Sunday, July 29, 2018

4.4 kitkat - How to remove a Virus that installs an unlimited amount of APPs causing the smartphone to stop once an internet connection has been established?


Once the smartphone (android 4.4.2, kazam tornado 350) has been booted, is connected to WIFI and an unlimited number of APPs is installed causing the phone to stop, i.e. swipe is stopped, another home screen is installed.


Symptoms




  1. A number of unwanted apps is installed once the phone has been reset to factory defaults

  2. Unlimited amount of unwanted apps is installed once wifi is installed

  3. Phone battery is consumed quickly

  4. Home screen cannot be entered

  5. Popups that ask to install (fake) security updates appear


Attempts



  1. The unwanted APPs remained installed on the smartphone once the phone was reset to factory defaults


  2. The installation of the APPs persisted even after encryption and subsequently resetting to factory defaults

  3. Resetted the phone to factory defaults, disabled wifi, disabled malicious apps, rebooted and enabled wifi installed an unlimited number of APPs again

  4. Tried to install a Virusscanner, but everytime the connection to internet is established various malicious apps are installed immediately

  5. The issue persists as well once the SD card was removed

  6. The internal phone storage cannot be removed. In an attempt to remove it the screen was busted :'(


Discussion



  1. The APPs that are installed do not appear in the downloaded APPs section

  2. After resetting to factory defaults, there seems to be malicious APPs recognized as default APPs, e.g. com.andriod instead of com.android



Question


How to remove this Virus?



Answer



As I already mentioned in the comments, here are the primary points you need to be careful about:




  1. Whenever you install an app from the Play Store, you should pay attention to things like permissions, ratings, reviews by existing users, etc. before installing it on your device. One malicious install, and your phone could become compromised. It doesn't matter then, whether you are rooted or not.





  2. When you install an app, it asks you a bunch of questions like what all things it needs access to (like SDCARD, telephony resources, system tools, etc.). Even without root access, a malicious app can do lots of damage to your phone, if you permit them these resources.




  3. As the existing answer suggests, rooting is your only option if the malware has landed itself in the system area. But if you go along that route, proceed with care and caution, as there is a risk of bricking if incorrectly done.




  4. For future reference, make a mental note to double check at least two things before installing an app: 1) The permissions it needs are sane and safe. 2) There are at least 500 million installs already with at least a 3.5+ rating. You can make rare exceptions for popular apps like WhatsApp/Skype, but this is generally what you should do. You may or may not be able to recover this phone, but life goes on and these things will go a long way to ensure that such a situation will never arise.




No comments:

Post a Comment

samsung galaxy s 2 - Cannot restore Kies backup after firmware upgrade

I backed up my Samsung Galaxy S2 on Kies before updating to Ice Cream Sandwich. After the upgrade I tried to restore, but the restore fails ...