Trojan

What is “Trojan:Win32/Lokibot.BB!MTB”?

Malware Removal

The Trojan:Win32/Lokibot.BB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lokibot.BB!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Lokibot.BB!MTB?


File Info:

crc32: D010E0B4
md5: 21f077fa0e739f6174e2452abc30bb7c
name: 21F077FA0E739F6174E2452ABC30BB7C.mlw
sha1: 9d60988db53eb662eb6a8e2f824036348f5e7ec0
sha256: 6f536ae781fd98358126408aa6991b4bb3ec3f9940929a22b25f785b71ec770d
sha512: 33e9b0e9d0f7897aa56c69187f8e797b695e729774afa9f81a23618443cd11911c10777dfc1af6294135c3a16df6b23942c7f8f2ee3fcb3522c4ebe77c9af38e
ssdeep: 12288:D1cg+pOHH8f/6xUJ492ctspCbQHA8N44Oo40vqX0uNb+T0HXX+jBnnXLVgKR3mEx:D1BjH8f/6AwbL24Eq/XQBmEsG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Lokibot.BB!MTB also known as:

K7AntiVirusTrojan ( 0057db511 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.53434
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.75717
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057db511 )
Cybereasonmalicious.db53eb
CyrenW32/Injector.STGJ-1263
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPME
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderTrojan.GenericKDZ.75717
MicroWorld-eScanTrojan.GenericKDZ.75717
Ad-AwareTrojan.GenericKDZ.75717
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZelphiF.34722.cHX@ai1cU5pi
McAfee-GW-EditionFareit-FZO!21F077FA0E73
FireEyeGeneric.mg.21f077fa0e739f61
EmsisoftTrojan.GenericKDZ.75717 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.BestaFera.igx
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Lokibot.BB!MTB
ArcabitTrojan.Generic.D127C5
GDataTrojan.GenericKDZ.75717
AhnLab-V3Trojan/Win.Fareit.C4518593
McAfeeFareit-FZO!21F077FA0E73
MAXmalware (ai score=84)
VBA32BScope.Trojan.Fuerboos
MalwarebytesSpyware.LokiBot
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.D2D5 (CLASSIC)
YandexTrojan.Igent.bV0oeC.10
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EPMJ!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Lokibot.BB!MTB?

Trojan:Win32/Lokibot.BB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment