Spy

Win32/Spy.VB.OCQ (file analysis)

Malware Removal

The Win32/Spy.VB.OCQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.OCQ virus can do?

  • Unconventionial language used in binary resources: Turkish
  • Anomalous binary characteristics

How to determine Win32/Spy.VB.OCQ?


File Info:

crc32: DD851293
md5: 09d87ac40716815100e0090eb4dd95a3
name: 09D87AC40716815100E0090EB4DD95A3.mlw
sha1: 6ff99408b4900cd236c70838defb91b96aad7246
sha256: 8c183e1d1ca55b8cb8d3dd2a6c99885f00e90376e9eb142e5c8bf5b34a90facc
sha512: 41bb140dba65fb437629767825a8ed4e7f1b25533dfdd2b0e5278da2249cdd9d0929c6df848f11fca8aa45f971f6e074ba12ef4dd3c8b82651ae63675d0acb20
ssdeep: 24576:PRatmGlhfHN6hnRlLmZk6JTNYbHR5Pf2xO96ayy9:PotmGlhHN6hTqk2iLGxU6ayy9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: x130xe1xd3xd8xedxe4
FileVersion: 6.01
CompanyName: Al-Ahdal
Comments: This copy which sent to MSDN library by Abdullah Al-Ahdal
ProductName: MultiMedia Controller
ProductVersion: 6.01
FileDescription: Part from Microsoft Samples
OriginalFilename: x130xe1xd3xd8xedxe4.exe

Win32/Spy.VB.OCQ also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.AVKill.60350
CynetMalicious (score: 85)
ALYacGen:Variant.Ser.Ursu.3205
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.33704
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.d92f2358
K7GWSpyware ( 005052f91 )
K7AntiVirusSpyware ( 005052f91 )
SymantecTrojan Horse
ESET-NOD32Win32/Spy.VB.OCQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Worm.Vobfus-7014260-0
KasperskyTrojan-Ransom.Win32.Blocker.idwj
BitDefenderGen:Variant.Ser.Ursu.3205
NANO-AntivirusTrojan.Win32.Blocker.etswch
MicroWorld-eScanGen:Variant.Ser.Ursu.3205
TencentMalware.Win32.Gencirc.10babc57
Ad-AwareGen:Variant.Ser.Ursu.3205
SophosMal/VB-AQG
ComodoMalware@#3hnbjnwq8fzi3
F-SecureHeuristic.HEUR/AGEN.1107490
BitDefenderThetaGen:NN.ZevbaF.34608.kn3@aaEpSdgO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tc
FireEyeGeneric.mg.09d87ac407168151
EmsisoftGen:Variant.Ser.Ursu.3205 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.bvu
AviraHEUR/AGEN.1107490
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftBackdoor:WinNT/PcClient!rfn
ArcabitTrojan.Ser.Ursu.DC85
ZoneAlarmTrojan-Ransom.Win32.Blocker.idwj
GDataGen:Variant.Ser.Ursu.3205
AhnLab-V3Trojan/Win32.Dynamer.R181168
McAfeeArtemis!09D87AC40716
MAXmalware (ai score=99)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Agent
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!BytWhB8yYRI
IkarusTrojan.Win32.IRCBot
FortinetW32/Injector.CTDO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Win32/Spy.VB.OCQ?

Win32/Spy.VB.OCQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment