Trojan

Trojan.ConvagentPMF.S24877890 removal

Malware Removal

The Trojan.ConvagentPMF.S24877890 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ConvagentPMF.S24877890 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Trojan.ConvagentPMF.S24877890?


File Info:

name: FBDB1F09BC66B31448D8.mlw
path: /opt/CAPEv2/storage/binaries/bcef1381493cade6353d8c73f4b8f0d6fc29505e0002a09503ff4cfaf55d3a37
crc32: 30744945
md5: fbdb1f09bc66b31448d83573768d2011
sha1: 556fb1bd654ff5c8f41c7a858dea19dafad6c5af
sha256: bcef1381493cade6353d8c73f4b8f0d6fc29505e0002a09503ff4cfaf55d3a37
sha512: 5b91be189018a5d81d912608c3bb0e26573cf49a370354e77c3f8aa2475568f0a14c3ff69056c56f1df538b39dbdce6839052514a0248b012467abf02e7dd03b
ssdeep: 12288:OQNFtqgBst6sev1QKI8BjI/Mf6KJ4N6aXf6XOu8O2ozfixQIhqSwLuWr:kgByg9fIyjso2TXfTJHkfDIhqmWr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T15E947C6E94580348F68F6FFECC2D6FEEF599BA923B01911D926A29C78B2137FC401511
sha3_384: 2f00dfbae2784df89304cf18341a306b8ab4d72a1ac4abf6c3d6423501240ec4e281b4acb74a38ab96826266fa3a1249
ep_bytes: 558bec83ec188b450c8945f4837df401
timestamp: 2021-11-18 08:39:05

Version Info:

0: [No Data]

Trojan.ConvagentPMF.S24877890 also known as:

MicroWorld-eScanTrojan.GenericKDZ.80412
FireEyeTrojan.GenericKDZ.80412
CAT-QuickHealTrojan.ConvagentPMF.S24877890
McAfeeTrickbot-FUBI!FBDB1F09BC66
CylanceUnsafe
K7AntiVirusTrojan ( 0058ab1e1 )
BitDefenderTrojan.GenericKDZ.80412
K7GWTrojan ( 0058ab1e1 )
CyrenW32/TrickBot.GZ.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HNKT
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareTrojan.GenericKDZ.80412
SophosTroj/Trickb-DM
DrWebTrojan.Trick.46920
ZillyaTrojan.Convagent.Win32.7760
McAfee-GW-EditionTrickbot-FUBI!FBDB1F09BC66
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34D6B0B
MicrosoftTrojan:Win32/Trickbot.AB!MTB
GDataWin32.Trojan.PSE.4MYCK3
AhnLab-V3Trojan/Win.FUBI.R451717
ALYacTrojan.GenericKDZ.80412
VBA32Trojan.Convagent
MalwarebytesTrojan.MalPack
YandexTrojan.Kryptik_AGen!ctruSyjZ8lU
IkarusTrojan-Spy.Win32.TrickBot
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]

How to remove Trojan.ConvagentPMF.S24877890?

Trojan.ConvagentPMF.S24877890 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment