Backdoor

How to remove “Backdoor.Win32.Mokes.alvi”?

Malware Removal

The Backdoor.Win32.Mokes.alvi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alvi virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Mokes.alvi?


File Info:

crc32: 90968686
md5: 49c42bf2c041fef989305fe5c40ba20f
name: 49C42BF2C041FEF989305FE5C40BA20F.mlw
sha1: 7fb19ec2fb1cb5d6360106e8130f4178fcf3d2fa
sha256: 56e1e2ef8dfaaf84dddc8c6761fca37ea95cdff64fd2960cb0a49d915795eac3
sha512: c98d9d2a214ecd7c1f7c58c67ea965145d4029ce5ae2087c45243d12e2a297ca6c5449d707fc7d57363f066a40517b63f7855e61af36a5d10c5d5004b762df80
ssdeep: 3072:/ORHJWM4tL7zxn3tObtota+8h9v8tKyeB0GjSHzVQvRL/OnZe:0p7oZdOy4hP0GgKvA
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x054e

Backdoor.Win32.Mokes.alvi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45354982
FireEyeGeneric.mg.49c42bf2c041fef9
Qihoo-360Win32/Backdoor.27f
McAfeeArtemis!49C42BF2C041
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45354982
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2fb1cb
BitDefenderThetaGen:NN.ZexaF.34742.omKfaytxfzmG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIOX
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alvi
AlibabaBackdoor:Win32/Mokes.857a8b2f
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.45354982
EmsisoftTrojan.GenericKD.45354982 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.SmokeLoader.shcqy
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B40FE6
AhnLab-V3Malware/Win32.RL_Generic.R362115
ZoneAlarmBackdoor.Win32.Mokes.alvi
GDataTrojan.GenericKD.45354982
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKD.45354982
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
RisingTrojan.Kryptik!8.8 (TFE:5:V4nJcY6klTD)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Mokes.alvi?

Backdoor.Win32.Mokes.alvi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment