Trojan

What is “Trojan.Agent.FWGG”?

Malware Removal

The Trojan.Agent.FWGG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FWGG virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PCRat malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.FWGG?


File Info:

name: 4B015FE3B094CD27FB36.mlw
path: /opt/CAPEv2/storage/binaries/8bc844d892bd2626beb87ce97333d121da0b71468cd683a3bbce90bc4a23b4dd
crc32: 57FB480C
md5: 4b015fe3b094cd27fb36ea30dbc2a2dd
sha1: 54c8bc021c05cd8154066d687d1b7c8689ac20ef
sha256: 8bc844d892bd2626beb87ce97333d121da0b71468cd683a3bbce90bc4a23b4dd
sha512: 21dca16eb896eb653e24cb1d365cd41fb5089ff155053b36bc544437f46f2ff841c8ffbd9553634e1a82f62f9249ab51682d08bbd2ef5aa5f16864c65acb5906
ssdeep: 3072:ZTeTY1Zm5WBqwP35sWQ/Xz7iasewyC/hX69xv3IUt75kZuzLJBAyTizzzz1zzzz9:ZiToiWB2NL7tkJ5wp3IbkFm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A348D32B5C700F3E904193040EA7BF96A3AFE8713626ECFE714DE697C63195D226196
sha3_384: aad509dd0f3f0b19ea259c30366a507972e43abe65c97ff9f31ccbf5bcdb5c70835779036bfbef85a8bd63c648b12c57
ep_bytes: 558bec6aff68e841420068088f410064
timestamp: 2011-04-13 15:37:23

Version Info:

CompanyName: 疼讯扣扣
FileDescription:
FileVersion:
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0804 0x04b0

Trojan.Agent.FWGG also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FWGG
FireEyeGeneric.mg.4b015fe3b094cd27
CAT-QuickHealTrojan.Redosdru.K4
ALYacTrojan.Agent.FWGG
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Palevo.Win32.58460
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.3b094c
ArcabitTrojan.Agent.FWGG
BitDefenderThetaGen:NN.ZexaF.36318.oq0@aaFjPgej
VirITTrojan.Win32.Generic.HNE
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Farfli.RG
APEXMalicious
ClamAVWin.Trojan.Redosdru-9875198-0
KasperskyVHO:Trojan-Spy.Win32.Agent.gen
BitDefenderTrojan.Agent.FWGG
NANO-AntivirusTrojan.Win32.Keylog.cqolzo
AvastWin32:Agent-AQGZ [Trj]
TencentBackdoor.Win32.Gh0st.g
EmsisoftTrojan.Agent.FWGG (B)
BaiduWin32.Trojan.Farfli.ai
F-SecureBackdoor.BDS/Zegost.Gen
DrWebTrojan.Keylog.507
VIPRETrojan.Agent.FWGG
TrendMicroTROJ_PALEVO.SMUM
McAfee-GW-EditionBehavesLike.Win32.Infected.dh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusP2P-Worm.Win32.Palevo
JiangminWorm/Palevo.cglh
WebrootW32.Worm.Palevo
GoogleDetected
AviraBDS/Zegost.Gen
MAXmalware (ai score=86)
XcitiumTrojWare.Win32.Magania.~AAD@f80tc
MicrosoftBackdoor:Win32/Zegost.AD
ZoneAlarmVHO:Trojan-Spy.Win32.Agent.gen
GDataWin32.Trojan.PSE.10P0BG1
CynetMalicious (score: 100)
AhnLab-V3HEUR/UnSec.X1469
McAfeeBackDoor-DVB.gen.a
VBA32BScope.TrojanBanker.Gozi
Cylanceunsafe
PandaGeneric Malware
ZonerTrojan.Win32.31202
TrendMicro-HouseCallTROJ_PALEVO.SMUM
RisingBackdoor.Farfli!1.64D7 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/KeyLogger.514D!tr
AVGWin32:Agent-AQGZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.FWGG?

Trojan.Agent.FWGG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment