Ransom

About “Ransom.Loki.7379” infection

Malware Removal

The Ransom.Loki.7379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Loki.7379 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.Loki.7379?


File Info:

name: FB89424C9387F22355A6.mlw
path: /opt/CAPEv2/storage/binaries/82d4849172434f0a73ceb102ca5fd57f02f0165d599001b290ffabf6b189d86c
crc32: 7407B635
md5: fb89424c9387f22355a6f1318391a7eb
sha1: ccec452a2bd875522e7a9c8ea6b29d9bfeb03808
sha256: 82d4849172434f0a73ceb102ca5fd57f02f0165d599001b290ffabf6b189d86c
sha512: 3a7a3bb478475c66fcecb1c601df2319778efde9cc0a8e38002eb153f068d81e513ab89a29c4ce0a1b212aac18a36a99d68c9da163d02e2e2a611135287dd2b1
ssdeep: 12288:MqsEFFGjdwHrVoedDq/lyzMbS89i7BGJ/CBCi7uT:0MFwwpoeE/lygZi1U/CBCbT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CE402F27281C632C6857D70A856CFA14ABFAC20C5608947F3B05B9E2F717D16A6634F
sha3_384: c748937fbeb02f3148bfe78fa3e5b31606355a5840ae387de10c07f8056087dc4d9932207d2f252b8e4eb15f7dfb58ca
ep_bytes: e805420000e978feffff8bff558bec51
timestamp: 2021-08-31 02:53:28

Version Info:

FileVersion: 21.79.127.9
InternationalName: povgwaoci.iwe
Copyrighz: Copyrighz (C) 2022, fuzkorta
Translations: 0x0124 0x010f

Ransom.Loki.7379 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Loki.7379
FireEyeGeneric.mg.fb89424c9387f223
CAT-QuickHealRansom.Stop.P5
SkyhighBehavesLike.Win32.Lockbit.jc
McAfeeLockbit-FSWW!FB89424C9387
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3717130
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 0058ee0a1 )
AlibabaRansom:Win32/StopCrypt.96b62d8b
K7GWTrojan ( 0058ee0a1 )
Cybereasonmalicious.c9387f
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HONX
APEXMalicious
ClamAVWin.Malware.Filerepmalware-9940328-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderGen:Variant.Ransom.Loki.7379
AvastWin32:AceCrypter-I [Cryp]
TencentTrojan.Win32.Mokes.xa
EmsisoftTrojan.Crypt (A)
F-SecureHeuristic.HEUR/AGEN.1312669
VIPREGen:Variant.Ransom.Loki.7379
TrendMicroRansom.Win32.STOP.SMYXCDGT.hp
Trapminemalicious.high.ml.score
SophosMal/Agent-AWV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Stop.dlz
GoogleDetected
AviraHEUR/AGEN.1312669
VaristW32/Kryptik.HKO.gen!Eldorado
Antiy-AVLTrojan/Win32.Chapak
MicrosoftRansom:Win32/StopCrypt.PAZ!MTB
ArcabitTrojan.Ransom.Loki.D1CD3
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataGen:Variant.Ransom.Loki.7379
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win.BeamWinHTTP.R475178
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
ALYacGen:Variant.Ransom.Loki.7379
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.DC53 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenericKDZ.B41B!tr
AVGWin32:AceCrypter-I [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan.Win.UnkAgent

How to remove Ransom.Loki.7379?

Ransom.Loki.7379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment