Categories: Trojan

What is “Trojan:Win32/Lokibot.BB!MTB”?

The Trojan:Win32/Lokibot.BB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lokibot.BB!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Lokibot.BB!MTB?


File Info:

crc32: D010E0B4md5: 21f077fa0e739f6174e2452abc30bb7cname: 21F077FA0E739F6174E2452ABC30BB7C.mlwsha1: 9d60988db53eb662eb6a8e2f824036348f5e7ec0sha256: 6f536ae781fd98358126408aa6991b4bb3ec3f9940929a22b25f785b71ec770dsha512: 33e9b0e9d0f7897aa56c69187f8e797b695e729774afa9f81a23618443cd11911c10777dfc1af6294135c3a16df6b23942c7f8f2ee3fcb3522c4ebe77c9af38essdeep: 12288:D1cg+pOHH8f/6xUJ492ctspCbQHA8N44Oo40vqX0uNb+T0HXX+jBnnXLVgKR3mEx:D1BjH8f/6AwbL24Eq/XQBmEsGtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Lokibot.BB!MTB also known as:

K7AntiVirus Trojan ( 0057db511 )
Elastic malicious (high confidence)
DrWeb Trojan.Siggen13.53434
Cynet Malicious (score: 100)
ALYac Trojan.GenericKDZ.75717
Cylance Unsafe
CrowdStrike win/malicious_confidence_90% (W)
K7GW Trojan ( 0057db511 )
Cybereason malicious.db53eb
Cyren W32/Injector.STGJ-1263
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.EPME
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Kaspersky HEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefender Trojan.GenericKDZ.75717
MicroWorld-eScan Trojan.GenericKDZ.75717
Ad-Aware Trojan.GenericKDZ.75717
Sophos Mal/Generic-S
BitDefenderTheta Gen:NN.ZelphiF.34722.cHX@ai1cU5pi
McAfee-GW-Edition Fareit-FZO!21F077FA0E73
FireEye Generic.mg.21f077fa0e739f61
Emsisoft Trojan.GenericKDZ.75717 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin Trojan.Banker.BestaFera.igx
eGambit PE.Heur.InvalidSig
Microsoft Trojan:Win32/Lokibot.BB!MTB
Arcabit Trojan.Generic.D127C5
GData Trojan.GenericKDZ.75717
AhnLab-V3 Trojan/Win.Fareit.C4518593
McAfee Fareit-FZO!21F077FA0E73
MAX malware (ai score=84)
VBA32 BScope.Trojan.Fuerboos
Malwarebytes Spyware.LokiBot
Panda Trj/GdSda.A
Rising Trojan.Kryptik!1.D2D5 (CLASSIC)
Yandex Trojan.Igent.bV0oeC.10
Ikarus Trojan.Inject
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Injector.EPMJ!tr
AVG Win32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Lokibot.BB!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Lazy.280688 removal guide

The Lazy.280688 is considered dangerous by lots of security experts. When this infection is active,…

56 mins ago

Malware.AI.3454153382 information

The Malware.AI.3454153382 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Midie.100502 removal tips

The Midie.100502 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.3915743673 (file analysis)

The Malware.AI.3915743673 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.2034266737 removal

The Malware.AI.2034266737 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan.Win32.Agent.xbmkmt removal tips

The Trojan.Win32.Agent.xbmkmt is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago