Trojan

How to remove “Trojan:Win32/Lokibot.PA!MTB”?

Malware Removal

The Trojan:Win32/Lokibot.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lokibot.PA!MTB virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Trojan:Win32/Lokibot.PA!MTB?


File Info:

crc32: 4B63302C
md5: b0fdc1d5d662600356931895750433e3
name: B0FDC1D5D662600356931895750433E3.mlw
sha1: 7caacb3ea5931b8b48f78ebea88ff04257b1ee95
sha256: ef0e7b943e7baf777538a3b2b83c30ed0e4f8282a014a9d6a73aac1e4b08d2b9
sha512: 44d77a2df7aaaaa8bda030ac5d393969bb123b2a1b3922c7ee1dcc726f245bbc4eb6fca211208e798e8fc8007ba9627f628724ea94fd834540cccf53c2db9882
ssdeep: 6144:F8LxBsQD6P34xvCGg0f0XVKwn+P8r5g6BKGsUz6vPJa0eaNgYqUsy6Y7qQoOn:/QJxvPg0sXU8r5g6YGCIR7y6GqXe
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/Lokibot.PA!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 004bf6371 )
LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.16906
CAT-QuickHealTrojanpws.Agensla
ALYacTrojan.Generic.30278443
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Lokibot.e6aee0bb
K7GWSpyware ( 004bf6371 )
Cybereasonmalicious.5d6626
CyrenW32/Agent.DLR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32MSIL/Spy.Agent.AES
APEXMalicious
AvastNSIS:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
BitDefenderTrojan.Generic.30278443
MicroWorld-eScanTrojan.Generic.30278443
TencentWin32.Trojan-qqpass.Qqrob.Pgcz
Ad-AwareTrojan.Generic.30278443
SophosMal/Generic-S
ComodoMalware@#yqq60tc9v8lw
TrendMicroTROJ_FRS.0NA103J521
McAfee-GW-EditionGenericRXQF-BS!4A45FA56B148
FireEyeGeneric.mg.b0fdc1d5d6626003
EmsisoftTrojan.Generic.30278443 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1142742
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Lokibot.PA!MTB
GDataTrojan.Generic.30278443
McAfeeArtemis!B0FDC1D5D662
MAXmalware (ai score=100)
VBA32TrojanPSW.Agensla
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103J521
IkarusTrojan.Win32.Injector
FortinetW32/Injector.EQCM!tr
AVGNSIS:PWSX-gen [Trj]

How to remove Trojan:Win32/Lokibot.PA!MTB?

Trojan:Win32/Lokibot.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment