Help me to eliminate this malware. - General Questions and Answers

Hello, everyone. A few months ago a relative received a brandless Android 4.4.2 smartphone as a present for suscribing to a journal. Once he started using it he began noticing that strange apps would install alone in the phone, and once in a few days the phone would start behaving weirdly (making calls to his contacts, opening apps randomly and writing random characters. The phone wouldn't respond to touch while that was happenning). I have read on the Internet that several users had also had malware problems with the same phone model (which html5test.com detects as a 77x while imei.info detects it as a Zora T-6). It seems that there is some kind of pre-installed malware on it, as the problems do not disappear after factory-resetting the phone. I have also tried uninstalling suspicious system apps by rooting it, which stopped the phone from installing apps alone. But it keeps making calls, opening or closing stuff itself, etc. I tried lots of aniti-viruses and they did not find any malware at all. I do not know what else to do in order to get rid of this annoying malware. Could anyone please help me?
Thanks in advance!

Related

[Q] E-wallet closing itself suddenly

I'm using Illıum's ewallet (one of the major factors of me using WM), and my Rom is Energy Cookie 28Aug. version. Trough day, I've been using ewallet lots of time for account numbers, personal pass codes, card numbers etc. . Untill today I never faced a self closedown with this application, but today after I open it, just whilst reading a text it shuts itself suddenly without any warning. It happened 3-4 times, I did restart the device but it couldn't help. What could be the reason? Due to Rom or any other thing like settings or other tweak programs? This program is very important for me, and for this very reason I need your help.
same problem
I've installed the same ROM and also E-Wallet.
I have the same problem, after i deleted the empty wallet, i can use my own wallet. Somethimes it still closes itself, but not so often.
Is there a real posibility to solve this problem?

[Q] Antivirus s/w detected malware in my settings

Hi Everyone,
OK, I am completely new to using tablets and android (and XDA! ) but I recently bought an Android tablet and although I put AV s/w on it I seem to have caught a bug. The problem is that, apparently, my settings app is now malware and it seems the only option to resolve it is to uninstall my settings application. Understandably I don;t want to forge ahead and do this because then I cannot manage my device. Anyone got any suggestions or can point me somewhere that could help? I have trawled the internet for an answer but haven't found anywhere reporting the same thing, so far. I am flummoxed and getting very frustrated. Also, any recommendations for malware prevention apps? Ta.
Thanks for taking time to read this. Sorry if it's in the wrong place!
You do know you should provide more details like which phone, which firmware, what antivirus app, etc.
But the simplest answer you would get is to stop using antivirus apps. Because most of them are hoaxes or give false results. There is nothing wrong with your settings app. I suggest you uninstall the AV app first.
immortalneo said:
You do know you should provide more details like which phone, which firmware, what antivirus app, etc.
But the simplest answer you would get is to stop using antivirus apps. Because most of them are hoaxes or give false results. There is nothing wrong with your settings app. I suggest you uninstall the AV app first.
Click to expand...
Click to collapse
It's not a phone, it's just a no-mark tablet (Tabtronics, if that makes any difference).
Seeing as the last several days (maybe a week now) it has had serious performance issues -- crashing, rebooting itself without my initiating it, not turning on for long periods, notification messeges telling me apps don't work when I have never tried to use them -- I'd say this is not a false result. And the AV (Avast) is the same brand I've been using on my desktop for years and has always been fiine, and I've had no problems with it until the last week.
Seems odd that the assumption here is that there isn't a problem, when there are a shed load of articles online stating how vulnerable Android is to malware. Unfortunately I can't find any that tell you where to go/ what to do in order to get rid of the bug. :crying:
Anyway, thanks for the reply.
BlankScreen said:
It's not a phone, it's just a no-mark tablet (Tabtronics, if that makes any difference).
Seeing as the last several days (maybe a week now) it has had serious performance issues -- crashing, rebooting itself without my initiating it, not turning on for long periods, notification messeges telling me apps don't work when I have never tried to use them -- I'd say this is not a false result. And the AV (Avast) is the same brand I've been using on my desktop for years and has always been fiine, and I've had no problems with it until the last week.
Seems odd that the assumption here is that there isn't a problem, when there are a shed load of articles online stating how vulnerable Android is to malware. Unfortunately I can't find any that tell you where to go/ what to do in order to get rid of the bug. :crying:
Anyway, thanks for the reply.
Click to expand...
Click to collapse
Here's a good discussion that might interest you:
http://forum.xda-developers.com/showthread.php?t=2186782
As for the issues you have, I would attribute it to either a rogue app or low memory. Try uninstalling any apps you recently installed. Also, try clearing app caches, freeing memory etc. See if that helps.

[Q] Avast recent problems + Wifi reconnecting

Hello everyone,
Due to the recent problem with Avast Antivirus for Android, I've seen many problems on my phone.
First, to let everyone know, here's what happened with Avast : http://www.stayprotected.com/2014/01/false-positive-avast-mobile-security/
So, false positive about every app on the phone.
Indeed I was surprised, I uninstalled 2-3 things, but here's the thing. Is it normal that everytime I turn OFF the Wifi, it keeps turning ON by itself ?
In the list of viruses found, there is GinMaster, which sends personnal data. In order to send, you need wifi, which tells me that maybe Avast may not be wrong. Seriously, how does my wifi keeps turning on by itself ?
I backed up my phone yesterday, and restored a previous version (about mid-December). The thing is, if my problem does not come from Avast, then there is also an SmsSend virus or I don't know what, and that GinMaster on my phone.
First, do you have any idea what would cause the wifi to turn on automatically every time ? I'd really like to get back to my yesterday backup, but if it really sends data, I'd prefer not. Plus if I turn on wifi, it could really send data while I'm trying to update Avast.
Also, when I open avast, it keeps force closing, due to all the "viruses" detected.
Sooo, what do you think about it ? Do you have any solution ?
Thank you all !
EDIT : Well, as I was discouraged to obtain any good solution except than reseting the phone (most successful way, I think), I tried the impossible. I restored the last back up, checked if Wifi still connects by itself. So, first it wouldn't, so that's a good point. I turned it on, and updated Avast, which scanned again all the files. Seems like all the "viruses" are gone, so that's another good news.
Still, it weirds me out that after many reboots, the wifi would turn on by itself (even if it doesn't now). Anyway, auto-solution
Thank you readers !

Whatsapp Requesting Root Access

Today I reboot my Op3 after a while.
I usually keep it running without any problem and i just reboot a couple of times in a month.
Before this, I've not done anything new, no strange websites, no strange apk, no installation of anything exept for the app HeyMonster, installed a week ago and I've update 2 modules of Xposed (Wifi Password and Youtube Background Player) right before rebooting.
A part from those, I've not done anything that could have created this problem.
So, I reboot.
After that, WhatsApp started to ask to gain root access.
As a normal root app.
But this is not normal at all.
So, I searched around, but i found nothing, I looked in my phone, in services, app, stuff, but i didn't find anything abnormal.
I run a scan of my phone with PandaAntivirus Pro, but it found nothing (not that I was really believing in it).
So, I guess that is a malware that i got from IDon'tKnowWhere.
And I actually don't really know what to do about it.
I Know that reflashing and start over is the sure solution but, before that, I'd like to realize what and why is this happening.
Thanks to anyone
Weird that I too got the same root request from WhatsApp only a while ago. Two requests from "WhatsApp" and "WhatsApp UID". Any leads?
$$% ¥*hftd÷$_
Me too, but for now I will deny

Issue with Coolpad Torino R108 (CoolReaper?)

My cell phone still is under guarantee protection but I it doesn't help. Well, I discovered few times strange app installed w/o my action with Chinese title, something like eNews or feed app. I deleted it and thought that's all. After some time I started to receive push notification with red background and yellow Chinese sign! In same time I discovered again same app and stock app Sim1 changed its name into something Chinese! After factory reset I thought everything is OK but it last just 3 weeks and same game again! Malwarebytes detect Wireless Update as culprit for this "feature" but it wasn't able to solve problem as this app is part of OS! I have read many facts about Coolpad.Coolreaper.a so I planned to remove this nasty part from my device but don't know how? Service officer didn't find out nothing suspicious after few days of observation and blamed me for click onto ads and adverts links!
Please help me!
Hey there, did you solve the problem with the Coolreaper?
I have the same problem, i just flashed with another Official ROM but Malwarebites finds again the Coolreaper. Now going to wait few days to see if its going to start installing the apps again...
https://forum.xda-developers.com/general/general/coolpad-torino-r108-max-lite-y91-u00-t3735792
ludush1 said:
My cell phone still is under guarantee protection but I it doesn't help. Well, I discovered few times strange app installed w/o my action with Chinese title, something like eNews or feed app. I deleted it and thought that's all. After some time I started to receive push notification with red background and yellow Chinese sign! In same time I discovered again same app and stock app Sim1 changed its name into something Chinese! After factory reset I thought everything is OK but it last just 3 weeks and same game again! Malwarebytes detect Wireless Update as culprit for this "feature" but it wasn't able to solve problem as this app is part of OS! I have read many facts about Coolpad.Coolreaper.a so I planned to remove this nasty part from my device but don't know how? Service officer didn't find out nothing suspicious after few days of observation and blamed me for click onto ads and adverts links!
Please help me!
Click to expand...
Click to collapse
Unfortunately its part of coolpad's system core programs and I havent found any way of removing it... Nasty piece of work from them to include something like that.. but I guess it serves me right for buying a phone made by them... I guess I will either stay away from any chinese made phone in the future - coolpad for certain, but if they are allowed to do this then I dont see what is there to stop other chinese companies from doing the same... very dissapointed.... but not surprised really...

Categories

Resources