Spy Trojan

Trojan-Spy.Mekotio (A) (file analysis)

Malware Removal

The Trojan-Spy.Mekotio (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Mekotio (A) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Mekotio (A)?


File Info:

crc32: F18DF99A
md5: f5d015422c420959c18e5a5c1e5f8de7
name: CG4KWEMBK1HMJOIJSFQJNCYZ8Z6OMUL72R6
sha1: 3ed0f1c62db254e4094a13afb183ca0f69902a11
sha256: 2aaad8177d08507b09dc3d419b4d31f65db6fe6bc6314ffce650b9fc57f0817c
sha512: ff3254e19cbfeaa8b4cdd9add6968cd1b1f45a32aee43e71ab2147ff77e4d3a45ee3cc01bb55d144ccac895bf8676778dd1e46502ac2af566799deb92ea3d19c
ssdeep: 98304:pn2sfWLmKuaDohO1HQ8VdMQPvnHUr2jQ4oBxY3IyJWtUHEwzP4X8qP1pU83vZtJ:pndngvLoBi4kHEw748yppZt9yfL
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

ProgramID: com.embarcadero.WVPWN07LEJL9NY1
ProductVersion: 1.0.0.0
ProductName: WVPWN07LEJL9NY1
FileVersion: 1.0.0.0
FileDescription: WVPWN07LEJL9NY1
Translation: 0x0409 0x04e4

Trojan-Spy.Mekotio (A) also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.44249251
CAT-QuickHealTrojan.Multi
McAfeeArtemis!F5D015422C42
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderTrojan.GenericKD.44249251
K7GWSpyware ( 0055a97d1 )
K7AntiVirusSpyware ( 0055a97d1 )
ArcabitTrojan.Generic.D2A330A3
InvinceaMal/Generic-S
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Mekotio.DA
APEXMalicious
KasperskyTrojan-Banker.Win32.Melcoz.uz
AlibabaTrojanBanker:Win32/Melcoz.7f09c415
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
RisingSpyware.Mekotio!8.F5DF (TFE:5:ZwRJIAfOojE)
Ad-AwareTrojan.GenericKD.44249251
EmsisoftTrojan-Spy.Mekotio (A)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
TrendMicroTROJ_GEN.R023C0GJV20
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGeneric.mg.f5d015422c420959
SophosMal/Generic-S
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Spy]/Win32.Mekotio
GridinsoftSpy.Win32.Keylogger.oa
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmTrojan-Banker.Win32.Melcoz.uz
GDataTrojan.GenericKD.44249251
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C3521187
Acronissuspicious
ALYacTrojan.GenericKD.44249251
MAXmalware (ai score=99)
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R023C0GJV20
TencentWin32.Trojan-spy.Mekotio.Efam
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_53%
FortinetW32/Mekotio.DA!tr.spy
MaxSecureTrojan.Malware.109195461.susgen
AVGWin32:Trojan-gen
PandaTrj/CI.A
Qihoo-360Generic/HEUR/QVM39.1.E5BB.Malware.Gen

How to remove Trojan-Spy.Mekotio (A)?

Trojan-Spy.Mekotio (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment