New Adware / Malware in populair apps - Xperia Z5 General

Anyone saw this?
ht tps://blog.lookout.com/blog/2015/11/04/trojanized-adware/
This looks like real nasty stuff..
You'll use a AV?
Sent from my E6653 @ XDA Portal

Duvel999 said:
Anyone saw this?
ht tps://blog.lookout.com/blog/2015/11/04/trojanized-adware/
This looks like real nasty stuff..
You'll use a AV?
Sent from my E6653 @ XDA Portal
Click to expand...
Click to collapse
Actually it uses old exploits, so Z5 won't affect.
Also Sony uses dm-verity and ric, which prevents virus from modifying system even if virus got root privilege.

Related

Battery update

Hi!
Does anybody know what this battery update is. I got it as an update and to unlock the full features, I had to pay 3€per month!
I immediately unistalled this.
Is it spam? Virus!
Best regards
Sent from my GT-N7000 using Tapatalk
What are you referring to? No link.
It sounds suspicious though.
It came like a system update and then it installed a battery app that monitored my battery behavior and wanted me to pay 3€ per month ;-)
This is the first time I see something like this on my android phones!?
Sent from my GT-N7000 using Tapatalk
I've never heard of anything like that. It does sound very suspicious.
As you say, probably scareware/malware.
Now I have to look for an app to remove what ever is doing this ;-)
Sent from my GT-N7000 using Tapatalk
It is probably related to an app you have already installed. Go through any apps you aren't sure are from trusted sources/devs.
Thanks for the tip, I will check my apps. All my apps are from market place, its sad if we cannot trust the market?
Regards
Sent from my GT-N7000 using Tapatalk
The sad thing is mate you can't trust the market. You have to be careful what your installing!
Always check what permissions needs the app you are downloading depends of the type you dl it should need the right permissions. So lets say you dl a game and it needs permission for your contacts and call services then it is up to you to dl it I would never. And as long the developers have no other way to get cash they implant ofc in their apps some advertises so be carefully all the time.
And market is like Facebook a no money platform that helps people to find things, but it moment check what it provides, it is on the user to report bad apps. So many people abuse that.
Sent from my GT-N7000 using XDA App
Thanks a lot, I will try to be careful, and read before accepting anything this time.
Regards
Sent from my GT-N7000 using Tapatalk
Are you serious?
Lol that's one of the scammiest things I've ever heard of.
If I were you I'd factory reset, and in future only install well reviewed and tested apps.
Sent from my GT-N7000 using Tapatalk
As a rule of thumb, I don't click on any links from any app, except the browser
I use a program that lets you assign permissions to any app. Anything that I install that I don't think needs to access contacts, location etc, I just block.
It has a side benefit of blocking the stupid ads in the apps also.
Try to use "LBE privacy guard" from the market its free!
NEED ROOT!
With this app u can control every app u installed give and take permissions!
https://market.android.com/details?id=com.lbe.security.lite&feature=search_result#?t=W251bGwsMSwxLDEsImNvbS5sYmUuc2VjdXJpdHkubGl0ZSJd
I had one of these updates in my notification menu. Never installed it though.
Sent from my GT-N7000 using XDA App
I get this when I play certain games.
its just an in game advert made to look official which links to an app in the market.
It reads something like " You have two Battery updates available"
Download addon detektor then you can see whats causing the the push ad
And remove that battery thingy its probably the one that steals your contacts for spam
MikeFRG said:
Try to use "LBE privacy guard" from the market its free!
With this app u can control every app u installed give and take permissions!
https://market.android.com/details?id=com.lbe.security.lite&feature=search_result#?t=W251bGwsMSwxLDEsImNvbS5sYmUuc2VjdXJpdHkubGl0ZSJd
Click to expand...
Click to collapse
It requires root for full features.
equalness said:
Hi!
Does anybody know what this battery update is. I got it as an update and to unlock the full features, I had to pay 3€per month!
I immediately unistalled this.
Is it spam? Virus!
Best regards
Sent from my GT-N7000 using Tapatalk
Click to expand...
Click to collapse
Unfortunately you have been hit by a 'Scareware' attack.
As Android is becoming more popular and unlike Apple which has tighter control the Android OS is much more open to attacks such as this.
You really have to be on your guard watching for these malicious attacks.
Read the comments from PCWorld and 2Viruses for a greater explanation.

Anti virus

Does anybody run a anti virus scanner on their phone.. if so which one...
Sent from my X10 using xda app-developers app
I use Lookout sometimes
That said, as long as you check what permissions the apps you're installing are asking for, you're fine
I mean, an RPG game does not need access to your contacts or permissions to send SMS messages
The best antivirus in the end, is an observant end user
Sent from my PG06100
I use Comodo which I also use on my home computer. It does a lot more than just scan apps. I love it and its free.
Sent from my X10 using xda app-developers app
I use lookout and it works great for me. Scans everything i download and backs up contacts. Also has good locate and scream case you lose it and will save last location before your phone dies. But as Cnexus said being observant of what you download is your best protection. Hope this helps!
Sent from my PC36100 using xda app-developers app
CNexus said:
I use Lookout sometimes
That said, as long as you check what permissions the apps you're installing are asking for, you're fine
I mean, an RPG game does not need access to your contacts or permissions to send SMS messages
The best antivirus in the end, is an observant end user
Sent from my PG06100
Click to expand...
Click to collapse
I agree %100 with the Observant end user.I've never used antivirus on my phone,just another app to lag it down,lol.
Diablo67 said:
I agree %100 with the Observant end user.I've never used antivirus on my phone,just another app to lag it down,lol.
Click to expand...
Click to collapse
Just what I was thinking.. I only DL from the play store and here...
Sent from my X10 using xda app-developers app
Not advocating piracy, but if you pirate apps that have been cracked then an AV is a good choice. But as the second post the best av is you paying attention to what the app accesses.
Sent from my Nexus 10 using xda app-developers app
Watch the permissions when you install and steer clear of skecthy sources.
I use web root secure anywhere. It has turned up some Trojans in some ROMs which kind of blew me away. I thought everything on xda was safe.
Sent from my Nexus 7 using xda app-developers app
Has anyone actually gotten a virus on android?
Sent from my T.A.R.D.I.S
motoelliot said:
Has anyone actually gotten a virus on android?
Sent from my T.A.R.D.I.S
Click to expand...
Click to collapse
Well to begin with, the fact that android is based on Linux makes it even harder to exploit because of the whole permissions structure
On top of that you have the Android app permissions system and you have something very difficult to exploit in itself....I've never gotten one, but I've heard of malicious apps getting released (on the play store) back in the baby stages of Android (when froyo was just out) that used the froyo rooting exploits to bypass security checks and mess with the stuff on your phone.
But other than that, I've never heard of a any virus/exploit/targeted attack on android devices
The latest Android virus that I know of is BadNews.. It hit a few apps a few days ago, in the google play store. I believe it infected something like 2 Million phones.
So saying "I just get them from Google Play store" doesn't keep you safe.. Because apps are not tested before they hit the play store, and most of the android virus hit via the play store.
And if you have never heard of a virus that targets the Android, it's because you haven't taken the time to actually see if any actually exist. Linux is not hard to exploit, and neither is Android.
CNexus said:
I use Lookout sometimes
That said, as long as you check what permissions the apps you're installing are asking for, you're fine
I mean, an RPG game does not need access to your contacts or permissions to send SMS messages
The best antivirus in the end, is an observant end user
Sent from my PG06100
Click to expand...
Click to collapse
Completely agree on that the best anti virus is yourself. I don't even use one on my computers because most viruses mask themselves as anti virus programs.
Sent from my Galaxy Nexus using xda app-developers app
CNexus said:
Well to begin with, the fact that android is based on Linux makes it even harder to exploit because of the whole permissions structure
On top of that you have the Android app permissions system and you have something very difficult to exploit in itself....I've never gotten one, but I've heard of malicious apps getting released (on the play store) back in the baby stages of Android (when froyo was just out) that used the froyo rooting exploits to bypass security checks and mess with the stuff on your phone.
But other than that, I've never heard of a any virus/exploit/targeted attack on android devices
Click to expand...
Click to collapse
So where good on jellybean right? I dont run any anti-virus, same reason as Diablo..
souleman said:
And if you have never heard of a virus that targets the Android, it's because you haven't taken the time to actually see if any actually exist. Linux is not hard to exploit, and neither is Android.
Click to expand...
Click to collapse
Android is based on Linux. And if you say Linux is not hard to exploit, I suggest you do some reading yourself.

Do I need Anti Virus software on my NEXUS 4?

This question is really a basic for the sake of device security, but still, I need opinion from you guys. And maybe some recommendations?
R. Hansen | Nexus 4 | noob
No, it's just a waste of space.
Sent from my Nexus 4 using Tapatalk 2
I have never needed it.. I download/install things from allot of sites too.
I wouldn't worry about it myself.
Sent from my Nexus 4 using xda premium
Agreed with the above, its not necessary. Provided you are careful with what you download and install you'll have no issues.
Sent from my Nexus 4
Is it even possible to get a virus from installing an app
Sent from my Nexus 4 using xda app-developers app
mattoaida said:
Is it even possible to get a virus from installing an app
Sent from my Nexus 4 using xda app-developers app
Click to expand...
Click to collapse
Yeah, but it's pretty rare
An AntiVirus App will just slow down your phone I think.
rusak2 said:
An AntiVirus App will just slow down your phone I think.
Click to expand...
Click to collapse
And waste an already limited space.
Sent from my Nexus 4 using xda premium
So I sum up that nobody use antivirus here. Okay then, I guess it is enough for me I guess
R. Hansen | Nexus 4 | noob
Android is based on unix/linux, this is not windows. No need for an antivirus, it's just a waste of space and RAM.
"Riddle me this, Riddle me that."
They wouldn't find the in built NSA/CIA stuff anyway. In fact they would probably add more snoopware.
I installed avg antivirus. Pretty happy with it
Sent from my Nexus 4 using xda premium
I wouldn't see it as necessary if you're a crack flasher or swap ROMs often.
if you are a noob, yes use 3 antivirus at the same time, lol
most play store apps are virus itself,, full of ads, crapware,
use greenefy to put them down and adaway
if you want your n4 to behave like a S3 S4 sony htc lg, then put antivirus to make it slow and lag
I had the same question so i set to answer it myself.
I installed a free anti virus one of the best,, AVG/Avast was it? I cant remember. I then went and pulled out a keylogger version of swiftkey. What it does is it send everything i type passwords and all to a remote server.
I scanned the apk and i scanned the folder it was installed to and then scanned the entire phone.
It was deemed clean and safe.
The hack to insert the keylogger code is easy to reproduce and doesnt mar the app's digital signature. It was malicious but could nt be caught.
I uninstalled the "anti virus" and went on with my life.
I know and understand that you most probably won't ever feel the need of an antivirus from normal usage of your mobile device, but the numbers show all over the place that there is an epidemic of malware on android, just check the following articles, some of them may be biased since they are coming from a an antivirus seller, but there is no denying that the threat exists and if you care about your privacy, having a basic antivirus/antimalware, app permission control and the use of some sort of anonymity protection (OpenVPN, TOR, etc) is a necessity to avoid having your data put on the internet by every free game or stupid free app out there.
Check all these out for example:
http://techcrunch.com/2013/04/15/ma...ing-around-32-8m-android-devices-report-says/
http://techcrunch.com/2013/03/07/f-...of-all-mobile-malware-in-2012-96-in-q4-alone/
https://www.lookout.com/resources/reports/state-of-mobile-security-2012
https://blog.lookout.com/blog/2012/12/13/2013-mobile-threat-predictions/
https://en.wikipedia.org/wiki/Mobile_virus
I will probably strike most of you as a crazy, tinfoil-hat-wearing paranoid but the internet is a scary place...
Kasnar said:
I know and understand that you most probably won't ever feel the need of an antivirus from normal usage of your mobile device, but the numbers show all over the place that there is an epidemic of malware on android, just check the following articles, some of them may be biased since they are coming from a an antivirus seller, but there is no denying that the threat exists and if you care about your privacy, having a basic antivirus/antimalware, app permission control and the use of some sort of anonymity protection (OpenVPN, TOR, etc) is a necessity to avoid having your data put on the internet by every free game or stupid free app out there.
Check all these out for example:
http://techcrunch.com/2013/04/15/ma...ing-around-32-8m-android-devices-report-says/
http://techcrunch.com/2013/03/07/f-...of-all-mobile-malware-in-2012-96-in-q4-alone/
https://www.lookout.com/resources/reports/state-of-mobile-security-2012
https://blog.lookout.com/blog/2012/12/13/2013-mobile-threat-predictions/
https://en.wikipedia.org/wiki/Mobile_virus
I will probably strike most of you as a crazy, tinfoil-hat-wearing paranoid but the internet is a scary place...
Click to expand...
Click to collapse
You're not crazy... I was looking at it from the shoes of the person asking. If someone has to ask, then they are somewhat new and more susceptible to clicking on things that shouldn't be clicked. Like my grandma clicking a "YOU HAVE A VIRUS, CLICK HERE TO CLEAN" pop-up. IMHO, most responses were opinions based on that specific person's usage/knowledge without considering the source. And I can agree.. it's not needed if you know what you're doing. Since you asked the question, I say get something..
How much porn do you download?
Sent from my Nexus 4 using muh freedoms
ryohansen said:
This question is really a basic for the sake of device security, but still, I need opinion from you guys. And maybe some recommendations?
R. Hansen | Nexus 4 | noob
Click to expand...
Click to collapse
It's not really needed. I used it for a but but never needed it.
If you still want one though. Lookout is decent.
Sent from my Nexus 4 using xda premium
Beerad875 said:
How much porn do you download?
Sent from my Nexus 4 using muh freedoms
Click to expand...
Click to collapse
Just enough. *wink*
Sent from my Nexus 4 using Tapatalk 2

App Ops on Z1

Those who are using 4.3, try using App Ops to tame the battery hungry apps from causing wakelocks and having unnecessary control over your personal data.
It'll probably be hidden but there's nothing the Android peeps can't solve right?
https://play.google.com/store/apps/...tm_medium=organic&utm_term=app+ops+play+store
Use this or any other App Ops starter to access the hidden menu.
Sent from my C6902 using xda app-developers app
I have tried couple of these appops and non worked for me, when I open the app it just shuts by itself. Do you access it through the app itself or from somewhere else, am I missing something here??
ahomad said:
I have tried couple of these appops and non worked for me, when I open the app it just shuts by itself. Do you access it through the app itself or from somewhere else, am I missing something here??
Click to expand...
Click to collapse
I tried it on both my xperia Z1 and my xperia tablet Z, and they both do the same thing. I'm guessing sony took it out for their 4.3 update.
I'm also looking for an app ops that can work with my Z1... but can't get any... if someone can give a tip it will be highly appreciated.
Sony patched it up like Google did on 4.4.
Sorry guys, I just assumed it would work like it does on my other devices. I updated to 4.3 myself today. No luck. Root needed.
Sent from my C6902 using xda app-developers app
SnapDragon BatteryGuru Do what you are saying with 10/10 performance and add about 25% battery life.
Try this
"https://play.google.com/store/apps/details?id=com.colortiger.appopsinstaller"
kulvertti said:
Try this
"https://play.google.com/store/apps/details?id=com.colortiger.appopsinstaller"
Click to expand...
Click to collapse
I'm not on 290 right now, but if Sony patched it the same way that Google did, it's not possible to open the App Ops activity at all anymore.
XDA article: Source Code Commits in Android 4.4.2 KOT49H Reveal Flash SMS Attack Fix and App Ops Removal
Google code commit: android / platform/packages/apps/Settings / 37f06a4^! / .
Yes, the article refers to 4.4.2, but that doesn't mean Sony didn't incorporate it into their 4.3 release.
kulvertti said:
Try this
"https://play.google.com/store/apps/details?id=com.colortiger.appopsinstaller"
Click to expand...
Click to collapse
Not working. No app will work unless we're rooted.
Sent from my C6902 using xda app-developers app
Try Downloading AppOps module from Xposed installer... works perfectly !
http://developer.sonymobile.com/201...-aosp-for-xperia-on-github-video-open-source/
Z1 added to AOSP

ICE info on lockscreen. Opinions?

Sony have now given us the choice to show ICE (in case of emergency) info on the lockscreen. This allows the emergency services to see your next of kin info or even call them directly from the lockscreen without you ever having to divulge your password or pin.
What do people think of this?
A useless gimmick or a genuinly good idea?
I work in construction and welcome it. Should anything happen and I am injured or killed on site the emergency services can easily find out who I am and notify the relevant people. (provided the phone isn't destroyed along with me). A fair few sites now insist on staff wearing hard hat tags for the same purpose containing the same info.
Sent from my C6903 using XDA Premium 4 mobile app
Kirkymole said:
Sony have now given us the choice to show ICE (in case of emergency) info on the lockscreen. This allows the emergency services to see your next of kin info or even call them directly from the lockscreen without you ever having to divulge your password or pin.
What do people think of this?
A useless gimmick or a genuinly good idea?
I work in construction and welcome it. Should anything happen and I am injured or killed on site the emergency services can easily find out who I am and notify the relevant people. (provided the phone isn't destroyed along with me). A fair few sites now insist on staff wearing hard hat tags for the same purpose containing the same info.
Sent from my C6903 using XDA Premium 4 mobile app
Click to expand...
Click to collapse
I don't think it's a bad idea. Probably not something everyone needs, but I think it has valid appeal. I'm not a dev, but I'd guess you could do most, if not all, of what you're saying with an Xposed module.
Sent from my Xperia Z1 using Tapatalk
where is this option located? only on 4.4.? I am still on 4.3 (z1s)
scoobdude said:
where is this option located? only on 4.4.? I am still on 4.3 (z1s)
Click to expand...
Click to collapse
Yeah it's a 4.4 thing. An exposed mod may be able to replicate it on 4.3 for you
Sent from my C6903 using XDA Premium 4 mobile app

Categories

Resources