Malware

What is “Win32/Agent_AGen.CQD”?

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 0D3CA1730C3D51A4FB72.mlw
path: /opt/CAPEv2/storage/binaries/29d33866c716623b77721b851a71565247914184630c2a624581243b7d3294d8
crc32: 48C8992A
md5: 0d3ca1730c3d51a4fb72bc4c489fe582
sha1: 93b1e0f04360354ba05b629fab97e5c33efe6808
sha256: 29d33866c716623b77721b851a71565247914184630c2a624581243b7d3294d8
sha512: 5dbab9c7959a7dee2504ed7cb6ed94995b46b7542fdce8b5aea4f54bc893dcb607f2b4c41e2a516fb72df23da6fbde7559fa5363fb12159164b7b611d7e5e05a
ssdeep: 384:wbM9nJ2be687uFuFuFuFuFuFuFuFuFuFuFuFuFuFurAMOOzZYkDE045HPn:wYJJ/68CooooooooooooooEMa+A1n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A5208F3778E0439FB0A25F34D1A439554E73221B6839B56853EE16C9F2D7A02476B0B
sha3_384: a19f8118f7e0b753eb6f0167a6931883b294db1bcffc236fd85ef68550680d8afc4105c9b8b8c4927561c40a82488d3b
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.labP
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Poison.B
FireEyeGeneric.mg.0d3ca1730c3d51a4
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!0D3CA1730C3D
Cylanceunsafe
ZillyaTrojan.VB.Win32.1244501
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059befd1 )
AlibabaTrojan:Win32/Grandoreiro.bf984d3e
K7GWTrojan ( 0059befd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.Poison.B
BitDefenderThetaGen:NN.ZevbaF.36792.amW@aKovO2i
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.VB.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.xhae
SophosMal/ExeSax-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
TrendMicroTROJ_GEN.R011C0DHR23
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ransom.Poison.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bghcg
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.1000
XcitiumHeur.Packed.MultiPacked@1z141z3
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
ZoneAlarmHEUR:Trojan.Win32.VB.gen
GDataTrojan.Ransom.Poison.B
VaristW32/Cerbu.BW.gen!Eldorado
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacTrojan.Ransom.Poison.B
MAXmalware (ai score=85)
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0DHR23
RisingTrojan.Generic@AI.100 (RDMK:3/FgUE/yW6uwY5A5QKVROw)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.043603
DeepInstinctMALICIOUS

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment