Clarification of suspicious files. - General Questions and Answers

Have some suspicious files that keep appearing. I'm under heavy fire being hacked recently.
I've never noticed these before but they keep showing up in my download folder, folder: system_conifg, then file: system_file16844973xxxxx 32bytes
Anyone shed some light on these for me. Even after factory reset and even loading a different firmware.
Note 10+ unlocked snapdragon.

Don't believe everything you read on the Internet. You aren't being hacked, and those are normal files.

Oh I'm def being hacked, no question about that. Have police reports, breaking and entering,, theft, vandalism. Oh it's all tied together.
What exactly are those files for?

Related

GC and CC logs of Mozilla (Firefox ? ) consuming huge amount of space

I have previously posted this question in the Samsung S7 Edge section here http://forum.xda-developers.com/s7-edge/help/gc-cc-logs-mozilla-consuming-huge-space-t3397783 but didn't get any response. It is possible that the topic didn't get any attention as it is in the wrong section and I also feared that my problem could be due to malware and some other security bugs.
My problem started when I was suddenly told that my S7 is running out space without any new huge apps being installed. I tracked down the sudden lose of storage space to a folder named "memory-reports" inside the default Download folder. The folder content comprise multiple logfiles with each file sizes averaging 30mbs, and the number of files gradually increase and eventually hogging over 3gigs of storage space. I deleted the entire folder with the logfiles but the folder appeared again with similar logfiles.
after Googling around, I found the description of the logfiles here https://developer.mozilla.org/en-US/...GC_and_CC_logs. it seem to relate to Mozilla Firefox and I doubt this problem is specific to Samsung S7 Edge although this is the phone I am using now and the problem only occurred to me for the first time recently. couldn't find any mention of similar issue anywhere else via Google, but maybe some of you guys are better at digging them up. Seeking some comments, suggestions as to what cause, possible solutions...
NOTE: My phone is NOT rooted. the logfiles are still being generated periodically and have to be deleted to recover the space. deleting them don;t seem to affect the operation of any apps and especially FIREFOX, which is the only connection I can find with mention of those logfiles name with MOZILLA. The problem seem unique to me at the moment as I still couldn't find any reference on Google to them. Any head-up suggestion on possible reason and ways to track down exactly which apps, background process are generating the log files are certainly welcomed.
I am experiencing the same issue on my Motorola Nexus 6.
Thanks for this. I was facing the same problem. I just deleted the files. It didn't seem to hurt firefox. ]

Tencent Ransomware File?

I stumbled across a file on my S10+ that's peaked my interest; although it could be nothing it still serves a purpose of some kind and I'm not sure what.
I haven't noticed any symptoms of malicious software as of yet and none of my files have been encrypted, though I did recently have to re-flash stock firmware due to overheating issues and a plethora of errors in the dumpsys logs.
The file came along with Call of Duty Mobile, or is at least hiding in one of it's folders.
I haven't downloaded anything from Tencent in awhile due to privacy concerns, and now I've found this file which seems pretty suspicious. I've looked around online and can't seem to find anything, anyone have any idea on this?
SuperIronOut said:
I stumbled across a file on my S10+ that's peaked my interest; although it could be nothing it still serves a purpose of some kind and I'm not sure what.
I haven't noticed any symptoms of malicious software as of yet and none of my files have been encrypted, though I did recently have to re-flash stock firmware due to overheating issues and a plethora of errors in the dumpsys logs.
The file came along with Call of Duty Mobile, or is at least hiding in one of it's folders.
I haven't downloaded anything from Tencent in awhile due to privacy concerns, and now I've found this file which seems pretty suspicious. I've looked around online and can't seem to find anything, anyone have any idea on this?
Click to expand...
Click to collapse
The file you referenced is only 48 bytes; My initial impression is that whatever your phone uses to identify a file "type" (file signature? extension?) has likely collided with the same signature/extension that someone noted the referenced ransomware as having. I suspect this to be pure coincidence and not to represent any evidence of infection or threat to your device.
As always, if you have data that you care about on any device, make sure you keep backups in a safe, disconnected location.

Urgent: how to backup photos and contacts from a hacked Huawei P30 phone?

I have a Huawei P30 phone not rooted and never been in strangers hands.
Few months ago this crazy woman shared a fake video on my Facebook page. I clicked on it but won't open unless I installed a "flash plugin", obviously fake. I did it and the video won't open anyway. Few hours later she started to tease me about things I said privately to my friends via Whatsapp and Instagram, and in the following months she started insulting me with fake Instagram profiles every time I chatted privately with other girls, once making a clear reference to a picture I held in my private gallery.
I believe that the only way to get rid of this trojan/RAT is to factory reset my phone. But, considering I have more than 10 thousands photographies, 700 videos and 1500 contact numbers, I would like to save these datas, even manually.
To do this, can I 1) plug the hacked smartphone into my PC with a USB cable, while keeping them both OFFLINE, 2) then manually export contacts, photos and videos? Then 3) transfer these datas, always manually, into a brand new Iphone?
THANKS
A nice Russian girl
Rather sloppy not to keep backups and to wait even a day to purge that rootkit.
You could have other infected files on there now as well. Put it on a flash stick. Alternatively upload to cloud.
It needs to be scanned and even then there's malware that might evade detection. It could infect the PC as well if there's more hidden wuv packages. Malware jpegs are a terror, both Windows and Adroids are vulnerable to them... it only takes one. If present it/they must be deleted... thousands of images you say.
Oh my.
Reset all your passwords after the reload.
THIS IS DUPLICATE TO THIS THREAD:
My Huawei P30 has been hacked with a RAT! can I still save my accounts?
I have a Huawei p30 phone with last security patch received in august 2020, not rooted and never been in strangers hands. This crazy psycopath woman has been stalking me badly for a year, but then in september 2020 she shared a weird (fake) video...
forum.xda-developers.com
jwoegerbauer said:
THIS IS DUPLICATE TO THIS THREAD:
My Huawei P30 has been hacked with a RAT! can I still save my accounts?
I have a Huawei p30 phone with last security patch received in august 2020, not rooted and never been in strangers hands. This crazy psycopath woman has been stalking me badly for a year, but then in september 2020 she shared a weird (fake) video...
forum.xda-developers.com
Click to expand...
Click to collapse
LMAO, I'd been reloaded by now
jwoegerbauer said:
THIS IS DUPLICATE TO THIS THREAD:
My Huawei P30 has been hacked with a RAT! can I still save my accounts?
I have a Huawei p30 phone with last security patch received in august 2020, not rooted and never been in strangers hands. This crazy psycopath woman has been stalking me badly for a year, but then in september 2020 she shared a weird (fake) video...
forum.xda-developers.com
Click to expand...
Click to collapse
OK SIR, you can delete that one thread because at the time I lacked many informations that I gathered only now. Please delete that one, NOT this one.
blackhawk said:
LMAO, I'd been reloaded by now
Click to expand...
Click to collapse
LMAO, I can't reload until I know for sure how to save my photos, videos and contacts! I also work with my Whatsapp and Gmail profiles!
blackhawk said:
A nice Russian girl
Rather sloppy not to keep backups and to wait even a day to purge that rootkit.
You could have other infected files on there now as well. Put it on a flash stick. Alternatively upload to cloud.
It needs to be scanned and even then there's malware that might evade detection. It could infect the PC as well if there's more hidden wuv packages. Malware jpegs are a terror, both Windows and Adroids are vulnerable to them... it only takes one. If present it/they must be deleted... thousands of images you say.
Oh my.
Reset all your passwords after the reload.
Click to expand...
Click to collapse
I made a scan of all the content on the hacked phone with 1) Kaspersky full version and then 2) Panda security dome full version but nothing was found. Then I exported all my photo albums and videos with a usb cable on my PC, and repeated a scan on it with Panda dome. Nothing was found again. No weird jpegs were ever sent to me. Only that damn video which asked to download a fake flash plugin on my Huawei.
What if I finally transfer all this stuff into an APPLE IPHONE? will it be compromised too?
Columbus93 said:
I made a scan of all the content on the hacked phone with 1) Kaspersky full version and then 2) Panda security dome full version but nothing was found. Then I exported all my photo albums and videos with a usb cable on my PC, and repeated a scan on it with Panda dome. Nothing was found again. No weird jpegs were ever sent to me. Only that damn video which asked to download a fake flash plugin on my Huawei.
What if I finally transfer all this stuff into an APPLE IPHONE? will it be compromised too?
Click to expand...
Click to collapse
Ideally you would have wiped everything on the phone and restored from known good backups.
iPhones are not impervious to malware.
Depends how resourceful and determined your hacker is. All that social media crap will be your undoing. You're wide open and an easy target.
Columbus93 said:
LMAO, I can't reload until I know for sure how to save my photos, videos and contacts! I also work with my Whatsapp and Gmail profiles!
Click to expand...
Click to collapse
Depending on what's been loaded the hacker could do all kinds of nasty stuff.
You're going to be enchanted if the reload gets infected too... the more time you wait, the more potential for greater damage.
We're just strangers on the internet... do you see a pattern here?
I do.
blackhawk said:
Ideally you would have wiped everything on the phone and restored from known good backups.
iPhones are not impervious to malware.
Depends how resourceful and determined your hacker is. All that social media crap will be your undoing. You're wide open and an easy target.
Click to expand...
Click to collapse
my hacker just want to do me wrong and give me a hard time with insults, humiliations etc because she is a stalker psychopath who has been refused by me.
So, you are suggesting me to lose all my social media and more than 10.000 photos because a stalker psychopath decided to do so? No defence, no strategy against such a threath? I knwo social media is basically ****, but the sole idea to let this psychopath win because she decided so is unaccettable for me.
blackhawk said:
Depending on what's been loaded the hacker could do all kinds of nasty stuff.
You're going to be enchanted if the reload gets infected too... the more time you wait, the more potential for greater damage.
We're just strangers on the internet... do you see a pattern here?
I do.
Click to expand...
Click to collapse
Dude I understand, but WHAT can I do? Delete everything while not even trying a backup? yesterday I even saw some strange notification about my phone having just been being link to google Chromcast.. beside I was at work, and never had Chromcast installed and nobody has in my house ! I just want to save my 10 thousands pictures before to thrash my phone!
Do what you want... dude.
You screwed up by not backing anything up for how long? Ever?
So save the data and hope for the best.
I have over a dozen hdds I use for backup in different locations. My phone SD card is redundantly backed up with 3+ copies on different hdds. All are offline.
The time to do something was before this happened... first mistake.
Second mistake, still using the device with known malware on it.
If found something like that on my phone this morning by now it either be gone or the phone be reloaded.
blackhawk said:
Do what you want... dude.
You screwed up by not backing anything up for how long? Ever?
So save the data and hope for the best.
I have over a dozen hdds I use for backup in different locations. My phone SD card is redundantly backed up with 3+ copies on different hdds. All are offline.
The time to do something was before this happened... first mistake.
Second mistake, still using the device with known malware on it.
If found something like that on my phone this morning by now it either be gone or the phone be reloaded.
Click to expand...
Click to collapse
I know that I screwed up by never backing anything up.. hard lesson learned. But it's like a month and nobody, not even professionals, could tell me how to safely backup my stuff before to wipe everyhting out! This hacker is owning my phone by such a long time before I could understand what had happened that she literally had time to backup herself ALL my stuff, even the smallest details in my life! I even had to block my bank accounts!!! Anything worse than that?
All the worse already happened, that's the problem. And considering that, I feel like I have nothing to lose anymore, so I just want to pick all my personal stuff or at least my accounts and savely bring them into another phone, that I just bought. An iphone 12. But looks like a complicated math equation to export stuff from a hacked phone into another phone!
What If I reboot this hacked phone with safe mode, and I transfer all my stuff and files in this mode? No trojan should be active in safe mode, isn't it?
I already told you, a flash drive... I would use two and make 2 backup copies.
Confirm the data is complete and readable on the flash drive(s) before wiping phone.
See what happens on the new load before and after the old data is reloaded.
A month? Jeeeesze... stop screwing around.
@Columbus93
Pulling data of interest only is possible if
Phone's Android's USB-service mode is set to adb,mtp
Phone is OTG capable and/or phone's Android is ADB enabled
I have no idea how to do that
jwoegerbauer said:
@Columbus93
Pulling data of interest only is possible if
Phone's Android's USB-service mode is set to adb,mtp
Phone is OTG capable and/or phone's Android is ADB enabled
Click to expand...
Click to collapse
I'm sorry but I have no idea how to even control if these options are enabled. I just enabled developer options and entered developer menu but I don't know how to check these options.
Some steps for your reference.
1. Make sure that your Windows PC has both the latest Windows updates and a strong enough security software installed.
2. Connect the P30 to your PC in order to make a full data backup.
3. Reset your P30( Factory Reset + Wipe Cache Partition ).
4. Reset the passwords of your social network apps ASAP.
5. For the data backed up from the mobile phone, or even the entire Windows PC, run a full security scan.
Columbus93 said:
I have a Huawei P30 phone not rooted and never been in strangers hands.
Few months ago this crazy woman shared a fake video on my Facebook page. I clicked on it but won't open unless I installed a "flash plugin", obviously fake. I did it and the video won't open anyway. Few hours later she started to tease me about things I said privately to my friends via Whatsapp and Instagram, and in the following months she started insulting me with fake Instagram profiles every time I chatted privately with other girls, once making a clear reference to a picture I held in my private gallery.
I believe that the only way to get rid of this trojan/RAT is to factory reset my phone. But, considering I have more than 10 thousands photographies, 700 videos and 1500 contact numbers, I would like to save these datas, even manually.
To do this, can I 1) plug the hacked smartphone into my PC with a USB cable, while keeping them both OFFLINE, 2) then manually export contacts, photos and videos? Then 3) transfer these datas, always manually, into a brand new Iphone?
THANKS
Click to expand...
Click to collapse
Huaweis hisilicon chips have huge root security issues xd.
Lmao maybe one of the zero day exploits imparted in this? Who knows
Columbus93 said:
I have no idea how to do that
I'm sorry but I have no idea how to even control if these options are enabled. I just enabled developer options and entered developer menu but I don't know how to check these options.
Click to expand...
Click to collapse
For HUAWEI devices the HiSuite utility exists with which you can transfer files from phone to computer.
All you have to do is to activate on phone USB Debugging and additionally turn on HDB.
James_Watson said:
Some steps for your reference.
1. Make sure that your Windows PC has both the latest Windows updates and a strong enough security software installed.
2. Connect the P30 to your PC in order to make a full data backup.
3. Reset your P30( Factory Reset + Wipe Cache Partition ).
4. Reset the passwords of your social network apps ASAP.
5. For the data backed up from the mobile phone, or even the entire Windows PC, run a full security scan.
Click to expand...
Click to collapse
Thank you sir, you're precious. You're all being precious. One redundant question since I'm passing from my Huawei hacked phone to a brand new apple Iphone 12. At first boot time, It asks me the possibility to export selected datas from a PC or Android phone, by using an app called "switch to iOS". Can I also do that or is it better doing the whole manual thing we're talking about, avoiding such "in app" data transfers?

Question Worth rooting phone to attempt photo recovery?

First of all I know I'm really stupid for doing this, I blame sleep deprivation.
2 days ago I imported all the photos from my z flip 3 to my ipad. After completing the import I used the option at the end of the import to delete off the phone. Found out tonight that the imported photos were only at ~400x400px.
Now I can't find the photos anywhere on the phone.
I have checked the recycle bin/trash in the photos and files apps but there is nothing in there. I have also tried Tensorshare Ultdata recovery, but no luck with that either. https://www.tenorshare.com/products/android-data-recovery.html
Would it be worth rooting the device to allow for a deeper scan of the file system, the phone is completely stock currently. If not is there anything else I can try or should I take it to a data recovery company?
Thank you taking the time to read and for any assistance you can share.
ghostgundam742 said:
First of all I know I'm really stupid for doing this, I blame sleep deprivation.
2 days ago I imported all the photos from my z flip 3 to my ipad. After completing the import I used the option at the end of the import to delete off the phone. Found out tonight that the imported photos were only at ~400x400px.
Now I can't find the photos anywhere on the phone.
I have checked the recycle bin/trash in the photos and files apps but there is nothing in there. I have also tried Tensorshare Ultdata recovery, but no luck with that either. https://www.tenorshare.com/products/android-data-recovery.html
Would it be worth rooting the device to allow for a deeper scan of the file system, the phone is completely stock currently. If not is there anything else I can try or should I take it to a data recovery company?
Thank you taking the time to read and for any assistance you can share.
Click to expand...
Click to collapse
rooting it would format data, which in turn would generate new encryption key when you boot next time so you would be in even more of a mess sadly, if you didnt have online backup taking it to data recovery company might be your best choice
Thank you very much for the reply and advice, I dived a bit deeper and it turned out that the import was successful, there was a duplicate thumbnail image that was showing first.
Sounds like you solved it, but having gone through some fun data loss in the past, I wanted to leave this here for posterity.
If you need to recover data, do not root. Do not reboot. Do not delete or add anything unnecessary. The best results come from doing the least. When an image is deleted, it is similar to tearing up a physical photo and throwing it in the trash. The data still exists, but can be fragmented. The more you do, the more likely some or all of that data will be overwritten and become unrecoverable.
After searching through about 100 different recovery programs, I had the best results with https://play.google.com/store/apps/details?id=com.defianttech.diskdigger
It is the equivalent of the recovery programs for a computer, so it will show you thumbnails from that Facebook account of the ex you stalked 6 months ago in the results. It will also find almost anything that was deleted through normal means. Last time I used it personally was a couple years ago, but the reviews seem to imply it is still pretty effective.
Similar to what you described, you will also end up with a lot of thumbnails and previews. The easiest way to handle that is to run all of it through https://dupeguru.voltaicideas.net/ with the Picture option and the setting to "Match pictures of different dimensions" enabled. This will group all of the thumbnails and the originals to let you get rid of the junk.
Disclaimer: This is only personal preferences. I am a professional, but both apps listed in this post were downloaded free and used without any premium or paid features. This is not a sponsored suggestion.

Question Lost photos that are not in cloud or trash can.

Please help. Long time user but havent been on in forever.
Story.
My S22 ultra was giving me warnings for being close to full on the memory. I had to have Google backup off for work reasons, work provided phone. I normally use Android file transfer and make copies on a Mac computer.
The usb was giving my fits and i couldnt connect. I ended up using a Windows pc and i started coping over my pics. The windows track pad glitched and i deleted the new file and the old file on both the PC and the S22. My Camera folder was missing on the S22 where the phone default saves.
Ive tried a bunch of the data recovery apps and none work. I have read you need root to be able to see the delete files as they stay on the device until over written.
Is there truth to needing root to see the deleted files. I havent rooted a device in probably close to 10 years so the easiest method would be awesome.
Thanks in advance and please excuse my cluelessness im a bit rusty.
The files are lost especially if you ran out of memory; likely overwritten by now.
Always copy/paste to backup.
Keep work and personal phones separate.
In lieu of expandable storage use a OTG flashstick in the future. Thank Samsung for taking away your easiest, most sane option... on a flagship none the less.
radiofoneguy said:
have read you need root to be able to see the delete files as they stay on the device until over written.
Click to expand...
Click to collapse
There is no guarantee that with root you'd be able to recover lost files. You only have a better chance.
radiofoneguy said:
Is there truth to needing root to see the deleted files. I havent rooted a device in probably close to 10 years so the easiest method would be awesome.
Click to expand...
Click to collapse
To root, you need an unlocked bootloader first.
If you unlock your bootloader, the process will wipe everything on your device. So you need to backup whatever files you have before proceeding with the unlock process, i.e. you have no chance of recovering already deleted files.
How come your files in PC that were deleted aren't in the recycle bin?
TheMystic said:
How come your files in PC that were deleted aren't in the recycle bin?
Click to expand...
Click to collapse
It happens from time to time. When it happens if the source file is gone so is the data, unrecoverable.
That's why you always copy/paste rather than cut/paste critical data. Delete the source file only after the transfer is verified.
blackhawk said:
It happens from time to time.
Click to expand...
Click to collapse
If recycle bin is enabled, it should not happen.
blackhawk said:
That's why you always copy/paste rather than cut/paste critical data. Delete the source file only after the transfer is verified.
Click to expand...
Click to collapse
100% true.
So the files disappeared because he was cut-pasting them, and not 'deleted' as he wrote. Now I understood what actually happened.
Yep nothing in any recycle bins. I was able to recover all the files on the PC side but they are corrupt and won't open. I've used several different programs to recover and to fix the corrupt files. I normally triple and quadruple backup everything. I used to test devices so i was constantly swapping SIMs so I used to save all the time. The program ended and I've been on this s22 since it came out and I became complacent with updating. It sucks a wipe is needed. I was hoping the files were just hidden like PC and Mac when deleted and easily archived. Thanks for the comments, I learned a hard lesson and I knew better.
TheMystic said:
If recycle bin is enabled, it should not happen.
Click to expand...
Click to collapse
That won't save you if the file is lost during transfer. Seen it happen enough to know.
It's different from deleting a file with the trash bin active. You need to be careful of that with critical data.
Never clone media files ie discs, partitions either, always copy/paste. Cloning or compacting media like .wav files can toss the null marks and they are needed and functional in that context.
Never encrypt data drives... as you are the most likely one to get locked out.
blackhawk said:
That won't save you if the file is lost during transfer. Seen it happen enough to know.
It's different from deleting a file with the trash bin active. You need to be careful of that with critical data.
Click to expand...
Click to collapse
Like I said, he didn't explain properly.
I have lost files too with a cut-paste, so I'm aware of this problem.
This is why on macOS, they don't give you a 'cut' or move (except move to bin) option, but only 'copy'. Those who are absolutely sure they need to cut will have to use the 'Option' key to make it show up.
radiofoneguy said:
Yep nothing in any recycle bins. I was able to recover all the files on the PC side but they are corrupt and won't open. I've used several different programs to recover and to fix the corrupt files. I normally triple and quadruple backup everything. I used to test devices so i was constantly swapping SIMs so I used to save all the time. The program ended and I've been on this s22 since it came out and I became complacent with updating. It sucks a wipe is needed. I was hoping the files were just hidden like PC and Mac when deleted and easily archived. Thanks for the comments, I learned a hard lesson and I knew better.
Click to expand...
Click to collapse
Always leave enough head room on Android internal memory. It can putt along like that for a while with just warnings until one day... boom.
If you're seeing warnings you're cutting it way too close. Leave at least 10% headroom. Lol, I played that wicked game with my S4+, 16gb isn't much.
Samsung should have a base starting at least 256gb internal memory in this day and age especially if they were rude enough to drop expandable storage. Since the N10+ I haven't been pleased with the Samsung flagships; they all have multiple issues. As such I haven't bought any. Samsung continues their ball dropping fest unabated. Here Sammy this Bud's for you
blackhawk said:
Always leave enough head room on Android internal memory. It can putt along like that for a while with just warnings until one day... boom.
If you're seeing warnings you're cutting it way too close. Leave at least 10% headroom. Lol, I played that wicked game with my S4+, 16gb isn't much.
Samsung should have a base starting at least 256gb internal memory in this day and age especially if they were rude enough to drop expandable storage. Since the N10+ I haven't been pleased with the Samsung flagships; they all have multiple issues. As such I haven't bought any. Samsung continues their ball dropping fest unabated. Here Sammy this Bud's for you
Click to expand...
Click to collapse
I was bummed about not having an SD reader. I didn't know it was gone until 4 days ago.

Categories

Resources