samedi 28 novembre 2015

Malware survives factory reset

I have a cheap phone, Onix bought from an Aldi store, running Android 5.0. For a month or so, it has been fine, but lately it became unusable due to pop-up ads. After trying a few different virus checkers (Avast, AVG, Norton, Avira) finally one, Malwarebytes Anti-Malware, detected a problem, in a system file /system/app/OP_GoogleSearch/OP_GoogleSearch.apk.

This is found on a scan, and also the real-time detection, everytime an ad pops up. Trying to uninstall it fails (because it is a system file?) Anyway, nothing to lose, I did a full factory reset. After a reboot, I put my Google account in again, but told it to do a new setup, clean - i.e. no previous apps restored.

Very soon after, up pops a window claiming to be from airpush, and asking if I want to opt out. I say yes, but it comes back a few more times, and the other pop-up ads start again. I install Malwarebytes Anti-Malware, and it finds the same malware as before.

So, has the malware found a way to install itself in the factory image? I think, at this point, the phone is junk, because, being an unknown brand, I can't even root it, and/or install a custom ROM.

This entry passed through the Full-Text RSS service - if this is your content and you're reading it on someone else's site, please read the FAQ at http://ift.tt/jcXqJW.



Malware survives factory reset

Aucun commentaire:

Enregistrer un commentaire