Saturday, March 17, 2012

Counterclank Adware on Android -- hijacking Google search is spreading.

This morning I discovered that my phone default search had been changed to searchmobile.com without my consent -- similarly to this blog posting from Symantec, and this one from Lookout.

Importantly, I did not have any apps from that original Symantec app list.  This seems to mean that the adware is spreading.

So anyway, to work around the problem of the malware, you first have to find it.  As far as I can tell, it was probably a live wallpaper: Sakura Live Wallpaper by Xllusion.  According to Symantec's original blog entry, the Hearts Live Wallpaper was a host, but the original developer is no longer listed in Google Play Store.  The only clue that I have, is that I was playing around switching my wallpaper last night, including playing with the previously installed (and updated) Sakura Wallpaper.  It makes sense: free wallpapers have no other means to gain income other than to get you to upgrade to the paid versions, making it the most likely culprit.

So I uninstalled the Sakura Live Wallpaper and another live wallpaper, just to be safe.  I did find this live wallpaper that has no permissions: SwampWater.

Screen capture of Swamp Water Live Wallpaper.


Once you've uninstalled their app, I suggest running Norton Security Lite to check if there are any other apps hosting counterclank.  Note: Since Lookout doesn't view counterclank as malware, it won't identify it as such, so you'll have to use an antivirus that does.

Installed and ran Norton Security Lite


Now, you would think that Google would have an issue with adware software that redirects traffic away from Google's own search, but apparently not.

I have to strongly disagree with Google and Lookout: counterclank IS malware because it changes settings on my phone without my permission.

What if every free app moved to the counterclank tactic, then began to alter other settings and dropping icons onto your phone?  Obviously the list of apps that are infected is growing.  Eventually, your phone would be completely hijacked, and people, out of disgust, would move the iPhone or Windows Phone platforms.

I hate to say it, but the Googleplex has been infected by evil, and they're ignoring it.

No comments: