Latest News

Amazon Fire TV and Fire TV Stick Devices are being Infected with Cryptocurrency Malware
Friday, June 15, 2018 IST
Amazon Fire TV and Fire TV Stick Devices are being Infected with Cryptocurrency Malware

Several users in our forums have reported that their Amazon Fire TV and Amazon Fire TV Stick devices have suddenly become very slow to use. This sudden slowdown coincides with the appearance of an app simply called “test” that keeps popping up randomly. Not only is the popup annoying, but it also causes video playback to stop and apps to stop responding, making it very difficult to continue using the device normally.

 
 

As it turns out, this “test” app is actually cryptocurrency malware that is infecting Amazon Fire TV and Fire TV Stick devices. The Test APK with the package name “com.google.time.timer” autostarts itself to execute a variation of the infamous ADB.Miner malware. Once a device is infected, the virus begins to use 100% of the device’s processing resources to mine Monero using CoinHive. To make matters worse, the malware spreads itself to other Android devices on the same network using ADB, making it difficult to deal with the situation.
 
Is my device infected?
 
Amazon Fire TV devices that are infected are slowed down drastically, with apps taking really long to load and all actions responding lazily. The Test app will also randomly pop up on the screen and make interaction with the UI difficult.
 
Simply checking for the Test application in the application list or in the application management settings doesn’t work as the app does not appear in these lists. Instead, use an app like Total Commander from the Amazon App Store to check. The Test app can appear even on devices that have not sideloaded any apps themselves, as the malware can spread itself to other devices over the network.
 
The exact source application of the malware is currently uncertain. However, it would not be far-fetched to pin the blame on sideloaded apps that aid in piracy of movies and TV shows.
 
Cleanup Solutions
 
If one of your devices is infected, there is a high chance that other Android devices (and not just Amazon Fire TV devices) on the same network are infected too. Before proceeding for cleanup, ensure that you disable ADB Debugging on all your devices, infected or otherwise.
 
Factory Reset
 
The most effective solution is to factory reset the infected device, as well as all other devices on the same network. Factory reset can be found in system settings. It will erase everything on the device and start from scratch. Make sure to back up anything important before doing a factory reset.
 
Uninstall Modded Virus
 
This solution is not recommended because the extent of the virus and the modifications it does on your system are unknown. You should only consider this option if factory resetting your devices is absolutely not an option.
 
You can delete the virus files using the following ADB commands:
 
shell rm data/local/tmp/ufo.apk
shell rm data/local/tmp/lock.txt
shell rm data/local/tmp/smi
shell rm data/local/tmp/endat
shell rm data/local/tmp/nohup
uninstall com.google.time.timer
reboot
 
 

 
 

Install a modded virus
 
This solution is inferior to factory resetting your device and hence, not recommended. You can install a modified virus application, created by XDA Member innovaciones, which “turns off” the mining function of the virus. This is achieved by substituting the run.html file in the virus with a blank page that does not have a mining script. Other changes fool the virus into reporting success, while in effect, the virus will not be generating any revenue. You can then hide the application.
 
You can find the modified virus attached in this post in our forums.
 
To prevent a re-infection, be careful of the applications that you install on your devices, and turn off “ADB Debugging” when not in use. Even if your devices are not showing a sign of infection, it would be prudent to check for the existence of this app and to keep ADB Debugging disabled until you actually need it.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 2K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 2K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
Google Pixel 3, Pixel 3 XL: Design, notched display, dual cameras and everything else we know

Google Pixel 3, Pixel 3 XL will launch in October, but we are seeing more leaks around the two flagships ahead of official debut.  

Recently posted. 818 views . 1 min read
 

 Article
Tata Blackbird in the making to take on Hyundai Creta, Maruti S Cross – Render

Here is a digital rendering of the new Tata Blackbird SUV, which is reportedly planned for launch by 2021. Digital render is credit to rendering artist Saneet Fulsu...

Recently posted. 1K views . 1 min read
 

 Article
Here’s how you can tweet in 280 characters right away.

Twitter is set to roll out the biggest ever change to its platform -- the 140-character limit will now be doubled to 280 characters. This is the first time since ...

Recently posted. 720 views . 5 min read
 

 Video
Best Skills and Technology



Recently posted . 696 views
 

 Article
Reliance Jio Summer Surprise Will Continue to Bleed Industry, Says COAI

The new Reliance Jio Summer Surprise offer will continue to bleed the industry, says cellular operators' body COAI, adding that the impact may even extend to ba...

Recently posted. 701 views . 26 min read
 

 Article
Airtel giving away free Netflix membership to customers: How to activate

Netflix content will also be available to the customers via MyAirtel app and Airtel TV app  

Recently posted. 829 views . 0 min read
 

 
 
 

   Prashnavali

  Thought of the Day

“If you are able to change your mind, you are able to change your life.”
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top