View Full Version : [Need Help] GPRS Traffic not normal !!!



PHoeZies
24th April 2007, 11:16
[Need Help] GPRS Traffic not normal !!!

Dear Mods,
If I've posted in the wrong place, please move in correct place.

Dear All, Please help...:?:

Recently my phone acts strangely...
Everytime I'm making GPRS connection, It was kinda like downloading a certain amount of data from unknown address, and it won't stop until I disconnect manually from the Connection Manager.

For example :
I was only running Internet Time/Clock Sync & connected using GPRS. Usually it will only take less than 1KB to synchronize time, then the GPRS traffic connection will stop.
But when I check with Connection Manager the GPRS traffic is used up to 50KB and it keeps downloading something I dont know...
I had to disconnect it manually, otherwise my phone bill will explode.
Also that damn thing :vom: really makes my connection slow, especially when browsing using OperaMini.

I suspect it all started when I tried some Java games sponsored advertising by gamejump.com. It seems that the 1st time I was connected to gamejump.com, they sent some kind of trojan script, so the phone keeps making GPRS connection with certain address.

Eventhough I had removed the game & checked with Symantec (no virus found) my phone still acts strangely.



My question is :
- Anyone has same experience like me ??
- How to remove that damn trojan WITHOUT hard format ??

NOTE :
I found strange folder in my C:/SYSTEM/DATA/MIDP2/SYSTEMAMS.
There is a subfolder CONNECTION / BBB4D6988AE09BBDB7A916879A37293ED5B6388C
And there is a folder [TMP83DE5.$$$] in my C:/ which has no file in it....


I delete these two folder but the next time after I'm connected to GPRS again... those folders will be back again...


More technical question :
- Is it safe to delete the whole C:/SYSTEM/DATA/MIDP2/SYSTEMAMS ?

Thank you :)

Barabba
24th April 2007, 12:23
suggest you to instal ezsniffer to look at which address the phone want to connect to. With this info maybe you can find the related application.

spikje
24th April 2007, 15:41
Use gnubox to connect, then check with a packet analyzer the remote hosts that are accesed and the transferred data. (Google for WireShark).
You should consider trying Kav Mobile or a process manager to look for suspect processes running from flash memory(NOT ROM!). Try updating with memory card ejected. Hope this solved out.

danial
24th April 2007, 15:51
maybe u can change your default home page?

or change ur phone?:)

PHoeZies
25th April 2007, 07:53
thanks guys for ur advice, let me try :)