[Completed] I need help to remove andriod/trojan.spy.agent.ytb from my phone - XDA Assist

I have an issue with my one click xmusic pro 2 (Chinese) phone, i have this malware that i cannot remove (andriod/trojan.spy.agent.ytb) full path is system/priv-apps/youtube/youtube.apk
It looks like its affecting the youtube, i cannot either update the app (its really old version) or even uninstall. i tried to remove it using malware but it cannot be deleted, i downloaded avg but it didnt even detect it was even an a problem
i tried Ahnlab V3 it detected the issue but it said (unremovable)
how can i remove it
Model xmusic 2 pro
Andriod : 6.0
Andriod security patch : sept 5 2016
Baseband version : oneclick xmusic 2 pro 20161101
Kernel 3.18.19

Hi !
This malware apps are so bad ... the only way to fully get rid of them is by performing a factory reset and also avoid the installation of suspect applications
Delete after saving your data from your phone too
A flash to stock should do the trick as well , if available , I couldn`t find anything though here on xda
Good luck !

Related

[Q] Root Issue : Phone reboots during root access.

DEVICE : SAMSUNG GALAXY PRO GT-B7510
Installed firmware : enzag/technology/android/how-to-upgrade-samsung-galaxy-pro-b7510-to-gingerbread/
Rooted by : enzag/technology/android/how-to-root-samsung-galaxy-pro-b7510-gingerbread/
(NEW MEMBER. Restriction in links .. it's h t t p : / / e n z a g . c o m )
My galaxy pro reboots every time when some root applications like busybox installer or avast anti theft has used root access to copy files. The phone reboots automatically after/( when it feels to..) making any further tasks cut off.
(I tried to install Alsa Mixer and had to run the app numerous times before it's installation is complete )
The stock firmware DDKC4 (Froyo) after rooting via Super One-Click root didn't have such an issue.
If any of the devs have any solution, so that i could switch to manual reboot. HELP ME.
vynonline said:
DEVICE : SAMSUNG GALAXY PRO GT-B7510
Installed firmware : enzag/technology/android/how-to-upgrade-samsung-galaxy-pro-b7510-to-gingerbread/
Rooted by : enzag/technology/android/how-to-root-samsung-galaxy-pro-b7510-gingerbread/
(NEW MEMBER. Restriction in links .. it's h t t p : / / e n z a g . c o m )
My galaxy pro reboots every time when some root applications like busybox installer or avast anti theft has used root access to copy files. The phone reboots automatically after/( when it feels to..) making any further tasks cut off.
(I tried to install Alsa Mixer and had to run the app numerous times before it's installation is complete )
The stock firmware DDKC4 (Froyo) after rooting via Super One-Click root didn't have such an issue.
If any of the devs have any solution, so that i could switch to manual reboot. HELP ME.
Click to expand...
Click to collapse
Is this happening only with root apps or with normal apps too?
Daedalus.p1 said:
Is this happening only with root apps or with normal apps too?
Click to expand...
Click to collapse
Root apps which , I believe , makes edit in my ROM files ..
I think the instruction to reboot after such access is coded in the files of flashed zip package. Or is it that all GB Roms does so after root access.
Great Help recieved . Thank you . Atleast tell me why it reboots.
Sent from my GT-B7510 using xda app-developers app
vynonline said:
Great Help recieved . Thank you . Atleast tell me why it reboots.
Sent from my GT-B7510 using xda app-developers app
Click to expand...
Click to collapse
Hi there! I had a similar issue with my B7510. I figured out the issue was with the limited internal storage. When your internal memory fills up, the rooted application doesn't have any free space to write the cache eventually creating panic & forcing your phone to reboot. I cleaned up the stock applications which I wouldn't use much & also moved a couple of allowed applications from my phone memory to the sdcard mem to have some free space generated. This fixed my issue & my phone doesn't reboot anymore while running rooted applications. Hope this helps..
--
Linux Rules...

[Q] App can not open in Rooted mobile

"https://play.google.com/store/apps/details?id=com.pro90d&hl=en"
app name : "How to Stop Stuttering-Trainer" in playstore
my device : Redmi 1s
Rom : miui v5 - JHCMIBH45
App can not open in Rooted phone
pls slove the problem and Link the sloved APK file..................
do not reply "to unroot ur phone"
Possible Problem
I think, i know what could possibly the problem.
Maybe the App is Programmed to Detect a Rooted Device and if it does, then it won't run properly. Like HillClimbRacing..
HillClimbRaceg for example Detects, if your device is rooted. Then it saves the XML-File with your Coins-Number veeeeery Hiddenly.
Try to Disable the Root-Rights for this app with a Android-Dev-Superior App, which can disable root/some rights for some speciefied apps.
ANOTHER POSSIBLE PROBLEM: Android Version
••••• ·Which Android Version do you have?••#•••
If your Version is 4.4.2, then let you know, that 4.4.2 is bogus.:crying:
Android 4.4.2 was horrible to me! Very much bugs. One of them (the „Data-Loss Bug“ in combination with the MTP-Instability) erased 10 GB of Data on my Device. Even the BEST DATA REVOCERY PROGRAM IN THE ENTIRE WORLD, isn't able to do ANYTHING in combination with MTP:crying: Hrorible! :crying::crying:
u can crack the APK file
crack the APK file
or give patch file for slove the problem
solution:
http://forum.xda-developers.com/xposed/modules/mod-rootcloak-completely-hide-root-t2574647

Multiple malware apps preinstalled on Infocus phone?

I bought Infocus M2 phone from Tinydeal. Infocus is not so well known brand and I am bit suspicious about chinese phones, I have used Lenovo phone quite some time now but I replaced its rom in the beginning, altough how can I be sure that the rom I have been using is totally pure? Well, I can't but I have used bank applications etc. without problems.
However, I first checked this Infocus phone with Avast which reported one PUP -rated app, related to updating the phones firmware. However, after running Malwarebytes it reports three malicious apps and none of them is the one Avast reported.
Apps cannot be uninstalled since this phone is not rooted and those are system apps. Should I stop using this phone? Nice device but...
I managed to root this phone and I removed those three apps, dunno if this phone is now secure to use.
how to root M2
Diexi said:
I managed to root this phone and I removed those three apps, dunno if this phone is now secure to use.
Click to expand...
Click to collapse
Can you share details or URL on how you rooted this phone?
I scanned mine with Malwarebytes (0 found). I'd still be interested in rooting it, though.
I bought my M2 in Taiwan through official channels, where did you get yours?
spawnflagger said:
Can you share details or URL on how you rooted this phone?
I scanned mine with Malwarebytes (0 found). I'd still be interested in rooting it, though.
I bought my M2 in Taiwan through official channels, where did you get yours?
Click to expand...
Click to collapse
I bought mine from Tinydeal. I cannot share links because I am new user, but google infocus m2 101 and check that facebook page, Taiwan rom factory.
Basically you boot the phone with alternative recovery and then install root package, there was confusion after you leave the recovery when it asks should root permission be fixed, I tried this whole process more than once I recall answering differently to that last question, can't remember which one was correct since it asks that even when you donn't try to flash that supersu zip package
Contacted Tinydeal and asked about the malware apps. The phone works and I have now dared to use it after removing those apps, no problems so far.
Tinydeal just said that those are system apps installed by manufacturer and that I shouldn't worry, but clearly all M2 phones do not have them so I doubt InFocus did install them. Spawnflagger, does your rom have finnish (Suomi) language in it? If not, I might have unofficial rom since finnish is very often absent from phones bought from China and many times only added by seller who replaces the rom.
Tinydeal so far does not admit installing malware.
Diexi said:
Contacted Tinydeal and asked about the malware apps. The phone works and I have now dared to use it after removing those apps, no problems so far.
Tinydeal just said that those are system apps installed by manufacturer and that I shouldn't worry, but clearly all M2 phones do not have them so I doubt InFocus did install them. Spawnflagger, does your rom have finnish (Suomi) language in it? If not, I might have unofficial rom since finnish is very often absent from phones bought from China and many times only added by seller who replaces the rom.
Tinydeal so far does not admit installing malware.
Click to expand...
Click to collapse
It's very possible that TinyDeal didn't do anything at all to the phone, just wherever they got the phone from, had a modded ROM. Another possibility is that an early version of the ROM had some code that scanners found as malware (false positive), and newer updated ROMs removed it. Did your phone do any OTA updates? Mine had an update as soon as I put it on WiFi, which I installed. Then after I setup Google account, there were several Google Play updates to Google Play Services, Gmail, Maps, etc. Only pointing out that it seems to ship from the factory with an outdated image, and maybe this is what modders added the Finnish language support to. Mine doesn't have Finnish though. (after updates, mine is Android 4.4.2, build # 00WW_2_260)
From infocusphones.com, seems they are targeting China, Taiwan, and India. InFocus is an American company, but all their phones are made by a Taiwanese company (but probably manufacture in China). I've used InFocus projectors before, didn't know they even had phones until a few weeks ago.
The phone did suggest updates, but because my past experience is that updating a China product via automatic updates might result in an OS without Finnish language and/or bunch of Chinese apps etc. My rom version is with "240" end so it is older, Needrom.com has "260" rom available but it says limited multilanguage and no mention of "FI". Also Avast and couple other virus scanners reported "update.apk" to be malware altough since Virustotal.com scans by using 57 scanners and only couple of them reported malware that might have been false positive.. however, I have removed update.apk. Those three apps mentioned were reported by several scanners of those 57 so I kinda believe those really were malware, also if the Twitter app really was genuine then why couldn't it be updated from Google Play? Also when looking for Cleanmaster from Google Play it showed that the apps wasn't even installed so I think there really was something about those three apk-files.
Diexi said:
The phone did suggest updates, but because my past experience is that updating a China product via automatic updates might result in an OS without Finnish language and/or bunch of Chinese apps etc. My rom version is with "240" end so it is older, Needrom.com has "260" rom available but it says limited multilanguage and no mention of "FI". Also Avast and couple other virus scanners reported "update.apk" to be malware altough since Virustotal.com scans by using 57 scanners and only couple of them reported malware that might have been false positive.. however, I have removed update.apk. Those three apps mentioned were reported by several scanners of those 57 so I kinda believe those really were malware, also if the Twitter app really was genuine then why couldn't it be updated from Google Play? Also when looking for Cleanmaster from Google Play it showed that the apps wasn't even installed so I think there really was something about those three apk-files.
Click to expand...
Click to collapse
There's a ROM translation app (video on youtube) that will use Bing Translate to recompile all the APKs, removing or adding languages desired. (I haven't tried it). It might be possible to get the stock 260 ROM and add Finnish to it.
Also, another XDA thread mentioned that the Cyanogen mod supports pretty much all languages... The officially supported devices wiki page doesn't list the M2 yet, but perhaps check back in future:
I also have malware on a new Infocus phone, its model M310, purchased from Banggood.com. The malware causes the internet to redirect randomly to coo123 or Qoocc web sites,this is both with the stock browser and firefox. Also a window comes up randomly with a sexy picture,this can happen anytime,even when brownser not open. I have tried a factory reset but didnt help.
After running various virus scans it seemed the preinstalled facebook app was suspect along with smsreg app. I managed to delete these, but the problem still remains. All virus scans are now clear (malwarebyes,eset,avg,360 security). So i am at a loss what to do. There is a newer rom on needrom, but it seems this may not have gapps or rooted and i wonder if this will be infected also. Would welcome any other suggestions?
After obtaining root access I deleted those three infected apps and then went trough every app I had on the phone and deleted everything I concluded not to belong into stock Android. I had one strange app named lyc_1.apk and since Google did not find anything about it I deleted it and so on. Stock browser had baidu mentioned in its name so I deleted that also and opted to run Chrome from Google Play.
I'm not experienced with network stuff, but have you looked at your hosts-file, how does it look? You can use Root -browser and edit it, atleast if you have root permissions.
My phone displayed an ad on the notification bar which had same kind of icon like Update.apk, after deleting Update.apk it never happened again, but also I cannot update the phone trough Settings. Not big loss probably since updating may cause problems...
After these things I have used phone without problems.
I updated the phone with original firmware from infocusphone.com.
I would happily provide the links for more convenience but I was restricted from the system because I am new.
Save the zip file on the sd-card.
To install the new firmware put the phone into recovery:
) Switch off the phone
) attach phone to charger
)press and hold Volume up + power button until you get into recovery
) choose install zip from the menu
With the new firmware there is a app Dr. Safety (trend micro) that reports no malware. Using eset the app meiyanxiangji is reported as malware. I uninstalled it using settings-> apps->uninstall
I am quite happy with the Phone.
I connected the phone to my PC today I noticed that there are multiple files in the root internal storage, they are labeled like following:
as643a27-b490-4x0a-49f6-c66fdbecb5e0
Anyone have idea what these are? They are all 36 bytes and seem to contain same text as they are named.
Diexi said:
I bought Infocus M2 phone from Tinydeal. Infocus is not so well known brand and I am bit suspicious about chinese phones, I have used Lenovo phone quite some time now but I replaced its rom in the beginning, altough how can I be sure that the rom I have been using is totally pure? Well, I can't but I have used bank applications etc. without problems.
However, I first checked this Infocus phone with Avast which reported one PUP -rated app, related to updating the phones firmware. However, after running Malwarebytes it reports three malicious apps and none of them is the one Avast reported.
.
Click to expand...
Click to collapse
I bought the same phone from dx.com (DealeXtreme) and had the same 3 apps show up with MalwareBytes.
I ended up getting the code from infocusphone.com. I can't post a link since I haven't posted enough.
It took a bit of trial and error to find the right file. The one I loaded was LSO-2260-0-00WW-A02-update.zip. If you copy it to an SD card and load it as described earlier in this thread, you should be set.
Malwarebytes no longer reports anything (neither does Avast). Will be looking get root next....
Diexi said:
I bought mine from Tinydeal. I cannot share links because I am new user, but google infocus m2 101 and check that facebook page, Taiwan rom factory.
Basically you boot the phone with alternative recovery and then install root package, there was confusion after you leave the recovery when it asks should root permission be fixed, I tried this whole process more than once I recall answering differently to that last question, can't remember which one was correct since it asks that even when you donn't try to flash that supersu zip package
Click to expand...
Click to collapse
I downloaded the alternate recovery from Taiwan 101. It is a rar file and asks for a password when I try to extract it. Do you know the password?
EDIT: found it on another Facebook page; password is taiwan101
EDIT: Rooted successfully ... thanks Diexi
Thanks
Getting Error while rooting
Getting Error reboot failed: -1
Plz suggest i am doing as it is said in the Taiwan rom Factory
---------- Post added at 10:05 PM ---------- Previous post was at 10:00 PM ----------
Exclamation Getting Error while rooting
Getting Error reboot failed: -1
Plz suggest i am doing as it is said in the Taiwan rom Factory
Diexi said:
I bought Infocus M2 phone from Tinydeal. Infocus is not so well known brand and I am bit suspicious about chinese phones, I have used Lenovo phone quite some time now but I replaced its rom in the beginning, altough how can I be sure that the rom I have been using is totally pure? Well, I can't but I have used bank applications etc. without problems.
However, I first checked this Infocus phone with Avast which reported one PUP -rated app, related to updating the phones firmware. However, after running Malwarebytes it reports three malicious apps and none of them is the one Avast reported.
Apps cannot be uninstalled since this phone is not rooted and those are system apps. Should I stop using this phone? Nice device but...
Click to expand...
Click to collapse
no joke, scan that thing with multiple anti viruses from the market. if they support root , there better because they can do a complete scan. also try completely swiping the SD card clean
A big mistake was to delete the possible malware, because now we have only rumors but nothing we can definitely say about. So, you learned now that next time just backup the infected stuff or directly scan it against known antivirus sites (or attach here). But without anything it's impossible to say what could be the risk now.
As written down a fresh and clean install would be help now to make sure no leftovers are left on the system.
Looking for rooting method for InFocus M2 and custom ROM
Sent from my XT1033 using XDA Free mobile app
Rom Devlopers
hi all good day
any one try to deodex this rom and any custom rom works for this device stop all these malware nonsense give me stable rom whats the version specific any one find custom boot theese questions help us to make new best rom please make it possible
I received InFocus M2 today.. I don't believe in this malware thing...
Sent from my XT1033 using XDA Free mobile app

MediaTek T906 Tablet(Made in China!!)

Good Evening All(or whatever time it may be there),
I'm new to XDA and Rooting, etc. etc. I purchased a MediaTek T906 Tablet(Made in China!!). After I received it and charged it, the first thing noticed it wasn't allowing some apps to download and install. Keep in mind this is suppose to be Android 9 and 512Gig 8Gig ram device.
Below is what MTK Droid Tool v2.5.3 says about it(and yes I Root it, am fully aware that it voids warranty):
Hardware : MT6582 (MT6797 is Fake!)
Model : T906
Build number : T906_vEN52S2_TB_20191205
Build date UTC : 20191205-085910
Android v : 9.0
Baseband v: MOLY.WR8.W1315.MD.WG.MP.V54, 2018/01/02 15:01
Kernel v : 3.4.67 ([email protected]) (gcc version 4.7 (GCC) ) #1 SMP Thu Dec 5 16:56:01 CST 2019
Too root(successfully)it I used KingoRoot and Got SuperUser Status/Privileges. I did a lot of reading on root and other root apps(to be used in conjunction with). Long story short, I'm trying to get a specific app to download to this tablet and am not sure how to go about it. I did the dump data/cache thing in Play Store and Google Play Services and reboot. Didn't work. Did all the steps before I root the device. I even used Root Essentials Editor to mod the device name and manufacturer, that didn't work. And the time zone is set to right time zone. So, I'm making this post asking for some guidance and/or help on what I can do? Any and all help is greatly appreciated!!
I am in the same situation as the previous poster with the same Version, Kernel, Baseband, Build and my experience with this should be considered at a beginner's level. In researching this and came across a post that indicated that the tablet is not actually Android 9.0 but suspected to be KitKat. Please, if anyone knows how I could get this setup with Android Oreo, I would be grateful.
Hi guys,
just got the tablet too, it also seems to me it has this config:
- MT6582
- 1GB RAM
- 16GB Storage
- 1280 * 800, 7.19" display
- Android 4.4
Not sure what options there are, but I hope there are some newer Android builds that would work on this?
I'm following
So far....
I have been successful in rooting my device and hope to find a ROM that will move it up to a level that will allow KODI -Leia to be installed. I will let you know what my findings are. I'm just afraid as I don't want to brick the device.
Hi guys . Same problem. But. Works to me. Go in accounts remove account. then try loggin again.
uncheck all boxes. Unynchronize the two options in the account. Agenda and contacts. Deselect the check options. If it doesn't work restart and turn off the wifi. then rewire. Do it again. good luck
A brother in distress
I've got the exact same issue with my T906 Mediatek. I downloaded the Root app (Thanks!) and kept trying to get the things to load and run. I'm specifically having the issue with Alexa app. I can find it but I get that the app isn't compatible. It runs on my Samsung phone that's running A9.0. It keeps saying the app is already installed, yet it isn't . I went into the Play Store and Play Services apps and deleted the updates and caches as suggested on YouTube. No difference. I'm sort of at a "What Now!?" POINT.
Any help would be appreciated.
Be safe out there and for goodness sake, wear your masks until this crap is beat.
The REAL OldGeezer
you can't upgrade generic android devices until version 9. Android 9 seperates the drivers with the treble abstraction layer allowing you keep the drivers and upgrade the rest. The T906 has android 5.11. If you run CM lite scan you will see a huge Opera beta file that is always 3 times your storage. This is how they fake the RAM and ROM sizes. If you take off the back and look at the board you will ussually see printed on the board 1GB ram 16GB rom. They have also faked the CPU by using the ROM for the upspec version with better camera, screen resolution and CPU which uses the same drivers. Thus these are also falsely reported. Sadly Google no longer supports android 5 for things like Google sheets so your apps will soon stop upgrading. I love this machine because the screen size makes it cheap for 50 USD
Help to get ROM image to restore same model
I have the same model but when trying to get root access managed to brick it. I have got SP Flash working and managed to get some T906 firmware on it so I get the Mediatek logo and battery charging symbol on screen however the boot options i.e. Fastboot etc just gives an error message when selecting any of them.
I've got a development background but new to Android and scatter files but is it possible for anyone on this thread with the exact same model to help get back to a working system? I assume there is a way to back it all up using SP Flash ?
hi everyone are in the same problem boot error !!!
how to solve it I have tried in all ways but I find myself as soon as I turn it on boot error !!!! you can not even go into recovery?
Help!!!
These manufacturers need to be found and dealt with cause they are robbing customers. They are giving fake specifications. They need to be sued asap.
I got a Mediatek tablet and try put it in recovery mode and now I got black screen with blue bar with SIM and Chinese Characters. Any way to fix it
Hali! Mi lehet a probléma, hogy nem lehet rá filmet másolni számítógépről? Össze van kötve a géppel, megjelenik a fájlátvitel, és a gépen is egy belső tárhely, és az sd kártya, de amikor át akarom húzni a filmet, nem tud semmit se csinálni.
A Fordító így fordította,
Hali! Mi lehet a probléma, hogy nem lehet filmet másolni a számítógépről arra?
Hello guys.
I have a different problem with my T906. It works fine and it is fast and reliable but I had problems downloading apps from the Google Play Store. When I checked it said that the Device is not certified under the Play Protect Certification. I remembered that it came without the Google Play app and I installed from another APK store (apkmirror.com) and it installed without issues. I've tried to download another Google Play app but can't find the correct match for my version and OS (64-bit - Android 8.1).
Any help will be truly appreciated.
I've just created a dump of this tablet with flash tool, maybe you can try to revive yours
T906_191205_ForFlashtoolFromReadBack_221023-012402
MediaFire is a simple to use free service that lets you put all your photos, documents, music, and video in a single place so you can access them anywhere and share them everywhere.
www.mediafire.com
Btw I'd welcome any kind of rom that would make this device more usable

download & format all on sp flash, missing apps

So i tried rooting my huawei y5 prime 2018 and then i got a red warning on boot (awhile ago) so the only thing that fixed it was to use the download & format all option through spflash, Now my phone there is no keyboard, and many other apps are missing (like files app), plus imei, mac address, serial code is gone
so is there possible ways to fix it and also get latest update from huawei?
ty

Categories

Resources