Ransom

About “Ransom:AutoIt/Lokmwiz.B!bit” infection

Malware Removal

The Ransom:AutoIt/Lokmwiz.B!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:AutoIt/Lokmwiz.B!bit virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to disable UAC
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:AutoIt/Lokmwiz.B!bit?


File Info:

crc32: 6845F4BE
md5: 88aa0d0824f945aee01034dab0c342f7
name: 88AA0D0824F945AEE01034DAB0C342F7.mlw
sha1: cf7cc940bf55558a49ab029c5299dfe8548a8e0f
sha256: bb610ab0d2f9c7b33271d4d40db1f92965fd562214ba8ea74d518effeb8845d2
sha512: ebc1137f8e04801beb64cd2bb865372eb22d392b46751c99d32313af577d9b2ec9fd13cc76c7098e216ebb93c4df29ba70e7f0c3b05a56bb12887248e9ade4d1
ssdeep: 12288:o6Wq4aaE6KwyF5L0Y2D1PqLut8+O2PqhBkEFY9ddNdDYaTW3CZ9KoXQOay3:+thEVaPqLy8+6kF9YaT1qxO/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Ransom:AutoIt/Lokmwiz.B!bit also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 004d38111 )
Elasticmalicious (high confidence)
DrWebTrojan.Bankfraud.3628
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacGen:Variant.Ursu.519232
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.824f94
ESET-NOD32multiple detections
APEXMalicious
AvastOther:Malware-gen [Trj]
ClamAVWin.Trojan.Autoit-73
KasperskyTrojan-Banker.Win32.Agent.yhk
BitDefenderAIT:Trojan.Nymeria.4490
NANO-AntivirusTrojan.Win32.Bankfraud.efjtmx
MicroWorld-eScanAIT:Trojan.Nymeria.4490
Ad-AwareAIT:Trojan.Nymeria.4490
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.920B065C17
TrendMicroRansom_Lokmwiz.R002C0CFE21
McAfee-GW-EditionBehavesLike.Win32.Spyware.jc
FireEyeAIT:Trojan.Nymeria.4490
EmsisoftAIT:Trojan.Nymeria.4490 (B)
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_84%
Antiy-AVLTrojan/Generic.ASCommon.168
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftRansom:AutoIt/Lokmwiz.B!bit
GDataGen:Variant.Ursu.519232 (3x)
AhnLab-V3Trojan/Win32.Banki.R213572
McAfeeTrojan-AutoIt.d
MAXmalware (ai score=89)
VBA32Trojan.Autoit.F
MalwarebytesMalware.AI.435473774
TrendMicro-HouseCallRansom_Lokmwiz.R002C0CFE21
RisingTrojan.Generic@ML.89 (RDML:TcFdWgvvuTVGFg68ZC1SFw)
YandexTrojan.GenAsa!IZxoZO1iAfE
IkarusTroajn-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Filecoder.6114!tr.ransom
AVGOther:Malware-gen [Trj]
Qihoo-360HEUR/QVM11.1.9B87.Malware.Gen

How to remove Ransom:AutoIt/Lokmwiz.B!bit?

Ransom:AutoIt/Lokmwiz.B!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment