Malware

Should I remove “Win32/Flyagent.NGZ”?

Malware Removal

The Win32/Flyagent.NGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Flyagent.NGZ virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Flyagent.NGZ?


File Info:

crc32: 28A4E1BE
md5: cff71da55035fcc84bdd0441cfae7786
name: CFF71DA55035FCC84BDD0441CFAE7786.mlw
sha1: ee55e057d4cd526d21093505dbe59f282123d785
sha256: 604f52d59cd107b912faa4d006109ce42ab86b1a227ae1361b1ba37263e5ed03
sha512: 8ea4007de1d4ceb0861384d99334c969fbb079f72c086c5a9de2908b55eb7bf0efebf1101e29a2b0502bd1a32cb45860221488186179b640e68df81a83477552
ssdeep: 24576:veunxXNtHy5+wXby/hH5Kp3iOCPQVSsnr4TK:v3xNBwXb6hZKKPQg2sK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ? 2008 Advanced Micro Devices, Inc.
InternalName: CLIStart
FileVersion: 3.5.0.0
CompanyName: Advanced Micro Devices, Inc.
ProductName: Catalyst? Control Center
ProductVersion: 3.5.0.0
FileDescription: Catalyst? Control Center Launcher
OriginalFilename: CLIStart.exe
Translation: 0x0804 0x04b0

Win32/Flyagent.NGZ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72423
CAT-QuickHealHacktool.Flystudio.16558
Qihoo-360HEUR/QVM07.1.0B1B.Malware.Gen
McAfeeGenericRXBN-SB!CFF71DA55035
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.GenericKDZ.72423
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.55035f
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Flyagent.NGZ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Vimditator.gen
NANO-AntivirusTrojan.Win32.Banbra.dnbbrb
TencentWin32.Trojan.Vimditator.Tetb
Ad-AwareTrojan.GenericKDZ.72423
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
DrWebTrojan.Replacer.1
ZillyaTrojan.Banbra.Win32.22701
TrendMicroTROJ_GEN.R035C0PB321
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.cff71da55035fcc8
EmsisoftTrojan.GenericKDZ.72423 (B)
IkarusTrojan.Win32.MBRlock
JiangminTrojan.Generic.eiwgq
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojanDownloader:Win32/Emotet!ml
ArcabitTrojan.Generic.D11AE7
ZoneAlarmHEUR:Trojan.Win32.Vimditator.gen
GDataWin32.Packed.PSE.1RYG8S7
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanBanker.Banbra
ALYacTrojan.GenericKDZ.72423
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R035C0PB321
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqlWJkA394Vp17dJrabmwyp)
YandexTrojan.GenAsa!b+RJocxRF90
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.B9965!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Flyagent.NGZ?

Win32/Flyagent.NGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment