Malware

What is “Win32/Agent_AGen.CQD”?

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 8FEB038FF64C74FDA524.mlw
path: /opt/CAPEv2/storage/binaries/85dbeb31a5bf40033038c506b67611abc200c9564f75d9d4ac5899f50742fb18
crc32: 84F83BF8
md5: 8feb038ff64c74fda52485958e49d718
sha1: 86206e35efd85cc4b48dd22be3cfef804eb3b8e9
sha256: 85dbeb31a5bf40033038c506b67611abc200c9564f75d9d4ac5899f50742fb18
sha512: 7a5687267268693f583626c67c578b52063ea75b7cf5633a2e11d6bb76a8add94af528707ab047379c57e35a93cd72470df2982a8859090de6786a0da4e3a6cc
ssdeep: 384:xall+kwqA+++++++++++KTT9BW0UvHXa/9DE045Hx888:UT+kwqA+++++++++++KTT9QiFA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF034C75CEFE00E7FE0F4273C8AAE568E1667C71CF69880E5417E6966E08905214AB1F
sha3_384: bfcfb1705391f8c8f31193bb89a2d4c9ad1a8d3717de33db14152ba223824a5fab4d670e55a74369d638a113e136ef92
ep_bytes: ad00a9dffc4fd56a8d7715adc9f7caa6
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Cerbu.173465
FireEyeGeneric.mg.8feb038ff64c74fd
SkyhighBehavesLike.Win32.Generic.pz
ALYacGen:Variant.Cerbu.173465
MalwarebytesMachineLearning/Anomalous.100%
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Cerbu.173465
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:5mI1NsXxbGS9BeYMlfxEog)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.173465
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Cerbu.173465 (B)
IkarusTrojan.Patched
VaristW32/S-9bdefeb6!Eldorado
AviraTR/Patched.Ren.Gen
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Cerbu.D2A599
GDataGen:Variant.Cerbu.173465
GoogleDetected
Acronissuspicious
McAfeeArtemis!8FEB038FF64C
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CK923
TencentTrojan.Win32.Patched.kd
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
BitDefenderThetaGen:NN.ZexaE.36792.cmY@aihbphl
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.5efd85
AvastWin32:Evo-gen [Trj]

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment