Infected with browser hijacking malware, how can I remove it from my device

Peter417

Member
Nov 26, 2015
7
0
0
Visit site
Infected with browser hijacking malware

I have tablet which is running Android 4.4.2. I installed one app from google play and after the installation the app opened a list of suggestions for other apps and i click on one of the apps and then i got infected with malware. Now if i open a browser, any browser, after few seconds it auto opens a page that redirects to malware sites. In most of the cases the redirecting url have this in the begining global.ymtracking.com. Sometimes it auto downloads a file ym_vb_local_2_cs.apk which is with size 2.50mb.

My device is rooted and i have Adaway and Adblock Plus installed. I tried different antivirus apps with no success. I even tried the Adblock Browser for Android and it still redirects to this malware url when i open the browser.

Any idea how to remove this malware from my device? It is, so annoying.
 

Golfdriver97

Trusted Member Team Leader
Moderator
Dec 4, 2012
35,367
113
63
Visit site
Re: Infected with browser hijacking malware

Welcome to the forums. Have you tried clearing the data for that browser?
 

Peter417

Member
Nov 26, 2015
7
0
0
Visit site
Re: Infected with browser hijacking malware

Welcome to the forums. Have you tried clearing the data for that browser?
Yes, i have tried to clean the data on all browser, i have five browsers installed, but it didn't help. The malware doesn't seem to target a specific browser but it has integrated itself more deeply in the system, and activate itself when a browser is launched, even if it is a newly downloaded browser.

Is there any manual method for manual removal of malware? Maybe using the terminal emulator? Usually in which locations the malware try to hide on the android file system? I am more familiar with Windows, than Android, so i am not sure where to look.
 

Bruce39

Well-known member
Dec 30, 2014
232
0
0
Visit site
Re: Infected with browser hijacking malware

If Golfdriver's suggestions don't work then you may have "Kemoge" or similar malware. This malware actually gains root access and the only possible solution is reflashing your device's firmware. Has been reported that this may not work, so removal is then impossible. There is a lot of links on internet about Kemoge, you may find more useful information.