Trojan

WinGo/TrojanDropper.Agent.CN removal guide

Malware Removal

The WinGo/TrojanDropper.Agent.CN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/TrojanDropper.Agent.CN virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine WinGo/TrojanDropper.Agent.CN?


File Info:

name: 6A9A8830A4C845691102.mlw
path: /opt/CAPEv2/storage/binaries/0019d51be25f61d71ea13808bd3f8f4e76f3e15a254114dc9c6755539e8536ff
crc32: 7713AFD8
md5: 6a9a8830a4c845691102a9cf91a92e22
sha1: da8ee30609175279ea72581c722e310f981b34fd
sha256: 0019d51be25f61d71ea13808bd3f8f4e76f3e15a254114dc9c6755539e8536ff
sha512: b8583c525a6d77a7efc00a50c216a79e4147b2890581d9cd455436d8055cafbef18d8c6db21ecb15ab3bbf68a7021d74d9318325b088465e22c52067e8f332fd
ssdeep: 49152:MwAoUvqHIhXjEK9lLYYcUreB9UHcv1EelrdeMgmJmZ+:9ArFhoKprftexTgmJX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115168D41FAC7C4B2E9426835855763AF63308D0A8F28DF97F2007BAEE9776921C77245
sha3_384: 03c01eada9b06d01c22acbfbdd9cd7d81da758cffbef0f4252e1dc5b4badc660217c192e31d1b2666b23bc8aff4765e2
ep_bytes: e9dbddffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: Software Appcation
CompanyName: Alibaba
FileDescription: Files Menager
FileVersion: v1.0.0.1
InternalName: Menager
LegalCopyright: Copyright (c) 2021 XCGUI
OriginalFilename: Menager.exe
ProductName: Menager
ProductVersion: v1.0.0.1
Translation: 0x0804 0x04b0

WinGo/TrojanDropper.Agent.CN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lotok.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70243783
SkyhighArtemis!Trojan
ALYacTrojan.GenericKD.70243783
Cylanceunsafe
ZillyaDropper.Agent.Win32.566195
K7AntiVirusTrojan ( 005ad58e1 )
AlibabaBackdoor:Win32/Lotok.a59c6be1
K7GWTrojan ( 005ad58e1 )
ArcabitTrojan.Generic.D42FD5C7
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of WinGo/TrojanDropper.Agent.CN
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Lotok.sdw
BitDefenderTrojan.GenericKD.70243783
NANO-AntivirusTrojan.Win32.Lotok.kcxpcs
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent_yh.16001067
EmsisoftTrojan.GenericKD.70243783 (B)
F-SecureBackdoor.BDS/Redcap.romsf
VIPRETrojan.GenericKD.70243783
TrendMicroTROJ_GEN.R011C0XKC23
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.70243783
SophosMal/Generic-S
IkarusTrojan-Dropper.WinGo.Agent
GoogleDetected
AviraBDS/Redcap.romsf
Antiy-AVLTrojan[Backdoor]/Win32.Lotok
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmBackdoor.Win32.Lotok.sdw
GDataTrojan.GenericKD.70243783
AhnLab-V3Malware/Win.Malware-gen.R619258
McAfeeArtemis!6A9A8830A4C8
MAXmalware (ai score=88)
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011C0XKC23
RisingBackdoor.Agent!1.ECF5 (CLASSIC)
MaxSecureTrojan.Malware.219918995.susgen
BitDefenderThetaGen:NN.ZexaF.36744.6F2@ae00v!ii
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove WinGo/TrojanDropper.Agent.CN?

WinGo/TrojanDropper.Agent.CN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment