Trojan

Trojan:Win32/Mokes.MA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Mokes.MA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Mokes.MA!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Performs some HTTP requests
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
t.gogamec.com
apps.identrust.com

How to determine Trojan:Win32/Mokes.MA!MTB?


File Info:

crc32: 8EBCAA29
md5: 31b60c806a072a224cadf2c9ac462925
name: 31B60C806A072A224CADF2C9AC462925.mlw
sha1: 95bc16b37c1fa02ed6b7bceb68d10191615134cf
sha256: 6ec12336693703701b3dcba2c3fab2d0bbfd1ea6cd0924e3dc3c41c1a214b79c
sha512: 271859dc12f528555973d9d59260e7b2f3b80e1a21ca6b9c95d706ed5f4cbbbdd51d8edc558efa10d3c39311e44fd5ed23edffe3df8153fd3bdd77a8bae66b28
ssdeep: 768:bTqFuprJlHnvGeURxaBl74SOK5nGekDEThgH8XwkP7h/m8HszrlaO9OgB3t3P9U:/qI5zn0xaBiSOKhsMgcgkN/m8H7Ot3FU
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Mokes.MA!MTB also known as:

K7AntiVirusTrojan-Downloader ( 0058a4761 )
DrWebTrojan.DownLoader43.63052
CynetMalicious (score: 99)
ALYacGen:Variant.Mikey.130488
K7GWTrojan-Downloader ( 0058a4761 )
ESET-NOD32a variant of Win32/TrojanDownloader.Agent_AGen.G
AvastWin32:MalwareX-gen [Trj]
KasperskyBackdoor.MSIL.Mokes.bi
BitDefenderGen:Variant.Midie.103566
MicroWorld-eScanGen:Variant.Midie.103566
Ad-AwareGen:Variant.Midie.103566
FireEyeGen:Variant.Midie.103566
EmsisoftGen:Variant.Midie.103566 (B)
JiangminBackdoor.Mokes.erv
WebrootW32.Malware.Gen
AviraTR/Redcap.yghdt
Antiy-AVLTrojan/Generic.ASMalwS.34CD6A4
MicrosoftTrojan:Win32/Mokes.MA!MTB
GDataGen:Variant.Midie.103566
AhnLab-V3Trojan/Win.Generic.C4769340
MAXmalware (ai score=89)
VBA32Trojan.Sabsik.FL
MalwarebytesRiskWare.Downloader
PandaTrj/GdSda.A
YandexBackdoor.Mokes!G8J56GJQ+IM
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Mokes.MA!MTB?

Trojan:Win32/Mokes.MA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment