Trojan

What is “Trojan:MSIL/LokiBot.RPO!MTB”?

Malware Removal

The Trojan:MSIL/LokiBot.RPO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/LokiBot.RPO!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/LokiBot.RPO!MTB?


File Info:

name: BD87ED67A08D2E9E4CEC.mlw
path: /opt/CAPEv2/storage/binaries/7bc37a2f4e71dd95aa4e40048f4aca478e8e63b9393a8c2811e8470bb6f4aba1
crc32: EA8CA8D2
md5: bd87ed67a08d2e9e4cec6526666b563e
sha1: 6ec0878c6a65ec969617287f19fde458bf0c5461
sha256: 7bc37a2f4e71dd95aa4e40048f4aca478e8e63b9393a8c2811e8470bb6f4aba1
sha512: 236f79f09a7b150c68fc899d08d620fa64ccaeb4ef21c85401296047d3b179a818d33abd22ac38d8018b7f4bc13f2a5419bbf9b1de5570ace87cc1babc815f22
ssdeep: 24576:OGmYbj/2yjk37WwHsOzj4j85M1hUQDAxzJX44qxpWo:OGmY2OghsOzj4jGM1aK4FXo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E645E11B17C58BA0C5B877BF73D8A9A463F1E3EB1140DB5B1E0942E5F7132853A2A253
sha3_384: 94abfe9b0d2559d4eef1b6e5dfdfb5e868d27070a717328d447a2c0e4d973e4a419b3fbe19206f910ed0ac5a909aabb8
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-08-04 22:34:23

Version Info:

Translation: 0x0000 0x04b0
Comments: 7IJ::?=J=<B<7?
CompanyName: <879A@=677G@CF;=B7<C?F
FileDescription: DH?G;@EC459BB99I6F2
FileVersion: 7.11.14.18
InternalName: kkihyhj.exe
LegalCopyright: Copyright © 2011 <879A@=677G@CF;=B7<C?F
OriginalFilename: kkihyhj.exe
ProductName: DH?G;@EC459BB99I6F2
ProductVersion: 7.11.14.18
Assembly Version: 1.0.0.0

Trojan:MSIL/LokiBot.RPO!MTB also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Blocker.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Pretoria.1
McAfeeArtemis!BD87ED67A08D
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005990ba1 )
BitDefenderGen:Heur.MSIL.Pretoria.1
K7GWTrojan ( 005990ba1 )
Cybereasonmalicious.7a08d2
ArcabitTrojan.MSIL.Pretoria.1
CyrenW32/MSIL_Kryptik.DSR.gen!Eldorado
SymantecPacked.Generic.619
ESET-NOD32a variant of MSIL/Kryptik.AGQP
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
AlibabaTrojan:Win32/CrypterX.4fd62297
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:7p041ZsTEw9UNf6IIpEmxA)
Ad-AwareGen:Heur.MSIL.Pretoria.1
SophosML/PE-A + Mal/Generic-L
VIPREGen:Heur.MSIL.Pretoria.1
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.bd87ed67a08d2e9e
EmsisoftGen:Heur.MSIL.Pretoria.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1251650
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.3E3F
MicrosoftTrojan:MSIL/LokiBot.RPO!MTB
GDataGen:Heur.MSIL.Pretoria.1
GoogleDetected
AhnLab-V3Trojan/Win.Pretoria.C5272837
ALYacGen:Heur.MSIL.Pretoria.1
MalwarebytesTrojan.MassLogger
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.F0D1C00J422
TencentMsil.Trojan.Blocker.Ytjl
YandexTrojan.Igent.bYPNMw.5
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AGQA!tr
BitDefenderThetaGen:NN.ZemsilF.34698.jn0@aGtgaMj
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/LokiBot.RPO!MTB?

Trojan:MSIL/LokiBot.RPO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment