Trojan

Trojan:Win32/Lokibot.VALC!MTB removal instruction

Malware Removal

The Trojan:Win32/Lokibot.VALC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lokibot.VALC!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • CAPE detected the AsyncRat malware family

Related domains:

wpad.local-net

How to determine Trojan:Win32/Lokibot.VALC!MTB?


File Info:

name: 47573A330F3B2B556D14.mlw
path: /opt/CAPEv2/storage/binaries/afa855e33524aa1b8988de7b0f204a5d5397359225fafdacf31b434eb31a756d
crc32: 882A5EF0
md5: 47573a330f3b2b556d144cf2cc863042
sha1: 6ba0679311d7e1bede662e3c1981f2283f23dd75
sha256: afa855e33524aa1b8988de7b0f204a5d5397359225fafdacf31b434eb31a756d
sha512: 04566fa18ad07819bcc4f2b20a5eeda287242768dbdd7ff7542cb170051783bdc80eefa69ae5377d98f9c667f9c9924887c3ddd4f908979e4570331bc26b0e5e
ssdeep: 6144:rGi5OUEtwvO/7anqEueAnE5eXUUf2wmHnedO6oGqQyE2uUdwsVC2:d3Eto0o+je5efopQyEbQws1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150842359B1D02676CB9A213634B273FFD7BEE26D069187030B203FFEFB11526165A1A4
sha3_384: df80b0a3098e77d301b2a8401cbf8ed0e398d8bdebd2c3512b7361b493b3b472ea4625029e259da341e998c8d82f0ab6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan:Win32/Lokibot.VALC!MTB also known as:

LionicTrojan.Win32.Crysan.m!c
DrWebTrojan.Siggen15.51438
MicroWorld-eScanTrojan.GenericKD.47479478
FireEyeTrojan.GenericKD.47479478
McAfeeRDN/Samas
CylanceUnsafe
ZillyaBackdoor.Crysan.Win32.4966
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 0058acf81 )
AlibabaBackdoor:Win32/Lokibot.b4779309
K7GWTrojan ( 0058acf81 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Injector.ARM.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQPJ
TrendMicro-HouseCallTROJ_GEN.R067C0DL321
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Crysan.gen
BitDefenderTrojan.GenericKD.47479478
AvastWin32:Trojan-gen
TencentNsis.Trojan.Nsisx.Pcix
Ad-AwareTrojan.GenericKD.47479478
SophosMal/Generic-S
Comodofls.noname@0
TrendMicroTROJ_GEN.R067C0DL321
McAfee-GW-EditionRDN/Samas
EmsisoftTrojan.GenericKD.47479478 (B)
IkarusTrojan.NSIS.Agent
GDataTrojan.GenericKD.47479478
AviraTR/Injector.imgts
MAXmalware (ai score=86)
GridinsoftTrojan.Win32.Downloader.sa
ViRobotTrojan.Win32.Z.Spy.386440
MicrosoftTrojan:Win32/Lokibot.VALC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4788638
VBA32Trojan.Sabsik.FL
ALYacTrojan.GenericKD.47479478
MalwarebytesTrojan.Injector
APEXMalicious
FortinetW32/Injector.EQPH!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan:Win32/Lokibot.VALC!MTB?

Trojan:Win32/Lokibot.VALC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment