Koler Android Trojan

Поділитися
Вставка
  • Опубліковано 4 тра 2014
  • malwareup.org
    In today's video I take a look at a new ransomware trojan for Android called Koler. Koler very closely resembles the Reveton/Moneypak desktop locking ransomware found on Windows. When closed, Koler will open its block page every few seconds, making device use nearly impossible. While not always feasible, it is possible to open some type of task manager and kill the "BaDoink" process.
    I apologize for the lack of videos lately, I've been pretty busy with classes and the semester ending so I haven't had much time to make these videos.
  • Наука та технологія

КОМЕНТАРІ • 455

  • @liv3mau5
    @liv3mau5 10 років тому +61

    "Let's just install our animal porn" Never thought I'd hear that.

  • @MarshallRA
    @MarshallRA 10 років тому +45

    "consequences will never be the same
    cyber police"
    fucking dead lol

    • @CleggyCool
      @CleggyCool 10 років тому +3

      The best part is how "be the same" is absolutely tiny in comparison to the rest.

  • @glitchedoom
    @glitchedoom 8 років тому +23

    As someone who works with cellphones, it's amazing how many times I have had to remove this thing from customer's phones...

    • @yotoprules9361
      @yotoprules9361 6 років тому

      I had a similar trojan on my sony xperia tipo, much more persistant than the Koler trojan, I wasn't able to remove it, no antimalware could remove it so I just factory reset the device and it was gone.

    • @TheSinkBoy
      @TheSinkBoy 6 років тому +2

      So you had to remove... That APK file too? xDD How would they explain that? Or would it be named something else?

    • @skystoyhunts7225
      @skystoyhunts7225 7 місяців тому

      Well that tells me what people like

  • @VENIX75
    @VENIX75 10 років тому +148

    3:22 anyone else notice that it says "your computer will be blocked" "instead of your phone will be blocked"? fail.

  • @Ecohazard118
    @Ecohazard118 10 років тому +59

    OH SHIT, OBAMA'S POINTING AT YOU

    • @godatlas
      @godatlas 10 років тому +10

      Almost as scary as going to one of those shit haunted houses.

    • @bren7080
      @bren7080 9 років тому +4

      It would be fucking spooky as Hell if it was Uncle Sam

    • @LipstickSuccubus
      @LipstickSuccubus 7 років тому

      Ecohazard118 since Trump is the president will it show him now :/...?

  • @CertifiedNEETClassic
    @CertifiedNEETClassic 10 років тому +24

    I think at the point when your animal porn pack asks for full control of your phone, you would shut it down. Are people really that desperate for bestiality?

    • @MysticalGeek
      @MysticalGeek 9 років тому +7

      Miles "Tails" Prower
      *Judge*

  • @AnonymousSuperTuber
    @AnonymousSuperTuber 10 років тому +41

    >consequences will never be the same
    Topkek

    • @TehHijack
      @TehHijack 10 років тому

      ROFL

    • @TheQustinnus
      @TheQustinnus 10 років тому +2

      I laughed at Cyber Police being there but when I saw it said Consequences will never be the same I just choked on my cereal.

  • @hierkonnteihrewerbungstehe6428
    @hierkonnteihrewerbungstehe6428 8 років тому +26

    Just boot it into save mode.

    • @hierkonnteihrewerbungstehe6428
      @hierkonnteihrewerbungstehe6428 8 років тому

      *****​ Maybe he gave it administrator rights.

    • @hierkonnteihrewerbungstehe6428
      @hierkonnteihrewerbungstehe6428 8 років тому

      ***** Some time ago I had an app using admin rights to change the pincode. Even after booting it into the save mode I could not uninstall it so I had to do a full wipe using the recovery.

    • @hierkonnteihrewerbungstehe6428
      @hierkonnteihrewerbungstehe6428 8 років тому

      ***** Yeah it just loads the preinstalled apps but it seems that admin rights can avoid it.

  • @BradenBest
    @BradenBest 8 років тому +11

    That police badge is hilarious!

  • @GingerChristmas
    @GingerChristmas 10 років тому +3

    FYI Rogue if you're running 4.4 you can use the built in recording feature.

  • @Mareepu
    @Mareepu 9 років тому +8

    Consequences will never be the- _are you fucking kidding me...?_

    • @Eminster
      @Eminster 7 років тому

      Mareepu no I'm not. why?

  • @FubarMike
    @FubarMike 10 років тому

    if you are rooted can't you just plug the phone into the computer and delete the badoink apk or what ever its called straight from the computer?

  • @Kylemsguy
    @Kylemsguy 10 років тому

    Can't you reboot into safe mode and remove this? (to boot into safe mode hold the power button and then hold the reboot button on the power menu and click ok)

  • @ChrisYx511
    @ChrisYx511 8 років тому

    Does it work if I just plug it in the computer and move the file to C:/$RECYCLE$ (RECYCLE BIN) I didn't get infected but I'm just asking.

  • @joshuasteele349
    @joshuasteele349 10 років тому +2

    You do know that on most android systems now, if you hold down power off on the screen on the power off menu, it will open a dialog box 'reboot in safe mode?'. This will disable all startup applications and allow you to run MalwareBytes quite easily.

  • @glaciersoft1919
    @glaciersoft1919 10 років тому

    Couldn't you run the device in Airplane Mode so it cannot connect to its server, kill the process, then run Malwarebytes Mobile?

  • @nathanpremo
    @nathanpremo 9 років тому

    Where do you get that task manager program?

  • @AnarchyEngineer
    @AnarchyEngineer 10 років тому +4

    Could the user not use ADB and pull the app/delete from the device?
    Of course, not everyone would know what to do but it would beat having to factory reset or flash a new ROM.

    • @toomastamm7044
      @toomastamm7044 10 років тому +4

      If you have TWRP recovery you could also delete it with its file manager, which should be easier than ADB.

    • @itsjustkyle7719
      @itsjustkyle7719 6 років тому

      I'm not really up to date with tech terms, but if your talkin about using a computer to search through the phones file manager via usb, then theoretically you can by just deleting the apk off the phone. Androids can not get a virus which makes it 100000 times easier to remove because it's just a Trojan that stays with the defected file.

  • @airhead0523
    @airhead0523 9 років тому

    What rim do you have rogueamp?

  • @EmilysStuffAkaChocolateCat
    @EmilysStuffAkaChocolateCat 7 років тому

    rougeamp how are you recording your phone if you have a virus in the backround? vurtual machine?

    • @TheSinkBoy
      @TheSinkBoy 6 років тому

      I think an emulator. Idk, I'm not him.

  • @CarlMylo
    @CarlMylo 10 років тому

    If you enable developer options, you could enable a shortcut that allows you to kill apps by holding the back button. There is also another option, whose name I forgot, which allows you to force quite and wipe app data via task list.

  • @henryso4
    @henryso4 10 років тому

    Rogue I need help. I downloaded some crap off google play and I keep getting "senddroid notifications" which are all fake and/or spam

  • @KyleCainNintendoShine
    @KyleCainNintendoShine 7 років тому

    Is Rougeamp really from Flower Mound, TX or is that a fake IP?

  • @AzakaSekai
    @AzakaSekai 10 років тому +1

    Safe mode should usually work, it's pretty much the same as the Windows one, disables third-party apps and services, one downside is that the widgets on your launcher might be reset, but again that's just a minor issue.

  • @TheCoverGirl96
    @TheCoverGirl96 10 років тому

    What happens if you enter the wrong code three times?

  • @Panlew2
    @Panlew2 10 років тому

    Couldn't you restart the phone and open task manager as soon as possible to kill it?

  • @cannon9009
    @cannon9009 9 років тому +9

    This just teaches you not to download furry p0rn.
    If you can find some online then okay.

  • @hannahb9326
    @hannahb9326 5 років тому +1

    Anyone else wondering who where why and how somebody discovered a trojen with that name...?

  • @jure.
    @jure. 8 років тому +2

    could u use
    Android
    Debug
    Bridge

  • @xcryi
    @xcryi 7 років тому

    Ya know, you could've went to the launcher, long pressed ln, "BaDoink", went to app info, and uninstalled from there, right?

  • @denkhak
    @denkhak 10 років тому +1

    You should see what happens after you wait the time period until arrest and see if it does anything.

  • @blaisedurham1332
    @blaisedurham1332 9 років тому

    What kind of android phone do you have?

  • @leonardoadame3100
    @leonardoadame3100 9 років тому

    Can some knows how to unlock the prism from a tablet reset bottom isnt working

  • @googlemyharbl
    @googlemyharbl 10 років тому

    What android emulator do you use?

  • @Gioxzy_
    @Gioxzy_ 9 років тому

    This happend to my phone it just pop up with out me downloading anything my phone been acting up the pass days idk what to do

  • @shaunzhang733
    @shaunzhang733 10 років тому

    Can't you just connect your Android device to your computer and use some antimalware program from the computer to scan your device, and remove this trojan?

  • @adambbu
    @adambbu 10 років тому

    Hey rogueamp, will you take a look at some android fake AVs? Like Virus Shield, Skulls antivirus or something like that?

    • @SlamTF2
      @SlamTF2 10 років тому

      He did two fake AVs for android already (Armor for Android and some other one), if you meant if he can look at more then I'd also like to see some of that. Too bad android malware is boring 99% of the time...

    • @adambbu
      @adambbu 10 років тому

      I have in mind making a bunch of boring android malware in one video, becouse it wouldn't make sense to record dedicated vido for just one useless malware app.

  • @WWEUniversee3
    @WWEUniversee3 10 років тому +2

    can u do, the phone videos in landscape instead if portrait?

    • @jakem5039
      @jakem5039 10 років тому +2

      Widescreen ftw!

    • @ILoveWomen
      @ILoveWomen 10 років тому +2

      depends if the app supports it

    • @princessdar68
      @princessdar68 10 років тому

      Banned From Life it depends if the ogrelord loves me

  • @Tacom4ster
    @Tacom4ster 9 років тому

    I rhink found this on malware did it gave you an option to reload?

    • @sgtslothsub1138
      @sgtslothsub1138 9 років тому

      Adrian Dezendegui This isn't malware..

    • @andreiiftode4784
      @andreiiftode4784 8 років тому +1

      +Roth Gaming (TheLonelyGamer) IT A VURIS! A VURISSS!!!!!

  • @500youtubesubscribers5
    @500youtubesubscribers5 6 років тому

    what is droid VNC server.

  • @VeeTHis
    @VeeTHis 10 років тому

    I have seen the SAME thing on my Windows 7 Computer. It blocked my browser (Google Chrome).

  • @nostalgianinja
    @nostalgianinja 10 років тому

    I think that's why I backup often using the ClockWorkMod tool, if something like this were to happen to my phone I'd possibly reflash it using a CWM backup.
    Best option is like you said, to avoid using external applications outside of the Google Play Store, but even then, it's more helpful to be protected from things like this (using Lookout Android Security and Antivirus for Android 3.2.0 myself)
    From Android 4.4 ADB now has a function to do screen recording from the phone. Would it make things smoother? I don't exactly know,

  • @MaxTiger8
    @MaxTiger8 9 років тому

    i was looking for some help on the fbi virus but while looking on my hct desire i found something i never seen before with all my apps its was called browser update i didnt know what it was so i deleted it now the virus has gone. luckily its an old android phone so its a bit slow but it worked in my favour i deleted the virus before it started up, so if you get a fbi virus keep an eye out for an app called browser update hope that helps.

  • @douro20
    @douro20 9 років тому

    You could also kill it remotely over the Android Debug Bridge if you have it enabled...

  • @mooselexus
    @mooselexus 10 років тому

    Enjoyed! Keep them coming!

  • @lan1ern
    @lan1ern 6 років тому

    Did you now You can emulate Android

  • @StealthNinja4577
    @StealthNinja4577 9 років тому

    dual window?

  • @opensourceftw3282
    @opensourceftw3282 8 років тому

    u can adb uninstall if u enabled debugging

  • @connorm955
    @connorm955 2 роки тому +2

    I remember when i had a windows version of this from looking at porn (early 2013) it took over the whole screen and no way to exit. I had to reinstall Windows because i didn't know how to fix it.

  • @formerlycringe
    @formerlycringe 9 років тому +4

    why didn't you emulate android?

    • @cldgonz
      @cldgonz 8 років тому

      +Antonio Rodarte (DiamondEevee) i think this is emulated

  • @SparkGlassesVocaloid
    @SparkGlassesVocaloid 9 років тому

    I've always wondered what would happen if you typed in a $5 code...

  • @chriskalos_xyz
    @chriskalos_xyz 9 років тому

    What the hell kind of ROM is that?

  • @SCHAT15
    @SCHAT15 8 років тому

    how to remove the fbi virus in my samsung tablet ?

  • @no_4259
    @no_4259 7 років тому +1

    i just wonder what is his cellphone provider thinking...

  • @independent9910
    @independent9910 10 років тому

    What phone does he have?

  • @tntiscool54
    @tntiscool54 10 років тому

    how did you get task manager and file manager?

    • @DyoKasparov
      @DyoKasparov 10 років тому

      Google Play

    • @CleggyCool
      @CleggyCool 10 років тому

      Google Play, but they are pre-installed on most custom ROMs. By the looks of things, rogueamp is using either Cyanogenmod or another ROM based on it.

  • @SilasGrieves
    @SilasGrieves 10 років тому

    Read the vid description, hope you did well on your finals, Rogue. I'm in the same boat.

  • @yaboiskinnybenis4835
    @yaboiskinnybenis4835 9 років тому +5

    "Obama is pointing at you" lol

  • @avoh111
    @avoh111 7 років тому

    I got the finnish version of this malware on my phone like 2 years ago. Stupid me tried to download a game from the internet and dowloaded some game that added a sketchy system update notification on my phone. Then I tried to install the "update" and soon sauli niinistö was staring at me through the screen with my ip addres below him. I managed to remove the virus by booting into safe mode and factory resetting from the service menu.

  • @alexdaian
    @alexdaian 8 років тому +1

    Why didn't you tried to uninstall it manually then delete the .apk file.
    You also can long press the power button then long press the Shut Down option and reboot in Safe Mode where no external apps can run except the system ones.

  • @TuffyTheFox
    @TuffyTheFox 10 років тому +1

    That picture of Zapdos, its amazing

  • @hyberjection
    @hyberjection 8 років тому +7

    "Virgin Mobile" oh.

  • @_lun4r_
    @_lun4r_ 5 років тому

    Your voice sounds like the audio has been heavily compressed.

  • @CyberVisionGaming
    @CyberVisionGaming 6 років тому

    Your from texas?

    • @TheSinkBoy
      @TheSinkBoy 6 років тому

      Yoooo Cybervision, never expected to see you here.

  • @tubemaster567
    @tubemaster567 10 років тому

    or, your are going to wish you could dual-boot with windows mobile or Firefox OS to remove the app from there.

  • @United3183
    @United3183 9 років тому

    What happened to your intros on every video ?

  • @skepticmisfit2
    @skepticmisfit2 10 років тому

    couldn't you reboot the phone and it would end the process?

  • @ls_91201
    @ls_91201 8 років тому +1

    Do u now how to fix my pic it has Trojan into computer lags so bed

    • @skreefgeore6983
      @skreefgeore6983 8 років тому +3

      Grammar Nazis are having a field day right now.

    • @yincheri1421
      @yincheri1421 8 років тому

      Translation; do you know how to fix my PC it has a probable Trojan in it.
      Answer: specify

  • @ben_kallelp8142
    @ben_kallelp8142 9 років тому

    I have no taskmanager. And what I do now?

    • @realvivifromloona
      @realvivifromloona 9 років тому

      Ben_kalleLP Hold the power button in your device.A window appears.Then hold "Power off" option in the window that appeared.Click OK then your phone will reboot.Finally you can manually delete the malicious files and the malicious app.

  • @ayaya-ayaya
    @ayaya-ayaya 9 років тому +1

    The badge beats everything

  • @average7962
    @average7962 7 років тому

    wait wtf why is there a file called animalporn.apk

  • @nokiasnakes
    @nokiasnakes 8 років тому

    Couldn't you just use bluestacks? Vnc is kinda choppy :p

  • @fargeeks
    @fargeeks 9 років тому

    What phone is he using?

    • @fargeeks
      @fargeeks 8 років тому

      its either of those because i recongnize the design of this phone and these came out in 2011

  • @woop6727
    @woop6727 2 роки тому +1

    holy shit did they seriously look up "cyber police badge" and believed it was a real one

  • @ToastyTHT
    @ToastyTHT 10 років тому

    I CAN'T GET THIS TO RUN!

  • @Gioxzy_
    @Gioxzy_ 9 років тому

    How u do that with a Samsun device galaxy

    • @lolo20adaify
      @lolo20adaify 9 років тому

      Turn off your phone then reboot it when its rebooting keep pressing the "menu" button on the lest side (for Samsung ga3) that will turn safe mode on then you can go to your files find the virus and get rid of it.

    • @Gioxzy_
      @Gioxzy_ 9 років тому

      I could do that with a galaxy s3

  • @nickkazakos7512
    @nickkazakos7512 8 років тому

    works 100%
    thank you !!!!

  • @ChimeraX0401
    @ChimeraX0401 8 років тому +1

    a quick adb can remove this as long as the trojan doesn't ask for root permission you're fine....

  • @krampus_
    @krampus_ 10 років тому

    fantastic.

  • @MagikGimp
    @MagikGimp 10 років тому

    Jessy Slaughter badge? Really? Are they even trying?

  • @cyberjack
    @cyberjack 10 років тому

    definitely the way rouges going to be in future

  • @huntergman8338
    @huntergman8338 8 років тому

    Why do they want money packs?

    • @kurbackik7837
      @kurbackik7837 8 років тому

      It's ransomeware and money packs are anonymous to send.

    • @DenkiKaminari-lq7kl
      @DenkiKaminari-lq7kl 8 років тому

      moneypak is harder to trace then credit card

  • @Nathan55411
    @Nathan55411 10 років тому

    im pretty sure that all android devices has a task manager by default.

    • @jakem5039
      @jakem5039 10 років тому +1

      Not the Xperia u and the google nexus 7

    • @scrapmail770
      @scrapmail770 10 років тому

      nope but many oems do

  • @curtlaurenceacedo1081
    @curtlaurenceacedo1081 8 років тому

    Where did you download it man? cause i want to prank up my friends.

  • @FortOfBlankets
    @FortOfBlankets 10 років тому +1

    I laughed so hard at the badge!

  • @BinaryHedgehog1
    @BinaryHedgehog1 10 років тому +2

    Teh Engrish! It burns!

  • @DyoKasparov
    @DyoKasparov 10 років тому

    You could download Clean Master from CM Mobile, it can end all the apps from one click

  • @Pazzknallie
    @Pazzknallie 10 років тому +7

    It's the Cyber Police! Ya dun goofed.

  • @mick894noonoo
    @mick894noonoo 10 років тому

    You should try "Best Antivirus" adware. I got it once.

  • @repremand
    @repremand 7 років тому

    That happens to me on mediafire it takes me to fake scammers and says I'll be in jail for banned and underage things

    • @sterlingjoseph5068
      @sterlingjoseph5068 7 років тому +1

      ItZ ReDz 😂😂😂😂

    • @repremand
      @repremand 7 років тому +1

      Sterling Joseph the internet for you screw you scammers

  • @convenientparking903
    @convenientparking903 8 років тому

    I guess the name Koler is supposed to be a reference to the toilet brand Kohler.

  • @andycanyouteachmejapanese
    @andycanyouteachmejapanese 10 років тому +2

    MoneyPak how origanal e.e

    • @kbhasi
      @kbhasi 10 років тому +1

      It's supposed to be a way to transfer money to PayPal instead of using a credit card but it's abused by cyber criminals the same way wire transfers are abused by scammers

    • @andycanyouteachmejapanese
      @andycanyouteachmejapanese 10 років тому

      ***** Thanks :P

  • @PratosKS
    @PratosKS 10 років тому

    Huh. I live closer to you than I thought. San Antonio here

  • @Nieczytelny_official
    @Nieczytelny_official 4 місяці тому

    You can always go to safe mode on android and uninstall that sgit

  • @MoneyBrozYT
    @MoneyBrozYT 6 років тому

    His isp is Verizon wireless

  • @stixstixy
    @stixstixy 9 років тому

    Only Do On Android Emulator

  • @irishfever1
    @irishfever1 10 років тому

    Try and do the GameOver Zeus trojan. It looks through your financial data and if it finds any credit card information/phone numbers/names it will open up CryptoLocker.

  • @n_3719
    @n_3719 8 років тому

    BaDoink. Such a good name!

    • @commentchannel2362
      @commentchannel2362 8 років тому

      Bad oink.

    • @n_3719
      @n_3719 8 років тому

      CommentChannel yep.

    • @douro20
      @douro20 7 років тому

      It's the name of an old porn site, but not the kind which served animal porn.

  • @Stoic_sensei
    @Stoic_sensei 9 років тому

    is that zello I see

  • @artinnemati332
    @artinnemati332 4 роки тому +1

    Hi bro
    I use spynote v5
    A want to delete sms from victim phone without root and device Admin
    Can you help me ?
    And i think i can use android terminal with payload
    Tnx