adb virus? - General Questions and Answers

Recently I installed the minimalistic platform tools pakage with adb from Google. Then yesterday I tried to test it out and connected my phone to the computer. In the first trial, it didn't seem to work and so I typed adb reconnect, all of a sudden the antivirus software Avast installed on my computer prompts that the adb.exe has been infected with Idp.generic virus and it has blocked its action and put the file in something like quarantine. I would like to know if anyone is experiening such weird behavior and if it is a false positive or is my ROM has been infected with virus?

Related

Big Problem

So im I started to root my Inspire 4g. I was able to put the temporary rom on the phone but when it came time to run the commands on the terminal on the phone as far as RAGE ect. it did nothing. Wemt back to prompt in windows and realized that the rage file never coped. said the directory doesnt exist. After several times of retyping the commands didnt work. Now I am stuck because every time I go and start the process over it says invalid model. Please help!!!!
rage was detected as a malware under my Microsoft Security Essentials and was deleted. I had to force it to take no action before it would leave rage alone.
You may need to disable your antivirus while you do the hack kit.
Moved as not android development

[Q] adb doesn't recognize my phone

I posted this question over on Phandroids but this forum seems perhaps more appropriate. My Lenovo laptop running XP sees my phone just fine (Samsung Gravity Smart SGH-T589) and I'm able to transfer files to/from the phone. However, adb doesn't seem to be able to see it. A search about this problem turns up solution suggestions that mostly involve drivers, but my Samsung driver is up to date and clearly working (or else the phone wouldn't show up to Windows and I wouldn't be able to transfer files). My phone is rooted, which also makes it obvious that my laptop can talk to it just fine -- I used OneClick to root it last week using the same computer.
I'm using the DOS prompt (cmd) to run adb, and adb works fine. It simply doesn't see any devices. Here's an actual text transcript:
===============================
C:\Android\adt\sdk\platform-tools>adb devices
* daemon not running. starting it now on port 5037 *
* daemon started successfully *
List of devices attached
C:\Android\adt\sdk\platform-tools>adb shell
error: device not found
C:\Android\adt\sdk\platform-tools>
===============================
Any ideas? I'm pretty new to this, so perhaps I'm missing something really simple. I hope so anyway!
--
Craig
Sunnyvale, California
Make sure that USB debuggin is enabled on your device. (This option should be changed only while device is disconnected from USB).
Also, try to restart adb server by killing it from the device manager.
Thanks for the suggestions. I had indeed already done both of those things. USB debug must be enabled to do file transfers, so I already knew it was definitely on. I still cycled it off/on anyway to make sure. And I did both kill-server and start-server commands as part of my checkout to assure myself that adb was in fact working correctly. I had Windows task manager up as well so I could watch adb disappear and reappear with those commands.
--
Craig
Sunnyvale, California
Hmmm... Try to reboot both your computer and device.
Have you tried to connect other devices to ADB? May be there is a problem with ADB installation?
Phone and laptop have both been rebooted many times. I also tried it with the phone in charge-only mode because that's what One Click Root required, but nothing changed. I also tried using all of the different USB ports on my laptop and tried two different USB cables, although that was silly because the phone is obviously talking to the laptop via USB. It shows up in file explorer, and I am able to transfer files using Windows drag and drop.
I'm afraid I have only one device, my recently rooted Samsung Gravity Smart phone, so I can't try it out on anything else.
I'm not sure how the adb installation could be at fault since the commands work as long as they don't involve the USB port. And I know that it MUST be possible to shell to the phone with what's already on this computer because One Click did it. I tried running the adb commands from the One Click Root > ADB directory just in case something about that particular install of adb was different, but I got exactly the same result.
It seems to me that I must be failing to do some setup step that an experienced Android developer might know about. I've never done anything like this before, so I wouldn't have even known about downloading the Android sdk if it weren't for forums like this! I sure appreciate the community of knowledgeable people here, who are clearly willing to help newbies like me.
If there are any software tools that anyone can suggest using to help me figure out what's going on, please let me know.
EDIT: Is there something that I need to load on my phone before adb will work? It occurs to me that OneClick might push something to the phone when it does the root, then delete it when the task is complete. I tried using QTadb, which is an adb GUI, and got the same result: no devices seen on the port even though Windows sees my phone and can talk to it via USB.
--
Craig
Sunnyvale, California

[Q] ADB, RSA, Android 4.2.2, Android Commander

http://www.youtube.com/watch?v=JmvCpR45LKA
I have seriously searched EVERY DAMN INCH of the Internet for this. Okay, obviously, I've seen all the posts like this one:
http://forum.xda-developers.com/showthread.php?t=2351390 (I actually wanted to reply there but can't, sad)
And I've done all those steps, I've uninstalled everything, I've reinstalled everything, I've called my mom to tell her she wasn't lying to me about me being special, I've done it all ten times. This is what happens:
System stuff: Windows XP, cyanogenmod 10, ADB and Apps set to root, USB debugging on, Android 4.2.2, latest Android Commander, Galaxy S3 Sprint, Android Debug Bridge version 1.0.31
I open cmd and type adb devices, it shows me a device is available:
adb server is out of date. killing...
* daemon started successfully *
List of devices attached
ba0a8be4 device
I open Android Commander, it has a blank line that's highlighted blue, I click "OK", it says:
Connected device has status offline and cannot be used. Please reboot your device.
I reboot my device, same thing happens.
Does anyone have any ideas? I'm seriously about to just flash it to 421 but I hate just giving up. I hate it almost as much as I hate asking for help. I spent 7 hours last night (I was up until 2am!!) and then another 4 or 5 today just trying to figure this out. I'm completely lost here. Oh, another thing, since I'm at it, does anyone know how to delete the saved RSA key from my phone? I looked in that data/adb place that link said and renamed it but it didn't seem to reset the key... maybe I need to restart, I'll try restarting after I rename it. Yep, I bet that'll work. It probably had it in memory. Anyway, pointless rant about RSA done. I hope someone has some ideas before I resort to just sitting in the corner, cuddling up with my phone, and crying until my mommy tells me I'm special.
Another possibly important thing is that Droid Explorer works briefly (I can see phone's files come up) but then crashes when I try opening anything.
It also, as I was just playing with it, seems like Android Commander causes the adb server to become outdated. Does that mean anything? I just ran adb devices, then tried AC, then did adb dev again and it needed to restart the service. I don't know if that means anything. Just something I noticed.
Oops I had to update the link, I just realized I copied the wrong one from the page suggestions it does. This now has the one I meant.
Did you find a solution? I am having the same problem.
I gave up. Flashed stock, then cm 10 with system and cache wipes then cm 10.1 without wiping system. Haven't tried with my computer since I mostly use my phone. I'll check later and update this and let you know. I would have just kept stock but my god that stuff sprint puts on sickens me......
I found a solution and it works.
http://forum.xda-developers.com/showpost.php?p=40276190&postcount=1488
Yeah, I even said in my message that I made sure that was up to date. I was able to connect to adb and see it show up as a device now but Android Commander doesn't work. I did find out that adb push (and I assume pull) works but that probably worked before and I just didn't try. Anyway, I'm not too concerned. Glad you got yours figured out.
Hope this helps!
I managed to get android commander to work by installing the latest adb with the sdk manager and then I copied adb.exe, AdbWinApi.dll and AdbWinUsbApi.dll to the bin folder located where ever you install android commander!
lukesheardown said:
I managed to get android commander to work by installing the latest adb with the sdk manager and then I copied adb.exe, AdbWinApi.dll and AdbWinUsbApi.dll to the bin folder located where ever you install android commander!
Click to expand...
Click to collapse
Copying the adb files to the bin directory worked for me, thanks!

[Completed] [Q] XXX Video / Droid Porn Ransomware Removal via ADB

Hello,
So long story short my brothers an idiot and installed a "Flash Player" because he thought he needed it. Now he has the "Prism FBI Child Porn/Bestiality" ransomware installed. I can get into safe mode and I am unable to uninstall the app. It is listed as "XXXVideo Droid Porn." It does not exist in safe mode under "Device Administrators" so the uninstall button is locked in normal and safe mode. I have since rooted his phone and I can gain access via ADB, I figure removing the package via ADB is my only option at this point. Within the shell I can gain Superuser access and can navigate fairly well having just learned how to do all this in an hour. So far I am having no luck locating the package or where to go at this point to remove this for him. I have tried Avasts ransomware removal tool as well as some others but none of them are working. I can get into these apps and run them normally but after about 30 seconds the ransomware starts and cuts off any progress made, and none are available in safe mode. About the only thing I can find is when I connect through the ADB Shell and list the packages I recognize all but one. It is labeled "package:ysvv.dvvsg.bfydrij." I cannot find any information online regarding this package, I even hail mary-d and tried to uninstall the package but it failed. I have also searched through the root folders looking for some hint of where it could be. If there is a way to enable one of these in safemode to try and have them run it then i cant find it. Or if there is some shell command to list packages by install date, I can try to uninstall it that way.
So any help at this point would be appreciated. Sorry if this is the wrong area but after a few hours working on it I am at a loss.
Phone: Galaxy S3
Carrier: Tmobile
Model: SGH-T999
Android: 4.1.2
vyletrakun said:
Hello,
So long story short my brothers an idiot and installed a "Flash Player" because he thought he needed it. Now he has the "Prism FBI Child Porn/Bestiality" ransomware installed. I can get into safe mode and I am unable to uninstall the app. It is listed as "XXXVideo Droid Porn." It does not exist in safe mode under "Device Administrators" so the uninstall button is locked in normal and safe mode. I have since rooted his phone and I can gain access via ADB, I figure removing the package via ADB is my only option at this point. Within the shell I can gain Superuser access and can navigate fairly well having just learned how to do all this in an hour. So far I am having no luck locating the package or where to go at this point to remove this for him. I have tried Avasts ransomware removal tool as well as some others but none of them are working. I can get into these apps and run them normally but after about 30 seconds the ransomware starts and cuts off any progress made, and none are available in safe mode. About the only thing I can find is when I connect through the ADB Shell and list the packages I recognize all but one. It is labeled "package:ysvv.dvvsg.bfydrij." I cannot find any information online regarding this package, I even hail mary-d and tried to uninstall the package but it failed. I have also searched through the root folders looking for some hint of where it could be. If there is a way to enable one of these in safemode to try and have them run it then i cant find it. Or if there is some shell command to list packages by install date, I can try to uninstall it that way.
So any help at this point would be appreciated. Sorry if this is the wrong area but after a few hours working on it I am at a loss.
Phone: Galaxy S3
Carrier: Tmobile
Model: SGH-T999
Android: 4.1.2
Click to expand...
Click to collapse
Your best bet is gonna be to fully wipe the device. Then reload the rom.
[Solved!]
zelendel said:
Your best bet is gonna be to fully wipe the device. Then reload the rom.
Click to expand...
Click to collapse
Actually I was able to do it without wiping the phone.
I just navigated to /data/app and did the "rm" command on the suspicious package and it worked. The prism ransom ware became broken and I was able to boot up normally and delete the broken piece of the app.
-----
adb shell
su
pm list packages -3 [found the start of the ransom ware]
cd /system/app
ls [found the ransomeware .apk file here]
rm /system/app/ysvv.dvvsg.bfydrij-2.apk
------
Then it worked

I need help with an apk that comes with a malware

Hi, everyobody. So, I've downloaded an apk for a multiplattform emulator that I used to have installed in my phone but lost when rebooting and happens to have been removed from the PlayStore. The thing is, said apk seems to come with a malware. I've done a couple of test to see if the malware was from somewhere else or if it comes from the phone's system but it seems like it comes in the apk of the emulator.
This malware installs some bloatware apps and even if I uninstall them, the malware just installs them again by itself. It also starts to take control of the phone. The malware, however, disappears if I do a factory reset. I tried opening the apk file with a file explorer and see what's inside the apk file to see if I could identify the malware files or whatever that triggers it and erase them from the apk, but unfortunately I lack the knowledge to tell what belongs to the emulator and is the malware.
I know it's a little bit silly of a help request, but I really like that emulator and I can't find a clean malware-free apk of it. If someone with knowledge on the subject has some spare time and is willing to help me with this silly request I would be really greatful to them.
Here's one of the few links to the apk. CAREFUL: don't install it, the malware seems to install itself in your phone's system and won't gomeven if you uninstall the emulator.
Retrogaming Emulator for Android for Android - APK Download
Download Retrogaming Emulator for Android apk 4.14.0 for Android. PSX Emulator, GBA Emulator, SNES Emulator, NES Emulator, PSP Emulator, TV Box
www.google.com
I have read the rules and I don't think I'm breaking them by asking help with this, but if I'm making something wrong or if this is not the place for asking for this kind of help, please let me know and I'll delete the post. Also, it would be nice if you could tell me what is a proper site for asking help with this.
Thanks in advance, everybody.
I wouldn't even attempt to download a known infected file
Scan it with online Virustotal and see what you got. You should have done this before side loading it... not very clever.
If it's not the cause a factory reset is in your future, and if you're running Android 8 or lower more may be required if its a rootkit.
Find and ID the malware and uninstall/delete it... if you can.
ZIGS318 said:
Hi, everyobody. So, I've downloaded an apk for a multiplattform emulator that I used to have installed in my phone but lost when rebooting and happens to have been removed from the PlayStore. The thing is, said apk seems to come with a malware. I've done a couple of test to see if the malware was from somewhere else or if it comes from the phone's system but it seems like it comes in the apk of the emulator.
This malware installs by itself again if I uninstall it and starts to take control of the phone. I tried opening the apk file with a file explorer and see what's inside the apk file to see if I could identify the malware files or whatever that triggers it and erase them from the apk, but unfortunately I lack the knowledge to tell what belongs to the emulator and what could not.
Click to expand...
Click to collapse
how does this malware manifest itself?
you can always run the apk through an online android-apk decompiler to get the source code and then look into it
ZIGS318 said:
Hi, everyobody. So, I've downloaded an apk for a multiplattform emulator that I used to have installed in my phone but lost when rebooting and happens to have been removed from the PlayStore. The thing is, said apk seems to come with a malware. I've done a couple of test to see if the malware was from somewhere else or if it comes from the phone's system but it seems like it comes in the apk of the emulator.
This malware installs by itself again if I uninstall it and starts to take control of the phone. I tried opening the apk file with a file explorer and see what's inside the apk file to see if I could identify the malware files or whatever that triggers it and erase them from the apk, but unfortunately I lack the knowledge to tell what belongs to the emulator and what could not.
I know it's a little bit silly of a help request, but I really like that emulator and I can't find a clean malware-free apk of it. If someone with knowledge on the subject has some spare time and is willing to help me with this silly request I would be really greatful to them.
Here's one of the few links to the apk. CAREFUL: don't install it, the malware seems to install itself in your phone's system and won't gomeven if you uninstall the emulator.
Retrogaming Emulator for Android for Android - APK Download
Download Retrogaming Emulator for Android apk 4.14.0 for Android. PSX Emulator, GBA Emulator, SNES Emulator, NES Emulator, PSP Emulator, TV Box
www.google.com
I have read the rules and I don't think I'm breaking them by asking help with this, but if I'm making something wrong or if this is not the place for asking for this kind of help, please let me know and I'll delete the post. Also, it would be nice if you could tell me what is a proper site for asking help with this.
Thanks in advance, everybody.
Click to expand...
Click to collapse
Did u just said malware can't be uninstalled even after doing factory reset. The malware is called xhelper that's a malware that can't be uninstalled once u get it.
Austinredstoner said:
Did u just said malware can't be uninstalled even after doing factory reset. The malware is called xhelper that's a malware that can't be uninstalled once u get it.
Click to expand...
Click to collapse
Yeah but that's on Android 8 and lower.
On Pie and above it can't do that.
It's a nasty little critter
blackhawk said:
I wouldn't even attempt to download a known infected file
Scan it with online Virustotal and see what you got. You should have done this before side loading it... not very clever.
If it's not the cause a factory reset is in your future, and if you're running Android 8 or lower more may be required if its a rootkit.
Find and ID the malware and uninstall/delete it... if you can.
Click to expand...
Click to collapse
Thanks for the advice.
xXx yYy said:
how does this malware manifest itself?
you can always run the apk through an online android-apk decompiler to get the source code and then look into it
Click to expand...
Click to collapse
Well, for what I've seen it's a malware that hides in the system files (I don't know where). Once there, it starts installing bloatware and spyware on the phone and starts to take control of things like the browser (mostly to show pages of ads and bets) and calls and messages. I can uninstall the bloatware apps, but the malware installs them again after some time has passed. After a Factory Reset, the malware is gone, that's how I realized the malware comes from the emulator apk. But Iike that emulator so I want to erase the malware from the apk. Also, thanks for the advice, I will try it. :"D
Austinredstoner said:
Did u just said malware can't be uninstalled even after doing factory reset. The malware is called xhelper that's a malware that can't be uninstalled once u get it.
Click to expand...
Click to collapse
No, I expressed myself wrong. The malware disappears after a factory reset. What I can't uninstall is the bloatware apps that the malware installs while it's in the phone. Once the malware is gone, so are the bloatware apps.
ZIGS318 said:
Once the malware is gone, so are the bloatware apps.
Click to expand...
Click to collapse
The hard reset deletes the malware together with the apps, what am I missing here?
Can't help with de-compiling but when I was investigating a malware outbreak, I turned off the system setting apk.
It later turned out to be ES file explorer and the apps were being installed via google play/mobile services.
Of course you can't change any settings but at least I could use the phone and nothing got installed.
Use the terminal/adb commands to turn off and back on when your done:
pm disable com.android.settings / pm enable com.android.settings
mobnoob said:
The hard reset deletes the malware together with the apps, what am I missing here?
Click to expand...
Click to collapse
I want to identify which parts of the app files are the maleare ones so I can delete them and get the app to be malware-free.
xdabookam said:
Can't help with de-compiling but when I was investigating a malware outbreak, I turned of the system setting apk.
It later turned out to be ES file explorer and the apps were being installed via google play/mobile services.
Of course you can't change any settings but at least I could use the phone and nothing got installed.
Use the terminal/adb commands to turn off and back on when your done:
pm disable com.android.settings / pm enable com.android.settings
Click to expand...
Click to collapse
Emmm...I didn't get that well. How do I enter that command? Thabks you for the answer, though.
ZIGS318 said:
Emmm...I didn't get that well. How do I enter that command? Thabks you for the answer, though.
Click to expand...
Click to collapse
ZIGS318 said:
Emmm...I didn't get that well. How do I enter that command? Thabks you for the answer, though.
Click to expand...
Click to collapse
He’s talking about ADB, android debug bridge.
That needs to be installed on ur pc and run while your phone is connected to the PC.
I’ll post a tutorial here.
K3V1991 said:
View attachment 5520451
NFO:
Code:
• Versions: Installer, Portable & ADBKit
• Android Debug Bridge & Fastboot updated to latest v1.0.41 (Version 32.0.0-8006631, January 2022)
Installer Features:
• Installation Folder chooseable
• Creates Desktop & Start Menu Shortcut
• Toolkit & Desktop Shortcut
• Creates Commands Shortcut
• View Commands List
• Add to System Path Environment
• Universal ADB Driver Installation
ADBKit:
• Pure ADB (Android Debug Bridge)
• Open CMD.bat to easily open a CMD
• Only 5.81MB (compressed 2.74MB)
Requirements:
Code:
• Windows OS
• USB Driver for your Device or Universal ADB Driver (Included in the Installer)
• PowerShell for the Toolkit
​Developer Options & USB Debugging:
Code:
01. Install the USB Driver for your Phone or Universal Adb Driver.
02. On your Phone, go to Settings > About Phone. Find the Build Number and tap on it 7 times to enable Developer Options.
03. Now enter System > Developer Options and find "USB debugging" and enable it.
04. Plug your Phone into the Computer and change it from "Charge only" to "File Transfer" Mode.
05. On your Computer, browse to the directory where you extracted the Portable Version or use Tiny ADB & Fastboot Shortcut.
07. Launch a Command Prompt with Open CMD.bat or use Tiny ADB & Fastboot Shortcut.
09. Once you’re in the Command Prompt, enter the following Command: adb devices
10. System is starting the ADB Daemon (If this is your first Time running ADB, you will see a Prompt on your Phone asking you to authorize a Connection with the Computer. Click OK.).
11. Succesful enabled USB Debugging.
Installer:
Code:
1. Download ADB_&_Fastboot++_vXXX.exe
2. Follow the Installers Instructions and select where you would like to install ADB & Fastboot++
3. After the Installation Wizard has completed you can select to start ADB & Fastboot++
4. You should see a Command Window open, now you can use ADB and Fastboot Commands
Portable:
Code:
1. Download ADB_&_Fastboot++_vXXX_Portable.zip
2. Extract the Zip Archive
3. Double click on Open CMD.bat
4. You should see a Command Window open, now you can use ADB and Fastboot Commands
ADBKit:
Code:
1. Download ADBKit_vXXX.zip
2. Extract the Zip Archive
3. Double click on Open CMD.bat
4. You should see a Command Window open, now you can use ADB Commands
Toolkit Features:​
• Uninstall Bloatware without Root Access
(This works because Applications truly aren’t being fully uninstalled from the Device, they are just being uninstalled for the current User
• Re-install uninstalled Apps
• Install Kernel (Popup Menu, reboots automatically to Bootloader)
• Install Recovery (Popup Menu, reboots automatically to Bootloader)
• Install APKs (Popup Menu)
• Push Files (Popup Menu)
• Check Firmware Version
• Check Android Version
• Check Kernel Version
• Check Firmware Build Date
• Check Kernel Build Date
• Check Security Patch Date
• Check IMEI
• Check IP Adresses
• Check App Packages
• Check Process Activity (Real Time)
• Take Screenshots (PNG Format)
• Video recoding - 30 Seconds (Without Device Sound)
• Video recoding - 60 Seconds (Without Device Sound)
• Video recoding - 120 Seconds (Without Device Sound)
• Video recoding - 180 Seconds (Without Device Sound)
• Reboot the Device
• Reboot to Bootloader
• Exit Bootloader to System
• Reboot to Recovery
• Create Logcat
• Exit (adb kill-server & close Toolkit)
Downloads:
• Installer
• Portable
• ADBKit
• Universal Adb Driver
View attachment 5521523
Donate Link​
Click to expand...
Click to collapse
You could try firewall blocking the app or maybe running under VMOS.
Personally I just ditch it...
There are decompiler apps that might enable you to defang it.
blackhawk said:
You could try firewall blocking the app or maybe running under VMOS.
Personally I just ditch it...
There are decompiler apps that might enable you to defang it.
Click to expand...
Click to collapse
Or there are perfectly “virus-free” emulators on the internet.
The malware will be downloaded by a background process. You need to find the link for the website and break it.
The best place to start would be an app that can log dns and ip calls, like Adguard. It will also block any already known links.
If you can break the link to prevent the apps installing its a start.. But as already suggested you are better off using a more up to date app because retroarch may not run correctly on newer tech.
Kenora_I said:
He’s talking about ADB, android debug bridge.
That needs to be installed on ur pc and run while your phone is connected to the PC.
I’ll post a tutorial here.
Click to expand...
Click to collapse
Yes the pm command was entered via adb from a PC via USB. A shell terminal on the device as a standard user never seems to have the right privileges to run the pm command but su - (superuser root) will.
shivadow said:
The malware will be downloaded by a background process. You need to find the link for the website and break it.
The best place to start would be an app that can log dns and ip calls, like Adguard. It will also block any already known links.
If you can break the link to prevent the apps installing its a start.. But as already suggested you are better off using a more up to date app because retroarch may not run correctly on newer tech.
Click to expand...
Click to collapse
Thanks for the advice! I'll see what I can do!
Kenora_I said:
He’s talking about ADB, android debug bridge.
That needs to be installed on ur pc and run while your phone is connected to the PC.
I’ll post a tutorial here.
Click to expand...
Click to collapse
Thank you for putting it more clear for me. I'll see what I can do when I get some free time!

Categories

Resources