Malware

Should I remove “Win32/Agent.NFX”?

Malware Removal

The Win32/Agent.NFX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.NFX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Agent.NFX?


File Info:

name: C3D998866D84F3B2F11C.mlw
path: /opt/CAPEv2/storage/binaries/e9b376b0b8328df9db6e1c2ab4fe23ea89d1ca82eae4e94305fc26a151b84b5c
crc32: CD2E779D
md5: c3d998866d84f3b2f11c91328425043b
sha1: 89a41a04c441a7e18437a9dc3c0ac48dc440538b
sha256: e9b376b0b8328df9db6e1c2ab4fe23ea89d1ca82eae4e94305fc26a151b84b5c
sha512: 67abda7e0ca339a7c5ad041758f4439138542d1d559d9faf62ed2abf690ceb0b0a6ab63fd60ec157b5dd8c846ad504e7719d3f41da8a964bc571b60fa4c77bf2
ssdeep: 24576:YFQ17F7rTgtJ/9KyXOCi115LdB/SrjNXbh2NI292y2GO3EtcrjNDqUTiZDYPz4+n:RfZyXa1XWZMTO38cviA4+B/zmnfxC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182B5BF13B682C0F1D64D193414E6673A9E759E431A20CBC3E764ED797C322D1AA3F29E
sha3_384: 4272cdfd7947a927bacee410b7e97da6de95eb6094291f5582a93e0963a657d493eaa6bb176ede60ec45891c584a205e
ep_bytes: 68b7ed5c00e805000000e90669edff55
timestamp: 2023-02-11 20:52:16

Version Info:

CompanyName: HUAJING-QQ
FileDescription: HUAJING-QQ
FileVersion: 199726387
InternalName: 交流群199726387
LegalCopyright: 凶神
OriginalFilename: HUAJING-QQ.exe
ProductName: HUAJING-QQ
ProductVersion: 1.0.0.0
Translation: 0x0804 0x04b0

Win32/Agent.NFX also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.kYJP
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.67361016
ClamAVWin.Malware.Generic-9820446-0
FireEyeGeneric.mg.c3d998866d84f3b2
MalwarebytesTrojan.MalPack.FlyStudio
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b87ea1 )
AlibabaVirus:Win32/FlyStudio.b7f6afe1
K7GWAdware ( 004b87ea1 )
Cybereasonmalicious.4c441a
BitDefenderThetaGen:NN.ZexaF.36250.xw1@a4YMuNlb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.NFX
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.FlyStudio.cqia
BitDefenderTrojan.GenericKD.67361016
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
TencentWin32.Virus.Agent.Vsmw
EmsisoftTrojan.GenericKD.67361016 (B)
VIPRETrojan.GenericKD.67361016
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18JA6Q4
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Generic.D403D8F8
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.cqia
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R480010
Acronissuspicious
McAfeeArtemis!C3D998866D84
VBA32BScope.Trojan.Downloader
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R011H0CF323
RisingVirus.Agent!8.9D (CLOUD)
IkarusTrojan.Win32
FortinetW32/GenKryptik.EHSZ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Agent.NFX?

Win32/Agent.NFX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment