Malware

How to remove “Win32/Agent_AGen.CQD”?

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 4EFF283F3EB35862768A.mlw
path: /opt/CAPEv2/storage/binaries/ebe7ab80574aa0c7bc668c2ce20bf19fa59793836ac6e7e797da70eb9f85e537
crc32: E2B7D57F
md5: 4eff283f3eb35862768adfcac85ab047
sha1: bcd956371fb3d446cf617f0b9a3657288ee73e05
sha256: ebe7ab80574aa0c7bc668c2ce20bf19fa59793836ac6e7e797da70eb9f85e537
sha512: b89a57a4cd5da4ac87263ddf556fe764f30464d8c9797580be36f55dd099bc002fb185dca9c7178d988900eb5f98800537efbb27f70471f1a039e411865b69b3
ssdeep: 192:rVXY/dWhZ+DkbL0tEqCuNRYkvCGL222BdXb3xAPtXtQmW0tgcLbdsaMl8CZ2dzc7:rVM5tEGgZBBb3GtTsaMl8C8daDE045H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191037CB31AAD7935F70D43F742235AC886A9752086A21D66D60EF04C2F78D473A21F8B
sha3_384: 242d10ba1d5824dccbbcd2432b73bff5b010633903bdea78811af37b4c4d1eddd1388b3ec402c93f11b7b8fc301a6c44
ep_bytes: d7eaa9e13ed2d51993f46fdb4ec9d5df
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.465768
FireEyeGeneric.mg.4eff283f3eb35862
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!4EFF283F3EB3
MalwarebytesMachineLearning/Anomalous.100%
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.465768
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.71fb3d
BitDefenderThetaGen:NN.ZexaF.36792.cmY@aihbphl
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
CynetMalicious (score: 100)
APEXMalicious
AlibabaTrojan:Win32/Generic.f32910ca
SophosMal/Generic-S
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Zusy.465768
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.465768 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/S-9bdefeb6!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=81)
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Script/Phonzy.B!ml
ArcabitTrojan.Zusy.D71B68
GDataGen:Variant.Zusy.465768
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Zusy.465768
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CK523
RisingTrojan.Generic@AI.100 (RDML:0FOFd9PS46uTczzHtW1VXQ)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Malware

Win32/Agent_AGen.CQD information

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: A63797BC2DE46615105C.mlw
path: /opt/CAPEv2/storage/binaries/ebf6ccb32525601392f65dd33f4a8198e804b99aebed9210c053ef810f33c458
crc32: EAD94BA4
md5: a63797bc2de46615105c503e16bb3c3f
sha1: 995be2a3fd0e97409e3e3282b030f527548a1924
sha256: ebf6ccb32525601392f65dd33f4a8198e804b99aebed9210c053ef810f33c458
sha512: e99bed9d07a134e07a7cf165136ac13ac0d2c6603416826c7418cbe2c2903b507f9369dd5ead209864d83836738612e0b17d0e88c7fa4f7902b212a88e41f30c
ssdeep: 384:zDY+lUycDyqPo0T+ezW2fQc/9hk437BkmFDE045HWhhh:zDY+lNYg0T1zHQc9hk07BfAohhh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2528EA3A41C7CF7FF6C61FB097256DA686A72244F53841A010FD56C0F2C5168B9670B
sha3_384: aac06e2ea1cc5dd88250dca87d73adf4cbe11279c11ba73eb44145ab1298fa0efdd3719b2d57212c46f8b5fadff7b94a
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.labP
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.a63797bc2de46615
CAT-QuickHealTrojan.Grandoreiro
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!A63797BC2DE4
MalwarebytesTrojan.Downloader
VIPRETrojan.Ransom.Poison.B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
BitDefenderTrojan.Ransom.Poison.B
K7GWTrojan ( 0059befd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36792.amW@aKovO2i
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
AlibabaWorm:Win32/Grandoreiro.9e155c34
NANO-AntivirusTrojan.Win32.VB.juiskq
ViRobotTrojan.Win.Z.Poison.14336.TAFX
RisingTrojan.Generic@AI.100 (RDMK:3pRJXgFIe7PuQZLzjr9FTA)
EmsisoftTrojan.Ransom.Poison.B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
TrendMicroTROJ_GEN.R03BC0DK523
Trapminemalicious.high.ml.score
SophosMal/ExeSax-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bghcg
VaristW32/Cerbu.BW.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
GoogleDetected
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacTrojan.Ransom.Poison.B
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DK523
TencentTrojan.Win32.VB.xhae
IkarusVirus.Win32.VB.FEW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3fd0e9
AvastWin32:Evo-gen [Trj]

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment