Trojan

TrojanDownloader:Win32/Lokibot.SS!MTB malicious file

Malware Removal

The TrojanDownloader:Win32/Lokibot.SS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Lokibot.SS!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fegaam.com

How to determine TrojanDownloader:Win32/Lokibot.SS!MTB?


File Info:

crc32: D7F4A58B
md5: 473e05acc6195bf707b34546e23d31ed
name: 473E05ACC6195BF707B34546E23D31ED.mlw
sha1: 43f800228bf4401a06ad271470ac7f415eccc864
sha256: 73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28
sha512: 8d806b3bca31d1e0e021ee11102b5f41259857946ac6bbaba77070fc7d39eaa10192bb565459b9cd0a64ffdca7a58ac4914719090e16cfbe94ba763e2bfb11eb
ssdeep: 12288:dbtCM55UcR6nwT2KPU69ffadHe/+kOzR4iSRZ0zJLpVdXD16m9MQJiomEK:dZlSnwTX1WHkldiW+JpVUQJ/K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Lokibot.SS!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45604225
FireEyeTrojan.GenericKD.45604225
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.45604225
K7GWTrojan-Downloader ( 0057690b1 )
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_FRS.VSNTAN21
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaTrojanDownloader:Win32/Lokibot.e0c855e0
ViRobotTrojan.Win32.Z.Remcos.862464
RisingDownloader.Delf!8.16F (TFE:5:0u7t3glFqVR)
Ad-AwareTrojan.GenericKD.45604225
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Delf.xywwt
TrendMicroTROJ_FRS.VSNTAN21
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45604225 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dldr.Delf.xywwt
MicrosoftTrojanDownloader:Win32/Lokibot.SS!MTB
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.45604225
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4307848
McAfeePWS-FCVN!473E05ACC619
MalwarebytesSpyware.LokiBot
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DDJ
TencentWin32.Trojan.Falsesign.Pbpm
FortinetW32/Delf.DDJ!tr.dldr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.a07

How to remove TrojanDownloader:Win32/Lokibot.SS!MTB?

TrojanDownloader:Win32/Lokibot.SS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment