Malware

Should I remove “Win32/PSW.Agent.NHI”?

Malware Removal

The Win32/PSW.Agent.NHI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Agent.NHI virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Win32/PSW.Agent.NHI?


File Info:

name: C04C5317EE40A9376D9C.mlw
path: /opt/CAPEv2/storage/binaries/79908e1258faaf8b6a4a22994ff53a08c0cf5d11cacb0291cfa5adc814b33ee4
crc32: 765E249D
md5: c04c5317ee40a9376d9cecf5a85cf396
sha1: edaa53ccd6aa10dcf9d6e5efbdd946fa763d32f2
sha256: 79908e1258faaf8b6a4a22994ff53a08c0cf5d11cacb0291cfa5adc814b33ee4
sha512: 4dc0d6eb8fd5ee33648dbfc2a3d423ade819a8b83b9328a92807e1c83a9153a52dd3fcdfd519db584b31efb68479d7cab2a6ea5ddc30db96ff07f040d15e2dc0
ssdeep: 1536:cG9obwc+/5hX1m/d4w5n2ThA3+RNexPnyAqTnfnfllgI+ntU5OOgD6:clbwc+/5hGp5n2ThWsNexPnCrnfbgbnc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D73027A07025A63F89039735B9F807956F9A3504EDBF7D042D6B3BB8CB9D4251C8B44
sha3_384: adc49c788a231c4e710872e66e50d76696333e51fce6a3b12696f2fec7250d01b140523809af29ce4620020713828a24
ep_bytes: 60be00b040008dbe0060ffff5783cdff
timestamp: 2008-03-30 15:20:09

Version Info:

0: [No Data]

Win32/PSW.Agent.NHI also known as:

tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Crypt.EJ
CAT-QuickHealTrojan.Toga.26581
ALYacTrojan.Crypt.EJ
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 000345c61 )
K7GWPassword-Stealer ( 000345c61 )
Cybereasonmalicious.7ee40a
ArcabitTrojan.Crypt.EJ
BaiduWin32.Trojan-PSW.Agent.e
VirITTrojan.Win32.Agent.BME
CyrenW32/Socks.B.gen!Eldorado
SymantecW32.Mandaph
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/PSW.Agent.NHI
APEXMalicious
ClamAVWin.Worm.Socks-9892592-0
KasperskyWorm.Win32.Socks.au
BitDefenderTrojan.Crypt.EJ
NANO-AntivirusTrojan.Win32.Socks.wsiw
SUPERAntiSpywareWorm.Socks
AvastWin32:Socks-L [Wrm]
TencentMalware.Win32.Gencirc.10b077e2
Ad-AwareTrojan.Crypt.EJ
EmsisoftTrojan.Crypt.EJ (B)
ComodoTrojWare.Win32.PSW.Agent.NHI@dcdc
F-SecureWorm.WORM/Socks.AU.166
DrWebTrojan.DownLoader.56630
ZillyaWorm.Socks.Win32.13
TrendMicroWORM_SOCKS.EA
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
FireEyeGeneric.mg.c04c5317ee40a937
SophosML/PE-A + W32/Socks-H
SentinelOneStatic AI – Malicious PE
JiangminWorm/Socks.t
AviraWORM/Socks.AU.166
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.9947BE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotWorm.Win32.Socks.7680
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Crypt.EJ
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R2364
McAfeegeneric!bg.eky
VBA32SScope.Worm.Socks.afv
MalwarebytesGeneric.Trojan.Dropper.DDS
TrendMicro-HouseCallWORM_SOCKS.EA
RisingWorm.Socks!1.C134 (RDMK:cmRtazrxIFSLCJwmZ6qsM/q2o72W)
YandexTrojan.GenAsa!+24XGDb3mMA
IkarusTrojan-Downloader.Win32.Small
MaxSecureWorm.Socks
FortinetHeuri.D
BitDefenderThetaAI:Packer.79E6D8FC1A
AVGWin32:Socks-L [Wrm]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.Agent.NHI?

Win32/PSW.Agent.NHI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment