I have witnessed virus on Droid ongoing issue
***OKAY THIS IS ONE HELLUVA LONG READ. IF YOU KNOW ANYTHING ABOUT PHONE VIRUSES, THE DROID, OR STALKERS HACKING CELL PHONES, PLEASE READ AND PLEASE HELP. THIS IS 100% TRUTH. I AM NOT CRAZY, THE PEOPLE INVOLVED IN THIS ARE NOT LYING AND THIS IS F'ED UP AND WEIRD!***
1) I am 100% convinced that the Motorola Droid can be infected with a virus.
2) My best guess at this point is the virus on the phone I'm experiencing problems with came pre-loaded with malware (
Vodafone distributes Mariposa botnet | Panda Research Blog) or it is related to the sync feature that lets you repopulate a new phone with old contacts.
3) I do not know the best way to confirm this without infecting another device to scan it...any advice?
4) Here's why I know that they can be infected:
My girlfriend bought a droid 3 or 4 months ago. It worked perfectly, no issues, no problems and she loved it. Well that is until she dropped and broke the phone. This was roughly 3 weeks ago. She went and got a new Droid from a Verizon stored. Now on her 1st droid, she sync'ed her phone with google so her contacts were all saved. When she got her new droid, she re-synced and got back all her old contacts.
Within 3-5 days after that, I started getting many missed calls (like 14 in 1 hour) from a coworker at work. When I called her back, she swore she never called me. What's weird is my coworkers exact number and name (from my stored contacts) would show up. Well I googled it and learned all about spoof calling and how it works.
Long story short, these calls on my phone (same network, not a droid) kept coming. Soon after, text messages started coming. The difference, the txt msgs would say "unconfirmed sender) and show my coworker's contact but her name wouldn't show up. This made me more sure it wasn't just the coworker messing with me (even though it is possible I'm sure it's not..this gets weirder, I assure you its worth reading more).
Next my girlfriend (with the new droid that just re-synced) started getting the text messages from this unconfirmed sender (appearing to be my female coworker). All of the messages were geared to make it seem like I was having an affair and that this coworker wanted my girlfriend to know and leave. Needless to say this caused about 2 weeks of arguing and fighting between the three of us (I assure you nothing of the sort was going on). Well we all made peace (ironically through text messages, all of which passed through the droid).
A few days went by with no "weirdness" but soon the calls started again. This time to my girlfriend (on her droid) from a mutual male friend of ours (whose # was in her contact list but my coworker had no human way possible of knowing). Now when he swore he wasn't calling, we knew something was up. Next more messages kept coming in to her droid telling her she needs to leave and get out and more creepy messages of that nature. This naturally caused more fighting between us. Both of us being convinced it had to be the other since we were the only ones to know all three of the numbers.
So here we are now (about 3 days ago) wondering who the hell is doing this, how and why. So yesterday we go out for a little bit but leave our phones at home (at this point we are paranoid and a little scared...thinking, conspiracy, Ghostnet, government spying, whatever...just plain weird and scary). Well we were only gone about 20 minutes and when we returned home, she unlocked her phone (its locked with a complex password), the web browser window was open to a webpage for a Thai resturant in NYC (I have the address if this happens to anyone else who wants to confirm they aren't alone). She wasn't on the web when we left nor did she look up that website. We looked at her browser history to see more new searches since we left...none of which were her. They were for thank you letters, a Thai airline and a few other random things. The very creepy thing...the female coworker who's phantom phone calls started this has a Thai husband. However, as far as we can remember that was never discussed via text message between my girlfriend and I nor my coworker and I or my coworker and girlfriend. The other way that this fact could have been known to a 3rd party is that both my coworker and girlfriend are facebook friends and access facebook via their cell phone (my girlfriend using this droid I'm convinced is infected...it gets creepier, keep reading). That is the only way a 3rd party could find out about her Thai husband unless the web searches for Thai stuff were random.
We're now pissed and freaked out. My girlfriend called Verizon and told them everything was going on. They explained that it could be from an infected app she downloaded and if that is the case, they are not liable. They wouldn't check anything to find the origin of the calls or messages. They said they do not have a list of any apps from the marketplace that were flagged as dangerous (they claim to not have a list of Marketplace apps they host at all....total BS). Their best advice was to change her phone number (they did this free) and reset her phone to factory default settings. They did this prettty much immediately (last night). They then told her she could resynch er phone with google to get back her contacts. She explained that we have not ruled out that being the cause of the infection / intrusion. With that in mind, she had no intention of using her new smartphone for the internet at all. She put her phone in airplane mode and just left it alone. Later that night (just last night) she took it out of airplane mode to check messages and all of a sudden the phone was already resynced and all her old contacts were back.
Now remember, this is that same 2nd droid she bought as a replacement about 3 weeks ago. It has a new number, had "factory settings" reset by Verizon and then magically sync'ed itself shortly after. The only person who knows this number are myself, my girlfriend and verizon.
Well she got 2 harrassing messages from an "unconfirmed sender" this type not even attempting to leave a fake number (Just a "U" in parentheses instead of a name or number). I won't even get into the content of the messages because they are just plan sick and creepy.
My phone (same network, not a droid) also got a text in the middle of the night (about 10 minutes after her two messages). They were also from the "unconfirmed sender", "U". One message, saying "U Get her out".
I swear to God I am not making this up. I am not doing this. There is no way humanly possible the lady I work with is doing this. This is why I know it must be a virus. However, how can I prove this? How can I scan the phone? If the stalker has her new phone number, the phone has to be infected. My question is how did it get infected? My best guesses are:
1) Straight from factory like I read in the link I pasted above and here:
Vodafone distributes Mariposa botnet | Panda Research Blog
2) There an app she downloaded (I've read this phone is linux based and very secure...I just don't think this is the case)
3) Someone on the Verizon Network (disgruntled employee?) is behind this
4) Someone nearby is really f'ed up in the head and good enough with RF technology to hack into her phone.
5) Something in the sync feature either with google, or facebook is the backdoor allowing this person in.
Is #4 really likely unless we are talking military or sickly smart individual with expensive equipment???
Now trust me, my coworker is not lying, nor am I or my girlfriend. That would be the easy explanation but this is 100% truth, no bull****. It is making my life hell, I would not make this up nor would any inolved.
Sorry I get so long winded but this is the strangest thing I have ever seen in my life. However, I can not believe this is an isolated incident.
Any advice on how this is possible, or what I can and should do?
-NJDuke