Spy

Win32/Spy.Lydra information

Malware Removal

The Win32/Spy.Lydra is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Lydra virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Win32/Spy.Lydra?


File Info:

name: 0C47AC490901422B5085.mlw
path: /opt/CAPEv2/storage/binaries/9282b1f4e35c8b4eecce2b98e7f2de0f14082792f03b9ed083428283da056550
crc32: 1CF6D206
md5: 0c47ac490901422b508596c18b564cb9
sha1: 0019659d0f6a7c5e4888110211d9dace01242503
sha256: 9282b1f4e35c8b4eecce2b98e7f2de0f14082792f03b9ed083428283da056550
sha512: 62fd94ef4464a8cd95d6ba7b3fe21cb56e787519523d09f09cf00989ca295a2312e01471248bcb2503735c77b217ff08e81ddadfb00cf5aa7316d759e623111f
ssdeep: 1536:ULqlQMjurZeH1K/Gy97KJCZBwu91ungxK6FEMMcC/jmyN1WJ1rkWmngFSpKKMf5H:pZjurA1K+w7KMuu1F+/jmSkmngV5CvMX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174B35A76F481D77AE02704FA7E4EE3E42AE8B5304FA21C73B2D65F4C887819269595C3
sha3_384: 8987958290290b556018aabae79d8dd7a1e5d722fc8c5245e1cd50bca9e193b465875427a4dc71ba7d0be16e98426609
ep_bytes: 558bec83c4e85333c08945ec8945e8b8
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Lydra also known as:

BkavW32.FamVT.LydraK.Trojan
MicroWorld-eScanTrojan.GenericKDZ.96538
FireEyeGeneric.mg.0c47ac490901422b
CAT-QuickHealTrojan.Generic.20804
SkyhighBehavesLike.Win32.SpywareLyndra.ch
ALYacTrojan.GenericKDZ.96538
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0000b1001 )
K7GWSpyware ( 0000b1001 )
Cybereasonmalicious.d0f6a7
BitDefenderThetaAI:Packer.7AFE6C291F
VirITTrojan.Win32.Generic.ABL
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Lydra
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Lydra.aamt
BitDefenderTrojan.GenericKDZ.96538
NANO-AntivirusTrojan.Win32.Lydra.epztwa
TencentTrojan.Win32.Fednu.a
EmsisoftTrojan.GenericKDZ.96538 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.Siggen1.39299
VIPRETrojan.GenericKDZ.96538
Trapminemalicious.high.ml.score
SophosTroj/Lydra-Gen
IkarusTrojan.Win32.Buzus
JiangminTrojanSpy.Lydra.kp
GoogleDetected
AviraTR/Spy.Gen
Antiy-AVLTrojan[Spy]/Win32.Lydra
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanSpy.Lydra.~v001@1qupho
ArcabitTrojan.Generic.D1791A
ZoneAlarmTrojan-Spy.Win32.Lydra.aamt
GDataWin32.Trojan.PSE.1EJY54W
VaristW32/Lydra.D.gen!Eldorado
AhnLab-V3Win-Trojan/Agent.108088
Acronissuspicious
VBA32BScope.Trojan.Renamer
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Lydra.AR
ZonerTrojan.Win32.36820
TrendMicro-HouseCallTROJ_LYDRA.SMA
RisingTrojan.Win32.Fednu.beq (CLASSIC)
YandexTrojan.GenAsa!oZQ8UvGEpfc
SentinelOneStatic AI – Malicious PE
MaxSecureSpy.Lydra.aamt
FortinetW32/LYDRA.SMB!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.Lydra?

Win32/Spy.Lydra removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment