Malware

BAT/Agent.NQQ removal instruction

Malware Removal

The BAT/Agent.NQQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Agent.NQQ virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/Agent.NQQ?


File Info:

crc32: 17AEF1DE
md5: 88e3a7661b64d432e44694187511a902
name: 88E3A7661B64D432E44694187511A902.mlw
sha1: 90518fa3abac8859dc6fd397db4a36155a8c86b9
sha256: fff8a624da8971bb073e77a15592318d1fc1c03275db0c15658ed2719188b6d0
sha512: 64d067595cf5916933ed02e80016490583ae454fb477f9ea6b91d29807f914db08aec0d231c1a3fbe97f16dcf06a062bedb08ef6ca7ca0a130e047d96e61a1db
ssdeep: 6144:NKg2wV4oLvPh+WdpZglg0TgihDSWULqdylPgO646n5:/2ghLvPhXpe3PlelPgOp6n5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/Agent.NQQ also known as:

K7AntiVirusTrojan ( 004611b61 )
LionicTrojan.Win32.RegistryDisabler.4!c
DrWebBAT.Siggen.85
CynetMalicious (score: 99)
ALYacGen:Trojan.RegistryDisabler.aaW@aaaaa
CylanceUnsafe
AlibabaTrojan:BAT/RegistryDisabler.f30fef5f
K7GWTrojan ( 004611b61 )
Cybereasonmalicious.61b64d
CyrenW32/S-86332536!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/Agent.NQQ
APEXMalicious
AvastBV:Agent-ASS [Trj]
BitDefenderGen:Trojan.RegistryDisabler.aaW@aaaaa
NANO-AntivirusTrojan.Script.Agent.fmhxnk
MicroWorld-eScanGen:Trojan.RegistryDisabler.aaW@aaaaa
TencentWin32.Trojan.Registrydisabler.Edxr
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.dh
FireEyeGeneric.mg.88e3a7661b64d432
EmsisoftGen:Trojan.RegistryDisabler.aaW@aaaaa (B)
AviraBAT/Agent.mquxw
eGambitUnsafe.AI_Score_69%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.RegistryDisabler.ED11F2
GDataGen:Trojan.RegistryDisabler.aaW@aaaaa
McAfeeArtemis!88E3A7661B64
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R067H0CIO21
YandexTrojan.BAT.SystemMod.A
IkarusBAT.Deleter
FortinetBAT/Agent.NQQ!tr
AVGBV:Agent-ASS [Trj]
Paloaltogeneric.ml

How to remove BAT/Agent.NQQ?

BAT/Agent.NQQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment