Backdoor

Backdoor.Win32.Mokes.alth removal instruction

Malware Removal

The Backdoor.Win32.Mokes.alth is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alth virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alth?


File Info:

crc32: 58700D82
md5: 820340c7d36d2e69fdc322599e99c1fe
name: 820340C7D36D2E69FDC322599E99C1FE.mlw
sha1: 5dedbc164c97d6609337985f6d23ec372afbb6f7
sha256: 159286f7c57ccbd7278a8edb69875ee9ba774674fd1e3738addf1215cd71f4ce
sha512: e8d086bba17b2d3ae6b8a9f421ef8700f8ae883532b0d8ea92edc6da937208a4080d49746b11d67061d71782368b1d1615bf5b4c11ce44e979ba6ee750f73a1d
ssdeep: 3072:uVmRDRoxmy2PAS2FDL9goa/MBicu0vcDdItLN91:uVKEN2PAS2Zlwf0va01
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.alth also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45329513
FireEyeGeneric.mg.820340c7d36d2e69
ALYacTrojan.GenericKD.45329513
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575a811 )
BitDefenderTrojan.GenericKD.45329513
K7GWTrojan ( 00575a811 )
Cybereasonmalicious.7d36d2
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alth
AlibabaBackdoor:Win32/Mokes.f023ef72
Ad-AwareTrojan.GenericKD.45329513
EmsisoftTrojan.GenericKD.45329513 (B)
TrendMicroTROJ_GEN.R023C0DA721
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Glupteba
AviraTR/Crypt.Agent.jbbgb
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3AC69
ZoneAlarmBackdoor.Win32.Mokes.alth
GDataTrojan.GenericKD.45329513
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeGenericRXAA-AA!820340C7D36D
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HING
TrendMicro-HouseCallTROJ_GEN.R023C0DA721
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfaOOPeAhG
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.61FA.Malware.Gen

How to remove Backdoor.Win32.Mokes.alth?

Backdoor.Win32.Mokes.alth removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment