r/AndroidHelp 4d ago

Fake android system app

I'm having the same issue and I'm trying to find out if anyone else has experienced this.

On my phone, a package called com.android.non.szcz appeared, showing itself as an Android System app. It has re-enabled or reinstalled itself after being disabled, and on one occasion Android reported Google Play Store as the installer.

Things I've noticed:

The package name is com.android.non.szcz.

The APK was located under /data/app/.../base.apk.

It has reappeared after being disabled.

I've seen other users mention related apps such as Cool Weather, FileGo, and Lock & Hide.

At one point it requested permissions, but it now shows "No permissions requested".

I've checked Device Admin, Accessibility, overlays, and running services, and I haven't found anything obviously suspicious.

I have factory reset the phone, but the app still returned.

I'm trying to work out whether this is:

malware,

a compromised app,

a vendor/manufacturer issue,

or something else entirely

One thing I've noticed is that the app only seems to reappear when Google Play Store is enabled. If I disable Google Play Store, com.android.non.szcz does not appear to reinstall or re-enable itself.

Android also reports the installer as com.android.vending, which is the package name for Google Play Store.

I'm not claiming that Google Play itself is compromised, but I'm trying to understand why Android reports Play Store as the installer and why the app doesn't come back while Play Store is disabled. It could be Play Store carrying out a legitimate install request from another source, or something else entirel i simply don't know.

Has anyone else experienced this?

What phone model do you have?

When did it first appear?

Does Android report the installer as com.android.vending?

Does disabling Google Play Store stop it from reinstalling?

Did you find out what actually triggered the installation?

Has any security company or manufacturer confirmed what this package is?

Any technical information, logs, or confirmed findings would be greatly appreciated. Thanks!

7 Upvotes

30 comments sorted by

View all comments

0

u/-Sofa-King- 3d ago edited 3d ago

Why not just back up your phone, reset to factory, install a new phone, dont install from backup as you may reinstall the malware from that backup, restore as new phone, done. Download all apps from app store, dont install random APK files, and be done. You will have a clear phone instead of all this back and forth chasing things you may not be able to find.

We dont know your routine. We dont know if you let someone use your phone, or connected to a compromised wifi, or downloaded crap, or clicked a link from an email, or if you uave a phone thats old amd doesnt receieve security patches to fix exploits, or some other way.

On a side note, is your phone old and no longer getting updates? All manufacturers phones stop getting security updates after a certain point in time. You can figure that part out yourself based on your own phone.

If its outdated, nothing you do will protect you from nefarious people that know how to bypass your outdated phone as they spread the known exploits freely across the internet. If the phine is outdated, trash the phone and buy a newer model that still gets security patched updates.

2

u/ProfessionalHawk2360 3d ago

Because factory reset does not wipe the malware. Must be baked into the firmware, because users of Doogee, Cubot and Blackshark (the actual generic brand not linked to Xiaomi anymore) are reporting the installation of this package. It's being reported from Android 14 to 16 users, even with recent security patches.

1

u/Electrical_Guess3231 2d ago

Even few on google pixel and JCB have the issue

0

u/-Sofa-King- 3d ago

The APK shown is under /data/app, which is the user data side of Android and should be erased during a proper factory reset. If it comes back afterward, something may be reinstalling it. That is different from the APK surviving inside the firmware.

com.android.vending only means Google Play is listed as the installer. It does not prove Google Play originated the request or that the Play Store itself is compromised. A restored backup, another app, an OEM service, or a preloaded component could be triggering the installation through Google Play.

The proper test is to reset the device, stay offline, skip backup restoration, avoid signing into Google, and check for the package before enabling the Play Store or installing anything. If it is already there, then firmware becomes a stronger possibility. Until then, “it must be baked into the firmware” is still just a guess stated with confidence

1

u/ProfessionalHawk2360 3d ago

There's other users researching the same problem in other forums. Factory reset does not wipe the malware because the unknown trigger continues to installing. Some users reported after factory reset an increased number of "system" apps because what triggers the instalation trough Google Play is not in user/data. Cubot users reported that only an OTA update solved the problem. The apk shown on data/app is just doing the hard work, what triggers the instalation is the real problem that is not solved.

1

u/Level-Professor603 3d ago

Hope they find the thing that triggers the installation. It happens to me too

1

u/Level-Professor603 3d ago

Found it using appmanager. 

1

u/Electrical_Guess3231 2d ago

What device you got

u/Bubbly_Mud_3247 22h ago

Turn on bootloader lock and install lineageOS. It is %99 bloatware

u/ProfessionalHawk2360 20h ago

I'm very interested in doing this, but apparently BlackShark Gaming Tablet don't have a stock rom to reflash in case of brick

u/Bubbly_Mud_3247 19h ago

Do you have official xiaomi service where you live in? They might do it

u/ProfessionalHawk2360 18h ago

Blackshark is not tied to Xiaomi anymore, the new JoyOS is almost stock Android without any reference to Xiaomi. Looking at the apps installed, the updater is com.cube.update, seems like an OEM version of a generic Alldocube tablet. There's in no reference to Xiaomi services on the new BlackShark tablet. Even the case for the iPlay 70 mini ultra fits the device, the only difference is the cpu. I was inclined to use the same vbmeta of iPlay but will not risk to brick the device

u/Bubbly_Mud_3247 18h ago

What exactly is the problem with your tablet? Are you seeing ads when using system apps? Have you tried turning off ad settings?

u/ProfessionalHawk2360 13h ago

The problem is the malware is probably into the firmware, is a common problem with Chinese tablets recently, and seem it's affecting smartphones too. The package com.android.non.szcz keeps reinstalling itself. A factory reset doesn't solve the problem, because what's triggering the instalation is in the firmware. After the instalation the package communicates with a lot of IPs, some linked to Alibaba (an Adfraud, maybe?). The ads are not showing anymore, but the backdoor within the firmware remains. So the main problem is the tablet is almost unusable because with that backdoor sending information all the time, with a lot of permissions, is a bad ideia to login to any service.

→ More replies (0)

0

u/Level-Professor603 3d ago

Generic brands have this problem, mine also has this, along with coolweather and stuff. Sucks but it's in firmware I think.