Backdoor

Backdoor.Win32.Mokes.altf removal

Malware Removal

The Backdoor.Win32.Mokes.altf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.altf virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.altf?


File Info:

crc32: 52F7B5BB
md5: 288f967dc35facd55907c31de8c5052f
name: 288F967DC35FACD55907C31DE8C5052F.mlw
sha1: df3b79f15c02be59f355dc881c19c8d3d88be48c
sha256: 2843b7c3d7c2d196b15e9b6da7d0782df0ba36a7ec0f9f876eba5d25734997e7
sha512: 9fdf57a301d68b75e7d4978b6ddffbaf37e2dea546217cf1bd7389f3805f76e65a128a839e5f5b21ad3529d5f337906a9dcc2d98113504d423ad9309f66947ea
ssdeep: 3072:3M81DcSzuB8Q79SyaP5POtxwKe/aVwr7iht8JaPk/:aSo979+pX/xrU/Pk/
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.altf also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35997214
FireEyeGeneric.mg.288f967dc35facd5
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575a811 )
BitDefenderTrojan.GenericKD.35997214
K7GWTrojan ( 00575a811 )
Cybereasonmalicious.dc35fa
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.altf
AlibabaBackdoor:Win32/Mokes.de042c41
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Backdoor.Mokes.Hrzj
Ad-AwareTrojan.GenericKD.35997214
EmsisoftTrojan.GenericKD.35997214 (B)
F-SecureTrojan.TR/AD.SmokeLoader.pyvow
TrendMicroTROJ_GEN.R023C0DA721
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.SmokeLoader.pyvow
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225461E
ZoneAlarmBackdoor.Win32.Mokes.altf
GDataTrojan.GenericKD.35997214
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.omKfaGAqIgaG
ALYacTrojan.GenericKD.35997214
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HING
TrendMicro-HouseCallTROJ_GEN.R023C0DA721
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.6149.Malware.Gen

How to remove Backdoor.Win32.Mokes.altf?

Backdoor.Win32.Mokes.altf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment