Instructions and issues with advertising on the screen and status bar, with SMS extortionists and blockers of all kinds



Rep: (2807)
Instructions and issues with advertising on the screen and status bar, with SMS extortionists and blockers of all kinds.

Redirect from browsers to third-party sites | Attention! SMS fraud on Android | Help in finding programs for Android OS | Help to flash the device | Help me find the firmware | Getting ROOT | Questions beginner root user | Android OS FAQ | Terms and jargon | Newbie Questions

Talk in topic: Viruses | Advertising in the notification panel | Annoying advertising notifications | Advertising banners | Advertising banners in browsers | Opening applications (for example Google Play) without a request | Advertising on the lock screen | Advertising banners fully blocking device | Install applications without prompting users | Suspicious files |

Introduction
  • Where and what kind of advertising happens.
    It happens that by installing an application, or an update to a device, an annoying advertisement appears in the blind (notification panel). Sometimes it can be seen as a pop-up banner. Sometimes advertising appears on the lock screen. It even happens that the device is completely blocked and you see a message asking you to send an SMS, or pay a bill to unblock it.All this is cheating and do not believe him! Options for such "a divorce for money" lots of. Carefully read the instructions provided in the spoilers below to get rid of malicious files that run on the device advertising banners or otherwise harm you and your device.
  • "Infection"Sewn into the firmware initially.
    Unfortunately, increasingly"malware"There are sewn into the system files of the stock (standard) firmware of the device initially. Antiviruses may often not see them, the user may not notice anything for a long time (weeks or even months), but then advertising banners or other manifestations will appear"contagion".Most often this can be observed in Chinese devices and firmware. If you are just going to buy a new gadget, be sure to visit its profile topic on our forum. It is risky to buy devices that have just appeared, then you become a pioneer and if you yourself have no experience, then there will be no one to tell you about your device. If there is a suspicion that"infection"In the firmware, carefully study the header (first message) of the profile topic on the device firmware, in turn type in the search for the topic requests:"viruses", "banner" , "advertising" . If after that you did not find out the information, ask the question in the topic itself, whether someone from the user had such a thing. Read the recommendations below to find the source. "contagion" and getting rid of it. Read the ready-made instructions of those who solved the problem and shared this solution.
  • Banners in the browser.
    Banners may also occur while browsing the browser. The most unpleasant of them appear in pop-up windows, closing the main browser window. Contain frightening butcompletely lying information that "The device is locked MVD", "There is a virus on your device", or "You need to download an important update" and the like. The pop-up window (browser tab) must be closed using the browser, without clicking on the banner itself. It is recommended after that to clear the browser cache. Below you can find links to useful applications for blocking ads and pop-up banners in browsers, as well as learn how to block ads in other ways (for example, through the hosts file).
  • Advertising in applications and on the Internet.
    Regular advertising in installed applications, or while surfing the Internet is not dangerous. But you can get rid of it by installing the necessary program to block ads. Also, ads can be removed if you buy the full version, or by installing a modified / hacked version of the application without ads, most of these versions can be downloaded from our forum. In the application topic header, they may be indicated, for example, as:"Full", "Pro", "Without advertising", "Premium", "Ad-Free" ... Or you can order to modify the application, removing advertising from it in a special topic: Club Mod APK . Keep in mind that not all applications on our forum are allowed to modify. If the profile of the program says that the version and modification are prohibited, then you can’t ask about it on the forum.
  • Do not believe what is written on the banners.
    Never trust information on pop-up banners, or other manifestation."malicious". Do not send any messages or replenish the account to anyone! All this "divorce for money" and you will not receive any promised code! Do not follow the suggested links!
  • How to quickly stop data transfer.
    If, however, you clicked on the advertising link and the download began, or the sending of your personal data (usually occurs without a request),put the phone inFlight mode which will avoid sending SMS to premium numbers. In the case when all the same SMS sent and withdrawn funds from the account, read the recommendations from the topic: Attention! SMS fraud on Android .
  • Download applications from trusted sources.
    If you downloaded the application / game and advertising banners appeared, or other manifestations"malware",not always to blame the developer. Often,"malicious"can be added to a popular application by an attacker and uploaded to the website from which you downloaded the installation file.You can not download applications and games from unverified sources! The best applications, as well as their light versions without ads, banners, sending your personal data and other things, can be downloaded from our forum.
  • Find the source of the "infection".
    The appearance of advertising banners is not always solved by simply removing any one application. When fightingcomplex "malware"the most basic thing to do is find the source"contagion".Emerging banners, advertising in the curtain, self-installing applications do not arise from nowhere. It is necessary to find the services and files that activate the appearance"contagion".Carefully read the instructions below, they have all the necessary information on how to find the root cause and get rid of it.
First steps
  • We remember how it all began.
    First of all, you need to find out which applications, or files on your device aremaliciousand get rid of them. If the "trouble" began after installing some application, or a game and you remember what was installed last - feel free to delete it.
  • We scan the device with antivirus.
    Install antivirusDr.Web.Perform a full device scan for viruses. Remember that if you do not have Root-rights, the antivirus will not be able to remove malicious files that are registered as system files (they are in the system files). Only Root devices can access the system.
  • If necessary, we get Root-access.
    Most of the tips from this topic imply Root rights on the smartphone. How to get them is written in the theme of your Android - Devices, or you can tryuniversal methods for obtaining Root rights.
  • We are looking for a source"contagion".
    If suspicious files are found on the device; Self-installing applications (which reappear after your removal) need to find a malicious source somewhere in your device (most often in the system folders) and manage the installation and download of all these files.
  • Source Search Application"contagion"and control access to the internet.
    Keep track of applications that access the Internet before the appearance of advertising, or downloading questionable files will help firewall:NoRoot Firewall.A source"contagion",It often loads ads on your device via the Internet. The firewall also blocks access to the Internet to all applications that are trying to get it and shows you those applications that made such a request to the Internet access. Gradually allow access to applications and see in the "event log" of the firewall which applications went online when advertising appeared on your device or some files were downloaded.
  • Remove ads from the notification bar.
    If an advertisement appears in the notification panel, install the application:AirPush DetectorSometimes it helps to find which of the applications send ads to the notification panel. You can try to find out from which application the notification comes by holding your finger on the notification itself in the panel and then clicking on the exclamation mark that appears to the right.
  • The best way is flashing.
    If you don’t want to receive Root on a device, or it is not yet possible for this device - flash the device. Changing the stock (default) firmware to custom (unofficial, modified) is the easiest and most effective way to combat"malware"which were installed in the firmware initially. Also to those for whom independent source search"contagion"complicated and who fears do more harmflashing is recommended.In the firmware thread on your device, find out all the instructions on how to flash the device and how to choose the firmware.
  • We continue to study the instructions.
    Carefully read the topic header, a lot of useful instructions are available in the spoilers below. There is also a list of applications that users find dangerous.
  • Other applications.
    In all the recommendations from this topic it is proposed to use the most famous and well-proven applications, but if for some reason they are not satisfied, you can ask their counterparts in the subject.Help in finding programs for Android OS.
Instructions
The authors of the instructions are not responsible.in case of your wrong actions. Before any removal operations; replace; editing system applications is highly recommended Make a backup of the firmware through the recovery.
The device is completely blocked by the banner
Recovering after removing "malware"
Useful applications
Questions about how to use the applications are set in their profile topics at the indicated links. Search for other applications is conducted in the subject:Help in finding programs for Android OS
Dangerous applications
Information about the applications below cannot be 100% correct. It is possible that the developer has already deleted the virus code, or the application with the virus is distributed only on some sites. The list was not created to discredit the developer’s “honest name”, but as a warning to users, be careful with these applications.


Many thanks to all who filled and filled the topic with useful instructions. Special thanks to the distinguishedW.Masterfor the activity and constant assistance to users.

K
Theme needsCurator . Those who wish, please read Requirements for candidates to the curators of the forum . If the desire is not lost, the application can be left in the topic - I want to be curator .


Post has been edited4Serg13 - 20.01.20, 02:09
Reason for editing: Texet TM-5073



Rep: (-1)
2ultra-slim

Always went on locale)

Post has been editedkohb83 - 03.10.14, 18:24



Rep: (2)
blew root uninstaller-th hayskrinovsky software for updates that helped
hs zera s



Rep: (0)
Really
Helped
Thanks to all
All good)



Rep: (0)
Kanji 大 垃圾 translated as a large garbage. What does this mean exactly I do not know.



Rep: (57)
Highscreen Zera F, stock 4.2.2, when the Red Cross after the lock (and nowhere else!), 1 time the Chinese notifications, market worked fine, on the main screen Nova nothing appears, the system is not checked. Decided by clearing the data updates.



Rep: (0)
good day.
climbed a strange lock (in the screenshot in the center of the red circle).
It works as a lock screen. is removed by pressing the circle button or the back.
how to remove?
Attached Image


Post has been editedKEEPERekb - 08.10.14, 07:50
Reason for editing: spoiler



Rep: (0)
gigabyte gsmart guru g1
description of the problem:
Downloaded mx player or vxplayer (do not remember exactly), antivirus eset checked and said that everything is in order, then found and after installing popped the setup menu (standard with the installation of any program), and asked for the activation, after pressing the activation jumped banner - MIA Ukraine has blocked your phone blah, transfer money or your phone will be locked forever. any key except the shutdown does not respond, and the off button turns on or off the backlight. the phone can not be switched off.


There have been actions:
there were attempts to turn off devaysa pressing combinations of results has not given keys. It was an attempt to connect the phone to the computer via usb, but the computer does not see the phone

are tips to make roll back to factory settings, but the problem is that the phone does not get shut down, and no access to Batteries
Maybe someone knows how to turn the phone off or get to the battery or other method to solve the problem

Post has been editedavpavlenkobk - 04.10.14, 20:16



Rep: (0)
Thank you all for the help. I resolved the issue by clamping off button (about a minute), and then wipe data / factory reset.



Rep: (0)
Advertising in all music player.

Lenovo K900
OS and firmware: Android 4.2.2

Description of the problem:
I'm having such a problem:
When listening to music, no matter which player, instead of the image of artist or album art - there is a picture of a moose with the text "This is how our advertising" and phone number 8-917-544-46-76. How to remove this banner? And then he took me already.

There have been actions:
Was looking for the picture itself on this device, but did not find it, you see it somewhere for archiving. It turns out only when playing music.

Post has been editedTigerSS - 06.10.14, 13:09



Rep: (2304)
TigerSS @ 06.10.2014, 16:08*
When listening to music, no matter which player, instead of the image of artist or album art - there is a picture of a moose with the text "This is how our advertisement"

It is possible that enclosing a certain composition tag. Check the media, for example, these programs \SEARCH programs for Android OS (Post # 23030408) \



Rep: (0)
Hmm, what if one of the songs the tag is registered, it will be displayed on all the songs?



Rep: (12)
Caught here is ... cured rutovaniem and removing com.android.systems ...
Attached Image


Post has been editedKEEPERekb - 08.10.14, 07:50
Reason for editing: spoiler



Rep: (2304)
TigerSS @ 06.10.2014, 17:12*
and that if one of the songs the tag is registered, it will be displayed on all the songs?

Advertising is aggressive and passive (America did not open)

If the example of the software: there advertising that is displayed only when the program is running, but there is what is shown in time (at regular intervals) and violet, running software from such advertising or not - advertising in the show ...

There, the user sees it when you turn on the Internet - the principle is similar to how the code is registered. In some programs - only when you turn the program + Internet, in others - the launch of the software is not important, just when the Internet, but she did not need. Not to be confused with advertising that reaches from internet ...

A tag can prescribe anything and advertising as well. A display is activated on an event. In our case, we take the player launch ..

But this version is one of the ...

Post has been editedKEEPERekb - 06.10.14, 14:50



Rep: (0)
Here's one more feature noticed that the picture vylaziet only files with the extension .mp3, and not vylaziet other music formats.



Rep: (4106)
* TigerSS,

hypothesis "as delirium":
- you've turned on Search and download covers from some "general" of the site.
- in your hosts file the malware was prescribed redirect requests for a site to a site with advertising.



Rep: (2304)
W.Master @ 06.10.2014, 19:03*
hypothesis "as delirium":

Why delirium? Also an option. The only thing that the advertisement appears in the event that, in our case - the launch of any prigryvatelya ...

Post has been editedKEEPERekb - 06.10.14, 18:03



Rep: (4106)
KEEPERekb @ 06.10.2014, 19:02*
...
Why delirium? Also an option. The only thing that the advertisement appears in the event that, in our case - the launch of any prigryvatelya ...
If you find the cover for the media library begins when the player starts?



Rep: (8)
It can help clean the hosts
В® AdAway



Rep: (0)
* KEEPERekb,
KEEPERekb @ 06.10.2014, 14:30*
It is possible that enclosing a certain composition tag. Check the media, for example, these programs \ Search programs for Android OS (Post # 23030408) \

Yes, you were right, this picture has been sewn into the body of music files, and almost all of them. Zaytsev.net music rocked by the program.
NikSavilov @ 06.10.2014, 21:13*
It can help clean the hosts

File obsalyutno clean except zabigotogo local ip.



Rep: (2304)
TigerSS @ 07.10.2014, 09:51*
Yes, you were right, this picture has been sewn into the body of music files, and almost all of them. Zaytsev.net music rocked by the program.

This software "kroleg.net" -neodnoznachny, well .. For example, a flashing "meow", is that in general does not allow to set. Emboss error during installation Store -В® LBE Security Masterdo not miss it

Post has been editedKEEPERekb - 08.10.14, 07:43


Full version    

Help     rules

Time is now: 17/09/20 03:00