Backdoor

Backdoor.Win32.Mokes.aknz malicious file

Malware Removal

The Backdoor.Win32.Mokes.aknz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.aknz virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.aknz?


File Info:

crc32: 81BD06BA
md5: df40ac59f1022b97894abf0582662ff8
name: upload_file
sha1: 98fdf7535a017bea950e9124f5022617b4787f34
sha256: 1765e5f0ee49b2b6cf4a7361bbaac484f15c6c1d003de02338fffdb615e831d8
sha512: 4d5ef29ac454462f5fcb91e27c71949caa36f016edd86d32c5e8a22f9cb86027799fce805cffac9e3b0b4f3d93aa4c412cd34480551ff3e6a9128825416665e7
ssdeep: 3072:AO1LzxGZ9Vag6ujkyamUoo7Or0WpVJTtTDTvDhZmJ8:AO1LsAyjZamroJGJTtTDTvD6J8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: SMSvcHost.exe
FileVersion: 3.0.4506.5420 (Win7SP1.030729-5400)
CompanyName: Microsoft Corporation
PrivateBuild: DDBLD247
Comments: Flavor=Retail
ProductName: Microsoftxae .NET Framework
ProductVersion: 3.0.4506.5420
FileDescription: SMSvcHost.exe
OriginalFilename: SMSvcHost.exe
Translation: 0x0409 0x04b0

Backdoor.Win32.Mokes.aknz also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43889328
Qihoo-360Win32/Backdoor.508
ALYacTrojan.GenericKD.43889328
SangforMalware
K7AntiVirusTrojan ( 0056f76f1 )
AlibabaBackdoor:Win32/Mokes.6b68ed68
K7GWTrojan ( 0056f76f1 )
Cybereasonmalicious.35a017
TrendMicroTROJ_FRS.0NA103IP20
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.aknz
BitDefenderTrojan.GenericKD.43889328
TencentMalware.Win32.Gencirc.10ce05be
Ad-AwareTrojan.GenericKD.43889328
SophosMal/EncPk-APV
ComodoMalware@#3i1q1vtl4cf72
F-SecureBackdoor.BDS/Mokes.iycyt
DrWebTrojan.DownLoader34.49647
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Mal/EncPk-APV
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.df40ac59f1022b97
EmsisoftTrojan.GenericKD.43889328 (B)
IkarusTrojan.Win32.Gencbl
GDataTrojan.GenericKD.43889328
WebrootW32.Trojan.Gen
AviraBDS/Mokes.iycyt
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D29DB2B0
ZoneAlarmBackdoor.Win32.Mokes.aknz
MicrosoftTrojan:Win32/Ymacco.AA17
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.C4199611
McAfeeGenericRXMB-KR!DF40AC59F102
MAXmalware (ai score=99)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.SmokeLoader
ESET-NOD32Win32/TrojanDownloader.Zurgop.DA
TrendMicro-HouseCallTROJ_FRS.0NA103IP20
RisingTrojan.Bunitu!8.109AF (TFE:2:GHjEnFJNmFO)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/GenCBL.AS!tr
BitDefenderThetaGen:NN.ZexaF.34254.5u1@aW1bZ4bi
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Mokes.aknz?

Backdoor.Win32.Mokes.aknz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment