Adware

Win32/Adware.Agent.NUT removal guide

Malware Removal

The Win32/Adware.Agent.NUT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Agent.NUT virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.Agent.NUT?


File Info:

name: 28CC98253A2A24A0794C.mlw
path: /opt/CAPEv2/storage/binaries/d0687e7b33094aab3a06af2619114c3df5e56bbb39a09d91de191cbca56cac0f
crc32: 07A3F3A6
md5: 28cc98253a2a24a0794c0f96d8129297
sha1: cc8fb565b8edc7009a59be2c004c116f3ddbf577
sha256: d0687e7b33094aab3a06af2619114c3df5e56bbb39a09d91de191cbca56cac0f
sha512: 486988857244e7d3faac685aa8427d976f50b449a1a75a0076e25891c357000d52aeff1331692e4de71fc7142be6be33ad351c1f09efc7766917ba118f34428f
ssdeep: 3072:EgXdZt9P6D3XJeeDCnn7OQ4zrVe6wytfBib9GltYTuKfueejHvLy+en:Ee34gnn7eXw6waEbIltYT6NzLy+q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C24020B79C66876C9C643320AB2F73AF3F69FFD424121934FE41FAB7A610AB0516185
sha3_384: 6778c8faa5bea69a100159fca12d2770846c0499e288b34638c89f28bb7a12bb2d9685974a30b35104351d860c3f61d0
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Win32/Adware.Agent.NUT also known as:

BkavW32.AIDetect.malware2
LionicAdware.NSIS.Relevant.2!c
Elasticmalicious (high confidence)
FireEyeAdware.GenericKD.38125461
ALYacAdware.GenericKD.38125461
ZillyaAdware.Relevant.Win32.2087
Cybereasonmalicious.5b8edc
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Adware.Agent.NUT
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Relevant.gen
BitDefenderAdware.GenericKD.38125461
MicroWorld-eScanAdware.GenericKD.38125461
AvastNSIS:AdwareX-gen [Adw]
Ad-AwareAdware.GenericKD.38125461
EmsisoftAdware.GenericKD.38125461 (B)
DrWebAdware.Relevant.193
McAfee-GW-EditionBehavesLike.Win32.PUP.dc
SophosGeneric PUA MM (PUA)
SentinelOneStatic AI – Suspicious PE
GDataAdware.GenericKD.38125461
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3PUP/Win32.Helper.R349644
McAfeeArtemis!28CC98253A2A
MAXmalware (ai score=64)
MalwarebytesMalware.AI.4041066520
TrendMicro-HouseCallTROJ_GEN.R002H07KQ21
FortinetAdware/NSIS.AGENT.NUT
AVGNSIS:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Adware.Agent.NUT?

Win32/Adware.Agent.NUT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment