Question Malware?

ade23

New member
Jun 6, 2023
2
1
1
Visit site
Galaxy S10+, Android 12

Kaspersky antivirus picked up an old file (part of an old Chrome extension) as the following type of aware on my PC during a scan in April:


On May 9th, I realised that this file was also on Dropbox (thru am old Chrome default folder backup) and, as I couldn't sign into Dropbox on my PC at the time, I decided to delete it thru the Dropbox app and then a browser on my phone. I did this. But then became concerned that this could've affected my phone, so I asked on the Dropbox forum. They basically told me to wait & see.

Later that day, I realised there were other copies of the same file on Dropbox from other Chrome default backups (which had yet to be flagged) , & decided to removed them too. The problem was that this time I accidentally (at least nearly) opened one of the files as I was deleting it (it was a javascript file - named redirect.js) - I hit the back button before I saw any of the file. I deleted the files & cleared that browser's data & cookies, except bookmarks.
There has been no indication in the time since of any malicious aware or other malware on my phone, or any other device on my network. No popups, overheating, new battery issues, etc. The possible exception being my mom's and my call forwarding settings suddenly changed. Which is worrying but could also be chalked up to a bug.

I've scanned countless times with Bitdefender & Malwarebytes and native scanners (100% clean). And scanned attached USB drives with Bitdefender. But I still cannot get over the worry. I haven't signed into anything on my phone since.
What prompted this post was that I accidentally turned on WiFi on the phone without noticing the other day, I've kept it on data since the 9th May. And for some reason it's not showing up on my router's interface. This increased my anxiety further.
There have however also been other strange things happening before and since, which is adding to my stress even more - issues with not getting security emails from Microsoft, preexisting WiFi problems (now mostly resolved), a Kindle on the network suddenly deregistering itself. (I realise this stuff is outside this forum's wheelhouse).

My health is also very bad at the moment, hence the delay in posting here and just general slowness in doing anything proactive - eg my phone *needs* to be updated.
And advice would be appreciated. Thank you.
 

B. Diddy

Senior Ambassador
Moderator
Mar 9, 2012
165,536
4,671
113
Visit site
Welcome to Android Central! I would not worry. This is what Google's generative AI search came up with for me:

"A redirect JS Chrome extension is a software program that can be installed on the Google Chrome web browser. It allows users to redirect web pages to other URLs. This can be useful for a variety of purposes, such as:

Skipping confirmation pages: Some websites require users to confirm their actions before they can be completed. For example, a website might require users to confirm that they want to delete an account. A redirect JS Chrome extension can be used to automatically redirect users to the confirmation page, so they don't have to click through it manually.

Skipping ad pages: Many websites display ads before users can view the content they want. A redirect JS Chrome extension can be used to automatically redirect users to the content, so they don't have to see the ads.

Redirecting from HTTP to HTTPS: Some websites are still using the HTTP protocol, which is not as secure as the HTTPS protocol. A redirect JS Chrome extension can be used to automatically redirect users to the HTTPS version of a website, so they can browse the website more securely.

Redirecting from one hostname to another: A redirect JS Chrome extension can be used to redirect users from one hostname to another. This can be useful for proxy servers, or for any other situation where you want to redirect users to a different server."

It's purely part of a Chrome browser extension, and would not be malware in itself. If it were still working, the worst that would happen would be an annoying redirect to some website.
 
  • Like
Reactions: ade23

ade23

New member
Jun 6, 2023
2
1
1
Visit site
Welcome to Android Central! I would not worry. This is what Google's generative AI search came up with for me:

"A redirect JS Chrome extension is a software program that can be installed on the Google Chrome web browser. It allows users to redirect web pages to other URLs. This can be useful for a variety of purposes, such as:

Skipping confirmation pages: Some websites require users to confirm their actions before they can be completed. For example, a website might require users to confirm that they want to delete an account. A redirect JS Chrome extension can be used to automatically redirect users to the confirmation page, so they don't have to click through it manually.

Skipping ad pages: Many websites display ads before users can view the content they want. A redirect JS Chrome extension can be used to automatically redirect users to the content, so they don't have to see the ads.

Redirecting from HTTP to HTTPS: Some websites are still using the HTTP protocol, which is not as secure as the HTTPS protocol. A redirect JS Chrome extension can be used to automatically redirect users to the HTTPS version of a website, so they can browse the website more securely.

Redirecting from one hostname to another: A redirect JS Chrome extension can be used to redirect users from one hostname to another. This can be useful for proxy servers, or for any other situation where you want to redirect users to a different server."

It's purely part of a Chrome browser extension, and would not be malware in itself. If it were still working, the worst that would happen would be an annoying redirect to some website.
Thank you so much! I feel a lot better now.
 
  • Like
Reactions: B. Diddy

Forum statistics

Threads
942,991
Messages
6,916,771
Members
3,158,765
Latest member
gofuckyourselfandroid