to see if they are rogue apps, might send SMS, "phone home", or otherwise mess with other applications or the system software installed on my phone?
Lets give another example: say I thought 15 minutes was not long enough to evaluate a relatively expensive Android game (it certainly isn't!) and I want to test it out first. Let's assume my only option in that case might be an illegally downloaded copy from unknown sources. Of course, we shouldn't do that. But if we did, how could we know if the file is safe and not risk installing some Chinese spyware?
About Android AV programs: anybody know how effective they are? Do some defend against "trojans" - I would think these days trojans are 99% of problems and viruses mostly a relic of the past?
My biggest concern is actually just unwanted crap that runs in the background which eats up battery, makes my phone warm (which I hate), or, perhaps even sends SMS message [this would be even worse because I don't have a text message plan].
EDIT: I see web pages with tiles like "new study finds Android antivirus apps not effective" and articles like this one: http://www.zdnet.com/blog/hardware/...bouncer-does-it-offer-enough-protection/17981
Do we have an easy way to boot Galaxy S3 off of "external" SDCARD instead of internal memory?
Search play store for avast antivirus, completely free, updates daily and works really well (firewall. Anti theft. And many more Features
sony xperia ray ics 4.0.4
stock rom unrooted
I found this website, maybe it can help someone.
h t t p://scan.netqin.com/en/
Maybe someone can post another one...
an easy way to check for safe apk
The easiest way to check for safe apk is to have one gmail account and another "whatever" email account. Then just send the apk from the gmail one to the second account, gmail always find viruses in any apk and stop the process to join the file (virus alert). Bad point is you are limited with the size of the file you wanna send.
Nowadays, even pc antiviruses can detect viruses in apks. I would rather not burden my phone with any android antivirus,since they are literally battery hogs.
sent using my HTC One S
Go here and upload the APK
http://anubis.iseclab.org/
Anubis is a service for analyzing malware.
Submit your Windows executable or Android APK and receive an analysis report telling you what it does. Alternatively, submit a suspicious URL and receive a report that shows you all the activities of the Internet Explorer process when visiting this URL.
Andrubis executes Android apps in a sandbox and provides a detailed report on their behavior, including file access, network access, crypto operations, dynamic code loading and information leaks. In addition to the dynamic analysis in the sandbox, Andrubis also performs static analysis, yielding information on e.g. the app's activities, services, required external libraries and actually required permissions.
Found a good one too
apkscan.nviso.be - give it a try. Drag and drop - wait for the upload - than click SCAN . Wait for a few minutes. That`s all. Unlike ANUBIS it has a resolution at the end of the analysis . Usually helpful.
You can also email the file to [email protected] and it will email the report back in about ten minutes. Virustotal can display some interesting info, for example it said that Lucky Patcher is a "Potentially Infected Hosts File (v)", as reported by VIPRE and AVware.
Virustotal also has an official android app.
The Netqin scanner is also an android mobile app.
Late answer, sure, but I think ClamAV is what you want. You also want its bytecode signature file, and to speed things up, you only want that single file (speeds up things quite a bit).
It is the only offline apk scanner i know of, and as for its efficiency i cannot say, but it seems like it is what you are asking for.
An alternative would be to install something like BlueStacks and remap your "Windows shared folder" (through registry) to the folder you have your apk files in, and then run BitDefender on it. BD is by far the most pernickety AV app out there for Android.
I'll have to check out bitdefender (it's also included on virustotal.com)
apkscan.nviso.be seems to be pretty good at analyzing files for suspicious activity, and it also uploads the file to virustotal for you. Then you can copy the sha256 hash into the virustotal's search, to get all the gory details.
anubis.iseclab.org limits files to 8 megabytes.
Another way to avoid malware is:
when installing an update to an already-installed version of an application, it will 99% of the time prompt you to update an existing app. There's been rare instances where some apps do use a new digital signature (for example when spotify had a big security hole, and for awhile there were two apps by spotify in the app store).
One other way to tell, as a final check when launching the apk for installation on the phone: the icon will not have the right icon. I've installed apps before that I thought came from a trusted source, but the icon was not right. In fact, I was considering not posting this publically, so the "bad dudes" would not update their methods.
Another tool I found:
http://andrototal.org/
Although it might be a duplicate of virustotal.
nintendo1889 said:
Another tool I found:
http://andrototal.org/
Although it might be a duplicate of virustotal.
Click to expand...
Click to collapse
I just tried out this site. To me, it appears to be the most thorough virus testing site that I have seen. It takes some time for it to complete the scans. mainly because it scans the file with about 7 or 8 different scanning engines. Just just have to keep refreshing the page every few minutes to see if the results have updated.
I will be using this one as my go to site for apk scanning.
Just install it on the default emulator in the Android SDK
You can also install your apps on other emulator live bluestacks(best for games), jar of beans(best for rooted app) and windroy(the lightest)
Hit thanks if this helps
nintendo1889 said:
I'll have to check out bitdefender ...
Click to expand...
Click to collapse
Your signature photo ... awesome ... Bad Dudes
By using GDATA security , When you want to install an app the GDATA will scan it befor installing
Sent from my LG-D855 using Tapatalk
Use google scanning service VirusTotal to scan any app, secondly always use secure source. There are many well reputed apk sites but I personally use apklink.com , on this site required apk file is just a click away and its quite easy as well...
be safe & secure
This threads out of date, but it has me thinking I want to use something as mentioned in several replies to OP.
Are there any sites, or apps that can warn me if an .apk (for example) has malware etc.?
Thanks in advance for any help, including a link to another discussion that may have my answer
denise1952 said:
This threads out of date, but it has me thinking I want to use something as mentioned in several replies to OP.
Are there any sites, or apps that can warn me if an .apk (for example) has malware etc.?
Thanks in advance for any help, including a link to another discussion that may have my answer
Click to expand...
Click to collapse
Malwarebytes can detect malware.
Sent from my LGL84VL using Tapatalk
I tried this site and I like it because it goes into a lot of detail after analyzing and sends me a report in email. It was mentioned, and it is still available to use: https://apkscan.nviso.be/
Thank you for the heads up on MB, I use that on my PC and works great
You can use virustotal.

Clash of clans robot (bot) android

Hey guys I'm glad to share you a CLASH OF CLANS BOT
►►here's the direct apk link for those who have trouble accessing the site:
DIRECT APK LINK Introducing: COC ROBOT FOR ANDROID!
NOTE: PHONE MUST BE ROOTED
yes you read it right, this is for ANDROID. A great alternative for the CoC bot for BLUESTACKS.
→FEATURES:
✓AUTO COLLECT RESOURCES
✓AUTO DONATE TROOPS
✓AUTO TRAIN TROOPS
✓AUTO SEARCH ENEMY
✓AUTO BATTLE!!!
►First go to: [Moderator edit: Referral link removed]
►then "Tutorial For Android Mobile/Pad"
►Then click the "DummySprite" Link. That will redirect you into a download page, download the THIRD ONE
►after that, install it normally.
►Then open the app, the setup will take a few minutes, don't worry it's for the first run only.
►When setup finishes, you will see a Clash of Clans Bot there, go install it.
►run it after installing, it will ask for you to register, go register. and if you don't mind, use my invite code
→INVITE CODE: 61535
→When you register under my code, you will receive an instant 50 BEANS which is the virtual currency of the app and I, who referred this to you, will receive 20 beans.
→The only CON of this app is, it is not free, every account is entitled only TWO HOURS of usage.
→But here is a trick! Go to Settings>Manage Applications> DummySprite > Clear data. After clearing data, you can register another account again! If you don't do this trick, you can't create another account because of the limitations.
Here's my invite code again, enter this if you like
→INVITE CODE: 61535
FOR ALL MEMBER THIS APP IS !100 %SAFE AND NEVER GET BANNED FROM COC I USE IT FOR 2MONTH AND NOTHING HAPPENED
I cleared my data uninstalled and reinstalled apk but i cant create another account, am i the unic one?
problem with the programme
I cleared the data, unistalled it, used a vpn but i still can't create a new account!
Has this been proven safe?
Auto search enemy and auto battle? So with this app you can download and never play clash of clans...
Yeah, call me skeptical of downloading this from some random Chinese site. I'd rather just play the game.
I can almost guarantee this to be fake and get your account banned on COC. anyone have any proof of it working?
memekmek said:
I can almost guarantee this to be fake and get your account banned on COC. anyone have any proof of it working?
Click to expand...
Click to collapse
In a(trusted) german forum where I'm sometimes they say it's safe but I didn't test it by myself
This app is !100 %safe and never get banned from coc
.apk might not be safe aswell, I'd skipp this and just enjoy the game by playing it yourself.
Sent from my NX507J using XDA Free mobile app
30 mins
why mins expire at 30mins

How I got malware on my OP6 and how I got rid of it (at least I think so)

So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch (I already have one different working app for that now). Someone suggested a very shady link to download an apk but since I'm desperate and dumb I just downloaded and installed it. However, after installation there was only a "done" button but "open" button was greyed out, there was no new app on app drawer and there was no new app in application list in settings. I started getting worried that I had just installed some bitcoin mining software or another kind of malware.
I got even more worried because if I tapped on the apk again it was asking me if I wanted to UPDATE the app instead of if I wanted to install it so it was already installed and it had permissions to access gps, phone history, and read, modify and delete USB storage.
After a while during the day, my phone started doing random noises from the speakers like audio from ads but without opening any app, then later it started opening random chit on google chrome and that is not even my default browser (my default is samsung browser), it opened those very intrusive ads that tell you you have a virus and you cannot go back you have to close the whole tab or app it also opened some ads with sexual content a few times.
I always thought all free anti-virus app on the play store were completely useless and just bloating apps but I started installing a bunch, most didn't detect absolutely anything after the option "scan all apps" I tried kaspersky, avast, AVG, Norton, etc. then I installed this (it's called "hi security" so not known brand and I thought it was going to be the worse but after opening it was powered by "McAfee" so at least McAfee is known):
https://play.google.com/store/apps/details?id=com.ehawk.antivirus.applock.wifi
And it actually detected some malware after scanning all apps, there was an app with completely blank name on device administrators that I never gave permission to become device administrator as far as I remember, so I unchecked that app from admin and then the antivirus app was able to uninstall it.
After the virus cleaner uninstalled the app I haven't had any more issues with audios or ads opening on chrome. Do you think I'm safe now or could I still have some spyware?
I posted some screenshots showing everything.
I doubt that anyone wants the apk but if a developer wants it for reverse engineering or whatever reason I can post it the the name "MALWARE_do_NOT_install.apk" or something like that
If you are afraid of malware then flashing stock room is the best bet to get rid of it
vwite said:
So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch.
Click to expand...
Click to collapse
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
surface13 said:
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Click to expand...
Click to collapse
good app, that's the one I've been using for a while It has a few issues but overall good
Manivannan9444 said:
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
Click to expand...
Click to collapse
I'm not rooted at the moment, phone has been doing everything I want except HBM but I don't think I'll root just because of that because I also use samsung pay plugin for my gear s3 and don't want to risk it
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
herecomesmaggi said:
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
Click to expand...
Click to collapse
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
vwite said:
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
Click to expand...
Click to collapse
I mentioned Avira nd AVG as antivirus. Malwarebytes is best bro for malware infection. I m using it since 2009 for pc. Every time it does the job.
Also for ur round corner.. I suggest u search for "round R" a app found on xda in 2011 or 12, since then It does it job beautifully.
Regards

Categories

Resources