Malware in SoundRecorder.apk in priv-apps folder - Security Discussion

Hello.
How can I remove this app from my Ulefone S8 Pro?
/system/priv-apps/SoundRecorder/SoundRecorder.apk
It has Android.SmsSend.1947.origin malware.
Thanks!

r1kkman said:
Hello.
How can I remove this app from my Ulefone S8 Pro?
/system/priv-apps/SoundRecorder/SoundRecorder.apk
It has Android.SmsSend.1947.origin malware.
Thanks!
Click to expand...
Click to collapse
Is it from your phone manufacturer, i.e. part of official ROM? probably I guess, which means it will probably come back if you remove it, best to try disable it (maybe some other related apps also eg that do ota updates)
See link in this thread
https://forum.xda-developers.com/general/security/triada-aw-trojan-brand-ulefone-s8-pro-t3722886
Or try an app like debloater if you cannot root (to freeze/remove app)

Hi !
you should take the action, first of all, to delete malware quickly. if this is really a malware attack on your phone, it will damage various applications.

Related

Adware/Virus on Android

Hello
im facing an ad-ware issues on my htc desire 610
out of no where my phone's screen dims and an add appear (while im on my home screen and all the apps are closed)
You can see the adds in the attachment
please tell me how to locate and remove it
You could try running Malwarebytes, I've normally had quite good results with it.
It's one of the apps you're using. Go through the permissions your apps have
genius911 said:
Hello
im facing an ad-ware issues on my htc desire 610
out of no where my phone's screen dims and an add appear (while im on my home screen and all the apps are closed)
You can see the adds in the attachment
please tell me how to locate and remove it
Click to expand...
Click to collapse
i also have this problem... i guess "Clean Master" is doing it in my Z3 Compact.
I have solved this issue on canvas a116 and core duos (gt i8262)
firstly, to check the severity of the virus do this : go to settings>security>device administrators
try to remove all apps under device administrators. If u are unable to remove them implies the virus is now embedded to ur fone's firmware.
solution : 1. backup ur contacts and media only, (do not backup apps and app data)
2. now u need to do a factory reset either from recovery menu or using adb (factory reset from 'settings' wont work)
3. if u again see any app under device administrators then the only solution is to reflash ur firmware
About the virus: This virus come packed in several apps on playstore in april 2015, those apps were immediately removed from playstore. however before its removal from playstore the virus had infected around 5000 smartphones. some websites refer to it as ghosthost virus. Still some non playstore apps carry this virus with them. once you install such apps, the virus will first root ur fone, and then grant itself superuser permissions without u even knowing it. Then it will install itself into system folder so dat it appears to be a system app. Whenever u r connected to internet it will download adware and install them in system folder. Its a very powerful virus, it also hides itself by running a script. Once it is in system folder u wont be able to delete it because it imitates the file names of the system files.
There's a huge list of infected apps hosted by Google playstore. So I think it's not easy to keep our devices secure from virus infection.
AVG can be as correct the problem
Hi guys! i have a serious adware problem on my elephone p7000 and i hope you can help me out.
So it's been a few days and i haven't been able to uninstall this mofo.
Here's what the adware is doing:
-Used to open ads on homescreen. it did that disguising itself as a dancing matrioska doll (which you could move around). since i installed CM security it stopped showing this kinds of ads.
-It opens pop up windows with du batery saver or other related apps (from appstore and from non-official stores). Mostly when i browse the internet.
-it places vertical ad banners (like the normal ones on almost every app on the store) on some apps, it seems to be random, cause it doesn't always happen on the same app, but it's always placed on the lower side of the phone.
-it installs push notifications with ads
-i believe it shows app ads on google play store (i haven't installed any app in quite a while so it could be google implementing this).
i have tried a lot of apps:
-Avg
-Avira
-Avast
-Malwarebytes
-CM manager (found a stagefright vulnerability and fixed it)
-Stagefright detector (with vulnerable result)
-addons detector
-airpush detector
-trustgo ad detector
-adware
-ad clean & antivirus security
and not even has been able to remove this damn malware, they don't even spot it!
i've also tried looking for all the apps on the phone,searching for apps with all the permissions and here's the list ( i don't know if these are the problem or not):
-Aging test
-agoldFactory test
-Bluetooth
.Bluetooth Share
-Bluetoooth LE
-Common data service
-e_Compass
-Elephone launcher (apparently it's the same as X launcher mysterious)
-LocationEM2
-MTK THERMAL MANAGER
- at least 3 different phone apps, 2 with 4.4 icons and 1 with android 5.0 icon. all have access to everything (is it normal to have 3 apps with the same name but different icons? )
- settings storage
-trusted face
-ygps
i have also cleared the cache of the phone, because i've read on several places that it helps (settings -> storage -> clear cache data) but with no positive result.
i have also tried looking for admin permissions but the only things in there are CM security and android manager (which i suppose is NOT an app but part of the OS).
I have tried looking for hidden files while checking my phone on my pc but there wasn't any nor did i find any weird app NOT installed by me.
i don't know if you have any other advice on what to do, or if you can help me reduce this list of apps so i can find the culprit app.
i'm afraid this is the ghost virus everyone's talking about, it appeared out of nowhere.
i haven't browsed that much. and when i do i always go to trusted sources. apart from the netflix app which i downloaded a few days ago i haven't downloaded anything in like 1 or 2 months and didn't have this problem until a few days ago. Right after my girlfriend's phone (same model as mine) got the same problem.
We both had the "install from untrusted sources" option on because i was testing an app i am making, but i doubt that's the problem since we only activated it whenever i tried to install the app on the phone (like twice in a week).
she has sent me pictures or files through mail, whatsapp or telegram only and it's the only link between our phones, besides being under the same wifi connection, of course.
thanks in advance for the help!
This is a known issue with these types of devices. They have these ads built into the system apks.
Hi !
Thanks for that solutions !
I have a question : where could I find malwarebytes for android ?
Best regard.
Adware and infected htc desire 526 g plus
Guys I am in a pickle! :silly:
I want to wipe my HTC desire 526 plus clean of malware that is causing it to download unwanted apps without consent. The malware seems capable of modifying the inherent permissions and bypassing all security features.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
It can gain permission to automatically start wifi, gain pemission to install 'Unknown Apps' and sends location and data with impunity. The ads are everywhere.:crying:
I have tried stock backup but it still reinstalls all the malware and the same cycle begins again. What I want is a freash stock rom/nand backup for this menace. Surprisingly I still cant find one link on the world wide web. Please Help me find it.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
alokmey3 said:
Guys I am in a pickle! :silly:
I want to wipe my HTC desire 526 plus clean of malware that is causing it to download unwanted apps without consent. The malware seems capable of modifying the inherent permissions and bypassing all security features.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
It can gain permission to automatically start wifi, gain pemission to install 'Unknown Apps' and sends location and data with impunity. The ads are everywhere.:crying:
I have tried stock backup but it still reinstalls all the malware and the same cycle begins again. What I want is a freash stock rom/nand backup for this menace. Surprisingly I still cant find one link on the world wide web. Please Help me find it.
I am unable to gain root access by kingoroot alone. adware is not letting me update the Superuser app and being nasty on purpose.
Click to expand...
Click to collapse
Kingo root is the reason you are in this jam as it is. I don't think HTC ever released anything for this device so your best bet is to contact HTC.
ENERGYSER400 MTK 6572 virus help android 4.4.2
Bonjour, hy
For me it's exactly the same on my phone.... i have the snowfoxer folder with a lot of malicious apk on it and i don't know how to delete or erase the virus .... without wifi and google play ..... how i can flash the firmwire please
!
philjps said:
Bonjour, hy
For me it's exactly the same on my phone.... i have the snowfoxer folder with a lot of malicious apk on it and i don't know how to delete or erase the virus .... without wifi and google play ..... how i can flash the firmwire please
!
Click to expand...
Click to collapse
Find the forum that supports your device
model/carrier and post there. You'll likely find your answers there. If not someone will help you.
HTC desire 526G+ bricked
zelendel said:
Kingo root is the reason you are in this jam as it is. I don't think HTC ever released anything for this device so your best bet is to contact HTC.
Click to expand...
Click to collapse
I have deleted my priv-app folder and now I am stuck in boot loop, or just the HTC logo.
cant boot into recovery or bootloader (I tried). Tell me if you know something

Fotaupdate,malware ?

Hi,I have an android box and just done a scan with Malwarebytes.
It brought up this threat
Android/PUP.Riskware.Autoins.Fota
/system/app/FotaUpdateReboot
FotaUpdateReboot.apk
Is it genuine malware or a false positive ?
Cheers.
ascender13 said:
Hi,I have an android box and just done a scan with Malwarebytes.
It brought up this threat
Android/PUP.Riskware.Autoins.Fota
/system/app/FotaUpdateReboot
FotaUpdateReboot.apk
Is it genuine malware or a false positive ?
Cheers.
Click to expand...
Click to collapse
Looks like several firms are flagging it as malware on virus total, at least according to the following thread
https://forums.malwarebytes.com/topic/216168-pre-installed-malware/
Thanks for that.
Looks like the system app FotaProvider allows adverts to pop up in the browser,which is exactly the issue I've been having.
I've uninstalled it now.Have to see how I get on
Cheers
update
ascender13 said:
Thanks for that.
Looks like the system app FotaProvider allows adverts to pop up in the browser,which is exactly the issue I've been having.
I've uninstalled it now.Have to see how I get on
Cheers
Click to expand...
Click to collapse
HI.
Is everything fine after you deleted the fota provider?
Yes,that fixed it.
remove problem apps
How do you delete these unwanted system apps?
The main sources of malware are google play store, and wireless update (the system app)
both are pre-installed malware when you buy the device
mprox said:
How do you delete these unwanted system apps?
The main sources of malware are google play store, and wireless update (the system app)
both are pre-installed malware when you buy the device
Click to expand...
Click to collapse
If I remember correctly I just used a file manager with root access

anti virus

sup?
anyone has the name of the antivirus security BS of the stock rom? titanium backup is no help. myriads of xiaomi entries. wanna get rid of that snakeoil annoyance
thanks in advance
If you mean the "Security" app (which includes permissions, cleaner and antivirus etc), I'm not sure it can be disabled or removed as it seems tightly integrated with everything. I would also love to remove it all.
ias i know, this are the packages for "security" on XIAOMI phones -> com.miui.securitycenter / com.miui.guardprovider / com.miui.cleanmaster
the security patches are from AVAST, AVL and Tencend.
ATTENTION: If you remove this apps, your phone will crash!!!! DON’T DO IT!!! Only cleanmaster app could be frozen by adb command.
Buster99 said:
sup?
anyone has the name of the antivirus security BS of the stock rom? titanium backup is no help. myriads of xiaomi entries. wanna get rid of that snakeoil annoyance
thanks in advance
Click to expand...
Click to collapse
You can't remove it, it's an integral part of the system. One of the reasons why I can't wait for custom ROMs without this BS.
thanks
i tinkered a bit but this miui is worse bloatware than old sony stock roms.
yeah i am almost ready to sell it and go oneplus 8

Android and viruses

Hi everyone. Is It possibile to get a virus on an Android phone (Samsung S7) without installing any app?
Yesterday i opened for 2 seconds a likely malicious URL but then I rapidly closed It before the page's contents showed up. I haven't noticed any download.
Is It possibile to get a virus in this way?
I'd say you are probably safe. Do you have a file explorer installed? If so, check your Downloads folder & delete anything suspicious.
Short answer though, just opening a URL won't give you a virus.
Android has gotten better at protecting the is system...
chance is 1% you most likely visited scareware web or some unwanted ads, you dont have to worry about malware being installed just by visiting link
Please advise a good antivirus program for android
JohnMes said:
Please advise a good antivirus program for android
Click to expand...
Click to collapse
I am using ESET mobile security, it works well and has good results in antivirus tests

Question Can I stop google putting stuff on my phone without consent

So I'm tired of crap being added to my phone without my consent like Google one it was added recently to my phone and is really annoying when editing photos and now I got this cov*d alerts I really don't want this crap on my phone is there a way to remove them or prevent Google from adding it?
Unistall or disable it.
blackhawk said:
Unistall or disable it.
Click to expand...
Click to collapse
I can't I tried using a root uninstaller
ShadowFox141 said:
So I'm tired of crap being added to my phone without my consent like Google one it was added recently to my phone and is really annoying when editing photos and now I got this cov*d alerts I really don't want this crap on my phone is there a way to remove them or prevent Google from adding it?
Click to expand...
Click to collapse
Debloat/Disable System Apps
So you got your new shiny realme device but you hate bloatware or want to disable system apps so you can use 3rd party apps instead? Follow the steps below: THIS DOES NOT REQUIRE ROOT HOWEVER MAKE SURE NOT TO DISABLE IMPORTANT SYSTEM APPS. WIPE...
forum.xda-developers.com
^ Posted in the Realme 7 forum, but it works on every phone I've used.
Search up "package name viewer" on the Google Playstore to get an app that lets you see the name of packages.
OrthodoxOxygen said:
Debloat/Disable System Apps
So you got your new shiny realme device but you hate bloatware or want to disable system apps so you can use 3rd party apps instead? Follow the steps below: THIS DOES NOT REQUIRE ROOT HOWEVER MAKE SURE NOT TO DISABLE IMPORTANT SYSTEM APPS. WIPE...
forum.xda-developers.com
^ Posted in the Realme 7 forum, but it works on every phone I've used.
Search up "package name viewer" on the Google Playstore to get an app that lets you see the name of packages.
Click to expand...
Click to collapse
Thanks man I'll give that a try
ShadowFox141 said:
I can't I tried using a root uninstaller
Click to expand...
Click to collapse
This...
Home - Package Disabler
The only NON-root solution that let’s you disable any unwanted packages that come pre-installed / installed with your phone / tablet.
www.packagedisabler.com

Categories

Resources