Recently, two applications designed with malicious intent were discovered within the Google Play application store.  The apps were built with a façade of being utility cleaners designed to help optimize Android-powered phones, but in reality, both apps had code built in designed to copy private files, including photos, and submit them to remote servers. 


The applications, named SuperClean and DroidClean, did not stop there. Researchers also found that the malware was able to AutoRun on Windows PC devices when the phones were paired, and infect the main computer.  The malware was designed to record audio through the computer’s microphone.


AutoRun has often been used as a method of infection, and Microsoft has since sent a security fix out to Windows XP/Vista/7 in order to disable the exploitable element. In some cases, however, the feature might have been re-enabled by the user for convenience or never changed through a backlog of updates.


An application such as this has not been seen in the past, and is showing the creative methods through which malware coders are attempting to break through a computer’s security.  With the Android device acting as a Trojan horse for the infection, malicious code has the potential of bypassing established security parameters that typically keep endpoint users safe within their network.


While Webroot has already classified the apps, and they have been removed from the Google Play application market, it goes to show that protective steps are necessary on all levels of devices to avoid an infection.  Below, we will highlight the steps you can take to help stay protected from attacks like these.


Android Devices:

  • Ensure latest version of Webroot SecureAnywhere is downloaded from official Android app stores.
Webroot SecureAnywhere (PC users)

  • Ensure USB shield is enabled
    • Steps: Open Webroot > Select PC Security Tab > Select Shields > Slide USB Shield to on (green)
    • Advanced users: Ensure USB Shield is Enabledilist]
    • Steps: Open Webroot > Select PC Security Tab > Select Scan > Select Change Scan Settings > Select Heuristics > Select USB > Select desired protection settings
[/list]For all users, we recommend ensuring that AutoRun is disabled on your computer.  Even though Microsoft rolled out updates to disable, it is possible AutoRun could still be enabled.  Finally, always ensure you scan USB and other connected devices for malware before storing data or using on other PCs.


Source: SecureList -

I appreciate your recommendations against such attacks but I would add another one, especially being truly valid for Google Play:

- Before downloading an application please look carefuly how many downloads have been done and what is public popularity (rating) of such application. Trust only these which are popular and have many downloads. Also please read user reviews which can give you some kind of a feeling how good or bad an application is.

Do you have an actual link for instructions on how to disable AutoRun in Windows 7 Pro 64 bit?  I quit looking!


Few links even discuss how to disable AutoRun and most discuss Win XP, even if the question was about Win 7.  Microsoft discusses Win XP but the link for Win 7 leads to a page with no information.


AutoPlay has been disabled. 
There are some detailed instructions on how to do that in this Microsoft KB article.  There's an automated "Fix-It" method and a manual method.


Instructions for Win 7 Home and Win 7 Home Premium can be found by searching Microsoft.


The following link appears to have a registry hack for Win 7 Pro (No mention of Win 7 Pro 64 bit, but it may be the same) .


In Win 7 Pro 64 Bit

AutoPlay can be disabled in Group Policy.  However, AutoRun can't fully be disabled.  The Win 7 help states that if AutoRun is disabled then Windows Vista will prompt the user whether the autorun command is to be run.


