Trojan

Trojan:Win32/Lokibot.SWM!MTB removal

Malware Removal

The Trojan:Win32/Lokibot.SWM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lokibot.SWM!MTB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Lokibot.SWM!MTB?


File Info:

crc32: 87AB7608
md5: 9c9f97be42dde00579d0150b28dfab7e
name: upload_file
sha1: f24982828f7963afd44af1b6f2c4b83c9a546e1c
sha256: e27846749619df94dd373cbbc3a27fe44a5790bac920ad7c2d8ed13296e71387
sha512: df6381c067fb1cb77dba4cb1e5ca5c608d838f4df6326be7e09dc5ba6a0359e916530362612a99064c6ae501fc2a72291cee203b2a248896e722dbfe20456ed4
ssdeep: 12288:v6LIdiPeP0pK+6kP/j2hEfPgqZkY4AJ0VSef9k2Kigm:v6rrc+6o+EAqqG0w2k4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Lokibot.SWM!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
MicroWorld-eScanTrojan.GenericKD.43986169
FireEyeGeneric.mg.9c9f97be42dde005
CAT-QuickHealTrojan.Kryptik
Qihoo-360Win32/Trojan.469
ALYacTrojan.GenericKD.43986169
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.43986169
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.28f796
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZelphiF.34298.SGW@aGEIbhki
CyrenW32/Agent.LYBB-3232
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9774214-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
NANO-AntivirusTrojan.Win32.SpyBotNET.hynihx
Ad-AwareTrojan.GenericKD.43986169
SophosMal/Generic-S
ComodoMalware@#246yzxkcog9jk
F-SecureTrojan.TR/Kryptik.lswaj
TrendMicroTROJ_FRS.0NA103J620
McAfee-GW-EditionBehavesLike.Win32.Fareit.bh
EmsisoftTrojan.GenericKD.43986169 (B)
SentinelOneDFI – Malicious PE
JiangminTrojan.Kryptik.cjy
AviraTR/Kryptik.lswaj
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Lokibot.SWM!MTB
ArcabitTrojan.Generic.D29F2CF9
AegisLabTrojan.Win32.Kryptik.4!c
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataTrojan.GenericKD.43986169
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4204183
McAfeeRDN/AgentTesla
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/Genetic.gen
ZonerTrojan.Win32.95435
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTROJ_FRS.0NA103J620
RisingMalware.Undefined!8.C (TFE:5:1Z0LmEyi4PG)
YandexTrojan.Kryptik!tqZz35Dq6c4
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_97%
FortinetW32/Injector.ETNW!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Lokibot.SWM!MTB?

Trojan:Win32/Lokibot.SWM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment