Malware

How to remove “Win32/Agent.NWI”?

Malware Removal

The Win32/Agent.NWI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.NWI virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

9u9u9.com

How to determine Win32/Agent.NWI?


File Info:

crc32: 6E64B746
md5: 590862bcb0522b495073dfdf01ea6aad
name: 590862BCB0522B495073DFDF01EA6AAD.mlw
sha1: 9b7b9ee6e101e982fa49d627cf92859657954790
sha256: be86aa7f10827afc7c2921f7591af1d8287ef04fcde5ce30ac60a6df1e08c4ff
sha512: fb86c4ae9d44e14a269b181c9cc5a2185cc4a41a7751d6503dbdbf7b935cfc0f4f27e134303b7370bade398ada08a4aa1cad04d6b908a5f929b4882a4b0c6432
ssdeep: 768:MC9fK8ynMJdoyYcjZSyoj/HmOCGteEE/NZRqTKmruVuZl5Ka1NB9YGXGb:MMK8ynMAhHj/HzCoeEmg5iuZaINJW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Agent.NWI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3dd1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.35541
CynetMalicious (score: 100)
CMCGeneric.Win32.590862bcb0!CMCRadar
ALYacTrojan.Rincux.AW
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.18866
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Jukbot.900f0bc8
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.cb0522
CyrenW32/QQhelper.C.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Agent.NWI
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Agent-68675
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Rincux.AW
NANO-AntivirusTrojan.Win32.Agent.sgav
ViRobotBackdoor.Win32.A.Agent.36864.AF[UPX]
MicroWorld-eScanTrojan.Rincux.AW
TencentWin32.Trojan.Spy.Suea
Ad-AwareTrojan.Rincux.AW
SophosMal/Emogen-R
BitDefenderThetaAI:Packer.34C9D1631E
VIPRETrojan.Win32.Generic!SB.0
TrendMicroBKDR_AGENT.MOO
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.590862bcb0522b49
EmsisoftTrojan.Rincux.AW (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.dewy
WebrootW32.Downloader.Gen
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.18633B4
KingsoftWin32.Hack.Agent.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Rincux.AW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Rincux.AW
AhnLab-V3Trojan/Win32.Agent.C102714
Acronissuspicious
McAfeeArtemis!590862BCB052
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
TrendMicro-HouseCallBKDR_AGENT.MOO
RisingBackdoor.Small!1.66ED (CLASSIC)
YandexTrojan.GenAsa!CnRyGDiCe8A
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.OZS!tr
AVGFileRepMalware

How to remove Win32/Agent.NWI?

Win32/Agent.NWI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment