Need help with infected Galaxy s21+ ultra (a11, unlocked, rooted) - Security Discussion

A while back I was quite under the influence and installed some kind of malware that infected my phone and desktop (I wish i could remember how I did that).
While I recovered my desktop, the phone is another story - at first it was unrooted+locked when the infection happened but since factory resets or flashing ROMs didn't help I decided to root and hopefully somehow save the phone. So:
1) Factory reset does nothing - phone comes back with 400+ system apps with A LOT of permissions that I dont think these apps should have (pretty much everything)
2) I can use ADB to uninstall a lot of this stuff but it persists - there are several apps that lock and softbrick the device if I uninstall them
3) I haven't rooted in ages, wasn't planning on doing it - the infection forced me to. As such I can only guess about what most of these system packages do or whether its backdoors, dummies or some spyware.
4) Flashing a ROM found by Frija didnt help, flashing Ketans ROM didnt help
5) Seems it killed my screen as well or its just coincidence, phone works, touchscreen works but the actual screen stays 100% black and doesnt display anything. I have some control on the phone via DEX.
If someone could help me with cleaning up the phone I would be very grateful - if you help me 100% purge the phone, im offering £25 reward.

Sounds like you need the full factory rom reinstalled. Or maybe (I haven't used Samsung for a while) Samsung SmartManager can find malware files etc and fix without reflashing the full rom?

Related

Rooted Tablet went bad...

I rooted my Samsung Galaxy Tab Plus 7.0 tablet with the tutorial from this site:
http://forum.xda-developers.com/showthread.php?p=24736900
It worked just fine for a couple days, then today I powered up the tablet and when I unlock it, it shows a problem loading all widgets, and within a few seconds the screen goes black, then proceeds back to the unlock screen. I unlock it again and this keeps repeating.
I didn't hack anything else, just installed superuser and a couple of other root apps. Really I haven't done anything else to cause this.
I don't even have enough time to go into settings and do a factory reset.
Any ideas? Perhaps in recovery?
EDIT - I did a factory reset in recovery. Is this going to fix it back to normal? I probably won't root ever again.
It probably has no affect, but what root apps did you install?
superuser, busybox, adfree, rom toolbox (which couldnt even detect my root but I never tried anything else)... those I can remember...
Did you install CWM and do a backup?
Im not sure what that acronym is for. I am new to all this. I followed the simple instructions in that tutorial and that was it.
It seems the issue is gone since my factory reset.
I am not sure if the root is still there however.
If there are extra steps to be done after a root it would help to have them with the tutorial....
A factory reset will remove root from your phone. Rooting it in and of itself should cause no issues like you are having it has to be something you installed and I would suspect ROM Toolbox. I'm not sure this app supports teh GTab+ or even has any useful purpose for us as we have no real ROMs to flash. It also contains a ROM Manager and if its the same one by Koush then it will defintely screw up our tablets.
repo97 said:
I rooted my Samsung Galaxy Tab Plus 7.0 tablet with the tutorial from this site:
http://forum.xda-developers.com/showthread.php?p=24736900
It worked just fine for a couple days, then today I powered up the tablet and when I unlock it, it shows a problem loading all widgets, and within a few seconds the screen goes black, then proceeds back to the unlock screen. I unlock it again and this keeps repeating.
I didn't hack anything else, just installed superuser and a couple of other root apps. Really I haven't done anything else to cause this.
I don't even have enough time to go into settings and do a factory reset.
Any ideas? Perhaps in recovery?
EDIT - I did a factory reset in recovery. Is this going to fix it back to normal? I probably won't root ever again.
Click to expand...
Click to collapse
I have done this ROOT like a million times (i'm a flash junkie)... testing the CM9 roms and back to stock again.. never had an issue with ROOTing the stock ROMs..
Suggest you download the latest firmware for your device and flash using ODIN and factory reset. Repeat the flash & factory reset a few times
Maybe you have the wrong clue of what your problem is. To root your tab is just a matter of put a binary called "su" on a directory on your PATH, usually /usr/bin and set it with proper permissions. This binary gives you superuser powers, but there's nothing on it or at least in the process that installs it that makes it interfere in anything without being called.
So accidentally you did anything that went wrong or any of programs that requires root did.
Sent from my GT-P6210
kzoodroid said:
A factory reset will remove root from your phone. Rooting it in and of itself should cause no issues like you are having it has to be something you installed and I would suspect ROM Toolbox. I'm not sure this app supports teh GTab+ or even has any useful purpose for us as we have no real ROMs to flash. It also contains a ROM Manager and if its the same one by Koush then it will defintely screw up our tablets.
Click to expand...
Click to collapse
Sorry for taking a bit to reply, havent had the chance to get much PC stuff done lately.
Aaah so you think it was the culprit.... its wierd because when I tried to run the rom toolbox it shown that my tab was not rooted.
Then the problems started... as in my tab was rebooting itself and was stuck in a loop.
I did do the factory reset and then used a root checker and noticed it shown as no root access.
I have read that a factory reset does not remove root... are you sure it does completely?
I'd hate to go through another reset as I have set everything up again.
The only bug I have noticed so far with my tab is that the odd app (so far market and dolphin browser) at times I am unable to go back a page... the page just kind of flashes and stays on that page but does not go back. I end up having to restart the app.
Should I reflash with latest firmware and do a factory reset?
If so... I found this site, shall I use these instructions and firmware?
http://www.androidauthority.com/galaxy-tab-7-0-plus-p6200-update-ddkl2-honeycomb-3-2-firmware-45993/

[Completed] [Q] I Factory Reset my Rooted Huawei Y220

Hello again in need of assistance asap.
I have a somehow minor problem with my phone. I decided to factory reset my rooted huawei y220 because
-All of a sudden I can't access websites like:
>facebook.com
>yahoo.com
>gmail.com
I also can't access their mobile sites. I can't access the said websites from any browser from my phone at the time(Stock browser & Dolphin Browser). There is no problem with my internet connection since I am able to access these websites from my laptop and other handheld devices.
FORTUNATELY, I stumbled upon a browser named UC MINI. I can somehow access these websites but only if I am using its feature call "Speed Mode". If I switch that off I can't access the said websites.
I also factory reset my phone because a person from XDA told me that unfortunately, there is no compatible Custom ROM with my phone.
I don't know why didn't I just Unroot my phone with Kingo Root(The program I used to root my phone). And I also wanted to start from a clean slate and since I deleted the bloatware using titanium backup.
After rebooting from the factory reset I noticed SuperSU was left behind and it said that "There is no SU binary installed, and SuperSU cannot install it This is a problem!" Why is that? I did my research that if you factory reset your phone with a custom rom it will cause problems(?) Well fortunately I wasn't using a Custom Rom and I checked my phone with root check to check it whether it is rooted, it isn't rooted anymore after the factory reset.
My doubts are:
>What is causing my phone from accessing these websites(And probably more)
>Is it a virus?
>Did I touch something with the system that made it faulty?
>I was kind of playing around with ROM Installer with the bootloader thing because I thought it would change the boot animation of my phone to something else.
>Is it okay if I root my phone again and see whether the SuperSU issue is fixed and the browsing thing fixed.
My Huawei Y220-U10 is working a smooth as new right now. Actually a bit faster than when I got it fresh because I uninstalled some bloatware when it was still rooted. My real concern is the connectivity issue and the SuperSU issue.
Hope to hear from you guys asap,
Jom
Hi,
I found this guide about factory reset for your phone, hope it is helpful.
As for the apps you are having trouble with, suggest deleting, doing a fresh install, and rebooting.
Not likely a virus.
Yes, if you root again you should regain superuser access... please note that superuser works on some devices and super su works on others.
As a reminder, we are happy to help when we can, as best we can- we are not here for troubleshooting issues.
Good luck !!

[Q] Setup Wizard Fails - Need to Restore Rooted Kitkat to Verizon factory default

