Malware

Win32/Agent.NHD removal instruction

Malware Removal

The Win32/Agent.NHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.NHD virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Agent.NHD?


File Info:

name: B2D5F68DBD48AD7FE1A0.mlw
path: /opt/CAPEv2/storage/binaries/c886d1bc2d684bf7412c5b41066908fad9bf5d9d37862b4575483dbc5a406566
crc32: 01C494E9
md5: b2d5f68dbd48ad7fe1a051579c365b16
sha1: 20aef331259919e508935275fd628170c8802959
sha256: c886d1bc2d684bf7412c5b41066908fad9bf5d9d37862b4575483dbc5a406566
sha512: aa87f4fbfe860736ce4f40a9667c3ae1457d899c45842ddcd4996d76b8130c00ba6e160deb43461f228119b4586a9d91219c1610cf99e7a7c126660d13126487
ssdeep: 3072:M+sEoOscy+upBSau5haEJt0JSHV/mR13bJqeLtZ2SHml+Oz:MxeyTpBpu5hHcJOWJFLtlH4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBF3D107B9F2CC26D940457244F5CB7623BF7AA508D25A07FB906E6E3E363E19D35282
sha3_384: 031e8e2bebdc03c3f7e689d5d5d759f70038460e08cfcc487b6746c5f55fb515755a6eeea66b3e19870eebd516c9df26
ep_bytes: 558bec6aff685881400068303b400064
timestamp: 2006-02-20 22:48:39

Version Info:

0: [No Data]

Win32/Agent.NHD also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Agent.tnHx
DrWebWin32.HLLW.HellSpawn.1
ClamAVWin.Malware.Hellspawn-9957597-0
SkyhighW32/Hellspawn.a
ALYacGen:Trojan.Malware.kqZ@aqa9Vkpi
Cylanceunsafe
ZillyaWorm.Agent.Win32.937
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004e5efb1 )
BitDefenderGen:Trojan.Malware.kqZ@aqa9Vkpi
K7GWTrojan ( 004e5efb1 )
Cybereasonmalicious.125991
ArcabitTrojan.Malware.EB579A
BitDefenderThetaAI:Packer.A46D6EAA1D
VirITWorm.Win32.Agent.VW
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.NHD
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Agent.vw
AlibabaWorm:Win32/Malex.23e67517
NANO-AntivirusTrojan.Win32.HellSpawn.flexbo
ViRobotWorm.Win32.Agent.53248
MicroWorld-eScanGen:Trojan.Malware.kqZ@aqa9Vkpi
AvastWin32:WormX-gen [Wrm]
RisingWorm.Agent!1.694B (CLASSIC)
SophosW32/Malex-J
F-SecureWorm.WORM/Angelus.nxc
BaiduWin32.Worm.Agent.gx
VIPREGen:Trojan.Malware.kqZ@aqa9Vkpi
TrendMicroWORM_HELLPWN.SMD
FireEyeGeneric.mg.b2d5f68dbd48ad7f
EmsisoftGen:Trojan.Malware.kqZ@aqa9Vkpi (B)
IkarusWorm.Win32.Agent
JiangminTrojan.Hesv.cai
WebrootW32.Malware.Gen
GoogleDetected
AviraWORM/Angelus.nxc
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.Agent
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Trojan.Agent.~HHP@1cn809
MicrosoftTrojan:Win32/Malex.gen!E
ZoneAlarmWorm.Win32.Agent.vw
GDataGen:Trojan.Malware.kqZ@aqa9Vkpi
VaristW32/Heuristic-131!Eldorado
AhnLab-V3Worm/Win32.RL_Agent.R305704
McAfeeW32/Hellspawn.a
VBA32BScope.Trojan.Agent
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_HELLPWN.SMD
TencentMalware.Win32.Gencirc.10b66474
YandexTrojan.GenAsa!4vDa0RqnQPo
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Hellspawn.NVW!tr
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.NHD?

Win32/Agent.NHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment