Spy

How to remove “Spyware:Win32/C2Lop.B”?

Malware Removal

The Spyware:Win32/C2Lop.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware:Win32/C2Lop.B virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ayb.host127-0-0-1.com

How to determine Spyware:Win32/C2Lop.B?


File Info:

crc32: DAD7EAA1
md5: b88b0943d70de9da77a4e92c671df5de
name: B88B0943D70DE9DA77A4E92C671DF5DE.mlw
sha1: cb4f28f09fe137da9cb5a95554a3b5a6ac5cbe01
sha256: dcb90530a55c688d42183829fc3d5432ac1d8c9f567506913ce7bd7283b7cf25
sha512: 8d48fd251623da26e76c0c8b7b65dd83cd299fd09bcc5d3f644249113154b671bf6b171bb0563aef50b3c573261847dd255e6a041e17baeb836509dfa0522aa7
ssdeep: 12288:LeX/iyyQQXRrNEkiV6JCtqrPoont04SW:LeXqyyQOEl6JoqLoce2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Presses Enwajian. All rights reserved.
InternalName: operand
FileVersion: 4, 0, 0, 6
CompanyName: Presses Enwajian
ProductName: Gameco no plioro running
ProductVersion: 4, 0, 0, 6
FileDescription: Ouceusar handler is isho want
OriginalFilename: operand.exe
Translation: 0x0409 0x04b0

Spyware:Win32/C2Lop.B also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Swizzor.2
FireEyeGeneric.mg.b88b0943d70de9da
McAfeeSwizzor.gen.g
CylanceUnsafe
VIPRETrojan.Win32.Swizzor.c (v)
AegisLabTrojan.Win32.Swizzor.4!c
SangforMalware
K7AntiVirusTrojan ( f10003021 )
BitDefenderGen:Variant.Swizzor.2
K7GWTrojan ( f10003021 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/SillyBackdoor.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Swizzor.B!generic
APEXMalicious
AvastWin32:Swizzor
KasperskyTrojan.Win32.Swizzor.d
NANO-AntivirusTrojan.Win32.Swizzor.efseel
RisingTrojan.Generic@ML.97 (RDML:pMk5SQfptydFcOv/7JL4uw)
Ad-AwareGen:Variant.Swizzor.2
EmsisoftGen:Variant.Swizzor.2 (B)
ComodoTrojWare.Win32.TrojanDownloader.Swizzor.Gen@1fy3o0
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader22.21711
ZillyaTrojan.Swizzor.Win32.172910
TrendMicroMal_Swizzor-2
McAfee-GW-EditionBehavesLike.Win32.Swizzor.hc
SophosML/PE-A + Mal/Swizzor-K
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Swizzor.mfe
AviraTR/ATRAPS.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Swizzor
KingsoftWin32.Troj.Swizzor.d.(kcloud)
MicrosoftSpyware:Win32/C2Lop.B
ArcabitTrojan.Swizzor.2
ZoneAlarmTrojan.Win32.Swizzor.d
GDataGen:Variant.Swizzor.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Swizzor.Gen
BitDefenderThetaAI:Packer.A4E51DB220
ALYacGen:Variant.Swizzor.2
VBA32SScope.Trojan.Swizzor
PandaTrj/Swizzor.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Swizzor.NFP
TrendMicro-HouseCallMal_Swizzor-2
TencentWin32.Trojan.Swizzor.Pgmt
YandexTrojan.Swizzor.Gen!Pac.6
IkarusVirus.Trojan.Win32.Obfuscated
FortinetW32/Swizzor.fam!tr
AVGWin32:Swizzor
Cybereasonmalicious.3d70de
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.e79

How to remove Spyware:Win32/C2Lop.B?

Spyware:Win32/C2Lop.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment