There is a rogue app on my android tv that randomly launches chrome with an ad. The URL contains my IP, network provider, system details etc.
This is what I was able to find in the logcat. Can someone review and confirm that org.myklos.btautoconnect created this? It has been removed from the play store. "Bluetooth Auto Connect"
Log:
3:38:35.855 I/am_create_activity( 3744): [0,176690350,5043,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity,NULL,NULL,NULL,276856832]
08-09 13:38:35.855 I/wm_task_moved( 3744): [5043,0,2147483647]
08-09 13:38:35.866 I/am_pause_activity( 3744): [0,210040029,pl.mkexplorer.kormateusz/.MKexplorerActivity,userLeaving=true]
08-09 13:38:35.866 I/am_on_paused_called( 2343): [0,pl.mkexplorer.kormateusz.MKexplorerActivity,performPause]
08-09 13:38:35.875 I/am_restart_activity( 3744): [0,176690350,5043,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity]
08-09 13:38:35.879 I/am_set_resumed_activity( 3744): [0,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity,minimalResumeActivityLocked]
08-09 13:38:35.884 I/sysui_count( 3744): [window_time_0,8]
08-09 13:38:35.884 I/sysui_multi_action( 3744): [757,803,799,window_time_0,802,8]
08-09 13:38:35.895 I/am_on_create_called( 8065): [0,org.gg.msdns.noroxi.GGChromeActivity,performCreate]
08-09 13:38:35.900 I/am_on_start_called( 8065): [0,org.gg.msdns.noroxi.GGChromeActivity,handleStartActivity]
08-09 13:38:35.905 I/am_on_resume_called( 8065): [0,org.gg.msdns.noroxi.GGChromeActivity,RESUME_ACTIVITY]
08-09 13:38:35.915 I/WindowManager( 3744): WindowState() - found Launcher @ mAppToken:AppWindowToken{4393ddc token=Token{ed2024f ActivityRecord{a8814ae u0 org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity t5043}}}
08-09 13:38:35.940 I/auditd ( 3239): avc: denied { find } for interface=vendor.nvidia.hardware.cpl.service::INvCplHalService sid=u:r:untrusted_app:s0:c97,c256,c512,c768 pid=8065 scontext=u:r:untrusted_app:s0:c97,c256,c512,c768 tcontext=u:object_r:hal_cplservice_hwservice:s0 tclass=hwservice_manager permissive=0
08-09 13:38:35.940 I/auditd ( 3239): avc: denied { find } for interface=vendor.nvidia.hardware.cpl.service::INvCplHalService sid=u:r:untrusted_app:s0:c97,c256,c512,c768 pid=8065 scontext=u:r:untrusted_app:s0:c97,c256,c512,c768 tcontext=u:object_r:hal_cplservice_hwservice:s0 tclass=hwservice_manager permissive=0
08-09 13:38:35.971 I/am_activity_launch_time( 3744): [0,176690350,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity,95,95]
08-09 13:38:35.973 I/sysui_multi_action( 3744): [319,154,322,153,325,53057,757,761,758,8,759,2,806,org.myklos.btautoconnect,871,org.gg.msdns.noroxi.GGChromeActivity,904,org.myklos.btautoconnect,905,0,1320,8,1321,5]
08-09 13:38:36.741 I/ActivityManager( 3744): START u0 {act=android.intent.action.VIEW dat=https://rtb-connect.space/... flg=0x10000000 pkg=com.android.chrome cmp=com.android.chrome/com.google.android.apps.chrome.IntentDispatcher} from uid 10097
08-09 13:38:36.772 I/wm_stack_created( 3744): 104
08-09 13:38:36.775 I/wm_task_created( 3744): [5044,104]
08-09 13:38:36.776 I/wm_task_moved( 3744): [5044,0,2147483647]
08-09 13:38:36.776 I/am_focused_stack( 3744): [0,104,103,reuseOrNewTask]
08-09 13:38:36.777 I/am_create_task( 3744): [0,5044]
08-09 13:38:36.777 I/am_create_activity( 3744): [0,144789083,5044,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher,android.intent.action.VIEW,NULL,https://rtb-connect.space/...,276824064]
08-09 13:38:36.777 I/wm_task_moved( 3744): [5044,0,2147483647]
08-09 13:38:36.778 I/am_pause_activity( 3744): [0,176690350,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity,userLeaving=true]
08-09 13:38:36.781 I/am_finish_activity( 3744): [0,176690350,5043,org.myklos.btautoconnect/org.gg.msdns.noroxi.GGChromeActivity,app-request]
08-09 13:38:36.782 I/sysui_count( 3744): [window_time_0,0]
08-09 13:38:36.782 I/sysui_multi_action( 3744): [757,803,799,window_time_0,802,0]
08-09 13:38:36.782 I/am_on_paused_called( 8065): [0,org.gg.msdns.noroxi.GGChromeActivity,performPause]
08-09 13:38:36.783 I/am_uid_running( 3744): 10003
08-09 13:38:36.811 I/am_proc_start( 3744): [0,7520,10003,com.android.chrome,activity,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher]
08-09 13:38:36.812 I/ActivityManager( 3744): Start proc 7520:com.android.chrome/u0a3 for activity com.android.chrome/com.google.android.apps.chrome.IntentDispatcher
08-09 13:38:36.834 I/am_proc_bound( 3744): [0,7520,com.android.chrome]
08-09 13:38:36.839 I/am_uid_active( 3744): 10003
08-09 13:38:36.839 I/am_restart_activity( 3744): [0,144789083,5044,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher]
08-09 13:38:36.843 I/am_set_resumed_activity( 3744): [0,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher,minimalResumeActivityLocked]
08-09 13:38:36.843 W/ActivityManager( 3744): Request to remove task ignored for non-existent task 4130
**08-09 13:38:37.036 I/ActivityManager( 3744): START u0 {act=android.intent.action.VIEW dat=https://rtb-connect.space/... flg=0x14002000 pkg=com.android.chrome** cmp=com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity (has extras)} from uid 10003
08-09 13:38:37.037 I/am_new_intent( 3744): [0,171242538,4940,com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity,android.intent.action.VIEW,NULL,https://rtb-connect.space/...,335552512]
08-09 13:38:37.037 I/wm_task_moved( 3744): [4940,0,2147483647]
08-09 13:38:37.038 I/am_focused_stack( 3744): [0,3,104,bringingFoundTaskToFront]
08-09 13:38:37.038 I/wm_task_moved( 3744): [4940,0,2147483647]
08-09 13:38:37.038 I/am_pause_activity( 3744): [0,144789083,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher,userLeaving=true]
08-09 13:38:37.039 I/am_task_to_front( 3744): [0,4940]
08-09 13:38:37.041 I/am_finish_activity( 3744): [0,144789083,5044,com.android.chrome/com.google.android.apps.chrome.IntentDispatcher,app-request]
08-09 13:38:37.042 I/sysui_count( 3744): [window_time_0,1]
08-09 13:38:37.042 I/sysui_multi_action( 3744): [757,803,799,window_time_0,802,1]
08-09 13:38:37.042 I/am_on_create_called( 7520): [0,com.google.android.apps.chrome.IntentDispatcher,performCreate]
08-09 13:38:37.045 I/WindowManager( 3744): WindowState() - found Launcher @ mAppToken:AppWindowToken{5097fb8 token=Token{d6cf21b ActivityRecord{a34f42a u0 com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity t4940}}}
08-09 13:38:37.104 I/am_restart_activity( 3744): [0,171242538,4940,com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity]
08-09 13:38:37.105 I/am_set_resumed_activity( 3744): [0,com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity,minimalResumeActivityLocked]
08-09 13:38:37.108 I/am_stop_activity( 3744): [0,210040029,pl.mkexplorer.kormateusz/.MKexplorerActivity]
08-09 13:38:37.110 I/am_on_stop_called( 2343): [0,pl.mkexplorer.kormateusz.MKexplorerActivity,STOP_ACTIVITY_ITEM]
The Ads stopped after uninstalling the "Bluetooth Auto Connect" app.
User contributions licensed under CC BY-SA 3.0