Backdoor

What is “Backdoor.Win32.Mokes.alrg”?

Malware Removal

The Backdoor.Win32.Mokes.alrg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alrg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.alrg?


File Info:

crc32: 6AC4A973
md5: abbcb208e3200a3e8a763bffde664d85
name: ABBCB208E3200A3E8A763BFFDE664D85.mlw
sha1: c172d001eb0ec60306b9f9b93096e8f96e7b7acb
sha256: 9a0f639f8cfcc4f36451b50d0b0a2052f73ad05f35c874e0213cf6fcd1977c3b
sha512: 94ca10fa7dda1397632ca418dec99acce58dad6c8accf5c399c472e3879a8e7ce68c62ca87fc6f9efb3c7f6437abe6b9114dfd5023d4c6db659391d60a59cb3b
ssdeep: 3072:V3OE17/8zv27Ccdk2DhzgRkw+viDaPsWGK+hqRZGUjrhblH32QjfHfyTT:Vp17/RecaShzgR7WB+UbRZHf4
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafuck
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x04d6

Backdoor.Win32.Mokes.alrg also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45290944
FireEyeGeneric.mg.abbcb208e3200a3e
Qihoo-360Generic/HEUR/QVM11.1.521F.Malware.Gen
McAfeeRDN/GenericM
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005758d81 )
BitDefenderTrojan.GenericKD.45290944
K7GWTrojan ( 005758d81 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34742.nmKfaOLgAHoG
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R067C0DA521
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alrg
AlibabaBackdoor:Win32/Mokes.baf82ce4
ViRobotTrojan.Win32.Z.Malpack.227328.A
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.45290944
EmsisoftTrojan.GenericKD.45290944 (B)
F-SecureTrojan.TR/Crypt.Agent.hvsum
TrendMicroTROJ_GEN.R067C0DA521
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan-Downloader.SmokeLoader.BCC7NO
AviraTR/Crypt.Agent.hvsum
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B315C0
ZoneAlarmBackdoor.Win32.Mokes.alrg
MicrosoftTrojan:Win32/Azorult.FW!MTB
CynetMalicious (score: 100)
VBA32Trojan.Azorult
ALYacTrojan.GenericKD.45290944
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIMQ
TencentWin32.Trojan.Inject.Auto
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/GenKryptik.DQNE!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.8e3200
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor.Win32.Mokes.alrg?

Backdoor.Win32.Mokes.alrg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment