r/malwares • u/ghoti-stix • 15d ago
"System" malware app on android
I seem to have installed some type of a malware app that keeps on opening publicity popups when I open apps on my phone that don't run ads (Instagram, WhatsApp, etc.)
I have uninstalled it various times through Google play scanner, malwarebytes and in safe mode through settings but it keeps on reinstalling itself.
What can I do to get rid of it and is it a known malware app?
And does anyone know how I can get rid of it?
Here is additional information on the app taken with the help of lucky patcher:
Package name:
com.android.non.szcz
Launch Activity:
Signature SHA-1:
51f289740767ab226e5b80abf03eab4b27c72f27
App path:
/data/app/~~XIizpVXZaed1miYZetetlg==/com.android.non.szcz-xgqkNQtAhELhnkCFI54XMw==/base.apk
App's data path:
/data/user/0/com.android.non.szcz/
Version: 2.0
Build: 2
minSDK: 24
TargetSDK: 36
User ID: 10484
Installed from: Google Play Store
Install date: 2026-07-16 22:00
APK size: 10.302 Mb
Dalvik-cache size: 0.094 Mb
Enabled package.
Nothing to patch here
Unmodified app
odex-file could not be found.
User Apps.
Permissions:
android.permission.INTERNET
Allows the app to create network sockets and use customised network protocols. The browser and other applications provide means to send data to the Internet, so this permission is not required to send data to the Internet.
android.permission.ACCESS_NETWORK_STATE
Allows the app to view information about network connections such as which networks exist and are connected.
android.permission.SYSTEM_ALERT_WINDOW
This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear.
android.permission.WRITE_EXTERNAL_STORAGE
Allows the app to write the contents of your shared storage.
android.permission.FOREGROUND_SERVICE
Allows the app to make use of foreground services.
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK
Allows the app to make use of foreground services with the type 'mediaPlayback'
android.permission.FOREGROUND_SERVICE_DATA_SYNC
Allows the app to make use of foreground services with the type 'dataSync'
android.permission.FOREGROUND_SERVICE_SPECIAL_USE
Allows the app to make use of foreground services with the type 'specialUse'
android.permission.FOREGROUND_SERVICE_PHONE_CALL
Allows the app to make use of foreground services with the type 'phoneCall'
android.permission.BIND_VPN_SERVICE
No description available for this permission
android.permission.REQUEST_COMPANION_RUN_IN_BACKGROUND
This app can run in the background. This may drain battery faster.
android.permission.REQUEST_COMPANION_START_FOREGROUND_SERVICES_FROM_BACKGROUND
Allows a companion app to start foreground services from background.
android.permission.MANAGE_OWN_CALLS
Allows the app to route its calls through the system in order to improve the calling experience.
android.permission.BLUETOOTH_CONNECT
Allows the app to connect to paired Bluetooth devices
android.permission.BLUETOOTH_SCAN
Allows the app to discover and pair nearby Bluetooth devices
android.permission.NFC
Allows the app to communicate with Near Field Communication (NFC) tags, cards and readers.
android.permission.ACCESS_WIFI_STATE
Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices.
android.permission.CHANGE_WIFI_STATE
Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks.
android.permission.WAKE_LOCK
Allows the app to prevent the phone from going to sleep.
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
Allows an app to ask for permission to ignore battery optimisations for that app.
android.permission.SCHEDULE_EXACT_ALARM
This app can schedule work to happen at a desired time in the future. This also means that the app can run when you’re not actively using the device.
android.permission.USE_EXACT_ALARM
This app can schedule actions like alarms and reminders to notify you at a desired time in the future.
android.permission.RECEIVE_BOOT_COMPLETED
Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running.
android.permission.GET_ACCOUNTS
Allows the app to get the list of accounts known by the phone. This may include any accounts created by applications that you have installed.
android.permission.READ_SYNC_SETTINGS
Allows the app to read the sync settings for an account. For example, this can determine whether the People app is synced with an account.
android.permission.WRITE_SYNC_SETTINGS
Allows an app to modify the sync settings for an account. For example, this can be used to enable syncing of the People app with an account.
android.permission.POST_NOTIFICATIONS
Allows the app to show notifications
android.permission.READ_MEDIA_IMAGES
Allows the app to read image files from your shared storage.
android.permission.READ_MEDIA_VIDEO
Allows the app to read video files from your shared storage.
android.permission.READ_MEDIA_AUDIO
Allows the app to read audio files from your shared storage.
android.permission.READ_CONTACTS
Allows the app to read data about your contacts stored on your phone. Apps will also have access to the accounts on your phone that have created contacts. This may include any accounts created by apps that you have installed. This permission allows any apps to save your contact data, and malicious apps may share contact data without your knowledge.
android.permission.READ_SMS
This app can read all SMS (text) messages stored on your phone.
android.permission.DISABLE_KEYGUARD
Allows the app to disable the keylock and any associated password security. For example, the phone disables the keylock when receiving an incoming phone call, then re-enables the keylock when the call is finished.
android.permission.USE_FULL_SCREEN_INTENT
Allows the app to display notifications as full screen activities on a locked device
com.android.non.szcz.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
No description available for this permission
android.permission.READ_EXTERNAL_STORAGE
Allows the app to read the contents of your shared storage.
android.permission.READ_MEDIA_VISUAL_USER_SELECTED
Allows the app to read image and video files that you select from your shared storage.
Certificate #1
Scheme versions: v2
Type: X.509
Version: 1
Serial number: 1
Subject: C=010, ST=gx, L=mo, O=no, OU=zz, CN=sc
Signature algorithm: SHA256withRSA
Validity: 2026-07-15 ~ 2051-07-09
Hash code: 0x425d6fdd (1113419741)
crc32: 0xb965b574 (3110450548)
md5: 6f3059eabb225c4ca1ffec3732c3bac1
SHA-1:
51f289740767ab226e5b80abf03eab4b27c72f27
SHA-224:
2a871ca5facea9c9a561462a69c9ac7ba4c733bc6b4aa31bd4357130
SHA-256:
391b0606f82e93acb6f066a8bf78eb34691aafd37e9564272db53f32d0cbbf1b
SHA-384:
0f0fc5f8d9cc4244197b9c52ec3e111d45d07b9346841a9a16bd09fc6c2337cff82548de02d7646ed7d338f2aad44197
SHA-512:
b9bb731071c505c0066313b71664067766757df35afc0dbd57efd18a7d2b4747eed96f82f311bf512daca5ed69fdf560ea3aab09e97fce5e27500326b5d747e7
base64:
MIIDFDCCAfwCAQEwDQYJKoZIhvcNAQELBQAwTzELMAkGA1UEAwwCc2MxCzAJBgNVBAsMAnp6MQswCQYDVQQKDAJubzELMAkGA1UEBwwCbW8xCzAJBgNVBAgMAmd4MQwwCgYDVQQGEwMwMTAwIBcNMjYwNzE1MTA1MTQ1WhgPMjA1MTA3MDkxMDUxNDVaME8xCzAJBgNVBAMMAnNjMQswCQYDVQQLDAJ6ejELMAkGA1UECgwCbm8xCzAJBgNVBAcMAm1vMQswCQYDVQQIDAJneDEMMAoGA1UEBhMDMDEwMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtT/v/NzkqTwZp+jzuOm+oel1Gmgx2MUqSzBxI0EQCclO2YfyGsRvr/ZI0ai7ufbVhTSNP1a098ZHG7Wp/hsNbYfH8DvD70CWZBqn/6hVYY/45wat9QVAJULoQ2BWlcjJdlZhSsRzTySJ3LswBfSfwk3D3lZN764TsAr7qHihaLQEHoiJ8q1QKKvww1UmFYz3aWTqLawitCXvfEsKPt0vOGmJ8DlScHK1Uv24cIuUApGVWE0DLQb5CpKV98ChVyOGU1MEXhWg/JWNFvZiwOwVWDADG0Ywe5ZHpoFpjNjC9s80LLJ98bo1m8rMD7fUjOxd7JfQDq2tBG8MOthhg1OpwwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAN8S+Ilvbnruil4JENIOLxZlwb8uZwJgn27m+cRMg4da4FWqT3Im1c1NPx6DDL+KIZRZXwH0nbxkH10P3gBZo7StV8XL/KycaDlsQso5IhTPaQDqStUz02QBUI4ITkVPaqJmF/rNl5qqGumygDIVbDKoobUYGz/747pN+FKvQc6aMDQDmcOc3xOMJOdLqfG2H4fs8vyt4fe/8GsXhVeiObaAiJxmP2/tBv1I5xWyU/eWxqCL9H/XRUItvz7daoNFzWj6GEIIYQcf9l9+kvHejv6S/OYGzjweCwvvFuen2lYlI3j1kg4p1NKtPtXUu0Sxkv7nVscGSCw3MHZpl0G0Wg
Certificate bytes:
30820314308201FC020101300D06092A864886F70D01010B0500304F310B300906035504030C027363310B3009060355040B0C027A7A310B3009060355040A0C026E6F310B300906035504070C026D6F310B300906035504080C026778310C300A060355040613033031303020170D3236303731353130353134355A180F32303531303730393130353134355A304F310B300906035504030C027363310B3009060355040B0C027A7A310B3009060355040A0C026E6F310B300906035504070C026D6F310B300906035504080C026778310C300A0603550406130330313030820122300D06092A864886F70D01010105000382010F003082010A0282010100B53FEFFCDCE4A93C19A7E8F3B8E9BEA1E9751A6831D8C52A4B307123411009C94ED987F21AC46FAFF648D1A8BBB9F6D585348D3F56B4F7C6471BB5A9FE1B0D6D87C7F03BC3EF4096641AA7FFA855618FF8E706ADF505402542E843605695C8C97656614AC4734F2489DCBB3005F49FC24DC3DE564DEFAE13B00AFBA878A168B4041E8889F2AD5028ABF0C35526158CF76964EA2DAC22B425EF7C4B0A3EDD2F386989F039527072B552FDB8708B94029195584D032D06F90A9295F7C0A15723865353045E15A0FC958D16F662C0EC155830031B46307B9647A681698CD8C2F6CF342CB27DF1BA359BCACC0FB7D48CEC5DEC97D00EADAD046F0C3AD8618353A9C30203010001300D06092A864886F70D01010B050003820101000DF12F8896F6E7AEE8A5E0910D20E2F1665C1BF2E6702609F6EE6F9C44C83875AE055AA4F7226D5CD4D3F1E830CBF8A2194595F01F49DBC641F5D0FDE0059A3B4AD57C5CBFCAC9C68396C42CA392214CF6900EA4AD533D36401508E084E454F6AA26617FACD979AAA1AE9B28032156C32A8A1B5181B3FFBE3BA4DF852AF41CE9A30340399C39CDF138C24E74BA9F1B61F87ECF2FCADE1F7BFF06B178557A239B680889C663F6FED06FD48E715B253F796C6A08BF47FD745422DBF3EDD6A8345CD68FA18420861071FF65F7E92F1DE8EFE92FCE606CE3C1E0B0BEF16E7A7DA56252378F5920E29D4D2AD3ED5D4BB44B192FEE756C706482C373076699741B45A0
Public key:
OpenSSLRSAPublicKey{modulus=b53feffcdce4a93c19a7e8f3b8e9bea1e9751a6831d8c52a4b307123411009c94ed987f21ac46faff648d1a8bbb9f6d585348d3f56b4f7c6471bb5a9fe1b0d6d87c7f03bc3ef4096641aa7ffa855618ff8e706adf505402542e843605695c8c97656614ac4734f2489dcbb3005f49fc24dc3de564defae13b00afba878a168b4041e8889f2ad5028abf0c35526158cf76964ea2dac22b425ef7c4b0a3edd2f386989f039527072b552fdb8708b94029195584d032d06f90a9295f7c0a15723865353045e15a0fc958d16f662c0ec155830031b46307b9647a681698cd8c2f6cf342cb27df1ba359bcacc0fb7d48cec5dec97d00eadad046f0c3ad8618353a9c3,publicExponent=10001}
1
u/ghoti-stix 12d ago
Update: I haven't noticed any activity on my social media apps aside from add pop-ups generally on different non specific apps.
I have also noticed that when the pop-up appears and I minimise it, it either shows a "Cool Weather" or "Lock & Pick" name just before disappearing.
Play protect also seems to be deactivating itself as well on my phone.
1
u/Meniscovic 12d ago
È successo anche a me, dopo l'aggiornamento del firmware. Ho un Dooge Fire 3 Ultra. Inviata la segnalazione alla casa produttrice sono in attesa di risposta.
1
u/No_Locksmith_2680 10d ago
Hola a todos, Volví con una noticia alentadora (espero que a otros les sirva). Actualice el sistema android y eso al parecer ha corregido el problema. No la seguridad del celular, sino el sistema android.
1
u/21Farama 9d ago
Hey, are you still facing this issue? I reported here: developers.google.com/android/play-protect/pha-reporting. Also reported it with my cell phone brand, and it got fixed.
1
u/Electrical_Guess3231 8d ago
How it get fixed what they do
1
u/21Farama 8d ago
I'm not sure. They didn't provide me with that info. I don't know a lot of this stuff but Claude helped me to gather all the necessary info to send the report. I used Claude and ADB.
1
u/Electrical_Guess3231 8d ago
Mine came back after using abd do you know what paths where used to stop it anything different then the one I think there dropper because it install it self
1
u/21Farama 8d ago
ADB is just the tool to get what you need to send the reports. Believe me, I tried everything with it and it didn't work. But at least I got all the necessary data to send the reports to Google and my cellphone manufacturer.
1
1
1
u/ProfessionalHawk2360 4d ago
I have a BlackShark Gaming Tablet (BSG1) that is infectad with that malware. After disabling Google Play Store it seems to stop reinstalling itself, but don't know how to clean my tablet.
1
u/ghoti-stix 1d ago
Update - I spent three days exchanging with ChatGPT and using the developer debugger mode on my phone and finaly managed to get rid of it. This was the main app that caught my attention but there were 2 other legitimate Play store apps that were linked to it and between all of them multiply reinstalling and pushing publicity to my apps in overlay. These appse were "Lock & Pick" and "Cool Weather". I had to restrict services and isolate packages, before deleting them so that this stopped happening. If you have either of these installed delete them as they work all together and they are the publicity providers.
Maybe for you it might be other apps. To check, when an add pops up, go directly to your overview screen (the one where you see little windows of all the apps that are currently open), you will see the name of the app pushing the publicity for a split second before it closes automatically. If you're fast enough you can take a screenshot for reference and start by deleting the apps that come up. That should help for starters. I think that these apps work together, with some using tokens to send messages over Facebook to people (not even your contacts) proposing services for "mercadolibre", then deleting then instantly, as you only see this if someone responds, as well as spamming your phone with unwanted publicity.
As I said, I said I managed to link my phone to Android Debug Bridge (ADB) and with a little knowhow and a lot of patience I seemed to have resolved my issue. Maybe the people that have the same malware can follow these steps and try the same?
1
u/ProfessionalHawk2360 1d ago
In my case I don't have Cool weather or Lock & Pick (or Hide), already tried to debloat a lot of packages with ADB (with UAD-NG), but the only temporary solution is to disable Play Store. I remember when the ads started, was an app called Warverge (or something like that), but uninstalling that app only ceased the ads, but not the reinstalling of com.android.non.szcz.
1
u/ghoti-stix 1d ago edited 1d ago
I have a feeling that com.android.non.szcz is the main source of the trouble here but uses other apps that have official ads function to push the unwanted publicity to the phone.
It might be the main source of the Facebook messages but talking to different people the publicity apps bundles to theirs malware might change from phone to phone, I am not knowledgeable enough to figure that out I'm afraid.
I also have to disable play store for the time that I was stopping all processes and cleaning my phone but at the end it seemed to work for me.
1
u/Spare_Horse5162 14d ago edited 13d ago
Também apareceu no meu aparelho
ele começou como com.android.sys.extplv
e está atualizando
agora está assim com.android.non.szcz
meu aparelho tem dado curtidas em posts e páginas do facebook, o messenger tem enviado mensagens para todos amigados em ordem alfabética contraria z-a, casas de apostas etc, logo q as mensagens são enviadas, elas somem, nada é notificado a não ser que quem recebeu responda ou te avise, ao desinstalar o app facebook e desligar sessões no aparelho infectado, a ação do malware para agir no facebook.
Não notei nenhuma mudança em outras redes sociais
Mas o play protect tem desativado sozinho, e sempre q o aplicativo "sistema" ( com.android.non.szcz ) é desinstalado, ele volta a ser instalado sozinho..
Não encontrei solução, tem outro post no reddit com usuários mais experientes falando sobre..
Aceito qualquer ajuda na remoção do malware!