Malware

Should I remove “Win32/Agent_AGen.CQM”?

Malware Removal

The Win32/Agent_AGen.CQM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.CQM virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent_AGen.CQM?


File Info:

name: 2FA4E09B32EB12E17A78.mlw
path: /opt/CAPEv2/storage/binaries/c9218b41c990fd2c2df34b8cea0aab2cc728f5294293d45a0dd310a688a0029e
crc32: D9ABE447
md5: 2fa4e09b32eb12e17a78dafc2cc0b6e2
sha1: a966927a19656dcb70a20a9ab1ac515de3a920c5
sha256: c9218b41c990fd2c2df34b8cea0aab2cc728f5294293d45a0dd310a688a0029e
sha512: 0f79cba8d05c1f1e98c883b419f81e4be787aa12c6f0bd4405206af9ef5b7c3baa48bc257ef8edfc83d540da75430bb057461e16b0076f34d1366f4b02c1360f
ssdeep: 6144:ngY7XTCMVQvLZ5cX9KJPVp54vMROHN/hgCqnzp:jTFq49KJyUm+Cq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107C47C2076408075E3A5073099A9EAF109696E3913A9E5CFF3B83E395E701E35B3724F
sha3_384: aa96cbbbc069844af0572dd3b3bfbc99acc7267d5cada74d7ba760d46a522a490eee8e83bd3b720b26786603c3d34c05
ep_bytes: 0dfdf3a5fcff2495cc2c41008bfff7d9
timestamp: 2013-09-30 12:35:48

Version Info:

0: [No Data]

Win32/Agent_AGen.CQM also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mikey.103257
CAT-QuickHealTrojan.Urelas
SkyhighBehavesLike.Win32.Generic.ht
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Wecod.Win32.6936
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ad01f1 )
K7GWTrojan ( 005ad01f1 )
Cybereasonmalicious.a19656
ArcabitTrojan.Mikey.D19359
BaiduWin32.Trojan.Urelas.d
VirITTrojan.Win32.Generic.DPE
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Mikey-9770489-0
KasperskyUDS:Trojan.Win32.Wecod.ajbo
BitDefenderGen:Variant.Mikey.103257
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1300631
VIPREGen:Variant.Mikey.103257
TrendMicroTROJ_GEN.R03BC0DAK24
EmsisoftGen:Variant.Mikey.103257 (B)
IkarusTrojan.Win32.Urelas
VaristW32/Urelas.AQ.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.994
XcitiumTrojWare.Win32.Urelas.DAQ@5qwr5f
MicrosoftTrojan:Win32/Urelas.AA
ZoneAlarmUDS:Trojan.Win32.Wecod.ajbo
GDataGen:Variant.Mikey.103257
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C4083037
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.KiZ@aG6FW0e
ALYacGen:Variant.Mikey.103257
TACHYONTrojan/W32.Wecod.593920
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAK24
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Agent_AGen.CQM?

Win32/Agent_AGen.CQM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment