Cannot delete malware from foundation storage

Hi,

my antivirus program “GData Mobile Security” recently detected a malware of type trojan on my phone. In the uploaded screenshot you see the message (in german).
When I try to have the antivirus software to delete the malware, it always states, that this action cannot be done.
So I tried to find the path to the given storage location to delete it myself - also with connection to my laptop. But I just cannot find or access the location on my phone. As per information from the antivirus program the malware seems to be in the drive section of the foundation software. I am not familiar enough with IT or programming topics to know what to do now. I updated the latest available OS version and deleted the stored data and cache from nearly all installed apps. But that changed nothing. I have a Fairphone 4 with Murena OS.

Can you please advise how to access the given storage location and to remove that malware?
Thanks in advance.

Marina

eDrive is a fundamental system app for /e/OS. It is involved in the process of sync of files on the phone to Murena cloud.

It is ofc not present in regular Google Android.

I would suggest that the warning should simply be ignored.

2 Likes

Antivirus Apps (the sense of which on smartphones is debatable) have to somehow identify malware, and the methods they employ don’t always lead to correct results. So-called “false positives” (totally harmless files wrongly identified as malware) are almost an everyday occurrence in overall Antivirus land. I would suspect this is one.

1 Like

Beware of false positives. This site has been useful for PC, probably good for phone too.

In any case, if there actually is an infection, I’d just do a factory reset. “nuke the entire site from orbit. It’s the only way to be sure.”

Only that an Android factory reset doesn’t “nuke the entire site”, but only deletes user data, user-installed Apps and their data as well as perhaps some settings. The OS itself remains untouched, so if some malware manages to infect the OS (as is suspected here), a factory reset would not help.