Malware

How to remove “WinGo/Agent_AGen.AG”?

Malware Removal

The WinGo/Agent_AGen.AG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Agent_AGen.AG virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine WinGo/Agent_AGen.AG?


File Info:

name: 80BB2DB7272002EF6250.mlw
path: /opt/CAPEv2/storage/binaries/7901d9f7e7b45d8665e6d2820b755c3271b2f5d0ab5d7c614bbf65b8cd157f7e
crc32: 6ABE1A1F
md5: 80bb2db7272002ef6250fda8ec98bb1f
sha1: e989325695bc6e6a4ec7533b4ca223a8ee2190ac
sha256: 7901d9f7e7b45d8665e6d2820b755c3271b2f5d0ab5d7c614bbf65b8cd157f7e
sha512: 22702b99583c31b553b33ddda180e934bcd2eb3afe56c6b840165b0794e0fa51fb0076f344e39af5ed08ac04913f54fc5da634b3f37b61caae21115e55b7b537
ssdeep: 98304:TptFaVXazoJ4ssXuM6EGATURta9UnYDCPGtddnB03dn:TpbZoG+3EURM2Y3ddB0t
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T167A6F848F9D780F6D9071C3044AA613F132869498B66DD97FB803B5BF8737A74E32A16
sha3_384: c955f5ff79d22a7356acd9c25c976efa6406610e3de7d38a79ded531c3363b37f97009ebb73d1952a8832296352182dc
ep_bytes: 83ec088b4424088d5c240c890424895c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

WinGo/Agent_AGen.AG also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.105496
FireEyeTrojan.GenericKDZ.105496
SkyhighBehavesLike.Win32.Trojan.th
ALYacTrojan.GenericKDZ.105496
Cylanceunsafe
SangforTrojan.Win32.Agent.V90w
K7AntiVirusTrojan ( 005b119e1 )
AlibabaTrojan:Win32/Redcap.f05e7dc3
K7GWTrojan ( 005b119e1 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of WinGo/Agent_AGen.AG
BitDefenderTrojan.GenericKDZ.105496
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.GenericKDZ.105496 (B)
F-SecureTrojan.TR/Redcap.ktjab
VIPRETrojan.GenericKDZ.105496
SophosGeneric Reputation PUA (PUA)
GDataTrojan.GenericKDZ.105496
GoogleDetected
AviraTR/Redcap.ktjab
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Generic.D19C18
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalwareX-gen.C5582915
McAfeeArtemis!80BB2DB72720
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.95 (RDML:V8uEiFwY7hGsHbd7nT1MPw)
IkarusTrojan.WinGo.Agent
FortinetW32/Agent_AGen.AG!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove WinGo/Agent_AGen.AG?

WinGo/Agent_AGen.AG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment