this post was submitted on 24 Mar 2025
16 points (100.0% liked)

Ask Android

2453 readers
1 users here now

A place to ask your questions and seek help related to your Android device and the Android ecosystem.

Whether you're looking for app recommendations, phone buying advice, or want to explore rooting and tutorials, this is the place for you!

Rules
  1. Be descriptive: Help us help you by providing as many details as you can.
  2. Be patient: You're getting free help from Internet strangers, so you may have to wait for an answer.
  3. Be helpful: If someone asks you for more information, tell us what you can. If someone asks you for a screenshot, please provide one!
  4. Be nice: Treat others with respect, even if you don't agree with their advice. Accordingly, you should expect others to be nice to you as well. Report intentionally rude answers.
  5. No piracy: Sharing or discussing pirated content is strictly prohibited. Do not ask others for a paid app or about how to acquire one.
  6. No affiliate/marketing links: Posting affiliate links is not allowed.
  7. No URL shorteners: These can hide the true location of the page and lead people to malicious places.
  8. No lockscreen bypasses: Please do not comment, link, or assist with bypassing lock screens or factory reset protection.
  9. No cross-posting: Please take the time to make a proper post instead of cross-posting.
Other Communities

founded 2 years ago
MODERATORS
 

So, an ac​quain​tance of mine has a malware which shows an ad every once a while especially when you install apps.

It's hiding in settings with an icon and name called "Settings". It has no icon in the launcher. It cannot be uninstalled. It has acquired device admin settings and even that cannot be revoked. Google play protect warns of this malware but even play protect does not have enough permissions to actually remove it for good.

I tried to enable developer options to nuke it via adb. Unfortunately, developer options are blocked with a pop-up saying Device managed by your organization.

Outside of official service center visit. Or reflashing the stock firmware. Are there any ways the malware can be deleted?

I have advised to get it fixed from the place he bought.

you are viewing a single comment's thread
view the rest of the comments
[–] ladfrombrad 2 points 4 days ago (1 children)

If it's MDM'ed, that 99.99% of the time means it's a stolen device.

Where did they buy it from exactly?

[–] limerod@reddthat.com 3 points 4 days ago (1 children)

Local shop. He had bought it on loan. Hence, I recommended he 1st try to get it fixed from the shop. Failing that the service center.

Why being MDM'ed would make it stolen?

[–] ladfrombrad 3 points 4 days ago (1 children)

Why being MDM'ed would make it stolen?

Because companies that have already implemented MDM on a device (which your friend has) will be the first to remove any trace of them on it (data protection/GDPR etc) and if it's being sold still with the credentials of said company (with bonus malware?) you might want to poke around it a little.

As the page above states - someone is in charge of that device still and can manipulate it as per the policies they introduced when locking the phone down to an entity.

tldr: most thieves ask for FRP exploits etc to get around a MDM secured device.

[–] limerod@reddthat.com 3 points 3 days ago* (last edited 3 days ago) (1 children)

He had bought the phone on loan. Loaned phones nowadays install this device management software and block dev options and adb so I have observed.

He has paid off the loan. So, there's a possibility the lock was not removed. Unless, this malware somehow managed to get more privileges than it should..

It would be comical if he bought a new stolen phone.

[–] ladfrombrad 1 points 3 days ago (1 children)

You've got me more curious about the device itself and a rough geographical area it was bought in. Care to share?

[–] limerod@reddthat.com 2 points 3 days ago (1 children)

Its a low end realme. I think Realme 12+ or something. It was bought in india. Not that I think it should make much of a difference.

[–] ladfrombrad 1 points 3 days ago (1 children)

Some of us love seeing dodgy devices and their nooks and crannies. If you wanna share them here, or even over on our TG * where there're many nerds from that region still ;)

t.me/randroidtg

[–] limerod@reddthat.com 2 points 3 days ago* (last edited 2 days ago)

Lol, its not mine. I make sure to keep mine updated and secure. Never browse the web naked without an adblocker. But, thanks for the recommendation. I'm present in that channel, just by a different name.