Backdoor

How to remove “Backdoor.Win32.Mokes.ajwz”?

Malware Removal

The Backdoor.Win32.Mokes.ajwz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.ajwz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Mokes.ajwz?


File Info:

crc32: 4B72D48B
md5: 404d21f2e640f82d2e662ee67df9d76a
name: upload_file
sha1: 4225c7345117e39ccee4e2822a4db3662846d2dc
sha256: 1657dcfd4a8c2eb9278fb15367501830e79c727b53ce3a3c7cb23fdc14b0787d
sha512: 61364df9f857319098d732e6f18570189141e6af16a5dc0d8a317aa662f5bd5163dd96e7cc487ac70b825b68d3d6d5bf717993ba29c83b46f5b1a28bcf5e96e0
ssdeep: 24576:AyIYBezq0JEcxL/+JUmWKGW+wuhgAvAv3vzvTvTvTvTvTvTvTvTvTvTvTvTvTvTV:Aywu0Uri302pcgHd+X6M51NwvpVA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Dpeams
Comments: This installation was built with Inno Setup.
ProductName: KASOL
ProductVersion: 7.45
FileDescription: KASOL Setup
Translation: 0x0000 0x04b0

Backdoor.Win32.Mokes.ajwz also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43715106
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!404D21F2E640
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.43715106
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecSMG.Heur!gen
TrendMicro-HouseCallTROJ_GEN.R002H0CHN20
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Mokes.ajwz
AlibabaBackdoor:Win32/Mokes.37c076a4
NANO-AntivirusTrojan.Win32.Mokes.hsncui
ViRobotTrojan.Win32.Z.Mokes.1062937
AegisLabTrojan.Win32.Mokes.m!c
TencentWin32.Backdoor.Mokes.Ozij
Ad-AwareTrojan.GenericKD.43715106
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Zurgop.ypauw
InvinceaMal/Generic-S
EmsisoftTrojan.GenericKD.43715106 (B)
IkarusTrojan.Dofoil
JiangminBackdoor.Mokes.cnq
MaxSecureTrojan.Malware.105527999.susgen
AviraTR/Dldr.Zurgop.ypauw
MicrosoftTrojan:Win32/Ymacco.AA16
ArcabitTrojan.Generic.D29B0A22
ZoneAlarmBackdoor.Win32.Mokes.ajwz
GDataTrojan.GenericKD.43715106
AhnLab-V3Trojan/Win32.Agent.R348617
BitDefenderThetaGen:NN.ZexaF.34216.mqW@a0c1MocG
ALYacTrojan.GenericKD.43715106
MAXmalware (ai score=86)
VBA32Backdoor.Mokes
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Zurgop.DA
FortinetW32/Ursu.926483!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM42.3.566D.Malware.Gen

How to remove Backdoor.Win32.Mokes.ajwz?

Backdoor.Win32.Mokes.ajwz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment