Spy

Win32/Spy.VB.NGZ removal guide

Malware Removal

The Win32/Spy.VB.NGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.NGZ virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win32/Spy.VB.NGZ?


File Info:

crc32: F6FF13B7
md5: b68d5bdb3f87f138d659e07df2319728
name: B68D5BDB3F87F138D659E07DF2319728.mlw
sha1: 4d772792620b844b19985540747dc000d00176d6
sha256: 790f7abf06311011e3f350bd1a5ce6e55dd178ad8de7035c2ad9425ac7fbc47c
sha512: 0c5b07e62d6f434e02a38fdb3a29639dd393a3f1938803110aa754f09e16da8b73aa589f65bf588309d8debaa6fed2fb56387601f5cd383b17e2068eff974316
ssdeep: 384:bbgGl59EPhZqHmFe/zP9neXPvNuW6af92i0EKP7pK:b8GvQqHm0T9GtuWnh0EKTM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: DataDLL
FileVersion: 12.43.0054
CompanyName: SunCorporation Inc.
Comments: Cj6OFyg
ProductName: Java(TM)UpdateStart
ProductVersion: 12.43.0054
FileDescription: Windows Hizmetleri Ana Bilgisayar x130x15flemi
OriginalFilename: DataDLL.exe

Win32/Spy.VB.NGZ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.47880
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.Elzob.12855
CylanceUnsafe
ZillyaTrojan.Miser.Win32.128
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.18f26c36
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.b3f87f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.VB.NGZ
APEXMalicious
AvastFileRepMalware
ClamAVWin.Dropper.LokiBot-7601662-0
KasperskyTrojan-Ransom.Win32.Blocker.blhy
BitDefenderGen:Variant.Graftor.Elzob.12855
NANO-AntivirusTrojan.Win32.Blocker.fehmgh
ViRobotTrojan.Win32.A.Miser.18955[UPX]
MicroWorld-eScanGen:Variant.Graftor.Elzob.12855
Ad-AwareGen:Variant.Graftor.Elzob.12855
SophosML/PE-A + Mal/VB-TS
ComodoTrojWare.Win32.Miser.B@36gnb2
F-SecureTrojan.TR/Dropper.Gen
BitDefenderThetaAI:Packer.7497DE8320
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R002C0DD521
McAfee-GW-EditionBehavesLike.Win32.Trojan.lc
FireEyeGeneric.mg.b68d5bdb3f87f138
EmsisoftGen:Variant.Graftor.Elzob.12855 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Miser.cu
WebrootW32.Trojan.Miser.Gen
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.18A09D5
MicrosoftTrojan:Win32/Miser.A
ArcabitTrojan.Graftor.Elzob.D3237
AegisLabTrojan.Win32.Miser.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.blhy
GDataGen:Variant.Graftor.Elzob.12855
AhnLab-V3Worm/Win32.VBNA.R13846
McAfeeArtemis!B68D5BDB3F87
VBA32Trojan.VBRA.06839
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallRansom_Blocker.R002C0DD521
RisingTrojan.Miser!1.6766 (CLASSIC)
YandexTrojan.Miser!XmKpg2nee/s
IkarusTrojan.Win32.Miser
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KeyLogger.VBY!tr
AVGFileRepMalware

How to remove Win32/Spy.VB.NGZ?

Win32/Spy.VB.NGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment