Malware

Should I remove “BAT/Disabler.NCZ”?

Malware Removal

The BAT/Disabler.NCZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Disabler.NCZ virus can do?

  • Attempts to modify Internet Explorer’s start page
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Attempts to disable System Restore
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

How to determine BAT/Disabler.NCZ?


File Info:

crc32: B1C36106
md5: 7e1d61cec03a7705d370884dbcc4e5d5
name: 7E1D61CEC03A7705D370884DBCC4E5D5.mlw
sha1: 99cc263e3ada58b6ef4b90c0a67e52daa4d6dad2
sha256: f18c0fcc2250f6ef324f1283ea517cd2f60369b49dfd542d941809f111a2b506
sha512: 90b3d14a10812c55d40e1acaff9857256ba3b21641ffd6a6b39522d45bb67dfd047dd8fc20667c839069f8e6f0b8aec1d12597c6c2b27f2bf834bd398b3ad21c
ssdeep: 3072:yzFfHgTWmCRkGbKGLeNTBfmD0BoO446D0oBdogHauqJV:w5aWbksiNTBurO4TD0oBdfHD8
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6eafx6c50x6f6e
InternalName: x6eafx6c50x6f6e
FileVersion: 0.0.0.0
CompanyName: x6eafx6c50x6f6e
PrivateBuild: x6eafx6c50x6f6e
LegalTrademarks: x6eafx6c50x6f6e
Comments: x6eafx6c50x6f6e
ProductName: x6eafx6c50x6f6e
SpecialBuild: x6eafx6c50x6f6e
ProductVersion: 0.0.0.0
FileDescription: x6eafx6c50x6f6e
OriginalFilename: x6eafx6c50x6f6e
Translation: 0x0000 0x04e4

BAT/Disabler.NCZ also known as:

K7AntiVirusTrojan ( 005622641 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.42833397
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.be7957f1
K7GWTrojan ( 005622641 )
Cybereasonmalicious.ec03a7
CyrenW32/Delf.MV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Disabler.NCZ
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Blocker.mezy
BitDefenderTrojan.GenericKD.42833397
NANO-AntivirusTrojan.Win32.Blocker.heukef
MicroWorld-eScanTrojan.GenericKD.42833397
TencentWin32.Trojan.Blocker.Aiin
Ad-AwareTrojan.GenericKD.42833397
SophosMal/Generic-S
ComodoMalware@#1cy0a6p351f8a
BitDefenderThetaGen:NN.ZexaF.34804.mu0@a4fmmKn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransom.dh
FireEyeGeneric.mg.7e1d61cec03a7705
EmsisoftTrojan.GenericKD.42833397 (B)
WebrootW32.Blocker.Mezy
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.CF1
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Generic.D28D95F5
AegisLabTrojan.Win32.Blocker.j!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.mezy
GDataTrojan.GenericKD.42833397
McAfeeArtemis!7E1D61CEC03A
MAXmalware (ai score=83)
VBA32TrojanRansom.Blocker
MalwarebytesMalware.Heuristic.1008
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan.BAT.Disabler
FortinetW32/Blocker.MEZY!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove BAT/Disabler.NCZ?

BAT/Disabler.NCZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment