Malware

About “Win32/Agent_AGen.CQD” infection

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 7D33E563E476E40FAD4F.mlw
path: /opt/CAPEv2/storage/binaries/297386f3d28b6b7f97fbcfcf0137e737966aab5e71f1eb5aa6661e9a0b7d3303
crc32: 70AA1ADA
md5: 7d33e563e476e40fad4f30f07e6e0f0a
sha1: 740d2f1016b6e4ab4c0e74c04f7ec9961db21b11
sha256: 297386f3d28b6b7f97fbcfcf0137e737966aab5e71f1eb5aa6661e9a0b7d3303
sha512: 4bea5a25dd0927de27c04a0909d9e515d28423d117ab01dff56c5ae23bd82af9c5a9c6bac8bfce6d8953830a71717463c41745e293aa2db27a19588616420b92
ssdeep: 384:6ceoOT8LoOwgvqiTABrhM2ClUOFcCWqE9DE045Hy:DeV8L9wKT0hM2XOFccEtAA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146529EB3F67E5A72FE7D06FF134359E04453AA612E824840469FE0A50FB676D2B01B4B
sha3_384: a27c6b42c08b7bca67f8f8a7fbe775ffac0e9302a5f875a820de80898ad9d456fb836a3294392314b3aa94e3832b6823
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Grandoreiro
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!7D33E563E476
MalwarebytesTrojan.Downloader
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
K7GWTrojan ( 0059befd1 )
Cybereasonmalicious.016b6e
BitDefenderThetaAI:Packer.44249F861F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.VB.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
MicroWorld-eScanTrojan.Ransom.Poison.B
RisingTrojan.Generic@AI.100 (RDMK:7MWYZgnrJypviDTs1seLkw)
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
TrendMicroTROJ_GEN.R03BC0DJV23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7d33e563e476e40f
EmsisoftTrojan.Ransom.Poison.B (B)
IkarusVirus.Win32.VB.FEW
JiangminTrojan/Generic.bghcg
VaristW32/Agent.FJT.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:Trojan.Win32.VB.gen
GDataTrojan.Ransom.Poison.B
GoogleDetected
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacTrojan.Ransom.Poison.B
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJV23
TencentTrojan.Win32.VB.hh
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment