Malware

About “WinGo/PSW.Agent.M” infection

Malware Removal

The WinGo/PSW.Agent.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/PSW.Agent.M virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine WinGo/PSW.Agent.M?


File Info:

crc32: 31171BB6
md5: 24e83aecd38d651f87c6f4fe78b42e3e
name: 24E83AECD38D651F87C6F4FE78B42E3E.mlw
sha1: 8d6dae3d3859db0a811ceff8df98639e060e7d6d
sha256: 40e61c2548308c49a91a232b1e00c49aeb6cc11fde68a99066ef4ed3463610d4
sha512: 06550666bce1c819b16b6d572d9fe4e6632404beaec35de7fb5951997ed6c39cc6d969c1902b7e11adb6ea0f058678cc333580eec1c1d4b4fb24c034d8db4546
ssdeep: 49152:z6HUGsHNGr11oRM/zKkO9RShOfGIE3XoZy50T/3hpldVTuO/Sd0o6y2:rGZhKyzKhPSwu6y50bhpld5h/Sd0o6y
type: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright:
FileVersion: 2.8.1.0
CompanyName: Telegram FZ-LLC
Comments: This installation was built with Inno Setup.
ProductName: Telegram Desktop
ProductVersion: 2.8.1
FileDescription: Telegram Desktop Setup
OriginalFileName:
Translation: 0x0000 0x04b0

WinGo/PSW.Agent.M also known as:

CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaVirTool:Win64/Splinter.ab476969
K7GWTrojan ( 0057d6791 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of WinGo/PSW.Agent.M
APEXMalicious
AvastWin64:Trojan-gen
KasperskyTrojan-PSW.Win32.Stelega.bsn
BitDefenderTrojan.GenericKD.37269528
MicroWorld-eScanTrojan.GenericKD.37269528
Ad-AwareTrojan.GenericKD.37269528
McAfee-GW-EditionBehavesLike.Win64.Trojan.vc
FireEyeTrojan.GenericKD.37269528
EmsisoftTrojan.GenericKD.37269528 (B)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftVirTool:Win64/Splinter.A!MTB
GDataTrojan.GenericKD.37269528
McAfeeArtemis!24E83AECD38D
MAXmalware (ai score=99)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0DGK21
IkarusTrojan-PSW.Agent
FortinetW32/Agent.M!tr.pws
AVGWin64:Trojan-gen
Qihoo-360Win64/Trojan.Generic.HgEASYwA

How to remove WinGo/PSW.Agent.M?

WinGo/PSW.Agent.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment