VIRUS NAME LIBRARY

APK virus name library

Every detection (virus) name that has come up in VendorGuard APK scans, each with its own page: what each part of the name means, how the vendor words the warning, how severe it is and what to do about it.

Detection names: 12

Detection nameVendor warningRisk levelAppsLast seen
Android.Virus.Gray.Poker.A.WLDB.LuckyCashGameThis software is suspected to be an illegal gambling software and may cause financial losses. Please use it with caution.Risk208/07/2026
Android.Virus.Gray.PiggyGoldcoin.OThis software may cause financial losses and easily leaks privacy: It is suspected to be fraudulent financial software, so install with caution!Risk208/31/2026
Android.Virus.Gray.SexBLTWbindsnake.A.CBWFXX.PornViolThis application may contain illegal content such as pornography. To avoid any infringement on your rights, please carefully consider whether to install and use it.Risk207/11/2026
Android.Virus.Gray.Sexpay.S.CBWFXX.PornViolThis software may cause financial loss and easily leak privacy: it is suspected to be pornographic software and may use pornographic content to induce deductions and the installation of promotional software. Install with caution!Risk107/11/2026
Android.Virus.Gray.BulimiaTGen.HThis application may pose risks. To avoid any harm to your rights, please carefully consider whether to install and use it.Risk107/03/2026
Android.Virus.Gray.Generic.B该软件可能造成您的权益受损:被较多用户投诉存在风险行为,谨慎安装!Risk110/07/2026
Android.Risk.Risk/Android.R_Oth.AntiFraud.R_Oth.AntiFraud[欺诈应用]应用涉嫌诈骗行为,请谨慎使用。Virus110/06/2026
Android.Virus.Gray.Crackgame.A.EYXW.BundInst该应用可能造成您的权益受损:可能存在风险,谨慎安装!Risk110/02/2026
Android.Virus.Gray.Sexpay.M.CBWFXX.PornViolThis application may contain illegal content such as pornography. To avoid any infringement on your rights, please carefully consider whether to install and use it.Risk109/06/2026
Android.Riskware.Gray.Fraud.BZ.SZSPThis software is suspected of containing risky code and may involve deceptive or fraudulent activities, resulting in financial losses and privacy breaches. Please use it with caution.Virus108/20/2026
Android.Virus.Gray.Mixopteroidea.B.YYTS.UserComplThis software may cause harm to your rights: many users have reported that it poses a risk, please install with caution!Risk108/04/2026
Android.Virus.Gray.BulimiaTGen.FThis application may pose risks. To avoid any harm to your rights, please carefully consider whether to install and use it.Risk108/04/2026

How to read a detection name

Engines build detection names in a fixed format: dot-separated parts that go from general to specific, with a slash between names when an app matches more than one. Taking Android.Virus.Gray.Poker.A.WLDB.LuckyCashGame:

PartTypeMeaning
AndroidPlatformAndroid app, i.e. an APK package.
VirusCategoryVirus class: the engine files it under viruses or malware. Followed by Gray it means grayware rather than a destructive virus.
GrayCategoryGrayware: between a normal app and malware; typical of gambling, adult content, fraud, deceptive billing and bundled promotion.
PokerFamily / samplePoker / card games: card and board game apps, often related to gambling.
AVariantVariant letter: versions of the same family are lettered in sequence.
WLDBCategory codeProbably the pinyin initials of 网络赌博 (online gambling): gambling and betting apps.
LuckyCashGameFamily / sampleFamily or sample name that tells apart different apps or code traits within the same category.

FAQ

What is a detection name?

A detection name (virus name) is the label a security engine gives a flagged package, naming the platform, the risk category and the family. When a phone’s security app or app store warns about a “risky app” or a “virus”, such a name is usually behind it.

What does a detection starting with Android.Virus.Gray mean?

Gray means grayware: not necessarily destructive code, but considered harmful to users’ interests, e.g. gambling, adult content, fraud, deceptive billing or bundled promotion. The family name and tags after it give the specific reason.

Is every detection a virus?

No. Detections at the “Risk” level are mostly grayware or policy calls; “Virus” means malicious code or high-risk behavior. False positives happen too, so you can re-scan or appeal to the vendor.

What should a developer do about a false positive?

Check the detection name and the vendor’s warning, review third-party SDKs, packers, permissions and content for what triggers it, appeal through that vendor’s developer platform, and re-scan on VendorGuard once the appeal is accepted.