Categories: Malware

BAT/Agent.NQQ removal instruction

The BAT/Agent.NQQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Agent.NQQ virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/Agent.NQQ?


File Info:

crc32: 17AEF1DEmd5: 88e3a7661b64d432e44694187511a902name: 88E3A7661B64D432E44694187511A902.mlwsha1: 90518fa3abac8859dc6fd397db4a36155a8c86b9sha256: fff8a624da8971bb073e77a15592318d1fc1c03275db0c15658ed2719188b6d0sha512: 64d067595cf5916933ed02e80016490583ae454fb477f9ea6b91d29807f914db08aec0d231c1a3fbe97f16dcf06a062bedb08ef6ca7ca0a130e047d96e61a1dbssdeep: 6144:NKg2wV4oLvPh+WdpZglg0TgihDSWULqdylPgO646n5:/2ghLvPhXpe3PlelPgOp6n5type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/Agent.NQQ also known as:

K7AntiVirus Trojan ( 004611b61 )
Lionic Trojan.Win32.RegistryDisabler.4!c
DrWeb BAT.Siggen.85
Cynet Malicious (score: 99)
ALYac Gen:Trojan.RegistryDisabler.aaW@aaaaa
Cylance Unsafe
Alibaba Trojan:BAT/RegistryDisabler.f30fef5f
K7GW Trojan ( 004611b61 )
Cybereason malicious.61b64d
Cyren W32/S-86332536!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 BAT/Agent.NQQ
APEX Malicious
Avast BV:Agent-ASS [Trj]
BitDefender Gen:Trojan.RegistryDisabler.aaW@aaaaa
NANO-Antivirus Trojan.Script.Agent.fmhxnk
MicroWorld-eScan Gen:Trojan.RegistryDisabler.aaW@aaaaa
Tencent Win32.Trojan.Registrydisabler.Edxr
Sophos Mal/Generic-S
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.AdwareLinkury.dh
FireEye Generic.mg.88e3a7661b64d432
Emsisoft Gen:Trojan.RegistryDisabler.aaW@aaaaa (B)
Avira BAT/Agent.mquxw
eGambit Unsafe.AI_Score_69%
Microsoft Trojan:Win32/Wacatac.B!ml
Arcabit Trojan.RegistryDisabler.ED11F2
GData Gen:Trojan.RegistryDisabler.aaW@aaaaa
McAfee Artemis!88E3A7661B64
MAX malware (ai score=89)
TrendMicro-HouseCall TROJ_GEN.R067H0CIO21
Yandex Trojan.BAT.SystemMod.A
Ikarus BAT.Deleter
Fortinet BAT/Agent.NQQ!tr
AVG BV:Agent-ASS [Trj]
Paloalto generic.ml

How to remove BAT/Agent.NQQ?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Fragtor.545276”?

The Fragtor.545276 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Malware.AI.4236857157 removal tips

The Malware.AI.4236857157 is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

How to remove “Win32/AutoRun.VB.ALG”?

The Win32/AutoRun.VB.ALG is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

Win32/Spy.Virkonni.F removal instruction

The Win32/Spy.Virkonni.F is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

Should I remove “Backdoor.Farfli.AH”?

The Backdoor.Farfli.AH is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

Packed.Win32.Klone.ao removal

The Packed.Win32.Klone.ao is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago