KingRoot Malware / Adware root !!

Allow complete removal of KingRoot with another Root Manager


  • Total voters
    555
Search This thread

gatesjunior

Inactive Recognized Developer
Nov 12, 2010
1,877
4,082
Michigan
There has been a lot of discussion about this topic and opinions. But lets be clear about a few things that are facts:

KingRoot now installs a ton of Adware on your device
KingRoot takes over your lock screen now and splatters ads on it
KingRoot's Uninstall does NOT remove everything they have modified on your device
SuperSU replace method does NOT remove everything they put on it either
KingRoot intentionally ads multiple binary files to your /system/bin folder that have nothing to do with their rooting method and are even back dating them to try and hide them
AVG has reported this and even warns of possible personal information gathering, that is NOT just a warning of rooting exploits
KingRoot has now included a Wifi option within their latest version under tools, what do you think they are gathering there ?

I have been trying to tell users for a long time that they are up to no good and they have even lied saying they tried to contact me to work with me on what they refer to as my app doing a malicious removal of their tool. That is completely incorrect... They have NEVER tried to contact me about this. They did try and ask my to stop and I told them once they allowed SupeSU to cleanly take over their root and they allowed all traces of their program to be replaced/removed I would then do it, but they never have adhered to any of that.

You the user have been warned and my conscious has been cleared. Install this at your own risk. They even went as far as trying to prevent my program from gaining root, why ? Because it will in fact remove all traces of their program including their custom binaries they have added, etc.. Now, keep in mind, they have many binaries that they add, depending on the device, but I do my best to catch them.

KingRoot, you want all of this to stop ? Then comply with the request of all the users and myself to remove EVERY file modification you have made to their device and allow replacement of your tools with whatever the user desires, cleanly.. You want to make it a paid app for you to get compensation for your time ? Fine, but get rid of all this Adware and malicious take over you have done to their device.

Let all the people speak now. It is your device and your choice of what you want to see, I am just one voice of many...

Respectfully submitted,

Gatesjunior (One of the people in the community)

Reference:

AVG:
http://www.avgthreatlabs.com/us-en/virus-and-malware-information/info/android-kingroot/
http://www.avgthreatlabs.com/us-en/android-app-reports/app/com.kingroot.kinguser/
http://www.avgthreatlabs.com/us-en/android-app-reports/app/com.kingstudio.purify

Finger printing the device:
Has the ability to get the wifi MAC address (may be used to fingerprint device)
Has the ability to read the device ID (e.g. IMEI or ESN)

Location Services (Where have you been ?):
Permission request for "android.permission.ACCESS_COARSE_LOCATION"
Permission request for "android.permission.ACCESS_FINE_LOCATION"

Camera (Can I see what your doing ?):
Permission request for "android.permission.CAMERA

Super-Sume Pro: https://xdaforums.com/general/paid-software/supersu-please-t3110954

(Sony devices, or at least the majority, you are in a bad spot, because you are rooted, but try and mount your /system into (r/w) mode... Probably not going to happen unless you load a kernel module to allow this. Otherwise you are in a write-protected mode and can only factory restore your device to get rid of it.)
 
Last edited:

craigviar

Senior Member
Aug 9, 2012
173
22
I recently upgraded my old s4 for hangouts only use (no carrier) to 501 and I used an old version of Kingroot and current SuperSUme. No worries. Thanks for a great app.

Real question is. Why can't someone legit make a kingroot type rooter that's not all jacked. It's there really no one else who knows how to do it that is honest?
 

gatesjunior

Inactive Recognized Developer
Nov 12, 2010
1,877
4,082
Michigan
I recently upgraded my old s4 for hangouts only use (no carrier) to 501 and I used an old version of Kingroot and current SuperSUme. No worries. Thanks for a great app.

Real question is. Why can't someone legit make a kingroot type rooter that's not all jacked. It's there really no one else who knows how to do it that is honest?

Sure, it can be done. But they protect, for good reasons, their rooting methods. I can't disagree with them there. But someone else would have to come out with the exploits and wrap it into a rooting method for everyone to use. They definitely have the team and resources to be able to root devices. I am very thankful for that, don't get me wrong, but the way they make you accept it all is where I take issue.
 

gatesjunior

Inactive Recognized Developer
Nov 12, 2010
1,877
4,082
Michigan
Xda has a rule about having paid apps/donate version in threads. It does not seem unreasonable to ask for a similar policy with the more important and less costly demand of being able to uninstall the app, or at least not least not block the usage of other apps (like SuperSU).

Sent from my Nexus 6P using XDA-Developers Legacy app

I agree completely. Again, malicious behavior.
 

billa

Senior Member
Mar 30, 2006
864
389
Different versions/payloads??

Because we have not been able to prove that is what is going on, the ability is there, but this is extremely difficult to prove. But, the Adware and Malware are real and has been reported by AVG and others.


After a bit of digging through the same versions released, one on their website (https://kingroot.net/), and the other here on xda (https://xdaforums.com/devdb/project/?id=9793#downloads), it appears that the payloads have been customized through some variances contained in the following files:
channel.ini, config.properties, KINGROOT.RSA, MANIFEST.MF, KINGROOT.SF, km, classes.dex
Specifically in the release channel# (channel.ini), the encrypted properties file (propertiesconfig.properties), and the (km) file.
So it's possible to have slightly different version of the payloads depending on where you've downloaded it from.
Any constructive input is welcome.
 
Last edited:

gatesjunior

Inactive Recognized Developer
Nov 12, 2010
1,877
4,082
Michigan
After a bit of digging through the same versions released, one on their website (https://kingroot.net/), and the other here on xda (https://xdaforums.com/devdb/project/?id=9793#downloads), it appears that the payloads have been customized through some variances contained in the following files:
channel.ini, config.properties, KINGROOT.RSA, MANIFEST.MF, KINGROOT.SF, km, classes.dex
Specifically in the release channel# (channel.ini), the encrypted properties file (propertiesconfig.properties), and the (km) file.
So it's possible to have slightly different version of the payloads depending on where you've downloaded it from.
Any constructive input is welcome.

Interesting.. I wonder even though the release is the same, is the build a different number ?
 
  • Like
Reactions: liksalot35

liksalot35

New member
Sep 16, 2016
3
0
San Diego
Interesting.. I wonder even though the release is the same, is the a different number ?
It is a different build number bro.if u look at the build number compared to first realease of 5.05 compared to latest release 5.05 theres a few extra numbers and/or letters in the new 5.05. But like one of the xda devs said if it's to the only way to get root do it because u can uninstall purify and replace kinguser with supersu
 

JIJOK

Senior Member
Jun 24, 2015
145
23
Because we have not been able to prove that is what is going on, the ability is there, but this is extremely difficult to prove. But, the Adware and Malware are real and has been reported by AVG and others.

noob question here, flashing a ROM will remove whole kingroot stuff ? or there is some deep thing that can't be removed ?
 
Last edited:
  • Like
Reactions: GëëkSoumya

Top Liked Posts

  • There are no posts matching your filters.
  • 78
    There has been a lot of discussion about this topic and opinions. But lets be clear about a few things that are facts:

    KingRoot now installs a ton of Adware on your device
    KingRoot takes over your lock screen now and splatters ads on it
    KingRoot's Uninstall does NOT remove everything they have modified on your device
    SuperSU replace method does NOT remove everything they put on it either
    KingRoot intentionally ads multiple binary files to your /system/bin folder that have nothing to do with their rooting method and are even back dating them to try and hide them
    AVG has reported this and even warns of possible personal information gathering, that is NOT just a warning of rooting exploits
    KingRoot has now included a Wifi option within their latest version under tools, what do you think they are gathering there ?

    I have been trying to tell users for a long time that they are up to no good and they have even lied saying they tried to contact me to work with me on what they refer to as my app doing a malicious removal of their tool. That is completely incorrect... They have NEVER tried to contact me about this. They did try and ask my to stop and I told them once they allowed SupeSU to cleanly take over their root and they allowed all traces of their program to be replaced/removed I would then do it, but they never have adhered to any of that.

    You the user have been warned and my conscious has been cleared. Install this at your own risk. They even went as far as trying to prevent my program from gaining root, why ? Because it will in fact remove all traces of their program including their custom binaries they have added, etc.. Now, keep in mind, they have many binaries that they add, depending on the device, but I do my best to catch them.

    KingRoot, you want all of this to stop ? Then comply with the request of all the users and myself to remove EVERY file modification you have made to their device and allow replacement of your tools with whatever the user desires, cleanly.. You want to make it a paid app for you to get compensation for your time ? Fine, but get rid of all this Adware and malicious take over you have done to their device.

    Let all the people speak now. It is your device and your choice of what you want to see, I am just one voice of many...

    Respectfully submitted,

    Gatesjunior (One of the people in the community)

    Reference:

    AVG:
    http://www.avgthreatlabs.com/us-en/virus-and-malware-information/info/android-kingroot/
    http://www.avgthreatlabs.com/us-en/android-app-reports/app/com.kingroot.kinguser/
    http://www.avgthreatlabs.com/us-en/android-app-reports/app/com.kingstudio.purify

    Finger printing the device:
    Has the ability to get the wifi MAC address (may be used to fingerprint device)
    Has the ability to read the device ID (e.g. IMEI or ESN)

    Location Services (Where have you been ?):
    Permission request for "android.permission.ACCESS_COARSE_LOCATION"
    Permission request for "android.permission.ACCESS_FINE_LOCATION"

    Camera (Can I see what your doing ?):
    Permission request for "android.permission.CAMERA

    Super-Sume Pro: https://xdaforums.com/general/paid-software/supersu-please-t3110954

    (Sony devices, or at least the majority, you are in a bad spot, because you are rooted, but try and mount your /system into (r/w) mode... Probably not going to happen unless you load a kernel module to allow this. Otherwise you are in a write-protected mode and can only factory restore your device to get rid of it.)
    7
    I recently upgraded my old s4 for hangouts only use (no carrier) to 501 and I used an old version of Kingroot and current SuperSUme. No worries. Thanks for a great app.

    Real question is. Why can't someone legit make a kingroot type rooter that's not all jacked. It's there really no one else who knows how to do it that is honest?

    Sure, it can be done. But they protect, for good reasons, their rooting methods. I can't disagree with them there. But someone else would have to come out with the exploits and wrap it into a rooting method for everyone to use. They definitely have the team and resources to be able to root devices. I am very thankful for that, don't get me wrong, but the way they make you accept it all is where I take issue.
    5
    There are a few scripts and cleaners out that kill KR totally.. Attached is a list of components that KR installs during the takeover.. As far as I have tested, 360Root, PermRoot,Kingo Root all use a binary that easily transfers to SuperSU without any major hacks... The bins mentioned could serve a purpose of obfuscation of root, or they could be all the connections that are required for a remote ADB hack session. China knowing what apps I use, what device I use, and where it is does not bother me nearly as much as all of that access granted to parties within the CONTUS. That is why I don't use full versions of social network apps, and use 3c Toolbox Pro to edit out individual permissions and receivers.

    The list should give you something to plug in to a batch file for ease of use.
    4
    Kingroot is a malware since it exists, i rooted one device with it.
    I used Super-Sume Pro to erased this malware en replace it with SuperSU
    3
    Tiny screen made me click the wrong poll answer. ><

    Thanks for the info