• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Random apps keep installing by themselves

hi friends
i have this problem with my device:
three program ( timeservice, monkytest & null) automatically installed, when antivirus( kasper & nod32) is active can find and kill them but when antivirus be deactivated the virus come back.
i reset the device to factory data but when the phone be on the virus came back too
pleas help me
 
Fs man. And does the OS allow installs without permission?
Mainstream Android does via the Play Store (i.e. you can use the Play Store on the web to push apps to your phone), and Google Play Services updates silently all of the time. So if the Chinese ROM author has built this into the ROM via a different service then sure it's possible.
 
hi friends
i have this problem with my device:
three program ( timeservice, monkytest & null) automatically installed, when antivirus( kasper & nod32) is active can find and kill them but when antivirus be deactivated the virus come back.
i reset the device to factory data but when the phone be on the virus came back too
pleas help me
What device?

If they come back after a factory reset without you installing any of your apps then there's something built into the ROM (or something has your google login credentials, but you should see notification of their being installed in that case). If you do a reset and then restore your apps it's possible one of them is responsible.

Just trying to identify the cause.
 
Fs man. And does the OS allow installs without permission?

If the offending app store is installed as system and running as root, yes it can. :eek: I've seen them do it on non-Google Chinese devices, install and update apps with completely changed permissions, without any user interaction at all.

I'm expecting the worse here, a Lenovo phone bought from a "********" AF banned vendor, preinstalled with MoboGenie.
 
It is in the ROM.
Chinese phone with a Chinese app store sold by a Chinese vendor.

You can disable and hide it from the app settings, so it won't bother you again.
Which app do I disable or delete? This is what Im struggling to find
Thank you for the reply.
 
What device?

If they come back after a factory reset without you installing any of your apps then there's something built into the ROM (or something has your google login credentials, but you should see notification of their being installed in that case). If you do a reset and then restore your apps it's possible one of them is responsible.

Just trying to identify the cause.
my device is huawei g730 u10 v10
after reset i use another google account and don't restore backup Unfortunately the three Trojan horse comes back
It should be noted i format sd card too
 
Hello I fought these viruses, but each virulent process is called by others .. so there is more than what you can see .. anyway i could not eliminate the virus with a root user by -adb shell-, or a Root Explorer or other applications .. I could see is that they have set setuid for files, each file has permissions wrsx-sx-r, and when you run "rm /system/app/providerdown.apk" returns (read only) in some cases when mount and remount (operation not permitted).

One option was to install TWRP: TeamWin in recovery mode, use the native browser to delete files, but could not find a specific version for my phone, and adb shell does not work in that mode.

So my last option was to use a ROM, and flash the entire system. The problem was finding the right rom for my cell, with the fear of having a nice paperweight, to ruin the operator or override basic information.

Thanks to Alcatel Upgrade Tool (another problematic process), I could renew my phone again without any loss. The only bad thing with the tool was that did not appear the option for 6033a, only 6033 so it was a risk.


MonkeyTest
/system/app/providerdown.apk
/data/app/com.android.wp.net.log

TimeService
/system/app/UsTime.apk (can not remember exact name, view the permissions for identification)
com.android.hardware.ext0

Alcatel One Touch Idol Ultra, Operator IUSACELL from México.
 
Hey guys just signed up cause this is the same problem I'm having. Wondering if there's been a solution anyone has heard. I've deleted, disabled Monkeytest.apk from /system/app but it comes back when I reboot. I found it was re-installing itself from the /data/local folder. Also have found a different busybox in /system/bin, 2 hidden files in /system/xbin and my /system/etc/install-recovery.sh has a new entry but won't let me make any changes. I'm guessing chattr is not letting me make changes.
 
Hey folks, check your app list in Settings for something called DT Ignite. Disable that and it should solve the problem of apps just randomly being installed. I disable this app on every possible phone I sell.
Hope that helps!
 
Iam also facing the same issue .Today I disabled these two services monkeyTest and timeservice.Recently I installed easytouch which might be the reason for these installations and "com.amdroid.hardware.ext stopped" problems.What is most disgusting here is how can googleplaystore allow these apps to get installed without our permission.
 
Iam also facing the same issue .Today I disabled these two services monkeyTest and timeservice.Recently I installed easytouch which might be the reason for these installations and "com.amdroid.hardware.ext stopped" problems.What is most disgusting here is how can googleplaystore allow these apps to get installed without our permission.

You got a Chinese phone with a Chinese app store and it came from China? What phone have you actually got, make, model and Android version?
 
Micromax Canvas 2.2
Version:Android 4.2.2

OK, that's an Indian brand. Have you been sideloading app APKs from other sources? Like outside of Google Play, been using Chinese app stores?

"googleplaystore allow these apps to get installed without our permission."...yes, you just turn on installation of third-party apps. Next question, is your Micromax rooted? that's important.
 
OK, that's an Indian brand. Have you been sideloading app APKs from other sources? Like outside of Google Play, been using Chinese app stores?

"googleplaystore allow these apps to get installed without our permission."...yes, you just turn on installation of third-party apps. Next question, is your Micromax rooted? that's important.
No it is not rooted.sometimes got apks from other mobiles via bluetooth but never installed from other appstores
 
OK, so you're copying whatever APKs from other devices, rather than installing directly from Google Play. As your Micromax is not rooted, just doing a factory reset should clear it. Because if it was rooted and this shit got into system, you'd be looking at doing a complete wipe and reloading the original Micromax firmware clean.
 
OK, so you're just copying whatever APKs from other devices, rather than installing directly from Google Play. As your Micromax is not rooted, just doing a factory reset should clear it. Because if it was rooted and this hit got into system, you'd be looking at doing a complete wipe and reloading the original Micromax ROM clean.
No, i didnt mean that iam installing apps from other devices .I might have installed apps once or twice by copying apps.I have done factory reset several times in the past twodays because of "com.android.hardware....." Problem. It makes the device hang and touch doesnt work after that.once it was reset,it will work properly for 4 or 5 hours and shows the same problem
 
Same here please help random apps keep installing by themselve and ads keep popping out every time. And those apps are sexual apps like pornclub or sexposition etc. Please help i tried to uninstall but i cant! And i also tried factory restarting my phone but no it didnt work. Help me please
 
Same here please help random apps keep installing by themselve and ads keep popping out every time. And those apps are sexual apps like pornclub or sexposition etc. Please help i tried to uninstall but i cant! And i also tried factory restarting my phone but no it didnt work. Help me please
What device?
 
Back
Top Bottom