Malware

About “WinGo/Filecoder.GoGoogle.A” infection

Malware Removal

The WinGo/Filecoder.GoGoogle.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Filecoder.GoGoogle.A virus can do?

  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine WinGo/Filecoder.GoGoogle.A?


File Info:

crc32: 0B76F01D
md5: a7af86bb3015faad864bf02613a2d245
name: A7AF86BB3015FAAD864BF02613A2D245.mlw
sha1: 6a72925a64dc35c77aada929045bbfac09ca5ca5
sha256: 67a9cdac57ab811b0b0d327bd132f6def6e2b421839088ab50e6dd98929b0ff5
sha512: 934bf988c54ef824508cd3ae2592e56ed82fc2e140cbafd0e50e16a53c1cdd4e1e8a6c4fcdd5cc2883a635e6380105a0c41c5e1dae6302dabcfbae6787530d58
ssdeep: 24576:FJ2mxWmDAEzs9ue3MLYirSpUPa4HaG7zIrq7Q4wtoEpPQ:jdWm8sM+DrmUSo4qd
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

WinGo/Filecoder.GoGoogle.A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31423
MicroWorld-eScanTrojan.GenericKD.33595261
ALYacTrojan.GenericKD.33595261
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.13732
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/GoGoogle.42e0f6e2
K7GWTrojan ( 005639c21 )
K7AntiVirusTrojan ( 005639c21 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of WinGo/Filecoder.GoGoogle.A
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.33595261
NANO-AntivirusTrojan.Win32.Encoder.hicike
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.33595261
SophosMal/Generic-S
ComodoMalware@#2ojfee2q8iaoy
BitDefenderThetaGen:NN.ZexaF.34058.8mGfamO9XSf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.a7af86bb3015faad
EmsisoftTrojan.GenericKD.33595261 (B)
JiangminTrojan.Generic.eogjl
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Occamy.C67
ArcabitTrojan.Generic.D2009F7D
GDataTrojan.GenericKD.33595261
AhnLab-V3Malware/Win32.Generic.C4195249
McAfeeArtemis!A7AF86BB3015
MAXmalware (ai score=81)
VBA32Trojan.Encoder
PandaTrj/CI.A
YandexTrojan.Filecoder!2PiY1j5Junw
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Filecoder.EB14!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwsBoaMA

How to remove WinGo/Filecoder.GoGoogle.A?

WinGo/Filecoder.GoGoogle.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment