内部测试APK被Google Drive及邮件标记为病毒的排查求助
内部测试APK被Google标记为病毒,无法通过Drive/邮件共享,Virustotal仍报感染
我们有一个仅用于内部测试的build variant,之前一直通过Google Drive或邮件在团队内共享。但近一个月来,Google将该APK标记为病毒,导致无法正常共享。我已经尝试移除所有第三方依赖等疑似诱因,但Virustotal检测仍显示APK存在感染情况。
相关详情
- Virustotal检测显示该APK存在感染标记
- 邮件检测提示:

- 其他检测截图:

项目配置(build.gradle)
compileSdkVersion 33 buildToolsVersion "30.0.3" defaultConfig { applicationId "" minSdkVersion 26 targetSdkVersion 32 versionCode 21 multiDexEnabled true testInstrumentationRunner "android.support.test.runner.AndroidJUnitRunner" vectorDrawables.useSupportLibrary = true } packagingOptions { resources.excludes.add("META-INF/*") } buildTypes { release { minifyEnabled true proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro' signingConfig signingConfigs.release } debug { minifyEnabled true proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro' } } compileOptions { sourceCompatibility JavaVersion.VERSION_1_8 targetCompatibility JavaVersion.VERSION_1_8 } kotlinOptions { jvmTarget = JavaVersion.VERSION_1_8.toString() } androidExtensions { experimental = true } lintOptions { abortOnError false } dataBinding { enabled = true } applicationVariants.all { variant -> variant.outputs.all { def flavor = "" if (variant.name == "stagingDebug") { flavor = "SS" } else { flavor = "SS" } def versionName = variant.versionName outputFileName = "${flavor}-${versionName}.apk" } }
dependencies { implementation "org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.5.31" // SUPPORT implementation 'androidx.appcompat:appcompat:1.5.1' implementation 'androidx.core:core-ktx:1.8.0' // RecyclerView implementation 'androidx.recyclerview:recyclerview:1.2.1' // CardView implementation 'androidx.cardview:cardview:1.0.0' // ConstraintLayout implementation 'androidx.constraintlayout:constraintlayout:2.1.4' //Material implementation 'com.google.android.material:material:1.5.0-alpha02' // Scalable dimensions implementation 'com.intuit.sdp:sdp-android:1.0.6' implementation 'com.intuit.ssp:ssp-android:1.0.6' //print receipt // implementation files('libs/icod_3.1.7.jar') // implementation files('libs/posprinterconnectandsendsdk.jar') // implementation files('libs/scan_pro.jar') // annotationProcessor 'androidx.room:room-compiler:2.4.2' // LifeCycle Extensions : LiveData implementation 'androidx.lifecycle:lifecycle-livedata-ktx:2.2.0' // LifeCycle Extensions : ViewModel implementation 'androidx.lifecycle:lifecycle-viewmodel-ktx:2.4.1' // LifeCycle Extensions : Lifecycle Scope implementation 'androidx.lifecycle:lifecycle-runtime-ktx:2.2.0' // Activity Kotlin Extension implementation 'androidx.activity:activity-ktx:1.1.0' // Retrofit implementation 'com.squareup.retrofit2:retrofit:2.9.0' implementation 'com.squareup.retrofit2:converter-gson:2.6.2' implementation 'com.google.code.gson:gson:2.8.6' implementation 'com.squareup.okhttp3:logging-interceptor:4.9.0' implementation 'androidx.lifecycle:lifecycle-extensions:2.2.0' testImplementation 'com.squareup.okhttp3:mockwebserver:4.5.0' // Dagger Hilt implementation 'com.google.dagger:dagger:2.39.1' annotationProcessor "com.google.dagger:dagger-compiler:2.39.1" kapt 'com.google.dagger:dagger-compiler:2.39.1' implementation 'com.google.dagger:hilt-android:2.37' kapt 'com.google.dagger:hilt-android-compiler:2.37' kapt 'androidx.hilt:hilt-compiler:1.0.0' // Coroutines implementation "org.jetbrains.kotlinx:kotlinx-coroutines-core:1.3.7" implementation "org.jetbrains.kotlinx:kotlinx-coroutines-android:1.3.7" // Glide implementation 'com.github.bumptech.glide:glide:4.11.0' // kapt 'com.github.bumptech.glide:compiler:4.14.2' // implementation 'com.squareup.retrofit2:adapter-rxjava:2.1.0' // implementation 'com.squareup.okhttp3:okhttp-urlconnection:3.4.1' //tabSyncMenu // implementation 'io.github.ahmad-hamwi:tabsync:1.0.1' //stripe //implementation "com.stripe:stripeterminal:2.9.0" //firebase implementation platform('com.google.firebase:firebase-bom:30.1.0') implementation 'com.google.firebase:firebase-crashlytics-ktx' implementation 'com.google.firebase:firebase-analytics:21.1.1' //Layout to bitmap // implementation 'id.zelory:cekrek:1.0.0' // implementation 'com.hbb20:ccp:2.5.0' //for allergen filters implementation 'com.google.android:flexbox:1.1.0' //websocket // implementation 'tech.gusavila92:java-android-websocket-client:1.2.2' // implementation("com.piesocket:channels-sdk:1.0.5") }
解决方案建议
1. 更换测试APK签名密钥
debug build使用系统默认调试密钥签名,这类密钥签名的APK容易被杀毒软件误报。给debug build配置专门的测试签名密钥,或直接使用正式签名密钥打包测试包,能大幅降低误报概率。
2. 调整混淆配置
暂时关闭debug build的minifyEnabled,重新打包后检测是否还会被标记。若恢复正常,说明混淆后的代码触发了检测规则,需要优化proguard-rules.pro:添加必要的keep规则保留Android组件、第三方库核心类,避免过度混淆。
3. 提交误报申诉
确认APK无恶意代码后,直接向平台提交申诉:
- Google:通过Workspace管理员后台提交Drive/邮件误报申诉,或使用Google安全中心反馈通道
- Virustotal:在检测页面找到申诉入口,提交内部测试用途说明、签名信息、项目配置等材料,请求重新检测
4. 更新依赖与构建工具
项目中部分依赖版本较旧(如Kotlin 1.5.31、Material组件为alpha版),旧版本可能关联已知误报:
- 升级Kotlin至稳定版(如1.9.x)
- 替换Material组件为稳定版本(如1.11.x)
- 将buildToolsVersion更新为与compileSdkVersion匹配的版本(compileSdk33建议用33.0.2)
5. 临时更换共享方式
绕过Google检测,改用其他内部分发方案:
- 企业内部文件服务器
- 专业测试分发工具(Firebase App Distribution、蒲公英等)
- 加密压缩APK后发送,避免被扫描识别
内容的提问来源于stack exchange,提问作者tahreem
相关产品推荐
相关产品推荐

