Malware

Win32/Agent_AGen.CQD (file analysis)

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: E04EDEA25B40751FE92F.mlw
path: /opt/CAPEv2/storage/binaries/022e054cc23671cc8e73cd399caf8df2ac60fc96e795715b8a4f9b0471677b79
crc32: B7A7803B
md5: e04edea25b40751fe92fbe3f65d36835
sha1: 0be1bf5a89c4f30d92bed6a33db6794d77d6ae9f
sha256: 022e054cc23671cc8e73cd399caf8df2ac60fc96e795715b8a4f9b0471677b79
sha512: 346b735619b7af2ca842b1e58d81d4064ef553f59c01db2f352768e0ecdc40a8ec96df4fbc32d22aee1834e0fc9894452fcecee03fc44eb9278d884627c07f6f
ssdeep: 384:nSsTjS7Lkcacacacacacacacacacacacacacacacj/ZVLDE045H:JTjSvnxxxxxxxxxxxxxxxjB1A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0522A27D22DA20EF7784ABA8A07EDE7579F34343E6A4458841BC3181F3DA3119A1F17
sha3_384: 6395603f8ed588a96c244b53651969d589fcb8af7d539fbfceee14c91b5d6c094b4b41708064e2adc67a349c8c182221
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.e04edea25b40751f
SkyhighBehavesLike.Win32.Generic.lc
ALYacTrojan.Ransom.Poison.B
MalwarebytesTrojan.Downloader
VIPRETrojan.Ransom.Poison.B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
BitDefenderTrojan.Ransom.Poison.B
K7GWTrojan ( 0059befd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.VB.juiskq
RisingTrojan.Generic@AI.100 (RDMK:d/wGbPwCFe6G8D7Da8gpcQ)
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Poison.B (B)
IkarusVirus.Win32.VB.FEW
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Agent.FJT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
McAfeeGenericRXTL-LJ!E04EDEA25B40
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.General.3
Cylanceunsafe
TencentTrojan.Win32.VB.xhae
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
BitDefenderThetaAI:Packer.44249F861F
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a89c4f
AvastWin32:Evo-gen [Trj]

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment