Trojan

Trojandropper.Convagent removal guide

Malware Removal

The Trojandropper.Convagent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojandropper.Convagent virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojandropper.Convagent?


File Info:

name: 83197D21354AEE50559B.mlw
path: /opt/CAPEv2/storage/binaries/1b3b8df6ccf68a06ee76bc81cb3c9dd05c48ec6c29e9ebca0603ac8a55d1a2b0
crc32: 869810DD
md5: 83197d21354aee50559bcd305ea9edbe
sha1: 52a38210b2f5c074e6ce943ca376a0ec6d780559
sha256: 1b3b8df6ccf68a06ee76bc81cb3c9dd05c48ec6c29e9ebca0603ac8a55d1a2b0
sha512: a742f27c5d233fc33288b4929b7cc7cff2bce40550f3587fa23b2e6e5fb94fd55795846c1a488817d8fcacb1e0f2cf75facbfea33a489d491c6f7b51218b5d38
ssdeep: 384:P+MPc8IvIbMiqWa/injw7YBDoojyzEafa0BN5cZLntotrG+0rpxXhV5/3f6ffr:P+MPc8IvIbMBWa/injwUBDoo+zJpBN53
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0921A1513949732E86D67FBD86361000BF2F211C317FB5E3ECE90DA9A57A064B86F42
sha3_384: 71c11040b2ae5f67ba0c035cd6ddd2443bdccbe0028caa375e4ad52cee6f297eff8c5137cab58141577e90203b4acd46
ep_bytes: ff250020400000000000000000000000
timestamp: 2085-08-31 19:47:45

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Liikkuu
FileVersion: 1.0.0.0
InternalName: Liikkuu.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Liikkuu.exe
ProductName: Liikkuu
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojandropper.Convagent also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Convagent.b!c
MicroWorld-eScanTrojan.GenericKD.62045639
FireEyeTrojan.GenericKD.62045639
CAT-QuickHealTrojandropper.Convagent
ALYacTrojan.GenericKD.62045639
CylanceUnsafe
SangforDropper.Win32.Convagent.V82g
CyrenW32/ABTrojan.FWCA-8716
APEXMalicious
KasperskyVHO:Trojan-Dropper.Win32.Convagent.gen
BitDefenderTrojan.GenericKD.62045639
AvastWin32:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKD.62045639
VIPRETrojan.GenericKD.62045639
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.62045639 (B)
GDataTrojan.GenericKD.62045639
GoogleDetected
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.8182
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D3B2BDC7
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!83197D21354A
TrendMicro-HouseCallTROJ_GEN.R002H09IL22
RisingDropper.Convagent!8.123ED (CLOUD)
MaxSecureTrojan.Malware.109757858.susgen
FortinetPossibleThreat
AVGWin32:DropperX-gen [Drp]
PandaTrj/Chgt.AD

How to remove Trojandropper.Convagent?

Trojandropper.Convagent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment