Koodo Community
Question

Horrible BLUETOOTH Virus. 4 Phones Later. Still Infected.


I got infected with a computer virus on February 5, 3 months and 4 phones later, I am still plagued with it. I am blaming the fact that I live in a condo, and believe my neighbor has it, and the fact that every time you start a new device, for some stupid mf reason, Bluetooth is active.

 

4 phones, 3 laptops, new Google smart everything (lights, thermostat etc) and I still cannot get rid of it. It is dressed as a Google Update, and swaps out the real playstore for a fake one. Attached are just a few of the 12 pages of permissions PlayStore on my phone has, along with the a portion of the back end (hidden in Chrome). I am fairly computer savy, but am clueless with Mobile. Anything I download from playstore is just more malware. From what I gather, it is using my phone to cryptomine, but it also logs everything, and he can control everything. (I HAVE TYPED THIS TWICE NOW, AND NEVER TURNED ON CAPS).

 

CAN ANYONE HELP? I did reach out to Samsung, they directed me back to Koodo. Galaxy S 23

 


4 replies

Userlevel 7
Badge +4

First off, this would not be something Koodo can help with since Koodo is only a service provider, and you have identified this as a malware/virus issue.

 

From my understanding (and things can change), for a virus/malware to spread through bluetooth, the bluetooth connection must be established.  Just having bluetooth on should not be enough to infect.  This means you must allow the connection to the bluetooth device to pair it.

Now, with that said….

Have you tried setting up a new device away from the condo?

Once infected, does a factory restore (again away from the condo) fix the issue?

Respectfully, your understanding is inaccurate. Unlike Wifi, BT is a glorified radio. The "pairing code" is not authentication, but merely an identifier to ensure you are connecting to the correct device. Bluetooth requires no authentication whatsoever, just think about your wireless mouse/keyboard, plug and play, no password.

 

I have done several factory resets, the virus/malware pre-boots it, and does a "fake reset", I only discovered this after stumbling upon the video file used. It is the same for my computers. 

 

Check out the screenshot, where my BT is off, but in the backend of the virus, it's concurrently ready to roll.

 

I understand this is not a "koodo problem" persay, but I do truly believe that this infection does have the capability to topple them, or at minimum, devastate their customers.. Bluetooth is even the method utilized to read pacemakers.. Thanks for responding, and I am open to any suggestions. :)

P.s. yes. I named my phone VirusTime to hopefully ward off any of my neighbour's willfully connecting to it.

If your play store is a fake as you say it is, I recommend you use your WIFI to go to the actual play store and download a anti virus like ESET or kaspersky (please don’t get avast, it’s overrated) and scan your phone for everything the anti virus will allow to scan for. If yuo don’t feel safe doing this on your phone, if you own a computer use your computer instead.

If for some reason you can’t get to the play store by using play dot google dot com, I suggest going to apkpure dot com and downloading the anti virus from there.

I get that these app stores are intended to make people feel safe and secure but they are only as secure as google and apple can keep up to malice behavior from “hackers” and such. And if you ask me giving your email and password is just as invasive as a virus slowing down your computer, just a different method.

Lastly, a personal belief I have is that all these radios are on by default, cell, BT, WIFI so that we’re always connected 24/7 which can be a nice feeling but not necessary at all but if you want people to adopt that behavior this is the behavior you pull.

I hope you figure something out. :)

Reply