Re: factory reset unable to remove malware
i have uninstalled those apps and
performed factory reset but to my surprise virus is back. is it due
to google account syn??
threats: 4
1 : com.vwydya.snslxcjby (trojan)
2: com.nb.superuser (trojan)
3: com.nb.superuser (potentially unwanted app)
4: com.clrrlixw.hmotzhoh (potentially unwanted app)
Please help
I have a similar infection and need help !
My
stock, unrooted, Galaxy S5 got infected with a self rooting, app installer, living in the system partition along with many of it's friends.
It's a persistent infection, I think the cellphone got it from my computer that has a UEFI malware/datastealer when I plugged it in to charge -- that is infecting the rest of the store network.
Yeah, I need help getting that sucker out of those computers too.
It keeps adding apps, and actually taking screen shots of my cellphone and sending them somewhere - and a few ads and popups, but the phone is still "usable."
The apps are slightly different, but I think it used RootPA because that's a new "system app" I'd never seen before, and a "multi-csc" where I am now in Los Angeles AND somewhere in ENGLAND. And I don't know what to do next.
Things I've tried:
- Use App Manager to uninstall/stop them, but most "uninstall" buttons are greyed out and ineffective.
- finally turn on airplane mode.... duh.... and turn OFF sync, and turn on data caps, it stops it from uploading more stuff, and downloading more apps.
- Wipe data/cache - no luck, no change.
- Rooting the device and install apps that get to root and uninstall/delete apk files or kill what's there, but by the time I start the "killer" app and select the packages to delete/uninstall, my root priviledges have been removed by the virus/malware, got lucky the very first time and was able to delete 1 apk file, but it came back.
- RELOAD factory stock ROM using Odin - same thing. it's still there.
I looked at the log files, and it basically is setting up a "Multi-CSC" environment and has 2 locations in it. Me in "en-US" California, and the second one (the one that loads first) is in "en-GB" (Great Britain?). The virus is checking if it's in a special mode (recovery), and if a wipe starts, it copies itself and all it's buddies over to somewhere safe, does a FAKE zeroization (fake format?) and restores itself. Same thing with the ROM load, but copies itself (& friends) to the User data cache while the OS is loading and back once it's done -- I think -- I don't know how long a wipe is supposed to take, but 16GB of total RAM should take longer than 0.064 seconds right ?
Not sure what app is the "parent" that is directing all of this, but I've NEVER hacked my phone, never rooted it until today...
Is this a lost cause, or can this be remedied, and how ?
Thanks !
dave