Backdoor

What is “Backdoor.Mokes”?

Malware Removal

The Backdoor.Mokes is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Mokes virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Mokes?


File Info:

crc32: 68251A0A
md5: 2d2a72236628870121ae36241664026c
name: elin2.exe
sha1: 5f58b6cf926e9f42bca6199a60ad7af77ef5c362
sha256: 379f030e2b2ecadaa9e549e4d35d0999ded8b6c6f70fbfe055a0ed36dd6a6560
sha512: a44d8772b0baffd0bbea9ecb7a2542fd7328b873fb512be6479f5dd77ac102db0441c47202432af722e5566e6170f20f3616e8265cb1868b113ba8401acc0818
ssdeep: 6144:ELZJBxJFY33WBeXo8EWCeN509JA7PdIYh5MP:OzFY3mcXoxHeN4Gz5K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: SCBDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: SCBDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: SCBDemo MFC Application
OriginalFilename: SCBDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Mokes also known as:

DrWebTrojan.MulDrop11.24157
MicroWorld-eScanTrojan.GenericKD.32617409
FireEyeGeneric.mg.2d2a722366288701
CAT-QuickHealBackdoor.Mokes
ALYacBackdoor.Mokes.gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Mokes.m!c
SangforMalware
K7AntiVirusTrojan ( 0055a0701 )
BitDefenderTrojan.GenericKD.32617409
K7GWTrojan ( 0055a0701 )
Cybereasonmalicious.f926e9
TrendMicroTROJ_FRS.VSNTJL19
BitDefenderThetaGen:NN.ZexaF.33550.Cq3@amfKRhgi
F-ProtW32/Agent.BHZ.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_FRS.VSNTJL19
AvastWin32:PWSX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.ahbf
AlibabaBackdoor:Win32/Mokes.4e069579
NANO-AntivirusTrojan.Win32.Mokes.geiwzb
Ad-AwareTrojan.GenericKD.32617409
SophosMal/Generic-S
ComodoMalware@#3t3bxna48a2i8
F-SecureTrojan.TR/Kryptik.hgnia
ZillyaTrojan.Azorult.Win32.4
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gh
FortinetW32/Mokes.AHBF!tr.bdr
EmsisoftTrojan.GenericKD.32617409 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.YURO-0489
JiangminTrojan.Banker.Danabot.bje
WebrootW32.Trojan.Gen
AviraTR/Kryptik.hgnia
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Mokes
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F1B3C1
ZoneAlarmBackdoor.Win32.Mokes.ahbf
MicrosoftTrojanDownloader:Win32/Dofoil.AD
AhnLab-V3Trojan/Win32.Coinstealer.C3525369
Acronissuspicious
McAfeeRDN/Generic Downloader.x
TACHYONBackdoor/W32.Mokes.460312
VBA32Backdoor.Mokes
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.GXNC
YandexTrojan.PWS.Racealer!
SentinelOneDFI – Malicious PE
GDataTrojan.GenericKD.32617409
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.db9

How to remove Backdoor.Mokes?

Backdoor.Mokes removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment