Adware

Win32/Adware.MoKeAD removal

Malware Removal

The Win32/Adware.MoKeAD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.MoKeAD virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/Adware.MoKeAD?


File Info:

name: 4EDCB852DDF10219D682.mlw
path: /opt/CAPEv2/storage/binaries/efbf72c6cb159777c5759b3eff67acb1ce9e4832774073b39da8001e4b13a1d2
crc32: A98DF06C
md5: 4edcb852ddf10219d6827d985115b2b5
sha1: b4720e3df6d85efb4973f0df3d84726ebe14f8ee
sha256: efbf72c6cb159777c5759b3eff67acb1ce9e4832774073b39da8001e4b13a1d2
sha512: c2b4aa134c461e9fe29d2ebdae2a6011d87b46e4acad6fcd1b6fc9158a4fbd089569203cba2b41cb2418a26fed2a17c2c7c47cd051c388fb6ffc888a3cb80618
ssdeep: 6144:XME1nmg1tDbJ5621YN/Eff7eAGWAKM/qwOAWfmAbF9SzV3hKUb0wR+679dRNeStZ:8gnJDzNC/+lf1oL42+mR0Sdio
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100841202F78545F3D8401B70885C9B62E23DFF961BB4629BD7A7AE6C3C18342B61B875
sha3_384: 692ba6c8abeae043f7391c540ca6280e5eb7e1869e663241109e012fa0a2567238bb15eb32c3897d0b765b347c047059
ep_bytes: e89b27000050e8a72201000000000090
timestamp: 2005-10-07 09:05:22

Version Info:

0: [No Data]

Win32/Adware.MoKeAD also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.1327544
ClamAVWin.Malware.Daekom-9941342-0
FireEyeTrojan.Generic.1327544
CAT-QuickHealTrojan.Delf.10130
ALYacTrojan.Generic.1327544
MalwarebytesMalware.AI.3569221200
VIPRETrojan.Generic.1327544
K7AntiVirusAdware ( 004bf9361 )
K7GWAdware ( 004bf9361 )
Cybereasonmalicious.2ddf10
BitDefenderThetaAI:Packer.E1C60DC219
SymantecTrojan.Daekom
ESET-NOD32a variant of Win32/Adware.MoKeAD
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Agent.isjn
BitDefenderTrojan.Generic.1327544
NANO-AntivirusRiskware.Win32.Agent.dwkkhl
AvastWin32:Agent-ABKI [Trj]
RisingTrojan.Agent!1.66CB (CLASSIC)
Ad-AwareTrojan.Generic.1327544
EmsisoftTrojan.Generic.1327544 (B)
ComodoMalware@#380xyw6ojjnyx
F-SecureHeuristic.HEUR/AGEN.1214049
DrWebAdware.Mokead.1086
ZillyaAdware.Agent.Win32.3831
McAfee-GW-Editiongeneric!bg.ic
SophosMal/Generic-R + Mal/Behav-055
IkarusTrojan.Win32.Daekom
AviraHEUR/AGEN.1214049
Antiy-AVLTrojan/Generic.ASMalwS.2D
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.1327544
GoogleDetected
McAfeegeneric!bg.ic
MAXmalware (ai score=80)
VBA32BScope.Trojan.Keyloggerger
CylanceUnsafe
SentinelOneStatic AI – Malicious SFX
AVGWin32:Agent-ABKI [Trj]

How to remove Win32/Adware.MoKeAD?

Win32/Adware.MoKeAD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment