Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.
Issue abstract:
Detailed description: Tengo un problema en mi telefono movil con sistema Android, que a cada momneto detecta una aplicacion mailiosa pero solo me da la opcion de desinstalar, una vez que lo hago la vuelve a detectar y asi suscesivamente, cuando lo que realmente deberia es evitar que se instale, o bloquearle de alguna forma. Alguien tiene la solucion??
Product & version number:
OS details:
What is the error message you are seeing?
If you have any supporting screenshots, please add them:
1 Like
bjm
July 22, 2026, 5:40pm
2
Milton_Villacis:
I have a problem with my Android phone. It keeps detecting a malicious app, but only gives me the option to uninstall it. Once I do, it detects it again, and so on. What it should really do is prevent it from installing in the first place, or block it somehow. Does anyone have a solution?
Hello @Milton_Villacis
If Norton keeps detecting the same malicious app after you uninstall it, that often means something else on the device is reinstalling it rather than the original app surviving the uninstall.
A few questions that may help narrow it down:
Which Norton app are you using (Norton 360 or Norton Mobile Security), and what version?
What Android phone model and Android version do you have?
Does Norton identify the app by name, or provide a threat name?
Was the app installed from the Google Play Store, or from another source (APK, third-party app store, etc.)?
If the app keeps coming back, check for things like:
Another app with Device Administrator or Accessibility permissions that may be reinstalling it.
A third-party app store or installer app.
A work profile or device management app that automatically reinstalls applications.
In normal operation, Norton can detect and prompt you to remove malicious apps, but it generally cannot prevent every app from being installed in the first place because Androidâs security model limits what third-party security apps can do. If we can identify the app thatâs being detected, it may be possible to determine whatâs causing it to reappear.
AI sourced content may make mistakes
bjm
July 22, 2026, 5:59pm
4
Milton_Villacis:
Telefono marca doogee modelo fire 3 pro, android version 15
Norton 360 version 26.10.1.260610581
Sistem Android is the name
Se instala sola por lo que el origen es desconocido, aunque en la informacion de la misma indica que es de la tienda de google play
Phone: Doogee Fire 3 Pro
Android: 15
Norton 360: 26.10.1.260610581
Detected app name: âSystem Androidâ (âSistema Androidâ)
It installs itself , and the source is unknown, although the app information says it is from Google Play .
A few thoughts:
The fact that the detected app is called âSystem Androidâ is unusual. On a standard Android device, the Android system is a core component and should not be uninstalling and reinstalling itself.
On the other hand, malware sometimes disguises itself with names like âAndroid System,â âSystem Update,â or similar to look legitimate.
The OPâs statement that it âinstalls itselfâ but is shown as coming from Google Play is also suspicious. It could be a mislabeled source, a Play Protect-related component, a vendor customization, or malware masquerading as a system app.
I would not recommend Clear Data/Clear Cache or any other removal steps yet.
Instead, Iâd ask for one more critical piece of information:
Could you post a screenshot of the Norton detection showing the threat name and the app details? Also, if you tap on the detected app in Android Settings, what is the package name (for example, com.android...)?
The package name is much more reliable than the displayed name. If itâs something like com.android.systemui or another standard Android package, thatâs a very different situation than a fake package with a misleading display name.
Iâd also be interested to see whether other forum contributors recognize this on Doogee devices. Some manufacturers preload components with localized names that can confuse security software, and itâs possible this could even be a false positive specific to that device. Until thereâs more evidence, Iâd avoid telling the OP to keep uninstalling what appears to be a âSystem Androidâ app.
A screenshot of the Norton detection.
The appâs package name (com...).
The threat name Norton reports.
If it turns out to be a false positive against a legitimate package, then escalating it to Norton (and, if possible, providing the APK for analysis) would make sense. Right now, thereâs just not enough information to know what Norton is actually flagging.
AI sourced content may make mistakes
bjm:
System Android
@Milton_Villacis Have you ran a Google Play Store scan on your device?
AI Overview
Malware occasionally slips past Google Playâs security, commonly hiding in apps like QR code readers, document scanners, or keyboards. These malicious âdropperâ apps download hidden payloads later to steal credentials or hijack accounts.
How to Check and Remove Malware
1. Run a Play Protect Scan:
** * Open the Google Play Store app.**
** * Tap your profile icon in the top right.**
** * Select Play Protect and tap Scan to check for harmful apps.**
Review Permissions: Check your app list for recent downloads with suspicious permissions (e.g., Accessibility access or SMS reading rights) and uninstall them.
Use Safe Mode: If the app resists deletion, restart your phone in Safe Mode to disable third-party apps, then uninstall the malware.
Visit the Google Support Guide for official, step-by-step instructions on securing your device and removing unsafe software.
SA
1 Like
bjm
July 22, 2026, 6:08pm
6
SoulAsylum:
Run a Play Protect Scan:
Running a Play Protect scan is a good additional check. It would also be helpful to see a screenshot of Nortonâs detection, including the threat name and, if available, the appâs package name.
bjm
July 22, 2026, 6:15pm
8
Milton_Villacis:
Doogee brand phone model fire 3 pro, android version 15
Norton 360 version 26.10.1.260610581
Android System is the name
It installs itself, so its origin is unknown, although its information indicates that it is from the Google Play store.
In early 2023, there was a widespread Avast/AVG false positive where an app displayed as âAndroid Systemâ was suddenly flagged as malware on many devices. Other scanners (such as Malwarebytes) came back clean, and AVG later acknowledged it was a false positive and disabled the detection.
https://www.reddit.com/r/AndroidQuestions/comments/1049y17/android_system_malware/
I use Avast Antivirus and Malwarebytes applications to scan my Samsung Galaxy Tab S7+ device (running on Android version 13) regularly to check if there is viruses/malware detected and always results to none.
Until today, January 6, 2023, my Avast Antivirus app has detected one malware program named âAndroid systemâ (Detection ID: 2f53b9400cea). The app says that this malware is installed in my deviceâs system partition and cannot be uninstalled, instead I must deactivate it through the Settings app. When I tried to uninstall/disable, there is no option.
https://support.google.com/android/thread/195996096/my-antivirus-app-detected-android-system-as-malware-is-it-true
Similar false positives involving apps displayed as âAndroid Systemâ have occurred with other Android security products in the past. Before assuming this is malware or a false positive, it would be helpful to see the Norton detection details, including the threat name and the appâs package name.
============
Doogee is a Chinese smartphone manufacturer that focuses on budget and rugged phones. Theyâre legitimate, but theyâre not a mainstream brand like Samsung, Google, Motorola, or OnePlus.
A few things about Doogee that are relevant here:
They often ship heavily customized Android builds.
They may include vendor-specific system apps and utilities.
Their firmware and update cadence can differ from Googleâs Pixel devices or Samsungâs One UI.
Because of their smaller market share, security vendors may have less exposure to their custom system components, making false positives more plausible (though certainly not guaranteed).
Some Android devices from various manufacturers, particularly certain budget models, have been reported over the years to include unwanted software or, in isolated cases, malware embedded in the firmware. If malware is truly embedded in the system image, it may survive a factory reset and cannot always be removed by conventional antivirus software alone.
============
============
AI sourced content may make mistakes
bjm:
The fact that the detected app is called âSystem Androidâ is unusual. On a standard Android device, the Android system is a core component and should not be uninstalling and reinstalling itself.
On the other hand, malware sometimes disguises itself with names like âAndroid System,â âSystem Update,â or similar to look legitimate.
The OPâs statement that it âinstalls itselfâ but is shown as coming from Google Play is also suspicious. It could be a mislabeled source, a Play Protect-related component, a vendor customization, or malware masquerading as a system app.
I would not recommend Clear Data/Clear Cache or any other removal steps yet.
Instead, Iâd ask for one more critical piece of information:
Could you post a screenshot of the Norton detection showing the threat name and the app details? Also, if you tap on the detected app in Android Settings, what is the package name (for example, com.android...)?
The package name is much more reliable than the displayed name. If itâs something like com.android.systemui or another standard Android package, thatâs a very different situation than a fake package with a misleading display name.
Iâd also be interested to see whether other forum contributors recognize this on Doogee devices. Some manufacturers preload components with localized names that can confuse security software, and itâs possible this could even be a false positive specific to that device. Until thereâs more evidence, Iâd avoid telling the OP to keep uninstalling what appears to be a âSystem Androidâ app.
A screenshot of the Norton detection.
The appâs package name (com...).
The threat name Norton reports.
If it turns out to be a false positive against a legitimate package, then escalating it to Norton (and, if possible, providing the APK for analysis) would make sense. Right now, thereâs just not enough information to know what Norton is actually flagging.
thanks guru, but all done, and nothing resuts goods
bjm
July 22, 2026, 10:39pm
11
Hello @Milton_Villacis
Norton is displaying a generic malware alert :
âSoftware malicioso encontradoâ (âMalicious software foundâ)
The app name shown is simply:
âSistema Androidâ (âAndroid Systemâ)
Norton offers only:
There is an information (âiâ) icon , which may provide additional details if tapped.
The detection ID is:
Whatâs not shownâand what we still needâis:
Threat name (Trojan? Heuristic? Riskware?)
Package name (e.g., com.android...)
Any explanation of why Norton considers it malicious.
My next question to the OP would be
Could you tap the â (information) icon and post what it says? Also, if you tap the app in Android Settings > Apps , what is the package name?
The â may reveal the detection name or other metadata.
One thing I noticed
Norton is not saying âAndroid Systemâ is infected. Itâs identifying an app whose display name is âSistema Android.â
Those are not necessarily the same thing.
Android allows apps to present almost any display name. Malware authors have long used names like:
Android System
System Update
Google Services
Device Services
to appear legitimate.
Conversely, a legitimate system component may also have the localized display name âSistema Android.â
Thatâs why the package name remains the critical missing piece.
Where I stand now
I still think this is unlikely to be solved solely through the Community . If the OP confirms the app keeps returning after uninstalling and Norton continues detecting it, this is becoming a case for Norton Support to investigate. The Community can help identify whatâs being detected, but it canât determine whether detection ID 6b91dbbe4f13 corresponds to a legitimate threat, a false positive, or a vendor-specific system component. That will require Nortonâs internal detection database or engineering review.
What exactly is Norton detecting? (package name/threat name)
Is it actually a system app?
Does Play Protect agree?
Does the app reappear because Android restores it, or because something reinstalls it?
Thank you for providing the screenshot. Since Norton continues to detect the application after uninstalling it, and the application appears to be system-related (âSistema Androidâ), I recommend contacting Norton Support. Please provide them with the screenshot and mention the detection ID (6b91dbbe4f13). They can review the detection in more detail and determine whether it is a legitimate detection, a device-specific issue, or a possible false positive requiring further investigation.
OP has provided enough to justify contacting Norton Support, even though there are still unanswered technical questions.
Hereâs what Norton Support now has to work with:
Device: Doogee Fire 3 Pro
Android: 15
Norton 360: 26.10.1.260610581
Symptom: Norton repeatedly detects an app named âSistema Android.â
Behavior: The user uninstalls it, but Norton detects it again.
Evidence: A screenshot showing Norton identifying it as a malicious application and offering Uninstall .
Detection ID: 6b91dbbe4f13
Thatâs enough for support to begin investigating. They may ask for additional information (such as the package name or logs), but the case is sufficiently documented that it shouldnât remain solely in the Community.
Since Norton continues to detect the app after uninstalling it, and it appears to involve a system-related application, I recommend contacting Norton Support. They can determine whether this is a legitimate detection, a false positive, or an issue requiring further investigation.
AI sourced content may make mistakes
One other question coming to mind is has this device been ârootedâ at some point?
SA
If you have Norton 360 set to scan system files, you risk getting the kind of warnings you are seeing here. That is because Norton detects a system app doing things that would seem to be malicious.
To disable the System App scan tap on the Account icon at the bottom right of the 360 interface. Then tap on Settings > Security then be sure to turn off Scan System Apps.
As long as you have not rooted the device, this will not reduce your protection.
2 Likes