Ransom

Ransom.Loki.3093 removal tips

Malware Removal

The Ransom.Loki.3093 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Loki.3093 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.Loki.3093?


File Info:

name: 6145D7D7E8B79F5F1DE0.mlw
path: /opt/CAPEv2/storage/binaries/b59025ebb2c59872aacc5a6bc6f6eba0ebe5b1610c5c2a0eeb04ae6144268909
crc32: 9228BE1C
md5: 6145d7d7e8b79f5f1de07cef59878cc4
sha1: 3ac23a399ab88302f0885b5fa6d9d5a10c89b07b
sha256: b59025ebb2c59872aacc5a6bc6f6eba0ebe5b1610c5c2a0eeb04ae6144268909
sha512: 83efc018d5c323c319603ed71740a928ed8d48d60967fca9bea28b99b7ab1fbe2250b4d8b12a1f5561aac0897ae74eed93d8ec051724fc8008cc85ba38341d67
ssdeep: 12288:JhQVh9a17gNm5YnXDdx2OjKhNHySntnYjI0bsohfUAkIbcbbbbbbbbbbbbbbbbb6:JhQVh9FDdx2GKzSSt+I0bs6cAkIbcbb2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4C4BE1179818032C27334310B78F2B249BDA8706E659EDF67E809786F745D1B63AB6F
sha3_384: e8866fe79512f7a0b9a8542711b46e9a9165e1802932d354c81ba05a6c83c94719770b5a6d6e520935c0b6e2e3212cdf
ep_bytes: e8b3040000e95cfeffff558bec836104
timestamp: 2021-08-03 23:53:19

Version Info:

0: [No Data]

Ransom.Loki.3093 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Androm.m!c
AVGWin32:PWSX-gen [Trj]
MicroWorld-eScanGen:Variant.Ransom.Loki.3093
FireEyeGeneric.mg.6145d7d7e8b79f5f
SkyhighBehavesLike.Win32.Generic.hc
ALYacGen:Variant.Ransom.Loki.3093
ZillyaTrojan.Agensla.Win32.14979
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/FormBook.da94cdfa
K7GWTrojan ( 005807271 )
K7AntiVirusTrojan ( 005807271 )
SymantecTrojan!im
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HLYK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-9883784-0
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
BitDefenderGen:Variant.Ransom.Loki.3093
SUPERAntiSpywareTrojan.Agent/Gen-SpyPasswordStealer
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bc0881
EmsisoftTrojan.Crypt (A)
F-SecureHeuristic.HEUR/AGEN.1319809
DrWebTrojan.Siggen14.53796
VIPREGen:Variant.Ransom.Loki.3093
TrendMicroTrojanSpy.Win32.LOKI.SMYJBHC.hp
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Agensla.qa
VaristW32/Kryptik.EVG.gen!Eldorado
AviraHEUR/AGEN.1319809
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/FormBook.SM!MTB
ArcabitTrojan.Ransom.Loki.DC15
ZoneAlarmHEUR:Trojan-PSW.Win32.Agensla.gen
GDataWin32.Malware.LoctLoader.B
GoogleDetected
AhnLab-V3Malware/Win.Cryptor.R435861
McAfeeGenericRXPN-XS!6145D7D7E8B7
MAXmalware (ai score=82)
VBA32BScope.TrojanSpy.Noon
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D84E (CLASSIC)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.74493803.susgen
FortinetW32/GenKryptik.FJZP!tr
BitDefenderThetaGen:NN.ZexaE.36802.HyZ@a4A6RVei
DeepInstinctMALICIOUS

How to remove Ransom.Loki.3093?

Ransom.Loki.3093 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment