Backdoor

Backdoor.Win32.Mokes.alou removal instruction

Malware Removal

The Backdoor.Win32.Mokes.alou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alou virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.alou?


File Info:

crc32: 77185C75
md5: 594016a7828f1651bf20c7f6234bec7d
name: 594016A7828F1651BF20C7F6234BEC7D.mlw
sha1: d773c00da75dcfaf1c8fef67d854060f3c9500b6
sha256: a9cf3571b7ee4fd79d8c61c2b1d3add6528ef123513496a0a219fd2bb1afdf84
sha512: 5e933e76250b9ab9535911b04910ef074f203eb55bcc1beff6803d8b17a681d2e73f5f9ce216864dfdb3156fe861cfee084d646380dacadbecc8931fd19c4429
ssdeep: 6144:A6ciqUyaILJhHxyG8G2AacP4oacfdL6gBoKu0ce:ijU/IL0vGbPHdLjC50c
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.5
TranslationUsa: 0x0273 0x04d3

Backdoor.Win32.Mokes.alou also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45256554
FireEyeGeneric.mg.594016a7828f1651
McAfeeArtemis!594016A7828F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057576e1 )
BitDefenderTrojan.GenericKD.45256554
K7GWTrojan ( 0057576e1 )
Cybereasonmalicious.da75dc
BitDefenderThetaGen:NN.ZexaF.34700.omKfaiseauoG
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.alou
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.45256554
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
EmsisoftTrojan.GenericKD.45256554 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Generic.D2B28F6A
ZoneAlarmBackdoor.Win32.Mokes.alou
GDataTrojan.GenericKD.45256554
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361497
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIMH
IkarusWorm.Win32.Peerfrag
eGambitUnsafe.AI_Score_52%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.4B63.Malware.Gen

How to remove Backdoor.Win32.Mokes.alou?

Backdoor.Win32.Mokes.alou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment