Backdoor

How to remove “Backdoor.Win32.Mokes.alpj”?

Malware Removal

The Backdoor.Win32.Mokes.alpj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alpj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alpj?


File Info:

crc32: A2A5CDFF
md5: 15c65398dd952e2889fbe4bb95fd739e
name: 15C65398DD952E2889FBE4BB95FD739E.mlw
sha1: 47bb2a658e3a69077084294e8d26efeee849338a
sha256: 8a82cafff36efaf3a32b9ed94a075049d509075a0436a2e85f39926530ef3743
sha512: b92520f140ce80d6e41dbf7520532935c3f2b90ab8fda5f144e0d6e494b8b1b9a9ccf00177e9f3ca8b1028547a2df92e35984bf88462795859bf06325b71ea34
ssdeep: 3072:tINxpfighe07Sisv7etls4HY9XT2fnxDCj7FVE4C:61bheysjMK449D60dC/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.2
TranslationUsa: 0x0273 0x04d3

Backdoor.Win32.Mokes.alpj also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45263404
FireEyeGeneric.mg.15c65398dd952e28
ALYacTrojan.GenericKD.45263404
MalwarebytesTrojan.MalPack.GS
SangforMalware
K7AntiVirusTrojan ( 005758321 )
BitDefenderTrojan.GenericKD.45263404
K7GWTrojan ( 005758321 )
Cybereasonmalicious.58e3a6
CyrenW32/Kryptik.CUR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Mokes.alpj
AlibabaBackdoor:Win32/Mokes.9a820e4b
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.45263404
SophosMal/Generic-S
F-SecureTrojan.TR/AD.SmokeLoader.otiki
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
EmsisoftTrojan.GenericKD.45263404 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.SmokeLoader.otiki
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Generic.D2B2AA2C
ZoneAlarmBackdoor.Win32.Mokes.alpj
GDataTrojan.GenericKD.45263404
McAfeeGenericRXAA-AA!15C65398DD95
ESET-NOD32a variant of Win32/Kryptik.HIMI
TencentWin32.Trojan.Inject.Auto
MAXmalware (ai score=83)
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34700.mmKfaih@cfhG
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/HEUR/QVM11.1.496D.Malware.Gen

How to remove Backdoor.Win32.Mokes.alpj?

Backdoor.Win32.Mokes.alpj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment