Malware

About “Win32/Agent_AGen.CQD” infection

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 962DF8933CC5B40AACBB.mlw
path: /opt/CAPEv2/storage/binaries/e13f42444037c73d972350d5a5d094bbfc9d542528d4bb460f2d815623aa0b9d
crc32: 2B62B56D
md5: 962df8933cc5b40aacbbc50891104d88
sha1: 6311938e0ae6e9564cfd59cafd31e86147e73d35
sha256: e13f42444037c73d972350d5a5d094bbfc9d542528d4bb460f2d815623aa0b9d
sha512: 6482939e693a640adf7be6048293e7ee28d78cac6ad28f7f01fe99853c3d06829e5a53fa61df4a2bae674e784c89d94422df4a9260ceee5265af70cd5a8fa89e
ssdeep: 384:pfL1fvYvYvbXx//////sBGTMkrwDE045HGhhh:xL1/B//////mGgk+AAhhh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199523B33D66C3525FBDD06B7071A85CBCED6F4A09AB8C6020B87C4DA9DAB405395231F
sha3_384: 428e21a1ec4abd4db66056fc11c496b9246b097c9351ec07eaa282b78090d5e7123e9c7d6ad7b9a30ece59f6c0355b98
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.962df8933cc5b40a
CAT-QuickHealTrojan.Grandoreiro
SkyhighBehavesLike.Win32.Generic.lc
ALYacTrojan.Ransom.Poison.B
Cylanceunsafe
VIPRETrojan.Ransom.Poison.B
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Ransom.Poison.B
K7GWTrojan ( 0059befd1 )
K7AntiVirusTrojan ( 0059befd1 )
ArcabitTrojan.Ransom.Poison.B
BitDefenderThetaAI:Packer.44249F861F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.VB.juiskq
RisingTrojan.Generic@AI.100 (RDMK:+xXge/ptyUbBGDD+tL/Uog)
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
TrendMicroTROJ_GEN.R03BC0DJS23
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Poison.B (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Agent.FJT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
XcitiumHeur.Packed.MultiPacked@1z141z3
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
McAfeeGenericRXTL-LJ!962DF8933CC5
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJS23
TencentTrojan.Win32.VB.xhae
IkarusVirus.Win32.VB.FEW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e0ae6e
AvastWin32:Evo-gen [Trj]

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment