Solved

threat found: com.android.mms



Show first post

91 replies

Userlevel 6
@ wrote:
Just came up on my htc one, thought I was the only one Haha
Welcome to the community!
 
Beth
Support says it is a false positive
Userlevel 6
Welcome to the community seven_7_vii_th!
 
Thank you for your feedback.
 
In regards to this issue, users like you who experienced it have reported the issue. The issue was not  known prior to the user reports. Others who experience it as well may look here first to find an answer or they may turn to support for an answer.
 
Two peple did post the response from support. They responded promptly that the  issue will be fixed within 24 - 48 hours. 
 
Webroot employees do frequently visit the community. It is the feedback from users like you who post  that helps the Webroot Team to know what the users needs are, what features they would like and to keep Webroot  the best security protection out there.
 
Feel free to post your ideas in the Ideas Exchange and please do come often and share your experiences. Sharing helps all the members as we learn from one another and then can help each other out as well!
 
Beth
Support posted this was a false/negative scripting alert.
They will release a fix for it with 24-48 hrs
Go to your webroot mobile app and find the FORCE UPDATE of definitions tool. Also set your scan settings from weekly to daily. This was a result of a Google sms unblock setting within Chrome or gmail. Look for the fix before 08/09/14
Just came up on my htc one, thought I was the only one Haha
Userlevel 2
I have read through all of the pages of this thread up to thus far, but I have not gone through the other related threads.  I'm far from an expert on WebRoot and also must admit that aside from the contents of this thread I have relatively little knowledge of this situation other than my own experience.  Please forgive me for any lack of knowledge I may have on the subject.  So, just as I suspected when this popped up on my phone it is a false positive.
 
Not really saying anything that anyone else hasn't said so far; however, here are my thoughts on this issue.  I know I would (and I'm guessing at least a few others would) have liked to have had some form of official comunication out reach from Webroot notifying about the issue.  An e-mail to users with a registered Android device or even some type of in app notification pushed out would have been very valuable to me.  I know I was really worried and confused for at least a few hours as I was unable to really research the issue to find out what it was about.  To top it all off I was in the middle of a semi-important text conversation when the alert came in.  Another thing I would have found invaluable would have been for the app to provide more information on the infection than just a name.  Maybe a brief description and the location of the infected files to help me understand the nature of the infection.
 
Don't get me wrong these are not meant to be viewed as complaints.  These are intended to be viewed as suggestions or improvements that would perhaps make a situation like this better in the future.
 
I'm sure WebRoot will have the situation handled shortly, but in the mean time it is not too late to send out that message and help those that may still be out of the loop on the situation.
 
Now, perhaps this has already happened or is already available.  If so please disregard that part of this post.
Userlevel 6
@ wrote:
@BB613 wrote:
@ wrote:
GZOne Commando w Android keeps getting a spyware threat for Android Messaging app which I can't uninstall or keep Webroot for flagging. I also cannot use my messaging app because the shield pops up.
Welcome to the community.
 
I suggest you contact information to Tech Support by submitting a support ticket. They will be able to help you out.
 
Please do let us know what they say and come back often and share your experiences!
 
Beth
There is no need to contact support as they already know about the issue and it will be fixed in the next 24 to 48 hours.
 
From Support:
 
Hello,

Thank you for contacting Webroot Support. We apologize for any inconvenience this issue may have caused.

It does appear the detection in question was a false positive. We have re-evaluated the definition detecting the application you report and corrected the false positive on our end. Within the next 24-48 hours we will release a new definition set with those corrections and you should no longer see that detection. In the meantime, you may choose the option to "Ignore this threat" and this will prevent Webroot from displaying the alert again for that particular app. We appreciate your report and thorough troubleshooting!

Regards,

The Webroot Mobile Threat Research Team
So sorry Daniel!
 
When I responded, the post was in a different thread and I was not sure if it was in fact the same issue. I have referred all other inquiries to this thread.
 
Beth
Userlevel 6
@ wrote:
SAME HERE
CANT UNINSTALL
THINK SUPPORT IS IN PROCESS OF WRITING NEW SCRIPT TO MUTE THE ALERT
READ SOMETHING ABOUT A FALSE /NEGATIVE
RSS FEED NOT WORKING
KDR406
 
 
Welcome to the community!
 
Please take a look at this thread https://community.webroot.com/t5/Webroot-Mobile-for-Android/threat-found-com-android-mms/m-p/137461#M2999
 
albuchs and TripleHelix both shared from support that the issue will be fixed in the next 24-48 hours.
 
Sorry for the inconvenience.
 
Beth
SAME HERE
CANT UNINSTALL
THINK SUPPORT IS IN PROCESS OF WRITING NEW SCRIPT TO MUTE THE ALERT
READ SOMETHING ABOUT A FALSE /NEGATIVE
RSS FEED NOT WORKING
KDR406
Userlevel 7
Badge +56
@ wrote:
Support:
Have the same threat alert.
Will not complete scam of mobile device unless I select ignore.
Threat has two names:
under messaging apps: called : com.android.mms
also known as : Android.SmsSpy
Unable to remove or quarantine threat
Not sure if this is in device or SD card
RSS topic feed was also blocked.
Hope this helps.
KDR406
Please see above here: https://community.webroot.com/t5/Webroot-Mobile-for-Android/threat-found-com-android-mms/m-p/137449#M2995
 
Thanks,
 
Daniel
Support:
Have the same threat alert.
Will not complete scam of mobile device unless I select ignore.
Threat has two names:
under messaging apps: called : com.android.mms
also known as : Android.SmsSpy
Unable to remove or quarantine threat
Not sure if this is in device or SD card
RSS topic feed was also blocked.
Hope this helps.
KDR406
Userlevel 6
@ wrote:
Help! My antiviral says there is a critical threat in my messaging. It won't let me remove the messaging app. What do I need to do???
Welcome to the community!
 
Have a look at the posts from albuchs and TripleHelix on page 4 of this thread. If you are having the same message as the others who posted in this thread, the issue will be fixed in the next 24-48 hours.
 
If you are experiencing a different issue, please contact Tech Support by submitting a support ticket Please do let us know.
 
Sorry for the inconvenience
 
Thank you,
 
Beth
Userlevel 7
Badge +56
@ wrote:
*HOPEFULLY* there will be no more rolling out a new definition file just as the tech support desk goes dark for the day.
This is something that should never happen to begin with, but to roll out new defintions at the end of the business day, come on.
 
They said they were sorry and they didn't go dark at least WSA doesn't remove it without your permission right? ;)
 
They have Support Worldwide so there is always someone to help 24/7/365
 
Thanks for everyone's understanding in this matter!
 
Daniel 😉
As has been noted elsewhere, this is a false positive. Just have Webroot ignore it.
*HOPEFULLY* there will be no more rolling out a new definition file just as the tech support desk goes dark for the day.
This is something that should never happen to begin with, but to roll out new defintions at the end of the business day, come on.
 
Userlevel 7
Badge +56
@BB613 wrote:
@ wrote:
GZOne Commando w Android keeps getting a spyware threat for Android Messaging app which I can't uninstall or keep Webroot for flagging. I also cannot use my messaging app because the shield pops up.
Welcome to the community.
 
I suggest you contact information to Tech Support by submitting a support ticket. They will be able to help you out.
 
Please do let us know what they say and come back often and share your experiences!
 
Beth
There is no need to contact support as they already know about the issue and it will be fixed in the next 24 to 48 hours.
 
From Support:
 
Hello,

Thank you for contacting Webroot Support. We apologize for any inconvenience this issue may have caused.

It does appear the detection in question was a false positive. We have re-evaluated the definition detecting the application you report and corrected the false positive on our end. Within the next 24-48 hours we will release a new definition set with those corrections and you should no longer see that detection. In the meantime, you may choose the option to "Ignore this threat" and this will prevent Webroot from displaying the alert again for that particular app. We appreciate your report and thorough troubleshooting!

Regards,

The Webroot Mobile Threat Research Team
Help! My antiviral says there is a critical threat in my messaging. It won't let me remove the messaging app. What do I need to do???
Userlevel 6
@ wrote:
My webroot secure anywhere on my mobile is saying my messages are threats, I just need to know what to do.
Welcome to the community! 
 
Please have a look at this thread
https://community.webroot.com/t5/Webroot-Mobile-for-Android/threat-found-com-android-mms/td-p/137285/page/5
 
If you are experiencing a different issue, please contact Tech Support by submitting a support ticket
 
Please do let us know what you hear back.
 
Thank you,
 
Beth
My webroot secure anywhere on my mobile is saying my messages are threats, I just need to know what to do.
Userlevel 6
@ wrote:
GZOne Commando w Android keeps getting a spyware threat for Android Messaging app which I can't uninstall or keep Webroot for flagging. I also cannot use my messaging app because the shield pops up.
Welcome to the community.
 
I suggest you contact information to Tech Support by submitting a support ticket. They will be able to help you out.
 
Please do let us know what they say and come back often and share your experiences!
 
Beth
Getting the same threat. At least I'm not the only one
GZOne Commando w Android keeps getting a spyware threat for Android Messaging app which I can't uninstall or keep Webroot for flagging. I also cannot use my messaging app because the shield pops up.
Userlevel 6
I do hope everyone has seen the solution/report from tech support posted by TripleHelix and arholland84.
 
I see that many new members have received the same mesage from Webroot on their Android phone. I would like to thank all of you for sharing that information with us.
 
Welcome to the community ypekhman, albuchs, RKSJBeck, LGP, rocke06, nwalden,  napierite, tl97, tblairmaylee, boochman123, nathanedwards810, Bearle, albuchs, rocke06, tholland38, OKSooner1,
gbn08, mcgyyvr,  and aimeehart!
 
I hope I did not leave anyone out
 
Please do come back often and share your experiences. Thats what its all about, sharing experiences, learning from one another and helping each other out!
 
See all of you around in the community!
 
Beth
 
 
Same here, both our phones had this threat and unable to remove it. What do I do?
Userlevel 6
@ wrote:
From Support:
 
Hello,

Thank you for contacting Webroot Support. We apologize for any inconvenience this issue may have caused.

It does appear the detection in question was a false positive. We have re-evaluated the definition detecting the application you report and corrected the false positive on our end. Within the next 24-48 hours we will release a new definition set with those corrections and you should no longer see that detection. In the meantime, you may choose the option to "Ignore this threat" and this will prevent Webroot from displaying the alert again for that particular app. We appreciate your report and thorough troubleshooting!

Regards,

The Webroot Mobile Threat Research Team
  ______________________________________________________________________________________________
@ wrote:
I contacted customer support via this website and received an automated message saying it is a false positive that will be fixed in 24-48 hours.  If you look at the messaging app info on your phone it clearly shows that it does track you and what messages you write, so even when this is "bug" is fixed, you're still monitored.  It's just that now a lot more people are aware of it!:8
Thank you arholland84 and thank you Daniel for contacting support and sharing their answer with everyone.
 
arholland84, I would also like to welcome you to the community!
 
Beth

Reply