Trojan

Trojan.Detplock (file analysis)

Malware Removal

The Trojan.Detplock is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Detplock virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan.Detplock?


File Info:

crc32: 3FC5EF5F
md5: b14a7dd66e2637ad7e1001e844ccc806
name: mekon.exe
sha1: 91225583d75598143ecc6591a23f48b91c65662d
sha256: aa5156147e4ae2f87f0ed518112ccefea5f0776f74898dbd71d2f585ca55c8cf
sha512: 7acec6cbee21ad8bc005f1f19b7ad800204fadaefeb7bb65c8f72e10a332f709422357bbc6c727504a58688b4a29c030e0156ffabbb37bd0209176b80becd07f
ssdeep: 12288:u+XXJ8Al5o5qO0iXtWZMjaXUrAsYGsY//AkRITy8f3kkox:uYRK5WUtHSUrKXWoo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2005 - 2019
Assembly Version: 0.0.0.0
InternalName: mekon.exe
FileVersion: 6.9.12.15
CompanyName: G!f2*w3RZ_y8pA7-%9
Comments: 2z*R_4WgQ$p3mB8
ProductName: 6z=F?3Tc2d$Y_
ProductVersion: 6.9.12.15
FileDescription: 6z=F?3Tc2d$Y_
OriginalFilename: mekon.exe

Trojan.Detplock also known as:

MicroWorld-eScanGen:Variant.Razy.602926
FireEyeGeneric.mg.b14a7dd66e2637ad
CAT-QuickHealTrojan.Detplock
McAfeeGenericRXJM-SG!B14A7DD66E26
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Ursu.4!c
SangforMalware
K7AntiVirusTrojan ( 0055e84f1 )
BitDefenderGen:Variant.Razy.602926
K7GWTrojan ( 0055e84f1 )
TrendMicroTROJ_GEN.R023C0PAM20
BitDefenderThetaGen:NN.ZemsilF.34084.ln0@a89Ftmp
ESET-NOD32a variant of MSIL/Injector.URK
TrendMicro-HouseCallTROJ_GEN.R023C0PAM20
AvastWin32:PWSX-gen [Trj]
GDataGen:Variant.Razy.602926
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
APEXMalicious
RisingTrojan.Injector!8.C4 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Injector.pjuwk
ZillyaTrojan.Injector.Win32.680202
McAfee-GW-EditionGenericRXJM-SG!B14A7DD66E26
EmsisoftTrojan.Injector (A)
SentinelOneDFI – Malicious PE
CyrenW32/MSIL_Kryptik.ACW.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Injector.pjuwk
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Razy.D9332E
AhnLab-V3Trojan/Win32.MSIL.R316223
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
ALYacGen:Variant.Razy.602926
Ad-AwareGen:Variant.Razy.602926
MalwarebytesTrojan.PCrypt.MSIL.Generic
PandaTrj/GdSda.A
TencentMsil.Trojan-qqpass.Qqrob.Pcik
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_94%
FortinetMSIL/URK!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.PSW.374

How to remove Trojan.Detplock?

Trojan.Detplock removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment