Malware

Win32/Agent.WUY information

Malware Removal

The Win32/Agent.WUY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.WUY virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Win32/Agent.WUY?


File Info:

crc32: ED63D32E
md5: 021afbfa619f5c9741e53087145c24fe
name: 021AFBFA619F5C9741E53087145C24FE.mlw
sha1: 54e12d237e5969a90b16250b2be4ff8ba54abb0e
sha256: 75b1bf6097d77e39bcb761deec2ad7a742da0b6f6005602261eacc5c8947fc8f
sha512: 76d2fd6e3a3f755a2d82c244722bde7cde21311fdf7e47560c58c55cfc72035f85a4d7d5869784d455a77713297eed576c76663e4129090c60ffcc5c5e7dace6
ssdeep: 49152:mDaInyi8dWVySv/BTelNvvmYn30mtPUlsTn:m2i3VNBTelNvvmYEmt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

PrivateBuild: 0
CompositeBaseline: 1,6,1,1,3
FileVersion: 1.6.1.1
ProductVersion: 1,6,1,1
Translation: 0x0409 0x04b0

Win32/Agent.WUY also known as:

K7AntiVirusTrojan ( 004f7a581 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.Hr0@YM4Gqlk
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1302170
SangforTrojan.Win32.EqShell.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/DoubleFantasy.9c627a68
K7GWTrojan ( 004f7a581 )
Cybereasonmalicious.a619f5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.WUY
APEXMalicious
AvastSf:EqShell-A [Trj]
KasperskyTrojan.Win32.DoubleFantasy.gen
BitDefenderGen:Trojan.Heur.Hr0@YM4Gqlk
NANO-AntivirusTrojan.Win32.DoubleFantasy.hezxsd
ViRobotTrojan.Win32.Z.Doublefantasy.1600000
MicroWorld-eScanGen:Trojan.Heur.Hr0@YM4Gqlk
TencentWin32.Trojan.Doublefantasy.Bdy
Ad-AwareGen:Trojan.Heur.Hr0@YM4Gqlk
SophosMal/Generic-S
BitDefenderThetaAI:Packer.8F4439FD1B
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GJ121
McAfee-GW-EditionGenericRXQG-EE!3358B620DFB6
FireEyeGeneric.mg.021afbfa619f5c97
EmsisoftGen:Trojan.Heur.Hr0@YM4Gqlk (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DoubleFantasy.u
AviraTR/EquDrug.hswfs
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.3015910
MicrosoftTrojan:Win32/Occamy.C75
ArcabitTrojan.Heur.E95E95
GDataGen:Trojan.Heur.Hr0@YM4Gqlk
McAfeeArtemis!021AFBFA619F
MAXmalware (ai score=86)
VBA32BScope.Trojan.DoubleFantasy
MalwarebytesMalware.AI.1552780334
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GJ121
RisingTrojan.Generic@ML.80 (RDML:xgoeIAX3xCl9LeALM+P9Yw)
YandexTrojan.GenAsa!/Mn8gTEPk2o
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.8192751.susgen
FortinetW32/Agent.WUY!tr
AVGSf:EqShell-A [Trj]
Paloaltogeneric.ml

How to remove Win32/Agent.WUY?

Win32/Agent.WUY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment