OREANDA-NEWS. Russian anti-virus company Doctor Web would like to draw your attention to its review of mobile threats for the last month of the year just ended. The review is based on statistics collected with the aid of users who have installed and run the new, ninth version of Dr.Web for Android on their mobile devices. A total of 4,637,717 malicious or unauthorized applications were discovered on handhelds in the period from December 4-25, 2013, i.e., from the moment the new version of Dr.Web for Android was released.

Adware.Revmob.origin.1 (525,500 times), Adware.Airpush.origin.7 (476,304 times) and Adware.Airpush.origin.21 (387,881 times) were the programs most frequently detected. Android.SmsSend.origin.749 became the most “popular” malicious program (249,405 incidents). The top 20 undesirable and malicious applications found in December on mobile devices are listed in the table below.

Name

Quantity

1

Adware.Revmob.origin.1

525 500

2

Adware.Airpush.origin.7

476 304

3

Adware.Airpush.origin.21

387 881

4

Android.SmsSend.origin.749

249 405

5

Adware.Leadbolt.origin.7

240 274

6

Android.SmsSend.origin.872

234 596

7

Android.SmsSend.origin.990

126 982

8

Adware.Revmob.origin.3

125 555

9

Android.SmsSend.origin.315

101 150

10

Adware.Startapp.origin.8

95 639

11

Adware.Revmob.origin.2

91 756

12

Android.Subser.origin.1

78 124

13

Adware.Startapp.origin.5

67 906

14

Android.SmsSend.origin.987

66 512

15

Adware.Leadbolt.origin.5

64 833

16

Adware.Airpush.origin.3

62 143

17

Adware.Callflakes.origin.1

55 225

18

Android.SmsSend.origin.309

53 138

19

Android.SmsSend.origin.758

52 815

20

Android.SmsSend.origin.908

52 372

The statistics lead to the conclusion that various Android.SmsSend Trojan modifications remain the most common threats to Android. Also, Dr.Web anti-virus software for Android effectively neutralises various applications that display annoying ads on the screens of smart phones and tablets.

Whenever a malicious or unwanted program was detected, users most often removed it-this happened in 65.5% of incidents. In 27% of cases, the application was not yet installed but stored on the memory card or in the internal memory as an apk file that was removed by the anti-virus. A minor portion of users (4%) moved detected threats to the quarantine. Only 1.8% of users ignored danger warnings from the anti-virus and continued using the infected device, and another 1.4% immediately cancelled the installation of malicious applications on their mobile phones and tablets upon receiving an alert from the anti-virus program.

Samsung Galaxy S III became the most popular device among users of Dr.Web for Android in December-it accounted for 10.72% of the devices on which Dr.Web anti-virus software was installed. Samsung Galaxy S II ranks second with 5.19% of installations, Samsung Galaxy S IV ranks third with 4.70%, and Samsung Galaxy Note II ranks fourth-4.53% of Dr.Web for Android installations occurred on this device. Our users' preferences regarding Android-device manufacturer are shown in the chart below.

In addition to the threats that pose a danger to Android, Dr.Web for Android often detected and neutralised some malicious programs for Windows-those that penetrated devices while they were connected to a desktop or a laptop and used them as portable storage devices to spread further. Thus, 12,755 copies of the worm Win32.HLLW.Olala were identified and removed from mobile devices in December 2013. The mobile Dr.Web virus database contains multiple entries for malware that can replicate itself to removable media. In addition, Dr.Web promptly detected and removed numerous cross-platform Trojans of the Java.SMSSend family which can work on any mobile device that supports Java.

Doctor Web's analysts will continue to monitor the statistics and inform users about the latest threats and the overall security situation.