Trojan

BAT/TrojanDownloader.Agent.NOS removal guide

Malware Removal

The BAT/TrojanDownloader.Agent.NOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/TrojanDownloader.Agent.NOS virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Attempts to disable Windows Defender
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

How to determine BAT/TrojanDownloader.Agent.NOS?


File Info:

crc32: 8A86D04D
md5: 4eba2f9240b8426e93e67355b7bc4b4a
name: severstal_map.exe
sha1: 2fcf540284abf952af898fcffa31255fd369afe3
sha256: 137233acebb1085a95e246044ee2b686a062c50f6208d2897dd2007154cb7115
sha512: 81ad23af1f4a8090b534af20b9ee5bd19c736dd12dd209c1f22e6f5e2e43c81a3e9ad4308f5cb63052a1eb1da57d6080f2a8e0e9aee1bd3502a3bdecc509baee
ssdeep: 98304:tw6/TWvutLdXgqlr4wFBvpAdgQfcIOUzsCQDXOFjHt:h/CvutP94WvpAdgYxWs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/TrojanDownloader.Agent.NOS also known as:

BkavW32.SalideD.Trojan
MicroWorld-eScanDropped:Trojan.GenericKD.30979805
CMCTrojan-Ransom.Win32!O
CAT-QuickHealTrojan.Bitrep
ALYacDropped:Trojan.GenericKD.30979805
MalwarebytesTrojan.Script.Generic
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
BitDefenderDropped:Trojan.GenericKD.30979805
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R03FC0PF818
NANO-AntivirusTrojan.Win32.Mlw.fdxyfm
CyrenW32/Downloader.EDPR-8216
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R03FC0PF818
Paloaltogeneric.ml
GDataDropped:Trojan.GenericKD.30979805
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareDropped:Trojan.GenericKD.30979805
SophosMal/Generic-S
F-SecureTrojan.GenericKD.30979805
DrWebTrojan.MulDrop8.49034
Invinceaheuristic
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftDropped:Trojan.GenericKD.30979805 (B)
F-ProtW32/PsDownload.A
AviraTR/Dldr.Agent.mnanq
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Generic.D1D8B6DD
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.B
AhnLab-V3Malware/Win32.Generic.C2560692
McAfeeArtemis!4EBA2F9240B8
MAXmalware (ai score=98)
VBA32Trojan.Bitrep
PandaTrj/CI.A
ESET-NOD32BAT/TrojanDownloader.Agent.NOS
TencentBat.Trojan.Agent.Phha
YandexTrojan.DL.Agent!Ta6sGHyACl4
IkarusTrojan-Downloader.BAT.Agent
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM06.2.AD81.Malware.Gen

How to remove BAT/TrojanDownloader.Agent.NOS?

BAT/TrojanDownloader.Agent.NOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment