Ransom

Ransom.Loki.22424 information

Malware Removal

The Ransom.Loki.22424 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Loki.22424 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.Loki.22424?


File Info:

name: BF94CCF7A11A9B1FE6FB.mlw
path: /opt/CAPEv2/storage/binaries/6225eeeffe55735315cba81d4fff6116dab0309b468a82847cd2cf16d7b61e16
crc32: D7E329F5
md5: bf94ccf7a11a9b1fe6fb11bac4abba86
sha1: 99e6b6333a02d848be8e887f5e3a6d7488ad824c
sha256: 6225eeeffe55735315cba81d4fff6116dab0309b468a82847cd2cf16d7b61e16
sha512: c5619701e67ebdf1a42cfbb7a6f19e0468b606b71e9eda62297bf8b0255858fa1cd8b3e71e45003baf8a9d075f4271fc01bfe307301fe6d72972fb8f4e87704a
ssdeep: 12288:u77LBm2UHsZ8BUYZbciAT6Ero1PUbpy+w4:Ab/45ZbciAT6Ek1sbp3w4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194B4C0602B1AC191E88DB1FD60A7766F5BEB5433C20BD0DB8D59875E3CA2C5A0E5E0D3
sha3_384: 3e5b86d59c63386a3dff1650b48f1e5272e4c4340ccd7f55b5a7f91ba0fde0a90abb33c9a7fd8cfd59c1197d0c9bb6be
ep_bytes: 6874134000e8f0ffffff000000000000
timestamp: 2018-02-28 16:07:34

Version Info:

Translation: 0x0409 0x04b0
CompanyName: SAMsung
ProductName: TEXAS instruMENTS incorpoRATED
FileVersion: 2.02
ProductVersion: 2.02
InternalName: Synthetical8
OriginalFilename: Synthetical8.exe

Ransom.Loki.22424 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Noon.l!c
MicroWorld-eScanGen:Variant.Ransom.Loki.22424
FireEyeGeneric.mg.bf94ccf7a11a9b1f
SkyhighPacked-FBQ!BF94CCF7A11A
ALYacGen:Variant.Ransom.Loki.22424
Cylanceunsafe
ZillyaTrojan.Noon.Win32.1303
SangforSuspicious.Win32.Save.vb
AlibabaTrojanSpy:Win32/VBInject.86a1dff5
K7GWTrojan ( 0052908d1 )
K7AntiVirusTrojan ( 0052908d1 )
BitDefenderThetaGen:NN.ZevbaF.36804.Em0@am6W7Wji
VirITTrojan.Win32.VBZenPack_Heur
SymantecPacked.Generic.531
ESET-NOD32a variant of Win32/Injector.DWGO
APEXMalicious
TrendMicro-HouseCallTSPY_HPFAREIT.SMVB
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Noon.htl
BitDefenderGen:Variant.Ransom.Loki.22424
NANO-AntivirusTrojan.Win32.Noon.eylovp
AvastWin32:Malware-gen
TencentWin32.Trojan-Spy.Noon.Ogil
EmsisoftGen:Variant.Ransom.Loki.22424 (B)
F-SecureHeuristic.HEUR/AGEN.1335506
DrWebTrojan.DownLoader26.11210
VIPREGen:Variant.Ransom.Loki.22424
TrendMicroTSPY_HPFAREIT.SMVB
Trapminemalicious.high.ml.score
SophosMal/FareitVB-X
MAXmalware (ai score=98)
GoogleDetected
AviraHEUR/AGEN.1335506
VaristW32/VBInject.LJ.gen!Eldorado
Antiy-AVLTrojan[Spy]/Win32.Noon
Kingsoftmalware.kb.a.999
MicrosoftVirTool:Win32/VBInject.AID!bit
XcitiumMalware@#1d9hcgkpjn7y9
ArcabitTrojan.Ransom.Loki.D5798
ViRobotTrojan.Win32.Z.Noon.503808
ZoneAlarmTrojan-Spy.Win32.Noon.htl
GDataGen:Variant.Ransom.Loki.22424
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
McAfeePacked-FBQ!BF94CCF7A11A
VBA32BScope.Trojan.VBKrypt
MalwarebytesMalware.Heuristic.2046
PandaTrj/GdSda.A
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojanSpy.Noon!a1Z7YB6fiNY
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFIF!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Noon.htl

How to remove Ransom.Loki.22424?

Ransom.Loki.22424 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment