Backdoor

Should I remove “Backdoor.Win32.Mokes.alpk”?

Malware Removal

The Backdoor.Win32.Mokes.alpk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alpk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alpk?


File Info:

crc32: 4C9790F1
md5: 1bc6701deeb29ed1d50ac791b229ed0b
name: 1BC6701DEEB29ED1D50AC791B229ED0B.mlw
sha1: 91fcb64a2225ef733700faa8571e8e7e5779ffc6
sha256: 97068ecf7211dbf1b375726fb5544ba29ce9b0ed54f9c0a1c548b987b93c7364
sha512: 3ef95dcb1792a393db5530c4f0279ef0cc173448858d274a2de18b5a69de3b27a09e1580a86eb97e209c1a52265ce910c87371ca0e23123d3c13766f46be7db5
ssdeep: 3072:Ovgj5nx20puGmnq+D3EmzcrOGWGOsvDpq2JzlBl:DM0MGmn3wmz4NXOsvr
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.2
TranslationUsa: 0x0273 0x04d3

Backdoor.Win32.Mokes.alpk also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35943356
FireEyeGeneric.mg.1bc6701deeb29ed1
McAfeeGenericRXAA-AA!1BC6701DEEB2
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35943356
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.CUR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyBackdoor.Win32.Mokes.alpk
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.35943356
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
EmsisoftTrojan.GenericKD.35943356 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Azorult.FW!MTB
ArcabitTrojan.Generic.D22473BC
ZoneAlarmBackdoor.Win32.Mokes.alpk
GDataTrojan.GenericKD.35943356
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34700.mmKfaW99DqiG
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIMI
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM11.1.4FD7.Malware.Gen

How to remove Backdoor.Win32.Mokes.alpk?

Backdoor.Win32.Mokes.alpk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment