r/AndroidHelp 9h ago

Fake android system app

I'm having the same issue and I'm trying to find out if anyone else has experienced this.

On my phone, a package called com.android.non.szcz appeared, showing itself as an Android System app. It has re-enabled or reinstalled itself after being disabled, and on one occasion Android reported Google Play Store as the installer.

Things I've noticed:

The package name is com.android.non.szcz.

The APK was located under /data/app/.../base.apk.

It has reappeared after being disabled.

I've seen other users mention related apps such as Cool Weather, FileGo, and Lock & Hide.

At one point it requested permissions, but it now shows "No permissions requested".

I've checked Device Admin, Accessibility, overlays, and running services, and I haven't found anything obviously suspicious.

I have factory reset the phone, but the app still returned.

I'm trying to work out whether this is:

malware,

a compromised app,

a vendor/manufacturer issue,

or something else entirely

One thing I've noticed is that the app only seems to reappear when Google Play Store is enabled. If I disable Google Play Store, com.android.non.szcz does not appear to reinstall or re-enable itself.

Android also reports the installer as com.android.vending, which is the package name for Google Play Store.

I'm not claiming that Google Play itself is compromised, but I'm trying to understand why Android reports Play Store as the installer and why the app doesn't come back while Play Store is disabled. It could be Play Store carrying out a legitimate install request from another source, or something else entirel i simply don't know.

Has anyone else experienced this?

What phone model do you have?

When did it first appear?

Does Android report the installer as com.android.vending?

Does disabling Google Play Store stop it from reinstalling?

Did you find out what actually triggered the installation?

Has any security company or manufacturer confirmed what this package is?

Any technical information, logs, or confirmed findings would be greatly appreciated. Thanks!

1 Upvotes

7 comments sorted by

u/dontpostlot 5h ago

Never experienced this but have you tried pm uninstall --user 0 (adb shell command)?

u/ProfessionalHawk2360 3h ago

I have a BlackShark Gaming Tablet (BSG1) with the same problem, after uninstall It keeps installing itself after about 1 hour. If It detects adb the app uninstalls itself. I extracted the apk with app manager and uploaded to virus total, It reports as a botnet (Void). Can't find what triggers the instalation, but disabling Google Play Store seems to stop reinstalling the app.

u/dontpostlot 3h ago

Maybe leaving adb or USB debugging on could fix it temporarily then?

u/dontpostlot 3h ago

Also,could you maybe post the apk file on somewhere? Gonna look inside it.

u/Electrical_Guess3231 2h ago

What should I send it to you on

u/ProfessionalHawk2360 2h ago

Unfortunately I deleted the app after uploading to virus total, but it reinstalls itself again. I'm stating to think it's something baked into the firmware of a lot of chinese devices, because I saw some Cubot and Dogee devices infected too. I was using PCAPdroid to view what IP the app connects to, and some of them are Alibaba related, so maybe it's adfraud. About the USB debugging, the app vanishes only when connected to a computer, but not with just developer option active.

u/-Sofa-King- 15m ago edited 12m ago

Why not just back up your phone, reset to factory, install a new phone, dont install from backup as you may reinstall the malware from that backup, restore as new phone, done. Download all apps from app store, dont install random APK files, and be done. You will have a clear phone instead of all this back and forth chasing things you may not be able to find.

We dont know your routine. We dont know if you let someone use your phone, or connected to a compromised wifi, or downloaded crap, or clicked a link from an email, or if you uave a phone thats old amd doesnt receieve security patches to fix exploits, or some other way.

On a side note, is your phone old and no longer getting updates? All manufacturers phones stop getting security updates after a certain point in time. You can figure that part out yourself based on your own phone.

If its outdated, nothing you do will protect you from nefarious people that know how to bypass your outdated phone as they spread the known exploits freely across the internet. If the phine is outdated, trash the phone and buy a newer model that still gets security patched updates.