Spy

Win32/Spy.VB.NNG removal tips

Malware Removal

The Win32/Spy.VB.NNG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.NNG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Win32/Spy.VB.NNG?


File Info:

name: F2CECBC52937A73914B8.mlw
path: /opt/CAPEv2/storage/binaries/ba1cd6f60f0c4ac728a07a5117a0df293ae33f826d9a3b8e11676f955911dc5b
crc32: 7B902968
md5: f2cecbc52937a73914b89c2406341403
sha1: 4d467b5dd81a0da6341f3c6ccebb85885a8e1cde
sha256: ba1cd6f60f0c4ac728a07a5117a0df293ae33f826d9a3b8e11676f955911dc5b
sha512: 7942538bc51d8cdc61ec04a695c9ed5fbc14ebf46bc5b45df517dbe35056f4243ba69756cb7e02d2a91d2dcbb88d832cb75158f293b44adf6810f6c5b91b5e70
ssdeep: 1536:wbTuifFh8GPLNJ04OotWhmd7xwuc04OLh8GPLNdM:61CgLNm+TdWudhCgLN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188635AE3B7185ED2EA484AB4083E85544A1FBD724440DE4E6ACEFC160FF210769B5E9F
sha3_384: 0acfe58bd902103acba2de550cc1cf8d9a6ed955f9dda4a7f66a6cea180b08067c85a434f18a888087a58d48deb03a25
ep_bytes: 683c6d4000e8eeffffff000000000000
timestamp: 2010-11-13 09:54:37

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Bunga Aria
ProductName: Win32Host
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Win32Host
OriginalFilename: Win32Host.exe

Win32/Spy.VB.NNG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
CAT-QuickHealTrojan.MultiVMF.S21697399
McAfeeArtemis!F2CECBC52937
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.VB.Win32.325021
SangforRiskware.Win32.Agent.ky
AlibabaTrojanSpy:Win32/Generic.e38b27ef
BitDefenderThetaGen:NN.ZevbaF.36318.em0@aiyA6Cli
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.VB.NNG
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.VB.cyouot
AvastWin32:Malware-gen
TencentWin32.Trojan.Agen.Nsmw
F-SecureHeuristic.HEUR/AGEN.1336448
McAfee-GW-EditionBehavesLike.Win32.Infected.km
Trapminesuspicious.low.ml.score
IkarusTrojan-Spy.Agent
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1336448
Antiy-AVLTrojan[Spy]/Win32.VB
XcitiumMalware@#1n5bb8trhq8ql
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32Trojan.Wacatac
MAXmalware (ai score=99)
Cylanceunsafe
RisingMalware.Undefined!8.C (TFE:5:Uu5PoSjtdLE)
YandexTrojan.GenAsa!BbAT+nXzXoY
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.NNG!tr.spy
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Spy.VB.NNG?

Win32/Spy.VB.NNG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment