Backdoor

Backdoor.Win32.Mokes.alvt removal tips

Malware Removal

The Backdoor.Win32.Mokes.alvt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.alvt virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.alvt?


File Info:

crc32: 3C8C50F0
md5: 430ac82d11cf9f16fc505bb473fdc9cd
name: 430AC82D11CF9F16FC505BB473FDC9CD.mlw
sha1: a5297d11cbcdcbb0b8984adf3bdd7f33dee60086
sha256: 5c9c5a58171580835278b79ce54b8beeba97e9d8a4cb93a7f835d0490fee85ba
sha512: 717a23ab41498943df2f1d73333ffc0ec480aa68829c04b9f432ff0d265be6c8d58648ea573412febe4a710a218cd1bf98d9f84a7f453669c1647b33a915e5e7
ssdeep: 3072:D21YABawGf0HTRJ/aEDoQKna8XjddjNSiWzO2FI:D21HBm0zniIELXjddxSijD
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x04ea

Backdoor.Win32.Mokes.alvt also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36019838
FireEyeGeneric.mg.430ac82d11cf9f16
CAT-QuickHealTrojan.Glupteba
Qihoo-360Generic/Trojan.1c2
McAfeeArtemis!430AC82D11CF
CylanceUnsafe
K7AntiVirusTrojan ( 00575bfa1 )
AlibabaBackdoor:Win32/Mokes.6cb521ee
K7GWTrojan ( 00575bfa1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.alvt
BitDefenderTrojan.GenericKD.36019838
AegisLabTrojan.Win32.Malicious.4!c
AvastWin32:DropperX-gen [Drp]
TencentWin32.Backdoor.Mokes.Oyyk
Ad-AwareTrojan.GenericKD.36019838
SophosMal/Generic-R + Troj/Steal-AYV
F-SecureTrojan.TR/AD.SmokeLoader.nmpob
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DAA21
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
EmsisoftTrojan.GenericKD.36019838 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.36019838
AviraTR/AD.SmokeLoader.nmpob
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2259E7E
ViRobotTrojan.Win32.Z.Kryptik.230400.AJF
ZoneAlarmBackdoor.Win32.Mokes.alvt
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362115
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.omKfa4jeVqbG
ALYacTrojan.GenericKD.36019838
MAXmalware (ai score=100)
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIOX
TrendMicro-HouseCallTROJ_GEN.R002C0DAA21
RisingTrojan.Kryptik!8.8 (TFE:5:V4nJcY6klTD)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Mokes.alvt?

Backdoor.Win32.Mokes.alvt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment