Malware Analysis Malware - Smartdrone home page + Suspicious new settings option

Zender railen

New Member
Thread author
Jan 14, 2016
2
I've had alot of experience with computers and as such, have had my fair share of experiences with virus' and how to combat them, i found that the most simple way to deal with them is to use something of a cureall.

With how deeply virus' bare their fangs, and how useless anti virus' are are removing them once they have appeared, it only takes on niggling blighter to install itself through a rogue ad or one of the many countless pathetic methods they use to reach their common end game.

BUY THIS AND WE WILL GO AWAY!!!!!!

well, not had one of those for a long time, and i haven't owned an android for long either. So it didn't take long to have my first experience with a virus, considering i only browsed to trusted websites so far, Youtube and amazon. and yet somehow a virus has managed to latch on so quickly? usually for a virus to come from a trusted website its usually gotta be something that you cant trace the source of, its not as if you miss clicked a download link.

So naturally i used my two step method, Scan then nuke. =p

The two programs, avast and malware bytes combined are relatively very powerful when combined, Avast is a great prevention tool that does annoy a bit with day to day activity, but is still really useful. While malware-bytes is among the most successful at removing already existing viruses.

However. Malware-bytes showed absolutely no trouble rooting out the issue.

Android/trojan.loudw.a (three with this title with different sub titles)

/system/app/com.andoid.popup.apk
/system/app/cloudservice.apk
/system/app/com.google.android.lurkerplugin.apk

And oh look, the settings that installed itself.

android/trojan.agent.HC
/system/app/com.yahoo.en.gms.apk (This item is the same symbol for the new settings that has installed itself.

However... when i try to delete them using malwarebytes. Im faced with... (Uninstall unsuccessful)

A virus can literally tell the anti virus not to uninstall it. That's a major oversight, it doesn't matter how sophisticated a virus is, it never has the capacity to achieve that on a computer, it usually has to ensure a tiny hidden program exists within system 32 or god knows where to then reinstall itself.

Which leads me to my cure-all. System reset.

Did absolutely nothing. while it reset my android and nuked everything i had personally installed, the virus remained. and in doing so got worse as my anti viruses were uninstalled.

What kind of operating system must it be using to allow a virus to simply tuck itself in the data that remains untouched by a system reset?

The whole point in a system reset it to reset EVERYTHING. not save the stuff they'll be reinstalled anyway. That's a major vulnerability |:

I later read that formatting and reinstalling everything on the same level as a system recovery for a computer runs the risk of bricking it. so yeah, now im here, ranting away like a lunatic, attempting to find a fix.
 

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
First of all, welcome to MalwareTips.

Secondly, there's no need to rant it out mad :). Solution is the most important thing. Perhaps you could elaborate more on what you have done.

Third, I would suggest if you would post your configurations (be it PC or Phone, etc) on the thread below:
Security Configuration Wizard

That way we can assist you effectively by knowing what settings you already have.
 

Zender railen

New Member
Thread author
Jan 14, 2016
2
Honestly at this moment because its essentially out of the box knew, its pretty much default for a fusion 5 android. Any main details i don't really know, nor do i know where to look to find them =p

I am looking through the link you posted to try and find out more though.

Also, there was a need to rant >.> to make me feel better ofc!

i'll Edit or post again with updated details depending on what i read and the responses =p

Edit:

Not for the reason intended, but for a new development.

After following a step by step to open it in safe mode and attempt to remove it then, it still refused, and was still active. It appears i need to do something called Root. That's the thing i was referring to when i mentioned the risk of bricking it.

Attempts to scan with avast now result in the program to simply stop working.
Disabling every suspicious program has made them disappear completely yet still present. Symptoms still running rampant.

But whats more frustrating is that... PC scenario by comparison. Googling the name of the program or virus, adware, whatever. results in finding helpful posts of people who have dealt with it themselves. Second to this even if that isn't the case you can usually find out a ton. I haven't had to do a system recovery for ages.

yet... i cant find ANYTHING on regards to these issues. And i don't understand why my own config is required to help remove a program o.0

seems kinda irrelevant beyond general interface differences.

Especially since its fresh out of the box lol.

just checked the box too, doesn't seem to be any information detailing some of the things i need to create a config. in-fact all i know at the moment is that it's a fusion 5 10" tablet o.0
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top