Backdoor

Backdoor.Win32.Mokes.ansg information

Malware Removal

The Backdoor.Win32.Mokes.ansg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Mokes.ansg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Mokes.ansg?


File Info:

crc32: 9C9193DD
md5: 43c947d6eab1458e091c53bf07443ee3
name: 43C947D6EAB1458E091C53BF07443EE3.mlw
sha1: ec7f22544bc52a651ceddfff937620419cd90a39
sha256: 49c0d71588544307b3a27741ed46262fa1cb915a705301165bf8d7b5ed694d87
sha512: 39eda8325c12bd0ed438b7ac8ed8aded5e48e6502d0e178c542e997271426570e932ca488e26ecf696bbdd83e17be4e4b96687f8c797969f7e41010dce5a3215
ssdeep: 3072:XCT3xa0bDEGB4//AtoyP37pWKYaXJBd04TvE0nJc:XCA0EGBaoJPsKzJHTvE0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.32.51
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0115 0x046a

Backdoor.Win32.Mokes.ansg also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 00584baa1 )
LionicTrojan.Win32.SmartFortress.lEDV
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.33981
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S24455749
ALYacTrojan.GenericKD.37928677
CylanceUnsafe
ZillyaBackdoor.Mokes.Win32.4884
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Mokes.8b217871
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.44bc52
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNDZ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Generic-9906221-0
KasperskyBackdoor.Win32.Mokes.ansg
BitDefenderTrojan.GenericKD.37928677
ViRobotTrojan.Win32.Z.Racealer.155136.B
MicroWorld-eScanTrojan.GenericKD.37928677
Ad-AwareTrojan.GenericKD.37928677
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34294.ju0@ayaVOtdI
TrendMicroTrojan.Win32.SMOKELOADER.YXBKDZ
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.43c947d6eab1458e
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.erw
AviraHEUR/AGEN.1145786
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.34C6A84
KingsoftWin32.Hack.Mokes.An.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MSK!MTB
ArcabitTrojan.Generic.D242BEE5
GDataTrojan.GenericKD.37928677
AhnLab-V3Trojan/Win.Racealer.R448343
Acronissuspicious
McAfeePacked-GDT!43C947D6EAB1
MAXmalware (ai score=88)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBKDZ
RisingTrojan.Kryptik!1.DAA2 (CLASSIC)
YandexBackdoor.Mokes!AKBGxYzH4yY
IkarusTrojan-Ransom.StopCrypt
FortinetPossibleThreat.PALLASNET.H
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Win32.Mokes.ansg?

Backdoor.Win32.Mokes.ansg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment