Backdoor

Backdoor.Win32.Mokes.altp removal instruction

Malware Removal

The Backdoor.Win32.Mokes.altp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.altp virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.altp?


File Info:

crc32: 8F6B31D0
md5: 25a782e480346d7011a69529c9f92495
name: 25A782E480346D7011A69529C9F92495.mlw
sha1: 8afa48c01ea878f5cf9c94dd0f1abc34c37afe9f
sha256: 26ce825ee5672ac0298a367634425f74edcd3d27fb114077218930321d2067bc
sha512: c8ea920b8da89ece8b4fd6418710e312cff67c4384b2fcb22eb01cf51af2f38e53d2c0af10f177e301983a8d6e4ef5e95de63452c329180224b6c320d24950bd
ssdeep: 3072:WIQhEBvzCrQh4e2gWRqMkVVlK+iGgpHCA1/xTFYOp/g6:IEp+kz2gWZKfz8HCA1/xFYO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.altp also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35999951
ALYacTrojan.GenericKD.35999951
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35999951
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.480346
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.altp
AlibabaBackdoor:Win32/Mokes.ded92384
ViRobotTrojan.Win32.Z.Malpack.236032
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Backdoor.Mokes.Hrpf
Ad-AwareTrojan.GenericKD.35999951
EmsisoftTrojan.GenericKD.35999951 (B)
F-SecureTrojan.TR/AD.SmokeLoader.tfcgn
DrWebTrojan.Siggen11.57437
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.25a782e480346d70
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.SmokeLoader.tfcgn
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan[Backdoor]/Win32.Mokes
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22550CF
ZoneAlarmBackdoor.Win32.Mokes.altp
GDataTrojan.GenericKD.35999951
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=84)
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HINO
RisingTrojan.Kryptik!8.8 (TFE:5:M4loB2xS0kQ)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfaSqzrJaG
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.32c

How to remove Backdoor.Win32.Mokes.altp?

Backdoor.Win32.Mokes.altp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment