Original topic:

Possible Malware

(Topic created on: 06-30-2020 09:14 AM)
24543 Views
Ladyquinn10
Active Level 3
Options
Galaxy Note

I've had some serious issues with my phone. My calls are being listened to, texts and files being removed, calls being redirected. I was having the same issue with my router I'm dealing with that as. As for the phone, under developer options I checked whats running in the background and its a bunch of things I've never noticed before. I have reset my phone but am still having the issue and also noticed that all of a sudden there is work profile I never created. A lot of them say "remote" on them. Google Play Services has 17 services running which are all weird. Anyone else have this issue?  Below are some of the things Im seeing. I know some are legit. 

 

 

Google Play has these running: 

-CollectionService

-DispatchingService

- ExposureMatchingService

-DeviceConnectionWatcherSevice

- GcmService

- PendingIntenCallbackService

- FitRecordingBroker

- ContextManagerService

- NearbyDirectService

- CableAuthenticatorService

- EmergencyPersistentService

- ClearcutDebugDumpService

- EastworldService

 

MobileWips

-MobileWipsService

 

Bluetooth

- BluetoothAudioCastService

- A2dpService

- GattService

- BluetoothPbapService

- HearingAidService

- SapService

- HidDeviceService

Processes=

Main Process- com.android.blutooth

Service McfService in use - samsung Muliconnectivity (com.samsung.android.mcfserver)

 

Those are just some...It gets worse when WIFI is connected. I just did the update and nothing changed. 

 

Should I be concerned?

57 Comments
Anonymous
Not applicable
Galaxy Note

Hey I have been dealing with this for over a year now. I can’t get anyone to actually help me , mobile service providers,internet,samsung,or police. ,. I have changed phones, SIMS and passwords . I factory reset all my devices so many times cause that is about the only response I can get from the so called experts! I have been researching and trying to fix this myself this whole time. Finally I got a break! I was going over system logs and checking for open ports on my router, where my port forwarding was disabled and always double check now to make sure it is, and found one of my ports was forwarded to a PCSYNC. I have never synced any of my devices to any computer. That is how they keep hacking in. I turned the internet off and factory reset everything again . Left Wi-Fi off for a few days. This has not helped. They are still on my phone and computer.  I was wondering if you had any luck figuring out what those apps were, cause I have some of the same plus a few more and can’t disable or delete them. This is exhausting!..  they only positive thing to come out of this  is what I have learned this past year.   

T-Vegas
Active Level 1
Galaxy Note

Human Trafficking....

0 Likes
5150LvNv
Beginner Level 2
Galaxy Note

My router had "osync.lan" 

Then my phone had DRParser

SIM PIN

RINotifre

IMSlogger

Device keylogger

TetheringShare

CcInfo

And so many other apps still running while in safe/matienence mode.

But i know that some specific person is behind it. I just dont know how they could do so much to my devices in a very short timeframe.

0 Likes
Ladyquinn10
Active Level 3
Galaxy Note
0 Likes
dellerbroek
Beginner Level 2
Galaxy Note

Ladyquinn10 -   This appears to be related to this documented malware https://www.joesandbox.com/analysis/122930/0/html

 

 

0 Likes
Ladyquinn10
Active Level 3
Galaxy Note
So how do I get rid of it? Cuz it happend to my other phone as well.
0 Likes
Ladyquinn10
Active Level 3
Galaxy Note
0 Likes
Galaxy Note
I don't see anything suspicious in any of the screen shots.

If you Factory Reset from Recovery - Change your passwords - Enable 2-Step Verification like Google Authenticator - You should be good.
Kinsley
Moderator
Moderator
Options
Galaxy Note

@Ladyquinn10, Follow the suggestion provided by @Shaggyskunk1BLM, and as mentioned by @CHMultimedia, ("You're just showing screenshots of system components. Nothing wrong there. Android is an object-oriented system, like Windows. It's not just one big block, it's a collection of hundreds of smaller blocks working together to turn on your phone. It's like Windows for that matter. If you head to C:/Windows, you won't find Windows.exe, you'll instead find hundreds of files, with thousands more lurking within the many folders that appear there.")

But, how do you know that your device is showing up in two locations?

 

0 Likes