Backdoor

Backdoor.Win32.LolBot removal tips

Malware Removal

The Backdoor.Win32.LolBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.LolBot virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Backdoor.Win32.LolBot?


File Info:

name: 22EB96D1076F3E9F567A.mlw
path: /opt/CAPEv2/storage/binaries/e8c1b3daa0adb0779099af1f48af1b5148d181c5221224bd016962e153131315
crc32: 5C153C07
md5: 22eb96d1076f3e9f567a17570abd36ba
sha1: 1bd78bcd6f518199534250737a255774f9246e45
sha256: e8c1b3daa0adb0779099af1f48af1b5148d181c5221224bd016962e153131315
sha512: 2080a978a29b8626428f60789d312286c90bc9a55738d8ceca3ffffc412c0b7da5c3c043a3c177d2c1cbdfc9436304f8941c802a8e3231ce24dfe1405af2c836
ssdeep: 1536:9RsvcdCQjosnvnjs6SQ1EVrPdDG/PEzxVJsPcbYDOYrmwd8eCwe5cJ45:LsKjRvnhSGYB0EzXJsPcEDOHDzF555
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9346D2773410772D3810271370E1AE5B72AEE76222AF5A1E274F01D3773EA9977A391
sha3_384: 167e57e0d5fd4de4bc3668771649b26532d1b4e43a39f2bd1cd5adec5e3258e272f6be560f082e963cedfdea69765be7
ep_bytes: 5589e56aff68e4b54000684859400064
timestamp: 1994-04-19 11:14:40

Version Info:

0: [No Data]

Backdoor.Win32.LolBot also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.94923
FireEyeGeneric.mg.22eb96d1076f3e9f
SkyhighBehavesLike.Win32.Backdoor.dz
ALYacTrojan.GenericKDZ.94923
Cylanceunsafe
VIPRETrojan.GenericKDZ.94923
SangforTrojan.Win32.Save.a
BitDefenderTrojan.GenericKDZ.94923
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Agent.apt
VirITBackdoor.Win32.LolBot.RO
SymantecW32.Griptolo
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.RTF
APEXMalicious
ClamAVWin.Packed.Iho3wxi-10012347-0
KasperskyBackdoor.Win32.LolBot.gen
NANO-AntivirusTrojan.Win32.LolBot.cqyqex
RisingWorm.Win32.FakeFolder.ak (CLASSIC)
SophosW32/Clovis-A
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader5.5739
ZillyaTrojan.Agent.Win32.3740827
TrendMicroWORM_DUPTWU.SMIA
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94923 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
JiangminBackdoor/LolBot.ic
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/LolBot.E.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.LolBot
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/FakeFolder.AA!MTB
XcitiumBackdoor.Win32.LolBot.GB@48x7ig
ArcabitTrojan.Generic.D172CB
SUPERAntiSpywareTrojan.Agent/Gen-LolBot
ZoneAlarmBackdoor.Win32.LolBot.gen
GDataWin32.Worm.Ganelp.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.Duptwu.C5521988
McAfeeBackDoor-FAI.a
DeepInstinctMALICIOUS
VBA32Backdoor.LolBot
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Ircbot.DAC.worm
ZonerTrojan.Win32.32428
TrendMicro-HouseCallWORM_DUPTWU.SMIA
TencentTrojan.Win32.Agent.fk
IkarusTrojan.SuspectCRC
FortinetW32/Rbot.GQG!tr
BitDefenderThetaGen:NN.ZexaF.36792.o8Z@aeQ@Vdki
AVGWin32:Rbot-GQG [Trj]
Cybereasonmalicious.d6f518
AvastWin32:Rbot-GQG [Trj]

How to remove Backdoor.Win32.LolBot?

Backdoor.Win32.LolBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment