Trojan

How to remove “WinGo/TrojanDownloader.Agent.AW”?

Malware Removal

The WinGo/TrojanDownloader.Agent.AW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/TrojanDownloader.Agent.AW virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine WinGo/TrojanDownloader.Agent.AW?


File Info:

name: 4FB07099E1084EF23D8B.mlw
path: /opt/CAPEv2/storage/binaries/997b9e2dfd10eb0a22d5f2a34c1176d0fabd367922dc395a258b06a4a2636d37
crc32: 3535576D
md5: 4fb07099e1084ef23d8b51b4d5ec2fa0
sha1: edb7b7b420e30acab52c7edda7018e49a9521916
sha256: 997b9e2dfd10eb0a22d5f2a34c1176d0fabd367922dc395a258b06a4a2636d37
sha512: 339d8f74475977715b65fb8c99f3e74db88d7e74879a904966354faf21e4bbaa362e04bc20497b3b4ca3a49647143cd69b8ed2f650e0a92169e3923d8eca95d5
ssdeep: 12288:Xu6JcCx0qt6z21TDgZeMpfQVQWYG+0bbB/pegDh/8YqP5EFW2Plh1+:P7USDgZhdGrqgDh/GPj2PD1
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T103556B07B89060BAD07AD1328966B2A17B31B495033113C73BA2A7FE5F77BD41E79358
sha3_384: 87aaa9b09bfff09ec5c4ed82f8dc51f4b7a6d4786f8da263a1d7bf4e482fe45c0565709ebf8aeecb83a420ef4e59c531
ep_bytes: e97bc3ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

WinGo/TrojanDownloader.Agent.AW also known as:

Elasticmalicious (high confidence)
ClamAVWin.Trojan.Bulz-9879188-0
ALYacTrojan.GenericKDZ.79689
MalwarebytesTrojan.Downloader.GO
ZillyaBackdoor.Cobalt.Win32.80
BitDefenderTrojan.GenericKDZ.79689
CyrenW64/Agent.CJJ.gen!Eldorado
ESET-NOD32a variant of WinGo/TrojanDownloader.Agent.AW
APEXMalicious
AvastWin64:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Cobalt.jk
MicroWorld-eScanTrojan.GenericKDZ.79689
TencentMalware.Win32.Gencirc.10cf8907
Ad-AwareTrojan.GenericKDZ.79689
DrWebBackDoor.Meterpreter.157
FireEyeTrojan.GenericKDZ.79689
EmsisoftTrojan.GenericKDZ.79689 (B)
IkarusTrojan.WinGo.Rozena
GDataTrojan.GenericKDZ.79689
AviraHEUR/AGEN.1201992
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34CCAEE
ArcabitTrojan.Generic.D13749
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4759255
McAfeeGenericRXAA-AA!4FB07099E108
RisingBackdoor.CobaltStrike!1.D9A1 (CLASSIC)
YandexBackdoor.Cobalt!0M0A3rdHYJ4
SentinelOneStatic AI – Suspicious PE
AVGWin64:DropperX-gen [Drp]
Cybereasonmalicious.420e30
MaxSecureTrojan.Malware.300983.susgen

How to remove WinGo/TrojanDownloader.Agent.AW?

WinGo/TrojanDownloader.Agent.AW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment