Malware

Win32/Agent_AGen.CQD (file analysis)

Malware Removal

The Win32/Agent_AGen.CQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQD virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.CQD?


File Info:

name: 681F9AB14685D82CB07A.mlw
path: /opt/CAPEv2/storage/binaries/f8f92b57e12c3ed9167539ac89c2c147243bf3fbe8acee78f4e91f0fbc71a0d6
crc32: 9E44BED1
md5: 681f9ab14685d82cb07ae54557ffe0f9
sha1: 9df01e8a852012b459ac7887412a406da5eaf807
sha256: f8f92b57e12c3ed9167539ac89c2c147243bf3fbe8acee78f4e91f0fbc71a0d6
sha512: 827f1ec437fb4c3c706e0cae6465df1f6a7694a3d6c9201987f57de9fe8b209f656fae28a8315cb30c17463c47afc93c050e91988603a2bead03d13fd707e755
ssdeep: 384:CfdfTEoeIzDzDzDzDzDzDzDzDzDzDzDzDzDzDzDOk7SDE045H:kdfYbIzDzDzDzDzDzDzDzDzDzDzDzDz7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C752EA7E81ECDA21F399AEB9177E41DB1C1635742DF20C2F949B80E80F2F6451650F1A
sha3_384: 99bd0116682654f43fae9164a61c28dbc8e3010242939674e088056f17ee0063e9bd53a73717bf08b8b3f44265fdd0ad
ep_bytes: 5053b899040000b9984440008a1980eb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Win32/Agent_AGen.CQD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.681f9ab14685d82c
CAT-QuickHealTrojan.Grandoreiro
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXTL-LJ!681F9AB14685
MalwarebytesTrojan.Downloader
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0059befd1 )
K7AntiVirusTrojan ( 0059befd1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
KasperskyHEUR:P2P-Worm.Win32.Convagent.gen
BitDefenderTrojan.Ransom.Poison.B
NANO-AntivirusTrojan.Win32.VB.juiskq
MicroWorld-eScanTrojan.Ransom.Poison.B
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.VB.kn
EmsisoftTrojan.Ransom.Poison.B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.124
VIPRETrojan.Ransom.Poison.B
TrendMicroTROJ_GEN.R03BC0DB424
Trapminemalicious.high.ml.score
SophosMal/ExeSax-A
IkarusTrojan.Crypt
JiangminTrojan/Generic.bghcg
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.Krap.cku
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win64/Grandoreiro.psyE!MTB
XcitiumHeur.Packed.MultiPacked@1z141z3
ArcabitTrojan.Ransom.Poison.B
ZoneAlarmHEUR:P2P-Worm.Win32.Convagent.gen
GDataTrojan.Ransom.Poison.B
VaristW32/Cerbu.BW.gen!Eldorado
AhnLab-V3Trojan/Win.LJ.R535457
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.amW@aKovO2i
ALYacTrojan.Ransom.Poison.B
MAXmalware (ai score=86)
VBA32Malware-Cryptor.General.3
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DB424
RisingTrojan.Generic@AI.100 (RDMK:hWgJht8PqBrTopr62ao1aw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.a85201
DeepInstinctMALICIOUS

How to remove Win32/Agent_AGen.CQD?

Win32/Agent_AGen.CQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment