Spy Trojan

TrojanSpy:Win32/MeiSpy.BM!MSR removal instruction

Malware Removal

The TrojanSpy:Win32/MeiSpy.BM!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/MeiSpy.BM!MSR virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/MeiSpy.BM!MSR?


File Info:

name: 6EFF53E85A9CE9F1D99C.mlw
path: /opt/CAPEv2/storage/binaries/effa0e01adad08ae4bc787678ce67510d013a06d1a10d39ec6b19e2449e25fbd
crc32: 81713972
md5: 6eff53e85a9ce9f1d99c812270093581
sha1: f5900659e29ade3d3afeb3b8ce8306e1895b67e1
sha256: effa0e01adad08ae4bc787678ce67510d013a06d1a10d39ec6b19e2449e25fbd
sha512: d7a6276a9865009e35d1610762cade087d379cf4062e55d9065cdfcf1e3c797e452163c53f6b58f53bdc8e21c57ae2d01de567bea43e28153f542e051074fb68
ssdeep: 196608:xu6XqMDtV15yRkYRdexpx+3Lb6oNEtz7o/Y:x3aMD31sRdZ3LWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13096F136B346653EC0AB0A3A9837F758983FBB712512CC1757F0094C8E399852B7E65B
sha3_384: 429f275619628db17312d624e4ef5ee7303a134eec3d717124586e5e271280d2afe7799ad9ca911ee6a4075104fd157f
ep_bytes: 558bec83c4f0b818336800e81844d8ff
timestamp: 2018-10-17 12:33:17

Version Info:

FileDescription: musicAPP
FileVersion: 1.0.0.0
ProgramID: com.embarcadero.musicAPP
ProductName: musicAPP
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

TrojanSpy:Win32/MeiSpy.BM!MSR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.b!c
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.GenericKD.46134520
FireEyeGeneric.mg.6eff53e85a9ce9f1
CAT-QuickHealTrojan.RAT.S4064655
McAfeeGeneric.dzy
Cylanceunsafe
ZillyaTrojan.Delf.Win32.110418
SangforSuspicious.Win32.Save.ins
K7AntiVirusSpyware ( 0053fa351 )
AlibabaTrojanSpy:Win32/MeiSpy.1c787fb6
K7GWSpyware ( 0053fa351 )
Cybereasonmalicious.85a9ce
VirITTrojan.Win32.PSWStealer.AZH
CyrenW32/SpyRat.BPFE-8870
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Delf.QSU
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Micropsia-9811765-0
KasperskyTrojan-Dropper.Win32.Agent.bjwrei
BitDefenderTrojan.GenericKD.46134520
NANO-AntivirusTrojan.Win32.Rat.fjutjs
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11570a47
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1326605
DrWebBackDoor.Rat.253
VIPRETrojan.GenericKD.46134520
TrendMicroTROJ_GEN.R002C0CDN21
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.rc
EmsisoftTrojan.GenericKD.46134520 (B)
IkarusTrojan-RAT.Micropsia
JiangminTrojanDropper.Agent.ghgx
WebrootW32.Trojan.Casdet
AviraHEUR/AGEN.1326605
Antiy-AVLTrojan/Win32.Desertfalcon
MicrosoftTrojanSpy:Win32/MeiSpy.BM!MSR
XcitiumMalware@#ahvx7n4fs393
ArcabitTrojan.Generic.D2BFF4F8
ViRobotTrojan.Win32.Z.Agent.8762368
ZoneAlarmTrojan-Dropper.Win32.Agent.bjwrei
GDataTrojan.GenericKD.46134520
GoogleDetected
AhnLab-V3Trojan/Win32.Casdet.C2831514
BitDefenderThetaGen:NN.ZelphiF.36250.@V0@aGlJ1Uji
ALYacTrojan.Agent.Micropsia
VBA32BScope.TrojanDownloader.Delf
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0CDN21
RisingTrojan.Generic@AI.98 (RDMK:MdGVIeLEIrls5wSLZh+/uQ)
YandexTrojan.GenAsa!IqoyS/vtEL4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Delf.QSU!tr.spy
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:Win32/MeiSpy.BM!MSR?

TrojanSpy:Win32/MeiSpy.BM!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment