Malware

How to remove “Win32/Agent_AGen.CQM”?

Malware Removal

The Win32/Agent_AGen.CQM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQM virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent_AGen.CQM?


File Info:

name: F6C95CB578C321485742.mlw
path: /opt/CAPEv2/storage/binaries/bb250a5aaa8096a8c66b8c7b69398fa2726c247feef2c2f97f08c9682a718fc8
crc32: 23A50A93
md5: f6c95cb578c32148574258fd681009da
sha1: 679919c8c8df37eb62f1a56a670aec5e435741ce
sha256: bb250a5aaa8096a8c66b8c7b69398fa2726c247feef2c2f97f08c9682a718fc8
sha512: fdf3dc2bcd4181142dbdcbb2a90953277c2e0ebd2589a10100df01959e31e4f51cb52dd4134c6e1ad9e7b5e81ab0477a2ffab5a912abed69dd6cbd10a51e3d40
ssdeep: 6144:FgY7XTCMVQvLZ5cX9KJPVpE4vMROHN/hgCqnz0C:JTFq49KJRUm+Cq3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107D47C2076408075E3A5077089E9E6F509696E3913A9E5CFF3A83E396E701E35B3724F
sha3_384: 2ae4abeccef4f57ce2f4ca49e4391c7c59fefa410bd59d8a2f2fb5e796f7f715745662e4e783054ab78f321706781fc0
ep_bytes: 0dfdf3a5fcff2495cc2c41008bfff7d9
timestamp: 2013-10-04 01:36:50

Version Info:

0: [No Data]

Win32/Agent_AGen.CQM also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mikey.103257
SkyhighBehavesLike.Win32.Generic.jt
McAfeeGenericRXAA-AA!F6C95CB578C3
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Wecod.Win32.6936
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a93ce1 )
K7GWTrojan ( 005a93ce1 )
Cybereasonmalicious.8c8df3
ArcabitTrojan.Mikey.D19359
BitDefenderThetaGen:NN.ZexaF.36680.LmZ@aOzzcWm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Mikey-9891201-0
BitDefenderGen:Variant.Mikey.103257
AvastWin32:Malware-gen
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1300631
BaiduWin32.Trojan.Urelas.d
VIPREGen:Variant.Mikey.103257
TrendMicroTROJ_GEN.R03BC0DAH24
EmsisoftGen:Variant.Mikey.103257 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Ren.Gen2
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.981
XcitiumTrojWare.Win32.Urelas.DAQ@5qwr5f
MicrosoftTrojan:Win32/Urelas.AA
GDataGen:Variant.Mikey.103257
VaristW32/Urelas.AQ.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.R334843
Acronissuspicious
ALYacGen:Variant.Mikey.103257
TACHYONTrojan/W32.Agent.618496.QT
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAH24
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.74753478.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.CQM?

Win32/Agent_AGen.CQM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment