Spy

Win32/Spy.Zbot.ACG removal instruction

Malware Removal

The Win32/Spy.Zbot.ACG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zbot.ACG virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Spy.Zbot.ACG?


File Info:

name: 2CC22AB471C152FC10A1.mlw
path: /opt/CAPEv2/storage/binaries/14a5d49697748905db318a0c7223b4c48665be3033f564ef9cdc70cbb97cb876
crc32: CA56A33A
md5: 2cc22ab471c152fc10a1059e7a9ddf58
sha1: 0989b8aad4c46b15442817ab73dbf32263b02c35
sha256: 14a5d49697748905db318a0c7223b4c48665be3033f564ef9cdc70cbb97cb876
sha512: 3e0fd560271448a0724aab81437899a9e4b2733fd63b0a977803021f4863850fc8ff82aa58345f520bd1e00bb98daeb8757b96d25f2d3f9ce8f10f3b2d777402
ssdeep: 3072:YaMqqDLEMqqDLuW5GGZZTsRA97UHXNTSfTZBxEEhrz1XVpuOj/ix:YJqqDLHqqDLuWYIZTc6sXsbqmnrpuA/4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14604C011B4C08077D0FF1B7188F4777FA7B69B203E248993A36819992E32765962D3DB
sha3_384: 7b98fd27bddd8afa2e1525a3a05776f889ca9599afd27d654025d3870f841e45b0c62b6e773e7745419057c408c15c01
ep_bytes: 558bec8b450883ec645657a308861a01
timestamp: 2014-07-29 08:19:39

Version Info:

0: [No Data]

Win32/Spy.Zbot.ACG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
DrWebDLOADER.Trojan
MicroWorld-eScanGen:Heur.Mint.Dreidel.lqW@y0wVhab
FireEyeGeneric.mg.2cc22ab471c152fc
ALYacGen:Heur.Mint.Dreidel.lqW@y0wVhab
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004b57511 )
K7AntiVirusTrojan ( 004b57511 )
BitDefenderThetaGen:NN.ZexaF.36318.lqW@a0wVhab
CyrenW32/S-04b9d080!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zbot.ACG
APEXMalicious
ClamAVWin.Trojan.Zeus-9733730-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Dreidel.lqW@y0wVhab
NANO-AntivirusTrojan.Win32.Rovnix.dnzilh
AvastSf:Zbot-IB [Trj]
EmsisoftGen:Heur.Mint.Dreidel.lqW@y0wVhab (B)
F-SecureBackdoor.BDS/Backdoor.Gen2
BaiduWin32.Trojan.Rovnix.a
VIPREGen:Heur.Mint.Dreidel.lqW@y0wVhab
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
SophosMal/Behav-010
SentinelOneStatic AI – Malicious PE
AviraBDS/Backdoor.Gen2
MAXmalware (ai score=85)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.Rovnix.D@5s4xlt
ArcabitTrojan.Mint.Dreidel.EAD1A6
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Spy.Zbot.DB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R129791
McAfeePWSZbot-FAJD!2CC22AB471C1
VBA32BScope.Trojan.Inject
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_Xin1
RisingTrojan.Senta!8.66F (TFE:2:yc5DhdnWBCF)
YandexTrojan.GenAsa!g798vaYRons
IkarusTrojan-Downloader.Win32.Spyrov
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rovnix.R!tr
AVGSf:Zbot-IB [Trj]
Cybereasonmalicious.471c15
DeepInstinctMALICIOUS

How to remove Win32/Spy.Zbot.ACG?

Win32/Spy.Zbot.ACG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment