Malware

PWS:Win32/Lolyda!pz removal guide

Malware Removal

The PWS:Win32/Lolyda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lolyda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine PWS:Win32/Lolyda!pz?


File Info:

name: E76601E0E684C47EEE2B.mlw
path: /opt/CAPEv2/storage/binaries/ffecef397c1a15be86694c4bcb213f4b54e3d9390f012c8ff01cee6a3a5f611e
crc32: DBDABED0
md5: e76601e0e684c47eee2bde3fe2b12bab
sha1: 56300b6bfa204a5d657f0f242615ccfdd423409a
sha256: ffecef397c1a15be86694c4bcb213f4b54e3d9390f012c8ff01cee6a3a5f611e
sha512: 15fe3e747cd7c3c20953991b9230300c30de03dc30e5dae37c0bac9550ccdd54724a89b4043826a72572728f6974911cf4d066dd789c4c7f783b33aa36f75d75
ssdeep: 768:GUTHaQ5CPZ5mvC87Gt6ZWpNqOjsSRzVs+:GUTHb5i5mH7GtEDQRxJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T111E26C13774744B7E39B423475162FBEDBFC69301A4A85AACB6247CE1CB45C2EA36243
sha3_384: 5ece01c1d9ff68144cdd62dc60bd075f3e5d7b8674b3a44c5e5049c7f269ff3d1764ff5030475dbecc1fb4cfaeeba7bf
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2012-05-23 19:56:54

Version Info:

0: [No Data]

PWS:Win32/Lolyda!pz also known as:

BkavW32.ReplaceMiKsLT.Fam.RSF
LionicTrojan.Win32.Generic.ltBM
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e76601e0e684c47e
CAT-QuickHealTrojanPWS.Lolyda.BF5
SkyhighBehavesLike.Win32.PWSOnlineGames.nh
McAfeePWS-OnlineGames.hi.gen.a
Cylanceunsafe
VIPREGeneric.Dacic.C35DC41E.A.9B184257
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 00305a831 )
AlibabaTrojanPSW:Win32/Lolyda.df110f85
K7GWPassword-Stealer ( 00305a831 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitGeneric.Dacic.C35DC41E.A.9B184257
BitDefenderThetaGen:NN.ZedlaF.36680.cq5@aSjkysg
VirITTrojan.Win32.Generic.CYE
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.OnLineGames.PGB
APEXMalicious
ClamAVWin.Malware.Onlinegames-10008771-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Dacic.C35DC41E.A.9B184257
NANO-AntivirusTrojan.Win32.Gamania.sgzyv
SUPERAntiSpywareTrojan.Agent/Gen-GameSpy
MicroWorld-eScanGeneric.Dacic.C35DC41E.A.9B184257
AvastWin32:Agent-AMTO [Spy]
TencentTrojan.Win32.OnlineGame.e
EmsisoftGeneric.Dacic.C35DC41E.A.9B184257 (B)
BaiduWin32.Trojan-PSW.OLGames.i
F-SecureTrojan.TR/PSW.Lolyda.bfmna
DrWebTrojan.PWS.Gamania.36394
ZillyaTrojan.OnLineGames.Win32.120447
TrendMicroTROJ_RVERSE.SMI
SophosMal/PWS-AL
IkarusTrojan-PWS.Win32.Lolyda
JiangminTrojan/Generic.ppwm
WebrootW32.Trojan.Pws.Onlinegames
GoogleDetected
AviraTR/PSW.Lolyda.bfmna
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.HeurC.KVM005.a
XcitiumTrojWare.Win32.Agent.GOM@4ogssq
MicrosoftPWS:Win32/Lolyda!pz
ViRobotTrojan.Win32.A.Zbot.32925
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Spy.Lolyda.B
VaristW32/QQhelper.C.gen!Eldorado
AhnLab-V3Trojan/Win32.OnlineGameHack.R21894
Acronissuspicious
VBA32BScope.TrojanPSW.Gamania
ALYacGeneric.Dacic.C35DC41E.A.9B184257
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RVERSE.SMI
RisingStealer.OnlineGames!1.647F (CLASSIC)
YandexTrojan.GenAsa!HaHx2ZPDxNU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.HI.GEN
FortinetW32/OnLineGames.REV!tr
AVGWin32:Agent-AMTO [Spy]
DeepInstinctMALICIOUS

How to remove PWS:Win32/Lolyda!pz?

PWS:Win32/Lolyda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment