Malware

Win32/Agent_AGen.CQD (file analysis)

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: CCC820A005D12D8490D4.mlw
path: /opt/CAPEv2/storage/binaries/971bec3464c2c1c7e2741e7ab4b54053d2dd35fea49b0a6ad43cc5a6a20cd5ea
crc32: D7FBE59D
md5: ccc820a005d12d8490d4077eaf97090a
sha1: ad37cc43306ef3b9e1bd8fad1d938d2ad483c156
sha256: 971bec3464c2c1c7e2741e7ab4b54053d2dd35fea49b0a6ad43cc5a6a20cd5ea
sha512: a8e0e2f7c3326aad7c367c2113ba4a5670e4892928638c11f77776221d0a2b32453e9ce6ebe26f443ca2696f15859d7501fe23a5305426ef89420fea875c2265
ssdeep: 384:U8HvwCGo2Wff+LYV+D81RxMOTDE045HEJyJyJyJyJ:UAwK2WfggbROOPAeJyJyJyJyJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T176039D72153C18F3FA2E56FB466E97D100C579A40FAA14AC584CD68E4F383AD2D44B4F
sha3_384: 07fb033e08b197f3429824747d48f5f2d0c4f0bc2443f9cab49a663c74821f4cfc8bb9efe43ddbe7b7893ddc6cf85f74
ep_bytes: 6c0ff0dcab87c2631bb48c9df75c1684
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Cerbu.173465
FireEyeGeneric.mg.ccc820a005d12d84
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!CCC820A005D1
MalwarebytesMachineLearning/Anomalous.100%
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Cerbu.D2A599
BitDefenderThetaGen:NN.ZexaE.36792.cmY@aihbphl
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Cerbu.173465
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Patched.kd
EmsisoftGen:Variant.Cerbu.173465 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.173465
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=80)
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Cerbu.173465
VaristW32/S-9bdefeb6!Eldorado
Acronissuspicious
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CKI23
RisingTrojan.Generic@AI.100 (RDML:uoxclE7Epn5rSS0aYOt5Zg)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3306ef
DeepInstinctMALICIOUS

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment