Link to screenshots http://pho.to/AZrGr
So, I got from avast repeatedly that there is a malware present on my smartphone in the folder “call assistant” and I cleaned it every time but still it would return. Then I installed malwarebytes, he found a Trojan with no specific description and removed it. After that, malwarebytes says it all good, but avast keeps alerting. I used then cm cleaner that has integrated Antivirus and it found also that Trojan but now with more information and suggested me to disable it forcefully which I did:
App Name:Caller ID
Behavior
execute command
cat /proc/cpuinfo
Find other files
/mnt/sdcard/Android/data/.mf.report
/mnt/sdcard/Android/data/.mfca/data_cache
/mnt/sdcard/Android/data/.MFOcsSDK
/mnt/sdcard/.dbg.ca.txt
/mnt/sdcard/Android/data/.MFOcsSDK/upgrade
/mnt/sdcard/Android
/mnt/sdcard/Android/data/.mf.report/data_cache/idDir
/mnt/sdcard/Android/data/.mf.report/data_cache
/mnt/sdcard/Android/data/.mfca/image_cache
/mnt/sdcard/Android/data/.mfca/downloaded
/mnt/sdcard/Android/data
/mnt/sdcard/.dbg.ca
/mnt/sdcard/Android/data/.mfca
/mnt/sdcard/Android/data/.mfca/upgrade
APP protected
general junkcode protector
Start service
com.android.tools.callassistant/.report1.ReportCheck
Basic Information
Package Name: com.android.tools.callassistant
File Size: 2.32MB
Certificate Info: /C=CN/ST=ShangHai/L=Shanghai/O=Mobifun/OU=Mobifun/CN=Mov/emailAddress=mov@mobifun365.com
MD5: 03e4e5bc7a21f6b9b9f2c737f56b4c33
Sha-1: 0bda624b979bec4ca291025841e93e07b0663382
Permissions
High Risk Danger Normal
Read contact info(In use)
android.permission.READ_CONTACTS
Monitor and modify outgoing calls(In use)
android.permission.PROCESS_OUTGOING_CALLS
Install applications(In use)
android.permission.INSTALL_PACKAGES
Receive boot broadcasting(In use)
android.permission.RECEIVE_BOOT_COMPLETED
Get precise location (via GPS)(In use)
android.permission.ACCESS_FINE_LOCATION
Get rough location (via wifi, base station)(In use)
android.permission.ACCESS_COARSE_LOCATION
Get info of the current/recent running tasks(In use)
android.permission.GET_TASKS
Mount、unmount file system(Not used)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS
Read WIFI state(In use)
android.permission.ACCESS_WIFI_STATE
Read and write system settings items(In use)
android.permission.WRITE_SETTINGS
Read external storage (eg: SD card)(Not used)
android.permission.READ_EXTERNAL_STORAGE
read the user’s call log.(Not used)
android.permission.READ_CALL_LOG
Read phone state(In use)
android.permission.READ_PHONE_STATE
Connect to the network (2G or 3G)(In use)
android.permission.INTERNET
Read network state (2G or 3G)(In use)
android.permission.ACCESS_NETWORK_STATE
Must be required by device administration receiver, to ensure that only the system can interact with it.(Not used)
android.permission.BIND_DEVICE_ADMIN
connect to paired bluetooth devices(In use)
android.permission.BLUETOOTH
read or write the secure system settings.(In use)
android.permission.WRITE_SECURE_SETTINGS
Display system window(Not used)
android.permission.SYSTEM_ALERT_WINDOW
Write external storage (eg: SD card)(Not used)
android.permission.WRITE_EXTERNAL_STORAGE
Startup Mode
Start service when installing applications
com.android.tools.callassistant.utils.AppInstallReceiver
com.android.tools.callassistant.report1.InitReceiver
Start service after boot
com.android.tools.callassistant.report1.InitReceiver
com.m.ms.analytics.Reciver
Start service when network changed
com.android.tools.callassistant.report1.InitReceiver
Start service when WIFI status changed
com.android.tools.callassistant.report1.InitReceiver
com.m.ms.analytics.Reciver
Start service when screen unlocked
com.m.ms.analytics.Reciver
Start service when uninstalling applications
com.android.tools.callassistant.utils.AppInstallReceiver
File Operations
Status File Size File Path
Read 14 assets/IACF
Edit: I did factory reset, formatted SD card independently, still returns. Avast, help.