Malware

Win32/Agent_AGen.CQD (file analysis)

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 91B97AC46000448BF7F7.mlw
path: /opt/CAPEv2/storage/binaries/90fe9d08fe20c38ba5822d09120ba0fe84bbd4bc7e80cb16d72841817234afa8
crc32: F27148E2
md5: 91b97ac46000448bf7f79dd82f88b1f2
sha1: 9767b7fb7e2cba6e5641d6a0a4bcb6dae69ed95d
sha256: 90fe9d08fe20c38ba5822d09120ba0fe84bbd4bc7e80cb16d72841817234afa8
sha512: 7bb883410d1a5c9153ef646547a7204d1c6d1eb898f45219554fc483978612d5676b1a8cfe4e3ba5fb5bc434b504086dbe9bc0d391b6f0cc08777172d22e94ca
ssdeep: 192:DZT/0ECN1dxUIgy25OrWcK7Bq7bvrpdffHyBvNqDE045HQ:VnAd552gWXwDzfHyBvUDE045H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8038CBB5E5C52B3FA8D49B3426A91D381807BBE23E0184D455BE97CCFA51A00A30F03
sha3_384: 5127f51007ffc8e252bb5302b765264a37d8dc45114e83d3d72358ee1e17c8ecb0e5f3ae1ac50cb12a4166f810a01b92
ep_bytes: 6bbcac1366b6ecb79df1e397b1b02fdf
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Cerbu.173465
FireEyeGeneric.mg.91b97ac46000448b
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!91B97AC46000
MalwarebytesMachineLearning/Anomalous.100%
VIPREGen:Variant.Cerbu.173465
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Cerbu.173465
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b7e2cb
BitDefenderThetaGen:NN.ZexaE.36792.cmY@aihbphl
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:ayaJlkWMqitv4zj/6Adz7Q)
EmsisoftGen:Variant.Cerbu.173465 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/S-9bdefeb6!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=85)
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Script/Phonzy.B!ml
ArcabitTrojan.Cerbu.D2A599
GDataGen:Variant.Cerbu.173465
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Cerbu.173465
DeepInstinctMALICIOUS
Cylanceunsafe
TencentTrojan.Win32.Patched.kd
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment