Lolol is a computer worm that spreads via peer-to-peer networks

Worm Lolol spreads through file-sharing networks, mostly through a relatively old platform known as KaZaA. Nonetheless, it can also be spread in different methods, such as infected removable drives or malicious spam emails.
It installs itself to the system and places infected files in shared directories of KaZaA peer-to-peer client. The worm contains a backdoor, which can be used by attackers to control an infected computer remotely. This can be particularly dangerous and result in all kinds of malicious activities on the infected machine, including excessive spying, data theft, spam delivery, other malware infection, and much more.
| Name | Lolol, Worm:Win32/Lolol |
| Type | Computer worm, malware |
| Function | Opens a backdoor on a compromised system and spreads across various system and user files |
| Distribution | Peer-to-peer networks and clients, malicious emails, infected storage devices |
| Removal | Scan your machine with powerful anti-malware software |
| System fix | If you have noticed that your system is crashing, lagging or suffering from similar stability issues, use FortectIntego to repair corrupted files automatically |
The first thing this worm would do is execute itself into the following location on the infected Windows machine:
C:\Windows\System\lExplore.exe
From there, the virus begins its spreading routine – it places 88 of its copies into three different locations of the operating system on Windows. They are:
- C:\Program Files\Kazaa Lite\My Shared Folder
- C:\Program Files\Kazaa\My Shared Folder
- C:\My Downloads.
Once installed, the malicious program would be connected to the mIRC client and be silent, awaiting the commands from the remote host. This way, the attackers can issue various malicious actions to be executed on the infected computer.
It is vital to remove the worm as soon as possible to avoid more serious consequences as a result of its presence. Therefore, you should perform a full system scan with powerful anti-malware software – we recommend using SpyHunterCombo Cleaner. After that, FortectIntego can serve as a great tool to clean your web browsers and fix any system damage that could have been sustained due to the infection.
Worm infection prevention
In order to avoid being infected with worm Lolol, you should be very cautious when visiting various high-risk sites. Do not install or use KaZaA or other peer-to-peer platforms, as it is one of the main malware's distribution channels.
Also, you should never allow malicious spam email attachments to execute commands via the macro function (these attachments typically ask users to “Enable Content”). If you are not sure about an email link or its attachment, you can always use online analysis portals such as Virus Total to ensure that it is not malicious prior to opening it.
Was this guide helpful?
Be the first to comment