Malware

WinGo/Agent.R removal guide

Malware Removal

The WinGo/Agent.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Agent.R virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine WinGo/Agent.R?


File Info:

crc32: 25116BF6
md5: 229bf8ed402247f82b9980677f849e02
name: 229BF8ED402247F82B9980677F849E02.mlw
sha1: 88dad161ddb965219aa35462eafe0da83b309e37
sha256: ed1ab054fcc30c3d41d9f5158e528bdef126c4354d0a5a9a3260a90cdb0ad7a4
sha512: 18b43d7ac6dad5c905d4672bfb5cac40c06ceb36e2998ca1b6b612a958ddb686c96ba8bc2976bc7a0e1416bc8f89882e6aa85913cdbe236835dff425c3364e16
ssdeep: 98304:Zb5FM32YSPipxr2HpSLnNc0sUzlIWPHU16gPGBPjlpVZqVTw0HcWcWCPplLcr9eK:ZNi32Yu0iHkLNc0sUzlIWs16gkjlp+ld
type: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

WinGo/Agent.R also known as:

K7AntiVirusTrojan ( 0057760d1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.33919
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36432394
CylanceUnsafe
ZillyaExploit.BypassUAC.Win32.2995
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0057760d1 )
Cybereasonmalicious.d40224
CyrenW64/BypassUAC.K.gen!Eldorado
ESET-NOD32a variant of WinGo/Agent.R
APEXMalicious
AvastWin64:Trojan-gen
ClamAVWin.Malware.Bypassuac-9886477-0
KasperskyHEUR:Exploit.Win32.BypassUAC.pef
BitDefenderTrojan.GenericKD.36432394
MicroWorld-eScanTrojan.GenericKD.36432394
Ad-AwareTrojan.GenericKD.36432394
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
FireEyeGeneric.mg.229bf8ed402247f8
EmsisoftTrojan.GenericKD.36432394 (B)
JiangminExploit.BypassUAC.ccs
AviraEXP/BypassUAC.jtvyw
Antiy-AVLTrojan/Generic.ASMalwS.344B286
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D22BEA0A
GDataTrojan.GenericKD.36432394
Acronissuspicious
MAXmalware (ai score=89)
YandexExploit.BypassUAC!DH1wP/w1MI0
IkarusTrojan.WinGo.Agent
MaxSecureTrojan.Malware.124258105.susgen
FortinetW64/GenericKD.3643!tr
AVGWin64:Trojan-gen

How to remove WinGo/Agent.R?

WinGo/Agent.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment