• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Help I need help with a rooted virus.

Falvyun

Lurker
Jan 30, 2017
3
0
As title stated, i have a problem with a rooted virus on my phone. It could be GhostPush, or it may be Hummer, the new chinese virus, hence the name of the apk it downloads, that i'll show in the screenshots.

I tried anti-viruses, and they're all worthless; Yes, they detect SOME files that get downloaded by said virus, but they are no help when it comes to the virus itself. I tried to Factory Reset on several occasions, to no avail; and even start in safe mode after the factory reset and connect to the wi-fi; still downloads the malicious files. And no matter how many times i delete those number named files and the apk named SDK, they just keep getting downloaded right back up.

What makes me think it's rooted and not getting downloaded from google store when i connect to it?
Here's the answer: It doesn't need me connecting an account to Google Store. Just now, fresh out after a 9000th factory reset i did on this phone, i connect to the Wi-fi, and the malicious files get downloaded in my Download phone; and no, it is in the internal storage; i do not have my SD card in.

Here's my theory: There's some script of some sort rooted in my phone [ the virus ] which activates when i connect to the Wi-Fi, and it makes it so that it uses the system/default Browser app [ which i cannot uninstall, phone's not rooted ] and it goes to some website where i get these malicious files from.

And these malicious files do the following:
-Prompts me with a full-screen window at total random times that if i play say a tapping game and i tap on it, it instantly downloads an app like AliExpress, some boost apps and the such. Fortunately and not, there's an X in the top right; Fortunately, i can close that adware window and avoid installing the app [ Which btw is from an unknown source, even though i have the "Allow downloads from unknown sources" unchecked, so that's utterly worthless. ] Unfortunately, it shows that i'm active and will prompt another one of those ad windows at unexpected times.
-Adds a smaller sized window that does about the same thing, still can tap on the X to close it
-Takes me to Ali Express or some other app, while in google play, on it's own. Just like that, i get into google play to look for some games or what-not and it instantly takes me to the page of that Ali Express or the other apps.
-Whenever i'm in Google Chrome from the phone app, it gets me to some adware tab that it opens on it's own, which i try to close immediately, because it starts downloading stuff on it's own accord.
-The adware showing on every single app or game i would happen to be in, regardless of time or activity.

And with that i ask you.. Is there any way for me to rid myself of this virus? I want to ask and hopefully get to understand better what i have to do, before i root my phone and delete the wrong thing that would prove fatal to my phone.

I will also leave some screenshots to the problems and what i get in the download folder. Oh, and there's usually way more of those number named files, but these screenshots are literally fresh out of a Factory Reset, after i've connected to the wi-fi. And there should be a website there, that i think is where the virus directs me to get those malicious files. Also, there seems to be some script in the virus, making a game i was once playing allow the adwares to show over the game.

Screenshots: http://imgur.com/a/uwaRc
 
Almost certainly you're gonna have to re-flash it with the original manufacturer firmware, as factory resets and whatever other things will NOT clear root malware.

Blackview doesn't seem to have any firmware files available online for their phones. So I think you'll need to contact Blackview in Hong Kong, or one of their agents about it:
www.blackview.hk/global-agents/

Did this phone come rooted?



"广告SDK" that's an SDK or framework just for ads, and nothing else.
 
Last edited:
Upvote 0
Almost certainly you're gonna have to re-flash it with the original manufacturer firmware, as factory resets and whatever other things will NOT clear root malware.

Blackview doesn't seem to have any firmware files available online for their phones. So I think you'll need to contact Blackview in Hong Kong, or one of their agents about it:
www.blackview.hk/global-agents/

Did this phone come rooted?



"广告SDK" that's an SDK or framework just for ads, and nothing else.

No, it didn't come rooted, or i don't think it did, unless you can reset/remove the root with a factory reset. Regardless, I am certain that something was different about it when i bought it, because i feel like ever since my first factory reset, the battery is going down a lot faster; But that's somewhat off-topic.

But thanks for the advice, i will try contacting an agent in my country and see what i can do about it.
 
Last edited:
Upvote 0
Just to clarify, a Factory Reset won't clear up a system-level exploit, which from what you've described previously does sound like your problem. A Factory Reset only wipes the general user partition, where all your files and personal data is stored. The internal storage of your phone has several different, separate partitions and each have a specific purpose. Your phone's Android operating system resides in some of those protected partitions, which unless rooted you don't have open access. So if your phone was in fact rooted before, after a Factory Reset it would remain rooted as that doesn't have anything to do with any system partitions. But since it wasn't rooted, the issue is more complicated. A regular, less intrusive exploit, say some kind of bad script that compromised an app you installed, would be removed by a Factory Reset as the exploit itself was residing in your user data partition. A more serious exploit that has infected your operating system however is harder to fix. As @mikedt commented on, you'll need to re-flash your phone's original firmware, in essence reloading the operating system to its original state.
Also, regarding the AV utilities you tried, keep in mind that those are apps you installed. That also means that those apps can only have limited effectiveness on the operating system itself. They can clean up things on your user data partition as they're apps installed in that level of permissions, but being just as effective on system-level partitions is a different matter.
 
Upvote 0

BEST TECH IN 2023

We've been tracking upcoming products and ranking the best tech since 2007. Thanks for trusting our opinion: we get rewarded through affiliate links that earn us a commission and we invite you to learn more about us.

Smartphones