Android Android Zygote64 asking for root access?

  • Thread starter Thread starter Cyan
  • Start date Start date
  • Views Views 7,375
  • Replies Replies 4

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,745
Solutions
14
Reaction score
13,765
Trophies
4
Age
48
Location
Engine room, learning
XP
15,714
Country
France
My phone: honor6x android7 stock ROM, 3 month old.


Two days ago, SuperSu v2.82 on my rooted phone asked to allow root access to Zygote64.
The application log doesn't have an icon, the log access doesn't have any zygote history!
Checking the processes with 3CToolbox I saw both Zygote and zygote64 running, AND they have a "initial launch date" in the future : june's 10th 2018 with negative value "-22 day ago".



I tried to search on internet, the only information I found is from xda forum, it seems other users have the same prompt since 2016 but nobody really knows what the problem is.
people say it's either a malware, or a SuperSu bug. How can I be sure which one is mine?


Zygote is a system process, and should never ask root access, but I'm not sure Zygote64 is an official process or not.
Some people said to use adb to verify there is only ONE zygote process, all others are malware.
I found some screenshot with that process name, so I don't know if I can trust it or not.
maybe zygote64 is official and not malware ?

Zygote could be infected with Android.Triada malware? some phone seems to be shipped(sorry, french only) with that malware pre-installed, but huawei doesn't seems to be affected.


apps added last 15 days:
Soundcloud (google store). Strangely, all logs I found about zygote64 also had soundcloud installed.
NXLauncher (apk manual install)
OTB Checker (google store)


Symptoms:
the prompt happened while using "New pipe" (fDroid), but I used it a lot without issues.

The phone seemed very slow (specifically Firefox), and I had a lot of unknown process running. (app process)
Firefox (and also Chrome) closed themselves when trying to load a GBATemp page.

I rebooted, SuperSu doesn't have the app logged anymore.
I don't have hundred of process running anymore.


Do you think it's malware and I should restore a previous backup ? (unfortunately, I have only one from day one... I'll have to reinstall everything).

I didn't install a lot of apps, I don't use any social app, or visit suspicious websites (no porn, etc.)
I only use my phone for GBATemp and wikipedia/imdb/other common websites.
Only 2 app I installed not from google play are : lucky patcher and NXLauncher.

Thank you for any info you could provide :)
 
Last edited by Cyan,
I think its either malware (use malware bytes to check) or just an app that's checking for root access so it can block itself if it's found. Same way barcays app does.

Run an avast check and a malware check if all OK I would lean towards trusting it
 
  • Like
Reactions: Cyan
I installed malware bytes, but as expected it doesn't have root access, so how would it detect kernel's issues ?
it scanned all the "applications", but not the kernel's processes, and ended with result "no malware found". without scanning Zygote itself, it can't detect any malware in it.
I didn't try avast yet, but I suspect an antivirus would be as (un)useful.


here are some screenshot I took:

before reboot
SuperSu logs the application, without icon. but if I go to the second tab, that program is not logged at all, no rejection nor request. Maybe just a SuperSu bug while trying to grant another app? (usually AF+)
407412-zygote64_01.png


In 3CToolbox, When I activate kernel display, I can see both Zygote and Zygote64.
You can also note the RAM is almost full.
407413-zygote64_02.png


And the funny thing, the Zygote64 info tab shows : launch in the future !
launched on June 10th 2018, -21days ago.....
it was the same for a lot of System App (UID:0)
Zygote64 doesn't have any application path or apk package name, so it looks like a real system app.
407414-zygote64_03.png

After reboot
RAM is now using a lot less.
This is the "unknown running processes" I was talking about.
Before reboot, I had a loooot (50-100 ?), now it's back to around 10 processes
407415-zygote64_04.png


They are all UID:0
taking a lot of virtual Mem (2 GB)
After the reboot, the launch date is not negative anymore for system Process UID:0
407416-zygote64_05.png



And last; the "new" zygote64 screenshot after reboot.
Now it correctly display "launched 3h ago".
Is it normal it's using more than 2GB virtual memory ?
407417-zygote64_06.png



I blocked all "root process" to access internet.
here is a log.
Isn't it strange to see protocol [128] or [0]0.0.0.0 on port0? instead of TCP or UDP or ICMP?
407422-zygote64_07.png

I tried to kill Zygote64 manually from 3CToolbox, and the phone rebooted its graphical interface (launched apps were still open and active when the phone was back to usable state).


Could someone with 3CToolbox and Root access check their own kernel files?
see if you have both Zygote and Zygote64, and if the memory usage is correct. (but I suppose it's good, virtual mem is not RAM)

tell me if you have a lot of "app process" too. I also have 5 "sush" running processes.
Thank you :)


I don't do suspicious activities, don't visit lot of website, didn't install lot of apps, I didn't do anything special except install soundcloud in the last 15 days. to me, it would be very strange if it was a malware, but I'm a little paranoid now. I wouldn't want to keep a bank malware.
the only bad thing or setting I did was disable google play protect (because it always deletes Lucky patcher).
 
Last edited by Cyan,
I installed malware bytes, but as expected it doesn't have root access, so how would it detect kernel's issues ?
it scanned all the "applications", but not the kernel's processes, and ended with result "no malware found". without scanning Zygote itself, it can't detect any malware in it.
I didn't try avast yet, but I suspect an antivirus would be as (un)useful.


here are some screenshot I took:

before reboot
SuperSu logs the application, without icon. but if I go to the second tab, that program is not logged at all, no rejection nor request. Maybe just a SuperSu bug while trying to grant another app? (usually AF+)
407412-zygote64_01.png


In 3CToolbox, When I activate kernel display, I can see both Zygote and Zygote64.
You can also note the RAM is almost full.
407413-zygote64_02.png


And the funny thing, the Zygote64 info tab shows : launch in the future !
launched on June 10th 2018, -21days ago.....
it was the same for a lot of System App (UID:0)
Zygote64 doesn't have any application path or apk package name, so it looks like a real system app.
407414-zygote64_03.png

After reboot
RAM is now using a lot less.
This is the "unknown running processes" I was talking about.
Before reboot, I had a loooot (50-100 ?), now it's back to around 10 processes
407415-zygote64_04.png


They are all UID:0
taking a lot of virtual Mem (2 GB)
After the reboot, the launch date is not negative anymore for system Process UID:0
407416-zygote64_05.png



And last; the "new" zygote64 screenshot after reboot.
Now it correctly display "launched 3h ago".
Is it normal it's using more than 2GB virtual memory ?
407417-zygote64_06.png



I blocked all "root process" to access internet.
here is a log.
Isn't it strange to see protocol [128] or [0]0.0.0.0 on port0? instead of TCP or USP or ICMP?
407422-zygote64_07.png

I tried to kill Zygote64 manually from 3CToolbox, and the phone rebooted its graphical interface (launched apps were still open and active when the phone was back to usable state).


Could someone with 3CToolbox and Root access check their own kernel files?
see if you have both Zygote and Zygote64, and if the memory usage is correct. (but I suppose it's good, virtual mem is not RAM)

tell me if you have a lot of "app process" too. I also have 5 "sush" running processes.
Thank you :)


I don't do suspicious activities, don't visit lot of website, didn't install lot of apps, I didn't do anything special except install soundcloud in the last 15 days. to me, it would be very strange if it was a malware, but I'm a little paranoid now. I wouldn't want to keep a bank malware.
the only bad thing or setting I did was disable google play protect (because it always deletes Lucky patcher).
Had a little look into it and it looks as if its malware that's disguised itself as a system process. I would stay away from it, delete it if you can
 
you don't have that process?
when I forced its termination, the phone rebooted, as if it was an essential process.
If I delete it, I might not be able to boot the phone. and I don't know how to delete it. Manually from a root file explorer?

I'd better just restore a NANDRoid ROM backup, but I did it only right after rooting, so I'll have to re-do all my settings. But if it's safer, I'll do it.

Thank you for taking the time to read my messages and trying to help.

edit:
I removed malware Byte, it was sucking the battery. even if I force closed it and disabled realtime check, it always re-launched and the phone didn't like how much battery it used.
 
Last edited by Cyan,

Site & Scene News