ANDROIDOS_FAKEAV.F
Premium Service Abuser
Android

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This app pretends to be an antivirus app. It requires the user to install it with administrator privileges, which adds to the difficulty in removal of this app.
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
It bears the file icons of certain applications to avoid easy detection and consequent removal.
TECHNICAL DETAILS
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This Trojan bears the file icons of the following applications:
- Skype
NOTES:
This app pretends to be an antivirus app. It requires the user to install it with administrator privileges, which adds to the difficulty in removal of this app.
Similar to rogue antivirus on desktops, it attempts to perform a fake scan on the device and shows fake results:


When the user clicks on the REMOVE ALL THREATS NOW option, the app requires the user to purchase the full version:

Note that on this screen the home, menu, or back phone options do not work. This traps the user to purchase the app to be able to exit from the program.
When a user opens another app, this malware shows a popup message over the other app. This malware then tags the other app as infected.

When the user clicks Remove button, this app leads the user to the purchase screen. When the user clicks Stay unptotected button, this app leads the user to the phone desktop.