Trojan

How to remove “Trojan:Win32/Mokes.AARM!MTB”?

Malware Removal

The Trojan:Win32/Mokes.AARM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Mokes.AARM!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Mokes.AARM!MTB?


File Info:

name: EF346D1A66C9D43FEF05.mlw
path: /opt/CAPEv2/storage/binaries/8a7b76bbaef20aea58410979ab3531e65981de5f895dad0196b91b203a32a50a
crc32: 11A7C73A
md5: ef346d1a66c9d43fef053dc61fb39be1
sha1: d6552f2d56f1f36db17232bf613474b0ad77344a
sha256: 8a7b76bbaef20aea58410979ab3531e65981de5f895dad0196b91b203a32a50a
sha512: ff7f8195a9ddab0896900e9d88ffe94ded3b66064e24f1b99dfbcd937109598b4b9b87535fa2ac76242999f1bcc0de2a34e840e1d850e58a4747fe46a99fb174
ssdeep: 24576:suJ4WEBndDjd1Trdv7Dy6a9DhvhVK1PqzJ:QdDjd1V7G6a3va1w
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178850B1177F95B59F6F35EB85ABAA611087AFC69CF11C2DF1251908E0C21BE08970B3B
sha3_384: 0b09188c842194d3b23cd9d520c0703b53856050dfa443a15d3c7e4205c04971aabe38ef46781398170f3a66380b0634
ep_bytes: e9f6740400e928e90500e90f380100e9
timestamp: 2023-10-05 12:46:46

Version Info:

0: [No Data]

Trojan:Win32/Mokes.AARM!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanTrojan.GenericKDZ.103143
FireEyeTrojan.GenericKDZ.103143
SkyhighBehavesLike.Win32.Generic.tm
ALYacTrojan.GenericKDZ.103143
MalwarebytesSpyware.Stealer
VIPRETrojan.GenericKDZ.103143
SangforInfostealer.Win32.Agent.Vwaj
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.103143
K7GWTrojan ( 005ac0141 )
K7AntiVirusTrojan ( 005ac0141 )
VirITTrojan.Win32.GenusT.DSME
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUXB
APEXMalicious
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/Mokes.2bb1442f
NANO-AntivirusTrojan.Win32.Stealer.kbsfig
RisingStealer.Agent!8.C2 (TFE:5:w5ri9hSEXLB)
SophosTroj/Krypt-ACG
F-SecureTrojan.TR/AD.Nekark.gjeds
DrWebTrojan.Inject4.61810
ZillyaTrojan.Stealer.Win32.157291
TrendMicroTROJ_GEN.R002C0DJ523
EmsisoftTrojan.GenericKDZ.103143 (B)
MAXmalware (ai score=88)
JiangminTrojanSpy.Stealer.aiyj
GoogleDetected
AviraTR/AD.Nekark.gjeds
VaristW32/Agent.HIE.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik.gmvp
KingsoftWin32.Trojan-Spy.Stealer.gen
MicrosoftTrojan:Win32/Mokes.AARM!MTB
ArcabitTrojan.Generic.D192E7
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.17I3472
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWSX-gen.R609369
McAfeeGenericRXAA-AA!EF346D1A66C9
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.RedLine
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJ523
TencentTrojan.Win32.GenKryptik.kq
YandexTrojan.GenKryptik!KtlaQYoMnV0
IkarusTrojan.Win32.Redline
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Injector.ETFD!tr
BitDefenderThetaGen:NN.ZexaE.36792.WDW@aCIivCc
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Mokes.AARM!MTB?

Trojan:Win32/Mokes.AARM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment