Spy Trojan

How to remove “Trojan.Spy.Lydra.EM”?

Malware Removal

The Trojan.Spy.Lydra.EM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Lydra.EM virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Trojan.Spy.Lydra.EM?


File Info:

name: EFB241FF9109F7601933.mlw
path: /opt/CAPEv2/storage/binaries/179165e5b84dbf167716ac8b522452abb493a93cbbb368c7d8e63f551dd39bdd
crc32: 27A936F9
md5: efb241ff9109f7601933f2e8c3d44fbd
sha1: 8ba96ffa2e175d708706c255d0b5022ce17bf59f
sha256: 179165e5b84dbf167716ac8b522452abb493a93cbbb368c7d8e63f551dd39bdd
sha512: ca77066a08541401817d66890cbabdc94ac2456c5175ddda5566fec731b1d147f3f0d14c163eb72b44f43cd89c813608b2b002c92c2ffd28645f2a948cbac379
ssdeep: 3072:kWX5DzW6x+3a0TL6VVVVVVVVVhbhEEEEEEQVYYYYYYi5zv:kWrxQuVVVVVVVVVhWMF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5E3D08768CF471BEF8DA1BF6308F0CB514A06851A7F582C6CC27BB465BA46BD8944B1
sha3_384: 527cccaae18699fda3e229458284210332107926fb4fadaa4484b5133b93e6674fe1bf9e5950b526db39765120360bd0
ep_bytes: 60be00504100908dbe00c0feffc78790
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Spy.Lydra.EM also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Spy.Lydra.EM
FireEyeGeneric.mg.efb241ff9109f760
CAT-QuickHealTrojan.Upantix.AL3
ALYacTrojan.Spy.Lydra.EM
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005041d61 )
BitDefenderTrojan.Spy.Lydra.EM
K7GWTrojan ( 005041d61 )
Cybereasonmalicious.f9109f
BitDefenderThetaAI:Packer.C6E6E58D1F
CyrenW32/Lydra.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.FKPF
BaiduWin32.Trojan.Kryptik.bcp
ClamAVWin.Packed.Genpack-9795954-0
KasperskyHEUR:Packed.Win32.Upantix.gen
NANO-AntivirusTrojan.Win32.Upantix.ekofiv
APEXMalicious
RisingBackdoor.Simda!8.2D9 (TFE:dGZlOgP8ndxtQSXCOA)
Ad-AwareTrojan.Spy.Lydra.EM
SophosML/PE-A + Mal/EncPk-ANQ
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.39727
ZillyaTrojan.Kryptik.Win32.1153609
McAfee-GW-EditionBehavesLike.Win32.Sytro.cc
EmsisoftTrojan.Spy.Lydra.EM (B)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.Spy.Lydra.EM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upantix.R200892
McAfeePacked-KS!EFB241FF9109
VBA32Malware-Cryptor.General.3
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!AzlNHMcx33A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bundpil.72F8!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Spy.Lydra.EM?

Trojan.Spy.Lydra.EM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment