Trojan

What is “Trojan:Win32/Mokes!pz”?

Malware Removal

The Trojan:Win32/Mokes!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Mokes!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Mokes!pz?


File Info:

name: 09DE75BADEEF9B8A8623.mlw
path: /opt/CAPEv2/storage/binaries/2eb58e6f2812672db2f7378a661764be7be78b9375af7875ec86e7b3f3050e10
crc32: E6C0BEC6
md5: 09de75badeef9b8a8623c5e1d4ddb0f7
sha1: fdf6de224ef42fba05980c2ea770179ef95450ba
sha256: 2eb58e6f2812672db2f7378a661764be7be78b9375af7875ec86e7b3f3050e10
sha512: edec36c69771f10df2b8286393c8fb44be68d7ccc9846a8f1133645069d825f603a6a8d22814b3842735178e58238e566296f55e0adfde442fa666bdd43994cd
ssdeep: 24576:XxY5gDVim9LMzcV3T6gH/A2Rs6a9DhvhZvTCg+ACVGg:RDVim9LMz4j6SA+s6a3vjJgGg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163852D1136F94B59F9F34FB85ABAA6118A7AFC69DF11C2DF1251608E0C21BD08970B37
sha3_384: dcfc1f79ea60a955ec4f32efa5fc1fb397affab442ac1c2080a73383d6be3b4aa7bb6443b8de5eecec9db1dafeb427c8
ep_bytes: e938540400e962c80500e9992f0100e9
timestamp: 2023-10-05 21:45:24

Version Info:

0: [No Data]

Trojan:Win32/Mokes!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
SkyhighBehavesLike.Win32.Generic.tm
McAfeeGenericRXAA-AA!09DE75BADEEF
MalwarebytesSpyware.Stealer
VIPRETrojan.GenericKDZ.103150
SangforInfostealer.Win32.Kryptik.Vjfc
K7AntiVirusTrojan ( 005aa0d91 )
BitDefenderTrojan.GenericKDZ.103150
K7GWTrojan ( 005aa0d91 )
VirITTrojan.Win32.GenusT.DSNG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUXB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/Redline.06212556
NANO-AntivirusTrojan.Win32.GenKryptik.kbtmcs
MicroWorld-eScanTrojan.GenericKDZ.103150
RisingStealer.Stealerc!8.17BE0 (TFE:5:TwFUetDGxcV)
SophosTroj/Krypt-ACG
F-SecureTrojan.TR/AD.Nekark.bdnnf
DrWebTrojan.Inject4.61887
ZillyaTrojan.Stealer.Win32.157227
TrendMicroTROJ_GEN.R002C0DJB23
FireEyeTrojan.GenericKDZ.103150
EmsisoftTrojan.GenericKDZ.103150 (B)
IkarusTrojan.Win32.Krypt
JiangminTrojan.PSW.Stealerc.iv
GoogleDetected
AviraTR/AD.Nekark.bdnnf
Antiy-AVLTrojan/Win32.GenKryptik.gmvp
MicrosoftTrojan:Win32/Mokes!pz
ArcabitTrojan.Generic.D192EE
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.P9BJ4C
VaristW32/Agent.HIE.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5500981
VBA32TrojanPSW.Mystic
ALYacTrojan.GenericKDZ.103150
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJB23
TencentMalware.Win32.Gencirc.13f16fc9
YandexTrojan.Kryptik!0tYKGI/SR+o
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Injector.ETFD!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Mokes!pz?

Trojan:Win32/Mokes!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment