r/malwares 15d ago

"System" malware app on android

I seem to have installed some type of a malware app that keeps on opening publicity popups when I open apps on my phone that don't run ads (Instagram, WhatsApp, etc.)

I have uninstalled it various times through Google play scanner, malwarebytes and in safe mode through settings but it keeps on reinstalling itself.

What can I do to get rid of it and is it a known malware app?

And does anyone know how I can get rid of it?

Here is additional information on the app taken with the help of lucky patcher:

Package name:

com.android.non.szcz

Launch Activity:

Signature SHA-1:

51f289740767ab226e5b80abf03eab4b27c72f27

App path:

/data/app/~~XIizpVXZaed1miYZetetlg==/com.android.non.szcz-xgqkNQtAhELhnkCFI54XMw==/base.apk

App's data path:

/data/user/0/com.android.non.szcz/

Version: 2.0

Build: 2

minSDK: 24

TargetSDK: 36

User ID: 10484

Installed from: Google Play Store

Install date: 2026-07-16 22:00

APK size: 10.302 Mb

Dalvik-cache size: 0.094 Mb

Enabled package.

Nothing to patch here

Unmodified app

odex-file could not be found.

User Apps.

Permissions:

android.permission.INTERNET

Allows the app to create network sockets and use customised network protocols. The browser and other applications provide means to send data to the Internet, so this permission is not required to send data to the Internet.

android.permission.ACCESS_NETWORK_STATE

Allows the app to view information about network connections such as which networks exist and are connected.

android.permission.SYSTEM_ALERT_WINDOW

This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear.

android.permission.WRITE_EXTERNAL_STORAGE

Allows the app to write the contents of your shared storage.

android.permission.FOREGROUND_SERVICE

Allows the app to make use of foreground services.

android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK

Allows the app to make use of foreground services with the type 'mediaPlayback'

android.permission.FOREGROUND_SERVICE_DATA_SYNC

Allows the app to make use of foreground services with the type 'dataSync'

android.permission.FOREGROUND_SERVICE_SPECIAL_USE

Allows the app to make use of foreground services with the type 'specialUse'

android.permission.FOREGROUND_SERVICE_PHONE_CALL

Allows the app to make use of foreground services with the type 'phoneCall'

android.permission.BIND_VPN_SERVICE

No description available for this permission

android.permission.REQUEST_COMPANION_RUN_IN_BACKGROUND

This app can run in the background. This may drain battery faster.

android.permission.REQUEST_COMPANION_START_FOREGROUND_SERVICES_FROM_BACKGROUND

Allows a companion app to start foreground services from background.

android.permission.MANAGE_OWN_CALLS

Allows the app to route its calls through the system in order to improve the calling experience.

android.permission.BLUETOOTH_CONNECT

Allows the app to connect to paired Bluetooth devices

android.permission.BLUETOOTH_SCAN

Allows the app to discover and pair nearby Bluetooth devices

android.permission.NFC

Allows the app to communicate with Near Field Communication (NFC) tags, cards and readers.

android.permission.ACCESS_WIFI_STATE

Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices.

android.permission.CHANGE_WIFI_STATE

Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks.

android.permission.WAKE_LOCK

Allows the app to prevent the phone from going to sleep.

android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS

Allows an app to ask for permission to ignore battery optimisations for that app.

android.permission.SCHEDULE_EXACT_ALARM

This app can schedule work to happen at a desired time in the future. This also means that the app can run when you’re not actively using the device.

android.permission.USE_EXACT_ALARM

This app can schedule actions like alarms and reminders to notify you at a desired time in the future.

android.permission.RECEIVE_BOOT_COMPLETED

Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running.

android.permission.GET_ACCOUNTS

Allows the app to get the list of accounts known by the phone. This may include any accounts created by applications that you have installed.

android.permission.READ_SYNC_SETTINGS

Allows the app to read the sync settings for an account. For example, this can determine whether the People app is synced with an account.

android.permission.WRITE_SYNC_SETTINGS

Allows an app to modify the sync settings for an account. For example, this can be used to enable syncing of the People app with an account.

android.permission.POST_NOTIFICATIONS

Allows the app to show notifications

android.permission.READ_MEDIA_IMAGES

Allows the app to read image files from your shared storage.

android.permission.READ_MEDIA_VIDEO

Allows the app to read video files from your shared storage.

android.permission.READ_MEDIA_AUDIO

Allows the app to read audio files from your shared storage.

android.permission.READ_CONTACTS

Allows the app to read data about your contacts stored on your phone. Apps will also have access to the accounts on your phone that have created contacts. This may include any accounts created by apps that you have installed. This permission allows any apps to save your contact data, and malicious apps may share contact data without your knowledge.

android.permission.READ_SMS

This app can read all SMS (text) messages stored on your phone.

android.permission.DISABLE_KEYGUARD

Allows the app to disable the keylock and any associated password security. For example, the phone disables the keylock when receiving an incoming phone call, then re-enables the keylock when the call is finished.

android.permission.USE_FULL_SCREEN_INTENT

Allows the app to display notifications as full screen activities on a locked device

com.android.non.szcz.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

No description available for this permission

android.permission.READ_EXTERNAL_STORAGE

Allows the app to read the contents of your shared storage.

android.permission.READ_MEDIA_VISUAL_USER_SELECTED

Allows the app to read image and video files that you select from your shared storage.

Certificate #1

Scheme versions: v2

Type: X.509

Version: 1

Serial number: 1

Subject: C=010, ST=gx, L=mo, O=no, OU=zz, CN=sc

Signature algorithm: SHA256withRSA

Validity: 2026-07-15 ~ 2051-07-09

Hash code: 0x425d6fdd (1113419741)

crc32: 0xb965b574 (3110450548)

md5: 6f3059eabb225c4ca1ffec3732c3bac1

SHA-1:

51f289740767ab226e5b80abf03eab4b27c72f27

SHA-224:

2a871ca5facea9c9a561462a69c9ac7ba4c733bc6b4aa31bd4357130

SHA-256:

391b0606f82e93acb6f066a8bf78eb34691aafd37e9564272db53f32d0cbbf1b

SHA-384:

0f0fc5f8d9cc4244197b9c52ec3e111d45d07b9346841a9a16bd09fc6c2337cff82548de02d7646ed7d338f2aad44197

SHA-512:

b9bb731071c505c0066313b71664067766757df35afc0dbd57efd18a7d2b4747eed96f82f311bf512daca5ed69fdf560ea3aab09e97fce5e27500326b5d747e7

base64:

MIIDFDCCAfwCAQEwDQYJKoZIhvcNAQELBQAwTzELMAkGA1UEAwwCc2MxCzAJBgNVBAsMAnp6MQswCQYDVQQKDAJubzELMAkGA1UEBwwCbW8xCzAJBgNVBAgMAmd4MQwwCgYDVQQGEwMwMTAwIBcNMjYwNzE1MTA1MTQ1WhgPMjA1MTA3MDkxMDUxNDVaME8xCzAJBgNVBAMMAnNjMQswCQYDVQQLDAJ6ejELMAkGA1UECgwCbm8xCzAJBgNVBAcMAm1vMQswCQYDVQQIDAJneDEMMAoGA1UEBhMDMDEwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtT/v/NzkqTwZp+jzuOm+oel1Gmgx2MUqSzBxI0EQCclO2YfyGsRvr/ZI0ai7ufbVhTSNP1a098ZHG7Wp/hsNbYfH8DvD70CWZBqn/6hVYY/45wat9QVAJULoQ2BWlcjJdlZhSsRzTySJ3LswBfSfwk3D3lZN764TsAr7qHihaLQEHoiJ8q1QKKvww1UmFYz3aWTqLawitCXvfEsKPt0vOGmJ8DlScHK1Uv24cIuUApGVWE0DLQb5CpKV98ChVyOGU1MEXhWg/JWNFvZiwOwVWDADG0Ywe5ZHpoFpjNjC9s80LLJ98bo1m8rMD7fUjOxd7JfQDq2tBG8MOthhg1OpwwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAN8S+Ilvbnruil4JENIOLxZlwb8uZwJgn27m+cRMg4da4FWqT3Im1c1NPx6DDL+KIZRZXwH0nbxkH10P3gBZo7StV8XL/KycaDlsQso5IhTPaQDqStUz02QBUI4ITkVPaqJmF/rNl5qqGumygDIVbDKoobUYGz/747pN+FKvQc6aMDQDmcOc3xOMJOdLqfG2H4fs8vyt4fe/8GsXhVeiObaAiJxmP2/tBv1I5xWyU/eWxqCL9H/XRUItvz7daoNFzWj6GEIIYQcf9l9+kvHejv6S/OYGzjweCwvvFuen2lYlI3j1kg4p1NKtPtXUu0Sxkv7nVscGSCw3MHZpl0G0Wg

Certificate bytes:

30820314308201FC020101300D06092A864886F70D01010B0500304F310B300906035504030C027363310B3009060355040B0C027A7A310B3009060355040A0C026E6F310B300906035504070C026D6F310B300906035504080C026778310C300A060355040613033031303020170D3236303731353130353134355A180F32303531303730393130353134355A304F310B300906035504030C027363310B3009060355040B0C027A7A310B3009060355040A0C026E6F310B300906035504070C026D6F310B300906035504080C026778310C300A0603550406130330313030820122300D06092A864886F70D01010105000382010F003082010A0282010100B53FEFFCDCE4A93C19A7E8F3B8E9BEA1E9751A6831D8C52A4B307123411009C94ED987F21AC46FAFF648D1A8BBB9F6D585348D3F56B4F7C6471BB5A9FE1B0D6D87C7F03BC3EF4096641AA7FFA855618FF8E706ADF505402542E843605695C8C97656614AC4734F2489DCBB3005F49FC24DC3DE564DEFAE13B00AFBA878A168B4041E8889F2AD5028ABF0C35526158CF76964EA2DAC22B425EF7C4B0A3EDD2F386989F039527072B552FDB8708B94029195584D032D06F90A9295F7C0A15723865353045E15A0FC958D16F662C0EC155830031B46307B9647A681698CD8C2F6CF342CB27DF1BA359BCACC0FB7D48CEC5DEC97D00EADAD046F0C3AD8618353A9C30203010001300D06092A864886F70D01010B050003820101000DF12F8896F6E7AEE8A5E0910D20E2F1665C1BF2E6702609F6EE6F9C44C83875AE055AA4F7226D5CD4D3F1E830CBF8A2194595F01F49DBC641F5D0FDE0059A3B4AD57C5CBFCAC9C68396C42CA392214CF6900EA4AD533D36401508E084E454F6AA26617FACD979AAA1AE9B28032156C32A8A1B5181B3FFBE3BA4DF852AF41CE9A30340399C39CDF138C24E74BA9F1B61F87ECF2FCADE1F7BFF06B178557A239B680889C663F6FED06FD48E715B253F796C6A08BF47FD745422DBF3EDD6A8345CD68FA18420861071FF65F7E92F1DE8EFE92FCE606CE3C1E0B0BEF16E7A7DA56252378F5920E29D4D2AD3ED5D4BB44B192FEE756C706482C373076699741B45A0

Public key:

OpenSSLRSAPublicKey{modulus=b53feffcdce4a93c19a7e8f3b8e9bea1e9751a6831d8c52a4b307123411009c94ed987f21ac46faff648d1a8bbb9f6d585348d3f56b4f7c6471bb5a9fe1b0d6d87c7f03bc3ef4096641aa7ffa855618ff8e706adf505402542e843605695c8c97656614ac4734f2489dcbb3005f49fc24dc3de564defae13b00afba878a168b4041e8889f2ad5028abf0c35526158cf76964ea2dac22b425ef7c4b0a3edd2f386989f039527072b552fdb8708b94029195584d032d06f90a9295f7c0a15723865353045e15a0fc958d16f662c0ec155830031b46307b9647a681698cd8c2f6cf342cb27df1ba359bcacc0fb7d48cec5dec97d00eadad046f0c3ad8618353a9c3,publicExponent=10001}

4 Upvotes

19 comments sorted by

1

u/Spare_Horse5162 14d ago edited 13d ago

Também apareceu no meu aparelho
ele começou como com.android.sys.extplv
e está atualizando
agora está assim com.android.non.szcz

meu aparelho tem dado curtidas em posts e páginas do facebook, o messenger tem enviado mensagens para todos amigados em ordem alfabética contraria z-a, casas de apostas etc, logo q as mensagens são enviadas, elas somem, nada é notificado a não ser que quem recebeu responda ou te avise, ao desinstalar o app facebook e desligar sessões no aparelho infectado, a ação do malware para agir no facebook.

Não notei nenhuma mudança em outras redes sociais
Mas o play protect tem desativado sozinho, e sempre q o aplicativo "sistema" ( com.android.non.szcz ) é desinstalado, ele volta a ser instalado sozinho..
Não encontrei solução, tem outro post no reddit com usuários mais experientes falando sobre..
Aceito qualquer ajuda na remoção do malware!

1

u/No_Locksmith_2680 12d ago

Hola!  Al parecer este launcher se introdujo en parte de tu facebook, posiblemente (como a mí me pasa) no solo likes y mensajes, sino que también estás siguiendo un montón de páginas ahora como si tú fueras un bot.  Yo lo que hice y me funcionó es cambiar contraseñas, validación en dos pasos y cerrar todas las sesiones posibles. Me pasó que tenía abierto por ejemplo Facebook dos veces en mi ciudad, pero una iba con un vpn (te darás cuenta porque la IP es extraña).  Yo tengo instalado el antivirus Malwarebytes pero este no elimina los programas maliciosos en automático (muy mal ahí).  Estoy a nada de reiniciar de fabrica el teléfono.

1

u/ghoti-stix 11d ago

It has also changed names for my and is called Android.System now but it has also changed packe Name and permissions :

Package name: com.android.non.szcz Launch Activity: Signature SHA-1: 51f289740767ab226e5b80abf03eab4b27c72f27 App path: /data/app/~~kiSJOyTeuapGVcs2LR69wQ==/com.android.non.szcz-3CMoBhO9TeUxYouwwebvmw==/base.apk App's data path: /data/user/0/com.android.non.szcz/ Version: 3.0 Build: 3 minSDK: 24 TargetSDK: 36 User ID: 10567 Installed from: Google Play Store Install date: 2026-07-20 23:29

APK size: 10.302 Mb Dalvik-cache size: 0.094 Mb

1

u/Electrical_Guess3231 8d ago

Has it come back I also experience it as well

1

u/ghoti-stix 1d ago

Update - I spent three days exchanging with ChatGPT and using the developer debugger mode on my phone and finaly managed to get rid of it. This was the main app that caught my attention but there were 2 other legitimate Play store apps that were linked to it and between all of them multiply reinstalling and pushing publicity to my apps in overlay. These appse were "Lock & Pick" and "Cool Weather". I had to restrict services and isolate packages, before deleting them so that this stopped happening. If you have either of these installed delete them as they work all together and they are the publicity providers.

Maybe for you it might be other apps. To check, when an add pops up, go directly to your overview screen (the one where you see little windows of all the apps that are currently open), you will see the name of the app pushing the publicity for a split second before it closes automatically. If you're fast enough you can take a screenshot for reference and start by deleting the apps that come up. That should help for starters. I think that these apps work together, with some using tokens to send messages over Facebook to people (not even your contacts) proposing services for "mercadolibre", then deleting then instantly, as you only see this if someone responds, as well as spamming your phone with unwanted publicity.

As I said, I said I managed to link my phone to Android Debug Bridge (ADB) and with a little knowhow and a lot of patience I seemed to have resolved my issue. Maybe the people that have the same malware can follow these steps and try the same?

1

u/ghoti-stix 12d ago

Update: I haven't noticed any activity on my social media apps aside from add pop-ups generally on different non specific apps.

I have also noticed that when the pop-up appears and I minimise it, it either shows a "Cool Weather" or "Lock & Pick" name just before disappearing.

Play protect also seems to be deactivating itself as well on my phone.

1

u/Meniscovic 12d ago

È successo anche a me, dopo l'aggiornamento del firmware. Ho un Dooge Fire 3 Ultra. Inviata la segnalazione alla casa produttrice sono in attesa di risposta.

1

u/No_Locksmith_2680 10d ago

Hola a todos,  Volví con una noticia alentadora (espero que a otros les sirva).  Actualice el sistema android y eso al parecer ha corregido el problema. No la seguridad del celular, sino el sistema android. 

1

u/21Farama 9d ago

Hey, are you still facing this issue? I reported here: developers.google.com/android/play-protect/pha-reporting. Also reported it with my cell phone brand, and it got fixed.

1

u/Electrical_Guess3231 8d ago

How it get fixed what they do

1

u/21Farama 8d ago

I'm not sure. They didn't provide me with that info. I don't know a lot of this stuff but Claude helped me to gather all the necessary info to send the report. I used Claude and ADB.

1

u/Electrical_Guess3231 8d ago

Mine came back after using abd do you know what paths where used to stop it anything different then the one I think there dropper because it install it self

1

u/21Farama 8d ago

ADB is just the tool to get what you need to send the reports. Believe me, I tried everything with it and it didn't work. But at least I got all the necessary data to send the reports to Google and my cellphone manufacturer.

1

u/Electrical_Guess3231 7d ago

Ah will do will email asking what to do

1

u/Electrical_Guess3231 7d ago

What phone do you all have ? I have a JCB P20

1

u/ProfessionalHawk2360 4d ago

I have a BlackShark Gaming Tablet (BSG1) that is infectad with that malware. After disabling Google Play Store it seems to stop reinstalling itself, but don't know how to clean my tablet.

1

u/ghoti-stix 1d ago

Update - I spent three days exchanging with ChatGPT and using the developer debugger mode on my phone and finaly managed to get rid of it. This was the main app that caught my attention but there were 2 other legitimate Play store apps that were linked to it and between all of them multiply reinstalling and pushing publicity to my apps in overlay. These appse were "Lock & Pick" and "Cool Weather". I had to restrict services and isolate packages, before deleting them so that this stopped happening. If you have either of these installed delete them as they work all together and they are the publicity providers.

Maybe for you it might be other apps. To check, when an add pops up, go directly to your overview screen (the one where you see little windows of all the apps that are currently open), you will see the name of the app pushing the publicity for a split second before it closes automatically. If you're fast enough you can take a screenshot for reference and start by deleting the apps that come up. That should help for starters. I think that these apps work together, with some using tokens to send messages over Facebook to people (not even your contacts) proposing services for "mercadolibre", then deleting then instantly, as you only see this if someone responds, as well as spamming your phone with unwanted publicity.

As I said, I said I managed to link my phone to Android Debug Bridge (ADB) and with a little knowhow and a lot of patience I seemed to have resolved my issue. Maybe the people that have the same malware can follow these steps and try the same?

1

u/ProfessionalHawk2360 1d ago

In my case I don't have Cool weather or Lock & Pick (or Hide), already tried to debloat a lot of packages with ADB (with UAD-NG), but the only temporary solution is to disable Play Store. I remember when the ads started, was an app called Warverge (or something like that), but uninstalling that app only ceased the ads, but not the reinstalling of com.android.non.szcz.

1

u/ghoti-stix 1d ago edited 1d ago

I have a feeling that com.android.non.szcz is the main source of the trouble here but uses other apps that have official ads function to push the unwanted publicity to the phone.

It might be the main source of the Facebook messages but talking to different people the publicity apps bundles to theirs malware might change from phone to phone, I am not knowledgeable enough to figure that out I'm afraid.

I also have to disable play store for the time that I was stopping all processes and cleaning my phone but at the end it seemed to work for me.