Backdoor

Backdoor.Win32.Mokes.aloz malicious file

Malware Removal

The Backdoor.Win32.Mokes.aloz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.aloz virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.aloz?


File Info:

crc32: 72017330
md5: 8a9f67c8303c798df9794abbc60b558b
name: 8A9F67C8303C798DF9794ABBC60B558B.mlw
sha1: d5e1e4baf443e976df671042d05cbd17eb74f492
sha256: b1c525b12a46c0db21ea82a0689b7a6103a4f46fbc159441beee0d7dac8e62db
sha512: e66a85483cab76d59a4396ba4e3b663f0390a941f762b5a2df7e1a54e079f89e5a51a96b541ff64ae91940221f1e2e5c2b12749e8e150424ab2fdd53e46b3992
ssdeep: 6144:btbB/Q9rbkZ2W6E58EF5tcKOuXEgidOX:bnU8Z2yLteuXEiX
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.2
TranslationUsa: 0x0273 0x04d3

Backdoor.Win32.Mokes.aloz also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35939406
FireEyeGeneric.mg.8a9f67c8303c798d
CylanceUnsafe
BitDefenderTrojan.GenericKD.35939406
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.CUR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.aloz
Ad-AwareTrojan.GenericKD.35939406
EmsisoftTrojan.GenericKD.35939406 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Generic.D224644E
ZoneAlarmBackdoor.Win32.Mokes.aloz
GDataWin32.Trojan-Downloader.SmokeLoader.7FSGDN
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R361523
McAfeeGenericRXAA-AA!8A9F67C8303C
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/GenKryptik.EZHW
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34700.mmKfaK2ATfiG
AVGFileRepMetagen [Malware]
AvastWin32:DropperX-gen [Drp]
Qihoo-360HEUR/QVM11.1.4B63.Malware.Gen

How to remove Backdoor.Win32.Mokes.aloz?

Backdoor.Win32.Mokes.aloz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment