Ransom

Ransom.Loki.10445 removal tips

Malware Removal

The Ransom.Loki.10445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Loki.10445 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.Loki.10445?


File Info:

name: 63A9B934712167950DBE.mlw
path: /opt/CAPEv2/storage/binaries/25e5574fa2c12795a3dfccffa7566eabc55508357e4914f1ae653dda2bb6729b
crc32: 2A15C797
md5: 63a9b934712167950dbe911da663e978
sha1: 5b7b1a31fab153bcdef83726d4223a67b350e769
sha256: 25e5574fa2c12795a3dfccffa7566eabc55508357e4914f1ae653dda2bb6729b
sha512: ef6b83897f71b14ad95f715f797dadfbdd6b08a4cc072ce21205b3b4693ff93c6bc30d6f60ec0ed3ae20af3e576bf4d5357bb5e6bc012f79c45b2b2f58acfcfb
ssdeep: 12288:ysybHd/zvDue757IRUPCYm+eQcFlxypu82quAJ0gXwtwimJEW6gkmTcb1b:H2xzvv7IRUP/eRFyp2qXJ0gQ5wERglc5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106F4AF62F2E14433D1A31A7D5D1B5F78582EBE513D2869462BE45C4CAF38783383A29F
sha3_384: 96df00ce6ea7fdabeca041f4f3be3d980c66656426fcc1c0a3e1675f127b2cbabb2eb61924bd717561d27767ec280f90
ep_bytes: 558bec83c4f0b844884600e890d3f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Ransom.Loki.10445 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Loki.10445
FireEyeGeneric.mg.63a9b93471216795
SkyhighBehavesLike.Win32.Fareit.bc
ALYacGen:Variant.Ransom.Loki.10445
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Injector.Win32.739554
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/NanoCore.53a596d1
K7GWTrojan ( 0056739d1 )
K7AntiVirusTrojan ( 0056739d1 )
BitDefenderThetaGen:NN.ZelphiF.36680.TGW@aCIM86oi
VirITTrojan.Win32.Injector.CFD
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.EMHC
ZonerTrojan.Win32.91381
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Crypt.gen
BitDefenderGen:Variant.Ransom.Loki.10445
NANO-AntivirusTrojan.Win32.TrjGen.hknatj
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11b4d41c
EmsisoftGen:Variant.Ransom.Loki.10445 (B)
F-SecureHeuristic.HEUR/AGEN.1331248
DrWebTrojan.PWS.Siggen2.49254
VIPREGen:Variant.Ransom.Loki.10445
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
Trapminemalicious.moderate.ml.score
SophosMal/Fareit-AA
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.Loki.10445
JiangminTrojan.Crypt.fdo
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1331248
Antiy-AVLTrojan/Win32.Crypt
Kingsoftmalware.kb.a.1000
XcitiumMalware@#146txvbbbgpjz
ArcabitTrojan.Ransom.Loki.D28CD
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
MicrosoftPWS:Win32/Fareit.AKK!MTB
VaristW32/Delf.KX.gen!Eldorado
McAfeeFareit-FTB!63A9B9347121
MAXmalware (ai score=87)
VBA32Trojan.Wacatac
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
RisingTrojan.Injector!8.C4 (TFE:5:4jur9fKL6s)
YandexTrojan.Igent.bTMJg3.3
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.10374761.susgen
FortinetW32/Injector.ELZG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.1fab15
DeepInstinctMALICIOUS

How to remove Ransom.Loki.10445?

Ransom.Loki.10445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment