LightBlog

vendredi 27 février 2015

[Q] Spyware persists after 3 factory resets

Thanks for reading this and helping me sort this out.



My soon to be ex-roommate and ex-"friend" has been spying on me with computer backdoors and spyware on my Droid Maxx (4.4.4-7) I am 100% on this, I can list the reasons why but judging from other threads in random sites, that would be a distraction. I will leave it at knowing special knowledge, his behavior and "real-time" reactions while I use the phone (clearing throat when I do certain things... now coughing since I told him he does that and he can't hold it back), everytime I reset the phone he slams the doors, caused my phone to hang up when I said "fraud" on the credit card phone system. Anyways it's legit. He did the same stuff for my computer he responded to what I typed in even and relayed what I searched for (gloating). He made random sounds play and throttled my PC speed to a crawl.



So I read elsewhere after the stuff with my phone continued to happen that there is software that can survive factory resets... I'm not sure if the ROM or kernel is the issue or some other firmware (relative noob compared to most of you) or if it is the SIM card which provides access. (if you think I am crazy look into it: since I can't post links search "Sim card apps defcon notes" and "the secret life of sim cards" also from Defcon. Also there is a somewhat related story about SIM cards being hacked in the beginning of most sim card hack searches)



He had one of his always precisely timed coughing fits when I started looking into SIM Tookit Hacks so I am suspicious of that. This was after getting a new phone (unfortunately I had the old SIM card in the new one for about an hour, I didn't know they were essentially little computers)



What do I do here? I have stock 4.4.4-7, no root (Droid Maxx is usually impossible to root currently). I have a new SIM card in but I'm afraid that now the new phone and the card are infected.



The computer software he used (backdoor/rootkits) Were mostly undetectable. I got lucky and detected only one backdoor, but later had rootkit activity detected but nothing found. I believe he has access to some new "zeroday" PC/Android software or at least it is pretty advanced. Perhaps the SIMcard has an applet that allows him to install the software over and over again since the card is not formated. This capability has been discussed in I believe both of the two first links.



I want to flash EVERYTHING. ROM, kernels, other firmware... Not sure how that could be done since I don't have root (maybe I am ignorant here) and many Verizon techs I have talked to think factory resets always work. Yes, this stuff is unlikely in general, but he has made a concerted effort to target me. Antivirus has been worthless.



I need to know 100% that everything is clean.



Thank you!





from xda-developers http://ift.tt/1FDweE9

via IFTTT

Aucun commentaire:

Enregistrer un commentaire