Malware

About “Win32/Agent.NQT” infection

Malware Removal

The Win32/Agent.NQT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.NQT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent.NQT?


File Info:

name: 91B43924BB9D5725AA29.mlw
path: /opt/CAPEv2/storage/binaries/d2d27cbcec7bbe9507aca896a4e30116f40c56dd14a0f9bc42cd3bfcfd7b775a
crc32: C4C42253
md5: 91b43924bb9d5725aa2950d1afd6f472
sha1: 6e467053c36ea8a49639a4e5943ba1f9422c9858
sha256: d2d27cbcec7bbe9507aca896a4e30116f40c56dd14a0f9bc42cd3bfcfd7b775a
sha512: e5d8a9e069681f698ce3ad406a7c67c131df95649a7c6e0c0a87f2b2bd2257f4d0c815397f4093178a13cf22795d0d2cf96f5c6002e9d6a27ecb9e01b7ec9e48
ssdeep: 49152:1m5hQs04nOSem7VjKtnbVkSlNsuuNw6tLMm5:1ml0SOStj2kSlNe5NB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147D55C10E301512ADDB724F90A9D726EA11CEFB0072410D792C97BFE9E7AAE13D3525B
sha3_384: 1897688fbec9fa0865064201aa7c20a7cb6a2fb8f24b9906d3bfc8908b6c8491565e3502efd85081909255725b39596e
ep_bytes: 8bff558bece8963c0100e8110000005d
timestamp: 2013-08-24 04:16:20

Version Info:

Comments: U盘病毒 功能:模仿已有的U盘病毒 感染移动存贮器的一级目录
CompanyName: U盘病毒应用程序 测试使用请务非法传播
FileDescription: U盘病毒 只做测试使用 http:/www.郭华.com
FileVersion: 1, 0, 0, 0
InternalName: NetCorpse
LegalCopyright: 版权所有 JACK 只做测试 2009-1-22 http:/www.郭华.com
LegalTrademarks:
OriginalFilename: hacker.exe
PrivateBuild:
ProductName: U盘病毒应用程序 http:/www.郭华.com
ProductVersion: 1, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/Agent.NQT also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.150999
FireEyeGeneric.mg.91b43924bb9d5725
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ulise.150999
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cdaa31 )
BitDefenderGen:Variant.Ulise.150999
K7GWTrojan ( 004cdaa31 )
Cybereasonmalicious.4bb9d5
BitDefenderThetaGen:NN.ZexaF.34742.Rw0@aq2qSBaj
VirITTrojan.Win32.Siggen6.TPA
CyrenW32/Agent.CGS.gen!Eldorado
ESET-NOD32Win32/Agent.NQT
BaiduWin32.Worm.Agent.fi
TrendMicro-HouseCallWorm.Win32.MALEX.SMNH
KasperskyTrojan-Dropper.Win32.Daws.edea
NANO-AntivirusTrojan.Win32.Daws.erexrx
RisingTrojan.Win32.FakeFolder.ch (CLASSIC)
Ad-AwareGen:Variant.Ulise.150999
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.Daws.M@83sej7
DrWebTrojan.Siggen6.13234
ZillyaWorm.Agent.Win32.25838
TrendMicroWorm.Win32.MALEX.SMNH
McAfee-GW-EditionGenericR-DPF!91B43924BB9D
EmsisoftGen:Variant.Ulise.150999 (B)
APEXMalicious
JiangminTrojan/Generic.bahuh
AviraHEUR/AGEN.1243024
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ulise.150999
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Malex.R173297
McAfeeGenericR-DPF!91B43924BB9D
MAXmalware (ai score=80)
VBA32TrojanDropper.Daws
MalwarebytesTrojan.Malex
PandaGeneric Malware
TencentTrojan.Win32.FakeFolder.t
YandexTrojan.GenAsa!yHiL46hs8WM
IkarusTrojan.Win32.FlyStudio
FortinetW32/Agent.NQT!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Agent.NQT?

Win32/Agent.NQT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment