Malware

Win32/Agent_AGen.CQD (file analysis)

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: D21C19A0CEFD042C9864.mlw
path: /opt/CAPEv2/storage/binaries/7c5e83c7b91bed557501c0491b92e2670abac3de5f8721c7bc5a8a990623e976
crc32: 142C476A
md5: d21c19a0cefd042c98645de5f5076af0
sha1: 3b777f70fb88f7bdb505cbd2e3a24f3b74457327
sha256: 7c5e83c7b91bed557501c0491b92e2670abac3de5f8721c7bc5a8a990623e976
sha512: 7783cada7984b498738acecfb06ebb2449a23b7a9e32548fb21d48be288f85b9d399a4b2ce5c3d4c3de865b686cb923d6e91a736124bea711c6928bd3e4c31d7
ssdeep: 384:fVbz5PHj5Wxxi7o7o7o7o7o7OmmmmmM02DE045H:fVbNHr88888CmmmmmM0cA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184036D82807C5DF2F68C56FF26A5C8D0685732602DCBA804895FEBE41E7D3972B65B07
sha3_384: a3a1cd0eb8cf3ebb36121a84334024b64c110d5558b91b5983fa1a02820af84ffadec9bec30854ed0e3ee6ffe0246baa
ep_bytes: 6d7a81c188c6a75032b1bfb243a7c103
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Krap.x!c
MicroWorld-eScanGen:Variant.Cerbu.173465
FireEyeGeneric.mg.d21c19a0cefd042c
SkyhighBehavesLike.Win32.Generic.pz
ALYacGen:Variant.Cerbu.173465
MalwarebytesMachineLearning/Anomalous.94%
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaPacked:Win32/Generic.84747dd9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0fb88f
ArcabitTrojan.Cerbu.D2A599
BitDefenderThetaGen:NN.ZexaF.36792.cmY@aihbphl
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.w
BitDefenderGen:Variant.Cerbu.173465
AvastWin32:Evo-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:/d43AHVDgUP3DiBkeaUSqg)
EmsisoftGen:Variant.Cerbu.173465 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.173465
TrendMicroTROJ_GEN.R002C0XKK23
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=83)
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmPacked.Win32.Krap.w
GDataGen:Variant.Cerbu.173465
VaristW32/S-9bdefeb6!Eldorado
Acronissuspicious
McAfeeArtemis!D21C19A0CEFD
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0XKK23
TencentTrojan.Win32.Patched.kd
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment