Backdoor

Backdoor.Win32.Mokes.altq removal guide

Malware Removal

The Backdoor.Win32.Mokes.altq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.altq virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.altq?


File Info:

crc32: 6239EBDB
md5: 78aa631abe3547a95b5e4e666a6d1d7c
name: 78AA631ABE3547A95B5E4E666A6D1D7C.mlw
sha1: 6f4a06d5345c2f997e34bcab5222e9fc6df86064
sha256: 664298e94e8473fda5e1d6846b53f69229784e90c15f77629fbc5b3fde715938
sha512: fa069078330f97d65da1d4eb0fe943805c8c8822ed8d7ad2732b60b9d2674c5fae80c2a37abbd5fe0acfde5970c4ef28c597f2cc576d4ff180c3dfd9d09e2054
ssdeep: 3072:MwtcgVsGuUvlmPiyjFUS9v9gfHnUfuZFhJUq4YuKJ898kNCa9f:Mw1ruElmKWFP9v9guuVJ3zuKvkNJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Backdoor.Win32.Mokes.altq also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45331805
FireEyeGeneric.mg.78aa631abe3547a9
ALYacTrojan.GenericKD.45331805
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45331805
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.abe354
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.altq
AlibabaBackdoor:Win32/Mokes.9e5bfc19
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
Ad-AwareTrojan.GenericKD.45331805
EmsisoftTrojan.GenericKD.45331805 (B)
ComodoMalware@#2vxzaz5o0oy13
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
AviraTR/Crypt.Agent.ywrnp
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3B55D
ZoneAlarmBackdoor.Win32.Mokes.altq
GDataTrojan.GenericKD.45331805
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeRDN/GenericM
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HINO
TencentWin32.Backdoor.Mokes.Ajly
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfaConVqoG
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.PWS.d75

How to remove Backdoor.Win32.Mokes.altq?

Backdoor.Win32.Mokes.altq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment