?Virus/Trojan on AT&T Galaxy S7; found by malwarebytes, but not by Bitdefender or Lookout

sksahai

New member
Jan 18, 2011
1
0
0
Hi
In the past few weeks, i started getting those chrome popups saying that I had a virus and to "click here to install" I realized that it was clickbait scam, so closed out the browser, cleaned cache, etc
Just to be safe, I ran Lookout as deployed to my AT&T Samsung S7, it did not find anything. I also downloaded Malwarebytes and ran that, again, clean.

Two days ago, Malwarebytes informed me that I had a trojan in a system app.
Android/Trojan.Banker.Hqwar.i
in
/system/priv-app/ready2Go_ATT/ready2Go_ATT.apk

Funny thing is that this particular transfer app has not been updated since 2015 as far as I can tell, and I never used it. Malwarebytes did not detect it for the preceeding week, but did 2 days ago.

I can't delete the app, but I have disabled it. Is this a false positive? Lookout and Bitdefender don't see it all.

Thanks!
 
It could be a false positive, or it could be some app that attaches a Trojan to another app (or even replaces the app with one of the same name, but it's a Trojan, not the real app). And some apps will find malware that others won't. (It's surprising though, that MWB found a Trojan that LO and BD didn't.)

(You do know, don't you, that Ready2Go is AT&T's setup app, so unless you're setting up a new phone, you don't need it.)