So I have an old Galaxy S3 that I was playing around with, trying to figure out some basics to rooting, as I've never done it before. (I now have a new Galaxy S5 that I'd like to eventually root, but I figured if I was going to brick anything, it would be this older S3).
It has the stock Android 4.4.2 image on it.
After reviewing a number of forum posts on XDA and elsewhere, I've learned that this has a locked bootloader that hasn't been cracked. So, I decided to first try the easy route, and installed Towel Root.
After successfully rooting the phone, I uninstalled some apps that I probably should not have uninstalled, because now when I go to do a factory reset, the setup wizard allows me to select my language (English), but then fails with "Unfortunately setup wizard has stopped."
When I hit OK, I do get dumped out into the home screen, and the phone seems like its mostly (if not fully) functional, minus the apps that I removed which I shouldn't have removed.
So... is there any way of fixing this?
Bump
Moogly507 said:
So I have an old Galaxy S3 that I was playing around with, trying to figure out some basics to rooting, as I've never done it before. (I now have a new Galaxy S5 that I'd like to eventually root, but I figured if I was going to brick anything, it would be this older S3).
It has the stock Android 4.4.2 image on it.
After reviewing a number of forum posts on XDA and elsewhere, I've learned that this has a locked bootloader that hasn't been cracked. So, I decided to first try the easy route, and installed Towel Root.
After successfully rooting the phone, I uninstalled some apps that I probably should not have uninstalled, because now when I go to do a factory reset, the setup wizard allows me to select my language (English), but then fails with "Unfortunately setup wizard has stopped."
When I hit OK, I do get dumped out into the home screen, and the phone seems like its mostly (if not fully) functional, minus the apps that I removed which I shouldn't have removed.
So... is there any way of fixing this?
Click to expand...
Click to collapse
I'd suggest re flashing the 4.4.2 NE1 firmware. That should solve your problem. I'd suggest using Odin
Sent from my Nexus 5
Thanks.
I downloaded 4.4.2 from 2 different sources, and the md5sum were different for each, so I knew that at least 1 of them was either the wrong firmware or corrupted in some way.
After further research, I realized I could download Kies 3 onto my Windows computer (official Samsung software), and run a factory reset / image upgrade directly from the computer. I decided that was the safest method.
And it worked!

Stuck in a bootloop + CWM question

Edit: Solved, see bottom
ROM (D6633_Customized HK_1290-5630_23.4.A.0.546_R6C_HK_SuperSU2.46_XZDR2.8.21-signedv2)
Bit of a dumb move on my part. It all started when my snapchat stopped working, I updated, and then Titanium Backup wouldn't restore the data properly (giving me "parse error"). I was trying to fix that and read online that sometimes this is caused by improper permissions, so I booted into recovery mode, couldn't find the option, but somehow decided "hey, maybe my root permission (?) is wrong slash it's 6am and I just watched a wild 2016 election end" and I hit the button. Now my phone is stuck in a bootloop.
So my question:
1) What exactly does re-root phone do (in CWM), and why would that have messed me up? Is it because I have a pre-rooted rom?
2) I wiped cache and delvik and it doesn't help
3) How do I fix this? I was thinking of loading a SuperSU zip on the SD card from my computer and flashing that, assuming somehow a corrupted root is at fault. I can't seem to get the thing in ADB mode as a side note.
3b) If that seems like a good idea, does it matter what one I use?
4) If I reflash the ROM, it should keep my apps and stuff, ya? I don't actually care if my phone is crippled, I just need it to work long enough to properly back up some media, and mainly get my whatsapp over to my new SIM card. If I can't get in it's forever stuck on my old number which I don't have the SIM for anymore.
Any help would be GREATLY appreciated.
Edit: I don't know how to delete this. Anyways, with other resources I found out that because I used a pre-rooted ROM, there were issues with using CWM to try to do the rooting with its built in functions, softbricking the phone. Reflashing the original pre-rooted ROM worked fine.

Com.jui.services?

I purchased new Galaxy S+ before couple of days. I keep receiving a pop up saying "com.jui.services, This app may be harmful installation not recommended". I couldn't find such app in app list or anywhere. All installed apps were downloaded from playstore, resetting the phone to factory defaults didn't help.
Update: I scanned the device using Eset Antivirus, it found that some system apps are effected by android/gorilla malware . Is there a way to remove it?
Same issue
i got Galaxy Note 8 from china, i have this thing popingup every 10 minutes, i have no idea what it is
Do a full flash with odin
I have same issue and don't know how to remove it? Do you fix it?
If you buy your phone from china, they tend to use a modified version of a rom, like put in ad's so when you browse you will get a popup and they get eventually a little money on the side too till you figure out how to remove it. Best way to fix this issues is find you stock rom from XDA and flash it with odin so you wont be stuck with there modified version rom and start out clean ( a full wipe so make backup of images, muziek, data )

Categories

Resources