Android Virus #2 and I Need A ROM

whazzit

New member
Apr 3, 2016
3
0
0
Visit site
first off, a description of the problem.

I don't know what hell hole on the internet I went to for this to happen, but I got a notification on the smart phone saying you have a Security Update waiting to be installed. I was suspicious because I had never gotten any update notifications, like OS or app update or anything so why this? but I installed it. it involved rebooting the system.

after that, the web browser intermittently gets hijacked. randomly, and always after I log on to a website where I have an account. it rolls me to

http://mobfactory.info/r/28c2ba6ee317-11e5-8cd0-1100434798f9/1/

and

https://pkiconcurlms.com/c/39b50955-984b-11e5-b565-02f6361de079?transaction_id=102cd9386185316dd248a92a680f26&bid={bid}&pubid=7215#fb

then gives me some fake warning about being infected with a virus, give them money to fix it.

did a factory reset. that did not resolve the issue. apparently the "Security Update" has been applied to the factory image that is stored away for doing a factory reset. the other "FBI Police" or "Android Police" virus described on the other thread was not so intrusive.

therefore to resolve the issue, I need to replace the factory image and do a factory reset again. I have the instructions on how to do that, but I need to know where to get the factory image.

hardware details:

on the case, it says Motorola model XT1080. but it's supposed to be a Droid Maxx, which would be a XT1080M.

firmware details:

24.13.3.obake-maxx_verizon.Verizon.en.US

24.13.3 - OTA - 2015.10.30
24.13.3.obake-maxx_verizon.Verizon.en.US - system version
DROID MAXX - model number
4.4.4 - Android version
MSM8960PRO_BP_23255.132.81.01R - Baseband version
3.4.42-g6ca5516
hudsoncm@ilclbld27 #1
Tue Aug 18 04:48:11 CDT 2015 - kernel version
Tue Aug 18 0404:14 CDT 2015 - Build date
SU6-7.3 - Build number
 

doogald

Trusted Member
Jan 3, 2010
4,425
55
0
Visit site
Did you do a restore after the factory data reset? If so, you probably restored the malware.

Though it sounds more like a chrome hijack...???

Either way, this sounds like a job for the Verizon Software Update Assistant. I'd suggest doing a factory reset and NOT restoring from Google after the reset, but set up the phone from scratch.

See https://forums.androidcentral.com/e...support/knowledge-base-116950/&token=8yrUht_A

Note: the sua requires a usb2 port and won't work with usb 3, if I remember correctly.
 

doogald

Trusted Member
Jan 3, 2010
4,425
55
0
Visit site
And, yes, the casing is stamped XT1080 even though it's a 1080m. Obviously Motorola changed the model after they made the cases. My guess is that the ultra was a relatively last minute model addition.
 

whazzit

New member
Apr 3, 2016
3
0
0
Visit site
problem solved

factory reset did not resolve the issue. clearing the app cache for Chrome didn't do it either.

next step was to flash the firmware.

had Android 4.4.4 SU6-7.3 ver 24.14.3, could have re-flashed with the same version, stock image from

firmware.center

but it so happens that the newer version SU6-7.7 system version 24.21.7 just came out, and all I had to do was accept the notification to upgrade and let it do that automatically. no need for Motorola Device Manager and RSD Lite to install a firmware downloaded from the internet.

that resolved the issue.

apparently the virus/spyware/adware had inserted itself into the factory image on the phone just like I thought.

if you already have the latest version of firmware, you won't get a popup message offering to update with the latest of what you already have, and you might not find a copy available on the internet either. so what you can do is, use Motorola Device Manager and RSDLite to install an older version (virus now gone but you have older firmware) then when you use the phone you will get a message offering to upgrade to the latest version.
 

doogald

Trusted Member
Jan 3, 2010
4,425
55
0
Visit site
Re: problem solved

apparently the virus/spyware/adware had inserted itself into the factory image on the phone just like I thought.

I kind of doubt that, since the factory image is write protected without a signed Motorola updater. More likely you had a third party app that was doing this.
 

Forum statistics

Threads
943,766
Messages
6,919,953
Members
3,159,218
Latest member
blaze_3ds