PUA

ELF:MempoDroid-D [PUP] removal tips

Malware Removal

The ELF:MempoDroid-D [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ELF:MempoDroid-D [PUP] virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine ELF:MempoDroid-D [PUP]?


File Info:

crc32: CA8FC551
md5: ec49ee1d3eb903d12cd2668d610724ea
name: EC49EE1D3EB903D12CD2668D610724EA.mlw
sha1: 6fb18e7d659160aa324787bc93f55e716c5eb1d1
sha256: 18e2030062140a02c79e555126a3ae1833d1591f2581e0b356f3182a7131b5e8
sha512: e3f2054133197728104b05bb754162cf036a536e5741ceefd18a71d4d759eb4328c2c6433589f82ba557bb144560e9df7f70e36e4dbf46a96fe852a13cbb81e1
ssdeep: 196608:ZphzPuwsqrRHsxZf5zODpGGIYBO2tGenqBfIu/M7pPWEq4:FP6qrR4ZpOIGBr1nOfIu/M5WEj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 123Unlock
FileVersion:
CompanyName: 123unlock
Comments: This installation was built with Inno Setup.
ProductName: SRS Easy Root for Android
ProductVersion:
FileDescription: SRS Easy Root for Android
Translation: 0x0000 0x04b0

ELF:MempoDroid-D [PUP] also known as:

K7AntiVirusExploit ( 004dd7e41 )
LionicHacktool.AndroidOS.Lotoor.B!c
DrWebTool.Rooter.5
CAT-QuickHealAndroid.Roothack.Bed10 (PUP)
ALYacTrojan.GenericKD.2700324
CylanceUnsafe
ZillyaAdware.Amonetize.Win32.13855
CrowdStrikewin/malicious_confidence_100% (W)
K7GWExploit ( 004dd7e41 )
Cybereasonmalicious.d3eb90
CyrenAndroidOS/GingerBreak.B.gen!Eldorado
SymantecSecurityRisk.gen1
ESET-NOD32multiple detections
AvastELF:MempoDroid-D [PUP]
ClamAVWin.Exploit.Lotoor-3
KasperskyHEUR:Exploit.AndroidOS.Lotoor.be
BitDefenderTrojan.GenericKD.2700324
NANO-AntivirusExploit.ElfArm32.Lotoor.dytyin
MicroWorld-eScanTrojan.GenericKD.2700324
Ad-AwareTrojan.GenericKD.2700324
SophosMal/Generic-R
ComodoMalware@#1bx0819xl7nc8
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DGM21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.2700324
EmsisoftTrojan.GenericKD.2700324 (B)
JiangminExploit.AndroidOS.akq
WebrootW32.Gen.BT
AviraANDROID/Exploit.FNLK.A
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASELF.2365
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPUA:Win32/PhoneRooter
ArcabitTrojan.Generic.D293424
GDataLinux.Trojan.Agent.YB4BCA
AhnLab-V3PUP/Win32.ZergRush.R158571
McAfeeArtemis!EC49EE1D3EB9
MAXmalware (ai score=100)
MalwarebytesTrojan.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002C0DGM21
FortinetELF/DrdDream.CX!exploit
AVGELF:MempoDroid-D [PUP]
Paloaltogeneric.ml

How to remove ELF:MempoDroid-D [PUP]?

ELF:MempoDroid-D [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment