S
S
Sergey66613132018-05-30 18:50:54
Android
Sergey6661313, 2018-05-30 18:50:54

Why does the antivirus need all sorts of root / phone rights, but the virus does not? How is that?

A spammer virus named "Devices" registered on my phone (the monitor attributes the first process that comes across to the name - salmon, but this is still not the primary source of infection.). By itself, I received all possible access rights and constantly figachit ads. Resetting the firmware does not help. I think that it flies with some kind of application from the market. Not a single antivirus coped with it. I myself did not root the phone, and I did not give any application any rights other than telegram and vatsap - which I allowed access to read and write to the memory card and access to contacts.
1) Is there any analogue of the Windows process monitor for android - to at least see where the legs grow from?
2) If a virus manages to elevate its privileges without root installed, why don't antiviruses do the same?
And in general, where is it better to dig?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
S
Stalker_RED, 2018-05-30
@Stalker_RED

that's the joke that I follow all the precautions - I do not install applications from extraneous sources
this is not a sufficient condition.
That is, the rule “do not drag cats from the garbage dump home” is a useful practice so that fleas do not start up, but from apartment thieves, from a fire or from noisy neighbors, it does not protect against the word “at all”.
List of vulnerabilities: https://source.android.com/security/bulletin/
Here, for example, for February: https://source.android.com/security/bulletin/2018-...
The holes are unmeasured. Now try to check how long ago updates were released to your phone, and whether all the listed holes are closed there. But there is also 0-day (fresh, which simply has not yet managed to get into any lists, even closed ones).
About the root, everything is right pfg21 wrote.

P
pfg21, 2018-05-30
@pfg21

1) there are many, different ones, see the appropriate section of googleplay or 4pda :) I generally sometimes use top from busybox.
2) if the antivirus acts like a virus, then all sorts of programs will take it for a virus (for example, an antivirus program on Googleplay servers). But why does he need it, if there is an opportunity to officially register himself in the root program.
option A: put the same root on the phone and clean the / system partition from the left executable files. long time to think.
Option B: take it to the craftsman and reflash the phone (often requires root). fast and think ninada.
kament: the presence of a root on the phone has nothing to do with any hole in the protection (as most people think for some reason). virus and other filth is not calculated on the rootedness of the phone :)

D
d-stream, 2018-05-31
@d-stream

The virus - fits where it can, where it can not - does not fit. Antivirus - should work everywhere.
In general, similar to auto-thieves - they climb into different cars and they don’t feel sorry for breaking glass, tearing off tidy, breaking the steering lock, etc. For them, this is normal behavior. For signaling, frequent failures or false auto locks are not good.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question