Another reason why NOT use root toolkits..

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,056
25,931
0
BROOKLYN!
www.androidcommunity.com
Another reason to NOT use root toolkits.. http://www.symantec.com/connect/fr/blogs/malware-uses-google-go-language

Malware Uses Google Go Language


Designed in 2007 and introduced in late 2009, the Go programming language developed by Google has been gaining momentum the past three years. It is now being used to develop malware. Recently seen in the wild, Trojan.Encriyoko is a new threat associated with components which are written in Go. The Trojan attempts to encrypt various file formats on compromised computers, rendering the encrypted files unusable.

The original sample we acquired, a file named GalaxyNxRoot.exe, is actually a dropper written in .NET which disguises itself as a rooting tool to trick users into installing it.



Figure 1. GalaxyNxRoot.exe properties


Once executed, the GalaxyNxRoot.exe file drops and launches two executable files, both written in Go:

%Temp%PPSAP.exe
%Temp%adbtool.exe
The dropped PPSAP.exe file is an information-stealing Trojan. It collects system information such as current running processes, user name, MAC address, etc., and posts it to the following remote location:
[http://]golang.iwebs.ws/about/step1.php

The dropped adbtool.exe file downloads an encrypted file from the following remote location:
[http://]sourceslang.iwebs.ws/downs/zdx.tgz

This file is decrypted as a Dynamic-link library (DLL) file and then loaded. It attempts to encrypt various file formats on the compromised computer. The targeted file formats include:

Source code files (.c, .cpp, .cs, .php, .java, .pas, .vb, .frm, .bas, .go, .asp, .aspx, .jsp, .pl, .py, .rb)
Image files (.jpg, .png, .psd)
Audio files (.wav, .wma, .amr, .awb)
Archive files (.rar, .zip, .iso, .gz, .7z)
Document files (file extensions containing the following strings: doc, xls, ppt, mdb, pdf)
Other types of files (file extensions containing the following strings: dw, dx, sh, pic, 111, win, wvw, drw, grp, rpl, mce, mcg, pag)



Figure 2. Targeted file formats


The file paths are confirmed by the Trojan in order to avoid encrypting files under certain paths, such as %Windir%, %ProgramFiles%, %UserProfile%\Local Settings, and others.

The encryption uses the Blowfish algorithm. It either reads the encryption key from D:\nepia.dud or randomly generates one. The names of all of the encrypted files are then saved to the following location:
%Temp%\vxsur.bin

Restoration of the encrypted files will be difficult, if not impossible.

Symantec detects all these files: GalaxyNxRoot.exe as Trojan.Dropper, PPSAP.exe as Infostealer, adbtool.exe as Downloader, and zdx.dll as Trojan.Encriyoko.
 
Last edited:

El Daddy

Retired Forum Moderator
May 2, 2008
4,262
5,211
263
Roseville, MN
Unfortunately, we can come up with 1,000 reasons not to use Toolkits, but they will still be used and we'll still be answering "OMGZZ I BriKEd mY FONEz" threads.

Thanks for posting this though. Throw it in my thread if you wish. :)
 
  • Like
Reactions: Mach3.2

lowandbehold

Senior Member
Feb 26, 2011
3,535
574
0
Vandling, PA
Unless you have come up with your own root method and not just following a step by step thread, you really have no room to talk. The simple fact is that it is their phone, their property, and they can do with it as they please. Isn't that why we support Android? If you don't like the threads about people bricking their phone, don't open it. I hardly see how typing "oem bootloader unlock" teaches you the ins and outs of your phone. Drama queens...
(and just for the record, I have never used a toolkit)
 

Chocu1a

Senior Member
Sep 16, 2011
458
150
0
Might as well make a thread about installing .EXE or using Facebook, or opening email attachments, or...the list go on & on. You can get a virus from almost anything...if you are careless & stupid.
Pointless.
 

Mach3.2

Senior Member
May 1, 2012
2,042
446
0
Singapore
Unless you have come up with your own root method and not just following a step by step thread, you really have no room to talk. The simple fact is that it is their phone, their property, and they can do with it as they please. Isn't that why we support Android? If you don't like the threads about people bricking their phone, don't open it. I hardly see how typing "oem bootloader unlock" teaches you the ins and outs of your phone. Drama queens...
(and just for the record, I have never used a toolkit)
To type these commands, you will have to read up to install android adk and all the drivers, even if you follow the step by step guides blindly, you will learn something in the long run if you keep doing it.

Beamed from Maguro
 
  • Like
Reactions: efrant

JiminyCricket64

Senior Member
Apr 25, 2011
68
13
28
Might as well make a thread about installing .EXE or using Facebook, or opening email attachments, or...the list go on & on. You can get a virus from almost anything...if you are careless & stupid.
Pointless.
Agreed...you can probably get a virus on your TV now, but that won't discourage using websites/streaming on your TV either. The internet is still the "Wild Wild West" :cowboy: -- you have to watch your back or where you venture to. :eek:
 
  • Like
Reactions: Chocu1a

zephiK

Inactive Recognized Developer
Aug 23, 2009
21,657
37,704
0
New York, NY
Instead of why not to use a root toolkit. The thread title should of been, "don't download things from unreliable sources/users" which should be common sense to users but sadly it isn't for everybody.

Sent from my Galaxy Nexus using xda premium
 

slayr76

Senior Member
Mar 26, 2012
1,195
239
0
perth
So if we don't use root toolkits we should never have problems with malware or viruses lol, if only that was the case, I fail to see how one instance of a untrusted malware infected toolkit is the cause of everyone's worries an concern as its a bit more widespread than just a toolkit but I like how you somehow managed to blame toolkits for all the malware out there, I agree toolkits can cause problems by people not understanding how their phone works but malware is not one of them, people know what av is these days even if they are careless enough to not use a trusted app or get something like this, considering the toolkit everyone uses an trusts is made by a senior xda mod an not this toolkit is very unlikely to happen.
 
Last edited:
Our Apps
Get our official app!
The best way to access XDA on your phone
Nav Gestures
Add swipe gestures to any Android
One Handed Mode
Eases uses one hand with your phone