Spy

Win32/Spy.VB.NUT removal guide

Malware Removal

The Win32/Spy.VB.NUT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.NUT virus can do?

  • Executable code extraction
  • Sniffs keystrokes
  • Anomalous binary characteristics

How to determine Win32/Spy.VB.NUT?


File Info:

crc32: DAAA59EA
md5: 020b2eee9acc9415678ad63370f9c584
name: 020B2EEE9ACC9415678AD63370F9C584.mlw
sha1: 18981797cc2d2bad5be24d09ec1e42c5f34fd009
sha256: 5333bb8a3f078cba15b1ec32f589077981ec2b370f7962c967adc98f7eac1943
sha512: 6ed4cd856d0c878472400108348024eca51cc4272ed7bd3b21b46a084e74e2d88788785e5b8fb476bfe1a577bf147486af86ee53e41d9317ce16dd9206ade9d4
ssdeep: 192:YfoL0s9JNHJnFskQm3r+NP/I1sbaDmPWxE:Q0/HwkXuXI1eaDmPWxE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft Corp.
InternalName: svhcost
FileVersion: 2.00.0001
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoft Corp.
ProductName: svchost.exe
ProductVersion: 2.00.0001
FileDescription: svchost.exe
OriginalFilename: svhcost.exe

Win32/Spy.VB.NUT also known as:

DrWebTrojan.Bankfraud.1043
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.bm0@XudZxbli
CylanceUnsafe
AlibabaTrojanSpy:Win32/Generic.816dc412
Cybereasonmalicious.e9acc9
CyrenW32/Backdoor.QQCS-2202
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.VB.NUT
APEXMalicious
AvastWin32:ClipBanker-B [Trj]
BitDefenderGen:Trojan.Heur.bm0@XudZxbli
NANO-AntivirusTrojan.Win32.Bankfraud.ctjpob
MicroWorld-eScanGen:Trojan.Heur.bm0@XudZxbli
TencentWin32.Trojan.Keylog.Ud
Ad-AwareGen:Trojan.Heur.bm0@XudZxbli
SophosMal/Generic-S
ComodoMalware@#27synx2audi3r
BitDefenderThetaAI:Packer.C3EA54D81C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
FireEyeGen:Trojan.Heur.bm0@XudZxbli
EmsisoftGen:Trojan.Heur.bm0@XudZxbli (B)
AviraTR/Crypt.FKM.Gen
eGambitUnsafe.AI_Score_82%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Win32.VB.4!c
GDataGen:Trojan.Heur.bm0@XudZxbli
AhnLab-V3Trojan/Win32.Msposer.C255392
McAfeeArtemis!020B2EEE9ACC
MAXmalware (ai score=81)
VBA32TScope.Trojan.VB
TrendMicro-HouseCallTROJ_GEN.R002C0GDB21
RisingTrojan.Keylog!1.9946 (CLOUD)
YandexTrojanSpy.VB!hyQ3SukHkj0
IkarusTrojan.Win32.Spy
FortinetW32/VB.NUT!tr.spy
AVGWin32:ClipBanker-B [Trj]
Qihoo-360Win32/TrojanSpy.ClipBanker.HwMAEpsA

How to remove Win32/Spy.VB.NUT?

Win32/Spy.VB.NUT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment