I just red the Log file a bit and found this:
--------- switch to events
09-17 13:20:35.650 1296 1512 I am_wtf : [User=0,PID=1296,Process Name=system_server,Flags=-1,Tag=ActivityManager,Message=Starting FGS with type dataSync code=4 callerApp=ProcessRecord{2eeec27 16451:org.torproject.android/u0a156} targetSDK=33 requiredPermissions=all of the permissions allOf=true [android.permission.FOREGROUND_SERVICE_DATA_SYNC] ]
09-17 13:20:35.660 1296 1296 I notification_enqueue: [uid=10156,pid=16451,pkg=org.torproject.android,id=1,tag=NULL,userid=0,notification=Notification(channel=orbot_channel_1 shortcut=null contentView=null vibrate=null sound=null defaults=0x0 flags=0x42 color=0x00000000 category=service actions=1 vis=PRIVATE),status=1]
Things that make me suspicious:
09-17 13:20:35.650 1296 1512 I am_wtf :
And:
callerApp=ProcessRecord{2eeec27 16451:org.torproject.android/u0a156} targetSDK=33 requiredPermissions=all of the permissions allOf=true
It makes me think a hacker who call himself "wtf" has a malicious app on my phone called "callerApp" and it has started a process which is recording audio and send it through the for network to somewhere and the app has all permissions possible.
I do not have a sim card so I do not make phonecalls with a "caller app" when I do phone calls then with a third party app over the internet. But today I did not have a phone call.
There is more in the log files I think is suspicious but this hits me the most. I am pretty shire it is nothing but I want to go the safe route so I better ask you guys in the hope you KNOW that it is nothing or maybe it is something which I do not hope