Spy

Spyware:Win32/Zbot!mclg information

Malware Removal

The Spyware:Win32/Zbot!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware:Win32/Zbot!mclg virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware:Win32/Zbot!mclg?


File Info:

crc32: 57FC5351
md5: c8d0a6ed0d88df2fbf94cc095f8cef31
name: C8D0A6ED0D88DF2FBF94CC095F8CEF31.mlw
sha1: 0b444641a193d488450bc8cf46e716fb1fa2159f
sha256: 88794602c16bd10bee1ad30610bd288cdb091f82f0453aaec5e32dca79966083
sha512: fb2ffad18e5552fa27c1a25814688e61e9e58ad8293a5559873f3b7caea5b6cf1d4c3379d8c7dae3642bc790a901c14e3fbbbf42cd5acd64b69d5f8350d400a8
ssdeep: 3072:zfeI7HMd8243YHmdD/qy/RXoJwxnLuGvtKkWRpU:zfeILMipyy/RXoJQnL/1Kn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: SLSecurity
InternalName: rds
FileVersion: 6.01
CompanyName: DotNETUpdate
LegalTrademarks: SLSecurity
ProductName: SLSecurity
ProductVersion: 6.01
FileDescription: SLSecurity
OriginalFilename: rds.exe

Spyware:Win32/Zbot!mclg also known as:

K7AntiVirusP2PWorm ( 00073eba1 )
LionicTrojan.Win32.Johnnie.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.TiggreVMF.S22456853
ALYacGen:Variant.Johnnie.264611
CylanceUnsafe
SangforSuspicious.Win32.Johnnie.264611
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Generic.70148abc
K7GWP2PWorm ( 00073eba1 )
Cybereasonmalicious.d0d88d
CyrenW32/Trojan.BSCQ-2349
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.NQU
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderGen:Variant.Johnnie.264611
NANO-AntivirusTrojan.Win32.VB.jcdwxy
MicroWorld-eScanGen:Variant.Johnnie.264611
TencentWin32.Trojan.Johnnie.Tbie
Ad-AwareGen:Variant.Johnnie.264611
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34266.nm0@aGvvmJpi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PH821
McAfee-GW-EditionRDN/Generic.com
FireEyeGeneric.mg.c8d0a6ed0d88df2f
EmsisoftGen:Variant.Johnnie.264611 (B)
AviraHEUR/AGEN.1102282
Antiy-AVLTrojan/Generic.ASMalwS.3463D7D
MicrosoftSpyware:Win32/Zbot!mclg
GDataGen:Variant.Johnnie.264611
McAfeeRDN/Generic.com
MAXmalware (ai score=83)
MalwarebytesMalware.AI.2834914035
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PH821
RisingBackdoor.VB!1.651D (CLASSIC)
YandexTrojan.VB!U7zhboHMCkk
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen

How to remove Spyware:Win32/Zbot!mclg?

Spyware:Win32/Zbot!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment