Trojan

About “Trojan:Win32/Mokes.MAK!MTB” infection

Malware Removal

The Trojan:Win32/Mokes.MAK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Mokes.MAK!MTB virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Arabic (Algeria)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan:Win32/Mokes.MAK!MTB?


File Info:

crc32: CF4F894A
md5: 1394542595cc3afdd902b92b366858ef
name: 1394542595CC3AFDD902B92B366858EF.mlw
sha1: a81e431a36944dee3910de34168656475231d39f
sha256: 57cf3dd6af6d1b8e03c82a3d7eb2b1a94908015e03ae38d9c9f1f6090d1c012b
sha512: c1250631def74f6f6857913089050e7bd36b350ce90a86abc746bf918d87c744f545b8d2c8378ae736993194c58cb7031292a9aabc96b86ff126399c7edb7abe
ssdeep: 24576:Z8Z7t+w4sdXQbNliG7umLW7pLgD/uBgaH:4+wCb/tGaE5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sigzmeogeke.ewi
ProductVersion: 29.21.22.113
Copyright: Copyrighz (C) 2021, fodkageta
Translation: 0x0182 0x0102

Trojan:Win32/Mokes.MAK!MTB also known as:

K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37415555
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Generic.00930a76
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EUY.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HMCH
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Jaik-9886409-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.GenericKD.37415555
MicroWorld-eScanTrojan.GenericKD.37415555
TencentWin32.Trojan.Zenpak.Dxmy
Ad-AwareTrojan.GenericKD.37415555
SophosMal/Generic-R
ComodoTrojWare.Win32.Agent.hucby@0
BitDefenderThetaGen:NN.ZexaF.34088.dr0@a85u0XdG
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.1394542595cc3afd
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.wifey
MicrosoftTrojan:Win32/Mokes.MAK!MTB
GridinsoftTrojan.Win32.Packed.vl!heur
ArcabitTrojan.Generic.D23AEA83
GDataTrojan.GenericKD.37415555
AhnLab-V3CoinMiner/Win.Glupteba.R437490
McAfeeArtemis!1394542595CC
MAXmalware (ai score=88)
VBA32BScope.Trojan.Eb
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CHG21
RisingTrojan.Kryptik!1.B40D (CLASSIC)
IkarusTrojan-Downloader.Win32.Zurgop
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMCE!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCTHEA

How to remove Trojan:Win32/Mokes.MAK!MTB?

Trojan:Win32/Mokes.MAK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment