Trojan

Trojan.ConvagenPMF.S25423350 removal guide

Malware Removal

The Trojan.ConvagenPMF.S25423350 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ConvagenPMF.S25423350 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Nepali
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.ConvagenPMF.S25423350?


File Info:

name: 6493C8583C3F7122354B.mlw
path: /opt/CAPEv2/storage/binaries/5b3f6753284b50594ecb703a9f17586c62bba24fb55059802024e5baef128b96
crc32: 986C01F7
md5: 6493c8583c3f7122354b9ca880f5c68a
sha1: 31c11d3b1a44da215d65854d045899d9fe3f7c9a
sha256: 5b3f6753284b50594ecb703a9f17586c62bba24fb55059802024e5baef128b96
sha512: 77d5bb13ba07d5e753b59032aaa954ea513bc1bda5944fa801063a350b7e8d69648fa44511ceb8767bfc37cb489969f8c502271358ec0ec0a315fb3c5981e86c
ssdeep: 6144:yc4bw5wJGgzIr6FoZoDPCX1TxUTRoeWjXFe6G7zpIEdDh+c46I8M1s5:yc4izXsPCNqyeWLQFBImd+UGA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D94DF1132C0C032D4A664B54D27E7F15EBAB4B016666ACBBFD85FB85F346C1A72630E
sha3_384: 3242f260b74abe378aec1bdcea723a76ae85779fe797d21161f8e5dc3b1be09096d7e47d3f0cb989184dd100da2dc1ae
ep_bytes: e86f890000e978feffff8bff558bec83
timestamp: 2020-11-10 16:43:16

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.0.25.71
InternalName: eaLatemas
LegalCopyrighd: Jdfglsdffa
Translations: 0x0169 0x0300

Trojan.ConvagenPMF.S25423350 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38198222
FireEyeGeneric.mg.6493c8583c3f7122
CAT-QuickHealTrojan.ConvagenPMF.S25423350
McAfeePacked-GBE!6493C8583C3F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b6d61 )
AlibabaTrojanSpy:Win32/Azorult.a47a86c9
K7GWTrojan ( 0058b6d61 )
Cybereasonmalicious.b1a44d
CyrenW32/Kryptik.FXB.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNOO
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderTrojan.GenericKD.38198222
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan-spy.Stealer.Wopv
Ad-AwareTrojan.GenericKD.38198222
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Stealer.31716
ZillyaTrojan.Kryptik.Win32.3645321
TrendMicroTROJ_GEN.R002C0DL821
McAfee-GW-EditionBehavesLike.Win32.Worm.gc
SophosML/PE-A + Troj/Krypt-BO
IkarusTrojan.Win32.Azorult
GDataWin32.Trojan.PSE.182S8MB
JiangminTrojanSpy.Stealer.jvk
AviraTR/AD.GenSHCode.udtwy
Antiy-AVLTrojan/Generic.ASMalwS.34E68E8
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.AzorUlt.sa
ViRobotTrojan.Win32.Z.Win.425984
MicrosoftTrojan:Win32/Azorult.RM!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R456355
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.Aq0@a4eZZfiG
ALYacTrojan.GenericKD.38198222
MAXmalware (ai score=85)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0DL821
RisingTrojan.Kryptik!1.DAF8 (CLOUD)
YandexTrojan.Kryptik!qRzNZGIjZvU
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HNOL!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.ConvagenPMF.S25423350?

Trojan.ConvagenPMF.S25423350 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment