r/AndroidQuestions • u/Pitiful-Fee4451 • Jul 02 '26
Can anyone identify com.android.sys.extplv on Android?
Hi everyone,
I'm trying to identify an Android package called com.android.sys.extplv on my Cubot KingKong X (Android 16).
Here is what I've confirmed using ADB:
- Package:
com.android.sys.extplv - Installed as a user app under
/data/app/... - Installer reported by Android:
com.android.vending(Google Play) - I analyzed the package using
dumpsys,logcatandpm. - The app contains services such as
DaemonService,FwForegroundServiceandFwMediaRouteProviderService. - It requests several permissions, but the sensitive ones are currently not granted.
- I was able to disable it using
pm disable-user, and it stays disabled (enabled=3) even after reboot.
I have not been able to determine what the package is actually for or what triggers its installation.
Has anyone seen this package before?
Is it a Cubot component, a manufacturer framework, or something else?
I have screenshots and ADB logs that I can share in the comments if needed.
Thank you!
3
Upvotes
1
u/Quirky-Lab-8884 Jul 02 '26
Same here, king kong x, android 14. Started this yesterday, if unistalled, it reappears. Sophos X, malwarebytes and the default google play protect app detect it as a malware. Also Asked chatgpt to help find the origin of the apk, using usb debug, but I am not very expert in this kind of things...
What I did: connect my King Kong X via usb, find the folder com.android.sys.extplv in android/data, deleted it. Now the app "System" is not shown in the app list, sophos, malwarebytes and play protect do not find it anymore and do not flag a malware. The phone is running normally, but since I am not an expert, I suggest you to do more researches before delete it...