Ransom Trojan

How to remove “Trojan.Ransom.Loki.BAL”?

Malware Removal

The Trojan.Ransom.Loki.BAL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Loki.BAL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Ransom.Loki.BAL?


File Info:

name: 663B2BD9AD95FF450E8D.mlw
path: /opt/CAPEv2/storage/binaries/7976976d286eba47a4af0132f24f794c8e9eea5b84ebd137c55ddd012dcbdede
crc32: A8614238
md5: 663b2bd9ad95ff450e8d00352d37b47b
sha1: 817da9d0398965a90003171f74f59e41a39d7588
sha256: 7976976d286eba47a4af0132f24f794c8e9eea5b84ebd137c55ddd012dcbdede
sha512: f3c3574ebe1420fb3345f9c7451b83c31b448113cb5a8933e81a08ca266ca9317aaf365c45c799ca99133954f4ef3816798ef0ef07e8a58ec7405088a12adc9b
ssdeep: 12288:HqdMb7e4cuASzZcETeUiH6O1yHFNtyGWdL:HqKaMAzEqMlzyGWd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACA423AFA9DC1532E0420A37735B6D90262DD1560B4D7B63AC23DCEDA8F82D1D2F9247
sha3_384: 703dec74ea5d15e2923b39853bef25b18b6f4b9a2cca42c4d56c27d369af558875e3fbd5d1de2ae8ddbf81a3cca42c61
ep_bytes: 60be00f044008dbe0020fbffc7879c20
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: GN.org>
License: The;see www.gnu.org/copyleft/gpl.html.
FileDescription: Gperf: genect hash function from a key set
FileVersion: 3.0.1.1765
InternalName: gperf
LegalCopyright: © e Softwre Fof.org>
LegalTrademarks: GNUerf®
OriginalFilename: gperf.exe
ProductName: Gperf
ProductVersion: 3.0.1.1765
SpecialBuild: GNU iceforge.net>
WWW: http://wf.html
Translation: 0x0409 0x04e4

Trojan.Ransom.Loki.BAL also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FareIt.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Ransom.Loki.BAL
ClamAVWin.Trojan.Generickdz-8010887-0
FireEyeGeneric.mg.663b2bd9ad95ff45
ALYacTrojan.Ransom.Loki.BAL
Cylanceunsafe
ZillyaTrojan.Injector.Win32.730237
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005663731 )
AlibabaTrojan:Win32/Kryptik.23fc2266
K7GWTrojan ( 005663731 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36662.CmKfaSqhOrii
CyrenW32/Injector.ABY.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.ELUT
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Kryptik.ajh
BitDefenderTrojan.Ransom.Loki.BAL
NANO-AntivirusTrojan.Win32.Stealer.hjzthm
AvastWin32:Trojan-gen
TencentWin32.Trojan.Kryptik.Rqil
EmsisoftTrojan.Ransom.Loki.BAL (B)
F-SecureHeuristic.HEUR/AGEN.1347417
VIPRETrojan.Ransom.Loki.BAL
McAfee-GW-EditionFareit-FSK!B1FF3684A65A
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Ransom.Loki.BAL
JiangminTrojan/Genome.dghq
AviraHEUR/AGEN.1347417
Antiy-AVLTrojan/Win32.Kryptik
XcitiumMalware@#1hb6b6i12a2og
ArcabitTrojan.Ransom.Loki.BAL
ZoneAlarmTrojan.Win32.Kryptik.ajh
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Obfuscator.C4108793
McAfeeArtemis!663B2BD9AD95
MAXmalware (ai score=87)
VBA32BScope.TrojanSpy.Swotter
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:5:SVxnsCoZ9oM)
YandexTrojan.Injector!/JBPoTVNqt4
IkarusTrojan.Inject
MaxSecureTrojan.Malware.73736783.susgen
FortinetW32/Injector.ELXR!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.9ad95f
DeepInstinctMALICIOUS

How to remove Trojan.Ransom.Loki.BAL?

Trojan.Ransom.Loki.BAL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment