Malware

NetTool.Win32.Agent removal

Malware Removal

The NetTool.Win32.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NetTool.Win32.Agent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

kissmeifucan.ddns.net

How to determine NetTool.Win32.Agent?


File Info:

crc32: F22AAC72
md5: 54b91ef161ba1a420d2f8dbfe3b17c36
name: dj.exe
sha1: 32c08c2a727f6f9d999ecfe2c1ad27922666eca6
sha256: bfaf53c942d05021839abda78eee92d681871ebdc6e0038a295b892355391fc8
sha512: 1faea94c0fee5999002029799dd6f91569b31774cf2dde898c522629990a612d748c299d7018409e4e77b7df6615e66156a5bdc55a2eb0a2e0e4fa6483a9e934
ssdeep: 49152:Lu0c++OCvkGs9Fa/8Wywy83823yyrSkO939BWEazoY5urY:KB3vkJ9zWyw3hJr/OB9UN8Y4r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

NetTool.Win32.Agent also known as:

MicroWorld-eScanTrojan.AutoIT.Agent.AAJ
FireEyeGeneric.mg.54b91ef161ba1a42
Qihoo-360Win32/Virus.NetTool.f12
McAfeeArtemis!54B91EF161BA
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.AutoIT.Agent.AAJ
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
F-ProtW32/AutoIt.NS.gen!Eldorado
APEXMalicious
GDataTrojan.AutoIT.Agent.AAJ
Kasperskynot-a-virus:HEUR:NetTool.Win32.Agent.gen
AlibabaTrojan:Win32/AutoitU.ali2000008
AegisLabRiskware.Win32.Agent.1!c
Endgamemalicious (high confidence)
EmsisoftTrojan.AutoIT.Agent.AAJ (B)
F-SecureTrojan.TR/Autoit.dbwlp
DrWebTrojan.DownLoader33.7663
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.moderate.ml.score
SophosTroj/NanoCr-GM
IkarusTrojan.Autoit
CyrenW32/AutoIt.NS.gen!Eldorado
AviraTR/Autoit.dbwlp
MAXmalware (ai score=88)
ArcabitTrojan.AutoIT.Agent.AAJ
ZoneAlarmnot-a-virus:HEUR:NetTool.Win32.Agent.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/AU3.Wacatac.S1079
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FCX
FortinetAutoIt/Injector.EZG!tr
AVGFileRepMalware
Cybereasonmalicious.a727f6
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove NetTool.Win32.Agent?

NetTool.Win32.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment