Categories: Trojan

Trojan:Win32/LokibotCrypt.MV!MTB information

The Trojan:Win32/LokibotCrypt.MV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LokibotCrypt.MV!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

tttttt.me
apps.identrust.com
yearofthepig.top

How to determine Trojan:Win32/LokibotCrypt.MV!MTB?


File Info:

crc32: 107FF2DAmd5: 3aa41ad444d0f5d89f9c53a5677535f6name: 3AA41AD444D0F5D89F9C53A5677535F6.mlwsha1: 299665a9447471619814b577688694a6c30b5fdbsha256: dbbc522719582c66077a06ac1b94fedeed360335d5762dbc78a5744d4309ce93sha512: c96bb855050d72ce0936bad78976c6442faa8778dc9947f42b1eb3d2488fcfeb7ebb2eca022656b5e27692ae941f8e26e1e453ccf7c742cb2cdfb2d74ffa6247ssdeep: 12288:q0IWJO4rDw16c+iSKuwKtXdewqMGin2WNH+CL5gG1bPIoLgdBjSBgyLwJY:AmRD4p+iPuLDewqgnHffP4dBjSqyLqYtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersions: 7.0.0.25LegalCopyrights: VsekdaProductVersions: 67.0.20.45Translation: 0x0409 0x0678

Trojan:Win32/LokibotCrypt.MV!MTB also known as:

Bkav W32.AIDetectGBM.malware.01
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Siggen2.61686
MicroWorld-eScan Trojan.GenericKD.36359967
CAT-QuickHeal Trojanpws.Racealer
Qihoo-360 Win32/Trojan.Generic.HwoCVyIA
ALYac Trojan.GenericKD.36359967
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005780001 )
BitDefender Trojan.GenericKD.36359967
K7GW Trojan ( 005780001 )
BitDefenderTheta Gen:NN.ZexaF.34574.IqW@aifJnjhG
Cyren W32/Trojan.ASCS-2692
Symantec ML.Attribute.HighConfidence
TrendMicro-HouseCall TrojanSpy.Win32.RACEALER.USMANBI21
Avast Win32:DropperX-gen [Drp]
ClamAV Win.Dropper.Glupteba-9834556-0
Kaspersky HEUR:Trojan-PSW.Win32.Racealer.gen
Alibaba Trojan:Win32/LokibotCrypt.45f1e1c7
NANO-Antivirus Trojan.Win32.Racealer.imazrl
AegisLab Trojan.Win32.Blocker.mDYp
Rising Trojan.Generic@ML.95 (RDMK:94rUHULa2p/g0I51SK32fg)
Ad-Aware Trojan.GenericKD.36359967
Emsisoft Trojan.GenericKD.36359967 (B)
F-Secure Trojan.TR/AD.StellarStealer.dzcqv
TrendMicro TrojanSpy.Win32.RACEALER.USMANBI21
McAfee-GW-Edition BehavesLike.Win32.Emotet.hc
FireEye Generic.mg.3aa41ad444d0f5d8
Sophos Mal/Generic-S + Troj/Kryptik-SJ
Ikarus Trojan.Crypt
GData Trojan.GenericKD.36359967
Webroot W32.Malware.Gen
Avira TR/AD.StellarStealer.dzcqv
MAX malware (ai score=86)
Gridinsoft Trojan.Win32.Emotet.ns
Arcabit Trojan.Generic.D22ACF1F
ZoneAlarm HEUR:Trojan-PSW.Win32.Racealer.gen
Microsoft Trojan:Win32/LokibotCrypt.MV!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.RL_Generic.R366794
McAfee Packed-GBE!3AA41AD444D0
VBA32 Trojan.Glupteba
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
APEX Malicious
ESET-NOD32 a variant of Win32/Kryptik.HJMQ
Tencent Win32.Trojan-qqpass.Qqrob.Lmky
SentinelOne Static AI – Malicious PE
eGambit Unsafe.AI_Score_80%
Fortinet PossibleThreat.PALLAS.H
AVG Win32:DropperX-gen [Drp]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen

How to remove Trojan:Win32/LokibotCrypt.MV!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Graftor.636625 removal tips

The Graftor.636625 is considered dangerous by lots of security experts. When this infection is active,…

9 mins ago

Troj/Luder-A information

The Troj/Luder-A is considered dangerous by lots of security experts. When this infection is active,…

45 mins ago

How to remove “Malware.AI.2017919460”?

The Malware.AI.2017919460 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Malware.AI.2861677099”?

The Malware.AI.2861677099 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.4183435755 information

The Malware.AI.4183435755 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Dropped:Application.Generic.3571726 removal instruction

The Dropped:Application.Generic.3571726 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago