Malware

About “Win32/Flooder.Agent.NAS” infection

Malware Removal

The Win32/Flooder.Agent.NAS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Flooder.Agent.NAS virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

vtboss.yolox.net
www.virustotal.com
ddos.dnsnb8.net

How to determine Win32/Flooder.Agent.NAS?


File Info:

crc32: 5E8F24C9
md5: a7de93f2fe27c3853856047cac7b339d
name: A7DE93F2FE27C3853856047CAC7B339D.mlw
sha1: 1f8cd93f2eb2469bb047dff61248292831f95483
sha256: 7e644a01da647f3881398446161c98f4d379e59565d240480df566cfa8dcda9a
sha512: fa7e3ae6cf60599eea3b08d4181691bc16017cb65e684443704827cc236d63cedcce03002689a8a9d9a57d2454d239d6842a595553e28264c120c0aca1fb21da
ssdeep: 768:jd5u7mNGtyVfhfsQGPL4vzZq2oZ7G6x0v0xF2:jd5z/fhvGCq2w7l
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Flooder.Agent.NAS also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.VJadtre.3
FireEyeGeneric.mg.a7de93f2fe27c385
CAT-QuickHealTrojan.Vflooder.P.mue
McAfeeArtemis!A7DE93F2FE27
CylanceUnsafe
VIPRETrojan.Win32.Small.z (v)
SangforMalware
BitDefenderWin32.VJadtre.3
Cybereasonmalicious.2fe27c
TrendMicroPE_WAPOMI.BM
BitDefenderThetaAI:FileInfector.991137D00F
CyrenW32/PatchLoad.E
SymantecW32.Wapomi.C!inf
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Vtflooder-6260355-1
KasperskyVirus.Win32.Nimnul.f
NANO-AntivirusTrojan.Win32.Banload.cstqaj
TencentVirus.Win32.Loader.aab
Ad-AwareWin32.VJadtre.3
TACHYONVirus/W32.Ramnit.C
SophosMal/EncPk-ACE
ComodoVirus.Win32.Wali.KA@558nxg
F-SecureMalware.W32/Jadtre.B
DrWebTrojan.Flood.22061
InvinceaML/PE-A + Mal/EncPk-ACE
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
EmsisoftWin32.VJadtre.3 (B)
AviraW32/Jadtre.B
GridinsoftTrojan.Win32.Gen.sm!s1
ArcabitWin32.VJadtre.3
ZoneAlarmVirus.Win32.Nimnul.f
GDataWin32.VJadtre.3
CynetMalicious (score: 100)
Acronissuspicious
VBA32SScope.Trojan.Flooder.4614
MAXmalware (ai score=87)
ZonerVirus.Win32.23755
ESET-NOD32a variant of Win32/Flooder.Agent.NAS
TrendMicro-HouseCallPE_WAPOMI.BM
RisingTrojan.Patched!1.A9BE (CLASSIC)
YandexPacked/MPress
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Cerbu.207!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.352F.Malware.Gen

How to remove Win32/Flooder.Agent.NAS?

Win32/Flooder.Agent.NAS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment