Ransom

Ransom.LokiLocker removal

Malware Removal

The Ransom.LokiLocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.LokiLocker virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ransom.LokiLocker?


File Info:

name: 4055EAEC9AD528F780A8.mlw
path: /opt/CAPEv2/storage/binaries/7a6bb85d644ad5ff45c42175c1232c8796d65d5a6d40605f0cd3a4911e0a76f1
crc32: 317F3E3E
md5: 4055eaec9ad528f780a8f9109d17d95e
sha1: 6c4b9cb4ee8eb7ad017f8962a659f9adf0d693ae
sha256: 7a6bb85d644ad5ff45c42175c1232c8796d65d5a6d40605f0cd3a4911e0a76f1
sha512: 40d293e3090d8e0e4c3f88979440815b5d2a74d7842579223a9110a4f47f7d642f291720259aaf28793a77c685977656076a1b145853ad95007423ddac78b8de
ssdeep: 384:/w+eC8OH8XpDVnq6eCui9Q65nV13XonFE8KmMvLoeISeuulpIYryupoUANYsX:o+iOH8XpDVl31NxqtlevuG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14EE21A9222A55CCCCA21063F4EB0E9345F796D1C6B2B077A12C0F31FBDE2C9C4A86725
sha3_384: ef799d82cb54bacd222d12c53b074b9502406a2339d3d8755410044bdf6bdb7b260820dd7b289f9451eff000565ccb9e
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-01 14:24:31

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: eknxojgs.exe
LegalCopyright:
OriginalFilename: eknxojgs.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Ransom.LokiLocker also known as:

LionicHacktool.MSIL.FakeRansom.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.789706
FireEyeGen:Variant.Razy.789706
ALYacGen:Variant.Razy.789706
CylanceUnsafe
SangforRansom.MSIL.LokiLocker.MK
K7AntiVirusTrojan ( 0058b2951 )
AlibabaRansom:MSIL/LokiLocker.5e8fa2f3
K7GWTrojan ( 0058b2951 )
ArcabitTrojan.Razy.DC0CCA
CyrenW32/Ransom.PW.gen!Eldorado
ESET-NOD32a variant of MSIL/Filecoder.LokiLocker.C
APEXMalicious
KasperskyHEUR:Hoax.MSIL.FakeRansom.gen
BitDefenderGen:Variant.Razy.789706
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan-psw.Fakeransom.Ozrx
Ad-AwareGen:Variant.Razy.789706
SophosMal/Generic-S
TrendMicroRansom_LokiLocker.R002C0DA822
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
EmsisoftGen:Variant.Razy.789706 (B)
IkarusTrojan.MSIL.BadJoke
JiangminHoax.MSIL.bxw
AviraHEUR/AGEN.1211277
MAXmalware (ai score=88)
Antiy-AVLHackTool[Hoax]/MSIL.FakeRansom
GridinsoftRansom.Win32.AI.sa
MicrosoftRansom:MSIL/LokiLocker.MK!MTB
ViRobotTrojan.Win32.Z.Lokilocker.33280
GDataGen:Variant.Razy.789706
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R450560
McAfeeGenericRXAA-FA!4055EAEC9AD5
MalwarebytesRansom.LokiLocker
TrendMicro-HouseCallRansom_LokiLocker.R002C0DA822
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:OUpNqHH4W7xhWRY6lULndg)
YandexTrojan.Filecoder!SqidZ8giByw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Badjoke.ZP!tr
BitDefenderThetaGen:NN.ZemsilF.34160.cm0@aCHDEfk
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c9ad52
PandaTrj/CI.A

How to remove Ransom.LokiLocker?

Ransom.LokiLocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment