Spy

Win32/Spy.Agent.NYB removal tips

Malware Removal

The Win32/Spy.Agent.NYB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.NYB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Spy.Agent.NYB?


File Info:

name: C4D630E32D9D0F0BD8D9.mlw
path: /opt/CAPEv2/storage/binaries/58e5b9a60bef851c10ee17e46e0abdbab19a8685eafddedb2e7d3261e6a358d3
crc32: 8B7E03FC
md5: c4d630e32d9d0f0bd8d9d1ef380b5f57
sha1: b606707578b090b566d842bf85f60b2f2c677965
sha256: 58e5b9a60bef851c10ee17e46e0abdbab19a8685eafddedb2e7d3261e6a358d3
sha512: 171f4c5e53b335a5c91f5347bb9d4173a3468689bd15bfb3207caa0cbb14a327c73b76331f8a8bcd1b30d262b31ea6a7479b90ebf3fbee67924a939149c189d3
ssdeep: 6144:o6C5AXbMn7UI1FoV2gwTBlrIckPJYYYYYYYYYYYYE:o6RI1Fo/wT3cJYYYYYYYYYYYYE
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11E35F7C211D43095E4F3283A94A5BA57FE67EEB17CF88217025E4ECDC653E83B6A5B04
sha3_384: 54ccf0e25cab779b244b7622e2a28ab9d7bd1428e4a9ed5cf5529ff2b45146647771d43c4e1a164b09f586ee8b13623a
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2011-03-17 08:58:08

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Uniscribe Unicode script processor
FileVersion: 1.0420.2600.5512 (xpsp.080413-2105)
InternalName: Uniscribe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Uniscribe
ProductName: Microsoft(R) Uniscribe Unicode script processor
ProductVersion: 1.0420.2600.5512
Translation: 0x0409 0x04b0

Win32/Spy.Agent.NYB also known as:

BkavW32.AIDetectMalware
AVGWin32:Yunsip-A [Wrm]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.38816663
CAT-QuickHealTrojanPWS.Yunsip.A5
SkyhighBehavesLike.Win32.PWSYunsip.tz
ALYacTrojan.GenericKD.38816663
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.130937
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00060f0b1 )
K7AntiVirusTrojan ( 00060f0b1 )
BaiduWin32.Trojan.Agent.amh
VirITTrojan.Win32.Agent.AMYE
SymantecW32.Yunsip
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Agent.NYB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Yunsip-1
KasperskyTrojan-Spy.Win32.Agent.bqme
BitDefenderTrojan.GenericKD.38816663
NANO-AntivirusTrojan.Win32.Agent.vkmvm
SUPERAntiSpywareTrojan.Agent/Gen-Yunsip
AvastWin32:Yunsip-A [Wrm]
TencentTrojan.Win32.FakeMS.tpd
EmsisoftTrojan.GenericKD.38816663 (B)
F-SecureTrojan.TR/PSW.Yunsip.axyza
DrWebTrojan.PWS.Spy.20069
VIPRETrojan.GenericKD.38816663
TrendMicroWORM_YUNSIP.SMR
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c4d630e32d9d0f0b
SophosMal/YunSip-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.bhxd
VaristW32/Redosdru.B.gen!Eldorado
AviraTR/PSW.Yunsip.axyza
MAXmalware (ai score=81)
Antiy-AVLTrojan[PSW]/Win32.Yunsip.a
MicrosoftPWS:Win32/Yunsip!pz
XcitiumTrojWare.Win32.TrojanSpy.Agent.ny@4pn6tf
ArcabitTrojan.Generic.D2504B97
ViRobotTrojan.Win32.Agent.131072.BJ
ZoneAlarmTrojan-Spy.Win32.Agent.bqme
GDataWin32.Trojan-Stealer.Yunsip.A
GoogleDetected
AhnLab-V3Trojan/Win32.Infostealer.R758
Acronissuspicious
McAfeePWS-Yunsip.gen.a
VBA32TrojanSpy.Agent
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallWORM_YUNSIP.SMR
RisingTrojan.Usp10Hijack!1.998B (CLASSIC)
YandexTrojan.GenAsa!LogooVIKaNc
IkarusTrojan.Spy.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.NYB!tr
BitDefenderThetaGen:NN.ZedlaF.36802.bv@@a05rPXji
DeepInstinctMALICIOUS
alibabacloudPWS:Win/Yunsip.ed49dde8

How to remove Win32/Spy.Agent.NYB?

Win32/Spy.Agent.NYB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment