Backdoor

Backdoor:Win32/Lojax malicious file

Malware Removal

The Backdoor:Win32/Lojax is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Lojax virus can do?

  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Lojax?


File Info:

name: E00216958F15F1DB6371.mlw
path: /opt/CAPEv2/storage/binaries/81e96c07e6c9cb02f72c0943a42ff9f8f09a09c508f8bbaa1142a9ee4f1326cf
crc32: 1842F27B
md5: e00216958f15f1db6371b583a3ea438a
sha1: 4b9e71615b37aea1eaeb5b1cfa0eee048118ff72
sha256: 81e96c07e6c9cb02f72c0943a42ff9f8f09a09c508f8bbaa1142a9ee4f1326cf
sha512: 9d46b4fbf26c775929e95e145b390f0d12566e482920f629b342db2aaa37c5a40a789226ecfe51ba0f0b94fce827b9f53180232cda48bae510cce1e3b37bed16
ssdeep: 3072:/1sLvFfS/tB4NebyKwhlUHMjIV8JEmoXIpVoJEmoXIpVoJEmoXIpVoJEmoXIpVoW:/qFMtSLKwhAooXzoXzoXzoXzoXzoX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164749F4173289836E6C68A7489D5D5779EB7F8E1079499DF427442FA1E80BE0FE3830E
sha3_384: 357f438b36b3d13791e672bf89a14edc349aabe7addf7d99016aa7700282f0abfa3d93456c61239974929cbc296978ae
ep_bytes: e8ef380000e989feffff7501c3558bec
timestamp: 2012-08-11 02:49:24

Version Info:

0: [No Data]

Backdoor:Win32/Lojax also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lojax.4!c
MicroWorld-eScanGen:Variant.Doina.9292
ClamAVWin.Rootkit.Lojax-6715095-1
FireEyeGeneric.mg.e00216958f15f1db
CAT-QuickHealTrojan.Lojax.S3780226
McAfeeGenericRXGN-SO!E00216958F15
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaBackdoor.DoubleAgent.Win32.1
SangforBackdoor.Win32.Fancybear.IOC
K7AntiVirusTrojan ( 0053d6f81 )
AlibabaBackdoor:Win32/DoubleAgent.c517f2c1
K7GWTrojan ( 0053d6f81 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITBackdoor.Win32.Sofacy.AWM
CyrenW32/Backdoor.YDHE-8365
SymantecTrojan.Lojax
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ZXZ
APEXMalicious
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.DoubleAgent.k
BitDefenderGen:Variant.Doina.9292
NANO-AntivirusTrojan.Win32.DoubleAgent.jwmdhb
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bedd0c
EmsisoftGen:Variant.Doina.9292 (B)
F-SecureHeuristic.HEUR/AGEN.1353037
DrWebTrojan.LoJax.1
VIPREGen:Variant.Doina.9292
TrendMicroBackdoor.Win32.FALOJAK.AA
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Doina.9292
JiangminBackdoor.DoubleAgent.b
WebrootW32.Trojan.Lojack
AviraHEUR/AGEN.1353037
Antiy-AVLTrojan[Backdoor]/Win32.Apt28
XcitiumMalware@#1f48nrqx081z2
ArcabitTrojan.Doina.D244C
ZoneAlarmBackdoor.Win32.DoubleAgent.k
MicrosoftBackdoor:Win32/Lojax
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2767710
ALYacTrojan.Agent.Lojack
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Lojax
Cylanceunsafe
PandaTrj/Agent.OOX
TrendMicro-HouseCallBackdoor.Win32.FALOJAK.AA
RisingBackdoor.Lojax!8.102AC (TFE:5:yE73czEqHpT)
YandexTrojan.GenAsa!97vf49yaucQ
IkarusBackdoor.Agent
MaxSecureTrojan.Malware.73789041.susgen
FortinetW32/Agent.438A!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Lojax?

Backdoor:Win32/Lojax removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment