Trojan

Trojan:Win32/LokibotCrypt.ARK!MTB information

Malware Removal

The Trojan:Win32/LokibotCrypt.ARK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LokibotCrypt.ARK!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

Related domains:

googleforshares.publicvm.com

How to determine Trojan:Win32/LokibotCrypt.ARK!MTB?


File Info:

crc32: 11C64FD4
md5: e32c834a6a44255b6e94ca28cb59b1c1
name: E32C834A6A44255B6E94CA28CB59B1C1.mlw
sha1: f518c224939deb5e60e58e5347a60ef8456c703b
sha256: 45976a7b168fdbcb6c2bd82b39eddd7f75543948ca47d454a8f76cd43177bfb7
sha512: d6b8446f3a8927a84b008a0fa598465a3c2d346ad786e4cfe70f827450888c6fc02675004b070b7a1e9945bec903b7b6e92a457f711359187ded68fbfb92bf50
ssdeep: 49152:9EVUcgGV/c4vnNHCc4uqQhtCzaDD+kqK/DA2q1kioEtGyi:9E3gaMOCuDDFrk1ki/ti
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Trojan:Win32/LokibotCrypt.ARK!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056e5201 )
LionicTrojan.Win32.VB.lpG0
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.3238
CynetMalicious (score: 99)
CAT-QuickHealTrojan.DriveHide.VN8
ALYacTrojan.GenericKD.36090846
CylanceUnsafe
ZillyaTrojan.Injector.Win32.816597
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/DelfInject.ali2000015
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.a6a442
CyrenW32/Injector.TIUD-8484
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Dropper-DM [Trj]
ClamAVWin.Dropper.Lokibot-9791657-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
BitDefenderAIT:Trojan.Nymeria.3053
NANO-AntivirusTrojan.Win32.Kryptik.ibtmsr
MicroWorld-eScanAIT:Trojan.Nymeria.3053
TencentWin32.Trojan.Kryptik.Ahei
Ad-AwareAIT:Trojan.Nymeria.3053
SophosMal/Generic-S
ComodoMalware@#35c56xwnmhrs5
BitDefenderThetaGen:NN.ZelphiF.34266.sIW@aOStlngi
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.AutoIt.MALXMR.AD
McAfee-GW-EditionBehavesLike.Win32.Spyware.vc
FireEyeGeneric.mg.e32c834a6a44255b
EmsisoftAIT:Trojan.Nymeria.3053 (B)
JiangminTrojan.MSIL.Zapchast.ag
WebrootW32.Trojan.Gen
AviraTR/Injector.eajka
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.30FE5EA
MicrosoftTrojan:Win32/LokibotCrypt.ARK!MTB
ArcabitTrojan.Generic.D226B3DE
GDataWin32.Trojan.BSE.1X0BHAS
AhnLab-V3Malware/Win32.Generic.C4341828
McAfeeArtemis!E32C834A6A44
MAXmalware (ai score=82)
VBA32Trojan.Kryptik
MalwarebytesMalware.AI.3022078383
TrendMicro-HouseCallCoinminer.AutoIt.MALXMR.AD
RisingTrojan.Injector!1.CEB9 (CLASSIC)
YandexTrojan.Kryptik!r/g3s18CVzE
IkarusTrojan-Dropper.Win32.Autoit
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Injector.ENVN!tr
AVGAutoIt:Dropper-DM [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/LokibotCrypt.ARK!MTB?

Trojan:Win32/LokibotCrypt.ARK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment