Malware

What is “PWS:Win32/Lolyda.AA”?

Malware Removal

The PWS:Win32/Lolyda.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lolyda.AA virus can do?

  • Authenticode signature is invalid

How to determine PWS:Win32/Lolyda.AA?


File Info:

name: F9FE5EA72FFAF4A0E4EB.mlw
path: /opt/CAPEv2/storage/binaries/d3f4aa13867d63efca2bc9aa4a60262c8b4983f53de74f6b4d1b9efc31e0d672
crc32: 131DCCEF
md5: f9fe5ea72ffaf4a0e4eb6c13a22eafc5
sha1: 7be3d63729b24796f9167c91fee9fa7ab66f83f3
sha256: d3f4aa13867d63efca2bc9aa4a60262c8b4983f53de74f6b4d1b9efc31e0d672
sha512: 17b52db495bb5b869d4c67a6b8317b0a2c4addb4348e8061095e88135c1237d7577941d751b990baea483143420b825aeb3875e570940557103e1e0450678efd
ssdeep: 768:vlCjPj9prJ/4mYlAT8XIBNgzXlkX2cFEFGpBBQARQkshHAwwo:0PjvpY8FEFGpBBQARm5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C413E727758690F2D3864D36B83E227066FC2237CAB49655EB61D20D3FA56E7D7210C3
sha3_384: 8adf722d3f4e9f5765b7dbf7793917e1c7aa9adf1e10b2bca99c0a446e7b260dcdf53cc0ca61a622f723e8d4bafe8c1a
ep_bytes: 558bec81c4c8feffff60837d0c010f85
timestamp: 2009-02-18 11:38:40

Version Info:

0: [No Data]

PWS:Win32/Lolyda.AA also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.317501
FireEyeGeneric.mg.f9fe5ea72ffaf4a0
CAT-QuickHealTrojan.Onlinegames.17790
SkyhighBehavesLike.Win32.Generic.pm
McAfeeGeneric PWS.jn
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 000ff4001 )
AlibabaTrojanPSW:Win32/OnLineGames.27ab14ca
K7GWTrojan ( 000ff4001 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-PSW.OLGames.ae
VirITTrojan.Win32.OnlineGames.AZHS
SymantecInfostealer.Onlinegame
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.OnLineGames.NRS
APEXMalicious
TrendMicro-HouseCallTROJ_GAMETHI.GGN
AvastWin32:Lolyda [Trj]
ClamAVWin.Trojan.Onlinegames-276
KasperskyTrojan-GameThief.Win32.OnLineGames.akymb
BitDefenderGen:Variant.Barys.317501
NANO-AntivirusTrojan.Win32.OnLineGames.btwwj
TencentTrojan.Win32.Lolyda.aa
EmsisoftGen:Variant.Barys.317501 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.PWS.Wsgame.35655
ZillyaTrojan.OnLineGames.Win32.78993
TrendMicroTROJ_GAMETHI.GGN
Trapminemalicious.high.ml.score
SophosMal/Generic-S
MAXmalware (ai score=100)
JiangminTrojan/PSW.OnLineGames.bmjp
WebrootW32.Trojan.Pws.Onlinegames
GoogleDetected
AviraTR/Spy.Gen
VaristW32/OnlineGames.BQ.gen!Eldorado
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.Undef.a
MicrosoftPWS:Win32/Lolyda.AA
XcitiumTrojWare.Win32.GameThief.MultiFirst.C@f7zvk
ArcabitTrojan.Barys.D4D83D
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.akymb
GDataGen:Variant.Barys.317501
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnlineGameHack.R445
ALYacGen:Variant.Barys.317501
TACHYONTrojan/W32.Small.45056.HW
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/OnLineGames.gen
RisingStealer.OnlineGames!1.6AAC (CLASSIC)
IkarusGeneric.PWS.Games
MaxSecureTrojan.Malware.1124934.susgen
FortinetW32/OnlineGames.HLG!tr.pws
BitDefenderThetaGen:NN.ZedlaF.36802.cu4@aajKV1o
AVGWin32:Lolyda [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:Win/OnLineGames.NRS

How to remove PWS:Win32/Lolyda.AA?

PWS:Win32/Lolyda.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment