I don't think it is the ap but I have to ask, where did you get the ap?
Assuming it is not the ap itself can you check your phone for malware?
I still have to wonder, what the hell is up with the change? Why is there change? Where did it go? Strange. It is still sitting there. I guess you can monitor that address for movement.
The app is the formal blockchain.info app, I think I got it from the Play Store.
I will try to look for malwares on the phone, will get some reading.
The change is a good question indeed.

Although both payment still sit in the receiver accounts and I can track them, I don't really have what to do with it. This is the essence of Bitcoin, anonymity, isn't it?
I guess in the future, the network can develop a mechanism to mark "bad" address and then avoid taking payments from such address, today there is no such mechanism (I guess bigger thefts can be tracked and nothing can be done with them).