Threat Description





Trojan:Android/AVPass.C is distributed in the guise of a Clock app; while active however, it steals information from the device and attempts to uninstall or bypass security-related apps installed on the device.


F-Secure's Mobile Security product automatically blocks installation of this program.

Technical Details

Trojan:Android/AVPass.C is distributed in an app named 'Clock'. On installation, it creates several app icons in the device's App menu panel. The icons are named "system update", "360Antivirus" and "QQ"; the last two names refer to popular apps, but none of the icons actually lead to a program.

Clicking any of the icons silently starts the trojan in the background, while the newly created app icons are deleted. Meanwhile, the trojan harvests the following details from the device:

  • SMS message and calls log
  • GPS location data
  • Contacts data
  • Stored photos
  • Phone's recording data

In addition, the trojan checks to see if any security/antivirus apps on an internal list are installed on the device. If found, the trojan requests for user root privileges in order to uninstall the security/antivirus app, or bypass it by modifying its database to prevent detection of the app.


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More