Backdoor

How to remove “Backdoor.Win32.Mokes.alsb”?

Malware Removal

The Backdoor.Win32.Mokes.alsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alsb virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alsb?


File Info:

crc32: 12B7E2B1
md5: fc8ef49490488b97ad48a952c50fb752
name: FC8EF49490488B97AD48A952C50FB752.mlw
sha1: 4821f3a92f5b00bbb376a3e89351bfbb78f7ccd6
sha256: 9e42dbe47511f26007fbbd7f12559da56dfd6753a2859eff7535dc960605e6cb
sha512: 42a6a9eca189bb8cbea3e59e5cbb94534f25c27db17c66f5ab728be3de5a55de7727f71e86a5dfe56e3beec236293c78fbdac335d25d48fb187af56c5f014898
ssdeep: 6144:XVwil5Gr9QuvQHTLCdp0aEe8x8n6kC9Us:1YxQzLCnJRyP5Ss
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.alsb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45308237
FireEyeGeneric.mg.fc8ef49490488b97
Qihoo-360Generic/HEUR/QVM11.1.58FB.Malware.Gen
McAfeeArtemis!FC8EF4949048
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Mokes.f37cad68
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.490488
BitDefenderThetaGen:NN.ZexaF.34742.omKfaKm3lkfG
CyrenW32/Trojan.NDVJ-1465
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alsb
BitDefenderTrojan.GenericKD.45308237
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Mokes.Efus
Ad-AwareTrojan.GenericKD.45308237
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.qmfdc
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
EmsisoftTrojan.GenericKD.45308237 (B)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.qmfdc
MicrosoftTrojan:Win32/Ymacco.AB97
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3594D
AegisLabTrojan.Win32.Mokes.m!c
ZoneAlarmBackdoor.Win32.Mokes.alsb
GDataTrojan.GenericKD.45308237
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R361936
Acronissuspicious
VBA32Trojan.Glupteba
ALYacTrojan.GenericKD.45308237
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIMY
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
RisingTrojan.Kryptik!8.8 (TFE:5:beSYtboWWOS)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_84%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Mokes.alsb?

Backdoor.Win32.Mokes.alsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment