Backdoor

Backdoor.Win32.Mokes.ahwv removal instruction

Malware Removal

The Backdoor.Win32.Mokes.ahwv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.ahwv virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Mokes.ahwv?


File Info:

crc32: EBB6B574
md5: 0e2c09ef6b10e633e48f4ce972e0de0f
name: snok_priv.exe
sha1: 1305f41b6e749f63db846d12b79d31da161884e5
sha256: 3eba278a4cc7e7fbbc71549c1bd31f9e425cb9d51f54cd86dfb3e1a12195dc9f
sha512: 08980034b0a504671dd131777bf303cf6ffe4125004c17f34bb592ee582681cbc0652287d135c0bed64e59481bbd31d761c9adb6b64bdf9fed4852e5a0d8f8af
ssdeep: 6144:pPKl2hEAx/P6bR7iImMtK/tm987J2Tf/a+eyT:pZplibtiIw/k8gTHau
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Mokes.ahwv also known as:

McAfeeRDN/Generic.grp
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32966111
K7GWRiskware ( 0040eff71 )
TrendMicroTrojan.Win32.WACATAC.THABOBO
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Zurgop.DD
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.ahwv
RisingTrojan.Hancitor!8.B197 (RDMK:cmRtazpT8GMEQcoBa8uSd7Ys1hut)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32966111 (B)
DrWebTrojan.Siggen9.4857
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.fm
FortinetW32/GenKryptik.ECIJ!tr
FireEyeTrojan.GenericKD.32966111
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
MAXmalware (ai score=91)
ArcabitTrojan.Generic.D1F705DF
ZoneAlarmBackdoor.Win32.Mokes.ahwv
BitDefenderThetaGen:NN.ZexaF.34084.vyZ@a83b!aic
ALYacTrojan.Agent.Wacatac
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.WACATAC.THABOBO
TencentWin32.Backdoor.Mokes.Gca
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKD.32966111
Ad-AwareTrojan.GenericKD.32966111
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/HEUR/QVM08.0.AEB9.Malware.Gen

How to remove Backdoor.Win32.Mokes.ahwv?

Backdoor.Win32.Mokes.ahwv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment