|
Edited by Tuomu at 2018-8-1 21:46 \n\nHi,
I have a question: I lately installed the ROM via SPFT as adviced. This is what happened.
My phone keeps directing my browsers to an opening page called aiboo.cc
I've discovered this to be a trojan, since a lot of entries about it have appeared online. I don't know where it came from, but I did install MalwareBytes, Kaspersky mobile, F-Secure and AVG mobile. The weirdest thing, here's what they find:
Google Play services says that the native Settings app is harmful and asks to remove it. After removing the file of course returns.
Malwarebytes reports malware at /storage/emulated/0/.jm/Cool4100_1000_1003_2_1513241684921.xde and resolving the issue it asks to uninstall the native Settings app. This happens about 4 times a day.
Kaspersky reports a Trojan called Trojan.AndroidOS.Boogr.gsh at Settings -> base.apk -> /data/app/com.comona.bac-1 and resolving the issue it asks to uninstall the native Settings app. This happens about 4 times a day.
AVG say there's malware detected called: APK:RepMalware [trj] and Android:Agent-QZQ [trj]. Resolving the issue has the same result described above.
F-secure noticed something too, but I didn't get a screenshot. The point is 1. All of these appear at the same time, so I'm assuming they are caused byt the same problem. 2. They all have different names, but have the same resolve, ie. remove Settings-app. After that all issues are gone consequently, for a few hours. 3. Kaspersky says the file reported by MalwareBytes is safe, occasionally Malwarebytes says the same, but still flags it.
To me all this sounds like a false positive, just as there were a few before this update. The problem is the aiboo.cc-site, that still keeps opening (notice I have a C-note with OTA-version, that does not have the problem). So I'm wondering... what did I install on my phone, when I ran the ROM on SPFT?
Well, I thought I added screenshots, but I guess you get the drift anyhow.
-T--
|
|