Malware

Should I remove “PWS:Win32/Lolyda!pz”?

Malware Removal

The PWS:Win32/Lolyda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lolyda!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Lolyda!pz?


File Info:

name: 07BA14555B79C0A1905E.mlw
path: /opt/CAPEv2/storage/binaries/5a9145e0c20a3570f61ef66e057976a97b7c4501e998bec5ee4edea89744a3ec
crc32: 29280B87
md5: 07ba14555b79c0a1905edeea5a14cf46
sha1: 88c7ed6916a0ffd092a4f37923ffa6e7eade636d
sha256: 5a9145e0c20a3570f61ef66e057976a97b7c4501e998bec5ee4edea89744a3ec
sha512: c496b3b7c9529f6d0a4a3595a4bd0bda1b67786e04fe3a608bee3b8b3a3ec0760b0140bcad97642f1c9b59999aa54cc7ded7e42a17a67fe891c97995e1c18f7f
ssdeep: 768:00G1WZzEt5MGOtVfTW6K7EWeChW0mPztjQrH15wHYV+tqyXM:0oqMGOvfThUElChWXhjCH15GYV+tRXM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195F2D048EAEC54E1F23EAEBC57F7A637E2607D68B75CEB1F1340416E19340966B50811
sha3_384: c9a4dea97fe3dfe9d89fb50d343edf29271bbed264aacc32dacd52f69eb25fe780589f687c7b88ccdc92734d732880a5
ep_bytes: 60be00d040008dbe0040ffff5783cdff
timestamp: 2033-06-15 13:26:27

Version Info:

CompanyName:
FileDescription: DlgServer Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: DlgServer
LegalCopyright: 版权所有 (C) 2011
LegalTrademarks:
OriginalFilename: DlgServer.EXE
ProductName: DlgServer 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

PWS:Win32/Lolyda!pz also known as:

LionicTrojan.Win32.Generic.lq5E
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Generic.Dacic.C35DC41E.A.402F9702
FireEyeGeneric.mg.07ba14555b79c0a1
CAT-QuickHealTrojan.LolydaPMF.S31006844
SkyhighGeneric PWS.vv
McAfeeGeneric PWS.vv
MalwarebytesMachineLearning/Anomalous.100%
VIPREDropped:Generic.Dacic.C35DC41E.A.402F9702
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 000250261 )
AlibabaTrojanPSW:Win32/Lolyda.19a7b182
K7GWPassword-Stealer ( 000250261 )
ArcabitGeneric.Dacic.C35DC41E.A.402F9702
BaiduWin32.Trojan-Dropper.Dycler.a
VirITTrojan.Win32.OLG.CCDO
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.OnLineGames.PIR
APEXMalicious
ClamAVWin.Malware.Onlinegames-7647999-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDropped:Generic.Dacic.C35DC41E.A.402F9702
NANO-AntivirusTrojan.Win32.SchoolBoy.hhxhyl
AvastWin32:Trojan-gen
TencentWin32.Trojan.Psw.Fajl
EmsisoftDropped:Generic.Dacic.C35DC41E.A.402F9702 (B)
F-SecureTrojan.TR/PSW.Lolyda.BY
DrWebTrojan.PWS.Gamania.30164
ZillyaTrojan.OnLineGames.Win32.103252
TrendMicroTROJ_RVERSE.SMI
Trapminemalicious.moderate.ml.score
SophosTroj/Vakooja-Q
IkarusTrojan-GameThief.Win32.OnLineGames
JiangminTrojan/Generic.vksb
WebrootW32.Infostealer.Onlinegames.Gen
GoogleDetected
AviraTR/PSW.Lolyda.BY
VaristW32/Agent.JT.gen!Eldorado
Antiy-AVLTrojan[GameThief]/Win32.Frethoq
Kingsoftmalware.kb.b.905
XcitiumTrojWare.Win32.PSW.GamePass.AHD@4l3ra2
MicrosoftPWS:Win32/Lolyda!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDropped:Generic.Dacic.C35DC41E.A.402F9702
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnlineGameHack.R3318
VBA32BScope.Trojan.Dynamer
ALYacDropped:Generic.Dacic.C35DC41E.A.402F9702
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RVERSE.SMI
RisingStealer.OnLineGames!1.65EB (CLOUD)
YandexTrojan.PWS.OnLineGames!1d6wiNO82LE
SentinelOneStatic AI – Suspicious PE
FortinetW32/OnLineGames.SMI!tr
BitDefenderThetaGen:NN.ZexaF.36744.cmKfa0BPfKlb
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove PWS:Win32/Lolyda!pz?

PWS:Win32/Lolyda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment