Malware

WinGo/Agent.AU removal tips

Malware Removal

The WinGo/Agent.AU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Agent.AU virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings

How to determine WinGo/Agent.AU?


File Info:

name: CD589B2D54A538CA8730.mlw
path: /opt/CAPEv2/storage/binaries/17f57a0ab038e09fd5e3feb66b0229b84ce8cb22609f298b7810c80f02c9b740
crc32: 4CCB5224
md5: cd589b2d54a538ca8730471dae4e44b5
sha1: ba881cccc4cd245e6a773d3396febcfcb191abdc
sha256: 17f57a0ab038e09fd5e3feb66b0229b84ce8cb22609f298b7810c80f02c9b740
sha512: b77edcdbcc2e26b87f25e55d70c307ed1d6e52a6d30044e7ce5a9bd742c7472ca32679dbca22f260fed03512f3ac0a5d160a652cbc2d16d890a11cefbc1f76be
ssdeep: 98304:fbGZg9u9YymTn3TN35DqnXIP6Iq6Rm2uena:f4gM9YyyjNls4P6R6U2uena
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5163321FED65472C9F24D35A87E5764E8397A200B3CCB8FA3A48B1ECA7118156367C7
sha3_384: 93d87fc6ee49493bbfd1b7be99082ce574f9e5c7c6836a7fdc46b5bce3d92b490c15e4ea5cd9b194c9a682cdc39b4286
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

WinGo/Agent.AU also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.2011
MicroWorld-eScanTrojan.GenericKD.47602583
FireEyeGeneric.mg.cd589b2d54a538ca
ALYacTrojan.GenericKD.47602583
CylanceUnsafe
SangforTrojan.Win32.Bitmin.ysn
K7AntiVirusTrojan ( 0057c1001 )
AlibabaTrojanDownloader:Win32/Bitmin.b86a3960
K7GWTrojan ( 0057c1001 )
Cybereasonmalicious.d54a53
SymantecW97M.Downloader
ESET-NOD32a variant of WinGo/Agent.AU
TrendMicro-HouseCallTROJ_GEN.R002H0DL821
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Bitmin.ysn
BitDefenderTrojan.GenericKD.47602583
AvastWin64:Trojan-gen
TencentWin32.Trojan-downloader.Bitmin.Taey
Ad-AwareTrojan.GenericKD.47602583
EmsisoftTrojan.GenericKD.47602583 (B)
TrendMicroTROJ_GEN.R002C0WLB21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious SFX
GDataTrojan.GenericKD.47602583
AviraTR/Redcap.qowdw
MAXmalware (ai score=83)
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Agent.4247509.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!CD589B2D54A5
VBA32TrojanDownloader.Bitmin
APEXMalicious
YandexTrojan.DL.Bitmin!1Pk1AtTkgyU
IkarusTrojan.WinGo.Agent
FortinetPossibleThreat.PALLAS.H
AVGWin64:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove WinGo/Agent.AU?

WinGo/Agent.AU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment