Backdoor

Backdoor.Win32.Mokes.alqi removal guide

Malware Removal

The Backdoor.Win32.Mokes.alqi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alqi virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alqi?


File Info:

crc32: 7130A218
md5: 2e1c57fcc703660720120c5e984b416b
name: 2E1C57FCC703660720120C5E984B416B.mlw
sha1: ed30f8b5a4e4117904a134886207759b50d52c05
sha256: 4694ea3ba8f2b5b3144b8e417622d568fa53e39f0ad694a2c1432fad5147a1d6
sha512: d0978d2e4f3cf45a38f3916ce0db7166ca0addee2ed2b977a3caa39071af1615b087729f1165bb7939da6f8a12b77e393f2776b2a872f841dfe5b82aa08bf75f
ssdeep: 3072:xVjloNDj1wA/vsh9I/1v/ZYiEmOA5EFDznd1vB1KrhEvucojzHfL4Ks:/jloNDZwx9I/1BYL1lNrdlKrSvj8/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.5
TranslationUsa: 0x0273 0x04d3

Backdoor.Win32.Mokes.alqi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45267995
FireEyeGeneric.mg.2e1c57fcc7036607
ALYacTrojan.GenericKD.45267995
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005758251 )
BitDefenderTrojan.GenericKD.45267995
K7GWTrojan ( 005758251 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.34700.omKfayKRfObG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alqi
AlibabaBackdoor:Win32/Mokes.4d9600c0
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Backdoor.Mokes.Hrpk
Ad-AwareTrojan.GenericKD.45267995
SophosMal/Generic-S
F-SecureTrojan.TR/AD.SmokeLoader.ibtgs
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
EmsisoftTrojan.GenericKD.45267995 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.SmokeLoader.ibtgs
MicrosoftTrojan:Win32/Glupteba.NV!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B2BC1B
ZoneAlarmBackdoor.Win32.Mokes.alqi
GDataTrojan.GenericKD.45267995
CynetMalicious (score: 100)
McAfeeArtemis!2E1C57FCC703
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIML
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.HIFA!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/HEUR/QVM11.1.4BDB.Malware.Gen

How to remove Backdoor.Win32.Mokes.alqi?

Backdoor.Win32.Mokes.alqi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment