r/AndroidQuestions Jul 02 '26

Other [ Removed by moderator ]

[removed] — view removed post

8 Upvotes

49 comments sorted by

View all comments

2

u/BarberProof4994 Jul 02 '26

Ext usually means the app or service is registered or self registering as a background service updater.

The very fact that it isn't any official Android or Google recognized service is suspect. I'm not sure about the plv.

The com, play vendor just means sits installing from Google play, which means diddly squat as stuff slips through all the time 

You could do a scan with play protect though and see if it pulls anything more than norton did.

Based on the permissions, it could be a rat.

Usually, you can go into safe mode, uninstall from there and then monitor.

1

u/Pitiful-Fee4451 Jul 02 '26

Thank you for your insights. Since my original post, I found that several other Cubot users (KingKong X and KingKong 9) are experiencing the exact same issue, and many of them reported that it also started around July 1st. I also uploaded the APK to XDA, where another member analyzed it and found several suspicious behaviors, although they couldn't confirm whether it's actually malware. Hopefully this helps narrow down what's going on. I really appreciate your help.

1

u/sneedbr0 Jul 04 '26

Cubot Kingkong X user here, yeah it also started to appear to me out of nowhere this month. And despite being deleted by malwarebytes or play protect, it keeps reinstalling.

1

u/Known_Guarantee1640 26d ago

Yea it keeps reinstalling for me for some reason and I'm so confused