Fotaupdate,malware ? - Security Discussion

Hi,I have an android box and just done a scan with Malwarebytes.
It brought up this threat
Android/PUP.Riskware.Autoins.Fota
/system/app/FotaUpdateReboot
FotaUpdateReboot.apk
Is it genuine malware or a false positive ?
Cheers.

ascender13 said:
Hi,I have an android box and just done a scan with Malwarebytes.
It brought up this threat
Android/PUP.Riskware.Autoins.Fota
/system/app/FotaUpdateReboot
FotaUpdateReboot.apk
Is it genuine malware or a false positive ?
Cheers.
Click to expand...
Click to collapse
Looks like several firms are flagging it as malware on virus total, at least according to the following thread
https://forums.malwarebytes.com/topic/216168-pre-installed-malware/

Thanks for that.
Looks like the system app FotaProvider allows adverts to pop up in the browser,which is exactly the issue I've been having.
I've uninstalled it now.Have to see how I get on
Cheers

update
ascender13 said:
Thanks for that.
Looks like the system app FotaProvider allows adverts to pop up in the browser,which is exactly the issue I've been having.
I've uninstalled it now.Have to see how I get on
Cheers
Click to expand...
Click to collapse
HI.
Is everything fine after you deleted the fota provider?

Yes,that fixed it.

remove problem apps
How do you delete these unwanted system apps?
The main sources of malware are google play store, and wireless update (the system app)
both are pre-installed malware when you buy the device

mprox said:
How do you delete these unwanted system apps?
The main sources of malware are google play store, and wireless update (the system app)
both are pre-installed malware when you buy the device
Click to expand...
Click to collapse
If I remember correctly I just used a file manager with root access

Related

security concerns migrating from iOs to Android

As title suggests, coming from a so called "clean" iOS environment to Android, my main concern how susceptible is my data to being stolen. I have no (current) plans to root my next phone and will be used mainly from business, but from what I have read in the past even google play store apps have been to known to have malicious content. Am I worrying too much ? I do carry sensitive work data on my iPhone.
applefag said:
As title suggests, coming from a so called "clean" iOS environment to Android, my main concern how susceptible is my data to being stolen. I have no (current) plans to root my next phone and will be used mainly from business, but from what I have read in the past even google play store apps have been to known to have malicious content. Am I worrying too much ? I do carry sensitive work data on my iPhone.
Click to expand...
Click to collapse
As long as the apps you install are from known sources (i.e. Play Store) you don't need to worry. Also every time you download an app check the permissions. If you think that the app shouldn't have those permissions then don't download it. Finally for safety reasons never install any apps from unknown sources (i.e. outside of Play Store) unless you trust the developer.
If you still find yourself worrying read this.
applefag said:
Am I worrying too much ?
Click to expand...
Click to collapse
Yep
I think you won't install any app outside Google Play so install apps that you know and you won't need to worry. FYI http://en.wikipedia.org/wiki/Security-Enhanced_Linux
kalpetros said:
Also every time you download an app check the permissions. If you think that the app shouldn't have those permissions then don't download it.
Click to expand...
Click to collapse
Well only if you are sure. Sometimes apps need permissions that aren't justified for some people.
for the open nature of the android ecosystem, it is somewhat normal that you will have to be careful though there are several different techniques, i use this the most.
Root your phone, install xposed framework and install xprivacy. here is a review of what it does http://www.xda-developers.com/android/manage-individual-app-permissions-with-xprivacy/ . I know the installation pprocess may seem daunting, but it is easier than you think this module wil allow you to block apps of certain permission. IE. you can block location service for all the apps on your phone so that no app can get your location. There are bunch of other permissions that you can block like access to contact, gallery etc
My question to others is : Is antivirus application on android worth it? I mean can it protect me from real time attaks and malwares??
SaffatBokul said:
My question to others is : Is antivirus application on android worth it? I mean can it protect me from real time attaks and malwares??
Click to expand...
Click to collapse
Not useful IMO. FYI I remember this article.
User sensibility is your best defense. Don't install apps not from the market. Only install apps with a lot of positive comments.
I would advise again rooting your phone. It's true that there are ways to block apps from accessing your private data on a rooted phone, but the additional vulnerability from unlocking your bootloader and rooting is not worth it. Just stick to apps from major developers.
snapper.fishes said:
User sensibility is your best defense. Don't install apps not from the market. Only install apps with a lot of positive comments.
I would advise again rooting your phone. It's true that there are ways to block apps from accessing your private data on a rooted phone, but the additional vulnerability from unlocking your bootloader and rooting is not worth it. Just stick to apps from major developers.
Click to expand...
Click to collapse
I agree, rooting your phone comprimises your security even if you do it to install security apps.
Primokorn said:
Yep
I think you won't install any app outside Google Play so install apps that you know and you won't need to worry.
Click to expand...
Click to collapse
Unfortunately, new apps in Google Play are rarely verified by Google staff, so there is still always a possibility of trojan or other malware.

I've been hacked.

According to facebook report over my mail, someone has entered in to my fb via Xperia XA, Saratoga, CALIFORNIA, US. I am at Europe.
Most likely i was blocked because my phone Ip have changed somehow.Now i cant enter in to my account with msnger and facebook (only from browser) app on my phone. Think the security system is blocking my phone.
Ps: i had to swap Wifi with 4g in order to get access.
Did you use any vpn to access Fb?
Think not, just standart office Wifi connection. And i just check , my office location (according to my laptop is Europe), but according to my phone 4g i am at California ,Saratoga. So whats going on ?
Its something from the phone system, i changed the firmware few days ago, and the phone is encrypted now, so maybe its forcing the apps to connect via VPN network, or who knows...
really ?? my phones comes with greek firmware and now I use south Africa firmware !! is there any problem ?
Have you some apps from unofficial markets like Aptoide? Have you some apps downloaded from file-sharing links or P2P? If yes, don't search away, you probably have a malicious app.
If you are rooted, use a permission manager app, Xprivacy is good for that and allow blocking strange permissions (Facebook, Google accounts, contacts, device ident, ... for an app who don't need them).
rrvuhpg said:
Have you some apps from unofficial markets like Aptoide? Have you some apps downloaded from file-sharing links or P2P? If yes, don't search away, you probably have a malicious app.
If you are rooted, use a permission manager app, Xprivacy is good for that and allow blocking strange permissions (Facebook, Google accounts, contacts, device ident, ... for an app who don't need them).
Click to expand...
Click to collapse
Might have some. How to detect which one is virus ?
hp6830s said:
Might have some. How to detect which one is virus ?
Click to expand...
Click to collapse
1) Try to re-download apps from trusted sources.
2) Try AVG app integrated in the device to scan it.
3) Use Xprivacy and block unnecessary permissions on suspicious apps, make some test (block/unblock) to understand what mean each permissions. For sample, a game generally don't need root, phone contacts or SMS and needs sensors, storage and Internet.
rrvuhpg said:
1)
3) Use Xprivacy and block unnecessary permissions on suspicious apps, make some test (block/unblock) to understand what mean each permissions. For sample, a game generally don't need root, phone contacts or SMS and needs sensors, storage and Internet.
Click to expand...
Click to collapse
nICE,will try that ,got some apps which are not suitable for my device. Think they might be suspicious.
So Xprivacy installs xFrame too ?
hp6830s said:
nICE,will try that ,got some apps which are not suitable for my device. Think they might be suspicious.
So Xprivacy installs xFrame too ?
Click to expand...
Click to collapse
Not suitable ?? Big targets to be suspicious are warez/cracked apps.
rrvuhpg said:
Not suitable ?? Big targets to be suspicious are warez/cracked apps.
Click to expand...
Click to collapse
One reason I'll never use apps like that in the first place. Just asking for trouble.
Sent from my Xperia XA using XDA Labs
aidy.lucas said:
One reason I'll never use apps like that in the first place. Just asking for trouble.
Sent from my Xperia XA using XDA Labs
Click to expand...
Click to collapse
if you know what the app is its ok I think !
rrvuhpg said:
Not suitable ?? Big targets to be suspicious are warez/cracked apps.
Click to expand...
Click to collapse
yea few which i was trying to connect a DSLR and use the phone for shutter remote.
It looks like i have already removed the antivirus app.

How I got malware on my OP6 and how I got rid of it (at least I think so)

So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch (I already have one different working app for that now). Someone suggested a very shady link to download an apk but since I'm desperate and dumb I just downloaded and installed it. However, after installation there was only a "done" button but "open" button was greyed out, there was no new app on app drawer and there was no new app in application list in settings. I started getting worried that I had just installed some bitcoin mining software or another kind of malware.
I got even more worried because if I tapped on the apk again it was asking me if I wanted to UPDATE the app instead of if I wanted to install it so it was already installed and it had permissions to access gps, phone history, and read, modify and delete USB storage.
After a while during the day, my phone started doing random noises from the speakers like audio from ads but without opening any app, then later it started opening random chit on google chrome and that is not even my default browser (my default is samsung browser), it opened those very intrusive ads that tell you you have a virus and you cannot go back you have to close the whole tab or app it also opened some ads with sexual content a few times.
I always thought all free anti-virus app on the play store were completely useless and just bloating apps but I started installing a bunch, most didn't detect absolutely anything after the option "scan all apps" I tried kaspersky, avast, AVG, Norton, etc. then I installed this (it's called "hi security" so not known brand and I thought it was going to be the worse but after opening it was powered by "McAfee" so at least McAfee is known):
https://play.google.com/store/apps/details?id=com.ehawk.antivirus.applock.wifi
And it actually detected some malware after scanning all apps, there was an app with completely blank name on device administrators that I never gave permission to become device administrator as far as I remember, so I unchecked that app from admin and then the antivirus app was able to uninstall it.
After the virus cleaner uninstalled the app I haven't had any more issues with audios or ads opening on chrome. Do you think I'm safe now or could I still have some spyware?
I posted some screenshots showing everything.
I doubt that anyone wants the apk but if a developer wants it for reverse engineering or whatever reason I can post it the the name "MALWARE_do_NOT_install.apk" or something like that
If you are afraid of malware then flashing stock room is the best bet to get rid of it
vwite said:
So I was looking for an app to make the top radius match the bottom radius on the corners while using the option of hiding the notch.
Click to expand...
Click to collapse
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
surface13 said:
Well, that all sucks!
Back to your top radius matching the bottom problem, here is what your're looking for!
I saw it on some guys youtube channel
https://play.google.com/store/apps/details?id=com.thsoft.rounded.corner&hl=en_US
Click to expand...
Click to collapse
good app, that's the one I've been using for a while It has a few issues but overall good
Manivannan9444 said:
Bro if security is top priority dont unlock bootloader and root because if you root your device you need to be careful i use af wall and also in settings i will control the permissons of all the apps you need to be conscious because in today's world internet devloped along with it many hackers many trojan rats are devloped so first study some blogs how to use android mobile safely finally if you root and use right apps you can secure device tonhigh level .apps like x privacy lua afwall will secure your device and super user authentication should be set to promt not allow by default
Click to expand...
Click to collapse
I'm not rooted at the moment, phone has been doing everything I want except HBM but I don't think I'll root just because of that because I also use samsung pay plugin for my gear s3 and don't want to risk it
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
herecomesmaggi said:
First of all dont trust any antivirus app except major companies like AVG, Avira etc. Always download from playstore. Don't give permission to browser to install app (unknown sources) in 8.1.0 u can do that.
Now scan all apps.. And remove them. Malwarebytes is best to remove hidden malware on any platform.
Good luck.
If u r ready to format and clean ur internal memory then, format ur handset from settings, download whole stock rom and flash it from recovery..
Regards.
Click to expand...
Click to collapse
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
vwite said:
Thanks, as I said on first post AVG and Avira were useless for this infection but both "Hi Security" and Malwarebytes premium were able to do the job
Click to expand...
Click to collapse
I mentioned Avira nd AVG as antivirus. Malwarebytes is best bro for malware infection. I m using it since 2009 for pc. Every time it does the job.
Also for ur round corner.. I suggest u search for "round R" a app found on xda in 2011 or 12, since then It does it job beautifully.
Regards

installing and uninstalling applications

installing and uninstalling many applications Is it harmful?
marioswat81 said:
installing and uninstalling many applications Is it harmful?
Click to expand...
Click to collapse
Depends on where the application come from. Most apps from the Play Store are okay and if you want to uninstall something it's probably okay. Just don't go using adb and uninstall any system apps.
I ask about applications from Google play
marioswat81 said:
installing and uninstalling many applications Is it harmful?
Click to expand...
Click to collapse
It can potentially cause undesirable changes especially if the app is poorly written.
Avoid doing so when possible by not uploading an app for no good reason.
Read reviews about an app first.
Even a Playstore app can cost you a hard reset... did 2 back to back recently caused by a launcher.
If an app is running poorly, uninstall it. Clear the storage for the app first.
Keep an eye on what your apps are doing in the background with data/memory/battery usage.
Don't side load apps unless you -really- trust the source. If so -always- scan it with an online scanner like Virus Total before you install it!!!
Use SD Maid to pick off the remnants of uninstalled apps.
marioswat81 said:
I ask about applications from Google play
Click to expand...
Click to collapse
As I said apps from the Play Store are mostly safe as they are constantly being checked by Google. Every once in a while something will slip by but mostly safe. If you are worried activate device security in settings under device care.
marioswat81 said:
installing and uninstalling many applications Is it harmful?
Click to expand...
Click to collapse
ggrant3876 said:
As I said apps from the Play Store are mostly safe as they are constantly being checked by Google. Every once in a while something will slip by but mostly safe. If you are worried activate device security in settings under device care.
Click to expand...
Click to collapse
Just because an app is "safe" doesn't mean it isn't poorly coded. Bad uninstalls is more a PC issue but Androids aren't completely immune to it.
Just one change hidden (inaccessible) setting change can really screw up your machine. Saw that happen on an e-reader; it globally changed the screen tint and when uninstalled it remained. Had to reload it, toggle that off, uninstall. The was a bloody Goggle apk.
Be it a trojan or bad coding a hard reset is a hard reset.
It's rare for a Playstore Android app to crash and burn the OS but it definitely does happen
As do buggy uninstalls... best not do too many installs or uninstalls together so if there is an issue you can spot it and know where it came from.
This may be the only way to easily correct it...
thank you

Question Can I stop google putting stuff on my phone without consent

So I'm tired of crap being added to my phone without my consent like Google one it was added recently to my phone and is really annoying when editing photos and now I got this cov*d alerts I really don't want this crap on my phone is there a way to remove them or prevent Google from adding it?
Unistall or disable it.
blackhawk said:
Unistall or disable it.
Click to expand...
Click to collapse
I can't I tried using a root uninstaller
ShadowFox141 said:
So I'm tired of crap being added to my phone without my consent like Google one it was added recently to my phone and is really annoying when editing photos and now I got this cov*d alerts I really don't want this crap on my phone is there a way to remove them or prevent Google from adding it?
Click to expand...
Click to collapse
Debloat/Disable System Apps
So you got your new shiny realme device but you hate bloatware or want to disable system apps so you can use 3rd party apps instead? Follow the steps below: THIS DOES NOT REQUIRE ROOT HOWEVER MAKE SURE NOT TO DISABLE IMPORTANT SYSTEM APPS. WIPE...
forum.xda-developers.com
^ Posted in the Realme 7 forum, but it works on every phone I've used.
Search up "package name viewer" on the Google Playstore to get an app that lets you see the name of packages.
OrthodoxOxygen said:
Debloat/Disable System Apps
So you got your new shiny realme device but you hate bloatware or want to disable system apps so you can use 3rd party apps instead? Follow the steps below: THIS DOES NOT REQUIRE ROOT HOWEVER MAKE SURE NOT TO DISABLE IMPORTANT SYSTEM APPS. WIPE...
forum.xda-developers.com
^ Posted in the Realme 7 forum, but it works on every phone I've used.
Search up "package name viewer" on the Google Playstore to get an app that lets you see the name of packages.
Click to expand...
Click to collapse
Thanks man I'll give that a try
ShadowFox141 said:
I can't I tried using a root uninstaller
Click to expand...
Click to collapse
This...
Home - Package Disabler
The only NON-root solution that let’s you disable any unwanted packages that come pre-installed / installed with your phone / tablet.
www.packagedisabler.com

Categories

Resources