Backdoor

Should I remove “Backdoor.Win32.Mokes.altj”?

Malware Removal

The Backdoor.Win32.Mokes.altj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.altj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.altj?


File Info:

crc32: FA25CCA1
md5: 46d9acdcee25221b114c377c3c14548a
name: 46D9ACDCEE25221B114C377C3C14548A.mlw
sha1: c0cb626ac431801b9c484e3cf24832db821719b1
sha256: 2c3450fee007329326bb9d129935ce1dfa62a94bf53717ff909b96dc6e435696
sha512: af11d648544e259ac42fb0d4ca238f1b212c32faf7671d6a04503f890494929073da6c2135d1a8511cc44b713231beb61915755eb126ef1d1df2a4867efdd4bf
ssdeep: 3072:Fto+x0iX50VbllCuyTZlrSBPE1JxNH783ej8sxV1oWeOkZcy2:3o+xd3/lrhDxC3o1DCWeOsc
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.altj also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45330330
FireEyeGeneric.mg.46d9acdcee25221b
McAfeeGenericRXAA-AA!46D9ACDCEE25
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575a811 )
BitDefenderTrojan.GenericKD.45330330
K7GWTrojan ( 00575a811 )
Cybereasonmalicious.cee252
BitDefenderThetaGen:NN.ZexaF.34742.omKfaatTN@pG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.altj
AlibabaBackdoor:Win32/Mokes.05f863a6
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
Ad-AwareTrojan.GenericKD.45330330
SophosMal/Generic-S
F-SecureTrojan.TR/AD.SmokeLoader.amqdm
TrendMicroTROJ_GEN.R011C0DA721
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
EmsisoftTrojan.GenericKD.45330330 (B)
IkarusTrojan.Win32.Crypt
AviraTR/AD.SmokeLoader.amqdm
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3AF9A
ZoneAlarmBackdoor.Win32.Mokes.altj
GDataWin32.Trojan.Agent.RA87IO
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
VBA32BScope.Trojan.Caynamer
ALYacTrojan.GenericKD.45330330
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HING
TrendMicro-HouseCallTROJ_GEN.R011C0DA721
TencentWin32.Backdoor.Mokes.Pezx
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.61FA.Malware.Gen

How to remove Backdoor.Win32.Mokes.altj?

Backdoor.Win32.Mokes.altj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment