Malicious software (Trojan?) on Utopia M802/IMX515

Discussion in 'APAD IMX515' started by drmattp, Feb 12, 2011.

  1. drmattp

    drmattp Member

    Joined:
    Feb 12, 2011
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    60
    Location:
    NZ
    Tablet / Device:
    Utopia M802
    Hello,

    I purchased a Utopia M802/IMX515 from aliexpress. It came with a build dated 2011.01.01. I immediately installed the XAUMOD firmware on it, but I'm not sure which of these firmwares is responsible for the following program...

    There is a program that hides from all task managers, but is visible in Settings -> Applications -> Manage Applications -> All.

    At the very bottom is a strange chinese app:

    [​IMG]

    It has some fairly intrusive permissions:

    [​IMG]


    Does anyone have any idea what this program is? The 'uninstall' option is greyed out - how would I go about finding this program and uninstalling it?

    Many thanks,
    Dr Matt
     
    Last edited: Feb 13, 2011
  2. feverhost

    feverhost Super Moderator Staff Member

    Joined:
    Nov 26, 2010
    Messages:
    867
    Likes Received:
    47
    Trophy Points:
    210
    Location:
    San Diego, California U.S.A
    Tablet / Device:
    My Tablets: Pandigital White Novel - aPad iRobot RK2818 - Motorola Xoom 4G (Rooted JellyBean 4.1.2) - Kindle Fire - Novo Elf 7" - HP Slate 7" - Lenovo Yoga 2 Pro
    I have a tablet that has the same thing.... a bit alarming. Can anyone give some light?
     
  3. xaueious

    xaueious Administrator Staff Member

    Joined:
    Jul 9, 2010
    Messages:
    3,483
    Likes Received:
    435
    Trophy Points:
    222
    Location:
    Canada
    Tablet / Device:
    Asus Transformer TF300, Huwaei Ideos S7-104, HSG X5A, (Past APAD IMX515, APAD RK2808, RK2818 RT7)
  4. drmattp

    drmattp Member

    Joined:
    Feb 12, 2011
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    60
    Location:
    NZ
    Tablet / Device:
    Utopia M802
    Ahhhh... thanks for that! I can rest easy now.

    Thanks for a great firmware - it runs very well.
     
  5. drmattp

    drmattp Member

    Joined:
    Feb 12, 2011
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    60
    Location:
    NZ
    Tablet / Device:
    Utopia M802
    I gotta say - there is still something quite weird about that app. It says version 2.2, but Google Pinyin IME has only reached 1.3.2

    I installed Google Pinyin IME from the market... The installed size for that app is around 5.5 meg. The installed size for this weird app is only 149 kb.

    Most worrying of all, the permissions of this weird app don't match the official Market app. This weird app has access to "Your accounts" which the official Market app doesn't.

    Sorry to harp on about this, but anyone care to lay my concerns to rest? Are these permissions sufficient to send my gmail password to some chinese server?
     
  6. drmattp

    drmattp Member

    Joined:
    Feb 12, 2011
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    60
    Location:
    NZ
    Tablet / Device:
    Utopia M802
    No matter. I figured out how to remove this from the image and reflash.

    If anyone else would like to remove pinyin (or any other app for that matter) you can mount the system.img file in ubuntu using;

    sudo mount -o loop system.img /mnt/SDCARD

    (make the SDCARD directory first)

    remove what ever apps you want (pinyin is in /apps/PinYinIME.apk and /lib/libjni_pinyinime.so) and then umount;

    sudo umount /mnt/SDCARD

    create a new md5sum;

    md5sum system.img

    (paste the result into a new text file called system.md5)

    Proceed with flashing as per the original XAUMOD instructions.
     
    Last edited: Feb 13, 2011

Share This Page