Persistent Adware despite TWRP wipe of all data - Nexus 5X Q&A, Help & Troubleshooting

I got a nasty bit of adware from the internet--clicked a banner by mistake. Now I get popups telling me my SIM card is 58% infected, etc, and it wants to redirect me to download some app to remove it, etc. I never downloaded their app, but the persistent popups need to go.
I've tried running ~5 anti-virus/anti adware apps, none of which can even identify a suspicious program. I've done factory resets, which seem to fix the issue for 2 weeks, but then the popups recur. I figured it was either somewhere deep in my phone that didn't get erased with a factory reset, or it was being synced to my phone from my linked google account (I use project FI, and have to have a google account linked to the phone to have service).
So most recently, I installed TWRP, and wiped everything (cache, dalvik, data, system...completely removed the OS). While the phone was in that state, I used my laptop and cleared all my google sync data, removed all stored google data, and reset all settings to default. I then reinstalled stock Bullhead Oreo 8.1 over a USB. However, it again worked fine for 2 weeks before popups returned.
Is there some deep recess in my phone that I am not effectively deleting? Could it be syncing over my google account somehow (I don't have this problem on any other device with my google account on it)? Could it actually be my SIM card that infected?
I appreciate your help!

It's possible for a Sim card to get malware, but I haven't heard of anything specific. Are you restoring apps from Google? And if so, are there any sketchy apps you're restoring? Those are the only two areas I can think of where malware could be coming from. A complete os restore with the factory image should remove any malware. I'd get a new SIM card from your carrier, then restore the firmware. Use the flash-all batch file in the factory image.
Sent from my [device_name] using XDA-Developers Legacy app

Thanks for the reply. I don't restore apps as best as I can tell. When I reset the phone I select the option that says "start from scratch" or something like that, and at every choice during setup I choose to not import anything. I do have to link the phone to my google account for my Project Fi service, which does sync my contacts, so possibly something something gets transferred that way? Like I mentioned above, I've scrubbed my google data every way I could find.
I don't have any risky apps, just standard ones from the play store (outlook, pandora, etc). No risky online websurfing, just the one banner I clicked some months ago. I even rooted my phone not too long ago and used the ES File Explorer to try and find suspicious looking files, but didn't find anything. Phone is no longer rooted since flashing factory image recently.
My phone even had the bootlooper issue common to Nexus 5Xs, and I sent it to LG for free repair. They replaced some hardware (not exactly sure what), but still had the popup problem occur 2 weeks later. Bootlooping was fixed though.
I talked to Project Fi about a SIM card. They weren't keen on sending me a new one, but I'll try them again.

Related

help please applications constantly "computing"

in manage applications all apps are stuck at "computing" and will of stop. It used to be fixed by restoring my phone to an earlier date but now it just doesn't work.
Apps2sd, disk usage, and unmounting the SD card do not work. Force closing.
In the market I cannot install or uninstall apps.
And when I restart ill lose access to the apps on my SD card. But I can access all info using a task manager or taking the card out and accessing it from my pc.
Is my internal memory failing?
I don't know what else to do Ive tried so much.
Restore backup factory reset SD card format etc.
Froyo 2.2 stock rooted.
Any ideas?,I'm desperate.
Thank you.
Wipe completely and try a different ROM like CM6. If you're still getting the same problem, then it's a hardware issue and you're hosed. Run the RUU at that point, and take it in to get a replacement, and hope for the best.
How long do you give it? If you have a lot of apps, it might just take a lot longer than your are expecting, since it has to load the data for everything. I'd recommend just giving it a little more time (unless you already do). Before Froyo, even with just a handful of apps it seriously took around 3 minutes to load that kind of information.
I've given it up to 45 minutes at times, several times after a recovery it would all fully finish computing, then after i install an app or something to that effect it seems it 'breaks' again.
I tried other ROMs and after the first few apps i begin to reinstall it does it again. So i took a break, recovered it and went to bed. This morning it seems to be doing fine and now i'm reading there were market issues with other people last night, could this be connected? Is the market that integrated into the phone that it could cause issues like this?
i'm emailing HTC for some advice because i can't find a specific google/android technical support email address about the issue.
ii'm in the same boat.all my apps are stuck on computing. i cant even unistall, or move apps. the only positive is that i can still run all my apps. but i cant install anything new as it stays stuck on installing and never installs the app. this seems like a problem with froyo.
Mine does this ever since I installed modInstallLocation, and moved a ton of stuff over to the SD card. If I ever have to reboot for some reason, or if I have to use the phone as a USB device, most of the time the apps never recover. Sometimes (rarely) a reboot fixes it, but most of the time I have to pull the battery, pull the card, reboot several times before it will finally get all my apps back. It seems completely random. I can't uninstall or install anything either until everything is back to normal. It happened again last night, and I still haven't gotten it to recover. I let the thing "compute" all night (7 hours) with no luck.
btw, this is my second sd card, so I don't think its bad.
UPDATE: I got them all back! I wiped the Dalvik cache from within Clockwork Mod, and about 4-5 minutes after I rebooted, there they were!!!

[Q] Re-enabling RSS Apps

I backed up all my apps in Titanium and CWM before migrating from EG22 to EH06. The new version works fine after restoring apps and data using Titanium. The problem is that now both of my RSS readers (D7 Reader and gReader) get stuck trying to sign into my Google Reader account. The odd part is that the widgets seem to update the unread count, but I can't actually read them because the apps themselves won't move past the sign-in loops. I've tried deleting the data for the apps, and I've event tried uninstalling and reinstalling the apps, but the issue still persists. Internet browser applications work perfectly, so I know that it's not my internet connection. My only conclusion is that something else in the phone software (something that controls app access to the internet or to Google accounts) has the problem. As such, I should be able to go through Titanium and freeze/wipe anything that could cause the problem and proceed from there. However, I don't know where to start isolating the culprit.
Any ideas?
Dante of the Inferno said:
I backed up all my apps in Titanium and CWM before migrating from EG22 to EH06. The new version works fine after restoring apps and data using Titanium. The problem is that now both of my RSS readers (D7 Reader and gReader) get stuck trying to sign into my Google Reader account. The odd part is that the widgets seem to update the unread count, but I can't actually read them because the apps themselves won't move past the sign-in loops. I've tried deleting the data for the apps, and I've event tried uninstalling and reinstalling the apps, but the issue still persists. Internet browser applications work perfectly, so I know that it's not my internet connection. My only conclusion is that something else in the phone software (something that controls app access to the internet or to Google accounts) has the problem. As such, I should be able to go through Titanium and freeze/wipe anything that could cause the problem and proceed from there. However, I don't know where to start isolating the culprit.
Any ideas?
Click to expand...
Click to collapse
After you completely uninstall both apps go into /data/data and see if there are any leftover files for the apps if so delete them. And then reboot and reinstall and let me know what happens. I had it happen to me sometimes filesystem changes such as that retain their problematic nature until rebooted a few times.
Sent from my SPH-D700 using XDA App
Same sign-in loops as of early this morning. I'll try Odin'ing back to stock EH06, and trying again from there.
I've gone all the way back to Odin the stock EH06. I then flashed maddoggin's CleanBlue mod, and used Titanium to only restore any apps that weren't already loaded onto the phone. This should have stopped any system files from being overwritten. From there, I tried to open the D7 Reader. Same sign-in loop. I uninstalled the program, looked for any lingering data files (there were none), restarted the phone, then reinstalled the app. Still the same sign-in loop.
Am I missing something here? I've tried everything I can think of to isolate the problem, but there has to be something lingering that I'm missing.
Any other thoughts?
EDIT: Google Reader (the source) logs in fine, as does Pulse (3rd party reader). That means that it HAS to be something deep in Data concerning D7 and gReader that I'm unaware of.

Backup file in drive, but phone states no file associated with Google Account

Aloha!
As per the title, I haven't encountered this before. OTA to Android 10 performed, no longer rooted. Back up performed from settings, definitely completed. Can see said backup file in google drive on both mobile and desktop however upon setting up the phone from a clean flash just now, it states no backup associated with my google account.
Things I've tried -
adb shell bmgr list sets - no restore sets found
Reverted to android 9 - no associated backups found
Updated from 9 to 10 via OTA (as had done originally) and tried to set up from backup - no associated backups found
Tried clean flashes of both Android 10 images, one ending 19 and one ending 20. Same situation.
I thought it could be something to do with android version etc, but have backed up this morning as my drive shows.
Just wondering what went wrong or if I'm now simply out of luck.
It's things like my text messages I'm upset at losing etc
Anybody able to shed some light on this? I've had a quick search around but came up short so apologies.
Thanks in advance
info added in main post
I'm having the opposite problem. I can get my phone to back up, but it doesn't show up in Google Drive. I did have to uninstall Magisk 19.3 for the backup feature to work at all. I spent an hour with Google support trying to remedy this, but it didn't work.
Backup used to show up in Drive, and restore just fine. I figure it was one of the monthly updates, I just don't know which one. I really wanted a backup before upgrading to Android 10.
Really odd. I had no issues backing up, and it's still sat in Google Drive now, but nada, apparently no backups associated.
Wish there was a button there in drive that said restore.
Tried on my partner's phone as well which has never been touched in terms of root or bootloader unlocked. Still claims no backups associated.
Completely at a loss. Haven't tried Google support honestly but didn't think they'd be able to assist

Recovery Mode via Pixel

My brother died unexpectedly two weeks ago and I am trying to access data on his Google Pixel 2 XL. At this time, I have access to the google account that he used with the phone but I changed the password so "Find My Device" via Google cannot locate his device. I've verified that the phone was backed up at some point on the day he died, but am unsure of the time and am unsure of exactly what was backed up. I've done lots of research online and I've come to the conclusion that the only way to access the phone now is to enter recovery mode via the phone and wipe the phone and restore from the back up. I've found conflicting information about what the downside is to this approach. First, I know that I can only restore what was backed up. I'm okay with that. But I saw somewhere that the passcode for the phone is still necessary if you want to go this route. Is this true? I do not have the passcode and do not want to get stuck in the middle of trying to restore the phone. Second, will this approach erase all logins and passwords for all the apps that he currently had on the phone? What problems could this approach create as I try to further piece together his digital accounts/ information? Would it be possible to find out what his passcode was? This would help with all the other devices he has.
Finally, is there any way to look at the backup stored on the google drive without wiping and recovering the data to the actual phone? I do not want to do anything illegal; I'm just trying to piece together his last days. I'm the legal next of kin.
Thanks in advance for your help.
Someone else made a very similar post the other day....
The best thing to do do is this: https://support.google.com/accounts/troubleshooter/6357590
This is the only legal way to try and access someones account after death, and even then it my be limited:
In certain circumstances we may provide content from a deceased user's account. In all of these cases, our primary responsibility is to keep people's information secure, safe, and private. We cannot provide passwords or other login details. Any decision to satisfy a request about a deceased user will be made only after a careful review.
If Google themselves cannot provide password and logins, or data, then sorry, but no one here is able or going to help you break google security.
Knowing the passcode of one device wont help you with others, they can be different
Not knowing what youre hoping to recover, no one can tell you whether it accessible via google services
Depending on the phone there may be a lock that survives recovery wiping and is linked to the account, because its designed for preventing exactly what youre trying to do, and beat security.
Security is there for a reason, and not trivial.
So i refer you again to the google link above....
And a good reminder to not forget to enable inactive account manager, to avoid all this yourself: https://support.google.com/accounts/answer/3036546?hl=en
npchilders said:
My brother died unexpectedly two weeks ago and I am trying to access data on his Google Pixel 2 XL.
Click to expand...
Click to collapse
When setting up a device after a factory reset Android will ask for the email address and password of the last account used. Based upon your post, you have that information so you will be able to continue. If I recall correctly it won't ask for the pin as that is a local security feature and not backed up. His contacts and text messages should be restored after the factory reset. Usernames and passwords for non-Google apps may be restored, if I recall correctly, but keys for 2FA apps will not be restored. If your brother used 2FA you won't be able to access the accounts using 2FA unless he had backup codes stored somewhere on his PC.
Unfortunately, there is no way to look at the backup, as Google doesn't make the backup visible to the user in Google Drive.
Thank you.
Strephon Alkhalikoi said:
When setting up a device after a factory reset Android will ask for the email address and password of the last account used. Based upon your post, you have that information so you will be able to continue. If I recall correctly it won't ask for the pin as that is a local security feature and not backed up. His contacts and text messages should be restored after the factory reset. Usernames and passwords for non-Google apps may be restored, if I recall correctly, but keys for 2FA apps will not be restored. If your brother used 2FA you won't be able to access the accounts using 2FA unless he had backup codes stored somewhere on his PC.
Unfortunately, there is no way to look at the backup, as Google doesn't make the backup visible to the user in Google Drive.
Click to expand...
Click to collapse
Thank you! I have the information I need. I was just concerned that I would need a passcode and then I would get stuck. Otherwise, I located the backup on the google drive and can see that it was actually backed up on the day he died, so there should be very little data loss. Thanks so much.

Question Whatsapp run in a crash loop

HI
suddenly this afternoon, I don't know why, WhaptApp started to crashe every time I launch it. I tried to delete data, uninstall and install it again, but whatsapp still crash at start up. It is impossible to use it. I got this error message :
android.database.sqlite.SQLiteCantOpenDatabaseException: Cannot open database '/data/user/0/com.whatsapp/databases/sync.db': Directory /data/user/0/com.whatsapp/databases doesn't exist
Of course, even with adb, under Android 12, it is impossible to create the directory under /data because of permission denied.
Do you have any idea ?
Thank you for your help.
Get that trashware off the device! Use browser login only if you must use it.
It is a high security risk.
I had already thought of this solution, but I need the app to log in....
raph_quiroule said:
I had already thought of this solution, but I need the app to log in....
Click to expand...
Click to collapse
I would ditch it then. It's a multiple vector security risk. I don't use it.
If you insist on using it... what events lead up to the crash? Was it or anything updated? Any apps installed or uninstalled? Any downloads done?
Delete all it's data then ininstall it and see what you got. Clear the system cache. Download the latest version from a trusted source only. Scan with online Virustotal (scan what's loaded now too). Install. If it still pukes on you there's no guarantee a factory reset will solve this.
Malware is also a possibility. At some point a factory reset is in order especially if there's other odd behaviors or system issues. If it's a virus or rootkit a factory reset would purge it on Android 9 or higher.
If you think there's a possibility of malware, factory reset. Change account passwords then. Limit the damage by acting promptly. I give myself 2 hours to erraticate malware, then it gets nuked if not completely resolved. You wouldn't be the first to get tagged with malware through WhatsApp. Especially dangerous is doing -any- downloads from there including jpegs and pngs.
Thank you very much for your help. Despite I use alternatives like Signal, I still need WhatsApp to stay in touch whith some groups. I already tried to delete data and cache of WhatApp without success. I removed the app and installed it again but problem remains.
The log said :
Directory /data/user/0/com.whatsapp/databases doesn't exist
so I would like to create it manually, but it seems that it is impossible because of security of Android 12. I can't access to /data.
raph_quiroule said:
Thank you very much for your help. Despite I use alternatives like Signal, I still need WhatsApp to stay in touch whith some groups. I already tried to delete data and cache of WhatApp without success. I removed the app and installed it again but problem remains.
The log said :
Directory /data/user/0/com.whatsapp/databases doesn't exist
so I would like to create it manually, but it seems that it is impossible because of security of Android 12. I can't access to /data.
Click to expand...
Click to collapse
I don't know. That's a curious problem. 12 is a terror as far as I'm concerned. That's one reason I still run N10+'s on 9 and 10. Maybe use adb or ladb to edit it?
Double check all the permissions. Are any packages disabled on the phone? A small system app that's been disabled can cause all kinds of mischief.
Something, be it WhatsApp, an update, malware, a single event upset, etc screwed up the user partition data it sounds like. There's no guarantee a factory reset will fix it and even if it does it could reoccur if you don't find the root cause.
Play with it and keep doing Google searches, eventually you'll track it down. Might take a while.
Once again, thank you for your help. In fact, I've just found a workaround by installing the app in the "Work profile" of the phone. So I guess that factory reset will solve the problem. I also succeed in using an app that use web whatapp interface from F-Droid.
Independently with this story, the fingerprint sensor of the phone stopped working few weeks ago. So i'am preparing a Samsung Galays S9 under /e/OS. I'm going to switch on it to perform a factory reset of the xiaomi and send it for reparation because it is still under guarantee.
If the S9 and /e/OS do the job, I will sell the Xiaomi.

Categories

Resources