Latest News

Amazon Fire TV and Fire TV Stick Devices are being Infected with Cryptocurrency Malware
Friday, June 15, 2018 IST
Amazon Fire TV and Fire TV Stick Devices are being Infected with Cryptocurrency Malware

Several users in our forums have reported that their Amazon Fire TV and Amazon Fire TV Stick devices have suddenly become very slow to use. This sudden slowdown coincides with the appearance of an app simply called “test” that keeps popping up randomly. Not only is the popup annoying, but it also causes video playback to stop and apps to stop responding, making it very difficult to continue using the device normally.

 
 

As it turns out, this “test” app is actually cryptocurrency malware that is infecting Amazon Fire TV and Fire TV Stick devices. The Test APK with the package name “com.google.time.timer” autostarts itself to execute a variation of the infamous ADB.Miner malware. Once a device is infected, the virus begins to use 100% of the device’s processing resources to mine Monero using CoinHive. To make matters worse, the malware spreads itself to other Android devices on the same network using ADB, making it difficult to deal with the situation.
 
Is my device infected?
 
Amazon Fire TV devices that are infected are slowed down drastically, with apps taking really long to load and all actions responding lazily. The Test app will also randomly pop up on the screen and make interaction with the UI difficult.
 
Simply checking for the Test application in the application list or in the application management settings doesn’t work as the app does not appear in these lists. Instead, use an app like Total Commander from the Amazon App Store to check. The Test app can appear even on devices that have not sideloaded any apps themselves, as the malware can spread itself to other devices over the network.
 
The exact source application of the malware is currently uncertain. However, it would not be far-fetched to pin the blame on sideloaded apps that aid in piracy of movies and TV shows.
 
Cleanup Solutions
 
If one of your devices is infected, there is a high chance that other Android devices (and not just Amazon Fire TV devices) on the same network are infected too. Before proceeding for cleanup, ensure that you disable ADB Debugging on all your devices, infected or otherwise.
 
Factory Reset
 
The most effective solution is to factory reset the infected device, as well as all other devices on the same network. Factory reset can be found in system settings. It will erase everything on the device and start from scratch. Make sure to back up anything important before doing a factory reset.
 
Uninstall Modded Virus
 
This solution is not recommended because the extent of the virus and the modifications it does on your system are unknown. You should only consider this option if factory resetting your devices is absolutely not an option.
 
You can delete the virus files using the following ADB commands:
 
shell rm data/local/tmp/ufo.apk
shell rm data/local/tmp/lock.txt
shell rm data/local/tmp/smi
shell rm data/local/tmp/endat
shell rm data/local/tmp/nohup
uninstall com.google.time.timer
reboot
 
 

 
 

Install a modded virus
 
This solution is inferior to factory resetting your device and hence, not recommended. You can install a modified virus application, created by XDA Member innovaciones, which “turns off” the mining function of the virus. This is achieved by substituting the run.html file in the virus with a blank page that does not have a mining script. Other changes fool the virus into reporting success, while in effect, the virus will not be generating any revenue. You can then hide the application.
 
You can find the modified virus attached in this post in our forums.
 
To prevent a re-infection, be careful of the applications that you install on your devices, and turn off “ADB Debugging” when not in use. Even if your devices are not showing a sign of infection, it would be prudent to check for the existence of this app and to keep ADB Debugging disabled until you actually need it.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 2K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 2K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
FROM '12345' TO 'BLINK182', THE MOST HACKED PASSWORDS REVEALED IN WARNING OVER CYBER-SECURITY

Liverpool is most common Premier League football team used in passwords, with Superman most popular fictional character

Recently posted. 805 views . 0 min read
 

 Article
Honda CB300R vs Kawasaki Ninja 300, RE 650, KTM 390, Bajaj Dominar, BMW 310

The new Honda Cb300R enters a segment commanded by the likes of the KTM 390 Duke, BMW G 310 R, Bajaj Dominar, Kawasaki Ninja 300 and Royal Enfield Interceptor 650.<...

Recently posted. 1K views . 1 min read
 

 Article
Amazon Offers To Buy 60% Stake In Flipkart: Report

Amazon also offered Flipkart a breakup fee of $2 billion and is likely to be on par with Walmart Inc's bid for the e-commerce company.

Recently posted. 531 views . 1 min read
 

 Video
Galaxy X's RIVAL



Recently posted . 1K views
 

 Reviews
Samsung HW-N400 'TV Mate' Soundbar review



Recently posted . 1K views . 61 min read
 

 Article
WhatsApp Users Alert! From free flight tickets, Ayushmaan Bharat, WhatsApp Gold to free Paytm cash, beware of latest hacking tricks

Whatsapp Alert: Over the last few weeks, messages linked to free air tickets, WhatsApp Gold update and Ayushmaan Bharat registration have been doing rounds on the a...

Recently posted. 844 views . 1 min read
 

 Article
Draft E-Commerce Policy: Chinese Online Retailers May Have To Register Entities In India

Foreign online retailers will have to register entities in India if they want to set up e-commerce platforms in the country, besides ensuring that all product shipm...

Recently posted. 682 views . 1 min read
 

 
 
 

   Prashnavali

  Thought of the Day

We make our choices. Then our choices make us.
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top