Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

These 42 Phones Are Shipped With Triada Banking Virus

Who would thought that a brand new phone he or she bought came with a virus as it was shipped? This is exactly what is Happening now and some phone manufacturers are to be blamed. There is a new security report from Russia that about 42 smartphones are shipped with a banking Trojan virus called 'Triada'.
Phones shipped with virus
It's a bad news for those who love budget phones, especially from not-so-popular brands, like Leagoo.

According to a Russia-based antivirus vendor—Dr. Web, over 42 Android smartphones have been shipped with a trada Android banking trojan.

HOW IT WORKS
Once present can root devices and make it impossible for you to get rid of it without reinstalling the operating system. As stated in the report, the key feature of Android.Triada.231 is that cybercriminals inject this Trojan into the libandroid_runtime.so system library. The virus is not relatively new in the industry but it's very dangerous as it can still your banking information and other private info you type with your phone.

So, are the manufacturers to blame? According to the reports:

Although the blame should mainly go to the third party software developers who inject malware alongside the applications that come with the phones. In their words:

“This [software development] company provided Leagoo with one of its applications to be included into an image of the mobile operating system, as well as with an instruction to add third-party code into the system libraries before their compilation.”

But the phone manufacturers should also get some blame because it's their responsibility to test their devices before shipping them.

Having said that, here are the 42 smartphones that have been affected so far.

Leagoo M5
Leagoo M5 Plus
Leagoo M5 Edge
Leagoo M8
Leagoo M8 Pro
Leagoo Z5C
Leagoo T1 Plus
Leagoo Z3C
Leagoo Z1C
Leagoo M9
ARK Benefit M8
Zopo Speed 7 Plus
UHANS A101
Doogee X5 Max
Doogee X5 Max Pro
Doogee Shoot 1
Doogee Shoot 2
Tecno W2
Homtom HT16
Umi London
Kiano Elegance 5.1
iLife Fivo Lite
Mito A39
Vertex Impress InTouch 4G
Vertex Impress Genius
Advan S5E NXT
Advan S4Z
Advan i5E
STF AERIAL PLUS
STF JOY PRO
Tesla SP6.2
Cubot Rainbow
EXTREME 7
Haier T51
Cherry Mobile Flare S5
Cherry Mobile Flare J2S
Cherry Mobile Flare P1
NOA H6
Pelitt T1 PLUS
Prestigio Grace M5 LTE
BQ 5510

Personally, I think the surprise inclusion on this list is the Tecno W2. However, LEAGOO products made up a large number of the list.

MUST READ: Tips To Make Your Phone Free From Virus.

Which of these phones are you using? What will you do now? Remember the only option or step needed to get rid of the virus is to install a new software or clean custom rom of the phone in question.

Reason Why Adobe Flash is No Longer Safe For Your PC (Uninstall)

I will advise you to uninstall Adobe Flash on your PC as soon as possible but if you are too in love with it and don't want breakup or heartbreak, pls update it at least. This information is coming to you because there are security threats being discovered by Kaspersky that reveals exploit known as FinSpy or FinFisher targeted at computers with Adobe Flash player.

Apart from the malware threats, do you know that Adobe flash is a memory-and-battery-sucking monster that is riddled with holes and years-old unpatched code which makes it a fertile ground for hackers? Okay now you know.

So Kaspersky Labs has revealed that there has been a recent vulnerability discovered in Adobe’s Flash platform that allows hackers to plant malware. According to Kaspersky, the exploit is known as FinSpy or FinFisher and is actually a commercial product that is sold to countries and law enforcement agencies to conduct surveillance. The attacker, BlackOasis, is using the FinSpy malware through Microsoft Word documents to attack victim machines.

READ: Adobe Flash Malware Threat Reported in 2016

Now the most worrying part is the report claims that it has identified BlackOasis targets in countries like Russia, Iraq, Afghanistan, Nigeria, Libya, Jordan, Tunisia, Saudi Arabia, Iran, the Netherlands, Bahrain, United Kingdom, and Angola. So users in these regions should be extremely careful to avoid stories that touches.

Meanwhile, in their quest to curb this issue, Adobe has released a security update that is expected to fix the problem, but it wouldn't be a bad idea to uninstall Flash given that companies like Mozilla and Google have announced their plans to stop supporting flash in their browser and even Adobe has confirmed that they will be ending support for Flash in 2020.

READ: 10 Hidden Notepad Tricks You May Not Know

So the ball is in your court. Are you updating or uninstalling?

How Red Alert 2.0 Trojan Works: Android Malware That Steals Your Banking Login

The coming of internet and online activities made life more easier but I won't forget to highlight the dangers that could potentially emerge from the use of internet. Recently, we have seen an influx of malicious malware and viruses being released to affect the unsuspecting populace. One of the latest Malware to hit the internet is called "Red Alert 2.0 Trojan"

Red Alert 2.0 Trojan is a new Android malware whose main purpose is to steal your banking and social logins details from your phone. Note that Trojan horse, or Trojan, is any malicious computer programme (in this case a mobile application) that appears harmless but tricks users of its true intent so they download/install and use it. It may provide unauthorised access to your device or steal sensitive information.

HOW RED ALERT 2.0 TROJAN WORKS

The Red Alert 2.0 Trojan is hidden in plain site in apps available on third-party app stores as fake versions of legitimate banking or social networking mobile apps.

For instance, you could run a search for XYZ and find a replica of the app and go on to install. Once you launch the app in your phone, it presents you with similar login details as seen in the official app. Once you proceed to enter your login details, your details will be stolen. They are sent to the hackers over the internet and they now have access to your bank account.

What IS NEW ABOUT RED ALERT 2.0

This trojan has a few new tricks too. It is able to intercept and block incoming verification calls from banks and social networks. It can also intercept verification SMS and harvest info from those text messages for the use of the hackers.

The summary is that once Red Alert is active on your mobile phone, thieves can steal your login details and your money while keeping you unreachable by your bank if they suspect malicious activity going on. Nasty boy. This makes the trojan especially dangerous.

RED ALERT 2.0 TROJAN IS CHEAP!

Another problem that researchers point to is the fact that the trojan is being sold on hacking forums for as low as $500, meaning that it can get in the hands of a lot of bad people easily.

Is Your Smartphone Vulnerable To Red Alert 2.0?
Red Alert 2.0 is said to work on phones running Android version 6.0 (Marshmallow) and earlier.

WHAT CAN YOU DO?
Researchers RedAlert 2.0 targets over 60 Android banking and social apps. However, the number can increase quickly, considering how cheap the trojan is being sold. Here are the things you can do to keep yourself safe:

✔ Upgrade your smartphone to Android 7 Nougat, if there is an update available for it. This automatically takes you outside of the scope of Red Alert 2.0, as researchers say the trojan works only on smartphones running Android version 6.0 (Marshmallow) and earlier.

✔️ Be careful where you install your Android mobile applications from. The official app market is your best bet.

✔️ When you run a search for a banking or social networking app, always take a closer look at the details. Often there are little tell-tale signs that can give you a tip. Where in doubt, do not install.

✔️ When wanting to install banking and social apps, if possible, use a link provided on your bank’s website. via.

OTHER DANGEROUS MALWARE
Hummingbird
✔️ CopyCat
✔️ WanaCry
✔️ LeakerLocker

Be careful and stay safe.

VIRUS ALERT! Beware of ExpensiveWall Malware Now Spreading in Playstore

A new dangerous Malware called ExpensiveWall is currently affecting more than 21.1Million Android devices right now. To make things worst, this malicious malware/virus is also traced in Google Playstore according to reports. So this post is to alert you and other Android users about this Malware so that you can stay protected from being attacked.
Lovely wallpaper Malware
The ExpensiveWall Malware was revealed by researchers at Check Point and it has already affected at least 50 apps on Google Play, which were downloaded between 1 million and 4.2 million times before they were removed.

"Lovely wall paper" is one of the infected apps on Playstore. The ExpensiveWall malware was “packed” inside wallpaper apps, which allowed it to escape Google Play's built-in anti-malware protections.

HOW IT WORKS
The ExpensiveWall malware packed inside an android apps, will ask users for permissions, such as SMS and internet access. If granted, the malware will start sending premium SMS messages and register users for other paid services that don't exist without the user's knowledge.

Though granting apps permissions are normal but absolutely abnormal for a wall paper to be asking users for permission for sms or internet access.

SEE ALSO... Beware of LeakerLocker Virus

HOW TO PROTECT YOUR ANDROID FROM BEING INFECTED

It's always advisable not to install apps from unknown sources and if you want to install from playstore, ensure you install trusted apps that has been available for at least one year with good reviews and high number of downloads. Source 1 2.

Beware of Faketoken Trojan Virus That Mimics Ridesharing Apps

Another Trojan Virus is currently trending and it's called "Faketoken". It has been distributed and affected some Android devices through Ridesharing apps so you should be careful and more proactive when using such apps on your devices.

One thing is certain, Malware creators will continue creating and distributing their dangerous viruses as there is no sign of them stopping. Some of them has made so many dollars through these malicious activities and while you can't stop them completely, you can protect your devices and apply common wisdom while dealing with some sensitive online activities. Having said that, let's see how this Malware works.

HOW FAKETOKEN VIRUS WORKS

Some Ridesharing apps have been discovered to be harboring mobile Trojan horses. These malwares steal bank data by impersonating the interfaces of these ridesharing apps. According to Kaspersky Labs, if your ridesharing app asks you to re-enter your credit card information after you have already input it upon installation, you should proceed with caution. The malware responsible for this is known as the Faketoken Trojan, and apparently it has been around for a while now but more active and taking toll on many phones at the moment.

According to Kaspersky, the latest version of the Faketoken Trojan is called Faketoken.q. The company revealed that the malware infects phones through bulk SMS, where it prompts the user to download images. Once the user downloads the image, the Faketoken Trojan installs all its necessary parts, and begins to monitor everything done on the phone. Now, once the malware detects an app whose interface it can simulate, it overlays the app with its own screen. Then, instead of proceeding as usual, the app prompts you to enter your credit card information.

SEE ALSO... How LeakerLocker Virus Infects Your Phone and How To Stay Safe

Some sensitive apps like mobile banking apps, Android Pay, the Google Play Store, and of course ridesharing apps has been infected already. However, the Virus is more popular in Russia but I am spreading this information globally as it could be unleashed to other parts of the world to cause more havoc.

HOW TO STAY SAFE FROM FAKETOKEN VIRUS

Kaspersky recommends that you go to Android settings and prevent the installation of apps from unknown sources.
✔️ Simply go to Settings
✔️ Tap on Security
✔️ Then uncheck Unknown Sources.

On a more serious note, you need to be aware of the permissions an app requests before installation, even if you download the app from a presumably safe source, like Google Play Store. Also, it would be prudent to install an antivirus app on your phone.

Personally, I usually read app permission and requests to know what the app can do on my phone before installing it. Some apps that requires the permission to access my sms, call log, override other apps, galleries and some other sensitive information are carefully examined before i decide to install. I urge you to also apply that principle and you should at least minimize the chances of being attacked by this dangerous and malicious malware in circulation.

New Virus: LeakerLocker Malware Demands $50 From You

LeakerLocker is a form of Android ransomware that threatens to send all your private information, data and web history to all of your contacts and demands $50 from you if you don't want it expose you to the public.

This ransomware is called LeakerLocker, and it was found in the Google Play Store. It works in a different and weird way because unlike other ransomware, it does not encrypt its victims’ files. Rather, it makes a backup of victims’ data stored on the device. Then the developers of the malware demand $50 in exchange for not leaking your personal info to your phone and email contacts. Some of your personal info at risk includes your web history, emails, location history and more.

The LeakerLocker Malware was found in two apps in the Google Play Store. These are Wallpaper Blur HD, which has been downloaded up to 10,000 times by Android users, and Booster & Cleaner Pro, which has been downloaded up to 5,000 times as well. So this simply means that at the moment, about 15,000 people have already fallen victim to this malware, which has been in the Google Play Store since April this year. Imagine the apps even had good reviews on playsStore; developers has manipulated fake reviews of the apps to deceive people who want to download.

HOW LEAKERLOCKER WORKS

Once you download any of these vulnerable apps, LeakerLocker asks for a large number of permissions, including the ability to manage calls, read and send text messages, and access contacts. After you grant it access, the malware communicates with a receiver, thus initiating the malicious activity and locking the Home screen of the device with an extortion threat. Analysis of the malware code shows that it is capable of accessing an email address, some contact information, Chrome browser history, text messages and calls, and photos from the camera.

HOW PAYMENT IS MADE

LeakerLocker demands the ransom via credit card. Researchers have advised victims not to pay up, because there’s no guarantee that the information will be released or will not be used to get at them again.

MUST READ: Checkout All New Viruses Trending Now and How To Stay Away From Them

McAfee researchers have reported the malware to Google, and the offending apps have been removed from the Google Play Store.
via

Beware of CopyCat Malware, 14M Android Phones Infected

There is a new dangerous Android malware in circulation right now called CopyCat and it has reportedly infected over 14 million devices globally.

At the moment, 280,000 Android devices has been affected by CopyCat in the US alone. Though Google has been tracking the malware since 2015 and the company has updated PlayProtect to block CopyCat. However, millions of devices are still getting attacked via third-party app downloads and phishing attacks.

HOW COPYCAT MALWARE WORKS

The CopyCat virus pretends to be a popular app to confuse you and once it is downloaded on your phone, the app collects data about the infected device and downloads rootkits to ease root the phone, essentially eliminating the security system. Then, CopyCat downloads fake apps, as well as taking control of the device’s Zygote, (launcher for every app on your phone). Immediately the malware has control of the Zygote, your phone is olin its total control and it knows every app you download, as well as every app you open. After that, the malware can now be able to replace the Referral ID on your apps with its own, which redirects ad revenue to the hackers instead of to your app’s creators. So far, CopyCat has helped hackers make over $1.5 million.

According to researchers at Checkpoint,
the malware basically roots devices and hijacks apps to make millions in fraudulent revenue. The majority of the devices affected by the CopyCat malware are in Asia right now, but this does not mean that devices in other places are safe.


THE CREATORS OF COPYCAT MALWARE

We can't really tell exactly the creators of this dangerous malware but considering the fact that CopyCat Virus checks to see if the infected device is located in China and sparing devices from that region, it could be a signal that the perpetrators of the cyberattack are located in China and are trying to avoid police investigation. The attack hit its highest number of victims between April and May of last year, but it still affects Android users today, especially those that use Android 5.0 and earlier Android versions. Also, users who download apps from third-party sites are at risk.

SEE ALSO... Beware of JUDY Virus

HOW TO BE SAFE

✔ It's advisable to use an updated Android phone with new OS version especially if it's your main phone for carrying out sensitive transactions and works.

✔ Also, you should endeavor to always install apps from Playstore or trusted sites.

✔ Be very careful when collecting apps from your friend's phones or via laptops

✔ Ensure your memory card isn't used on another person's phone or laptop. Alternatively, make sure you format an SD card before using on your phone.

✔ Be careful when installing apps shared on social media like whatsapp and telegram.

Stay safe!!

Dvmap is The New Deadly Android Virus - See How It Works

It's unfortunate that Viruses and Malware developers will continue finding ways to bypass security on mobile devices and PC in order to harm or hold the owner at ransom. Few weeks ago, we talked about Judy which was a serious ransomware that autoclicks ads thereby generating money for the owner and Ransomware which encrypts (locks) folders on users PC and demand for some thousands of dollars as ransom in order to regain access to the files, but thanks to the developers who found a way to descript and fix it BUT now there is a new trending Virus called Dvmap that is attaching Android devices.
Android virus
Dvmap is primarily targeting mobile devices, according to Kaspersky Labs . This threat is known as Dvmap, and it is different from all the malware we know and trust Google to protect us from.

Kaspersky has been monitoring the distribution of a Trojan horse in the Play Store since April 2017. Dvmap has been able to hide from Google’s protection and verification mechanisms by regularly swapping clean code with malicious code and vice versa. Now, we know that the Bouncers, which was introduced in 2012 to keep malware from the Play Store, can be tricked easily.

How It Works


This malware, classified by Kaspersky Labs as Trojan.AndroidOS.Dvmap.a is a particularly tricky form of malware, according to experts. It tries to gain root access in four different ways, even with 64-bit compatible code. Worse, it injects malicious code into system libraries libdmv.so and libandroid_runtime.so. Subsequently, the Trojan horse triggers protection mechanisms to verify and install third-party apps. This is done by an administrator service called com.qualcmm.timeservices, which looks similar to a legitimate background service like com.qualcomm.timeservices. Note the difference between the two service names, as it is a common ruse employed by hackers and malware advertisers to trick users into trusting them.

Now, the malware could install third-party software on infected devices at a later date. The author could offer this ability to anyone interested, on the black market. Right now, a huge number of devices could be affected. But so far, only a maximum of 50,000 devices are reported to be affected.

REASON WHY IT'S TOO DANGEROUS

Theoretically, Google can delete harmful apps remotely from your device. However, since the malware manipulates system libraries, it could prevent Google from being able to do so, or report the uninstallation immediately to the malware’s author. The author could then install a different version of the malware to escape the protection mechanism again.

HOW TO FIX YOUR PHONE IF INFECTED BY DVMAP

Right now, only formatting the system partition and reinstalling the original firmware can save an affected smartphone.

HOW TO SECURE AND PREVENT YOUR PHONE FROM. BEING ATTACHED

The only way to prevent this from happening is to have the latest security patches. However, not everyone gets the updates, as manufacturers fear that if they do so they will not buy new phones. But ensure your apps are up to date. Refrain from the habit of downloading or collecting apps, music, files etc from untrusted sites, phones or PC.
via

Beware of Judy Malware, Checkout Infected Apps on Playstore

Researchers at Check Point, which recently reported malicious subtitles, have now reported a new malware campaign on Google Play. Dubbed 'Judy', the auto-clicking adware was found on 41 apps developed by a Korean company, according to researchers.

The malware used infected devices to generate fraudulent clicks on advertisements for generating revenues. Researchers claim that the 'Judy' malware has affected between 8.5 million and 36.5 million Android devices as the malicious apps saw downloads between 4.5 million and 18.5 million. Notably, Google removed the malicious apps from the Google Play store after Check Point notified it about the threat.
judy malware
"Some of the apps we discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown," writes Check Point team talking about the Judy malware.
Researchers also found several apps containing Judy malware developed by other developers on Google Play. Though, any connection between the two malware campaigns couldn't be established. "The connection between the two campaigns remains unclear, and it is possible that one borrowed code from the other, knowingly or unknowingly," adds the team.

Check Point reported that the oldest app in the second campaign from other developers were last updated in April 2016 which means that the "malicious code hid for a long time on the Play store undetected."

Researchers also add that similar to previously reported malicious apps like FalseGuide, Judy also relies on the communication with its Command and Control server (C&C) for its operation.
Check Point last month reported FalseGuide botnet malware which infected millions of Android devices via Google Play, and which was hidden in over 40 guide apps for games in Google Play.

According to a security source, the researchers also uncovered a few more apps, published by other developers on Play Store, inexplicably containing the same the malware in them.
The connection between the two campaigns remains unclear, though researchers believe it is possible that one developer borrowed code from the other, "knowingly or unknowingly."

"It is quite unusual to find an actual organization behind the mobile malware, as most of them are developed by purely malicious actors," CheckPoint researchers say.

Apps available on play store directly do not contain any malicious code that helped apps to bypass Google Bouncer protections.

Once downloaded, the app silently registers user device to a remote command and control server, and in reply, it receives the actual malicious payload containing a JavaScript that starts the actual malicious process.

"The malware opens the URLs using the user agent that imitates a PC browser in a hidden webpage and receives a redirection to another website," the researchers say. "Once the targeted website is launched, the malware uses the JavaScript code to locate and click on banners from the Google ads infrastructure."

The malicious apps are actual legitimate games, but in the background, they act as a bridge to connect the victim’s device to the adware server.

Once the connection is established, the malicious apps spoof user agents to imitate itself as a desktop browser to open a page and generate clicks.

Here’s a list of malicious apps developed by Kiniwini and if you have any of these installed on your device, remove it immediately:

INFECTED & MALICIOUS APPS

  1. Fashion Judy: Snow Queen style
  2. Animal Judy: Persian cat care
  3. Fashion Judy: Pretty rapper
  4. Fashion Judy: Teacher style
  5. Animal Judy: Dragon care
  6. Chef Judy: Halloween Cookies
  7. Fashion Judy: Wedding Party
  8. Animal Judy: Teddy Bear care
  9. Fashion Judy: Bunny Girl Style
  10. Fashion Judy: Frozen Princess
  11. Chef Judy: Triangular Kimbap
  12. Chef Judy: Udong Maker – Cook
  13. Fashion Judy: Uniform style
  14. Animal Judy: Rabbit care
  15. Fashion Judy: Vampire style
  16. Animal Judy: Nine-Tailed Fox
  17. Chef Judy: Jelly Maker – Cook
  18. Chef Judy: Chicken Maker
  19. Animal Judy: Sea otter care
  20. Animal Judy: Elephant care
  21. Judy’s Happy House
  22. Chef Judy: Hotdog Maker – Cook
  23. Chef Judy: Birthday Food Maker
  24. Fashion Judy: Wedding day
  25. Fashion Judy: Waitress style
  26. Chef Judy: Character Lunch
  27. Chef Judy: Picnic Lunch Maker
  28. Animal Judy: Rudolph care
  29. Judy’s Hospital: Pediatrics
  30. Fashion Judy: Country style
  31. Animal Judy: Feral Cat care
  32. Fashion Judy: Twice Style
  33. Fashion Judy: Myth Style
  34. Animal Judy: Fennec Fox care
  35. Animal Judy: Dog care
  36. Fashion Judy: Couple Style
  37. Animal Judy: Cat care
  38. Fashion Judy: Halloween style
  39. Fashion Judy: EXO Style
  40. Chef Judy: Dalgona Maker
  41. Chef Judy: ServiceStation Food
  42. Judy’s Spa Salon


At least one of these apps was last updated on Play store in April last year, means the malicious apps were propagating for more than a year.

MUST READ... 8 Ways To Keep Your Smartphone and PC Safe From Virus Attack

Google has now removed all above-mentioned malicious apps from Play Store, but since Google Bouncer is not sufficient to keep bad apps out of the official store, you have to be very careful about downloading apps.

Ransomware Virus: NCC Warns People About The Dangerous WannaCry Attack

The Nigerian Communications Commission (NCC) in fulfilment of its statutory mandate to assure the security and integrity of the national telecommunications network wishes to alert all operators and their respective subscribers of the recent outbreak of a Ransomware Virus known as “WannaCry”.

The Ransomware is capable of infecting and encrypting all files on a system or any smart device until an amount is paid for a decryption key, or other means of retrieval (which may lead to data loss) are used to recover the system as an alternative. This situation demands that proactive measures be taken by all players in the telecommunication eco-system to forestall the hazards of critical data loss, financial losses and ultimately network/business disruption.

The NCC therefore wishes to advise that the following protective measures be taken, amongst others:

✔ To obtain software patch released by Microsoft in March 2017 to fix the Ransomware Virus.

✔️ To plan scheduled penetration tests on the networks and systems to ensure protection and availability at all times.

✔ Subscribers who use their smartphones as substitutes to computers for internet access should protect themselves and their devices by:

✔️ Not opening e-mail attachments/links from unknown sources.

✔ Not clicking pop-ups and applets on unknown websites.

✔ Installing effective antivirus software for their mobile devices.

Furthermore, the NCC has taken the following proactive measures in fulfilling its statutory mandate;

The Commission has advised Mobile Network Operators (MNOs) to initiate regular assessment and audit of their cybersecurity readiness. All operators should continue to ensure that their backup/ disaster recovery strategies are in place and up to date.

✔ The Commission has further advised all operators to ensure continued deployment of effective firewalls, login passwords and antivirus management regime.

SEE ALSO... Best Antivirus Apps For Android and Tablets

✔ The Commission is working towards creating a link with the Cybersecurity Alert System on its website so that current information on global cyber threats/incidents could be immediately communicated to stakeholders.

✔ The Commission will continue to provide more cybersecurity training for its staff.

Beware!!!

8 Tips To Keep Your Phone and PC Safe From Virus and Malware Attacks

Computer and smartphone viruses can ruin your device and even your life if you are not careful. Computer viruses are some illegal or mischievous programs that when run, it can copy itself by infecting several files and programs on your computer system. Some of the popularly harmful computer viruses are Email viruses, Worms, and Trojan horses although there are many more.

So I will be giving you some tips which you should always apply to stay safe or at least, limit the manner in which your device is attacked by virus. Previously on this blog, I have written about several malwares and how they infect computers and your smartphones. You can check out some of the posts related to that here

This safety tips can be used both on your PC and mobile phones for optimal security. Note that this post is basically targeted at devices that have not yet been infested but if yours has already been attached, see how to remove virus here and here

8 TIPS TO KEEP YOUR PHONE AND PC SAFE FROM VIRUS

1. Updated Your Web Browser & Operating System Regularly
New OS and web browsers are frequently updated to fix some bugs in the older versions including improvements against viruses and malware attacks so it's very important to always update your web browser and OS to be on a safer side.

2. Download Apps From Playstore Or The Official Sources Only
Stop downloading apps from anywhere online. Make sure the source is official and known to you before downloading as many viruses are embedded in some of the apps or files you download from unknown sources without your knowledge.

3. Scan New Pen drive or Memory Devices
Before you insert any memory device on your PC or smartphone, make sure you scan it first and run a virus test using Antivirus app. This is because some memory devices are already infected and looking for where to spread the virus.

4. Install an Anti-Virus App in Your Smartphone
Although there are many anti-virus apps available for smartphones but there are ones that are more active in detection. Example is CM security, it serves as Antivirus, phone optimizer, and applock.

5. Don’t use Public Wi-Fi and Bluetooth
If you should use an open or public WiFi, make sure the source is trusted or else, don't try it. It is one of the common ways your device gets attacked and even hacked. So thread with caution.

6. Backup Your Device Data
Taking a full backup of your device data is necessary and very important as you don't know what might happen in the next hour. Your phone can be attacked and one of the best ways to get rid of the malware is by formatting your device. You see, if you had a backup in place, it won't be a problem to you as you can simply restore back your files when it was in safe mode.

7. Ignore Popups and Download Buttons
Some websites and even applications are filed with popups, while some of these popups are important, most times, they are not safe. It is another easy way of getting your phone infected with malware when you click on popups that's one of the reasons some web browsers blocks popups.

8. Don't Collect or Receive Files From a Public Cyber cafe
Whether it's a public cyber cafe or business center, pls don't ever think of collecting files from any of their computers with your phone or laptop. Instead, use an external memory device and after then, scan it before using it on your PC or mobile phone.

Is this article helpful? You can help others know about it by hitting the SHARE buttons below. Stay safe!

Tricks To Remove Netalpha Virus From Your Android Phone and Tablet

Netalpha Virus is a new type of malware that infect android phones and tablets. It installs apps on your phone without your permission, steals vital information on your device and send it to its creator. It renders your device useless and makes your privacy at risk as it reads your inputs.

Over the years, a lot of Android users have faced several virus attacks from popular viruses like Trojan, Xbot, Quadrooter etc and now we have yet another virus tormenting people and it's called 'Netalpha Virus'.

Viruses acts like kidnappers as they hold your device captive and at ransom in some cases, installs apps by itself, turn on your wifi and data all by itself and atimes hinder you from making calls. It can be so annoying and embarrassing that you can not even open applications without a virus popping out here and then. So annoying.

Well, today, I will show you how to remove Netalpha virus from your mobile device without flashing your phone or loosing any data. Follow me along.

SEE ALSO... How To Remove Xbot Virus From Your Phone

HOW TO REMOVE NETALPHA VIRUS FROM ANDROID

1. Boot your phone or tab into 'safe mode' (Press and hold the Power button until the respective screen pops up)

2. Click and hold the option that says Power off. Depending on the vendor and the phone model, the methods can vary.

3. Confirm rebooting into safe mode by tapping OK

4. When in safe mode, go to Settings and select Apps

5. Scroll down the list of programs and locate Netalpha, Key Chain, Fast Search, and Xiny. The troublemaker can also be an object named BaDoink, Engriks, Time Service, MonkeyTest, Quick Swipe, Measure, mobileOcr, UpService, org.on.phone.update or some other suspicious app that was recently installed

6. Tap each offending app in turn and select the Uninstall option. If this button is not active, try Force stop first

7. Tap OK on the confirmation dialog to uninstall the virus

8. Restart your device in normal mode. The Netalpha virus by now should be completely off your device and finally, make sure you install a standard antivirus to prevent future attack.

SEE ALSO... How To Remove Quadrooter Virus From Android Devices

I hope this guidelines help you to get rid of the disturbing virus attacks on your Android device. If you still encounter any problem on your quest to applying this method, kindly ask your questions via the comments box and i will guide​ you more.

Beware Of QuadRooter: The New Dangerous Security Flaw Affecting Android Phones On Qualcomm Chipsets

Another Android security flaw has been discovered by researchers at security Check Point . This new security issue affects Android devices powered by Qualcomm chipsets and it is called QuadRooter.

According to check point, the flaw is fundamentally a set of four vulnerabilities that has already affected over 900 million smartphones and tablets all over the world running Google's Android OS

Surprisingly, Samsung's latest Galaxy S7 flagships and BlackBerry DTEK50, which blackberry boasted to be "the world's most secure Android smartphone." were the most hit by QuadRooter.

How It Works
The QuadRooter security flaw gives attackers complete control of any affected phone or tablet, including access to sensitive personal and enterprise information stored on the device once exploited. This is made possible by the application of a trick to deceive android users to install a very dangerous and malicious app unknowingly to them as it would require no special permissions to suggest it's a malware. Once installed, your phone activities will then be monitored by the bad guys in the backyard.

What Is The Way Forward
At the moment, Qualcomm is now aware of this latest threat and the company is doing everything within their power to fix it as soon as possible. The company says that all the bugs were fixed at its end and patches were handed over to customers. While fix for three vulnerabilities have already made it to recent Android monthly security updates released by Google, one is still outstanding - it'll be be included in the September update.

How Do I Know If My Phone Is Infected With QuadRooter?
Fortunately, Check Point has launched a free QuadRooter Scanner app on Google Play which users of devices running on Qualcomm chipset can use to scan and analyze their phones to know if the flaw exist or not.

Beware Of Dangerous Android Phone Malware Called HummingBad

According to reports, HummingBad is another new android malware that is attacking and infecting android devices at the moment. It had already infected over 10Million Android devices all over the world and it makes around $300,000 (£232,000) Monthly for its creator. Imagine!

How Hummingbad Virus Works
It is a rootkit malware that installs itself deep inside someone's phone’s operating system to make is hard to detect and by so doing, it gives its creators overall control over the your cellphone.
When the malware is on a person’s phone, it installs apps without your consent and monitors your activities on your phone codedly. It also generate clicks for ads on your phone which is the major method it earns money for the owner.

How To Know if Your Android Cellphone is Infected By HummingBad Malware
1. Your phone starts showing strange advertisements
2. You start running out of data more quickly than before
3. You start receiving unnecessary system updates frequently while other people using the same make of phone is not receiving
4. Some unusual pics appearing on your phone
5. Constant prompts to install a new app
6. Finding apps on your phone which you didn't install
7. Finally, your battery start draining much quicker.

How To Protect Your Android Phone From Being Infected By Hummingbad Malware
You can use any of the below security apps.
1. Download Avast anti virus
2. Download CM security
3. Download Lookout Security Sofware
4. Or use 360 Security software and they will detect the presence of the Malware. Remember to always update your Antivirus apps.

How To Remove Hummingbad Malware From Your Phone
Too bad. The malware is very dangerous and hard to remove that's why Antivirus apps and software can't remove it. They only detect but can't delete so the best option is to factory reset your infected android phone.

How To Reset Your Phone
1. Create a backup of the data and content on your phone or tablet.
2. On your infected phone or tablet, tap on Settings > Backup and reset > Factory Data Reset. The location of Backup and reset will differ on various Android phones and tablets, but it will be relatively easy to find.
3. Tap Reset phone or Reset device. Your device will reboot in Recovery mode and will start wiping your infected phone or tablet.
4. Once your phone or tablet reboots you can start the setup of your HummingBad-free device.

READ ALSO 📖

Meet Xbot, The Virus That Hijack Your Android Phone Without Your Consent

Checkout The Best Antivirus App For Your SmartPhone


Another Method which works very fine is to flash custom ROM of your phone and the malware will be gone for good. Stay safe!

5 Reasons Why You Should Not Install Flash Keyboard On Your Android Phone

Android users are surrounded with several apps to download from both google playstore and other sources. There are millions of applications for almost every category of human beings. There are apps with different tasks and functions and one of the popular apps are keyboard apps as we need them for typing.

Flash Keyboard is among the most popular applications in Google playstore as it has recorded over 50 million downloads and was sometime ranked as the 11th most popular app on playstore but unknowingly to users, the app is full of malware and not safe for users. This was recently discovered by a UK-based cyber-security firm by name Pentest . They found the keyboard to be asking for “excessive permissions”, displaying infected ads, asking for admin privileges in order to make uninstall very difficult, monitoring user behavior, and then sending data to servers in China without the user’s consent.

Reasons Why Flash Keyboard App Is A Malware
According to Pentest
1. The app requires unwanted access to a phone’s Bluetooth connection, geo-location feature, or Wi-Fi status which is not ideal for a keyboard app.

2. The app always ask for access to kill background processes, read SMS messages, show system overlays, or remove download notifications. Pentest says there are no reasons for a keyboard app to require these intrusive permissions.

3. Flash Keyboard was asking for device admin permissions, and was using these powers to take over the smartphone’s lock screen and show ads even if users opted out.

4. Flash Keyboard secretly transfers data to secret servers located in China and other foreign countries. The app transmitted sensitive user data including the owner’s email address, device manufacturer, model number, IMEI and Android version to what it believes to be analytics servers in the US, Netherlands and China.

5. Flash Keyboard sends details of the currently connected Wi-Fi network and others in the proximity, the identity of the mobile network being used and GPS coordinates that are accurate to within three meters of the user.

Source: Pentest

READ ALSO 📖

Checkout How To Manually Remove Computer Virus Without And Antivirus Software

Learn How To Remove Dangerous Monkey test Virus From Your Cell Phone

Beware Of This Malware That Steals Your Bank Account Details

So you have seen it. If you noticed, the owners of the app are always running ads on Facebook and Google adword to promote it but seeing what is on ground now, i think you should think twice before downloading the app. Of course there are other nice and amazing android keyboard you should try. For instance SwiftKey, Google keyboard and Gokeyboard are all nice.

Please hit the SHARE BUTTONs to share this with your friends so that they will be aware of this malware pending the time the app developers fixes it. Thank you.

How To Remove Computer Virus Manually Without Antivirus Software

I published a similar post some months back and it saved a lot of readers on this site from many common virus attacks. An Antivirus software is one of the compulsory software any PC user should install on his or her computer but some people shy away from it because most of them are not free of charge and the free ones are not that strong 💪 in detecting viruses.

Another drawback in Antivirus software is that, it will make it hard for you to run a cracked software on your computer because these Antivirus apps see those cracked files as Malware. Example of this is when trying to install gaming software like PES or a cracked version of Autocad. The only way you can have this apps installed is to put them on ignore list or uninstall the Antivirus which in turn leaves your computer vulnerable to attacks.

So to save yourself from all those stuffs, you can easily use the alternative of removing viruses manually via command prompt.

NOTE
This method of removing virus is just an alternative. It can even remove some viruses that a normal virus app won't detect. There was a day i came across a shortcut virus on one of my laptops. The virus turns all my files into shortcuts and thereby making them not accessible. After trying many Antivirus softwares but couldn't fix it but this method was what i used to remove the stubborn virus successfully. Meanwhile, there are other viruses this method will not remove. Follow me as i walk you through the lane of removing viruses with command prompt.

READ ALSO

Meet The Virus That Hijacks Your Bank Details And Hold You On Ransom

Best Antivirus App For SmartPhones

See How To Remove Dangerous Monkey Test And Time Service Malware


How To Delete Computer Virus Without Antivirus App

Step 1
On your computer, click on start menu, and search for cmd

Step 2
Having done that, right click on the command prompt icon, and run it as administrator. (am aware you know how to do that)

Step 3
As soon as the command prompt window opens, choose the drive you wish to remove or wipe virus from. I will assume it's drive D


Step 4
Now all you need to do is to type the below command and click enter.

attrib -s -h /s /d *.*

Step 5
Having done that, type the below command and click enter. You will see all the file contents on the drive displayed with this command.

Step 6
Finally, if you notice any strange file.exe or any autorun.inf, on the list, just rename with the command (rename filename.extension newfilename).

With this method, you can easily remove all those autorun viruses that are common on memory cards. If you want to remove a virus from a memory card, insert the memory card in a card reader use this same process. Remember to note the drive name for your SD card.

So guys, that is it for today. Keep checking on this site for other important tips to keep you safe and enjoy your gadgets even more.

Another Android Malware That Steas Your Bank Details Is Going Viral. Beware!!!

Just last month, we got reports that tens of thousands of Android phones has already been infested with Monkey Test Malware and this time around another one named Spy.Agent.SI have surfaced, tormenting Android devices.

The malware is targeting 20 of the largest banks in New Zealand, Australia, and Turkey, also it can be tweaked and programmed to affect more devices from any part of the world. It locks up your device's screen unless users give up their login credentials. This dangerous malware can also capture text authentication codes sent out by different banks.

According to researchers at the Slovakian security firm ESET say they have discovered a new strain of malicious Android software called Spy.Agent.SI that could be mainly dangerous to phone users.

MUST READ Beware of Xbot Virus. It Hijack your banking details

HOW IT WORKS
The developers of the malware disguised it as a version of Adobe Flash Player, which is popularly known as a tool that runs video and animations on Internet browsers.
Just like every other deadly virus that affects Android devices, Spy.Agent.SI mostly affect users that download applications and software from unsecured, unknown and unofficial third party websites or mobile app markets other than Google Playstore.

Once it infects your device, it continue to spread in all over the memory space on your phone and multiplies itself. Whenever you are doing something on your phone like bank transactions or any other sensitive activities, it will decide to lock your phone screen and only reopens it after you have provided your private details. See similar Malware that uses this TRICK too here

To check if this virus is already on your phone at the moment, kindly search for Spy.Agent.SI in your app manager. For a better result, use titanium backup application to search for it and delete it immediately if you find the malware.

Stay Safe!!!

Source

How To Remove Dangerous Monkey Test And Time Service Malware From Your Phone

Is your Android phone displaying annoying pop-up ads on the screen after you exit from one application to the other? Are you seeing strange application being installed on your phone without your consent? Are you seeing some strange pictures of nüûdé ladies on your phone screen? If your answer to these questions is yes, then you are affected by this trending malware in town.

HOW IT WORKS
Monkey Test virus gets into your phone from unsecured websites and webpages that carry malware. Sometimes it comes through some applications that you installed from unknown sources. This happens without your knowledge because it won't inform you that it is about to come into your device so you will be enjoying what you are doing online until it gets into the medullar of your device.

Once your phone is infected, it will start spreading all over your phone. From memory card to your phone internal memory and create invisible partitions and small files on almost all folders on your phone without your knowledge. You will start noticing it when your phone screen starts dancing shokiti bobo by displaying un-invited ads. Most of the ads are nuuuude photos. Another noticeable change you will see on your phone is the installation of strange and new applications.

MOST LIKELY WAYS TO GET INFECTED BY THIS MALWARE
The most active place to get this malware on your phone is via p..ôrn sites. When you download all those blue movies, you are indirectly welcoming the malware to your phone. Another method to get it is by downloading apps from unknown sources.

Someone gave me his phone last month to check what is wrong on it. He told me his phone gets ads to the extend that it won't let him type things easily from his phone as the ads keep popping up. I noticed immediately that it is monkey test malware. I asked him if he downloaded blue films recently online and he said yes. So I will share with you guys how I removed the stubborn malware because it is very difficult to get rid of even after doing factory reset on the phone.

FIRST METHOD
Requirements
* You must root your phone
* Download Titanum back up HERE

OR download titanium backup PRO here
if you don't have it already on your device.

==>After downloading Titanum back up pro, install it and Tap back up and restore>>then click monkey test and time services


==> freeze the monkey test by clicking on Freeze



With the above, titanium backup application will automatically freeze the malware and disables its controlling power from pestering on your device.

To make your phone more secured,
==> Navigate to settings>>Security>Uncheck unknown souces


READ... Best Anti-Virus Apps To Use On Your Android And Tablets


==> Also Navigate to settings>Security>Slide on or switch ON app permission so that no apps will auto install itself.


SECOND METHOD
Flashing Stock or Custom ROMs
This is the last hope of any phone that has malware or virus issues that refuses to get solved. Flashing of a new custom or stock ROM will definitely fix the issue. So even if the virus is a big time wizard and refuses to leave your phone, kindly flash a new ROM.

I hope this helps.
Have you faced this kind of issues before on your phone? Let us know using the comment box below.

Xbot, A New Trojan Virus That Hijack Your Banking Details, And Force You To Pay $100

Everything that has advantage also has disadvantage so the ability of Android devices to be customized and tweaked can also be used to intrude inside it and create havoc.

The reigning virus/malware in town now is called Xbot. Just like the name suggests, Xbot is a virus that spys your activities in your phone and detects and lock your phone automatically. Not just that, it will demand for payments before the phone will be unlocked. The malware is really dangerous because it also steals your banking information and behaves as a ransomware, logging you out of your device and forcing you to pay the sum of $100 via PayPal. Your information that is stollen by the virus is sent to Xbot's C&C server and gets inscrypted

This dangerous Trojan Virus also uses a technique called activity hijacking to tap the stored personal details in your device like the credit card information, online banking details and all your activity passwords

HOW XBOT VIRUS WORKS
It clones your online banking application whenever you want to use it. This happens in a way you won't decode because you will think it is the main application that you are launching not knowing it is the cloned app so it will Hijack the main app and transfer it to the XBOT server via webview. It will collect all the contacts names and numbers on your phone and upload them to its C2 server, also it does the same to your SMS messages on your device.


READ... Monkey Test And Time Service Virus And How To Remove It From Your Phone

According to researchers at Palo Alto Networks on their blog post;

"While Android users running version 5.0 or later are so far protected from some of Xbot’s malicious behaviors, all users are vulnerable to at least some of its capabilities. As the author appears to be putting considerable time and effort into making this Trojan more complex and harder to detect, it’s likely that its ability to infect users and remain hidden will only grow, and that the attacker will expand its target base to other regions around the world"

From the above statement, you will see that those using Android 5.0 and above versions are more protected and safe from this wicked virus while those that are still stocked on older Android versions like jellybean and KitKat are more exposed and prone to this malware attacks. So it is advisable to upgrade your Android version as soon as possible to Android Lollipop or Android Marshmallow if your phone has OTA update but if it doesn't have, just read through the prevention methods below.

HOW TO PROTECT OR PREVENT YOUR PHONE FROM THIS ATTACK
This prevention method is applicable to all Android devices including later versions.
The Trojan is reportedly in Russia and Australian and it is still spreading wide everyday all over the world. If your phone and your personal details including your online banking data is very important to you, then you have to take some precautionary measures and do not download or install applications from an unknown source unless you are 100% sure of the app you are downloading.

In fact, Disable installation of applications from an unknown source by navigating to Settings > Security > Unknown Sources; so that you won't give an application administrative privileges.

Stay safe!!!