Riskware:Android/Smsreg.variant!Online

Threat description

Details

CATEGORYRiskware
TYPERiskware
PLATFORMAndroid

Summary

SmsReg.A is marketed under the name 'Battery Improve' and claims to help maximizes a device’s battery usage. It also silently collects data from the device without the user's knowledge or consent.

Removal

Automatic action

When detected during scanning, F-Secure SAFE will prompt you for a desired action. You may assess the detected file and choose to Uninstall, Quarantine or keep it installed on your device. More information about these options can be found at Help Center: Assess files detected during scanning.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more assistance.

Technical Details

Most variants in the Riskware:Android/SmsReg family are similar to the first variant, SmsReg.A.

SmsReg.A is marketed under the name 'Battery Improve' and claims to help maximizes a device’s battery usage. Unbeknownst to the user however, the application also collects the following information:

  • API key
  • Application ID
  • Carrier
  • Device manufacturer
  • Device model
  • GPS location
  • International Mobile Equipment Identity (IMEI) number
  • Network operator
  • Package name
  • SDK version
About the Security Cloud

F-Secure Security Cloud is a cloud-based threat analysis system that maintains a security rating for common programs, files and websites.

When an F-Secure security product encounters a suspect program or file, it sends a query over the Internet to the Security Cloud and checks for the latest rating available for the program (that is, whether it has already been rated as 'safe' or 'harmful'). Based on the rating, the security product may then either quarantine the suspect file, block it or allow it to proceed.

For more information about the Security Cloud, see:

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info