Spy

Should I remove “Win32/Spy.VB.NMW”?

Malware Removal

The Win32/Spy.VB.NMW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.NMW virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Network activity detected but not expressed in API logs
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Win32/Spy.VB.NMW?


File Info:

crc32: 29D281F2
md5: da7d889c76257019db17e0e5215a4b44
name: DA7D889C76257019DB17E0E5215A4B44.mlw
sha1: 37caf08aa1fa955b16e95b3ca87a036624b74ad5
sha256: d8bb4a8ceee1def734633451261c353c24a60c7e76d5d1081ea0e84d360904af
sha512: 728ed12b61789310e5964b5a8d4440a1ac370ca5cb7b570c05063fec098c19d5d83c040b3fc88c21031f8f97f4c26476a6ce09f04efab689bf594498457f5ac4
ssdeep: 1536:FESpoYEbh5ZH23buKvfE5deCpGF43xS7Yz6Pl8nk:+zZ25GdkzO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
InternalName: entel
FileVersion: 5.00.0002
CompanyName: CaSa
ProductName: Proyecto1
ProductVersion: 5.00.0002
OriginalFilename: entel.exe

Win32/Spy.VB.NMW also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
McAfeeGeneric.dx!DA7D889C7625
CylanceUnsafe
ZillyaTrojan.VB.Win32.100920
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Blocker.dc89e907
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.VB.NMW
APEXMalicious
AvastWin32:Spyware-gen [Spy]
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.auci
NANO-AntivirusTrojan.Win32.VB.bbaann
TencentWin32.Trojan.Blocker.Wstx
SophosML/PE-A + Mal/VBbl-PP
ComodoMalware@#2i4mudmkah6t9
DrWebTrojan.VbCrypt.68
VIPRETrojan.Win32.Generic!BT
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
eGambitGeneric.PSW
ZoneAlarmTrojan-Ransom.Win32.Blocker.auci
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
RisingBackdoor.Volk!1.CB47 (CLASSIC)
YandexTrojan.GenAsa!PZp4/g3K8LY
IkarusTrojan.Win32.Klovbot
FortinetW32/VB.NOP!tr
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml

How to remove Win32/Spy.VB.NMW?

Win32/Spy.VB.NMW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment