Malware

Win32/PSW.Agent.NHG removal

Malware Removal

The Win32/PSW.Agent.NHG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.NHG virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings

How to determine Win32/PSW.Agent.NHG?


File Info:

name: 4616A2374D0066C6EAA4.mlw
path: /opt/CAPEv2/storage/binaries/54da3dc97271ab324ed63509b029f6ba1ee6dd4b9a2b90cecd172f282ea9e05f
crc32: 9790E2CF
md5: 4616a2374d0066c6eaa4dba8cc712c30
sha1: de1b7b36ddc7d2589cf39ad761edbe4986204f55
sha256: 54da3dc97271ab324ed63509b029f6ba1ee6dd4b9a2b90cecd172f282ea9e05f
sha512: 6bf18c1255b07e502c82a6bdb2458ccc17866c6f990b3f66c2534c12274c9662a76ecdd5500be8c81e4270294d76f6ef16df7c50acf520d26363520c950408f1
ssdeep: 12288:aeeFOAHCLrmemh6h9xsvC4+ZOCYMzKWGV3j/QbHq2IVqdqV:aeeF/Hk6phG4+ZOmK5YAeE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4A4231E2243A734F68008F486A81D95ECEE8FCC4C1BCC246B945BDA1F5BD99B52752F
sha3_384: c788d0a19e070ffc0121b0335ba46469bc3c9ce4d042a093bd8e5607ec61bb413fb1e94d3505fd98907eb858fcab4394
ep_bytes: 60be001041008dbe0000ffff5783cdff
timestamp: 2008-03-17 16:24:57

Version Info:

0: [No Data]

Win32/PSW.Agent.NHG also known as:

Elasticmalicious (moderate confidence)
DrWebBackDoor.FireOn
CynetMalicious (score: 100)
FireEyeGeneric.mg.4616a2374d0066c6
CAT-QuickHealWorm.Socks.9031
McAfeeGenericRXAA-FA!4616A2374D00
CylanceUnsafe
VIPRETrojan.Crypt.AI
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004ac0a31 )
K7GWTrojan ( 004ac0a31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.4D873CF91B
VirITTrojan.Win32.Agent.BNP
CyrenW32/Downloader.KOEV-2620
SymantecW32.SillyFDC
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.Agent.NHG
TrendMicro-HouseCallWORM_SOCKS.BL
ClamAVWin.Worm.Socks-9892592-0
KasperskyTrojan-Downloader.Win32.Agent.lnr
BitDefenderTrojan.Crypt.AI
NANO-AntivirusTrojan.Win32.Agent.ppbm
MicroWorld-eScanTrojan.Crypt.AI
AvastWin32:Trojan-gen
Ad-AwareTrojan.Crypt.AI
EmsisoftTrojan.Crypt.AI (B)
ComodoTrojWare.Win32.PSW.Agent.NHG@9w63
BaiduWin32.Trojan-Downloader.Agent.au
ZillyaDownloader.Agent.Win32.66492
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Koceg-A
IkarusTrojan-Downloader.Win32.Small
GDataTrojan.Crypt.AI
JiangminTrojanDownloader.Agent.uuw
AviraTR/Dldr.Agent.agl
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASBOL.84D
ViRobotTrojan.Win32.Downloader.8192.CB
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R42121
VBA32BScope.Backdoor.Socks
ALYacTrojan.Crypt.AI
MalwarebytesGeneric.Worm.Autorun.DDS
APEXMalicious
RisingTrojan.Kryptik!1.BDF5 (CLASSIC)
YandexTrojan.GenAsa!fGxKSHl24x8
SentinelOneStatic AI – Malicious PE
FortinetW32/Socks.NAL!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.74d006
PandaTrj/Genetic.gen

How to remove Win32/PSW.Agent.NHG?

Win32/PSW.Agent.NHG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment