Spy

How to remove “Win32/Spy.VB.QQ”?

Malware Removal

The Win32/Spy.VB.QQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.VB.QQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Win32/Spy.VB.QQ?


File Info:

name: 08D9F340475393CEB1C1.mlw
path: /opt/CAPEv2/storage/binaries/94e524c7e72bf798cef6be21a4ab4d93a7a2476037e8c2a41f5e758ad4f40a32
crc32: 04258852
md5: 08d9f340475393ceb1c1fc36cb819db6
sha1: 97bc02cc1305002a8ef7aadf1b44d2f597a133f1
sha256: 94e524c7e72bf798cef6be21a4ab4d93a7a2476037e8c2a41f5e758ad4f40a32
sha512: 56422954a15f28511271a48fd7cd4ecd949e58a10d25f6eff471a6f161ff6a388e773a84611cbb4773604ef029e62b1dbe1925a611755bdf670540e8c19ecb42
ssdeep: 1536:nR8oocJKG88wy6Idiz2lMM1U9/5dxen0KdR91WcOw0OTwH4hWE0f1:bJ3l6Idiz2lnWZG04910O10d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5D3613AFA045019F5A182F53C385A9776481E705285AC27FB81BB4D32B2BD2F5F4B1B
sha3_384: fc1699504cae0e764cc3a6f03905fb0947c6ee93504f0f26cafdd2008a9a34b0e6187b05324cad39568acb67dd9bc390
ep_bytes: 68c82a4000e8f0ffffff000000000000
timestamp: 2007-12-12 02:54:28

Version Info:

Translation: 0x0409 0x04b0
Comments: Surf the Internet.
CompanyName: w.w.w
FileDescription: IE
LegalCopyright: 2008
LegalTrademarks: Trademark (TM)
ProductName: World.Wide Web
FileVersion: 4.03.0002
ProductVersion: 4.03.0002
InternalName: iexplorer
OriginalFilename: iexplorer.exe

Win32/Spy.VB.QQ also known as:

LionicTrojan.Win32.VB.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.im0@XetSTkpi
ClamAVWin.Malware.Xetstkpi-6807698-0
FireEyeGeneric.mg.08d9f340475393ce
McAfeeGenericRXRD-UW!08D9F3404753
CylanceUnsafe
VIPREGen:Trojan.Heur.im0@XetSTkpi
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0000000c1 )
AlibabaTrojanSpy:Win32/NewHeur.c2ba694b
K7GWTrojan ( 0000000c1 )
Cybereasonmalicious.047539
CyrenW32/VB-Wird-based!Maximus
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Spy.VB.QQ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan-Spy.Win32.VB.pi
BitDefenderGen:Trojan.Heur.im0@XetSTkpi
NANO-AntivirusTrojan.Win32.VB.ulsn
AvastWin32:VB-HGH [Spy]
RisingTrojan.Win32.VB.zsl (CLASSIC)
Ad-AwareGen:Trojan.Heur.im0@XetSTkpi
ComodoSuspicious@#31jm1hpr86or6
DrWebBackDoor.Generic.1662
ZillyaTrojan.VB.Win32.2012
McAfee-GW-EditionGenericRXRD-UW!08D9F3404753
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.im0@XetSTkpi (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.im0@XetSTkpi
JiangminTrojanSpy.VB.faw
AviraTR/VB.Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.11C
KingsoftWin32.Heur.KVM006.a.(kcloud)
ArcabitTrojan.Heur.E1E10D
ZoneAlarmTrojan-Spy.Win32.VB.pi
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
GoogleDetected
AhnLab-V3Spyware/Win32.VB.C208316
BitDefenderThetaAI:Packer.D8227AA61C
ALYacGen:Trojan.Heur.im0@XetSTkpi
MAXmalware (ai score=100)
TencentWin32.Trojan-Spy.Vb.Ekjl
YandexTrojan.GenAsa!UIXx9QQU4A8
IkarusTrojan-Spy.Win32.VB.qq
FortinetW32/VB.PI!tr
AVGWin32:VB-HGH [Spy]
PandaTrj/Genetic.gen

How to remove Win32/Spy.VB.QQ?

Win32/Spy.VB.QQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment