Backdoor

About “Backdoor.MSIL.Mokes.ck” infection

Malware Removal

The Backdoor.MSIL.Mokes.ck is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Mokes.ck virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.Mokes.ck?


File Info:

name: 170EF6E8B8A73C3E42EF.mlw
path: /opt/CAPEv2/storage/binaries/7b6cecfabf1bee2bf8e81a4ca3a9f4358e360817ee1b3b9221999f5c50433136
crc32: CF11CDA7
md5: 170ef6e8b8a73c3e42ef2ce0b5517db9
sha1: b3b6e9e97abb5720ed2e881ea1f5327af3659177
sha256: 7b6cecfabf1bee2bf8e81a4ca3a9f4358e360817ee1b3b9221999f5c50433136
sha512: c407122f196f9bc83b6852e3a77c783531bf8cf0597290441f96f46f19105bc18320fd27af7f19e57c50d4dcc6ffff21350aee6de0d77c2329f5d784ba793f3a
ssdeep: 768:4Ke6r0NVnxxS6vobyOlWUpN3RdO6jVTBR2r/A7izRGUR/lHJ/d2uoe5N1Eyw0trC:b3aV2xblpbOUf2U7Y1P/dfLttr9pS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102C3271276418471F70D0B304946FAE04AAA9D3D5AE4E48FFA7C7E7A29312C31A7725F
sha3_384: 0ac2c971080941d880b60ec2f36923d4f7eec57b3be3c8bfc9ab435a2bb081a1f1734ffb86c467cfb59e87a5a2779b15
ep_bytes: e8952d0000e917feffff558bec81ec28
timestamp: 2021-12-08 02:04:04

Version Info:

0: [No Data]

Backdoor.MSIL.Mokes.ck also known as:

LionicTrojan.MSIL.Mokes.m!c
ClamAVWin.Dropper.Xpiro-9917539-1
FireEyeTrojan.GenericKD.38281419
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.38281419
CylanceUnsafe
ZillyaBackdoor.Mokes.Win32.5082
SangforBackdoor.MSIL.Mokes.ck
K7AntiVirusTrojan-Downloader ( 0058b9041 )
AlibabaBackdoor:MSIL/Mokes.a3650db7
K7GWTrojan-Downloader ( 0058b9041 )
VirITTrojan.Win32.Genus.KZX
CyrenW32/Trojan.CDZM-0865
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.GAA
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.MSIL.Mokes.ck
BitDefenderTrojan.GenericKD.38281419
NANO-AntivirusTrojan.Win32.Mokes.jjdbdt
MicroWorld-eScanTrojan.GenericKD.38281419
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10cf9f4f
Ad-AwareTrojan.GenericKD.38281419
EmsisoftTrojan.GenericKD.38281419 (B)
ComodoTrojWare.Win32.Agent.sscgl@0
DrWebTrojan.Inject4.21632
TrendMicroTROJ_FRS.0NA103LA21
McAfee-GW-EditionGenericRXRD-GZ!170EF6E8B8A7
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Agent
GDataTrojan.GenericKD.38281419
JiangminBackdoor.MSIL.figz
Antiy-AVLTrojan/Generic.ASMalwS.34E9BA7
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
TACHYONBackdoor/W32.Mokes.122880.C
AhnLab-V3Trojan/Win.Generic.R457419
McAfeeGenericRXRD-GZ!170EF6E8B8A7
MAXmalware (ai score=100)
VBA32Trojan.Sabsik.FL
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_FRS.0NA103LA21
YandexBackdoor.Mokes!FoEeaNgazl0
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.10612570.susgen
FortinetPossibleThreat.MU
BitDefenderThetaGen:NN.ZexaF.34114.hqW@aWEXXVaj
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.MSIL.Mokes.ck?

Backdoor.MSIL.Mokes.ck removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment