Backdoor

How to remove “Backdoor.Win32.Mokes.ahbf”?

Malware Removal

The Backdoor.Win32.Mokes.ahbf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.ahbf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Mokes.ahbf?


File Info:

crc32: 68251A0A
md5: 2d2a72236628870121ae36241664026c
name: elin.exe
sha1: 5f58b6cf926e9f42bca6199a60ad7af77ef5c362
sha256: 379f030e2b2ecadaa9e549e4d35d0999ded8b6c6f70fbfe055a0ed36dd6a6560
sha512: a44d8772b0baffd0bbea9ecb7a2542fd7328b873fb512be6479f5dd77ac102db0441c47202432af722e5566e6170f20f3616e8265cb1868b113ba8401acc0818
ssdeep: 6144:ELZJBxJFY33WBeXo8EWCeN509JA7PdIYh5MP:OzFY3mcXoxHeN4Gz5K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: SCBDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: SCBDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: SCBDemo MFC Application
OriginalFilename: SCBDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Mokes.ahbf also known as:

MicroWorld-eScanTrojan.GenericKD.32617409
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Mokes.m!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.32617409
K7GWTrojan ( 0055a0701 )
K7AntiVirusTrojan ( 0055a0701 )
TrendMicroTROJ_FRS.VSNTJL19
CyrenW32/Trojan.YURO-0489
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.32617409
KasperskyBackdoor.Win32.Mokes.ahbf
AlibabaBackdoor:Win32/Mokes.4e069579
NANO-AntivirusTrojan.Win32.Mokes.geiwzb
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.32617409
SophosMal/Generic-S
ComodoMalware@#3t3bxna48a2i8
F-SecureTrojan.TR/Kryptik.hgnia
DrWebTrojan.MulDrop11.24157
ZillyaTrojan.Azorult.Win32.4
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gh
FireEyeGeneric.mg.2d2a722366288701
EmsisoftTrojan.GenericKD.32617409 (B)
IkarusTrojan.Win32.Krypt
F-ProtW32/Agent.BHZ.gen!Eldorado
JiangminTrojan.Banker.Danabot.bje
WebrootW32.Trojan.Gen
AviraTR/Kryptik.hgnia
Antiy-AVLTrojan[Backdoor]/Win32.Mokes
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F1B3C1
ZoneAlarmBackdoor.Win32.Mokes.ahbf
MicrosoftTrojanDownloader:Win32/Dofoil.AD
TACHYONBackdoor/W32.Mokes.460312
AhnLab-V3Trojan/Win32.Coinstealer.C3525369
Acronissuspicious
VBA32Backdoor.Mokes
ALYacBackdoor.Mokes.gen
MAXmalware (ai score=100)
MalwarebytesTrojan.Downloader
ESET-NOD32a variant of Win32/Kryptik.GXNC
TrendMicro-HouseCallTROJ_FRS.VSNTJL19
YandexTrojan.PWS.Racealer!
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74648675.susgen
FortinetW32/Mokes.AHBF!tr.bdr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.f926e9
PandaTrj/CI.A
Qihoo-360Win32/Backdoor.db9

How to remove Backdoor.Win32.Mokes.ahbf?

Backdoor.Win32.Mokes.ahbf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment