PLEASE HELP! Unknown Trojan Destroy My Family

Search This thread

boyfriend3088

New member
Sep 17, 2020
3
0
Hello friends and users of XDA forum. First I'm from Hong Kong and join XDA for more than 10 years, please accept my apprologize my poor english.

The story started from 6 years ago, during these days I changed over 20 phones. The first time I changed my mobile phone was image files and viedo files that I captured from IP cam some sensitive captures disappeared. Initially, I thought the problem of my LG-E988. So, I brought a new Phone LG-(forgot) DS. For the first few days. It looks perfectly fine, but the problems came back again. I beliveryed that it may caused by virus/malware/trojan, so I tried almost all different virus scanner avaliable, nothing was found. And sometimes I lost email, SMS message and GPS turned on by itself. I also saw the mobile screen changed itself, even took photos and videos. I told these to my family, because I have parkinson desease. So they believe I have organic psychosis and send me to hospital. Then I was trapped in hospital half a year because my wife lie and doctor did not believe what actually happened.

Over these 6 years, my computers all affected similar trojan (bootkit), It still there after fresh installed once infected. The mobile and computer can work offline, all photos and video files that copied in or out of computer / mobile will be damaged. These forum for mobile, so I concentrate on mobile trojan's issue, if you need solutions how I solve the problem, please feel free to ask.

I don't have much information about the trojan, but i have some clues can share.
(1) the trojan is not an apk nor zip package that installed by TWRP or any recovery.
(2) the trojan seems can be "inject" to any andriod systems and any brand, any model.
(3) the mobile seems must be opened physically. it must be injected into different partitions.
(4) Sometimes it works by root the mobile and install any ROM and the trojan will gone.
(5) I recently fixed a Samsung SM-A715F and I found an encrypted partition in adb shell.
(6) some files are set to some permissions even root can not copy, open, or chmod.
(7) the trojan will not infect other mobiles at same network or NFC, Bluetooth, Wifi.
(8) again, the trojan and see/listen using camera in realtime, see what you are doing, see your position, listen to background noise, the word you are typing or take full control of your phone, heat up your cpu and even turn your roaming on and transmit hundred of giga byte data.

I'm a programmer that I can write a little java program, root my mobile and install my favourite ROM, but not able to trace / detect / delete such trojan and where the data goes. Any expert can help me to doing that? It destory my family by capture something that my wife should not see. I still have a LG V20 and a honor 8A (JAT-L29) are infected. Please what to do next, or what you need.

Thanks for every one and sorry for my poor english.
 

mobnoob

Senior Member
Dec 25, 2014
138
19
LG G3
Lenovo P2
Hello friends and users of XDA forum. First I'm from Hong Kong and join XDA for more than 10 years, please accept my apprologize my poor english.

The story started from 6 years ago, during these days I changed over 20 phones. The first time I changed my mobile phone was image files and viedo files that I captured from IP cam some sensitive captures disappeared. Initially, I thought the problem of my LG-E988. So, I brought a new Phone LG-(forgot) DS. For the first few days. It looks perfectly fine, but the problems came back again. I beliveryed that it may caused by virus/malware/trojan, so I tried almost all different virus scanner avaliable, nothing was found. And sometimes I lost email, SMS message and GPS turned on by itself. I also saw the mobile screen changed itself, even took photos and videos. I told these to my family, because I have parkinson desease. So they believe I have organic psychosis and send me to hospital. Then I was trapped in hospital half a year because my wife lie and doctor did not believe what actually happened.

Over these 6 years, my computers all affected similar trojan (bootkit), It still there after fresh installed once infected. The mobile and computer can work offline, all photos and video files that copied in or out of computer / mobile will be damaged. These forum for mobile, so I concentrate on mobile trojan's issue, if you need solutions how I solve the problem, please feel free to ask.

I don't have much information about the trojan, but i have some clues can share.
(1) the trojan is not an apk nor zip package that installed by TWRP or any recovery.
(2) the trojan seems can be "inject" to any andriod systems and any brand, any model.
(3) the mobile seems must be opened physically. it must be injected into different partitions.
(4) Sometimes it works by root the mobile and install any ROM and the trojan will gone.
(5) I recently fixed a Samsung SM-A715F and I found an encrypted partition in adb shell.
(6) some files are set to some permissions even root can not copy, open, or chmod.
(7) the trojan will not infect other mobiles at same network or NFC, Bluetooth, Wifi.
(8) again, the trojan and see/listen using camera in realtime, see what you are doing, see your position, listen to background noise, the word you are typing or take full control of your phone, heat up your cpu and even turn your roaming on and transmit hundred of giga byte data.

I'm a programmer that I can write a little java program, root my mobile and install my favourite ROM, but not able to trace / detect / delete such trojan and where the data goes. Any expert can help me to doing that? It destory my family by capture something that my wife should not see. I still have a LG V20 and a honor 8A (JAT-L29) are infected. Please what to do next, or what you need.

Thanks for every one and sorry for my poor english.
It sounds to me that your computer is the main problem and I assume you connect the phone to it so the phone gets infected.
Regarding computer and virus the best thing to do is to format and reinstall the Operative System.
Regarding the phone, hard reset and no more problem.
 

boyfriend3088

New member
Sep 17, 2020
3
0
It sounds to me that your computer is the main problem and I assume you connect the phone to it so the phone gets infected.
Regarding computer and virus the best thing to do is to format and reinstall the Operative System.
Regarding the phone, hard reset and no more problem.

Thanks for the reply. Nope, plug-in into a computer won't infect the phone, but if debug turn on, it might be ture. But I'm 100% sure hard / factory reset, wipe cache won't clean the trojan. I did it million times with no apps was installed but still clear the trojan. it's not done by install an apk. according to infected 20+ phones, 80% of the phone's cover were openned. I believe they downloaded "EEPROM" boot partition and add a small portion of code. If I root the phone, sometimes i can see an unknown encrypted partition. And administrator can't access most of the files on root. The only solution is root the phone and wipe everything then, put stock rom from other sources install, but it's risky. Any others methods or suggestion to check or verify the ROMs are original stock ROM?

Please help me! Thanks!
#The attach file is rooted phone /root_files, but most file can't be copied.
 

Attachments

  • A71.tar
    415.5 KB · Views: 4
D

Deleted member 1890170

Guest
1. A Factory Reset - as its name implies - simply turns device into state when it was shipped by manufacturer, means all user-data / user-apps get wiped, system apps get reset to their original state if they got upgraded.

2. Wiping the Cache deletes only temporary system data, but not temporary user-app data.

Hence it should be obvious these 2 named actions will eliminate a trojan or other malware the Android device got infected with. But with the help of an activated Google Play Store they can re-install themselves.

Trojans ( hidden apps ) can easily get found on Android device.


FYI:

What all types of Trojans have in common is that they can only get onto the end device with the help of the user.

Trojans are not only found in email attachments. They can also piggyback on supposedly free programs. Therefore, it is once again important not to use dubious sources for software downloads such as codec packs or cracked programs, even if you might save a few bucks. The damage that can be caused by Trojans often exceeds the value of the software if it had been purchased regularly.

By the way, a Trojan should not be confused with a virus. Viruses reproduce independently, while a Trojan is merely a door opener - but with potentially devastating consequences.
 
Last edited by a moderator:
  • Like
Reactions: mobnoob

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    D
    Deleted member 1890170
    1. A Factory Reset - as its name implies - simply turns device into state when it was shipped by manufacturer, means all user-data / user-apps get wiped, system apps get reset to their original state if they got upgraded.

    2. Wiping the Cache deletes only temporary system data, but not temporary user-app data.

    Hence it should be obvious these 2 named actions will eliminate a trojan or other malware the Android device got infected with. But with the help of an activated Google Play Store they can re-install themselves.

    Trojans ( hidden apps ) can easily get found on Android device.


    FYI:

    What all types of Trojans have in common is that they can only get onto the end device with the help of the user.

    Trojans are not only found in email attachments. They can also piggyback on supposedly free programs. Therefore, it is once again important not to use dubious sources for software downloads such as codec packs or cracked programs, even if you might save a few bucks. The damage that can be caused by Trojans often exceeds the value of the software if it had been purchased regularly.

    By the way, a Trojan should not be confused with a virus. Viruses reproduce independently, while a Trojan is merely a door opener - but with potentially devastating consequences.